TrustCenter Mediator for Secure Digital Message Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital message transmission methods, such as E-letter services, do not adequately secure confidential information as they require recipients to manage and protect encryption keys, install additional software, and may expose professional secrets to third parties, including service providers.

Innovation Solution

A method utilizing a TrustCenter for asymmetrical encryption, where users create a password-derived user secret encrypted with the TrustCenter's public key, ensuring the service only administers and stores encrypted keys, allowing secure transmission without additional device requirements and maintaining confidentiality for professionals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end encryption is implemented, then security of confidential information is improved, but device complexity and key management requirements worsen

Engineering Contradiction:
Improvesecurity of confidential informationVSAvoidkey management requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a TrustCenter as an intermediary that generates and manages encryption keys on behalf of users. The TrustCenter creates key pairs, stores private keys securely, and provides public keys to communication parties. This mediator eliminates the need for users to manually manage cryptographic keys while maintaining end-to-end encryption security, directly resolving the contradiction between security and key management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The TrustCenter automatically performs key generation, storage, and distribution without requiring user intervention. The system self-manages the cryptographic infrastructure by automatically creating key pairs when users register, securing private keys in encrypted form, and providing public keys as needed. This automation eliminates manual key management tasks for users while preserving security

Inventive Principle:
Principle #25Self-service

2Reliability

If additional software modules are required for decryption, then security is improved, but ease of operation worsens

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The TrustCenter acts as a mediator that handles all cryptographic operations centrally. Instead of requiring recipients to install and configure decryption software modules, the TrustCenter manages key pairs and enables decryption through its service interface. Users simply interact with the TrustCenter portal to send and receive encrypted messages, eliminating the need for additional software while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines key generation, key storage, key distribution, and decryption functionality into a single integrated TrustCenter service. This consolidation eliminates the need for separate software modules on user devices, as all cryptographic functions are performed through the centralized TrustCenter platform, thereby improving ease of operation without compromising security

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If service providers can access message content, then ease of operation is improved, but confidentiality for professionals worsens

Engineering Contradiction:
Improveease of operationVSAvoidexposure of professional secrets
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cryptographic functions by separating private key storage from message transmission infrastructure. The TrustCenter generates and stores private keys in encrypted form, while the message transmission system only handles encrypted content without access to decryption keys. This segmentation ensures that even if the transmission system is compromised, professional secrets remain protected, while the service remains easy to operate through centralized management

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If conventional encryption methods are used, then ease of operation is improved, but security against third parties worsens

Engineering Contradiction:
Improveease of operationVSAvoidsecurity against third parties
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The TrustCenter serves as a mediator that implements end-to-end encryption automatically, protecting messages from third parties including the service provider itself. The TrustCenter generates key pairs, secures private keys in encrypted storage, and enables communication parties to exchange encrypted messages without the service provider having access to decryption capabilities. This maintains ease of operation through centralized management while achieving strong security against third parties

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9876642B2Method for securely transmitting a digital message
Publication Date: 2018.01.23 DEUT POST AG
  • US9876642B2 patent drawing
  • US9876642B2 patent drawing
  • US9876642B2 patent drawing

AI summary

A method is provided for securely transmitting a digital message that is transmitted by means of an electronic letter service. A user of the service has a computer with a functioning browser and an Internet connection, and the electronic letter service makes use of a TrustCenter. The user creates a password using his/her browser. A user password verifier is cryptographically derived from the password. The user password verifier is transmitted to the electronic letter service and stored on a storage medium. A user secret is generated from the password by means of a cryptographic derivation. The user secret constitutes the symmetrical key for the encryption of a user-specific user master secret. The user secret is encrypted using the public key of the TrustCenter and the encrypted user secret is transmitted to the electronic letter service, from where it is then forwarded to the TrustCenter.