Security Module Data Access Control via Multiple Verification Methods

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access control methods in security modules require users to remember multiple passwords and do not allow for specific release of subsets of data, as they use a single mechanism for different application contexts, limiting flexibility and user convenience.

Innovation Solution

A method for data access control in a security module that uses the same password for multiple verification methods, allowing access to different data sets based on selected password verification methods, such as alphanumeric comparison or cryptographic verification, enabling specific data access or blocking, and utilizing attributes for enhanced control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple independent user authentication data items are used for different applications, then data access security is improved, but user convenience deteriorates due to the need to remember multiple passwords

Engineering Contradiction:
Improvedata access securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process by introducing multiple password verification methods (first and second verification methods) that can be selectively applied. Instead of using multiple different passwords, the system divides the verification approach into distinct methods, where each method can be associated with different data access rights. This allows the same password to serve multiple purposes while maintaining security through method-based differentiation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of verification from password diversity to verification method diversity. By keeping the password constant and varying the verification method (e.g., different cryptographic protocols, different challenge-response mechanisms), the system achieves both security and convenience. The verification method acts as an additional parameter that controls access without requiring users to remember multiple passwords.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If a single password verification mechanism is used for all applications, then ease of operation is improved, but data access control flexibility deteriorates as specific data subsets cannot be selectively released

Engineering Contradiction:
Improveease of operationVSAvoiddata access control flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by associating different password verification methods with different data sets or application contexts. The first password verification method may be used for accessing general data, while the second method is used for accessing sensitive data subsets. This localized differentiation of verification methods enables selective data release without compromising overall system simplicity or user convenience.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If multiple password verification methods are implemented with the same password, then data access control flexibility is improved, but device complexity increases

Engineering Contradiction:
Improvedata access control flexibilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a password verification system where a single password can be verified through multiple different methods. The same password serves as the basis for both the first and second verification methods, allowing the system to handle different authentication scenarios without requiring multiple separate password storage mechanisms. This multi-functional approach reduces complexity compared to implementing entirely separate authentication systems for different data access levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3036673B1Method for data access control
Publication Date: 2018.11.28 BUNDESDRUCKEREI GMBH
  • EP3036673B1 patent drawingFigure 1
  • EP3036673B1 patent drawingFigure 2
  • EP3036673B1 patent drawingFigure 3

AI summary

The present invention relates to a method for data access control in a security module (100) that comprises a memory (103) having first data (105–1) and second data (105–2), wherein the first data (105-1) and the second data (105-2) are protected by means of the same password (101), having the steps of selection of a first password verification method (107-1) or a second password verification method (107-2); approval of access to the first data (105-1) of the security module (100) when the password is verified by means of the first password verification method (107-1); and approval of access to the second data (105-2) of the security module (100) when the password is verified by means of the second password verification method (107-2).