Security Module Data Access Control via Multiple Verification Methods
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data access control methods in security modules require users to remember multiple passwords and do not allow for specific release of subsets of data, as they use a single mechanism for different application contexts, limiting flexibility and user convenience.
Innovation Solution
A method for data access control in a security module that uses the same password for multiple verification methods, allowing access to different data sets based on selected password verification methods, such as alphanumeric comparison or cryptographic verification, enabling specific data access or blocking, and utilizing attributes for enhanced control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple independent user authentication data items are used for different applications, then data access security is improved, but user convenience deteriorates due to the need to remember multiple passwords
Solution Approach 1:
The patent segments the authentication process by introducing multiple password verification methods (first and second verification methods) that can be selectively applied. Instead of using multiple different passwords, the system divides the verification approach into distinct methods, where each method can be associated with different data access rights. This allows the same password to serve multiple purposes while maintaining security through method-based differentiation.
Solution Approach 2:
The patent changes the parameter of verification from password diversity to verification method diversity. By keeping the password constant and varying the verification method (e.g., different cryptographic protocols, different challenge-response mechanisms), the system achieves both security and convenience. The verification method acts as an additional parameter that controls access without requiring users to remember multiple passwords.
2Ease of operation
If a single password verification mechanism is used for all applications, then ease of operation is improved, but data access control flexibility deteriorates as specific data subsets cannot be selectively released
Solution Approach 1:
The patent applies local quality by associating different password verification methods with different data sets or application contexts. The first password verification method may be used for accessing general data, while the second method is used for accessing sensitive data subsets. This localized differentiation of verification methods enables selective data release without compromising overall system simplicity or user convenience.
3Adaptability or versatility
If multiple password verification methods are implemented with the same password, then data access control flexibility is improved, but device complexity increases
Solution Approach 1:
The patent implements universality by designing a password verification system where a single password can be verified through multiple different methods. The same password serves as the basis for both the first and second verification methods, allowing the system to handle different authentication scenarios without requiring multiple separate password storage mechanisms. This multi-functional approach reduces complexity compared to implementing entirely separate authentication systems for different data access levels.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method for data access control in a security module (100) that comprises a memory (103) having first data (105–1) and second data (105–2), wherein the first data (105-1) and the second data (105-2) are protected by means of the same password (101), having the steps of selection of a first password verification method (107-1) or a second password verification method (107-2); approval of access to the first data (105-1) of the security module (100) when the password is verified by means of the first password verification method (107-1); and approval of access to the second data (105-2) of the security module (100) when the password is verified by means of the second password verification method (107-2).