Segmented Data Protection with Blockchain Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection systems are inadequate in securing personal data from hacking and identity theft, as they often store sensitive information in a centralized database that can be compromised, leading to significant inconveniences and risks for users.
Innovation Solution
A data protection system that divides personal data into individually encrypted components, stored in a zero-knowledge storage repository using blockchain technology, with a separate authentication system providing selective access through a user interface and biometric authentication, ensuring secure transactions and protecting sensitive information from unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If personal data is stored in a centralized database for easy access and management, then data accessibility and operational efficiency are improved, but security against hacking and data breaches deteriorates
Solution Approach 1:
The patent divides personal data into multiple separate components and stores them in different locations within a distributed ledger system. Each component can be individually accessed and managed, eliminating the single point of failure inherent in centralized databases while maintaining data accessibility through selective component retrieval.
Solution Approach 2:
The patent introduces cryptographic keys and authentication mechanisms as intermediaries between users and their data. These intermediaries enable secure access control without requiring a centralized authority, allowing users to maintain control over their data components while ensuring security against unauthorized access.
2Reliability
If data is encrypted into multiple components and stored in a distributed ledger, then security and protection against breaches are improved, but system complexity and access management difficulty increase
Solution Approach 1:
The patent implements a universal authentication mechanism that works across all data components in the distributed ledger. The cryptographic key system serves multiple functions including authentication, authorization, and data retrieval, simplifying access management despite the distributed nature of the system.
Solution Approach 2:
The patent incorporates authentication feedback mechanisms where the system verifies user credentials and grants or denies access to specific data components based on authentication results. This feedback loop simplifies complex access management by providing clear authorization decisions for each data access request.
3Reliability
If traditional data breach response methods are used (issuing new credit cards), then data security is restored, but user convenience and time efficiency deteriorate due to manual updates and processing delays
Solution Approach 1:
The patent enables users to pre-authenticate and set up access rules for their data components before any breach occurs. In the event of a security incident, the system can automatically execute pre-configured responses such as revoking access to specific data components or generating new cryptographic keys, eliminating the need for manual card issuance and system updates.
Solution Approach 2:
The patent implements automated security response mechanisms where the system itself handles breach mitigation without requiring manual intervention. When a breach is detected or authorized, the system automatically manages data component access, generates new cryptographic credentials, and updates access controls, saving significant time compared to traditional manual processes.
Data Source
AI summary
A data protection system (10) and method are disclosed. The data protection system (10) includes a data repository (20), a data access interface (30) and an authentication system (40). The data repository (20) stores user data (25) for a user (50). The user data (25) comprises a plurality of individually encrypted components (25a-25e). The data access interface (30) is arranged to provide remote access to each of the individually encrypted components (25a-25e) in encrypted form. The data protection system (10) is arranged to provide selective access to each individual component in unencrypted form upon the authentication system authenticating the user for the respective component.


