Split Encrypted Data Storage for Recurring Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing tokenization systems for secure transactions do not adequately protect sensitive information, as a security breach of a single database can expose the information, and there is a need to allow recurring access without re-entering sensitive data.
Innovation Solution
Encrypt sensitive information into multiple parts and store these parts in separate, secure databases controlled by different entities, requiring collaboration from multiple parties to access the information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive information is stored in databases to enable recurring transactions, then access to sensitive information is enabled for recurring transactions, but the risk of unauthorized access increases
Solution Approach 1:
The patent divides the sensitive information into multiple separate databases, each storing only a portion of the data. To access the complete sensitive information, an attacker would need to breach multiple databases, significantly increasing the difficulty and risk of unauthorized access while still enabling legitimate recurring transactions through proper authentication mechanisms.
2Object-affected harmful factors
If sensitive information is not stored anywhere to minimize security risk, then the risk of unauthorized access is reduced, but access to sensitive information for recurring transactions is prevented
Solution Approach 1:
Instead of storing sensitive information in a single location or not storing it at all, the system segments the data across multiple databases. This allows the system to maintain security by distributing risk while enabling access through controlled retrieval operations that require proper authentication and authorization.
Solution Approach 2:
The patent introduces an intermediary mechanism (such as a security module or authentication system) that mediates between the need for secure data storage and the need for recurring access. This intermediary handles the retrieval and validation processes, allowing legitimate access while preventing unauthorized access to the segmented data.
3Ease of operation
If sensitive information is stored at a single location for convenience, then ease of access is improved, but the impact of a security breach increases
Solution Approach 1:
The patent applies segmentation by dividing the sensitive information into multiple separate databases stored at different locations. This segmentation ensures that a security breach at one location does not result in complete data exposure, as each database contains only a portion of the sensitive information. The system maintains ease of access through centralized retrieval mechanisms that properly authenticate users.
Data Source
AI summary
A transaction system avoids the storage of any single information item that can be used to provide access to sensitive information. To gain access to the sensitive information, information elements from at least two different databases must be provided, none of the information elements being sufficient to gain access to the sensitive information. In an example embodiment, a payment company encrypts the sensitive information, then partitions the encrypted information into at least two parts. These at least two parts are stored in at least two databases, each database being controlled by a different entity. To gain access to the sensitive information, each of the different entities must provide their part of the encrypted information. Absent any one of the parts of the encrypted information, it is virtually impossible to access the sensitive information.


