Selective data processing and transmission system
The system addresses the challenge of authenticating data transmission consent by separating and irreversibly transforming confidential and divulgable data, ensuring secure and efficient management of combined data sets with indisputable proof of authenticity.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- EDGEWHERE
- Filing Date
- 2024-11-27
- Publication Date
- 2026-05-29
AI Technical Summary
The challenge lies in ensuring the authenticity and verification of data transmission consent, particularly for combined data sets that include both confidential and divulgable information, while maintaining confidentiality and simplifying the management of large data volumes, which is currently complex and prone to falsification.
A system for selective data processing and transmission that separates confidential and divulgable data, irreversibly transforms them into unreadable forms, and records them in a blockchain for authentication, ensuring the authenticity of the original data through unique hash images.
This system guarantees the authenticity of data transmission by maintaining confidentiality and providing indisputable proof of consent, allowing secure and efficient management of large data sets while adhering to transmission limits and purposes agreed upon by senders.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Selective data processing and transmission system FIELD OF INVENTION
[0001] The present invention relates to a system for the management and selective transmission of data, for example, data from the communication of identity data and contactability data that can be transmitted with the consent of the sender. STATE OF THE ART
[0002] The customer data of a company used for transactions can be valued by companies with a complementary or other activity for their contact with customers or prospects constituting possible future customers.
[0003] However, the transmission of a customer's data is only possible with their consent, for a list of recipients, a specific use (purpose) and a specified duration.
[0004] This raises the problem of proving the authenticity of consent and the possibility of verifying this consent both by the recipient and by the sender of this data.
[0005] Currently, data valorization is complicated to manage for the collector who must be able to guarantee authenticity, in response to any request from the recipient (data user) and that of the data sender.
[0006] This is all the more complex because such data valorization is only of interest to the collector if it can be applied to a large number of data sets. However, this also multiplies the complexity of the operations and their management over time. Finally, the complexity of this situation also results in customers being reluctant to consent to the transmission of their data to recipients.
[0007] However, currently, the issuer cannot be guaranteed the authenticity of the proof of its consent which may have been modified or falsified with regard to the recipients or the use of the data communicated.
[0008] The difficulty is to be able to guarantee in a simple way the authenticity of the consent of the sender of the data to a data collector authorizing him to communicate his data of communicability to recipients defined in the consent, by guaranteeing to the recipients the authenticity of the consent and by allowing them to verify the consent at any time.
[0009] More specifically, the communication to recipients of contactable data forming part of a collector's (company's) file so that the The recipient's ability to contact such prospects (senders) is subject to strict rules requiring that the sender (the client) has agreed that:
[0010] - his contact details (name, address) may be communicated to recipients listed in the consent document approved by the issuer,
[0011] - the purpose of the communication to the recipient, i.e. the modalities according to which contact details can be used.
[0012] However, the example developed above of the transmission of customer files to recipients using this data, generally contact data, represents only one case of data transmission; in parallel, there are many situations of data transmission which necessarily originate from a sender with a view to a destination which may use this data for commercial, statistical, census, questionnaire or other purposes in which confidential data is hidden but necessarily remains combined with non-hidden data and whose proof of the original combination is difficult and complex to achieve although inconceivable for batches of data.
[0013] PURPOSE OF THE INVENTION
[0014] The present invention aims to develop a system for the processing and selective transmission of inseparable combinations of data which must remain confidential and data which can be disclosed, and to allow the secure and simple processing of such data streams or batches while establishing for each batch of combined data proof of the identity of the transmitted batches with the original batches and in particular allowing the keeping and control of proof of consent to the selective communication of data to determined recipients.
[0015] DESCRIPTION AND ADVANTAGES OF THE INVENTION
[0016] The invention relates to a system for the selective processing and transmission of data comprising: a set of operations for processing combined data received from a sender in a confidential collection space, a receiving space containing data, some of which is confidential and must be protected as such and must remain inaccessible, and a set of operations for processing combined data transferred in a non-confidential operator space, i.e., in which the data is in a non-confidential state since at least the confidential data is unreadable, the combined data provided by a sender being transmitted to the confidential collection space to: separate the combined data into confidential data and divulgable data, format the data to obtain formatted data,irreversibly transform the formatted data to obtain neutralized data and transfer the transformed and formatted data from the confidential collector space to the non-confidential operator space, the data being received in the non-confidential operator space for successively: , sum by addition, the received data, associate the sum obtained with the untransformed divulgable data, irreversibly transform the sum into a neutralized transformed sum, record the neutralized sum in a blockchain and, combine, the transformed sum and the deposit certificate to record it in a control database and form the certificate of authenticity with the neutralized sum.
[0017] According to a particular characteristic, irreversible neutralization transformations are data hashes.
[0018] This neutralization is particularly effective because it forms the image of the hashed data, which is a unique combination of signs that can be compared to the result of hashing another combination of data and makes it possible to prove the identity or non-identity of the data of the second combination and thus, in the case of identity of the images, to provide proof that the new data thus transformed are indeed identical to the initial data.
[0019] According to another feature, the database of the confined space and that of the operator space store the combined data as provided by the sender and the separate, formatted, and transformed data. In particular, the collector space has a database storing the received data, and the operator space has a database storing the data received from the collector space, a database storing the transformed data, and a database storing the transformed data, i.e., the certificates of authenticity. Brief description of the drawings
[0020] The present invention will be described in more detail below with reference to embodiments of a selective data processing and transmission system shown in the accompanying drawings, in which:
[0021] [Fig. 1] General diagram of the system for processing and selectively transmitting data,
[0022] DESCRIPTION OF EMBODIMENT METHODS OF THE INVENTION
[0023] According to [Fig. 1], the invention relates to a processing and transmission system 100 data to process the data flow between a sender Ei providing DEi data and an agent (or collector) so that the latter can transmit to a recipient X the usable data in plain text, combined with irreversibly neutralized (undecipherable) data essential to guarantee the authenticity of the usable data transmitted.
[0024] System 100 must allow for confirmation of authenticity in a certain manner and, if necessary in the event of a dispute, allow for recourse to confidential data recorded by the agent.
[0025] The DEi data from the transmitter Ei are transmitted within a precise framework, defined by the transmitter Ei or predefined and imposed on the transmitter Ei.
[0026] In all cases, this framework is fixed to the transmission of the DEi data to the agent and the authenticity of this framework and of the consent of the issuer Ei must be preserved and can be proven in a simple way, without having to disclose confidential data associated with this document and the consent but which do not constitute the data usable by the recipient X.
[0027] The general diagram of [Fig.1] shows the system 100 for the selective processing and transmission of data with authentication of data from a sender Ei to be transmitted to a recipient X.
[0028] More generally, an agent receives data from many different senders Ei (i=1, 2,...) to transmit them to the same recipient X or to different recipients X and similarly, several data collectors apply the processing and transmission system 100.
[0029] The sender Ei has an identifier represented by the subscript i, and the collector receiving this data has an identifier. These two identifiers are associated with the data at the various processing stages. The collector-agent is responsible for the data, its transmission, and its use in accordance with the commitments given to or accepted by the sender Ei.
[0030] The combined data DEi consists, on the one hand, of data DDij which must be transmitted to a recipient X for a use defined by the sender Ei, i.e. the use of the data and the user(s) and, on the other hand, of data DCij which must remain confidential, although combined with the data which can be disclosed to prove the authenticity of the combined data transmitted.
[0031] The system 100 includes applications (S), (F), (Hi), (H2), and databases BD1, BD2 for recording data in the different stages of the process of processing the data stream or, more generally, of combined batch data streams.
[0032] According to the system 100, data processing is first carried out in a confidential collector environment 101 to separate (S) confidential data (DCij) and divulgable data (DDij), i.e. non-confidential, to neutralize (make unreadable) the data irreversibly before their transfer to the non-confidential operator environment 102 in which the data stream is processed to make it available to recipients X while guaranteeing the authenticity of the transmitted data in an accessible state and combined with those in an inaccessible state in order to be able to prove the authenticity of the original combined DEi data.
[0033] According to a first step ET1, the DEi data provided by the sender Ei to the confidential collection space 101 of the processing system 100 combines confidential and non-confidential data for use by a recipient X. This combined DEi data is separated (S) by the processing system 100 into confidential data DCij and divulgable data DDij, with the identifier (j) of the confidential collection space 101 that received the data from the sender Ei. The data is communicated to the recipients X with proof that it forms part of the set of DEi data from the sender Ei for possible authenticity checks of the communication, i.e., to prove the link between the confidential data DCij and the data DDij, even though the DCij data is permanently unreadable as communicated to the recipients X.
[0034] Confidential data DCij and divulgable data DDij are formatted (step ET3) by a formatting program (F) that standardizes the presentation of data such as: name, surname, address, telephone number, email address, so that this data is unambiguously identifiable, regardless of its original presentation, and allows for its computerized processing. Some of the data may also consist of documents, diagrams, and images that are processed without specific formatting but are adapted for subsequent processing.
[0035] In a subsequent step ET4, the formatted data D'Cij, D'Dij are irreversibly neutralized to render them unreadable by a neutralization transformation yielding a unique image of this data, preferably by hashing. The data D'Cij and D'Dij are hashed separately by a hash function Hi of the processing system 100 in the form Hi(D'Cij) and Hi(D'Dij), so that they can exit the confidential collector space 101 and be transmitted by a transfer function to the non-confidential operator space 102 for further data processing and the creation of the authentication elements of the combined data DEi.
[0036] At the output of the confidential collector space 101, the data stream is transmitted (T) to the non-confidential operator space 102 in which the transformed confidential data, hashed Hi(D'Cij), and the usable data, hashed DD'ij Hi(D'Dij), arrive.
[0037] In the data stream, the hashes Hi(D'Cij), Hi(D'Dij) are supplemented by the formatted divulgable data D'Dij, which is also transmitted but as is, without hashing at this ET4 stage of the processing for:
[0038] - concatenate the hashes Hi(D'Cij), Hi(D'Dij) and the unhashed D'Dij hashes and form the sum Sij=[Hi(D'Cij) + Hi(D'Dij) + D'Dij] completed in parallel by the divulgable data D'Dij and thus joined separately to these hashed concatenated data.
[0039] In the next step ET5, the sum Sij is neutralized, hashed to obtain the global hash H2(Sij).
[0040] The global hash H2Sij is recorded in a BC blockchain with issuance of the Cdpi deposit certificate in the blockchain.
[0041] In some cases, there are so many issuers Ei that the numerous H2(Sij) hashes are combined into a batch recorded globally in the BC blockchain under a single registration number. This does not affect the proof of authenticity that space 102 can provide upon request from a recipient X or an issuer Ei, since the combined, hashed H2(Sij) sum of each of the issuers Ei in the batch can be authenticated.
[0042] At the output of processing, in the non-confidential operator space 102, the divulgable data D'Dij are available in combination with the certificate of authenticity Cauthij constituted by the hash H2(Sij).
[0043] The global hash H2(Sij) combined with the deposit certificate Cdpij is recorded in the BD2 database of operator space 102 as well as the divulgable data D'Dij associated with the global hash H2(Sij).
[0044] The successive states of the data being processed by system 100 are recorded, by way of example, in databases:
[0045] - the input data DEi and the classified data DCij, DDij are recorded in the BD1 database in the confidential collector space, inaccessible.
[0046] - the concatenated data Sij and the divulgable data D'Dij are recorded in the BD2 database of the operator space with:
[0047] - the global hash H2(Sij) associated with its Cdpi deposit certificate, the certificate of authenticity Cauth(ij) composed of the global hash H2(Sij).
[0048] In summary, the system 100 includes in the confidential collector space 101, the separation program (S) of confidential data (DCij) and divulgable data (DDij), the formatting program (F) and the hashing program (H i) before the transmission of the data to the non-confidential operator space (102) which establishes the Cauth authenticity certificate (ij) with the hashing program (H2) or the global hash and its recording in a BC blockchain.
[0049] The data processing for the summation S, the irreversible transformation H2 and the recording in a blockchain in the steps ET4, ET5 is done in the operator space 102 since the confidential data D'Cij is no longer in a readable form but in the form Hi(D'Cij) while retaining the indisputable link with the divulgable data DDij.
[0050] Another application of the selective data processing and transmission system 100 concerns senders E1, E2, E3,... of data collected during transactions to make this data from consenting senders available to recipients interested in using this data under the guarantee that the Recipients may use this data for agreed purposes and under the guarantee for the sender, that the agent transmits this data only within the limits of the recipients, the purposes and the agreed durations without transmitting to them the confidential data contained or integrated in the combined data collected.
[0051] For this, the conventions of these data transmissions must be able to be authenticated and this authentication must be available to both the recipients and the sender.
[0052] Senders are the partners in transactions, generally online, such as a purchase, a service, a consultation, ... and receivers are economic agents who seek contacts for the promotion of their activity.
[0053] This activity of exploiting contact data is strictly regulated to guarantee the authenticity of the exchanges and uses of the data to guarantee and authenticate their consent and compliance with the limits of use of the data.
[0054] System 100 according to the invention applies to multiple cases of transmission of data attached to a person and which may be the subject of a transmission; these combined data generally include, on the one hand, personal data which must remain confidential and hidden from the recipient(s) and, on the other hand, data to be communicated to him.
[0055] But, it must nevertheless have confirmation that the communicated data is identical to the original combined data including the now hidden data.
[0056] A common case is that of customers who provide the company with their personal data, for example, personal details other than those necessary for the transaction, i.e., name, surname, postal address, email address, telephone number, which are contact details. All of this data is generally recorded in the company's database.
[0057] Since contact data may be of interest to complementary companies for marketing purposes, the data collector (company) holding this customer data requests permission from its customers to transmit the non-confidential portion to interested third parties. These data sets may represent a significant volume for the data collector, and the interested third parties may include a number of companies wishing to use this data for various purposes and over a specified period.
[0058] The transmission of data defined by the consent of the customer, sender of the data, under the responsibility of the collector with the possibility of checking the authenticity of the terms of this transmission is managed by the system 100 described above.
[0059] According to system 100, the collector transmits the DEi data batches from the emitters Ei for authentication of the transmission to a confidential collector space 101 reserved for the collector and a non-confidential operator space 102 in which an operator intervenes.
[0060] As by definition, the collector (identifier) holds the DEi data which is provided to it by the emitters Ei, it processes the DEi data of each emitter Ei by classifying them, by a separation operation (S), into confidential data DCij and into divulgable data DDij.
[0061] The combined data DEi or already in the separate form of data DCij and DDij are recorded in its database.
[0062] Since the organization of the data flow is managed by the non-confidential operator space 102, the operator imposes the prior formatting (F) of the data to be transmitted and their irreversible transformation H2 for:
[0063] - transform (H2) the confidential data into an irreversible and unreadable image and,
[0064] - maintain the link between the confidential DCij data and the divulgable data DDij to prove the authenticity of the combined data communicated to third parties X.
[0065] To this end, the collector, after separating (S) the DCij and DDij data, formats them (F) to standardize their presentation, as the data provided may have different forms. Confidential DCij data includes, for example, civil status data, and disclosable DDij data includes:
[0066] - the contact details of the issuer Ei,
[0067] - the list of recipients X,
[0068] - the purposes, i.e. the possible uses of the communicated data.
[0069] The transformation Hi of the data in the confidential collector space 101 consists of providing an unreadable and irreversible image of the data D'Cij and D'Dij, i.e. Hi(D'Cij) and Hi(D'Dij), which in a way also represent the transformation Hi(D'Ei), i.e. the transformation of the combined formatted DEi data D'Ei.
[0070] Associated with this irreversible transformation are the divulgable data (D'Dij) formatted but not transformed and therefore readable.
[0071] The data are thus prepared to be transferred to the non-confidential operator space 102 in which the operator applies a summation S to all forms of transferred data: Sij= [Hi(D'Cij) + Hi(D'Dij) + D'Dij] and then this sum Sij is transformed into a new irreversible and unreadable image H2(Sij) which becomes the certificate of authenticity Cauthij.
[0072] Next, this deposit certificate (Cpdi) combined with the H2(Sij) image is recorded in the BD2 database.
[0073] The data stream can be supplemented by timestamps both in the confidential collector space 101 and in the non-confidential operator space 102 to date the different operations.
[0074] NOMENCLATURE OF MAIN ELEMENTS
[0075] 100 Processing system
[0076] 101 Confidential collector space / abbreviated: collector space
[0077] 102 Non-confidential operator space / abbreviated: operator space
[0078] DEi Data to be processed provided by an issuer Ei
[0079] DCij Ei Confidential Data
[0080] DDij Ei Discloseable Data
[0081] D'Cij Formatted confidential data
[0082] D'Dij Formatted Disclosed Data
[0083] Hi(D'Cij) Confidential hashed formatted data
[0084] Hi(D'Dij) Formatted hashed divulgable data
[0085] Sij Concatened data: sum of formatted, hashed confidential data, formatted, hashed divulgable data, and unhashed divulgable data
[0086] H2(Sij) Concatenated hashed data
[0087] Cauthij Certificate of Authenticity
[0088] ET1 Step of the process
[0089] ET2 Step of the process
[0090] ET3 Step of the process
[0091] ET4 Step of the process
[0092] ET5 Step in the process
Claims
Demands
1. A selective data processing and transmission system (100) comprising: - a set of operations for processing combined data received in a confidential collector space (101) and, - a set of operations for processing combined data transferred in a non-confidential operator space (102), A) the combined data (DEi) provided by a sender (Ei) being transmitted to the confidential collector space (101) to: - separate (S) the combined data into confidential data (DCij) and divulgable data (DDij), - format (F) the data (DCij) and (DDij) to obtain formatted data (D'Cij) and (D'Dij), - irreversibly transform (Hi) the formatted data to obtain neutralized data Hi(D'Cij) and Hi(D'Dij), and - transfer (T) (the transformed data Hi(D'Cij) and Hi(D'Dij) and the data D'Dij formatted from the confidential collector space (101) to the non-confidential operator space (102),B) The data Hi(D'Cij), Hi(D'Dj) and D'Dij are received in the non-confidential operator space (102) to successively: - sum (S) by addition, the received data H^D'Cij) + Hi(D'Dij) + (D'Dij) = Sij - associate the obtained sum Sij with the untransformed divulgable data D'Dij, - irreversibly transform (H2) the sum Sij into a neutralized transformed sum H2(Sij), - record the neutralized sum H2(Sij) in a blockchain BC and, - deposit, * the transformed sum H2(Sij) combined with the deposit certificate CBC(ij) in a database BDD2 of the operator space 102, - issue the certificate of authenticity Cauthij including the neutralized transformed sum (H2(Sij).,
2. System according to claim 1, characterized in that the irreversible neutralization transformations Hb H2 are data hashes.
3. System according to claim 1, characterized in that the database of the confined space (101) and that of the non-confidential operator space (102) record the combined data as provided by the issuer (Ei) and the separated, formatted and transformed data.
4. System according to claim 3, characterized in that the confidential collector space (101) has a database (BD1) recording the received data.
5. System according to claim 3, characterized in that the non-confidential operator space (102) has a database (BD2) recording - the data received from the confidential collector space (101), - the transformed data (H2), - the H2(Sij) data, Cdpij and the Cauthij authenticity certificates.