SYSTEM AND METHOD FOR MANAGING PERSONAL DATA
Patent Information
- Application Number
- DE502018016273
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2017-10-11
- Filing Date
- 2018-10-02
- Publication Date
- 2026-01-08
- Estimated Expiration
- 2038-10-02
AI Technical Summary
Existing personal data management systems lack robust security measures to prevent unauthorized access and misuse, particularly in decentralized environments, while ensuring individual privacy and data integrity.
A decentralized system comprising two security devices that capture, anonymize, and store personal data locally, with a management system managing access rights and permissions, using a blockchain structure for logging access and storing anonymized data, and ensuring secure data transfer based on identity-based authorizations.
Enhances data security and privacy by preventing unauthorized access, maintaining individual control over personal data, and ensuring secure, decentralized storage and management of personal data.
Description
[0001] Personal authentication often takes place in protected areas, such as security gates at buildings requiring protection, like scientific institutions or office buildings. For this purpose, personal data, such as an identity card, but also electronic data such as a token, are collected. This collected personal data can be stored.
[0002] Evaluating stored personal data requires security measures to prevent this personal data from falling into the hands of unauthorized third parties and thus to prevent misuse of the personal data.
[0003] Patent application US 2014 / 101453 A1 discloses a biometric authentication device which includes a fingerprint sensor.
[0004] Patent US 6,678,821 B1 discloses an encryption / decryption system.
[0005] Disclosure document WO 2008 / 110597 A2 discloses a method for authenticating a person.
[0006] The object of the present invention is to demonstrate an improved concept for managing personal data.
[0007] According to a first aspect of the invention, the problem is solved by a system for managing personal data associated with identities. The system comprises a first security device and a second security device, each configured to capture personal data, assign identities, and store the captured personal data locally. The system includes a management system configured to manage access rights to the identities. The first security device and the second security device are each configured to locally log access to locally stored personal data.
[0008] The system can be an authentication system. The security devices can include a capture device for personal data, such as a camera for capturing biometric data or an identity document, an input field for entering an alphanumeric string, or a radio module for capturing data from an electronic chip.
[0009] Collected personal data is anonymized and assigned identities. An identity is assigned to a person. An identity can comprise a data record belonging to a person, such as a name or employee number. Permissions can exist and be managed for each identity. This management is performed by the management system. The management system can be located in a central location, such as a server, and connected to the individual security devices, for example, the first security device and the second security device. The connection can be established via a data network. The first and second security devices can also be connected to each other via this or another data network.
[0010] The management system manages permissions for identities. This means that permissions for identities that relate to personal data are stored in the management system. Any security entity can access the management system via the data network and verify permissions for the identities.
[0011] This allows you to determine whether the collected personal data may be processed and / or stored locally. Further permissions that a user can grant to an identity include access by other identities and security systems to the collected personal data of that identity.
[0012] The first and second security devices are configured to log access to locally stored personal data. Creating a log for each access provides an overview of all access attempts to the personal data, regardless of who initiated the access.
[0013] This allows an administrator, when verifying an identity, or a person, when verifying their own identity, to obtain information about who wanted to access or has accessed personal data.
[0014] According to an advantageous embodiment, the first safety device and the second safety device are arranged spatially separately.
[0015] Parts of the system are spatially separated, meaning the system is divided across different locations, known as nodes. These different locations could be, for example, different entrances to a building or different turnstiles at a single entrance. The security devices can each be interconnected via a data network. The different arrangement of the first and second security devices can thus form a decentralized network.
[0016] According to an advantageous design, the first security device and the second security device are designed to allow access depending on the permissions to the personal data.
[0017] This applies to identities for which authorizations exist. Access is only permitted to personal data associated with identities for which access authorizations have been granted. This increases the privacy of the individuals belonging to these identities and also enhances the data security of the system.
[0018] According to a further advantageous embodiment, the first security device and the second security device are configured to store the logged accesses locally in a secure structure, in particular a blockchain structure.
[0019] The logs contain access information that may include security-relevant data. Storing the logs in a secure structure increases the security of the system.
[0020] According to a further advantageous embodiment, the first security device and the second security device are designed to store the collected personal data locally and anonymously.
[0021] The advantage here is that, once anonymized, the data can no longer be obviously linked to a specific person by unauthorized third parties. This increases system security and individual privacy. Storing the anonymized personal data locally eliminates the need to anonymize it via a central instance, such as a server.
[0022] According to a further advantageous embodiment, the first security device and the second security device are configured to release the recorded personal data to an operator.
[0023] By granting access, personal data is transferred to an operator. The operator can be a data analyst, i.e., a person or entity that evaluates personal data, or a software module specifically designed for this purpose. The data can be made available for reading, or it can be sent to the operator by one of the security systems. The transfer can be anonymized, further enhancing system security. The transferred personal data can then be analyzed by the operator.
[0024] According to a further advantageous embodiment, the first security device and the second security device are designed to anonymize the personal data depending on an authorization that can be attributed to the identity to which the personal data are assigned.
[0025] By granting permission to anonymize personal data based on the identity of the person to whom the personal data can be attributed, the security of the personal data and the privacy of the individual are increased. Attribution to the individual is no longer easily possible. Thus, another identity or operator cannot know to which person the anonymized data belongs. The advantage here is that the identity to which the personal data is attributed retains control over who is allowed to view the anonymized personal data.
[0026] In an advantageous configuration, the management system is set up to manage permissions based on an identity authorization.
[0027] Permissions can be managed separately for each identity. This means that every person who has registered an identity—that is, a person who uses or manages the system—can separately define permissions regarding the personal data pertaining to their own identity. This strengthens the rights of the person associated with that identity, as they can then define permissions and restrictions themselves.
[0028] According to an advantageous configuration, the management system is set up to release the authorizations and identities of the first security device and / or the second security device.
[0029] The permissions are managed by the administration system. It is the administration system's responsibility to distribute permissions and identities to the first and second security entities, i.e., to the decentralized nodes of the system. Thus, each security entity knows which identities exist and what permissions are assigned to each identity.
[0030] In an advantageous configuration, the management system is set up to assign certificates to authorizations and identities. Furthermore, the first and second security devices are each configured to verify certificates of retrieved or received authorizations and / or identities.
[0031] The security systems may include controllers. The controllers verify that the authorizations and identity information actually originate from the management system. For this purpose, the management system signs the data with a certificate that can be verified by the controller. This increases security.
[0032] According to an advantageous embodiment, the first security device and the second security device are each configured to refuse to respond to a request if the request does not include a certificate that can be authenticated by the first security device and / or the second security device.
[0033] Security is further increased if the security systems do not send any information and personal data to a sender of a non-certified request.
[0034] According to an advantageous embodiment, the first security device and the second security device are configured to store additional information, in particular a certificate or an identity number, relating to the identity that can be attributed to the personal data, in addition to locally stored personal data.
[0035] This allows the owner of the data records to be identified. The owner of the data records could, for example, be the identity to which the personal data can be attributed.
[0036] According to an advantageous design, the management system is set up to manage the managed permissions in relation to an operator, in particular an identity or a process.
[0037] An operator can be, for example, an identity, but also a process running on the decentralized network. This allows automated access to personal data within the system.
[0038] According to a second aspect of the invention, the problem is solved by a method for managing personal data, wherein the personal data is assigned to identities. The method comprises the following steps: Collection of personal data by a first security entity or a second security entity, association of the collected personal data with identities and local storage of the collected personal data by the first security entity if the first security entity collected the personal data or the second security entity if the second security entity collected the personal data, management of authorizations to the identities by a management system, logging of access to locally stored personal data by the first security entity and the second security entity.
[0039] According to a third aspect, the invention is solved by a computer program product with a program code for executing the method described above when the program code is executed on a computer system.
[0040] The invention will be explained in more detail below with reference to further exemplary embodiments and the figures. The figures show: Fig. 1 is a schematic representation of a system according to an embodiment of the invention; and Fig. 2 is a schematic flowchart for a method according to an embodiment of the invention.
[0041] Fig. 1Figure 1 shows a system 100. In the illustrated embodiment, system 100 is a safety gate. System 100 comprises a first safety device 101 and a second safety device 103. The first safety device 101 and the second safety device 103 are interconnected via a data network 105, thus forming a decentralized network. System 100 also includes further safety devices 102, which essentially correspond to the first safety device 101 and the second safety device 103. For the sake of clarity, system 100 will be described below with reference to the first safety device 101 and the second safety device 103. The descriptions apply accordingly to each of the further safety devices 102 arranged in system 100.In an alternative configuration, the system 100 includes only the first safety device 101 and the second safety device 103.
[0042] The first security device 101 has a memory 107, and the second security device has a memory 109. The first security device 101 is configured to store data in the first memory 107. The second security device 103 is configured to store data in the second memory 109. The memory locations 107 and 109 are each located at the corresponding first and second security devices 101 and 103, respectively. The personal data from the first security device 101 is therefore stored locally in the first memory 107. The personal data collected by the second security device 103 is also stored locally in memory 109.
[0043] The first security device 101 also stores a log locally in memory 107. The second security device 103 also stores a log locally in memory 109.
[0044] The following section describes the logging process in more detail using the security device 101 and the first memory 107 as examples. However, this is not intended to be a limiting description and should apply equally to the second security device 103 with the second memory 109, as well as to the further security devices 102 and their correspondingly assigned memory locations.
[0045] System 100 is designed to authenticate individuals and thus ensure the security of the protected area, i.e., the building. For this purpose, each person is assigned an identity 106, which includes personal data such as a name and / or employee number. The individual can then authenticate themselves within System 100. The personal data collected during this process is anonymized and assigned to identity 106, so that third parties cannot easily determine the identity of the person to whom identity 106 belongs from the stored personal data.
[0046] The first security device 101 is connected to a management system. For clarity, the management system is in Fig. 1Not shown. In the illustrated embodiment, the management system is a software module that can be executed on a computer system and is run on a server 104. In a further embodiment, the management system is run on the first security device 101 or on several, in particular all, security devices 101, 102, 103. In an alternative embodiment, however, it could also be a different implementation configured to manage information on personal data, such as a hardware implementation.
[0047] The management system is configured so that personal data can be assigned to an identity 106, and individuals belonging to identity 106 can manage permissions over their identity 106's personal data separately and individually. That is, a person who registers in system 100 and possesses an identity 106 can assign permissions to their identity 106 regarding their personal data. Such permissions can specify which security device 101, 102, 103 is authorized to do what with the personal data. The permissions can also include how other computer systems with access to system 100, as well as how other identities and processes within system 100, may handle the personal data. For example, the individual can grant permission to store their personal data locally on the first security device 101.The personal data may then be stored by the first security facility 101 in the local first storage 107. Further permissions that can be granted include, for example, authorization to forward the personal data for centralized or decentralized processing. Such authorization can be general or specific to selected other identities. These selected other identities could be, for example, a colleague, a human resources manager, an administrator of system 100, or even a process within system 100.
[0048] Authorizations can be granted to specific operators 108 or users, or to a specific security device 101, 102, 103 of the decentralized network. In this example, operator 108 is a process or an identity. An authorization can include the right to locally store the collected personal data to which this identity 106 is assigned. The management system can also have access permissions, meaning that the personal data belonging to identity 106 can be read by an operator 108 or another identity. These permissions are stored in the management system for the respective identity 106.
[0049] The management system is decentralized and, in the exemplary embodiment, runs on a server connected to each of the security devices 101, 102, 103 via the data network 105. In an alternative embodiment, the management system is stored and executed separately on each security device 101, 102, 103 of the decentralized network. In this case, the authorizations are stored locally on each security device 101, 102, 103. The authorizations are then transmitted via the decentralized network from one management system of a security device 101, 102, 103 to another management system of a different security device 101, 102, 103.
[0050] When new calculations and identities are available, the management system sends the authorizations or identities to each individual security device 101, 102, 103 of the decentralized network. In the exemplary embodiment, this occurs without the individual security devices 101, 102, 103 at the individual nodes requesting this data from the management system. In a further embodiment, the sending of new or all authorizations and identities only occurs upon a request from the first security device 101, the second security device 103, or another security device 102.
[0051] If operator 108, i.e., a process or identity, accesses personal data relating to identity 106, the first security device 101, where the personal data is stored, records that access to the personal data is requested and who is requesting access to the personal data, and stores this information in a log, regardless of whether the personal data is sent or not. For this purpose, the first security device 101 creates a log locally in storage 107. Additionally, information is also stored about whether, and if so, which personal data relating to which identity 106 has been released.
[0052] In the illustrated embodiment, operator 108's requests for personal data are made via the management system. Operator 108 sends a request to the management system to provide personal data relating to identity 106. The management system forwards these requests to the first security device 101, which provides this personal data to the management system, and thus to operator 108, according to the permissions granted. This process is logged by the first security device 101 in its associated local memory 107.
[0053] In another configuration, Operator 108 requests the desired personal data directly from the first security facility 101. In yet another configuration, the personal data is not sent to the management system, but directly to Operator 108.
[0054] System 100 also includes a data vault 111. Data vault 111 has a separate storage location for each of the stored identities 106. The data records of the security devices 101, 102, and 103, which are stored locally in the first storage location 107 or the second storage location 109, are also stored in data vault 111 for the respective identity 106. Such storage can occur, for example, on a time-dependent basis on specific days after specific periods or upon request.
[0055] The data vault 111 can be a hard drive or other storage device offering a high level of security. Personal data can only be read by the security devices 101, 102, and 103. Additionally, individual identities 106 can read their assigned personal data from the data vault 111. The management system or individual operators 108 do not have direct access to the data vault 111. This ensures that unauthorized third parties cannot directly access the personal data of an identity 106 via the data vault 111. Instead, every request must be routed through the decentralized network and the management system to the individual nodes, i.e., the security devices 101, 102, and 103.
[0056] Fig. 2Figure 200 shows a flowchart for a method according to one embodiment of the invention. Step 201 shows a request from an operator 108 to the management system for the release of personal data concerning identity 106. In a second step, the management system checks whether authorizations exist for identity 106.
[0057] In an alternative configuration, operator 108 queries the personal data not via the management system, but directly at the first security device 101. In this case, the authorization check is performed by the first security device 101 in step 203. The first security device 101 sends a request to the management system for this purpose.
[0058] If there are no authorizations to release personal data relating to identity 106, the procedure continues in step 211. At this stage, operator 108 may receive an error message or a negative response.
[0059] If, however, authorization exists, i.e., step 203 has been positively evaluated, the request is forwarded to the first security facility 101 in step 205. Alternatively, if operator 108 submits the request directly to the first security facility 101, it is processed there directly, and an authorization request is automatically obtained from the management system.
[0060] In step 207, the first security institution 101 verifies a certificate containing the data received from the management system, i.e., the authorizations and identity information. If the verified certificate is deemed invalid by the first security institution 101 and therefore not authenticated, the procedure is aborted and no response is sent to the management system. However, if the certificate is authenticated and declared valid, the procedure continues in step 209.
[0061] In the following step 209, the personal data relating to identity 106 are read from the first storage 107.
[0062] Both after step 209 and alternatively after step 203, a log is created in step 211 that provides information about requests made via the first security device 101. This log includes information about which personal data was disclosed to which identity 106, based on which authorizations, and when. In a further configuration, additional information can be stored in the log, such as an identification code of the operator 108 who requested the personal data.
[0063] In a subsequent step 213, the log data from the first security device 101 is stored locally in a file, a so-called log. The storage location is also the first storage location 107. Alternatively, it could be another local storage location.
[0064] The protocol, as described, is stored in a blockchain structure to increase the security and integrity of the stored protocols and data.
[0065] If personal data relating to identity 106 is distributed across more than one node, i.e., stored in different storage locations 107, 109, then steps 207 to 213 are performed not only by the first security device 101, but by each security device 101, 102, 103 that is either addressed by the management system or directly queried by the operator 108. Reference symbol list
[0066] 100 System 101 First security device 102 Second security device 103 Second security device 104 Server 105 Data network 106 Identity 107 First storage 108 Operator 109 Second storage 111 Data storage 200 Flowchart 201-213 Process step
Claims
1. A system (100) for managing personal data assigned to identities (106), comprising: a first security device (101) and a second security device (103), which are each configured to collect personal data and to assign the personal data to identities (106) and to store the collected personal data locally; and a management system, which is configured to manage permissions to the identities (106); wherein the first security device (101) and the second security device (103) are each configured to log accesses to the locally stored personal data locally, wherein the first security device (101) and the second security device (103) are configured to allow the accesses depending on the permissions to the personal data.
2. The system (100) according to claim 1, wherein the first security device (101) and the second security device (103) are arranged spatially separated.
3. The system (100) according to one of the preceding claims, wherein the first security device (101) and the second security device (103) are configured to store the logged accesses locally in a secure structure, in particular a blockchain structure.
4. The system (100) according to one of the preceding claims, wherein the first security device (101) and the second security device (103) are configured to store the recorded personal data locally and anonymized.
5. The system (100) according to one of the preceding claims, wherein the first security device (101) and the second security device (103) are configured to release the recorded personal data to an operator (108).
6. The system (100) according to one of the preceding claims, wherein the first security device (101) and the second security device (103) are configured to anonymize the personal data depending on a permission, which can be assigned to the identity (106) to which the personal data are assigned.
7. The system (100) according to any of the preceding claims, wherein the management system is configured to manage the permissions based on an authorization of an identity (106).
8. The system (100) according to any of the preceding claims, wherein the management system is configured to release the permissions and identities (106) of the first security device (101) and / or the second security device (103).
9. The system (100) according to any of the preceding claims, wherein the management system is configured to provide permissions and identities (106) with a certificate and wherein the first security device (101) and the second security device (103) are each configured to authenticate certificates of retrieved or received permissions and / or identities (106).
10. The system (100) according to claim 9, wherein the first security device (101) and the second security device (103) are each configured to refuse a response to a request if the request does not include a certificate that is authenticable by the first security device (101) and / or the second security device (101).
11. The system (100) according to one of the preceding claims, wherein the first security device (101) and the second security device (103) are configured to store, in addition to locally stored personal data, information about the identity (106), which can be assigned to the personal data.
12. The system (100) according to any of the preceding claims, wherein the management system is configured to manage the managed permissions with respect to an operator (108), in particular an identity (106) or a process.
13. A method for managing personal data assigned to identities (106), comprising: - collecting personal data by a first security device (101) or a second security device (103), assigning the collected personal data to identities (106) and locally storing the collected personal data by the first security device (101) when the first security device (101) has collected the personal data or the second security device (102) when the second security device (101) has collected the personal data; - managing permissions to the identities (106) by a management system; - logging accesses to the locally stored personal data by the first security device (101) and / or the second security device (103) locally, wherein the first security device (101) and the second security device (103) are configured to allow accesses depending on the permissions to the personal data.
14. A computer program product comprising program code for executing the method according to claim 13, when the program code is executed on a computer system.