Token Device Authentication via Root Directory Name Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud storage security methods, such as encryption and hashing, are inadequate in preventing unauthorized access to private data, and the use of USB flash drives for data storage limits accessibility and security, as they can be easily compromised if stolen.
Innovation Solution
A token device with wireless capabilities, including a memory, private data conceal engine, radio, and cryptosystem, is used to securely access and store data by transferring a root directory name as a password to authenticate and retrieve private data, while generating a unique compressed URL to hide URL footprints and manage data visibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and hashing are used to secure cloud storage, then data confidentiality is improved, but vulnerability to brute force attacks and unauthorized access persists
Solution Approach 1:
The patent segments the authentication process into multiple stages: first authentication using a password, then second authentication using a token generated by the security device. This multi-layered segmentation prevents brute force attacks from directly compromising the root password, as each layer independently validates credentials before granting access to protected resources.
Solution Approach 2:
The patent introduces a token as an intermediary authentication mechanism between the user and the cloud storage system. The token, generated by a separate security device, acts as a mediator that verifies the user's identity without exposing the root password to potential attackers, thereby preventing unauthorized access even if the password database is compromised.
2Ease of operation
If USB flash drives are used for data storage, then portability is improved, but security is worsened due to easy compromise if stolen
Solution Approach 1:
The patent extracts the authentication credentials (root password and token) from the cloud storage system and places them in a separate, user-controlled security device. This separation means that even if the USB flash drive or cloud storage is stolen, attackers cannot access protected resources without both the password and token from the security device, thereby maintaining security while preserving portability.
Solution Approach 2:
The security device acts as an intermediary that holds and manages authentication credentials separately from the storage media. This intermediary layer prevents direct compromise of stored data, as the security device must be present and authenticated to access protected resources, regardless of whether the storage device is lost or stolen.
3Ease of operation
If cloud storage is used for data accessibility, then data retrieval convenience is improved, but security control is worsened
Solution Approach 1:
The patent segments security control by implementing separate authentication mechanisms for different access levels: cloud-based password verification for initial access, and token-based verification for accessing protected resources. This segmentation allows convenient cloud accessibility while maintaining strict security control through the additional token authentication layer.
Solution Approach 2:
The security device serves as an intermediary that bridges cloud accessibility and security control. It enables users to access data conveniently from any location while the token authentication mechanism ensures that only authorized users can access protected resources, preventing unauthorized access even if cloud credentials are compromised.
Data Source
AI summary
A computer-implemented method for providing security to access and store data may include transferring first information for display from a token device having a memory to a first computing device at a first time, the token device connected to the first computing device and the first information describing public data stored on the token device. A request to retrieve a root directory of private data may be received, the request specifying a root directory name. In response to receiving the request to retrieve a root directory of private data, the root directory may be requested by establishing a wireless connection between the token device and a server computing device, transferring the root directory name to the server computing device, wherein the root directory name is used as a password to retrieve the root directory, and receiving the root directory from the server computing device by the token device.


