Trusted Intermediary for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data exchange processes, especially over the Internet, there is a lack of secure methods to ensure that sensitive information is only accessed by authorized parties, with intermediaries potentially learning identities or obtaining information without user consent, and existing solutions like secure comparison protocols can lead to privacy violations or increased risks of manipulation.

Innovation Solution

A method involving an intermediary device that uses secure comparison protocols with random bits and hash functions to ensure that only the user can authorize the forwarding of information, preventing intermediaries from accessing or learning identities, without requiring user certificates or additional cryptographic keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional encryption and signing techniques are used for data exchange, then security and authentication are improved, but privacy loss increases because intermediaries can infer information from requests and responses

Engineering Contradiction:
ImprovesecurityVSAvoidprivacy loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a trusted intermediary device C that acts as a mediator between the user U, information provider A, and information receiver B. This intermediary enables secure data exchange while preventing direct observation of sensitive information by any single party. The intermediary uses cryptographic techniques to ensure that no party can infer private information from the communication patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the comparison logic from the user device and places it in the trusted intermediary device. This allows the user to avoid directly comparing sensitive information with the information provider, thereby preventing the provider from inferring the user's private data while still enabling the comparison function.

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of information

If a trusted intermediary device is introduced to protect user privacy, then privacy protection is improved, but device complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The trusted intermediary device C is designed to perform multiple functions: it acts as a certificate authority, a secure comparison processor, and an encrypted communication relay. By consolidating these functions in a single multi-functional device, the patent reduces the need for multiple separate complex components while maintaining privacy protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If secure comparison protocols are used to prevent information inference, then privacy protection is improved, but the risk of manipulation increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidmanipulation risk
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the trusted intermediary device receives encrypted data from the user, performs comparison operations, and returns results to the user without revealing intermediate information. This closed-loop feedback system ensures that the comparison is performed securely while maintaining accountability and preventing manipulation by any single party.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10116445B2Method and system for protected exchange of data
Publication Date: 2018.10.30 TRUSTTESTER SOLUTIONS BV
  • US10116445B2 patent drawing
  • US10116445B2 patent drawing
  • US10116445B2 patent drawing

AI summary

A result of application of a test to information about a user (U) is securely transmitted between a source of information (A) and a destination of information (B) via an intermediary device (C). The source of information can be, for example, a database of personal data, and the destination of information (B) a server of a service provider performing services depending on an age limit. The intermediary device (C) minimizes the information that is made available to the source (A) and the destination (B) about the purpose of the test and the underlying data. To this end, the intermediary device (C) executes a secure comparison protocol with the source (A), whereby the encrypted result is additionally blinded, for example, with a blinding that comes from the user. The intermediary device (C) decrypts the blinded encrypted result, so that a blinded result is left. The destination B removes the blinding, preferably on the basis of blinding information of the user. The intermediary device (C) preferably sends the blinded comparison result to the user (U).