SYSTEM AND METHOD FOR DATA SECURITY ASSOCIATED WITH THE EXECUTION OF A TASK - Patent application
The method employs a data privacy vault to manage secure access to sensitive information for task completion, addressing the challenge of unauthorized access by ensuring controlled and logged access for trusted proxies, thus protecting sensitive data and enabling efficient task execution.
Patent Information
- Application Number
- JP2025505622
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-07
- Filing Date
- 2023-06-07
- Publication Date
- 2025-08-26
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing systems fail to securely manage and protect sensitive information on a need-to-know basis for authorized agents performing specific tasks on behalf of members, risking unauthorized access and exposure.
A computer-implemented method involving a data privacy vault that generates real-time access links for sensitive information, allowing trusted proxies to access and complete tasks while keeping the information inaccessible to unauthorized entities, with access controls and logs to monitor and correct violations.
Ensures secure, controlled access to sensitive information, preventing unauthorized exposure and enabling efficient task completion without revealing confidential data to representatives, while logging access for audit and corrective actions.
Smart Images

Figure 2025528066000001_ABST
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This patent application claims the benefit of priority to U.S. Provisional Patent Application No. 63 / 349,695, filed June 7, 2022, the disclosure of which is incorporated herein by reference.
[0002]
[0002] The present disclosure relates to automated securing of confidential information that is made accessible under limited circumstances for the performance of specific tasks. In one example, the systems and methods described herein can be used to protect confidential information that is associated with a member and that may be used only on a need-to-know basis by authorized agents for the performance of specific tasks on the member's behalf. Summary of the Invention
[0003]
[0003] The disclosed embodiments may provide a framework for automated securing of sensitive information that may be made accessible only under limited circumstances for the performance of a specific task. According to some embodiments, a computer-implemented method is provided. The computer-implemented method comprises receiving a request to perform a task on behalf of a member. The task corresponds to a set of actions that can be performed for completion of the task. Further, the set of actions includes a sensitive action. The task is assigned to a proxy associated with the member for performance of the task on the member's behalf. The computer-implemented method further comprises determining that the sensitive action is performable using sensitive information associated with the member. The computer-implemented method further comprises generating a link associated with a data privacy vault. The link is generated in real time as other actions in the set of actions associated with the task are performed. Further, the data privacy vault is inaccessible to the proxy. When the link is received by the member, the member stores the sensitive information in the data privacy vault. The computer-implemented method further comprises forwarding the task when the other actions are to be performed. When the task is received by a trusted proxy, the trusted proxy accesses the data privacy vault to obtain the sensitive information for performance of the sensitive action. Further, no confidential information is made available to the representative. The computer-implemented method further comprises communicating completion of the task. The completion of the task is communicated without the confidential information.
[0004] In some embodiments, the computer-implemented method further comprises obtaining an access log corresponding to historical accesses to the sensitive information through the data privacy repository. The computer-implemented method further comprises identifying any access violations associated with the historical accesses to the sensitive information. The access violations are identified based on the access log. The computer-implemented method further comprises implementing one or more corrective actions based on the access violations.
[0005] In some embodiments, when sensitive information is stored in the data privacy repository, the sensitive information is not available to members through the data privacy repository.
[0006] In some embodiments, access to sensitive information in the data privacy repository is subject to a timeout period, and when the timeout period expires, the trusted representative is automatically prevented from accessing the sensitive information.
[0007] In some embodiments, the computer-implemented method further comprises automatically providing a status corresponding to performance of the sensitive operation, wherein the status is provided without the sensitive information.
[0008] In some embodiments, the task is transmitted with an identifier corresponding to the sensitive information, the identifier not including any portion of the sensitive information, and the identifier can be used to query the data privacy repository to obtain the sensitive information.
[0009] In some embodiments, access to sensitive information is automatically terminated upon completion of the task.
[0010] In one embodiment, a system includes one or more processors and a memory containing instructions that, when executed by the one or more processors, cause the system to perform the processes described herein. In another embodiment, a non-transitory computer-readable storage medium stores executable instructions thereon, the executable instructions, when executed by one or more processors of a computer system, cause the computer system to perform the processes described herein.
[0011] Various embodiments of the present disclosure are discussed in detail below. While specific implementations are discussed, it should be understood that this is done for illustrative purposes only. Those skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of the present disclosure. Accordingly, the following description and drawings are illustrative and should not be construed as limiting. Numerous specific details are set forth to provide a thorough understanding of the present disclosure. However, in some instances, well-known or conventional details are not described to avoid obscuring the description. References to one embodiment or embodiments in this disclosure may refer to the same embodiment or any embodiments, and such references mean at least one of the embodiments.
[0012] Reference to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment of the present disclosure. The appearances of the phrase "one embodiment" in various places in this specification do not necessarily all refer to the same embodiment, or to separate or alternative embodiments that are mutually exclusive of other embodiments. Moreover, various features are described that may be exhibited by some embodiments but not by other embodiments.
[0013] The terms used herein generally have their ordinary meaning in the art, within the context of this disclosure and in the specific context in which each term is used. Alternative wording and synonyms may be used for any one or more of the terms described herein, and no particular importance should be placed on whether a term is recited or explained herein. In some cases, synonyms for some terms are provided. The recitation of one or more synonyms does not exclude the use of other synonyms. The use of examples anywhere in this specification, including examples of any term described herein, is illustrative only and is not intended to further limit the scope and meaning of the disclosure or any exemplary term. Similarly, the disclosure is not limited to the various embodiments provided herein.
[0014]
[0014] Without intending to limit the scope of the present disclosure, examples of devices, apparatus, methods, and their related results according to embodiments of the present disclosure are provided below. Please note that titles or subtitles may be used in the examples for the convenience of the reader, and in no case should this limit the scope of the present disclosure. Unless otherwise defined, technical and scientific terms used herein have the meanings commonly understood by those skilled in the art to which the present disclosure pertains. In the case of conflict, the present document, including definitions, will control.
[0015]
[0015] Additional features and advantages of the present disclosure will be set forth in the description which follows, and in part will be obvious from the description, or may be learned by practice of the principles disclosed herein. The features and advantages of the present disclosure may be realized and obtained by means of the instruments and combinations particularly pointed out in the appended claims. These and other features of the present disclosure will become more fully apparent from the following description and the appended claims, or may be learned by practice of the principles described herein. [Brief explanation of the drawings]
[0016] [Figure 1]
[0016] A diagram illustrating an illustrative example of an environment in which sensitive information associated with members is stored in a data privacy repository and made accessible to trusted agents for the performance of specific tasks, according to at least one embodiment. [Figure 2A]
[0017] FIG. 1 illustrates an illustrative example of an environment in which members associated with a task facilitation service add sensitive information to a data privacy repository for use in performing different tasks, according to at least one embodiment. [Figure 2B] FIG. 1 illustrates an illustrative example of an environment in which members associated with a task facilitation service add sensitive information to a data privacy repository for use in performing different tasks, according to at least one embodiment. [Figure 2C] FIG. 1 illustrates an illustrative example of an environment in which members associated with a task facilitation service add sensitive information to a data privacy repository for use in performing different tasks, according to at least one embodiment. [Figure 3A]
[0018] FIG. 1 illustrates an illustrative example of an environment in which a delegate prompts a member to provide confidential information for the completion of a task and transfers the task to a trusted delegate who has access to the confidential information and can complete the task, according to at least one embodiment. [Figure 3B] FIG. 1 illustrates an illustrative example of an environment in which a delegate prompts a member to provide confidential information for the completion of a task and transfers the task to a trusted delegate who has access to the confidential information and can complete the task, according to at least one embodiment. [Figure 3C] FIG. 1 illustrates an illustrative example of an environment in which a delegate prompts a member to provide confidential information for the completion of a task and transfers the task to a trusted delegate who has access to the confidential information and can complete the task, according to at least one embodiment. [Figure 3D] FIG. 1 illustrates an illustrative example of an environment in which a delegate prompts a member to provide confidential information for the completion of a task and transfers the task to a trusted delegate who has access to the confidential information and can complete the task, according to at least one embodiment. [Figure 4]
[0019] FIG. 1 illustrates an illustrative example of an environment in which a trusted delegate is assigned a task where sensitive information is required for the performance of the task, according to at least one embodiment. [Figure 5]
[0020] FIG. 1 illustrates an illustrative example of an environment in which a task facilitation service monitors access to sensitive information associated with members through an audit system to ensure that the sensitive information is accessed by trusted representatives for task performance, according to at least one embodiment. [Figure 6]
[0021] FIG. 1 illustrates an illustrative example of a process for performing one or more actions associated with a task and forwarding the task to a trusted representative when sensitive information is required for completion of the task, according to at least one embodiment. [Figure 7]
[0022] FIG. 1 illustrates an illustrative example of a process for accessing confidential information associated with a member for the performance of a task, according to at least one embodiment. [Figure 8]
[0023] FIG. 1 illustrates an illustrative example of a process for controlling access to confidential information associated with a member, according to at least one embodiment. [Figure 9]
[0024] FIG. 1 illustrates an illustrative example of a process for auditing historical access to sensitive information associated with members of a task facilitation service to identify any access violations and implement any required corrective actions, according to at least one embodiment. [Figure 10]
[0025] FIG. 1 illustrates a computing system architecture including various components in electrical communication with one another using connections, according to various embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0017]
[0026] In the accompanying figures, similar components and / or features may have the same reference label. Furthermore, various components of the same type may be distinguished by following the reference label with a dash and a second label that distinguishes between the similar components. When only a first reference label is used herein, the description is applicable to any of the similar components having the same first reference label, regardless of the second reference label.
[0018]
[0027] In the following description, for purposes of explanation, specific details are set forth in order to provide a thorough understanding of some invention embodiments. It will be apparent, however, that various embodiments may be practiced without these specific details. The figures and descriptions are not limiting. The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment or design described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments or designs.
[0019]
[0028] The disclosed embodiments may provide a framework for identifying and recommending experiences to members of a task facilitation service to reduce the member's cognitive load and enable the member to participate in enjoyable activities. Through this framework, the task facilitation service can generate a set of experiences in each marketplace in which the task facilitation service operates to enable personalization of member experiences within the marketplace. Furthermore, experiences may be recommended to members such that, if the member selects an experience, a representative assigned to the member can curate the experience on the member's behalf, thereby reducing the member's cognitive load.
[0020]
[0029] FIG. 1 illustrates an illustrative example of an environment 100 in which sensitive information associated with a member 110 is stored in a data privacy repository 108 and made accessible to a trusted surrogate 106 for performance of a particular task, according to at least one embodiment. In the environment 100, a member 110 of a task facilitation service 102 may engage in a communication session 116 with an assigned surrogate 104. Through the communication session 116, the member 110 may send one or more messages to the surrogate 104 to indicate that the member 110 needs assistance in completing a project and / or task for the member's benefit. For example, the member 110 may indicate that they need the surrogate's assistance in purchasing one or more items to be delivered to the member 110. The surrogate 104 may begin performing the task and / or project in response to these messages. For example, as shown in FIG. 1, the surrogate 104 may indicate through messages 118 exchanged via the communication session 116 that they have added all of the requested items associated with the member's request for assistance to a virtual cart.
[0021]
[0030] The task facilitation service 102 may be implemented to reduce the cognitive load on members and their families when performing various projects and tasks in and around the member's home by identifying and delegating projects and tasks to surrogates, who can coordinate the performance of these tasks for the member's benefit. A member, such as member 110, may be paired with a surrogate 104 during an onboarding process, during which the task facilitation service 102 may collect the member's 110's identifying information. For example, the task facilitation service 102 may provide the member 110 with a survey or questionnaire that may provide identifying information the member 110 can use to select the member's 110's surrogate 104. The task facilitation service 102 may prompt the member 110 to provide detailed information regarding the member's family composition (e.g., the number of residents in the member's home, the number and type of pets in the member's home, etc.), the physical location of the member's home, any special requests or requirements of the member 110 (e.g., physical or emotional disabilities, etc.), etc. In some examples, the member 110 may be prompted to provide demographic information (e.g., age, ethnicity, race, written / spoken language, etc.). The member 110 may also be prompted to indicate any information related to one or more projects and / or tasks that the member 110 would like to potentially delegate to the delegate 104. This information may specify the nature of these projects and / or tasks (e.g., cleaning gutters, installing carbon monoxide detectors, planning a party, etc.), the level of urgency for completion of these projects and / or tasks (e.g., timing requirements, deadlines, dates corresponding to upcoming events, etc.), any member preferences for completion of these projects and / or tasks, etc.
[0022]
[0031] The collected identification information may be used by the task facilitation service 102 to identify and assign a surrogate 104 to the member 110. For example, the task facilitation service 102 may use the member 110's identification information, any information regarding the member's comfort level or interest in delegating tasks to others, and any other information obtained during the onboarding process as input to a classification or clustering algorithm configured to identify surrogates who may be suitable to interact and communicate with the member 110 in a productive manner. Using the classification or clustering algorithm, the task facilitation service 102 may identify surrogates 104 who may be more likely to develop a successful, long-lasting relationship with the member 110 while addressing any tasks that may need to be addressed for the member 110.
[0023]
[0032] A surrogate 104 may be an individual who is assigned to a member 110 according to a degree or vector of similarity between the member's demographic information and the surrogate's demographic information. For example, if the member 110 and surrogate 104 share a similar background (e.g., attended college in the same city, are from the same hometown, share particular interests, etc.), the task facilitation service 102 may be more likely to assign the surrogate 104 to the member 110. Similarly, if the member 110 and surrogate 104 are in geographic proximity to each other, the task facilitation service 102 may be more likely to assign the surrogate 104 to the member 110.
[0024]
[0033] When a surrogate 104 is assigned to a member 110 by the task facilitation service 102, the task facilitation service 102 may notify the member 110 and the surrogate 104 of the pairing. Additionally, the task facilitation service 102 may establish a communication session between the member 110 and the assigned surrogate 104 to facilitate communication between the member 110 and the surrogate 104. For example, via an application provided by the task facilitation service 102 and installed on the computing device 112, the member 110 may exchange messages with the assigned surrogate 104 about a particular task in the communication session 116. Similarly, the surrogate 104 may be provided with an interface, such as a surrogate console (described in more detail herein), through which the surrogate 104 may exchange messages with the member 110 via the communication session 116.
[0025]
[0034] In one embodiment, the surrogate 104 may generate a new project or task that can be performed for the benefit of the member 110. For example, the surrogate 104 may submit a request to the task facilitation service 102 to generate a new project or task. In response to the request from the surrogate 104 to generate a new project or task to be performed for the benefit of the member 110, the task facilitation service 102 may identify one or more templates that can be used by the surrogate 104 to define the new project or task. The one or more task templates may correspond to task types or categories for the project and / or task being defined. For example, if the member 110 specifies, via a communication session facilitated between the member 110 and the surrogate 104, that the member 110 needs assistance purchasing a set of items from a particular online retailer for delivery to the member's home, the surrogate 104 may select a template that corresponds to online purchasing.
[0026]
[0035] For a new project or task, the surrogate 104 may define one or more actions that may be performed to complete the project or task. For example, if the member 110 submits a request for assistance with the member's 110's weekly meal plan via a communication session between the member 110 and the surrogate 104, the surrogate 104 may define a new task related to creating the member's weekly meal plan and define one or more actions for completing the member's weekly meal plan. These one or more actions may include developing a list of recipes corresponding to meals included in the plan, creating a shopping list for purchasing ingredients associated with these meals, purchasing items on the shopping list on behalf of the member 110, etc. Communications related to each of these actions may be exchanged via the communication session 116, whereby the member 110 and the surrogate 104 may exchange messages related to the particular task.
[0027]
[0036] In one embodiment, the surrogate 104 evaluates one or more actions associated with a particular task or project to determine whether confidential information associated with the member 110 is required for completion of the task. Returning to the previous illustrative example related to the member's weekly meal plan, the surrogate 104 may determine that the member 110 may be required to provide their account credentials associated with an online retailer in order for items on the shopping list to be purchased from the online retailer. In some instances, the surrogate 104 may determine that the member 110 may be required to provide payment information, such as a payment card number, a card verification value (CVV) associated with the payment card, and an expiration date associated with the payment card. As another illustrative example, if the surrogate 104 defines a task related to scheduling a medical procedure, the surrogate 104 may determine that the member 110 may be required to provide their medical insurance information in order for the medical procedure to be scheduled. Such information may be considered confidential in nature, whereby inadvertent or intentional distribution and exposure of such information to unauthorized entities may result in harm to the member 110. Therefore, the task facilitation service 102 may prohibit the surrogate 104 from accessing such sensitive information.
[0028]
[0037] In one embodiment, the task facilitation service 102 implements a machine learning algorithm or artificial intelligence that is dynamically trained to automatically determine whether any confidential information associated with the member 110 is required for the completion of the task. For example, the task facilitation service 102 may implement a machine learning algorithm, such as a natural language processing (NLP) algorithm, or other artificial intelligence, to process messages exchanged between the member 110 and the proxy 104 as they are exchanged in real time via the communication session 116 to determine whether any confidential information associated with the member 110 may be required for the completion of the task. For example, the task facilitation service 102 may process any incoming messages from the member 110 and the proxy 104 via the communication session 116 to detect actions associated with the task or project that may require confidential information associated with the member 110. As an illustrative example, if the surrogate 104 expresses via communication session 116 that they have completed adding requested items to a virtual cart associated with an online retailer, a machine learning algorithm or artificial intelligence implemented by task facilitation service 102 may determine that the member's account credentials and / or payment information may be required and process this message from the surrogate 104 automatically in real time to complete the checkout process for the requested items in the virtual card. As another illustrative example, when the surrogate 104 defines a particular task to be performed on behalf of the member 110, the machine learning algorithm or artificial intelligence may automatically evaluate the task to identify any possible actions associated with the task that may require sensitive information from the member 110.
[0029]
[0038] The machine learning algorithm or other artificial intelligence may be dynamically trained in real time using supervised training techniques. For example, a dataset of input messages, corresponding projects / tasks (including any associated actions), and member information used to complete the projects / tasks may be selected for training the machine learning algorithm or artificial intelligence. This dataset may include hypothetical data (e.g., hypothetical input messages, projects / tasks, member information, etc.), actual historical data (e.g., historical input messages, corresponding projects / tasks, actual member information associated with the projects / tasks, etc.), or a combination thereof. Based on sample inputs provided to the machine learning algorithm or artificial intelligence, the machine learning algorithm or artificial intelligence may be evaluated to determine whether the machine learning algorithm or artificial intelligence accurately identifies the need for confidential information associated with members based on the sample input messages and corresponding projects / tasks. Based on this evaluation, the machine learning algorithm or artificial intelligence may be modified to increase the likelihood that the machine learning algorithm or artificial intelligence accurately identifies the need for specific types of confidential information that may be required to complete the projects or tasks.
[0030]
[0039] The machine learning algorithm or artificial intelligence may further be dynamically trained in real time by soliciting feedback from members and delegates associated with the task facilitation service 102 regarding the requirement for confidential information for the completion of tasks and / or projects. For example, if the task facilitation service 102 determines that the machine learning algorithm or artificial intelligence failed to recognize the need for particular confidential information for the completion of one or more actions associated with a particular task or project, the task facilitation service 102 may use this feedback to retrain the machine learning algorithm or artificial intelligence to better identify the need for particular confidential information for similar tasks and / or projects. Alternatively, if the task facilitation service 102 determines that the machine learning algorithm or artificial intelligence accurately recognized the need for particular confidential information for the completion of one or more actions associated with a particular task or project, the task facilitation service 102 may use this feedback to enhance the machine learning algorithm or artificial intelligence for similar tasks or projects such that the machine learning algorithm or artificial intelligence is more likely to provide an indication of the confidential information required for those tasks or projects.
[0031]
[0040] In some cases, the machine learning algorithm or other artificial intelligence may additionally or alternatively be trained using a dataset of input tasks and / or projects, corresponding actions, and any information used to complete those actions. Based on these sample inputs, the machine learning algorithm or artificial intelligence may be evaluated to determine whether the machine learning algorithm or artificial intelligence accurately identifies the information needed for completion of the actions associated with the sample input tasks and / or projects. Through this evaluation, the task facilitation service 102 may retrain or enhance the machine learning algorithm or artificial intelligence to be more accurate in determining whether sensitive information is needed for a particular task or project when the particular task or project is initially defined by the delegate 104.
[0032]
[0041] It should be noted that the machine learning algorithm or artificial intelligence may be dynamically trained in real time to continuously and automatically process and monitor messages exchanged between different members and representatives as they are exchanged in real time via different corresponding communication sessions to determine, for these communication sessions, whether confidential information may be required for task completion. This continuous processing and monitoring of these different communication sessions and corresponding messages as they are exchanged may be performed independently and in parallel in real time for numerous active communication sessions between different members and representatives. Furthermore, the machine learning algorithm or artificial intelligence may be continuously updated in real time as decisions are made regarding confidential information that may be required for different tasks or projects corresponding to the different communication sessions, and as actions are taken based on these decisions (e.g., requests for confidential information are provided based on generated decisions, the generated decisions are discarded based on actual review of the corresponding tasks, etc.). Thus, based on the results resulting from the determination corresponding to the confidential information that may be required to complete the task (e.g., a obtained request for confidential information, a determination that the confidential information was not required, etc.), the machine learning algorithm or artificial intelligence may be continuously and dynamically updated in real time to improve or enhance the accuracy of the machine learning algorithm or artificial intelligence in generating determinations corresponding to the confidential information that may be required for different tasks and projects identified from the ongoing communication session between the member and the representative.
[0033]
[0042] In one embodiment, if a machine learning algorithm / artificial intelligence implemented by the surrogate 104 or the task facilitation service 102 determines that confidential information associated with the member 110 is needed for the completion of one or more actions associated with a particular task or project, the surrogate 104 can send, through the communication session 116, a link 120 to a form that the member 110 can select to provide the needed confidential information. The link 120 can be associated with a data privacy vault 108 that can be implemented to securely store and isolate the confidential information on behalf of the task facilitation service 102. Furthermore, the data privacy vault 108 can provide various access controls to facilitate access to the confidential information only to users authorized to access such confidential information. These access controls can be defined by the task facilitation service 102, which can provide or generate sets of credentials for different users who can be authorized by the task facilitation service 102 to access the confidential information stored in the data privacy vault 108.
[0034]
[0043] 1 , the surrogate 104 may indicate (e.g., via message 118) through communication session 116 that they have added all of the items associated with the shopping list to the member's virtual cart. However, in order for these items to be purchased from the online retailer, the member 110 may be required to provide their account credentials associated with the online retailer. As described above, the surrogate 104 may be prevented from viewing or otherwise accessing these account credentials on behalf of the member 110. Accordingly, the surrogate 104 may generate and present a link 120 to the data privacy repository 108, through which the member 110 may record their account credentials.
[0035]
[0044] In one embodiment, the representative 104 can send a request to the data privacy repository 108 to generate a link 120, which can be presented to the member 110 and used by the member 110 to provide their account credentials or other sensitive information that can be used to complete a particular task or project. For example, the representative 104 may access the data privacy repository 108 and select a particular type or category of sensitive information required from the member 110. As an illustrative example, when the representative 104 accesses the data privacy repository 108, the data privacy repository 108 may provide different sensitive information categories to the representative 104, and from the different sensitive information categories, the representative 104 may select a particular category associated with the sensitive information required from the member 110. When the representative 104 selects a particular category, the data privacy repository 108 may present the representative 104 with a form associated with the particular category, through which the representative 104 may provide a description or name of the sensitive information to be provided. For example, the surrogate 104 may assign the name "Brand Shopping Account," which may be used to indicate that the confidential information provided corresponds to the member's shopping account associated with the listed brand. In some examples, the surrogate 104 may be permitted to assign a description or name for the confidential information to be provided by the member 110, but the surrogate 104 may be prevented from entering any confidential information into the form or otherwise accessing any confidential information maintained by the data privacy repository 108. For example, if the form includes a confidential information entry field, the data privacy repository 108 may disable this field for the surrogate 104 to prevent the surrogate 104 from entering any information into the confidential information entry field.
[0036]
[0045] In some instances, the data privacy repository 108 may provide an application programming interface (API) through which the agent 104 may define a name or description of the confidential information provided by the member 110 for a particular task or project. Through an API call to the data privacy repository 108, the agent 104 may provide a name or description of the confidential information and contact information associated with the member 110 that can be used by the data privacy repository 108 to contact the member 110 to retrieve and securely store the confidential information associated with the member 110.
[0037]
[0046] Once the surrogate 104 defines a name or description of the confidential information to be provided by the member 110, the data privacy repository 108 may provide the member 110 with a link 120 to a corresponding form for entry of the confidential information. As shown in FIG. 1 , the link 120 to the form may be provided to the member 110 through a communication session 116 with the surrogate 104. If the member 110 selects the link 120, the member 110 may be redirected to the data privacy repository 108, through which the member 110 may access the form generated by the surrogate 104 for entry of the requested confidential information. The form may be presented to the member 110 without exposing the form or any information added to the form to the surrogate 104. For example, when the member 110 provides their confidential information through a form, the surrogate 104 may be prevented from obtaining any information corresponding to the member's entry of the confidential information into the form (e.g., keystrokes, clear text inputs, the form itself, etc.). Furthermore, once the member 110 submits their confidential information through a provided form, the member 110 may be prevented from accessing this confidential information. This may prevent the exposure of sensitive information to unauthorized entities, such as unauthorized entities that gain access to the member's computing device 112 or an account associated with the task facilitation service 102 .
[0038]
[0047] In one embodiment, when the member 110 completes entering their sensitive information through the provided form, the data privacy repository 108 sends a notification to the representative 104 indicating that the member 110 has provided the requested sensitive information. This notification may be provided to the representative 104 without including the sensitive information provided by the member 110. Furthermore, if the representative 104 attempts to access the data privacy repository 108 to retrieve the sensitive information, the data privacy repository 108 may prevent the representative 104 from accessing the sensitive information. For example, the data privacy repository 108 may implement one or more policy controls whereby only authorized entities assigned to a particular role (e.g., a trusted role, an authorized role, etc.) may access the sensitive information stored therein. In some instances, the data privacy repository 108 may require a set of credentials (e.g., a username and password, a cryptographic token, etc.) that can be verified to determine whether access to the sensitive information should be granted. Any attempt to access sensitive information stored in the data privacy repository 108 may be logged in order to audit authorized and unauthorized attempts to access sensitive information stored in the data privacy repository 108 and take any necessary corrective action accordingly (e.g., revoking access to sensitive information, taking punitive action for unauthorized attempts to access sensitive information, etc.).
[0039]
[0048] In one embodiment, once the surrogate 104 receives an indication from the data privacy repository 108 that the member 110 has provided the requested confidential information, the surrogate 104 can forward the particular task or project to the trusted surrogate 106 for completion of the task or project. For example, the surrogate 104 may forward the communication session 116 to the trusted surrogate 106, which may enable the trusted surrogate 106 to review all previously exchanged communications between the member 110 and the surrogate 104 for the particular task or project, including the request (e.g., link 120) provided to the member 110 to provide the confidential information. In some instances, through the surrogate console, the trusted surrogate 106 may review which actions were performed on behalf of the member 110 for the particular task or project. Furthermore, through this surrogate console, the trusted surrogate 106 may identify the category or type of confidential information submitted by the member 110 through use of the provided link 120 or other access through the data privacy repository 108.
[0040]
[0049] A trusted representative 106 may be a representative authorized to access confidential information associated with members of the task facilitation service 102 and perform various tasks or projects on behalf of these members. Trusted representatives 106 may be vetted by the task facilitation service 102 to reduce the likelihood that confidential information maintained in the data privacy repository 108 will be exposed (intentionally or unintentionally) to unauthorized entities. For example, a trusted representative 106 may be required to pass an extensive background check before being granted access to the data privacy repository 108 to access any confidential information. In some instances, access to the data privacy repository 108 by a trusted representative 106 may be facilitated only through a secure computing environment (e.g., a computing environment with controlled storage and network access, a cryptographically secure environment, an isolated network environment, etc.).
[0041]
[0050] In one embodiment, access to sensitive information in the data privacy vault 108 is provided on a “need-to-know” basis, whereby the trusted representative 106 is granted access only to sensitive information needed to perform the task or project transferred to the trusted representative 106. For example, when transferring a task or project to the trusted representative 106, the representative 104 may indicate which sensitive information is needed for the task or project (e.g., an identifier corresponding to a form or request for sensitive information provided to the member 110, an identifier corresponding to a name or description provided by the representative 104 for the sensitive information, etc.). This identifier may be used to generate a unique set of certificates or cryptographic tokens that can be used by the trusted representative 106 for the sole purpose of retrieving the sensitive information needed for the task or project. For example, if the trusted representative 106, through the representative console, selects an option to access sensitive information from the data privacy vault 108 for a particular task or project, the data privacy vault 108 may process the associated certificates or cryptographic tokens to determine which sensitive information is available to the trusted representative 106.
[0042]
[0051] The trusted representative 106 may access the data privacy vault 108 to obtain sensitive information needed for the performance of one or more operations associated with a task or project forwarded to the trusted representative 106. For example, through the representative console, the trusted representative 106 may select an option to access the data privacy vault 108 to retrieve sensitive information that may be needed for the task or project. Selection of this presented option may cause the task facilitation service 102 to redirect the trusted representative 106 to the data privacy vault 108. Through the data privacy vault 108, the trusted representative 106 may select a particular type or category of sensitive information being retrieved. For example, if the trusted representative 106 needs a member's account certificate for a particular brand, the trusted representative 106 may select a type or category that corresponds to a brand-specific account certificate.
[0043]
[0052] If the trusted representative 106 selects a particular type or category, the data privacy repository 108 may prompt the trusted representative 106 to provide their set of credentials for accessing sensitive information from the data privacy repository 108. The data privacy repository 108 may evaluate the set of credentials to determine whether the set of credentials is valid and, if so, whether the trusted representative 106 is authorized to access sensitive information corresponding to the selected type or category. As described above, the trusted representative 106 may be issued a set of credentials or cryptographic tokens that can be used by the trusted representative 106 for the sole purpose of retrieving sensitive information needed for a task or project. Thus, the set of credentials or cryptographic tokens may be specific to the particular sensitive information associated with the particular type or category. If the trusted representative 106 attempts to access a type or category that is different from the type or category associated with the sensitive information to which the trusted representative 106 is authorized to access, the data privacy repository 108 may automatically deny the request to access the selected type or category.
[0044]
[0053] The data privacy repository 108 may present available sensitive information to the trusted representative 106 if the trusted representative 106 has selected a particular type or category associated with sensitive information to which the trusted representative 106 is authorized to access. For example, the data privacy repository 108 may present a completed form submitted by the member 110 in response to a prompt from the representative 104 for entry of this sensitive information. The completed form may include a clear-text representation of the sensitive information so that the trusted representative 106 may review the sensitive information. However, the sensitive information may not be made available to the representative 104, the member 110, or any other unauthorized entity.
[0045]
[0054] In one embodiment, access to the sensitive information through the data privacy vault 108 is provided for a limited period of time, whereby, after the limited period of time has elapsed, access to the sensitive information is automatically revoked for the trusted representative 106. For example, when a task or project is transferred to the trusted representative 106 for performance of one or more operations that require access and use of sensitive information associated with the member 110, the task facilitation service 102 may provide the trusted representative 106 with an indication of the amount of time that the sensitive information will be made available to the trusted representative 106 through the data privacy vault 108. Once this amount of time has elapsed, the set of credentials or cryptographic tokens that can be used to access the sensitive information may be automatically revoked, thereby preventing the trusted representative 106 from accessing the sensitive information unless the trusted representative 106 submits a request to the task facilitation service 102 to be granted updated access to the sensitive information.
[0046]
[0055] Access to sensitive information through the data privacy repository 108 may be logged so that an auditor associated with the task facilitation service 102 can determine when the sensitive information was accessed and by whom. For example, if the task facilitation service 102 determines that particular sensitive information has been leaked to an unauthorized entity, the task facilitation service 102 may review the logs maintained by the data privacy repository 108 to determine which trusted representatives previously accessed the leaked sensitive information. This allows the task facilitation service 102 to focus on the particular entities that have accessed the sensitive information and tailor its investigation accordingly.
[0047]
[0056] Using the sensitive information from the data privacy repository 108, the trusted representative 106 may perform one or more operations associated with the task or project. For example, the trusted representative 106 may use the sensitive information to log into the member's third-party service account (e.g., an account associated with a particular brand, an account associated with a particular retailer or point of sale, etc.) and complete a checkout process. As another illustrative example, if the sensitive information includes payment information (e.g., a credit card number, a CVV, etc.) associated with the member 110, the trusted representative 106 may use this sensitive information to submit payment to the third-party service 114 for performance of one or more operations associated with the task or project. As yet another illustrative example, if the sensitive information includes health insurance information associated with the member 110, which may be provided for a task or project associated with a medical procedure or visit, the trusted representative 106 may obtain this health insurance information on behalf of the member 110 and provide it to a doctor, pharmacy, or other authorized entity (e.g., the third-party service 114) that may require the member's health insurance information.
[0048]
[0057] In one embodiment, the task facilitation service 102 enables the trusted representative 106 to communicate directly with the member 110, such as through a communication session 116. For example, if the trusted representative 106 encounters any issues related to confidential information previously provided by the member 110 (e.g., the confidential information is unavailable to access the member account, the confidential information lacks information necessary to perform one or more actions, the confidential information contains one or more typographical errors, etc.), the trusted representative 106 may communicate with the member 110 via the communication session 116 to address these issues. This may include providing the member 110 with a new link 120 for entering the confidential information through the data privacy repository 108 and removing any previously provided confidential information that may have errors or may be associated with one or more issues corresponding to the performance of one or more actions by the trusted representative 106. The trusted representative 106 may further communicate with the member 110 via the communication session 116 to address any issues related to the task or project itself. For example, the trusted representative 106 may prompt the member 110 to provide any one-time codes associated with a multi-factor authentication request from the third-party service 114 for any possible substitutions to the order.
[0049]
[0058] Once the trusted representative 106 has completed performing one or more operations requiring the use of confidential information, the trusted representative 106 may transfer the task or project to the representative 104. Any confidential information used by the trusted representative 106 may be obscured from the representative console utilized by the representative 104 to prevent exposure of the confidential information to the representative 104. The representative 104 may perform any remaining operations associated with the task or project on behalf of the member 110 without access to the confidential information previously used by the trusted representative 106.
[0050]
[0059] It should be noted that for the processes described herein, various operations performed by the surrogate 104 and / or trusted surrogate 106 may additionally or alternatively be performed using one or more machine learning algorithms or artificial intelligence. For example, as the surrogate 104 and trusted surrogate 106 perform or otherwise coordinate the performance of projects and tasks on behalf of the member 110 over time, the task facilitation service 102 may continuously and automatically update the member's profile according to the member's feedback related to the performance of these projects and tasks by the surrogate 104, trusted surrogate 106, and / or third-party service 114. In one embodiment, the task facilitation service 102 may utilize machine learning algorithms or artificial intelligence to automatically and dynamically generate new projects and tasks based on various attributes of the member's profile (e.g., historical data corresponding to communications between the member and the surrogate, member feedback corresponding to the surrogate's performance and presented tasks / suggestions, etc.) with or without surrogate interaction after the member's profile has been updated over a period of time (e.g., six months, one year, etc.) or over a set of projects and tasks (e.g., 20 tasks, 30 tasks, etc.). The task facilitation service 102 may automatically communicate with the member 110 to obtain any additional information needed for the new projects and tasks and automatically transfer these projects and tasks to a trusted surrogate 106 when confidential information is required for the performance of one or more operations associated with these projects and tasks. The surrogate 104 may monitor communications between the task facilitation service 102 and the member 110 to ensure that the conversation maintains a positive polarity (e.g., the member 110 is satisfied with their interaction with the task facilitation service 102 or bot, etc.). If the surrogate 104 determines that the conversation has a negative polarity (e.g., the member 110 is expressing frustration, the task facilitation service 102 or bot is unable to process the member's response or request, etc.), the surrogate 104 may intervene in the conversation.This may allow the representative 104 to address member concerns and implement projects and tasks on behalf of the member 110 .
[0051]
[0060] Thus, unlike automated customer service systems and environments that may have little knowledge of users interacting with agents or other automated systems, the task facilitation service 102 can continuously update a member profile to provide up-to-date historical information about the member 110 based on the member's automated interactions with the system or surrogate 104 / trusted surrogate 106, as well as projects and tasks performed on behalf of the member 110 over time. This historical information, which may be automatically and dynamically updated as the member 110 or system interacts with the surrogate 104 / trusted surrogate 106 and as projects and tasks are conceived, proposed, and performed for the member 110 over time, can be used by the task facilitation service 102 to anticipate, identify, and present appropriate or intelligent responses to the member's 110's queries, needs, and / or objectives.
[0052]
[0061] 2A-2C show an illustrative example of an environment 200 in which a member 110 associated with a task facilitation service 102 adds sensitive information to a data privacy repository 108 for use in performing different tasks, according to at least one embodiment. In the environment 200, the member 110 may be provided with an interface 204, through which the member 110 may communicate with a representative through a communication session facilitated by the task facilitation service 102, define and request performance of new tasks or projects on the member's behalf, update a member profile associated with the member 110, etc. In one embodiment, the task facilitation service 102 may further provide the member 110 with an option, through the interface 204, to add sensitive information to the data privacy repository 108 for use with various tasks and / or projects that may be performed on the member's behalf. For example, as shown in FIG. 2A , the task facilitation service 102 may present, through the interface 204, an add confidential information button 206 that, when selected, may allow the member 110 to provide any confidential information that may be used in the performance of various tasks and / or projects on behalf of the member 110.
[0053]
[0062] While the add confidential information button 206 is used extensively throughout this disclosure for illustrative purposes, it should be noted that additional and / or alternative elements may be integrated into the interface 204 to enable the member 110 to request access to the data privacy vault 108 to add confidential information associated with the member 110. For example, the task facilitation service 102 may provide, through the interface 204, a drop-down menu containing various options for managing the member's account. This may include an option for accessing the member's profile to add or modify any information associated with the member 110 that was collected during the onboarding process and / or during the performance of one or more tasks and projects on the member's behalf. Additionally, the drop-down menu may include an option for accessing the data privacy vault 108 to provide any confidential information that may be used for the performance of different tasks and projects on the member's behalf. In some instances, the task facilitation service 102 may not provide an option for accessing the data privacy vault 108, and as a result, the member 110 may be required to communicate with their assigned representative to request access to the data privacy vault to enter their confidential information.
[0054]
[0063] If the member 110 selects the add sensitive information button 206, the task facilitation service 102 may send a request to the data privacy repository 108 through the interface 204, presenting one or more options for entering the sensitive information. These one or more options may correspond to different categories or types of sensitive information that may be maintained by the data privacy repository 108 in the sensitive information data store 202. For example, as shown in FIG. 2B, the data privacy repository 108 may update the interface 204 to present a sensitive information category selection window 208, through which the member 110 may select a particular category or type of sensitive information to be entered. The sensitive information category selection window 208, as shown in FIG. 2B, may include different available categories or types of sensitive information that may be entered (e.g., driver's license information, passport information, bank account information, account credentials, payment card information, health insurance information, etc.). Each particular category may be associated with a corresponding form in which the member 110 may provide their sensitive information. For example, a form associated with a health insurance category may include one or more input fields that may correspond to health insurance information that may be provided (e.g., health insurance member identifier, processor control number, issuer identification number, etc.). As another illustrative example, a form associated with a driver's license category may include one or more input fields that may correspond to a member's driver's license (e.g., issuing state, identification number, member's address, date of birth, expiration date, issue date, any restrictions, etc.). As yet another illustrative example, a form associated with a payment card includes one or more input fields that may correspond to a payment card, such as a credit or debit card (e.g., name printed on the card, card number, CVV, expiration date, etc.).
[0055]
[0064] When the member 110 selects a particular category or type of sensitive information to be provided to the data privacy vault 108, the data privacy vault 108 may update the interface 204 to present the member 110 with a corresponding form that can be used to provide the sensitive information. For example, as shown in FIG. 2C , the member 110 has selected a category that corresponds to a username and password for a particular account. The corresponding form window 210 presented through the interface 204 may include a sensitive information entry form 212. As shown in FIG. 2C , the sensitive information entry form 212 may include a name field 214, through which the member 110 may provide a name that can be associated with the provided sensitive information. For example, through the name field 214 of the sensitive information entry form 212, the member 110 may indicate that the sensitive information being provided is the username and password for their account associated with a particular brand (e.g., “brand password” as shown in the name field 214).
[0056]
[0065] In addition to the name field 214, the data privacy repository 108 may provide a notes field 216 that can be used by the member 110 to enter sensitive information to be stored in the sensitive information data store 202 through the sensitive information entry form 212. As described above, the data privacy repository 108 may provide different forms for different categories or types of sensitive information that may be added to the data privacy repository 108. Thus, the notes field 216 may differ for different sensitive information categories or types and, accordingly, may include one or more input fields. For example, as shown in FIG. 2C , the notes field 216 corresponding to the username and password category may include a single input field in which the member 110 can enter both their username and password for a particular account. However, in some instances, the notes field 216 may include multiple input fields that can be defined according to the portion of the sensitive information that may be provided. As an illustrative example, if the member 110 is providing their driver's license information, the notes field 216 may include an input field for the state in which the driver's license was issued, an input field for the driver's license number, an input field corresponding to the issue date, an input field corresponding to the expiration date, etc. Thus, the data privacy repository 108 may customize each form according to the corresponding sensitive information category or type.
[0057]
[0066] In one embodiment, once the member 110 completes the entry of their confidential information through the confidential information entry form 212, the data privacy repository 108 can store the provided confidential information in the confidential information data store 202. The confidential information data store 202 may store the provided confidential information in association with the member 110 and a particular category or type of confidential information. For example, a query for the provided confidential information may require a certificate or set of cryptographic tokens associated with both the member identifier (e.g., username maintained by the task facilitation service 102) and the category or type associated with the confidential information (e.g., driver's license, username / password, payment card, health insurance, etc.). When a representative assigned to the member 110 creates a new task or project in which the member's confidential information may be required, the representative may indicate the category or type associated with the confidential information that may be required to perform the task or project. In one embodiment, the task facilitation service 102 may generate a certificate or set of cryptographic tokens incorporating the member's username and the category or type associated with this sensitive information, so that a trusted representative can submit the certificate or set of cryptographic tokens to retrieve this sensitive information from the sensitive information data store 202.
[0058]
[0067] The sensitive information data store 202 may provide secure storage for any provided sensitive information. For example, the sensitive information data store 202 may be encrypted so that an unauthorized entity cannot access the sensitive information data store 202 and obtain any sensitive information stored therein without providing a valid set of credentials or cryptographic tokens. As described above, this set of credentials or cryptographic tokens may be made available only to trusted delegates on a “need-to-know” basis. This may prevent other delegates (such as the delegate originally assigned to the member 110) and the member 110 from accessing any sensitive information once it is stored in the sensitive information data store 202. This may reduce the risk of any entered sensitive information being exposed (intentionally or unintentionally) to unauthorized entities.
[0059]
[0068] In one embodiment, the member 110 may access the data privacy repository 108 to remove any previously provided confidential information from the confidential information data store 202. For example, the member 110 may access the data privacy repository 108 through the interface 204 to submit a query to identify what confidential information is stored in the confidential information data store 202 on the member's behalf. In response to the query, the data privacy repository 108 may present the member 110 with identifiers or names previously provided by the member 110 for different confidential information stored in the confidential information data store 202. However, the data privacy repository 108 may not provide any of the confidential information associated with each of these identifiers or names, as described above. The member 110 may select, through the interface 204, specific identifiers or names corresponding to confidential information stored in the confidential information data store 202 and request the deletion of the confidential information. Thus, the member 110 may have control over the actual confidential information stored in the confidential information data store 202 while being prohibited from reviewing that information.
[0060]
[0069] 3A-3D show an illustrative example of an environment 300 in which a surrogate 104 prompts a member to provide confidential information for completion of a task and forwards the task to a trusted surrogate 106 that has access to the confidential information and can complete the task, according to at least one embodiment. In the environment 300, the surrogate 104 may communicate with the member through a communication session 116 associated with a particular task or project being performed on the member's behalf. The communication session 116 may be presented to the member through an interface 204 provided by the task facilitation service 102. For example, the interface 204 may be provided by the task facilitation service 102 and accessible through an application implemented on the member's computing device (e.g., a smartphone, a computer system, etc.). Additionally or alternatively, the interface 204 may be accessible through a web portal or other website provided by the task facilitation service 102.
[0061]
[0070] Communication sessions 116 may be facilitated between members and surrogates 104 using information from the user data store 304. For example, when a new communication session 116 is established between a surrogate 104 and a particular member, the task facilitation service 102 may generate and assign a unique identifier to the new communication session 116. This unique identifier for the new communication session 116 may be associated with the member input in the user data store 304, such that messages exchanged via the communication session 116 are automatically entered and stored in association with the member input. As described in more detail herein, the unique identifier may be provided to the trusted surrogate 106 when a task or project being performed on behalf of the member is transferred to the trusted surrogate 106 for performance of one or more operations requiring access to and use of confidential information associated with the member. Additionally, parameters associated with the task or project may be stored in a task data store 306 maintained by the task facilitation service 102. Thus, when a task or project being performed on behalf of a member is transferred to the trusted representative 106, the trusted representative 106 may retrieve parameters associated with the task or project from the task data store 306.
[0062]
[0071] Through the communication session 116, the representative 104 may communicate with the member to obtain any information that may be used for the completion of a particular task or project and to provide updates related to the implementation of a particular task or project. For example, through a message 118 provided to the member over the communication session 116, the representative 104 may indicate that they have added all of the items requested by the member to a virtual cart for checkout. Furthermore, through the message 118, the representative 104 may indicate that they need the member's account information associated with the brand for which these items are being purchased to complete the checkout process. The member's account information associated with the brand may be confidential and may not be made available to the representative 104 because the representative 104 is not authorized to access confidential information associated with the member. Therefore, the representative 104 may be required to provide the member with a link 120 to the data privacy repository 108 for entry of the required confidential information.
[0063]
[0072] In one embodiment, to provide the link 120 to the member through the interface 204, the surrogate 104 can submit a request to an information security system 302 implemented by the data privacy repository 108 to generate the link 120. The information security system 302 may be implemented using a computer system associated with the data privacy repository 108 or an application running on a computer system. In response to a form request from the surrogate 104, the information security system 302 may present the surrogate 104 with various sensitive information categories or types for which forms are available. For example, the surrogate 104 may access the information security system 302 through a surrogate console provided by the task facilitation service 102 to submit their request for a sensitive information form that can be provided to the member. Through this surrogate console, the information security system 302 may present the surrogate 104 with various sensitive information categories or types for which forms are available. As mentioned above, each sensitive information category or type may be associated with a specific form that may have different input fields corresponding to the category or type of sensitive information being provided. Thus, selection of a particular sensitive information category or type may indicate selection of a particular form corresponding to the selected sensitive information category or type.
[0064]
[0073] In response to the surrogate's selection of a particular sensitive information category or type, the information security system 302 may prompt the surrogate 104 for information corresponding to the member. This may include prompting the surrogate 104 to provide an identifier or username associated with the member. This identifier or username may correspond to an identifier or username utilized by the member for the task facilitation service 102. This may allow the information security system 302 to associate any sensitive information provided by the member with the member themselves. Additionally, the identifier or username may be used to tailor the link 120 that may be provided to the member so that when the member selects the link 120, the form presented to the member may be immediately associated with the member.
[0065]
[0074] In one embodiment, the task facilitation service 102 implements a machine learning algorithm or artificial intelligence that can be dynamically trained to automatically determine when sensitive information may be required for the performance of a particular task or project. The machine learning algorithm or artificial intelligence may be trained using supervised, unsupervised, reinforcement, or other such training techniques. For example, a dataset comprising tasks previously performed on behalf of members of the task facilitation service 102 (as indicated through the task data store 306) and decisions regarding whether sensitive information is required for the completion of these tasks may be used to identify correlations between different tasks and sensitive information without supervision and feedback (e.g., unsupervised training techniques). The machine learning data analysis algorithm may also be trained using sample or live data (e.g., sample tasks or live tasks being performed on behalf of members) to identify possible correlations between these tasks and the sensitive information required. Accordingly, the task facilitation service 102 may implement a clustering algorithm to identify similar tasks, the information required to perform these similar tasks, and the sensitivity (or lack thereof) of this information based on one or more vectors of similarity between the task being evaluated and other clusters of required information determinations. These similarity vectors may include, but are not limited to, task type or category, type or category of information required for completion of the task, third-party entities associated with the task (e.g., retailers, service providers, etc.), etc. In some instances, the sample dataset described above may be analyzed using a clustering algorithm to determine whether sensitive information is required for performance of the sample tasks represented in the dataset. Thus, in some embodiments, the task facilitation service 102 may perform such clustering through a machine learning algorithm or artificial intelligence to identify specific clusters and determine from these clusters whether sensitive information is required for performance of the underlying tasks, and obtain partial matches between other clusters of sensitive information requirement determinations.
[0066]
[0075] Exemplary clustering algorithms may include a k-means clustering algorithm, a fuzzy c-means (FCM) algorithm, an expectation-maximization (EM) algorithm, a hierarchical clustering algorithm, a density-based spatial clustering for noisy applications (DBSCAN) algorithm, etc. Other examples of machine learning or artificial intelligence algorithms include, but are not limited to, genetic algorithms, backpropagation, reinforcement learning, decision trees, linear classification, artificial neural networks, anomaly detection, etc. More generally, machine learning or artificial intelligence methods may include regression analysis, dimensionality reduction, meta-learning, reinforcement learning, deep learning, and other such algorithms and / or methods. As may be contemplated, the terms "machine learning" and "artificial intelligence" are often used interchangeably due to the degree of overlap between these fields, and many of the disclosed techniques and algorithms have similar approaches.
[0067]
[0076] As an example of a supervised training technique, a dataset for training a machine learning algorithm or artificial intelligence may be selected to facilitate the identification of correlations between specific tasks and projects and the need for confidential information for the completion of those specific tasks and projects. The machine learning algorithm or artificial intelligence may be evaluated to determine whether it is generating accurate correlations between different tasks / projects and the need for confidential information for the completion of those different tasks / projects based on sample inputs provided to the machine learning algorithm or artificial intelligence. Based on this evaluation, the machine learning algorithm or artificial intelligence may be modified to increase the likelihood that it will identify the desired correlations. The machine learning model may be further dynamically trained by soliciting feedback (i.e., monitoring) from a surrogate regarding the efficacy of the correlations provided by the machine learning algorithm or artificial intelligence. The machine learning algorithm or artificial intelligence may use this feedback to improve the algorithm for generating the correlations (e.g., the feedback may be used to further train the machine learning algorithm or artificial intelligence to provide more accurate correlations).
[0068]
[0077] In one embodiment, the dataset used to train the machine learning algorithm or artificial intelligence may further include conversation data corresponding to communication sessions previously facilitated between different members and representatives for different tasks or projects. The machine learning algorithm or artificial intelligence may be dynamically trained to identify correlations between different communications exchanged between the member and representative and a determination regarding the need for confidential information for the completion of the corresponding task or project. For example, if a member indicates through a communication session that they need assistance with meal planning for their meals, and an assigned representative subsequently purchases groceries for the member through an online grocery store where the member's account information is needed to complete the purchase, the machine learning algorithm or artificial intelligence may be dynamically trained to determine whether the member's account information (e.g., confidential information) for the corresponding grocery store may be needed for a similar task or project. In one embodiment, the machine learning algorithm or artificial intelligence is a natural language processing (NLP) algorithm that is dynamically trained to process communications between the member and representative in real time as they are exchanged to determine in real time whether confidential information is needed to perform the particular task or project associated with the exchanged communications.
[0069]
[0078] In one embodiment, if the machine learning algorithm or artificial intelligence determines, based on exchanged communications and / or based on the particular task or project being performed on behalf of the member, that confidential information may be required for the performance of a particular task or project, the machine learning algorithm or artificial intelligence may automatically access the information security system 302 to request a link 120 to a corresponding form that may be used to submit the confidential information. In response to obtaining the link 120 from the information security system 302, the machine learning algorithm or artificial intelligence may automatically update the communication session 116 between the member and the representative 104 to present the link 120 to the member. In some instances, if the member or representative indicates through the communication session 116 or through other feedback provided during or after the performance of the particular task or project that the link 120 was not necessary for the performance of the task or project, this feedback may be used to dynamically retrain the machine learning algorithm or artificial intelligence, thereby reducing the likelihood that, for similar tasks and projects, the link will be provided for the submission of confidential information for those similar tasks and projects.
[0070]
[0079] In some embodiments, as shown in FIG. 3D , the task facilitation service 102 implements a communication processing system 308 configured to automatically process communications between different members and representatives (such as the communication sessions between the members and representatives 104 shown in FIGS. 3A-3D ) in real time to determine whether sensitive information may be required for the performance of one or more sensitive operations associated with a particular task or project. The communication processing system 308 may be implemented as a special-purpose computing device that includes one or more special-purpose processors (such as the special-purpose processor described herein in FIG. 10 ) and other components specifically tailored to perform the above-described functions related to the automated processing of communication sessions between members and representatives in real time and determining whether sensitive information is required based on this automated processing of these communication sessions.
[0071]
[0080] The communications processing system 308, in one embodiment, automatically monitors the communications session between the member and the surrogate 104 to identify any anchors or other keywords that may correspond to actions associated with a current task or project for which confidential information may be required. Returning to the previous illustrative example, if the member indicates through the communications session that they need assistance with meal planning for their meals and the assigned surrogate subsequently indicates that groceries may need to be purchased through an online grocery store where the member's account information is required to complete the purchase, the communications processing system 308 may identify the need to purchase one or more items and any anchors or other keywords associated with the online grocery store to determine that confidential information may be required to facilitate the purchase of these groceries through the online grocery store.
[0072]
[0081] If the communication processing system 308 detects one or more anchors or other key terms indicating a need for confidential information, the communication processing system 308 may automatically send a request to the information security system 302 requesting a link 120 to a corresponding form that may be used to submit the confidential information, as shown in FIG. 3D . In response to obtaining the link 120 from the information security system 302, the communication processing system 308 may automatically update the communication session 116 between the member and the representative 104 to present the link 120 to the member.
[0073]
[0082] If the member selects the link 120 presented through the communication session 116, the information security system 302 associated with the data privacy repository 108 may dynamically update the interface 204 to present the confidential information form window 210 in which the information security system 302 may provide the member with a confidential information input form 212. For example, as shown in FIG. 3B , the member selects the previously provided link 120 through the interface 204. In response to selecting the link 120, the task facilitation service 102 may redirect the member to the information security system 302, which may update the interface 204 to present the confidential information form window 210 and the confidential information input form 212.
[0074]
[0083] As described above, the confidential information entry form 212 may include a name field 214, through which a member may provide a name that may be associated with the provided confidential information. In addition to the name field 214, the confidential information entry form 212 may include a notes field 216 that may be used by a member to enter confidential information to be stored in the confidential information data store 202. As described above, the data privacy repository 108 may provide different forms for different categories or types of confidential information that may be added to the data privacy repository 108. Thus, the notes field 216 may differ for different confidential information categories or types and may include one or more input fields accordingly. For example, the notes field 216 may include a single input field in which a member may enter both their username and password for a particular account. Alternatively, in some cases, the notes field 216 may include multiple input fields that may be defined according to the portion of the confidential information that may be provided. Thus, each form may be customized according to the corresponding confidential information category or type.
[0075]
[0084] In one embodiment, when a member provides their confidential information using the provided confidential information input form 212, the surrogate 104 can forward the corresponding task or project to a trusted surrogate 106 that can retrieve and use the confidential information to perform one or more operations associated with the task or project. For example, through a surrogate console, the surrogate 104 may indicate that the task or project is available for forwarding to the trusted surrogate 106. In response, the task facilitation service 102 may forward the task or project to an available trusted surrogate 106 to perform one or more operations associated with the task or project for which the confidential information may be required. For example, the task facilitation service 102 may update the surrogate console associated with the trusted surrogate 106 to indicate that the task or project is now assigned to the trusted surrogate 106. This may cause the trusted surrogate 106 to access the user data store 304 and the task data store 306 to retrieve any relevant information associated with the member and the particular task or project being performed, respectively.
[0076]
[0085] In one embodiment, once a member submits the requested confidential information through the provided confidential information input form 212, the information security system 302 may store the confidential information in the confidential information data store 202. The confidential information data store 202 may store the provided confidential information in association with a member and a particular category or type of confidential information. For example, for a provided username and password, the information security system 302 may associate the username and password with the “username-password” category and a particular member in the confidential information data store 202. Additionally, the information security system 302 may automatically generate a certificate or set of cryptographic tokens for the confidential information that can be used to access the confidential information from the confidential information data store 202. The certificate or set of cryptographic tokens may be provided to the task facilitation service 102, which may store the certificate or set of cryptographic tokens in the user data store 304 associated with the member.
[0077]
[0086] The task facilitation service 102 may restrict access to this set of credentials or cryptographic tokens to a trusted representative only when the corresponding sensitive information is needed for a particular task or project. For example, when the representative 104 transfers a task or project to the trusted representative 106, the representative 104 may indicate which sensitive information may be needed for the task or project. For example, if the representative 104 requests a form in which members must submit their account credentials for a particular brand, the representative 104 may indicate that these account credentials are needed for the task or project. Based on this indication from the representative 106 during the transfer of the task or project to the trusted representative 104, the task facilitation service 102 may provide the set of credentials or cryptographic tokens associated with this sensitive information to the trusted representative 106 through the user data store 304. This may enable the trusted representative 106 to retrieve the set of credentials or cryptographic tokens from the user data store 304.
[0078]
[0087] As described above, in one embodiment, access to sensitive information through the use of a certificate or set of cryptographic tokens may be subject to a timeout period, whereby, after the timeout period, the certificate or set of cryptographic tokens may automatically expire and become unusable to access the sensitive information. For example, when a task or project is transferred to the trusted representative 106, the task facilitation service 102 may provide the trusted representative 106 with an indication of the amount of time for which the sensitive information may be made available to the trusted representative 106 through the data privacy repository 108. After this amount of time has elapsed, the certificate or set of cryptographic tokens usable to access the sensitive information may be automatically revoked, thereby preventing the trusted representative 106 from accessing the sensitive information unless the trusted representative 106 submits a request to the task facilitation service 102 to be granted renewed access to the sensitive information. Furthermore, because the certificate or set of cryptographic tokens associated with the sensitive information is automatically revoked after the timeout period, access to the sensitive information may be time-limited, thereby reducing the likelihood that the sensitive information will be accessed when it is not needed to perform the task or project.
[0079]
[0088] As shown in FIG. 3C , the trusted representative 106 may use the provided set of credentials or cryptographic tokens to access the information security system 302 to obtain the required sensitive information. The information security system 302 may evaluate the provided set of credentials or cryptographic tokens to ensure that the set is valid. If the set of credentials or cryptographic tokens is not valid (e.g., expired, the trusted representative 106 is not authorized to use the set of credentials or cryptographic tokens, etc.), the information security system 302 may reject the request to obtain the sensitive information. However, if the information security system 302 successfully validates the provided set of credentials or cryptographic tokens, the information security system 302 may retrieve the corresponding sensitive information from the sensitive information data store 202 and provide this sensitive information to the trusted representative 106. Using this sensitive information, the trusted representative 106 may perform any operation requiring the sensitive information. For example, if a member's account credentials associated with a particular brand are required to complete the checkout process, the trusted representative 106 may use those account credentials (retrieved from the data privacy repository 108) to complete the checkout process on the member's behalf. As another illustrative example, if a member's health insurance information is required to schedule an appointment with a licensed physician on the member's behalf, the trusted representative 106 may retrieve the member's health insurance information from the data privacy repository 108 to complete the scheduling of this appointment for the member.
[0080]
[0089] In one embodiment, when a task or project is transferred from a surrogate 104 to a trusted surrogate 106, the task facilitation service 102 transfers a communication session 116 to the trusted surrogate 106 so that the trusted surrogate 106 can communicate directly with the member regarding the task or project. For example, as shown in FIG. 3C , the trusted surrogate 106 may begin with message 308 indicating that it has received the member's account information and used this account information to complete the checkout process. Through the communication session 116, the trusted surrogate 106 may further provide the member with information regarding the status of the particular task or project, any requests for assignment or clarification related to the task or project, any requests to provide a one-time code for a multi-factor authentication request from a brand or other third-party service, and the like. For example, as shown in FIG. 3C , the trusted surrogate 106 may indicate that for a particular task involving the purchase of one or more items, the one or more items will be delivered in two or three days.
[0081]
[0090] In some instances, when the trusted representative 106 completes performance of one or more operations requiring the provided confidential information, the trusted representative 106 may transfer the task or project to the representative 104. Any confidential information used by the trusted representative 106 may be obscured from the representative console utilized by the representative 104 to prevent exposure of the confidential information to the representative 104. The representative 104 may perform any remaining operations associated with the task or project on behalf of the member without access to the confidential information previously used by the trusted representative 106. Additionally, a set of credentials or cryptographic tokens previously used to access the confidential information may be automatically revoked so that the trusted representative 106 no longer has access to the confidential information upon which a particular operation was performed.
[0082]
[0091] 4 shows an illustrative example of an environment 400 in which a trusted surrogate 106 is assigned a task in which confidential information is required for the performance of the task, according to at least one embodiment. As described above, the surrogate 104 may forward the task or project to the trusted surrogate 106 for the performance of one or more operations that require the use of confidential information (e.g., confidential operations) associated with a member. When the surrogate 104 forwards the task or project to the trusted surrogate 106, the surrogate 104 may indicate which confidential information may be required to perform one or more confidential operations for the completion of the task or project. For example, if the surrogate 104 determines that a member's account credentials associated with a particular grocery store are required to complete the checkout process for a particular task or project, the surrogate 104 may indicate that these account credentials may be required to complete the particular task or project.
[0083]
[0092] In one embodiment, if the surrogate 104 requests a form in which members must submit their confidential information for the performance of one or more confidential actions associated with a task or project, the surrogate 104 may indicate that this confidential information is required for the task or project. As described above, based on this indication from the surrogate 106 during the transfer of the task or project to the trusted surrogate 104, the task facilitation service may provide the trusted surrogate 106 with a set of credentials or cryptographic tokens associated with this confidential information through a user data store. This may enable the trusted surrogate 106 to retrieve the set of credentials or cryptographic tokens from the user data store. In some instances, the set of credentials or cryptographic tokens may be automatically provided to the trusted surrogate 106 when the task or project is transferred to the trusted surrogate 106.
[0084]
[0093] In environment 400, trusted surrogates 106 may review particular tasks or projects forwarded to them through a surrogate console 402 provided by a task facilitation service. As shown in FIG. 4 , the task facilitation service may provide an account window 404 through the surrogate console 402, through which the trusted surrogate 106 may review account information associated with a member. For example, the account window 404 may include the account name (e.g., a unique indicator associated with the account defined by the member, surrogate 104, or by the task facilitation service based on characteristics of the account), a phone number associated with the account, a billing or other address associated with the account, a website associated with the account, the name of the account owner (e.g., the member or other entity acting as the account owner), etc. This information may be used to uniquely identify the account of the surrogate 104 and the trusted surrogate 106.
[0085]
[0094] The surrogate console 402 may further include a current task window 406 that may be implemented to present various parameters associated with a current task or project that has been forwarded by the surrogate 104 to the trusted surrogate 106. For example, as shown in FIG. 4 , the current task window 406 may include a task name field 408, through which the name or title of the task or project may be presented. Additionally, the task facilitation service may provide, through the current task window 406, a task description field 410 that may include a brief description of the task or project being performed on behalf of the member. For example, as shown in FIG. 4 , the task description field 410 may be used to indicate that the surrogate is purchasing groceries on behalf of the member through an online grocery service and providing an invoice and estimated time for delivery for these groceries.
[0086]
[0095] The task facilitation service may further provide, through the current task window 406, a task deadline field 412 in which a deadline for completing a task or project is provided. The current task window 406 may further include a priority field 414 in which a priority may be assigned to a particular task or project. The priority of a particular task or project may be defined by the surrogate 104 based on the surrogate's knowledge of the member and of the task or project being performed. For example, if the surrogate 104 determines, based on the surrogate's knowledge of the member and of the task or project, that the member considers a particular project or task to be of utmost importance, the surrogate 104 may assign the project or task a high priority. Conversely, if the surrogate 104 determines that the project or task is not urgent and can be performed at any time without any negative impact to the member, the surrogate 104 may assign a lower priority to the project or task.
[0087]
[0096] The current tasks window 406 may further include a budget field 416 in which a budget for the completion of a task or project may be defined. For example, the delegate 104 may define a budget for the completion of a task or project via the budget field 416 based on the delegate's knowledge of the member and of the particular task or project. In some examples, if the delegate 104 knows that the member does not adhere to a budget for the implementation of projects and tasks, the delegate 104 may omit providing a budget via the budget field 416. Thus, defining a budget via the budget field 416 may be optional, as shown in FIG. 4 .
[0088]
[0097] In one embodiment, the current task window 406 further includes a confidential information identifier field 418. As described above, when a task or project is forwarded to a trusted representative 106 authorized to access confidential information for performance of one or more confidential operations associated with the task or project, the trusted representative 106 may be provided with an indication of the categories or types of confidential information submitted by the member through a form provided by the data privacy repository 108 in response to selection of a link provided to the member. Thus, through the confidential information identifier field 418, the trusted representative 106 may be provided with an indication corresponding to the categories or types of confidential information that may be available to the trusted representative 106 for performance of those confidential operations. In some instances, the confidential information identifier field 418 may include a name provided for the confidential information (such as through the name field 214 described above with respect to FIG. 2C ).
[0089]
[0098] In one embodiment, the task facilitation service further provides, through the current task window 406, a confidential information access button 420 that can be used by the trusted representative 106 to obtain needed confidential information from the data privacy repository 108 for the performance of one or more confidential operations. As described above, access to confidential information may be provided on a "need-to-know" basis, whereby the trusted representative 106 is granted access only to the confidential information needed to perform the confidential operations associated with a task or project transferred to the trusted representative 106. Thus, the confidential information access button 420 may be presented to the trusted representative 106 only while a task or project requiring this confidential information is assigned to the trusted representative 106.
[0090]
[0099] When the trusted representative 106 selects the access sensitive information button 420, the task facilitation service may automatically provide a unique set of credentials or cryptographic tokens that can be used by the trusted representative 106 to retrieve needed sensitive information from the data privacy vault 108 for the assigned task or project. For example, when the trusted representative 106 selects the access sensitive information button 420, the task facilitation service may send a request to the data privacy vault 108 on behalf of the trusted representative 106 to retrieve the needed sensitive information. This request may include a unique set of credentials or cryptographic tokens that correspond to the sensitive information. In response to this request, the data privacy vault 108 may process this set of credentials or cryptographic tokens to determine what sensitive information is available to the trusted representative 106.
[0091]
[0100] In one embodiment, if the trusted representative 106 selects the sensitive information access button 420, the task facilitation service can redirect the trusted representative 106 to the data privacy vault 108 for authentication of the trusted representative 106 and identification of sensitive information that may be available to the trusted representative 106, while providing the data privacy vault 108 with a set of credentials or cryptographic tokens associated with the required sensitive information. Through the data privacy vault 108, the trusted representative 106 can select the particular type or category of sensitive information being retrieved. For example, if the trusted representative 106 needs a member's account credentials for a particular brand, the trusted representative 106 may select a type or category that corresponds to the brand-specific account credentials.
[0092]
[0101] In some instances, if the trusted representative 106 selects the sensitive information access button 420, the task facilitation service may provide a unique set of credentials or cryptographic tokens to the trusted representative 106. In this instance, if the trusted representative 106 selects a particular type or category, the data privacy repository 108 may prompt the trusted representative 106 to provide their set of credentials or cryptographic tokens to access sensitive information from the data privacy repository 108. The data privacy repository 108 may evaluate the set of credentials to determine whether the set of credentials is valid and, if so, whether the trusted representative 106 is authorized to access sensitive information corresponding to the selected type or category. If the trusted representative 106 attempts to access a type or category that is different from the type or category associated with sensitive information to which the trusted representative 106 is authorized to access, the data privacy repository 108 may automatically deny the request to access the selected type or category.
[0093]
[0102] As described above, the data privacy repository 108 may present available sensitive information to the trusted representative 106 if the trusted representative 106 has selected a particular type or category associated with sensitive information to which the trusted representative 106 is authorized to access. For example, the data privacy repository 108 may present a completed form submitted by the member for entry of this sensitive information. The completed form may include a clear-text representation of the sensitive information so that the trusted representative 106 may review the sensitive information. However, the sensitive information may not be made available to the representative 104, the member, or any other unauthorized entity. In some instances, the completed form or the sensitive information itself may be presented to the trusted representative 106 through the proxy console 402.
[0094]
[0103] In one embodiment, the confidential information access button 420 may be provided for a limited period of time, whereby the confidential information access button 420 may no longer be used to access confidential information after the limited period of time has elapsed. As described above, when a task or project is transferred to the trusted representative 106 for performance of one or more confidential operations requiring access and use of confidential information, the task facilitation service may provide the trusted representative 106 with an indication of the amount of time the confidential information may be made available to the trusted representative 106 through the data privacy repository 108. Once this amount of time has elapsed, the set of certificates or cryptographic tokens usable to access the confidential information may be automatically revoked. Additionally, the task facilitation service may remove the confidential information access button 420 from the representative console 402 or otherwise make the confidential information access button 420 unavailable (e.g., graphically indicating that the button 420 is unavailable, disabling use of the button 420, etc.).
[0095]
[0104] As described above, once the trusted representative 106 has completed performance of one or more sensitive actions requiring the use of sensitive information, the trusted representative 106 may transfer the task or project to the representative 104. The representative 104 may review the sensitive actions performed by the trusted representative 106 for the particular task or project through its own representative console. However, any sensitive information used by the trusted representative 106 may be obscured or omitted entirely from the representative console utilized by the representative 104 to prevent exposure of the sensitive information to the representative 104. Furthermore, the sensitive information access button 420 may be removed such that the representative console utilized by the representative 104 does not include the sensitive information access button 420. Thus, the representative 104 may perform any remaining actions associated with the task or project on behalf of the member without access to the sensitive information previously used by the trusted representative 106.
[0096]
[0105] 5 illustrates an illustrative example 500 of an environment in which the task facilitation service 102 monitors access to sensitive information associated with a member 110 through an audit system 504 to ensure that the sensitive information is accessed by the trusted surrogate 106 for task performance, according to at least one embodiment. In the environment 500, the surrogate 104 may forward a task or project to the trusted surrogate 106 for performance of one or more sensitive operations that require access to sensitive information provided by the member 110 and stored in the sensitive information data store 202 of the data privacy repository 108. As described above, the surrogate 104 may be prohibited from accessing any sensitive information associated with the member 110. Accordingly, the surrogate 104 may perform any other operations associated with the task or project and forward the task or project to the trusted surrogate 106 for performance of the sensitive operations associated with the task or project.
[0097]
[0106] When a task or project is transferred from the surrogate 104 to the trusted surrogate 106, the trusted surrogate 106 may send a request to the information security system 302 implemented by the data privacy repository 108 to obtain sensitive information that may be used to perform one or more sensitive operations associated with the task or project being performed on behalf of the member 110. As described above, the trusted surrogate 106 may select an option to access sensitive information from the data privacy repository 108 for a particular task or project through a proxy console provided by the task facilitation service 102. Selection of this presented option may cause the task facilitation service 102 to redirect the trusted surrogate 106 to the information security system 302 of the data privacy repository 108. The information security system 302 may provide the trusted surrogate 106 with various types or categories of sensitive information that may be stored in the sensitive information data store 202. From these presented types or categories of sensitive information, the trusted surrogate 106 may select specific types or categories of sensitive information that may be needed to perform one or more sensitive operations.
[0098]
[0107] If the trusted representative 106 selects a particular sensitive information type or category, the information security system 302 may prompt the trusted representative 106 to provide their set of credentials or cryptographic tokens (issued by the task facilitation service 102) for accessing sensitive information from the sensitive information data store 202. The information security system 302 may evaluate the set of credentials to determine whether the set of credentials is valid and, if so, whether the trusted representative 106 is authorized to access sensitive information corresponding to the selected type or category. The set of credentials or cryptographic tokens issued to the trusted representative 106 may be specific to the particular sensitive information associated with the particular type or category. If the trusted representative 106 attempts to access a type or category that is different from the type or category associated with the sensitive information to which the trusted representative 106 is authorized to access, the information security system 302 may automatically deny the request to access the selected type or category.
[0099]
[0108] If the trusted representative 106 selects a particular type or category associated with sensitive information to which the trusted representative 106 is authorized to access, the information security system 302 may retrieve the sensitive information from the sensitive information data store 202. Additionally, the information security system 302 may present available sensitive information to the trusted representative 106. For example, the information security system 302 may present a completed form submitted by the member 110 for storage of the sensitive information through a representative console utilized by the trusted representative 106. The completed form may include a clear-text representation of the sensitive information so that the trusted representative 106 may review the sensitive information. However, the sensitive information may not be made available to the representative 104, the member 110, or any other unauthorized entity.
[0100]
[0109] In one embodiment, the information security system 302 automatically records any attempt to access sensitive information from the data privacy repository 108. For example, when a trusted representative 106 submits a request to the information security system 302 to access specific sensitive information from the sensitive information data store 202, the information security system 302 may automatically generate an entry in an access log to record the request. This entry may indicate any identifying information associated with the entity attempting to access the sensitive information (e.g., a username or identifier corresponding to the trusted representative 106 or representative 104, an Internet Protocol (IP) address or other network address associated with the entity submitting the request, etc.), the category or type associated with the sensitive information being requested, a timestamp corresponding to the time the request was submitted, information corresponding to any credentials or cryptographic tokens provided, and the access decision (e.g., approved, denied, etc.). This access log may be updated in real time as requests are received and processed by the information security system 302.
[0101]
[0110] In one embodiment, the task facilitation service 102 includes an audit system 504 implemented to retrieve and process access logs from the information security system 302 to audit requests made to the information security system 302 to retrieve sensitive information from the sensitive information data store 202. The audit system 504 may be implemented using a computer system associated with the task facilitation service 102 or an application running on a computer system. In some instances, the audit system 504 may retrieve access logs maintained by the information security system 302 in real time as requests to access sensitive information from the sensitive information data store 202 are received and processed by the information security system 302. For example, the audit system 504 may maintain a real-time data feed between the audit system 504 and the information security system 302, whereby access logs maintained by the information security system 302 may be streamed to the audit system 504 in real time.
[0102]
[0111] In one embodiment, the audit system 504 processes the access logs obtained in real time as requests to access sensitive information are processed by the information security system 302 to determine whether any unauthorized attempts have been made to access sensitive information stored in the sensitive information data store 202. For example, the audit system 504 may process the access logs to identify any denied requests to access sensitive information and determine why these requests were denied. For example, if a request to access sensitive information is denied because the entity submitting the request did not have the required set of credentials or cryptographic tokens for entity authentication and authorization, the audit system 504 may determine whether the entity was actually authorized to access the requested sensitive information, and if so, why the entity did not have the required set of credentials or cryptographic tokens to access the sensitive information. As an illustrative example, if the audit system 504 determines that a trusted representative 106 has submitted a request to access sensitive information from the data privacy repository 108 and the request is denied as a result of the trusted representative 106 not having the required set of credentials or cryptographic tokens, the audit system 504 may determine whether the credentials or set of cryptographic tokens were previously provided to the trusted representative 106 and have expired as a result of the trusted representative 106 no longer needing access to the sensitive information. Additionally, the audit system 504 may determine whether an entity other than the trusted representative 106 has hacked an account associated with the trusted representative 106 or otherwise gained unauthorized access (e.g., an IP address associated with the request does not correspond to a known IP address of the trusted representative 106). As another illustrative example, if the audit system 504 determines that a representative 104 has submitted a request to access confidential information from the data privacy repository 108, the audit system 504 may automatically determine that such request should not have been made by the representative 104 because the representative 104 is not authorized to access confidential information associated with members of the task facilitation service 102 at any time.
[0103]
[0112] In addition to evaluating denied requests made to the information security system 302 to access sensitive information, the audit system 504 may evaluate any approved requests to ensure that these requests were made only by authorized entities and for active tasks or projects requiring the use of this sensitive information. For example, the audit system 504 may determine whether the information security system 302 granted a trusted representative 106 access to sensitive information from the sensitive information data store 202 using an expired certificate or set of cryptographic tokens. As another example, the audit system 504 may determine whether the information security system 302 granted access to sensitive information to a representative 104 who was not authorized to access any sensitive information from the data privacy repository 108 (e.g., the representative 104 accessed the sensitive information without the required certificate or set of cryptographic tokens, the representative 104 gained access to the certificate or set of cryptographic tokens associated with the sensitive information, etc.). As yet another illustrative example, the audit system 504 may determine whether an entity authorized to access sensitive information is a trusted representative 106, such as through an evaluation of an IP address or network address associated with the entity.
[0104]
[0113] In one embodiment, based on this real-time evaluation of the access logs maintained by the information security system 302, the audit system 504 may determine whether one or more corrective actions are needed to address any unauthorized access or attempts to access sensitive information from the data privacy vault 108. For example, if the trusted representative 106 attempts to access sensitive information that is not related to the particular task or project currently assigned to the trusted representative 106, the audit system 504 may suspend the trusted representative 106, thereby preventing the trusted representative 106 from accessing the data privacy vault 108 to access the sensitive information. Additionally or alternatively, the audit system 504 may require the trusted representative 106 to undergo corrective training to ensure that the trusted representative 106 is notified of the appropriate time to access sensitive information for the performance of sensitive operations associated with the task and / or project. As another illustrative example, if a representative 104 gains or attempts to gain access to confidential information associated with a member 110, the audit system 504 may suspend the representative 104 such that the representative 104 cannot be assigned to the member 110 or any other member for a period of time. Any member assigned to the representative 104 may be assigned a replacement representative, either permanently or for a period of time corresponding to the suspension of the representative 104.
[0105]
[0114] In one embodiment, the surrogate 104 or trusted surrogate 106 can coordinate with one or more third-party services 114 for the performance of a task or project through a task coordination system 502 implemented by the task facilitation service 102. The task coordination system 502 can be implemented using a computer system or as an application or other executable code implemented on the computer system of the task facilitation service 102. The task coordination system 502 can be used to identify one or more third-party services 114 and / or resources (e.g., retailers, restaurants, websites, brands, types of products, specific products, etc.) that can be used for the performance of the task or project for the benefit of the member 110. The task coordination system 502 can be used by the surrogate 104 and / or trusted surrogate 106 to further contact one or more third-party services 114 for the performance of the task or project.
[0106]
[0115] The task coordination system 502 may monitor the performance of tasks or projects by these third-party services 114. For example, the task coordination system 502 may record any information provided by the third-party services 114 regarding the timeframe for performance of the task or project, the costs associated with performance of the task or project, any status updates regarding the performance of the task or project, etc. The status updates provided by the third-party services 114 may be automatically provided to the members 110 via an interface provided by the task facilitation service 102 (e.g., interface 204 described above with respect to FIGS. 2A-2C ). Additionally or alternatively, these status updates may be automatically provided to the surrogates 104 and / or trusted surrogates 106 via a surrogate console.
[0107]
[0116] In one embodiment, if one or more sensitive operations are to be performed for a task or project, the trusted representative 106 can communicate with the third-party service 114 to coordinate the performance of those one or more sensitive operations without exposing sensitive information to the task coordination system 502 or the representative 104. For example, if the trusted representative 106 is tasked with completing a checkout process on behalf of the member 110 using the member's account credentials associated with an online retailer (e.g., the third-party service 114), the trusted representative 106 may directly contact the third-party service 114 to provide those account credentials to the online retailer for authentication and to complete the checkout process. Once the account credentials are authenticated, the task coordination system 502 may monitor interactions between the trusted representative 106, the online retailer (e.g., the third-party service 114), and the member 110 to ensure that the task or project is completed according to the defined parameters for the task or project.
[0108]
[0117] 6 shows an illustrative example of a process 600 for performing one or more actions associated with a task and forwarding the task to a trusted delegate when confidential information is required for completion of the task, according to at least one embodiment. Process 600 may be performed by a delegate assigned to a member for performance of one or more tasks or projects on the member's behalf. As mentioned above, the delegate may not be authorized to access confidential information associated with the member to mitigate the risk of such confidential information being exposed (inadvertently or intentionally) to unauthorized entities, including any entities not associated with the task facilitation service.
[0109]
[0118] In step 602, a delegate may receive a request to perform a task or project on behalf of a member. A delegate may be assigned to a member through an onboarding process, as described above. For example, the task facilitation service may use the member's identification information, any information regarding the member's comfort level or interest in delegating tasks to others, and any other information obtained during the onboarding process to identify a delegate who may be suitable to interact and communicate with the member in a productive manner. The request to perform a task or project on behalf of the member may be provided via a communication session facilitated by the task facilitation service between the member and the delegate. As an illustrative example, through this communication session, the member may indicate that they would like the delegate's assistance with their weekly meal plan, including purchasing groceries that can be delivered to the member for their meal plan.
[0110]
[0119] In some instances, the representative may create a new project or task on behalf of the member based on its communication with the member via the above-described communication session. For example, the representative may submit a request to the task facilitation service to create a new project or task. In response to the request, the task facilitation service may identify one or more templates that can be used by the representative to define the new project or task. The one or more task templates may correspond to a task type or category for the project and / or task being defined. Returning to the example described above, if the member specified via the communication session that they need assistance purchasing a set of items from a particular online retailer for delivery to the member's home, the representative may select a template that corresponds to online purchasing. Through this template, the representative may define one or more actions that can be performed to complete the project or task.
[0111]
[0120] In step 604, the representative may determine what information may be required to perform the task. For example, in step 606, the representative may evaluate one or more actions associated with a particular task or project to determine whether confidential information associated with the member is required to complete the task. Returning to the previous illustrative example related to a member's weekly meal plan, the representative may determine that the member may be required to provide their account credentials associated with an online retailer in order for items on the shopping list to be purchased from the online retailer. In some instances, the representative may determine that the member may be required to provide payment information, such as a payment card number, a CVV associated with the payment card, an expiration date associated with the payment card, etc. As another illustrative example, if the representative defines a task related to scheduling a medical procedure, the representative may determine that the member may be required to provide their medical insurance information in order for the medical procedure to be scheduled. As discussed above, such information may be considered confidential in nature, whereby the inadvertent or purposeful distribution and exposure of such information to unauthorized entities may result in harm to the member. Accordingly, the task facilitation service may prohibit the representative from accessing such confidential information.
[0112]
[0121] If the representative determines that confidential information is not required to perform the task or project, the representative may perform the task or project on behalf of the member in step 608. When confidential information is not required for a task or project, the member may perform the task or project without having to transfer the task or project to a trusted representative.
[0113]
[0122] If the representative determines that confidential information is needed to complete a particular task or project, the representative may send the member a link to a data privacy vault form for entry of the required confidential information in step 610. As described above, the data privacy vault may provide various access controls to facilitate access to confidential information only to users authorized to access such confidential information. These access controls may be defined by a task facilitation service, which may provide or generate sets of credentials for different users who may be authorized by the task facilitation service to access confidential information stored in the data privacy vault. To generate the link, the representative may access the data privacy vault and select a particular type or category of confidential information needed from the member. When the representative selects a particular category, the data privacy vault may present the representative with a form associated with the particular category, through which the representative may provide a description or name of the confidential information to be provided. Once the representative defines the name or description of the confidential information to be provided by the member, the data privacy vault may provide the member with a link to the corresponding form for entry of the confidential information. The representative may then provide the link to the member through a communication session between the member and the representative.
[0114]
[0123] In step 612, the surrogate may perform any operations associated with the task or project that do not require the use of the requested confidential information. Returning to the example task related to developing a weekly meal plan, including purchasing groceries that can be delivered to the member for the meal plan, the surrogate may develop one or more recipes that can be incorporated into the meal plan, prepare a grocery list of any meal items required for these recipes, and access an online retailer on the member's behalf to add these meal items to a virtual cart. At this point, completion of the task or project may require the use of confidential information (e.g., username and password, payment information, etc.) to complete the checkout process with the online retailer. Thus, the surrogate may determine that they cannot perform any further operations associated with the task or project until these confidential operations have been performed by a trusted surrogate. Thus, in step 614, the surrogate may transfer the task or project to a trusted surrogate for performance of any confidential operations that require access and use of confidential information associated with the member.
[0115]
[0124] In some instances, the delegate may wait for an indication from the data privacy repository that the member has provided the requested confidential information before transferring the task or project to the trusted delegate. For example, when a member executes a provided link to access a confidential information form from the data privacy repository, the data privacy repository may monitor the member's interaction with the form to determine whether the member has submitted the requested confidential information. For example, the data privacy repository may determine whether the member has submitted a request to submit the completed form for storage of the confidential information in the data privacy repository. Once the confidential information is successfully stored in the data privacy repository, the data privacy repository may send a notification to the delegate indicating that the confidential information has been submitted. In response to this notification, and upon completion of any other operations associated with the task or project that do not require access to the confidential information, the delegate may transfer the task or project to the trusted delegate.
[0116]
[0125] 7 shows an illustrative example of a process 700 for accessing confidential information associated with a member for performance of a task, according to at least one embodiment. Process 700 may be performed by a trusted representative who is authorized to access particular confidential information associated with a member in order to perform one or more confidential operations corresponding to a task or project being performed on behalf of the member. Further, process 700 may be performed when the representative transfers a task or project to the trusted representative for performance of these one or more confidential operations.
[0117]
[0126] In step 702, the trusted representative may receive a task or project to be performed on behalf of the member from the representative originally assigned to the member. As described above, the representative originally assigned to the member may forward the communication session facilitated between the member and the representative to the trusted representative. Through this communication session, the trusted representative may be able to review all communications previously exchanged between the member and the representative for the particular task or project, including requests provided to the member to provide its confidential information. In some instances, through the representative console, the trusted representative may review which actions have been performed on behalf of the member for the particular task or project.
[0118]
[0127] In step 704, the trusted representative may identify sensitive information that may be required to perform one or more sensitive operations associated with the task or project. For example, through a representative console provided to the trusted representative by the task facilitation service, the trusted representative may identify the category or type of sensitive information submitted by the member through use of a provided link or other access through the data privacy repository. The trusted representative may, for example, evaluate a previously provided link to determine which category or type of sensitive information the representative requested for use in completing the task or project. With reference to FIG. 3A , the link provided to the member through the communication session may include a descriptor (e.g., “account certificate”) corresponding to the category or type of sensitive information being requested. In some instances, the task facilitation service may indicate, through a representative console utilized by the trusted representative, the category or type of sensitive information stored in the data privacy repository for a particular task or project.
[0119]
[0128] In step 706, the delegate may access the data privacy vault to retrieve sensitive information needed for performance of one or more sensitive operations associated with the task or project. For example, the trusted delegate may select, through the delegate console, an option to access sensitive information from the data privacy vault for a particular task or project. Selection of this presented option may cause the task facilitation service to redirect the trusted delegate to the data privacy vault. The data privacy vault may provide the trusted delegate with various types or categories of sensitive information that may be stored in the sensitive information data store. From these presented types or categories of sensitive information, the trusted delegate may select specific types or categories of sensitive information that may be needed to perform one or more sensitive operations.
[0120]
[0129] As described above, in response to selection of a trusted representative of a particular type or category of sensitive information, the data privacy repository may prompt the trusted representative to provide its set of certificates or cryptographic tokens (issued by the task facilitation service) for accessing sensitive information from the sensitive information data store. The data privacy repository may evaluate the set of certificates or cryptographic tokens to determine whether the set of certificates is valid and, if so, whether the trusted representative is authorized to access sensitive information corresponding to the selected type or category. The set of certificates or cryptographic tokens issued to the trusted representative may be specific to the particular sensitive information associated with the particular type or category. In some cases, the set of certificates or cryptographic tokens may be subject to an expiration date, whereby the set of certificates or cryptographic tokens may be automatically revoked if the expiration date has passed. Thus, the trusted representative may be authorized to access this sensitive information, but if the set of certificates or cryptographic tokens is expired or otherwise unavailable to the trusted representative, the request to access the sensitive information may be automatically denied by the data privacy repository.
[0121]
[0130] Based on its interaction with the data privacy repository, the trusted representative may determine, in step 708, whether the required sensitive information is available to the trusted representative for use in performing one or more sensitive operations. For example, if a set of certificates or cryptographic tokens needed to access the sensitive information is unavailable to the trusted representative, the trusted representative may determine that the required sensitive information is not available to the trusted representative. As another illustrative example, if the trusted representative determines that the data privacy repository does not have a record of the requested sensitive information for the member, the trusted representative may determine that it cannot retrieve the required sensitive information from the data privacy repository. Thus, in step 710, the trusted representative may send the member (e.g., through a communication session between the member and the trusted representative) a link to a data privacy repository form where the member may provide the required sensitive information. The creation and presentation of this link may be similar to step 610 described above with respect to FIG. 6.
[0122]
[0131] If the trusted representative is able to retrieve the required confidential information from the data privacy repository, the trusted representative may use the confidential information to complete the task or project (e.g., any confidential operations associated with the task or project) on behalf of the member in step 712. For example, the trusted representative may coordinate with one or more third-party services for the performance of the task or project through a task coordination system implemented by the task facilitation service. In one embodiment, the trusted representative may communicate with the third-party services to coordinate the performance of one or more confidential operations associated with the task or project without exposing the confidential information to the task coordination system or the representative. For example, if the trusted representative is tasked with completing a checkout process on behalf of the member using the member's account credentials associated with an online retailer, the trusted representative may contact the online retailer directly to provide these account credentials to the online retailer for authentication and for completion of the checkout process. Once the account credentials are authenticated, the task coordination system may monitor interactions between the trusted representative, the online retailer, and the member to ensure that the task or project is completed according to the defined parameters for the task or project.
[0123]
[0132] Upon completion of the sensitive operation associated with the task or project, the trusted representative may communicate the completion of the task or project (or sensitive operation) to the member in step 714. For example, through the communication session between the member and the trusted representative, the trusted representative may indicate that it has received the member's sensitive information and used this sensitive information to complete the sensitive operation or task / project. Through the communication session, the trusted representative may further provide the member with information regarding the status of the particular task or project, any requests for assignment or clarification related to the task or project, any requests to provide a one-time code for a multi-factor authentication request from a brand or other third-party service, etc.
[0124]
[0133] As described above, when the trusted representative completes performance of one or more sensitive operations requiring the provided sensitive information, the trusted representative may transfer the task or project to the representative. Any sensitive information used by the trusted representative may be obscured from the representative console utilized by the representative to prevent exposure of the sensitive information to the representative. The representative may perform any remaining operations (if any) associated with the task or project on behalf of the member without access to the sensitive information previously used by the trusted representative. Furthermore, a set of credentials or cryptographic tokens previously used to access the sensitive information may be automatically revoked so that the trusted representative no longer has access to the sensitive information on which a particular operation was performed.
[0125]
[0134] 8 shows an illustrative example of a process 800 for controlling access to confidential information associated with a member, according to at least one embodiment. Process 800 may be performed by an information security system associated with a data privacy repository. The information security system may be implemented to manage access to confidential information stored in a confidential information data store of the data privacy repository.
[0126]
[0135] In step 802, the information security system may receive a request to access confidential information associated with a particular member of the task facilitation service. As described above, when a trusted representative receives a task or project that requires the use of confidential information for completion, the trusted representative may send a request to the information security system to obtain confidential information that can be used to perform one or more confidential operations associated with the task or project being performed on behalf of the member. For example, the trusted representative may select, through a provided representative console, an option to access confidential information from a data privacy repository for the particular task or project. Selection of this presented option may result in the trusted representative being redirected to the information security system. The information security system may provide the trusted representative with various types or categories of confidential information that may be stored in a confidential information data store. From these presented types or categories of confidential information, the trusted representative may select the specific type or category of confidential information needed to request access to the needed confidential information.
[0127]
[0136] In step 804, the information security system may determine whether the request to access the sensitive information was submitted from a secure environment. For example, access to the data privacy repository by the trusted representative may be facilitated only through a secure computing environment (e.g., a computing environment with controlled storage and network access, a cryptographically secure environment, an isolated network environment, etc.). The information security system may evaluate the network connection between the trusted representative and the data privacy repository to ensure that the network connection is secure (e.g., the network connection is encrypted, the network connection was established using one or more cryptographic or other authenticated methods, etc.). If the information security system determines that the request for sensitive information associated with the member was not submitted through a secure or trusted environment, the information security system may automatically deny access to the requested sensitive information in step 806. For example, the information security system may send a notification to the trusted representative indicating that the trusted representative's request has been denied. Additionally or alternatively, the information security system may terminate the network connection between the trusted representative and the data privacy repository.
[0128]
[0137] If the information security system determines that the request for sensitive information was submitted through a secure network environment, the information security system may determine whether access to the requested sensitive information is authorized in step 808. For example, in response to selecting a particular category or type of sensitive information, the information security system may prompt the trusted representative to provide its set of credentials or cryptographic tokens (issued by the task facilitation service) to access the sensitive information from the data privacy repository. The information security system may evaluate the set of credentials to determine whether the set of credentials is valid and, if so, whether the trusted representative is authorized to access sensitive information corresponding to the selected type or category. As described above, the set of credentials or cryptographic tokens issued to the trusted representative may be specific to the particular sensitive information associated with the particular type or category. Thus, if the trusted representative attempts to access a type or category different from the type or category associated with the sensitive information to which the trusted representative is authorized to access and / or the set of credentials or cryptographic tokens provided is invalid, the information security system may automatically deny the request to access the selected type or category in step 806.
[0129]
[0138] In one embodiment, if the information security system determines that the trusted representative is authorized to access the requested confidential information, the information security system may provide the trusted representative with access to the confidential information in step 810. For example, the information security system may retrieve the confidential information from a data privacy repository and present the available confidential information to the trusted representative. For example, the information security system may present a completed form submitted by the member for storage of the confidential information through a representative console utilized by the trusted representative. The completed form may include a clear-text representation of the confidential information so that the trusted representative may review it. In some cases, if access to the confidential information is provided for a limited period of time, the information security system may provide access to the confidential information only for this limited period of time, after which access to the confidential information may be automatically revoked.
[0130]
[0139] In step 812, the information security system may record a log entry corresponding to the submitted request to access the sensitive information, regardless of whether access to the sensitive information is granted or denied. For example, the information security system may automatically record any attempt to access sensitive information from a data privacy repository. For example, the information security system may automatically generate an entry in an access log indicating any identifying information associated with the entity attempting to access the sensitive information (e.g., a username or identifier corresponding to a trusted or other representative, an IP address or other network address associated with the entity submitting the request, etc.), the category or type associated with the sensitive information being requested, a timestamp corresponding to the time the request was submitted, information corresponding to any certificate or cryptographic token provided, and the access decision (e.g., approved, denied, etc.). This access log may be updated in real time as requests are received and processed by the information security system. Additionally, the access log may be used by the task facilitation service to automatically audit any requests made to the information security system to retrieve sensitive information associated with members of the task facilitation service.
[0131]
[0140] 9 shows an illustrative example of a process 900 for auditing historical access to sensitive information associated with members of a task facilitation service to identify any access violations and implement any required corrective actions, according to at least one embodiment. Process 900 may be performed by an audit system implemented by the task facilitation service. As described above, the audit system may be implemented to automatically process access logs maintained by a data privacy repository to identify any unauthorized attempts to access sensitive information associated with members of the task facilitation service and implement any required corrective actions to address such unauthorized attempts.
[0132]
[0141] In step 902, the audit system may retrieve access logs and historical data corresponding to tasks and projects performed by various agents and trusted agents. The audit system, in one embodiment, retrieves the access logs and historical data in real time as requests to access sensitive information from the data privacy repository are received and processed by the information security system. As described above, the audit system may maintain a real-time data feed between the audit system and the information security system, whereby access logs and historical data maintained by the information security system can be streamed to the audit system in real time.
[0133]
[0142] In step 904, the audit system may evaluate the access logs and historical data to determine the validity of requests to access sensitive information from the data privacy repository. For example, the audit system may process the access logs to identify any denied requests to access sensitive information and determine why these requests were denied. For example, if a request to access sensitive information was denied because the entity submitting the request did not have the required set of credentials or cryptographic tokens for entity authentication and authorization, the audit system may determine whether the entity was actually authorized to access the requested sensitive information, and if so, why the entity did not have the required set of credentials or cryptographic tokens to access the sensitive information. In addition to evaluating denied requests made to the information security system to access sensitive information, the audit system may evaluate any approved requests to ensure that these requests were made only by authorized entities and for active tasks or projects requiring the use of this sensitive information.
[0134]
[0143] Based on this evaluation of approved and denied requests to access sensitive information, the audit system may determine, in step 906, whether there are any access violations that require the implementation of one or more corrective actions to be addressed. For example, if the audit system determines that a trusted representative submitted a request to access sensitive information from a data privacy repository and the request was denied as a result of the trusted representative not having the required set of credentials or cryptographic tokens, the audit system may determine whether the credentials or set of cryptographic tokens were previously provided to the trusted representative and have expired as a result of the trusted representative no longer needing access to the sensitive information. Furthermore, the audit system may determine whether an entity other than the trusted representative hacked into or otherwise gained unauthorized access to an account associated with the trusted representative. As another illustrative example, if the audit system determines that a representative submitted a request to access sensitive information from a data privacy repository, the audit system may automatically determine that such request should not have been made by the representative. The audit system may further determine, for example, whether the information security system granted the trusted representative access to the sensitive information using an expired set of credentials or cryptographic tokens. As another example, the audit system may determine whether the information security system granted access to sensitive information to an agent who is not authorized to access any sensitive information from the data privacy repository. As yet another illustrative example, the audit system may determine whether an entity granted access to sensitive information is a trusted agent, such as through an evaluation of an IP address or network address associated with the entity.
[0135]
[0144] If the audit system determines that no access violations have occurred, the audit system may continue to obtain access logs and historical data from the information security system for the data privacy repository to audit requests made to the information security system for sensitive data in real time, and thus restart process 900. However, if the audit system determines that one or more access violations have occurred, the audit system may implement one or more corrective actions to address these access violations in step 908. For example, if a trusted representative attempts to access sensitive information that is not related to the specific task or project currently assigned to the trusted representative, the audit system may suspend the trusted representative to prohibit the trusted representative from being able to access the data privacy repository to access the sensitive information. Additionally or alternatively, the audit system may require the trusted representative to undergo corrective training to ensure that the trusted representative is notified of the appropriate time for accessing sensitive information for the performance of sensitive operations associated with a task and / or project. As another illustrative example, if a representative gains or attempts to gain access to confidential information associated with a member, the audit system may suspend the representative so that the representative cannot be assigned to the member or any other member for a period of time. Any member assigned to the representative may be assigned an alternative representative, either permanently or for a period of time corresponding to the suspension of the representative. Once these corrective actions are implemented, the audit system may continue to retrieve access logs and historical data from the data privacy repository's information security system to audit requests made to the information security system for confidential data in real time, and thus restart process 900.
[0136]
[0145] 10 illustrates a computing system architecture 1000 including various components in electrical communication with each other, according to various embodiments. The exemplary computing system architecture 1000 illustrated in FIG. 10 includes a computing device 1002 having various components in electrical communication with each other using a connection 1006, such as a bus, according to some implementations. The exemplary computing system architecture 1000 includes a processing unit 1004 in electrical communication with various system components, including a system memory 1014, using the connection 1006. In some embodiments, the system memory 1014 includes read-only memory (ROM), random access memory (RAM), and other such memory technologies, including, but not limited to, those described herein. In some embodiments, the exemplary computing system architecture 1000 includes a cache 1008 of high-speed memory directly connected to the processor 1004, in close proximity to the processor 1004, or integrated as part of the processor 1004. The system architecture 1000 can copy data from the memory 1014 and / or the storage device 1010 to the cache 1008 for quick access by the processor 1004. In this manner, the cache 1008 can provide a performance boost that reduces or eliminates processor delays in the processor 1004 due to waiting for data. Using modules, methods, and services such as those described herein, the processor 1004 can be configured to perform various actions. In some embodiments, the cache 1008 can include multiple types of cache, including, for example, a level 1 (L1) and a level 2 (L2) cache. The memory 1014 is sometimes referred to herein as system memory or computer system memory. The memory 1014 can, at various times, include elements of an operating system, one or more applications, data associated with the operating system or one or more applications, or other such data associated with the computing device 1002.
[0137]
[0146] Other system memory 1014 may also be available for use. Memory 1014 may include multiple different types of memory with different performance characteristics. Processor 1004 may include any general-purpose processor and one or more hardware or software services, such as services 1012 stored on storage device 1010, configured to control processor 1004, as well as special-purpose processors, where software instructions are incorporated into the actual processor design. Processor 1004 may be a completely self-contained computing system including multiple cores or processors, connectors (e.g., buses), memory, memory controllers, caches, etc. In some embodiments, such self-contained computing systems with multiple cores are symmetric. In some embodiments, such self-contained computing systems with multiple cores are asymmetric. In some embodiments, processor 1004 may be a microprocessor, a microcontroller, a digital signal processor (“DSP”), or a combination of these and / or other types of processors. In some embodiments, the processor 1004 may include multiple elements, such as a core, one or more registers, and one or more processing units, such as an arithmetic logic unit (ALU), a floating point unit (FPU), a graphics processing unit (GPU), a physical processing unit (PPU), a digital systems processing (DSP) unit, or a combination of these and / or other such processing units.
[0138]
[0147] To enable user interaction with the computing system architecture 1000, the input devices 1016 can represent any number of input mechanisms, such as a microphone for speech, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, a pen, and other such input devices. The output devices 1018 can also be one or more of several output mechanisms known to those skilled in the art, including, but not limited to, a monitor, speakers, a printer, a haptic device, and other such output devices. In some instances, a multimodal system may enable a user to provide multiple types of input for communication with the computing system architecture 1000. In some embodiments, the input devices 1016 and / or the output devices 1018 may be coupled to the computing device 1002 using a remote connection device, such as, for example, a communications interface, such as the network interface 1020 described herein. In such embodiments, the communications interface may govern and manage the input and output received from the attached input devices 1016 and / or the output devices 1018. As can be contemplated, there is no limitation to operating on any particular hardware configuration, and therefore the basic features herein can be readily substituted for other hardware, software, or firmware configurations as they are developed.
[0139]
[0148] In some embodiments, storage device 1010 may be described as non-volatile storage or non-volatile memory. Such non-volatile memory or non-volatile storage may be a hard disk or other type of computer-readable medium capable of storing data that is accessible by a computer, such as a magnetic cassette, a flash memory card, a solid-state memory device, a digital versatile disk, a cartridge, RAM, ROM, and hybrids thereof.
[0140]
[0149] As described above, the storage device 1010 may include hardware and / or software services, such as the service 1012, that can control or configure the processor 1004 to perform one or more functions, including, but not limited to, the methods, processes, functions, systems, and services described herein in various embodiments. In some embodiments, the hardware or software services may be implemented as modules. As shown in the exemplary computing system architecture 1000, the storage device 1010 may be connected to other parts of the computing device 1002 using system connections 1006. In one embodiment, a hardware service or hardware module, such as the service 1012, that performs a function may include necessary hardware components, such as the processor 1004, connections 1006, cache 1008, storage device 1010, memory 1014, input devices 1016, output devices 1018, as well as software components stored in a non-transitory computer-readable medium that can perform functions, such as those described herein.
[0141]
[0150] The disclosed process for generating and executing experience recommendations may be implemented using a computing system, such as the exemplary computing system shown in FIG. 10 , using one or more components of an exemplary computing system architecture 1000. The exemplary computing system may include a processor (e.g., a central processing unit), memory, non-volatile memory, and interface devices. The memory may store data and / or one or more sets of code, software, scripts, etc. The components of the computer system may be coupled to each other via a bus or through some other known or convenient device.
[0142]
[0151] In some embodiments, a processor may be configured to perform some or all of the methods and functions for generating and executing experience recommendations described herein by executing code using a processor, such as, for example, processor 1004, where the code is stored in a memory, such as memory 1014, as described herein. One or more of the user devices, provider servers or systems, database systems, or other such devices, services, or systems may include some or all of the components of a computing system, such as the exemplary computing system shown in FIG. 10, that uses one or more components of the exemplary computing system architecture 1000 described herein. As may be contemplated, variations of such systems may be considered within the scope of the present disclosure.
[0143]
[0152] The present disclosure contemplates a computer system taking any suitable physical form. By way of example and not limitation, a computer system may be an embedded computer system, a system-on-chip (SOC), a single-board computer system (SBC) (e.g., a computer-on-module (COM) or system-on-module (SOM)), a desktop computer system, a laptop or notebook computer system, a tablet computer system, a wearable computer system or interface, an interactive kiosk, a mainframe, a mesh of computer systems, a mobile phone, a personal digital assistant (PDA), a server, or a combination of two or more of these. Where appropriate, a computer system may include one or more computer systems that are unitary or distributed, across multiple locations, across multiple machines, and / or reside in a cloud computing system that may include one or more cloud components in one or more networks, as described herein in connection with computing resource provider(s) 1028. Where appropriate, one or more computer systems may perform one or more steps of one or more methods described or illustrated herein without substantial spatial or temporal limitation. By way of example and not limitation, one or more computer systems may perform one or more steps of one or more methods described or illustrated herein in real time or in batch mode. One or more computer systems may, where appropriate, perform one or more steps of one or more methods described or illustrated herein at different times or in different locations.
[0144]
[0153] The processor 1004 may be a conventional microprocessor, such as an Intel® microprocessor, an AMD® microprocessor, a Motorola® microprocessor, or other such microprocessor. Those skilled in the art will recognize that the terms "machine-readable (storage) medium" or "computer-readable (storage) medium" include any type of device that is accessible by a processor.
[0145]
[0154] The memory 1014 may be coupled to the processor 1004 by, for example, a connector, such as connector 1006, or a bus. As used herein, a connector or bus, such as connector 1006, is a communication system that transfers data between components within the computing device 1002 and, in some embodiments, may be used to transfer data between computing devices. The connector 1006 may be a data bus, a memory bus, a system bus, or other such data transfer mechanism. Examples of such connectors include, but are not limited to, an Industry Standard Architecture (ISA) bus, an Enhanced ISA (EISA) bus, a Parallel AT Attachment (PATA) bus (e.g., an Integrated Drive Electronics (IDE) or Enhanced IDE (EIDE) bus), or various types of parallel component interconnect (PCI) buses (e.g., PCI, PCIe, PCI-104, etc.).
[0146]
[0155] The memory 1014 may include RAM, including but not limited to dynamic RAM (DRAM), static RAM (SRAM), synchronous dynamic RAM (SDRAM), nonvolatile random access memory (NVRAM), and other types of RAM. DRAM may include error correcting code (EC). The memory may also include ROM, including but not limited to programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, mask ROM (MROM), and other types of ROM. The memory 1014 may also include magnetic or optical data storage media, including read-only (e.g., CD ROM and DVD ROM) or other (e.g., CD or DVD). The memory may be local, remote, or distributed.
[0147]
[0156] As explained above, the connector 1006 (or bus) may also couple the processor 1004 to a storage device 1010, which may include non-volatile memory or storage and may also include a drive unit. In some embodiments, the non-volatile memory or storage is a magnetic floppy or hard disk, a magnetic-optical disk, an optical disk, a ROM (e.g., CD-ROM, DVD-ROM, EPROM, or EEPROM), a magnetic or optical card, or another form of storage for data. Portions of this data may be written to memory during execution of software in the computer system by a direct memory access process. The non-volatile memory or storage may be local, remote, or distributed. In some embodiments, the non-volatile memory or storage is optional. As may be contemplated, a computing system may be created with all applicable data available in memory. A typical computer system will usually include at least one processor, memory, and a device (e.g., a bus) coupling the memory to the processor.
[0148]
[0157] The software and / or data associated with the software may be stored in non-volatile memory and / or a drive unit. In some embodiments (e.g., for large programs), it may not be possible to store the entire program and / or data in memory at all times. In such embodiments, the program and / or data may be moved in or out of memory from an additional storage device, such as storage device 1010. Nevertheless, it should be understood that in order for the software to operate, it is moved, when necessary, to a computer-readable location suitable for processing, and for purposes of explanation, that location will be referred to herein as memory. Even when the software is moved to memory for execution, the processor may utilize hardware registers to store values associated with the software and, ideally, a local cache to serve to speed execution. As used herein, a software program is assumed to be stored in any known or convenient location (from non-volatile storage to hardware registers) when the software program is referred to as being "implemented in a computer-readable medium." A processor is considered to be "configured to execute a program" when at least one value associated with the program is stored in a register readable by the processor.
[0149]
[0158] The connection 1006 may also couple the processor 1004 to a network interface device, such as a network interface 1020. The interface may include one or more of a modem or other such network interfaces, including but not limited to those described herein. It will be appreciated that the network interface 1020 may be considered part of the computing device 1002 or may be separate from the computing device 1002. The network interface 1020 may include one or more of an analog modem, an Integrated Services Digital Network (ISDN) modem, a cable modem, a token ring interface, a satellite transmission interface, or other interfaces for coupling the computer system to other computer systems. In some embodiments, the network interface 1020 may include one or more input and / or output (I / O) devices. The I / O devices may include, by way of example and not limitation, input devices, such as input device(s) 1016 and / or output devices, such as output device(s) 1018. For example, the network interface 1020 may include a keyboard, a mouse, a printer, a scanner, a display device, and other such components. Other examples of input and output devices are described herein. In some embodiments, the communication interface device may be implemented as a complete and separate computing device.
[0150]
[0159] In operation, a computer system may be controlled by operating system software, including a file management system, such as a disk operating system. One example of operating system software with its associated file management system software is the Windows® family of operating systems and their associated file management systems. Another example of operating system software with its associated file management system software is the Linux® operating system and its associated file management system, including, but not limited to, the various types and implementations of the Linux® operating system and their associated file management systems. The file management system may be stored in non-volatile memory and / or drive units and may cause a processor to perform various acts required by the operating system to input and output data and store data in memory, including storing files in non-volatile memory and / or drive units. As may be contemplated, other types of operating systems, such as MacOS®, other types of UNIX® operating systems (e.g., BSD® and subgenres, Xenix®, SunOS®, HP-UX®, etc.), mobile operating systems (e.g., iOS® and variants, Chrome®, Ubuntu Touch®, watchOS®, Windows 10 Mobile®, Blackberry® OS, etc.), and real-time operating systems (e.g., VxWorks®, QNX®, eCos®, RTLinux, etc.), may be considered within the scope of this disclosure. As may be contemplated, the names of operating systems, mobile operating systems, real-time operating systems, languages, and devices listed herein may be registered trademarks, service marks, or designs of the various associated entities.
[0151]
[0160] In some embodiments, computing device 1002 may be connected to one or more additional computing devices, such as computing device 1024, via network 1022 using a connection such as network interface 1020. In such embodiments, computing device 1024 may execute one or more services 1026 to perform one or more functions under the control of or on behalf of programs and / or services operating on computing device 1002. In some embodiments, a computing device such as computing device 1024 may include one or more of the types of components described with respect to computing device 1002, including, but not limited to, a processor such as processor 1004, a connection such as connection 1006, a cache such as cache 1008, a storage device such as storage device 1010, a memory such as memory 1014, an input device such as input device 1016, and an output device such as output device 1018. In such embodiments, computing device 1024 may perform functions such as those described herein with respect to computing device 1002. In some embodiments, computing device 1002 may be connected to multiple computing devices, such as computing device 1024, each of which may in turn be connected to multiple computing devices, such as computing device 1024. Such embodiments may be referred to herein as a distributed computing environment.
[0152]
[0161] The network 1022 may be any network, including the Internet, an intranet, an extranet, a cellular network, a Wi-Fi network, a local area network (LAN), a wide area network (WAN), a satellite network, a Bluetooth network, a virtual private network (VPN), a public switched telephone network, an infrared (IR) network, an Internet of Things (IoT network), or any other such network or combination of networks. Communication over the network 1022 may be a wired connection, a wireless connection, or a combination thereof. Communication over the network 1022 may occur via various communication protocols, including, but not limited to, Transmission Control Protocol / Internet Protocol (TCP / IP), User Datagram Protocol (UDP), protocols at various layers of the Open Systems Interconnection (OSI) model, File Transfer Protocol (FTP), Universal Plug and Play (UPnP), Network File System (NFS), Server Message Block (SMB), Common Internet File System (CIFS), and other such communication protocols.
[0153]
[0162] Communications over network 1022 may include information, sometimes referred to herein as content, within computing device 1002, within computing device 1024, or within computing resource provider 1028. The information may include text, graphics, audio, video, tactile, and / or any other information that may be provided to a user of a computing device, such as computing device 1002. In one embodiment, the information may be delivered using a transfer protocol, such as HyperText Markup Language (HTML), Extensible Markup Language (XML), JavaScript, Cascading Style Sheets (CSS), JavaScript Object Notation (JSON), and other such protocols and / or structured languages. The information may be initially processed by computing device 1002 and presented to a user of computing device 1002 using a form that is perceptible via sight, hearing, smell, taste, touch, or other such mechanism. In some embodiments, communications over network 1022 may be received and / or processed by a computing device configured as a server. Such communications may be sent and received using PHP, or Hypertext Preprocessor ("PHP"), Python, Ruby, Perl and variations, Java, HTML, XML, or another such server-side processing language.
[0154]
[0163] In some embodiments, computing device 1002 and / or computing device 1024 may be connected to computing resource provider 1028 over network 1022 using a network interface such as the network interface (e.g., network interface 1020) described herein. In such embodiments, one or more systems (e.g., services 1030 and 1032) hosted within computing resource provider 1028 (also referred to herein as within a “computing resource provider environment”) may execute one or more services to perform one or more functions under the control of or on behalf of programs and / or services operating on computing device 1002 and / or computing device 1024. Systems such as services 1030 and 1032 may include one or more computing devices, such as those described herein, to execute computer code to perform one or more functions under the control of or on behalf of programs and / or services operating on computing device 1002 and / or computing device 1024.
[0155]
[0164] For example, computing resource provider 1028 may offer a service operating on service 1030 to store data for computing device 1002, e.g., when the amount of data for computing device 1002 exceeds the capacity of storage device 1010. In another example, computing resource provider 1028 may offer a service to initially instantiate a virtual machine (VM) on service 1032, use that VM to access data stored on service 1032, perform one or more operations on that data, and provide the results of those one or more operations to computing device 1002. Such operations (e.g., data storage and VM instantiation) may be referred to herein as operating “in the cloud,” “within a cloud computing environment,” or “within a hosted virtual machine environment,” and computing resource provider 1028 may also be referred to herein as a “cloud.” Examples of such computing resource providers include, but are not limited to, Amazon® Web Services (AWS®), Microsoft's Azure®, IBM Cloud®, Google Cloud®, Oracle Cloud®, etc.
[0156]
[0165] Services offered by computing resource providers 1028 include, but are not limited to, data analytics, data storage, archival storage, big data storage, virtual computing (including various scalable VM architectures), blockchain services, containers (e.g., application encapsulation), database services, development environments (including sandbox development environments), e-commerce solutions, gaming services, media and content management services, security services, serverless hosting, virtual reality (VR) systems, and augmented reality (AR) systems. Various techniques that facilitate such services include, but are not limited to, virtual machines, virtual storage, database services, system schedulers (e.g., hypervisors), resource management systems, various types of short-term, intermediate, long-term, and archival storage devices, etc.
[0157]
[0166] As may be contemplated, systems such as services 1030 and services 1032 may implement versions of various services (e.g., service 1012 or service 1026) on behalf of or under the control of computing device 1002 and / or computing device 1024. Such implemented versions of various services may involve one or more virtualization techniques, for example, so that when the service is running on, for example, service 1030, it may appear to a user of computing device 1002 that service 1012 is running on computing device 1002. As may also be contemplated, various services operating within the computing resource provider 1028 environment may be distributed among various systems within the environment, as well as partially distributed on computing device 1024 and / or computing device 1002.
[0158]
[0167] Client devices, user devices, computer resource provider devices, network devices, and other devices may be computing systems that include, among other things, one or more integrated circuits, input devices, output devices, data storage devices, and / or network interfaces. The integrated circuits may include, among other things, one or more processors, volatile memory, and / or non-volatile memory, such as those described herein. The input devices may include, for example, keyboards, mice, keypads, touch interfaces, microphones, cameras, and / or other types of input devices, including, but not limited to, the input devices described herein. The output devices may include, for example, display screens, speakers, haptic feedback systems, printers, and / or other types of output devices, including, but not limited to, the output devices described herein. Data storage devices, such as hard drives or flash memory, may enable computing devices to temporarily or permanently store data. A network interface, such as a wireless or wired interface, may enable computing devices to communicate with a network. Examples of computing devices (e.g., computing device 1002) include, but are not limited to, desktop computers, laptop computers, server computers, handheld computers, tablets, smartphones, personal digital assistants, digital home assistants, wearable devices, smart devices, and combinations of these and / or other such computing devices, as well as machines and apparatuses in which a computing device is embedded and / or virtually implemented.
[0159]
[0168] The techniques described herein may also be implemented in electronic hardware, computer software, firmware, or any combination thereof. Such techniques may be implemented in any of a variety of devices, such as a general-purpose computer, a wireless communication device handset, or an integrated circuit device having multiple uses, including applications in wireless communication device handsets and other devices. Any features described as modules or components may be implemented together in an integrated logic device or separately as discrete but interoperable logic devices. If implemented in software, the techniques may be realized at least in part by a computer-readable data storage medium comprising program code including instructions that, when executed, perform one or more of the methods described above. The computer-readable data storage medium may form part of a computer program product, which may include packaging materials. The computer-readable medium may comprise a memory or a data storage medium, such as those described herein. The techniques may additionally or alternatively be realized at least in part by a computer-readable communication medium, such as a propagated signal or radio wave, that carries or communicates program code in the form of instructions or data structures and that can be accessed, read, and / or executed by a computer.
[0160]
[0169] The program code may be executed by a processor, which may include one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Such a processor may be configured to perform any of the techniques described in this disclosure. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor), multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. Accordingly, the term “processor,” as used herein, may refer to any of the above structures, any combination of the above structures, or any other structure or apparatus suitable for implementing the techniques described herein. Furthermore, in some aspects, the functionality described herein may be provided within dedicated software or hardware modules configured to implement an interrupted database update system.
[0161]
[0170] As used herein, the terms "machine-readable medium" and equivalent terms "machine-readable storage medium," "computer-readable medium," and "computer-readable storage medium" refer to media including, but not limited to, portable or non-portable storage devices, optical storage devices, removable or non-removable storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. Computer-readable media may include non-transitory media on which data may be stored, which does not include carrier waves and / or transitory electronic signals propagating wirelessly or over wired connections. Examples of non-transitory media may include, but are not limited to, magnetic disks or tapes, optical storage media such as compact discs (CDs) or digital versatile discs (DVDs), solid-state drives (SSDs), flash memory, memories, or memory devices.
[0162]
[0171] A machine-readable medium or machine-readable storage medium may have stored thereon code and / or machine-executable instructions, which may represent a procedure, a function, a subprogram, a program, a routine, a subroutine, a module, a software package, a class, or any combination of instructions, data structures, or program statements. A code segment may be coupled to another code segment or a hardware circuit by passing and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be passed, forwarded, or transmitted via any suitable means, including memory sharing, message passing, token passing, network transmission, etc. Further examples of machine-readable storage medium, machine-readable medium, or computer-readable (storage) medium include, but are not limited to, recordable-type media such as volatile and non-volatile memory devices, floppy and other removable disks, hard disk drives, optical disks (e.g., CDs, DVDs, etc.), and transmission-type media such as digital and analog communications links, among others.
[0163]
[0172] As may be contemplated, examples herein may illustrate or refer to a machine-readable medium or machine-readable storage medium as a single medium, but the terms "machine-readable medium" and "machine-readable storage medium" should be taken to include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) that store one or more sets of instructions. The terms "machine-readable medium" and "machine-readable storage medium" should also be taken to include any medium capable of storing, encoding, or carrying a set of instructions for a system to execute, causing the system to perform any one or more of the methods or modules disclosed herein.
[0164]
[0173] Some portions of the detailed descriptions herein may be presented in terms of algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the means used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. The operations require physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical or magnetic signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It has proven convenient at times, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like.
[0165]
[0174] It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. Unless otherwise indicated, and as will be apparent from the following description, it will be appreciated that throughout the description, descriptions utilizing terms such as "processing" or "calculating" or "computing" or "determining" or "displaying" or "generating" refer to the acts and processes of a computer system or similar electronic computing device that manipulates and converts data represented as physical (electronic) quantities in the computer system's registers and memory into other data that is similarly represented as physical quantities in the computer system's memory or registers or other such information storage, transmission or display device.
[0166]
[0175] It should also be noted that individual implementations may be described as a process that is depicted as a flowchart, flow diagram, data flow diagram, structure diagram, or block diagram (e.g., the processes shown in FIGS. 6-8). While a flowchart, flow diagram, data flow diagram, structure diagram, or block diagram may describe operations as a sequential process, many of the operations may be performed in parallel or simultaneously. Additionally, the order of operations may be rearranged. A process is terminated when the operations of a process depicted in a diagram are completed, but may have additional steps not included in the diagram. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, its termination may correspond to a return of the function to the calling function or the main function.
[0167]
[0176] In some embodiments, one or more implementations of algorithms such as those described herein may be implemented using machine learning or artificial intelligence algorithms. Such machine learning or artificial intelligence algorithms may be trained using supervised, unsupervised, reinforcement, or other such training techniques. For example, a set of data may be analyzed using one of various machine learning algorithms to identify correlations between different elements of the set of data without supervision and feedback (e.g., unsupervised training techniques). Machine learning data analysis algorithms may also be trained using sample or live data to identify potential correlations. Such algorithms may include k-means clustering algorithms, fuzzy c-means (FCM) algorithms, expectation-maximization (EM) algorithms, hierarchical clustering algorithms, density-based spatial clustering of noisy applications (DBSCAN) algorithms, etc. Other examples of machine learning or artificial intelligence algorithms include, but are not limited to, genetic algorithms, backpropagation, reinforcement learning, decision trees, linear classification, artificial neural networks, anomaly detection, etc. More generally, machine learning or artificial intelligence methods may include regression analysis, dimensionality reduction, meta-learning, reinforcement learning, deep learning, and other such algorithms and / or methods. As can be appreciated, the terms "machine learning" and "artificial intelligence" are often used interchangeably due to the degree of overlap between these fields, and many of the techniques and algorithms disclosed have similar approaches.
[0168]
[0177] As an example of a supervised training technique, a set of data may be selected for training a machine learning model to facilitate the identification of correlations between members of the set of data. The machine learning model may be evaluated to determine whether the machine learning model is generating accurate correlations between members of the set of data based on sample inputs provided to the machine learning model. Based on this evaluation, the machine learning model may be modified to increase the likelihood that the machine learning model will identify the desired correlations. The machine learning model may be further dynamically trained by soliciting feedback (i.e., monitoring) from users of the system regarding the efficacy of the correlations provided by the machine learning or artificial intelligence algorithm. The machine learning algorithm or artificial intelligence may use this feedback to improve the algorithm for generating the correlations (e.g., the feedback may be used to further train the machine learning algorithm or artificial intelligence to provide more accurate correlations).
[0169]
[0178] The various examples of flowcharts, flow charts, data flow diagrams, structure diagrams, or block diagrams described herein may further be implemented by hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware, or microcode, the program code or code segments (e.g., a computer program product) to perform the necessary tasks may be stored in a computer-readable or machine-readable storage medium (e.g., a medium for storing program code or code segments) such as those described herein. A processor implemented in an integrated circuit may perform the necessary tasks.
[0170]
[0179] The various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the implementations disclosed herein may be implemented as electronic hardware, computer software, firmware, or combinations thereof. To clearly illustrate this interchangeability between hardware and software, the various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as a departure from the scope of the present disclosure.
[0171]
[0180] It should be noted, however, that the algorithms and displays presented herein are not inherently related to any particular computer or other apparatus. Various general-purpose systems may be used with programs in accordance with the teachings herein, or it may prove convenient to construct more specialized apparatus to perform some example methods. The required structure for a variety of these systems will appear from the description below. Further, the techniques are not described with reference to any particular programming language, and thus various examples may be implemented using a variety of programming languages.
[0172]
[0181] In various implementations, the system operates as a standalone device or may be connected (e.g., networked) to other systems. In a networked deployment, the system may operate in the capacity of a server or a client system in a client-server network environment, or as a peer system in a peer-to-peer (or distributed) network environment.
[0173]
[0182] The system may be a server computer, a client computer, a personal computer (PC), a tablet PC (e.g., iPad®, Microsoft Surface®, Chromebook®, etc.), a laptop computer, a set-top box (STB), a personal digital assistant (PDA), a mobile device (e.g., cellular telephones, iPhone®, and Android® devices, Blackberry®, etc.), a wearable device, an embedded computer system, an e-book reader, a processor, a telephone, a web appliance, a network router, switch or bridge, or any system capable of executing a set of instructions (such as sequential) that specify actions to be taken by the system. The system may also be a virtual system, such as a virtual version of one of the above-mentioned devices that may be hosted on another computing device, such as computing device 1002.
[0174]
[0183] Generally, the routines executed to implement implementations of the present disclosure may be implemented as part of an operating system or as a specific application, component, program, object, module, or set of instructions referred to as a “computer program.” A computer program generally comprises one or more sets of instructions at different times in various memory and storage devices in the computer that, when read and executed by one or more processing units or processors in a computer, cause the computer to perform operations to execute elements involved in various aspects of the present disclosure.
[0175]
[0184] Furthermore, while the examples have been described in the context of fully functional computers and computer systems, those skilled in the art will appreciate that various examples may be distributed as program objects in various forms, and that the present disclosure applies equally regardless of the particular type of machine or computer-readable medium used to actually affect the distribution.
[0176]
[0185] In some situations, an operation of a memory device, such as a change of state from a binary 1 to a binary 0 or vice versa, may comprise a transformation, such as, for example, a physical transformation. In certain types of memory devices, such a physical transformation may comprise a physical transformation of an article to a different state or thing. For example, without limitation, for some types of memory devices, a change of state may involve the accumulation and storage of charge or the release of stored charge. Similarly, in other memory devices, a change of state may comprise a physical change or transformation of magnetic orientation or a physical change or transformation of molecular structure from crystalline to amorphous or vice versa. The above is not intended to be an exhaustive list of all examples in which a change of state from a binary 1 to a binary 0 or vice versa in a memory device may comprise a transformation, such as a physical transformation. Rather, the above is intended as an illustrative example.
[0177]
[0186] Storage media may generally be non-transitory or comprise a non-transitory device. In this context, non-transitory storage media may include a device that is tangible, meaning that the device has a concrete physical form, but the device may change its physical state. Thus, for example, non-transitory refers to a device that remains tangible despite this change in state.
[0178]
[0187] The above description and drawings are illustrative and should not be construed as limiting or restricting the subject matter to the precise form disclosed. Those skilled in the art will appreciate that numerous modifications and variations are possible in light of the above disclosure and may be made thereto without departing from the broader scope of the embodiments described herein. Numerous specific details are set forth to provide a thorough understanding of the present disclosure. However, in some instances, well-known or conventional details are not described in order to avoid obscuring the description.
[0179]
[0188] As used herein, the terms "connected," "coupled," or any variation thereof, when applied to modules of a system, means any connection or coupling, either direct or indirect, between two or more elements, and the coupling of connections between elements may be physical, logical, or any combination thereof. Furthermore, the terms "herein," "above," "below," and words of similar import, when used in this application, shall refer to this application as a whole and not to any particular portions thereof. Where the context allows, terms in the above Detailed Description using the singular or plural may also include the plural or singular, respectively. The term "or" with respect to a list of two or more items covers all interpretations of the term: any of the items in the list, all of the items in the list, or any combination of the items in the list.
[0180]
[0189] As used herein, the terms "a," "an," and "the," as well as other such singular referents, are to be construed to include both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context.
[0181]
[0190] As used herein, the terms "comprising," "having," "including," and "containing" should be construed as open-ended (e.g., "including" should be construed as "including, but not limited to") unless otherwise indicated or clearly contradicted by context.
[0182]
[0191] As used herein, the recitation of ranges of values serves as a shorthand method of referring individually to each separate value falling within the range, unless otherwise indicated or clearly contradicted by context, and thus, each separate value of a range is incorporated herein as if it were individually set forth herein.
[0183]
[0192] As used herein, use of the terms "set" (e.g., "set of items") and "subset" (e.g., "subset of a set of items") should be construed as a non-empty set containing one or more elements, unless otherwise indicated or clearly contradicted by context. Furthermore, unless otherwise indicated or clearly contradicted by context, the term "subset" of a corresponding set does not necessarily indicate a proper subset of the corresponding set, although the subset and the set may contain the same elements (i.e., the set and the subset may be the same).
[0184]
[0193] As used herein, the use of conjunctive language such as "at least one of A, B, and C" should be interpreted as indicating one or more of A, B, and C (e.g., any one of the following non-empty subsets of the set {A,B,C}: {A}, {B}, {C}, {A,B}, {A,C}, {B,C}, or {A,B,C}), unless otherwise indicated or clearly contradicted by context. Thus, conjunctive language such as "at least one of A, B, and C" does not imply a requirement of at least one of A, at least one of B, and at least one of C.
[0185]
[0194] As used herein, the use of example or exemplary language (e.g., "such as" or "for example") is intended to more clearly illustrate embodiments and does not impose a limitation on the scope unless otherwise claimed. Such language herein should not be construed as indicating that any non-claimed element is required to practice the embodiments described and claimed in the present disclosure.
[0186]
[0195] As used herein, when a component is described as being "configured to" perform some operation, such configuration may be achieved, for example, by designing electronic circuitry or other hardware to perform the operation, by programming a programmable electronic circuit (e.g., a microprocessor or other suitable electronic circuitry) to perform the operation, or any combination thereof.
[0187]
[0196] Those skilled in the art will appreciate that the disclosed subject matter may be embodied in other forms and manners not set forth below. It should be understood that the use of relational terms, such as first, second, top, and bottom, if any, are used only to distinguish one entity or action from another, without necessarily requiring or implying any such actual relationship or order between such entities or actions.
[0188]
[0197] While processes or blocks are presented in a given order, alternative implementations may perform routines having steps or employ systems having blocks in a different order, and some processes or blocks may be deleted, moved, added, sub-divided, substituted, combined, and / or modified to provide alternative or sub-combinations. Each of these processes or blocks may be implemented in a variety of different ways. Also, while processes or blocks are sometimes shown as being performed sequentially, these processes or blocks may instead be performed in parallel or at different times. Furthermore, any specific numbers referenced herein are examples only, and alternative implementations may employ different values or ranges.
[0189]
[0198] The teachings of the disclosure provided herein may be applied to other systems, not necessarily limited to the systems described above. Elements and acts of the various examples described above may be combined to provide further examples.
[0190]
[0199] Any patents and applications and other references referred to above, including those that may be listed in accompanying application papers, are incorporated herein by reference. Aspects of the present disclosure may be modified, where necessary, to adopt the systems, functions, and concepts of the various references described above to provide still further examples of the present disclosure.
[0191]
[0200] These and other changes may be made to the present disclosure in light of the above detailed description. While the above description sets forth some examples and describes the best modes contemplated, no matter how detailed it may appear in text, the teachings may be implemented in various ways. While the details of the system are still encompassed by the subject matter disclosed herein, their implementation details may vary considerably. As noted above, a particular term used when describing certain features or aspects of the present disclosure should not be taken to imply that the term has been redefined herein so as to be limited to any particular characteristic, feature, or aspect of the relevant disclosure. In general, the terms used in the following claims should not be construed to limit the disclosure to the specific implementations disclosed herein unless the above detailed description section explicitly defines such terms. Thus, the actual scope of the present disclosure encompasses not only the disclosed implementations but also all equivalent ways of practicing or implementing the disclosure under the scope of the claims.
[0192]
[0201] Although some aspects of the present disclosure are presented below in several claim forms, the inventors contemplate various aspects of the present disclosure in any number of claim forms. Any claim intended to be treated under 35 U.S.C. § 112(f) will commence with the words "means for." Accordingly, the applicant reserves the right to add additional claims after filing this application to pursue such additional claim forms for other aspects of the present disclosure.
[0193]
[0202] The terms used in this specification generally have their ordinary meaning in the art within the context of this disclosure and in the specific context in which each term is used.Some terms used to describe this disclosure are explained above or elsewhere in this specification to provide practitioners with additional guidance regarding the description of this disclosure.For convenience, some terms may be emphasized, for example, by using capital letters, italics, and / or quotation marks.The use of emphasis does not affect the scope and meaning of a term, and the scope and meaning of a term are the same in the same context regardless of whether it is emphasized or not.It will be appreciated that the same element may be described in more than one way.
[0194]
[0203] Thus, alternative language and synonyms may be used for any one or more of the terms described herein, and no particular importance should be placed on whether a term is recited or explained herein. Synonyms for some terms are provided. The recitation of one or more synonyms does not exclude the use of other synonyms. The use of examples anywhere in this specification, including examples of any term described herein, is illustrative only and is not intended to further limit the scope and meaning of the disclosure or any exemplified term. Likewise, the disclosure is not limited to the various examples provided herein.
[0195]
[0204] Without intending to further limit the scope of the present disclosure, examples of instruments, devices, methods and their related results according to examples of the present disclosure are given below. Please note that titles or subtitles may be used in the examples for the convenience of the reader, and in any case, this should not limit the scope of the present disclosure. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this disclosure pertains. In case of conflict, the present document, including definitions, shall prevail.
[0196]
[0205] Some portions of this specification describe examples in terms of algorithms and symbolic representations of operations on information. These algorithmic descriptions and representations are commonly used by those skilled in the data processing arts to effectively convey the substance of their work to others skilled in the art. These operations, while described functionally, computationally, or logically, are understood to be implemented by computer programs or equivalent electrical circuits, microcode, or the like. Further, it has proven convenient at times to refer to these arrangements of operations as modules, without loss of generality. The described operations and their associated modules may be implemented in software, firmware, hardware, or any combination thereof.
[0197]
[0206] Any of the steps, operations, or processes described herein may be performed or implemented using one or more hardware or software modules, alone or in combination with other devices. In some examples, a software module is implemented in a computer program object comprising a computer-readable medium containing computer program code, which may be executed by a computer processor to perform any or all of the described steps, operations, or processes.
[0198]
[0207] Examples may also relate to apparatus for performing the operations herein. This apparatus may be specially constructed for the required purposes and / or may comprise a general-purpose computing device selectively activated or reconfigured by a computer program stored in the computer. Such a computer program may be stored on a non-transitory tangible computer-readable storage medium that may be coupled to a computer system bus, or any type of medium suitable for storing electronic instructions. Furthermore, any computing system referred to herein may include a single processor or may be an architecture employing a multiple processor design to increase computing power.
[0199]
[0208] Examples may also relate to objects generated by the computing processes described herein. Such objects may comprise information resulting from the computing processes, where the information is stored on a non-transitory tangible computer-readable storage medium, and may include any implementation of a computer program object or other data combination described herein.
[0200]
[0209] The language used herein has been selected primarily for ease of reading and instructional purposes, and may not be selected to define or limit the subject matter. Accordingly, it is intended that the scope of the present disclosure be limited not by this detailed description, but by any claims published on an application based on this specification. Accordingly, the disclosure of the examples is intended to be illustrative, but not limiting, of the scope of the subject matter set forth in the following claims.
[0201]
[0210] Specific details have been provided in the preceding description to provide a thorough understanding of various implementations of systems and components for a context-connected system. However, those skilled in the art will understand that the above-described implementations may be practiced without these specific details. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form so as not to obscure the embodiments with unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail to avoid obscuring the embodiments.
[0202]
[0211] The above detailed description of the present technology has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the present technology to the precise form disclosed. Many modifications and variations are possible in light of the above teachings. The described embodiments have been chosen to best explain the principles of the present technology and its practical application, and to enable others skilled in the art to best utilize the present technology in various embodiments with various modifications as may be suitable for the particular uses contemplated. It is intended that the scope of the present technology be defined by the claims.
Claims
1. 1. A computer-implemented method comprising: receiving a request to perform a task on behalf of a member, wherein the task corresponds to a set of actions that can be performed for completion of the task, the set of actions including a sensitive action, and the task is assigned to a proxy associated with the member for performance of the task on behalf of the member; determining that the sensitive action is possible using sensitive information associated with the member; generating a link associated with a data privacy repository, wherein the link is generated in real time as other actions in the set of actions associated with the task are being performed, the data privacy repository being inaccessible to the representative, and wherein the member stores the sensitive information in the data privacy repository when the link is received by the member; forwarding the task when the other operation is to be performed, wherein when the task is received by a trusted representative, the trusted representative accesses the data privacy repository to obtain the sensitive information for performance of the sensitive operation, and the sensitive information is not made available to the representative; communicating a status of the task, wherein the status of the task is communicated without the confidential information. A method comprising:
2. obtaining an access log corresponding to historical accesses to the sensitive information through the data privacy repository; identifying any access violations associated with the historical accesses to the sensitive information, wherein the access violations are identified based on the access log. taking one or more corrective actions based on said access violation; and The computer-implemented method of claim 1 further comprising:
3. The computer-implemented method of claim 1 , wherein when the sensitive information is stored in the data privacy vault, the sensitive information is not available to the member through the data privacy vault.
4. 2. The computer-implemented method of claim 1, wherein access to the sensitive information in the data privacy vault is subject to a timeout period, and when the timeout period expires, the trusted representative is automatically prevented from accessing the sensitive information.
5. The computer-implemented method of claim 1 , further comprising automatically providing a status corresponding to performance of the sensitive action, the status being provided without the sensitive information.
6. 2. The computer-implemented method of claim 1, wherein the task is transmitted with an identifier corresponding to the sensitive information, the identifier not including any portion of the sensitive information, and the identifier usable to query the data privacy repository to obtain the sensitive information.
7. The computer-implemented method of claim 1 , wherein access to the sensitive information is automatically terminated upon the completion of the task.
8. one or more processors; A memory for storing instructions wherein the instructions, when executed by the one or more processors, result in the system: receiving a request to perform a task on behalf of a member, wherein the task corresponds to a set of actions that can be performed for completion of the task, the set of actions including a sensitive action, and the task is assigned to a proxy associated with the member for performance of the task on behalf of the member; determining that the sensitive action is possible using sensitive information associated with the member; generating a link associated with a data privacy repository, wherein the link is generated in real time as other actions in the set of actions associated with the task are being performed, the data privacy repository being inaccessible to the representative, and wherein the member stores the sensitive information in the data privacy repository when the link is received by the member; forwarding the task when the other operation is to be performed, wherein when the task is received by a trusted representative, the trusted representative accesses the data privacy repository to obtain the sensitive information for performance of the sensitive operation, and the sensitive information is not made available to the representative; communicating completion of the task, wherein the completion of the task is communicated without the confidential information. A system that allows the following to be performed.
9. The instructions may include: obtaining an access log corresponding to historical accesses to the sensitive information through the data privacy repository; identifying any access violations associated with the historical accesses to the sensitive information, wherein the access violations are identified based on the access log. taking one or more corrective actions based on said access violation; and The system of claim 8 , further comprising:
10. The system of claim 8 , wherein when the sensitive information is stored in the data privacy vault, the sensitive information is not available to the member through the data privacy vault.
11. 9. The system of claim 8, wherein access to the sensitive information in the data privacy vault is subject to a timeout period, and when the timeout period expires, the trusted representative is automatically prevented from accessing the sensitive information.
12. The instructions may include: The system of claim 8 , further comprising automatically providing a status corresponding to performance of the sensitive action, the status being provided without sensitive information.
13. 10. The system of claim 8, wherein the task is transferred with an identifier corresponding to the sensitive information, the identifier not including any portion of the sensitive information, and the identifier usable to query the data privacy repository to obtain the sensitive information.
14. The system of claim 8 , wherein access to the sensitive information is automatically terminated upon the completion of the task.
15. A non-transitory computer-readable storage medium having stored thereon executable instructions that, when executed by one or more processors of a computer system, cause the computer system to: receiving a request to perform a task on behalf of a member, wherein the task corresponds to a set of actions that can be performed for completion of the task, the set of actions including a sensitive action, and the task is assigned to a proxy associated with the member for performance of the task on behalf of the member; determining that the sensitive action is possible using sensitive information associated with the member; generating a link associated with a data privacy repository, wherein the link is generated in real time as other actions in the set of actions associated with the task are being performed, the data privacy repository being inaccessible to the representative, and wherein the member stores the sensitive information in the data privacy repository when the link is received by the member; forwarding the task when the other operation is to be performed, wherein when the task is received by a trusted representative, the trusted representative accesses the data privacy repository to obtain the sensitive information for performance of the sensitive operation, and the sensitive information is not made available to the representative; communicating completion of the task, wherein the completion of the task is communicated without the confidential information. A non-transitory computer-readable storage medium that causes
16. The executable instructions may include: obtaining an access log corresponding to historical accesses to the sensitive information through the data privacy repository; identifying any access violations associated with the historical accesses to the sensitive information, wherein the access violations are identified based on the access log. taking one or more corrective actions based on said access violation; and 16. The non-transitory computer-readable storage medium of claim 15, further comprising:
17. 16. The non-transitory computer-readable storage medium of claim 15, wherein when the sensitive information is stored in the data privacy vault, the sensitive information is not available to the member through the data privacy vault.
18. 16. The non-transitory computer-readable storage medium of claim 15, wherein access to the sensitive information in the data privacy vault is subject to a timeout period, and when the timeout period expires, the trusted representative is automatically prevented from accessing the sensitive information.
19. The executable instructions may include:
16. The non-transitory computer-readable storage medium of claim 15, further comprising automatically providing a status corresponding to performance of the sensitive operation, the status being provided without sensitive information.
20. 16. The non-transitory computer-readable storage medium of claim 15, wherein the task is transferred with an identifier corresponding to the sensitive information, the identifier not including any portion of the sensitive information, and the identifier usable to query the data privacy repository to obtain the sensitive information.
21. 16. The non-transitory computer-readable storage medium of claim 15, wherein access to the sensitive information is automatically terminated upon the completion of the task.
Citation Information
Patent Citations
Digital identity
EP3968194A1
System and method for safe electronic data storage and taking-out
JP2000200209A
Database access control method, database access control system, and program
JP2004258743A
Distributed, decentralized data aggregation
JP2020017298A
Proxy system for customer confidentiality
US20030069857A1