Press Relase / News Release Distribution Service [@Press]

Note: This page is a machine translation of the Japanese original and is provided for reference only.
In the event of any discrepancy between this page and the original, the original shall prevail. Click here for the original text.

Toward Security That "Prevents Further Exploitation Even If a Breach Occurs" K-Trust Obtains Its Sixth Patent for "Theory of Validation Points for Infinite-Key Multi-Time-Varying Systems"

~Dynamically changing validation conditions and controlling critical processes in multiple stages~

株式会社Kトラスト

無数鍵多重時変成立点理論モデル

Theoretical Model of a Multi-Key, Multi-Time-Varying Fixed-Point

成立点と多重時変のイメージ

Conceptual Illustration of Valid Points and Multiple Time-Varying Variables


Yuki Takeuchi of K Trust Co., Ltd. is pleased to announce the completion of the registration of the sixth patent right related to the intellectual property portfolio for the next-generation security concept, “Theory of Valid Points for Multiple Time-Varying Functions with Infinite Keys.”

The patent registered this time is Patent No. 7896833, titled “Information Processing Apparatus, Information Processing Method, Information Processing Program, and Information Processing System.”

To date, we have received 17 patent grants for related invention applications, and the registration of patent rights has been completed for six of these.



■ Our goal is not merely to “absolutely prevent information leaks”

In today’s internet-driven society, vast amounts of information are stored everywhere—including at companies, government agencies, financial institutions, medical facilities, e-commerce platforms, and social media sites. Of course, preventing information leaks themselves is extremely important.However, in the society of the future, that alone will not be enough. This is because leaked information can be reused to commit subsequent crimes, following a chain such as phishing scams → identity theft → account compromise → unauthorized fund transfers → fraudulent purchases → further attacks on individuals and companies.In other words, the real issue we must consider is not merely “Has information been leaked?” but rather, “Can the leaked information alone be used to carry out the next attack?”

We want to change this situation.



■ Moving toward a “future without data breaches” and, at the same time, a “future where leaked data cannot be exploited”

The ideal scenario is to eliminate data breaches entirely. However, it is not easy to permanently reduce all servers, devices, networks, human error, internal misconduct, and unknown vulnerabilities worldwide to zero. This is where second and third lines of defense become crucial.Even if some information were to leak externally, simply knowing that information would not be enough to execute the next critical process. This way of thinking represents the overarching direction of this initiative.

In addition to the first line of defense—“preventing leaks”—we aim to establish a second line of defense in society: “preventing the execution of critical operations even if a leak occurs.”

Through this, we aim to build a social infrastructure that curbs secondary and tertiary damages—such as phishing, identity theft, unauthorized logins, and fraudulent fund transfers—that stem from information leaks.


フィッシング詐欺撲滅

Eradicating Phishing Scams


■ Another challenge is that “people continue to adapt to PINs”

With current authentication methods, users are often burdened with requirements such as “Use a long password,” “Include uppercase and lowercase letters, numbers, and symbols,” “Do not reuse the same password,” “Change it regularly,” and “Manage multiple sets of credentials.”

The more we try to strengthen security, the more things people may have to remember and manage. As a result, other problems arise, such as forgetting passwords, reusing them, writing them down, or simplifying them.

Our goal is not to “make things complicated for people,” but rather to adopt an approach where “the system itself becomes complex and dynamic.”



■ From “Making Passcodes Complex” to “Making Validation Conditions Complex”

The key point is that using simple authentication credentials does not, in and of itself, guarantee security.The key point of this concept is not to rely solely on the number of characters or the complexity of the PIN itself for security. Instead, it utilizes multiple pieces of information and conditions, allowing the roles of some of these elements to change over time, thereby generating identification information that is valid only for a short period. Furthermore, critical operations are executed only when all necessary conditions are met.Once a condition has been met, time has elapsed, or it has been confirmed that the condition has not been met, the short-term identification information is revoked. In this way, the structure emphasizes not just “what you know,” but also “whether the necessary conditions are met at this very moment.” This approach aims to enhance security on the system side without placing an excessive memory burden on users.


成立点と時変と無数鍵のイメージ

Concept of Validation Points, Time-Varying Parameters, and Infinite Keys


■ Why “Multiple Passcodes” Are Important

In a structure where a single key is used throughout the entire process, there is a risk that if that key is compromised, the attacker could reach the critical processing steps that follow. In contrast, by establishing multiple validation conditions and making each of them short-lived and time-varying, we can move away from a structure where “compromising one key means compromising them all.” Moreover, it is important to note that this is not simply a matter of increasing the number of keys.Simply requiring users to enter the same set of keys multiple times each session increases their burden.

Therefore, it is important to adopt an approach that combines “multiple keys,” “short validity periods,” “time-varying keys,” and “expiration”—not by forcing users to memorize an unlimited amount of information, but by having the system dynamically adjust the authentication conditions.



■ “Logged in = Safe” Is No Longer True

By developing this concept further, it becomes possible to design systems where authentication isn’t limited to a single step at the entry point.

For example, a multi-stage structure might look like this: Stage 1: User logs in → Anomaly detection and device verification → Stage 2: User confirms validity again → Recheck immediately before API calls or critical processing → Execute transactions, contracts, data changes, etc.

In other words, the concept is to “have a user intervene again at necessary points even after logging in.” Just because a user has logged in once does not mean that all subsequent processes are unconditionally permitted. If new validation conditions can be established each time a user proceeds to a critical process, the system can be designed to make it difficult to proceed further even if the initial authentication is compromised.


従来との比較の全体図

Overall Comparison with Conventional Methods


■ As an “Additional Layer of Defense” Against Server Attacks, Malware, and More

By applying the concepts of multi-step login and multi-stage validation, it is possible to combine various checks between each stage, such as device status verification, communication status verification, malware and abnormal behavior detection, access path verification, AI-based anomaly detection, operation content verification, and time verification.

For example, the structure might be: Login (1) → Inspection → Validation Point (1) → API (1) → Inspection → Login (2) → Validation Point (2) → API (2) → Inspection → Final Confirmation.

Even if an attacker breaches the initial entry point, that alone does not guarantee they will reach the final critical processing stage. This represents a shift in thinking from merely protecting the entry point to the concept that “defense continues as long as processing continues.” Please note that this does not guarantee “complete prevention of all server attacks or viruses.”Actual defense performance varies depending on implementation, operation, inspection methods, integration with existing systems, and other factors.



■ The Patented Technology

In the patent registered this time, for critical confirmation processes requested from the outside, the following technical configuration is adopted: divide the input data into multiple blocks → randomly assign roles for each time window → generate a short-term first identifier and a short-term second identifier → determine whether the conditions are met → if conditions are met → execute the confirmation process as a “validation point”; or if conditions are not met → terminate as a “Final Non-Validation Point” → record the result, location, site, route, and time as an audit trail. The “confirmation process” in question is not limited to digital processing.

For example, applications are envisioned in finance (fund transfers and settlements), government (applications and approvals), healthcare (critical approval processes), the automotive industry (engine startup, etc.), manufacturing (operation of industrial machinery), and IT (critical processes via APIs).



■ Records not only “successful” but also “unsuccessful” outcomes

Another key feature of this technology is that it does not merely retain records of successfully processed transactions. If a critical process is not executed because conditions were not met, the system finalizes the status as a “point of failure” and retains that fact as part of the audit trail.Through this, the system aims to enable subsequent verification not only of what “was executed,” but also of the fact that “the process reached this point but the critical operation was not executed.” This holds significant importance in areas where accountability is required, such as finance, government administration, corporate auditing, accident investigations, and cybersecurity.



■ To put it simply: “The keyhole changes every time”

Let’s imagine a conventional system as one where “once you open the front door with a single key, you can proceed all the way to the back of the house.”

This concept aims for something different. Even after opening the front door, there is another door. Moreover, the key for that next door changes. The time window for use is short. The required conditions also change.Once used, the key becomes invalid. If the conditions aren’t met, the door itself won’t open. Furthermore, the system records “which doors were passed through correctly.” In other words, we’re moving from a world where “stealing a single key is the end of it” to a world where “even if you break through one barrier, what lies beyond remains inaccessible.” This is the direction we’re heading.



■ The Society We Want to Create

Our goal is not simply to replace one password with another.

What we’re aiming for is a shift from a “society where people adapt to security” to a “society where security protects people.” We want to reduce the stress of remembering PINs.We won’t burden people alone with the responsibility of remembering complex PINs. We aim for a society where information doesn’t leak. And if a leak does occur, we’ll make it difficult for that information to be used in subsequent crimes. We’ll create a structure where, even if the initial entry point is breached, it’s difficult for an attacker to continuously breach subsequent critical processes. Furthermore, we’ll retain evidence of both successful and unsuccessful attempts.


From “protecting information” to “preventing crimes from occurring.” From “protecting the entry point” to “providing continuous protection until the very end.” From “people having to remember complex PINs” to “the system handling the complexity.”


Amid growing social concerns over data breaches, phishing scams, identity theft, unauthorized access, and fraudulent fund transfers, K-Trust Co., Ltd. aims not merely to acquire intellectual property, but to build a new security infrastructure that allows people to use the digital society with greater peace of mind through research, implementation, verification, and societal deployment.



[Overview of This Patent]

Patent Number: Patent No. 7896833

Application Number: JP 2026-028168

Invention Title: Information Processing Device, Information Processing Method, Information Processing Program,

     and Information Processing System

Filing Date: February 25, 2026

Registration Date: July 21, 2026

Status: Sixth patent registration related to the “Theory of Time-Varying Solution Points with Innumerable Keys”



[Summary for the Media]

Rather than simply “making passwords more difficult,” the approach is to “create a mechanism that prevents users from proceeding even if they crack the password.”

Yuki Takeuchi of K Trust Co., Ltd. has completed the registration of the sixth patent right for a technology that controls whether critical processes can be executed using multiple short-term identifiers that change over time and validation conditions, while maintaining an audit trail for both successful and unsuccessful validations.

The goal is to create a society that not only prevents information leaks themselves but also curbs secondary and tertiary damages—such as phishing, identity theft, unauthorized logins, and fraudulent fund transfers—caused by leaked information.

Toward a digital society where “an information leak doesn’t spell the end.”

Rather than requiring people to continuously remember complex PINs, the system handles the diversification, short-term nature, time-varying characteristics, and expiration of these codes, while continuously verifying security right up to the point of critical processing.

This is the direction for next-generation security envisioned by the “Theory of Infinite-Key Multiple Time-Varying Fixed Points.”



[Contact Information for Inquiries Regarding This Matter]

K Trust Co., Ltd.

Licensing Business Promotion Division

Contacts: Hirakawa / Takeuchi

E-mail: k-trust@verda.co.jp

Address: 1-3313 Shimoshidami, Moriyama-ku, Nagoya City, Aichi Prefecture

URL: http://www.ktrust.info

Logo Image