Systems and methods for protecting and sharing data using distributed ledger technology

A distributed ledger technology system addresses the lack of secure data sharing in electronic dating and health monitoring by enabling users to control and share health data securely, enhancing transparency and reliability.

JP7861968B2Active Publication Date: 2026-05-19GETCHKD INC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
GETCHKD INC
Filing Date
2021-01-21
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing electronic dating solutions and health monitoring systems lack secure mechanisms for users to control and share their STD or COVID-19 data, leading to unreliable decision-making and potential disease spread.

Method used

A distributed ledger technology system that enables users to securely collect, protect, and share health data through customizable permissions and smart contracts, ensuring data ownership and control.

Benefits of technology

Provides users with transparent and informed decision-making by allowing secure sharing of up-to-date health data, enhancing privacy and reliability in dating and health monitoring systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007861968000001
    Figure 0007861968000001
  • Figure 0007861968000002
    Figure 0007861968000002
  • Figure 0007861968000003
    Figure 0007861968000003
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a distributed ledger technology (e.g., blockchain)-based system that provides tools and mechanisms for users to exercise control over their data. In embodiments, the system may include a platform device configured to initiate a connection with a laboratory testing service provider where the system (e.g., a computer system) may store data related to the user. In embodiments, the platform device is configured to protect data stored at the laboratory testing service provider by facilitating placement of that data in a distributed ledger. Once the data is protected in the distributed ledger, the platform device may be configured to provide controlled distribution or sharing of the protected data with other users or other third-party systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - reference to Related Applications This application claims priority to U.S. Provisional Patent Application No. 62 / 964,069, filed on January 21, 2020, entitled "SYSTEMS AND METHODS FOR ACCESSING, SECURING, AND SHARING DATA USING A BLOCKCHAIN ENVIRONMENT", the entire disclosure of which is incorporated herein by reference.

[0002] This application relates to systems and methods for enabling a user to protect and share data associated with the user using distributed ledger technology. Thus, the systems and methods disclosed herein enable the user to control the ownership of data associated with the user.

Background Art

[0003] Sexually transmitted diseases and infections (collectively referred to herein as sexually transmitted diseases (STDs)) are considered to be silent epidemics. Millions of new cases are discovered and reported each year. Electronic dating solutions currently in use, including websites and mobile applications, are exacerbating the rise in STD rates due to certain high-risk behaviors, including the use of these dating sites to arrange accidental, and often anonymous, sexual contact. People with STDs may engage in sexual contact without disclosing their condition, or people may simply believe, or hope, that their partners do not have an STD. In some cases, people with STDs do not exhibit the symptoms associated with their STD, as many STDs are asymptomatic. However, people can transmit the infection to their partners even without symptoms. Thus, people engaged in sexual contact may, knowingly or unknowingly, transmit their condition to some or all of their partners. This makes STDs common and often unnoticed.

[0004] Some electronic dating solutions offer users the option to disclose details about their STD status. For example, some dating websites offer users the ability to initiate whether they have an STD and / or disclose the type of STD they have. However, such electronic dating solutions often lack details and / or proof related to when the user underwent STD-related laboratory testing. This information is important if the user could have acquired different or more STDs, knowingly or unknowingly. Furthermore, current solutions rely heavily on users voluntarily considering or honestly sharing information related to their STDs. Consequently, existing electronic dating solutions do not provide important or reliable details related to the sexually transmitted infection status of other users so that the user can make informed decisions when meeting new people with whom they may have sexual contact. This could be because these solutions also do not provide a system that enables the user to securely control (e.g., access, protect, or share) their verified STD data (or a portion of their STD data) (e.g., by a laboratory), which would then enable the user to make informed decisions.

[0005] The problem of diseases spreading among the aforementioned human populations is not limited to STDs. Coronavirus disease 2019 (COVID-19) is another disease that has been silently spreading around the world, with hundreds of thousands of new cases being discovered and reported every day. Human behavior (e.g., the desire to have social contact or engage in recreational activities) and survival necessities (e.g., going to work or shopping at grocery stores) can be considered some of the reasons that stimulate the spread of COVID-19. Organizations and / or governments have implemented social distancing restrictions to control (e.g., reduce) the aforementioned spread. These social distancing efforts have led to remote work; remote or online education; cancellation of sports, entertainment and professional events; restricted entry to grocery stores; and the closure of museums, parks, churches and many others.

[0006] In the future, an organization may implement a system that helps it reopen its facilities and operate at pre-COVID levels. To do so, the organization may need to determine the COVID-19 status of a user entering its facilities in order to determine whether the user is allowed to enter the organization's buildings. For example, to make that decision, the organization may need to determine whether a person entering its facilities is COVID-19 positive / negative or has been vaccinated. For illustrative purposes, an organization such as the owner of a meat plant, whose business does not allow one or more users associated with them (e.g., employees, buyers, wholesalers and like-minded individuals) to participate in their business from home (e.g., cutting meat), may implement a system that helps it make informed decisions about whether one or more users are allowed to enter its facilities. For further illustrative purposes, another organization such as a concert organizer or live entertainment provider, whose business also does not allow participants to perform the recreational activity from home, may implement such a system to make informed decisions about whether participants should be allowed to enter its buildings.

[0007] As a provisional solution to make the above decision, an organization may require users to submit 1) a questionnaire detailing their current health status (e.g., whether they have suffered from one or more symptoms of COVID-19), and / or 2) their current (e.g., recently tested) COVID-19 status. However, implementing these tests and other health monitoring efforts would involve collecting a vast amount of personal data, which could raise concerns (by the user or government authorities) about the security integrity of the user's personal data. This raises further concerns regarding the organization's responsibility in determining how the data is protected, from whom it is protected, and who is responsible for its protection, if the organization requires the user to disclose the data to the organization in a protected state. Therefore, the existing solutions for implementing health monitoring efforts to restart organizations do not provide a system that enables one or more organizations to securely control (e.g., access, protect, or share) the user's personal data (e.g., health data), which further hinders organizations from implementing their own health monitoring efforts. [Overview of the project] [Problems that the invention aims to solve]

[0008] Embodiments of this disclosure address these challenges and disclose a distributed ledger technology (e.g., blockchain) system that provides tools and mechanisms for users to control their data. [Means for solving the problem]

[0009] Providing a user with the control over their data may enable the user to securely share data related to them (e.g., health data such as STD status, COVID status, and similar) with other users or third parties such as organizations, which may help those other users / organizations make informed decisions. For illustrative purposes, the system and method provide a user with the ability to collect information about them (e.g., their health data, e.g., STD status or COVID status) from a third-party system (e.g., a laboratory testing service provider's system), protect that data using distributed ledger technology, and share that data with another third-party system (e.g., in a dating environment, or to an organization deciding whether the user can enter those facilities considering a COVID outbreak) using customizable permissions. When used in a dating-based application, the ability to securely share up-to-date STD status-related data provides the user with transparency and the ability to make informed decisions when choosing who they want to relate to, talk to, message, or meet, and whether they want to engage in sexual activity. Furthermore, when used in applications related to an outbreak (e.g., COVID-19), the ability to securely share the latest COVID situation-related data (e.g., a user's COVID-19 test results or details related to COVID-19 vaccination) allows third parties to make informed decisions about whether to enable the user at their facilities.

[0010] In an embodiment, the system may include a platform device configured to initiate a connection with a laboratory testing service provider, the system (e.g., a computer system) which may store data related to the user. In an embodiment, the platform device is configured to protect the data stored in the laboratory testing service provider by facilitating the placement of the data in a distributed ledger. Once the data is protected in the distributed ledger, the platform device may be configured to provide controlled distribution or sharing of the protected data with other users or other third-party systems. In an embodiment, the system may include a platform device which may include a user interface running on a computer system that enables a user to create a platform profile by verifying themselves. Once the user has verified themselves, as described in detail below, the platform device may issue a set of keys (e.g., a private key and a corresponding public key) to the user (or the verified profile of the user) and store the user's public key and / or public key address (e.g., a hashed copy of the public key) in a local storage device associated with the platform. After having the public / private keys provided to or issued to the verified profile of the user, the user may access the services provided by the platform. In an embodiment, the service may also include enabling the user to initiate a connection with a third-party system (e.g., a laboratory testing service provider) which may have data related to the user stored within the service's computer system. In an embodiment, the service may further include facilitating the placement or storage of the data stored in the third-party system into a distributed ledger.For example, after the laboratory test has been performed and the results of the laboratory test are available, the platform device may be configured to facilitate the placement (or storage) of the data (e.g., laboratory test results) stored in the system of the laboratory test service provider to a distributed ledger (or blockchain network). In an embodiment, after storing the data from the third-party system, the service provided by the platform device may include providing the user with the ability to control the distribution or sharing of the data (e.g., laboratory test results) stored in the distributed ledger by other users or other third-party systems (e.g., using permissions or smart contracts).

[0011] In an embodiment, the platform device may be configured to receive other information related to the user and place such information on the blockchain. For example, the platform may be configured to receive personal information from the user, such as a name, contact information, social media information, identification information, background information, or any other details provided by the user to the platform device, and to place an encrypted version of this data on the distributed ledger. The data may be encrypted (for example, using the public key issued to the user) before being stored on the distributed ledger. For example, the platform device may be configured to receive personal information related to the user, encrypt this data using the user's public key, and then place the encrypted data on the distributed ledger. In an embodiment, the user data supplied from the third-party system may be encrypted by the encryption provided, for example, by the blockchain network, before being stored on the distributed ledger. Thus, in an embodiment, the data encrypted using the public key can only be stored in the user's digital wallet (or key manager) on the user's personal device or decrypted by the private key. Furthermore, in an embodiment, the data collected from the third-party system and encrypted by the blockchain network may also be decrypted and accessed only by the user (e.g., when accessing or sharing), thereby giving the user full ownership of the data stored in the distributed ledger without the platform device storing any of the decryption keys in their local storage devices. In this sense, the platform can never decrypt any information related to the user from the blockchain and therefore cannot access such information, thereby giving the user data ownership.

[0012] In an embodiment, the user can use the platform device to control (e.g., limit) the amount of information shared with a third party (e.g., a dating platform or another user or organization). In an embodiment, the user may also be able to control (e.g., limit) the information that the third party may make available (or essentially anywhere on the internet) by using a set of permissions and / or smart contracts, thereby obtaining complete control over the distribution of that personal information and how it is shared. In an embodiment, the user device may maintain a digital wallet (or key manager) that stores public and private keys (and all other decryption keys) associated with the user's data stored in the blockchain ledger.

[0013] In embodiments, particularly embodiments configured to comply with local data protection laws, the platform includes (for example, a hyperledger fabric) hyperledgerThe platform may be configured to store an encrypted version of the personally identifiable information (PII) associated with the user in an off-chain storage device in the personal data collection of fabric. The platform may further be configured to store the user's public key and / or public key address in the off-chain storage device. The platform may be configured to store a hash of the user's PII in the off-chain storage device. In an embodiment, the platform may be configured to retrieve and / or identify information stored in the off-chain storage device using the user's public key (or public key address) or a hash of the PII or any token that can retrieve the encrypted version of the user's PII. In such an embodiment, the platform may be configured to facilitate the storage of non-personally identifiable information (non-PII) associated with the user (e.g., STD status, COVID status, temperature information, answers to questionnaires, etc.) in the distributed ledger. In an embodiment, the non-PII may be encrypted by the blockchain network so that only the encrypted version of the non-PII is stored in the blockchain. In one embodiment, using the platform device, the user can view the placement data using an application (e.g., a web application) and share their non-PII (e.g., whether the user has an STD or whether the user has tested positive or negative for COVID) with one or more third parties using a set of permissions and / or smart contracts.

[0014] The foregoing broadly outlines the features and technical advantages of the present invention in order to enable a better understanding of the subsequent "Modes for Carrying Out the Invention." Further features and advantages of the present invention, which form the subject matter of the claims of the present invention, are described below. Those skilled in the art should understand that the disclosed concepts and specific embodiments may be readily available as a basis for modifying or designing other structures for carrying out the same object of the present invention. Those skilled in the art should also recognize that such equivalent structures do not deviate from the spirit and scope of the present invention as described in the appended claims. Novel features that are considered to be features of the present invention, both in terms of their organization and operation, along with further objects and advantages, will be better understood from the following description in relation to the appended drawings. However, it should be expressly understood that each of the aforementioned drawings is provided for illustrative and explanatory purposes only and is not intended to define any limitation of the present invention.

[0015] For a more complete understanding of the present invention, the following description, shown in conjunction with the accompanying drawings, is to be referenced herein. [Brief explanation of the drawing]

[0016] [Figure 1] This figure shows a system configured to perform operations according to the embodiments of this disclosure. [Figure 2] This figure shows the platform device according to an embodiment of the present disclosure. [Figure 3] This is a flowchart showing the functions of the system in Figure 1 relating to the aspect of this disclosure. [Modes for carrying out the invention]

[0017] Details of the various features and advantages are shown in the accompanying drawings and will be described more fully with reference to the non-limiting embodiments detailed in the following description. Descriptions of well-known processing methods, components and equipment are omitted in detail so as not to obscure the invention unnecessarily. However, it should be understood that the “Modes for Carrying Out the Invention” and the aforementioned specific examples are provided to illustrate embodiments of the invention and are not intended to limit it. Various substitutions, modifications, additions and / or rearrangements within the spirit and / or scope of the underlying concept of the invention will be apparent to those skilled in the art from this disclosure.

[0018] The aforementioned system may include a platform device that enables the collection of user data stored in a third-party system (e.g., laboratory test results stored at a laboratory service provider site) and facilitates the placement of the user data stored in the third-party system into a distributed ledger. Such placement may occur without the platform device having previously stored the data. The platform device may further enable controlled distribution or sharing of the user data stored in the distributed ledger, at least partially or entirely based on the user's discretion at various points in time. In this sense, aspects of the disclosure provide a mechanism for protecting and sharing personal data. Systems implemented in aspects of the disclosure may be considered to be a service-as-a-service (BAAS) system or a blockchain as software that uses a blockchain protocol and can therefore be considered to be placed on a blockchain.

[0019] The subsequent disclosures focus on applications related to health / medical data (e.g., STD or COVID-19 testing and / or vaccination status). In particular, parts of the disclosures focus on 1) collecting user data by enabling the user to initiate a connection with a laboratory testing service provider whose system (e.g., a computer system) may store data related to the user, and 2) facilitating the placement of the data stored in the laboratory testing provider's system into a distributed ledger. In this sense, the subsequent disclosures provide the user with the ability to protect user data stored in a third-party system (e.g., the laboratory testing provider's system) into a distributed ledger, and the ability to access the data using an application (e.g., a web application or dashboard). Part of the disclosures also focus on 3) providing controlled, distributed, or protected sharing of the data with other users or other third-party systems. In this sense, the subsequent disclosures hereby provide the user with the ability to share the data protected in the distributed ledger with other users or systems. Needless to say, the disclosures herein are equally applicable to collecting any kind of user data (i.e., not limited to laboratory test data) stored in any third-party system, protecting such data from the third-party system to a distributed ledger, and sharing such protected data with any user, system, or service provider.

[0020] Figure 1 is a block diagram of a system 100, which includes a platform device 120 that provides users with the ability to protect user data using distributed ledger technology and to control the distribution of the protected data, according to an embodiment of the present disclosure. The system 100 includes the platform device 120, one or more user devices 110, and a plurality of service providers, such as an identity verification service provider 140, a dating service provider 142, and a laboratory service provider 144. According to an embodiment of the present disclosure, the platform device 120 is configured to use distributed ledger technology to protect laboratory test data stored by a laboratory service provider (for example, in a laboratory service provider computer system) and to share the protected data (or a portion thereof) with another of the service providers (for example, a dating service provider).

[0021] Figure 1 shows service providers related to medical / health services and dating services, and it is understood that the system relating to this disclosure may include different service providers based on the application using the system 100. For example, in other applications, instead of protecting user data from laboratory service providers, the system 100 may protect data from social media service providers (e.g., Facebook). In such applications, the third party with whom the protected data is shared could be any third party (e.g., a video streaming service provider, another user, or any other internet-enabled computer system). It is further understood that the system relating to this disclosure may include additional or fewer service providers based on the application in which the system 100 is used. For example, the system 100 may include an identity verification service provider 140, a laboratory service provider, and a social media service provider, and the system may protect data from both the laboratory service provider and the social media service provider. In such applications, the third party with whom the protected data is shared could be any third-party system (e.g., a hotel service provider's computer system, a travel agency, and / or a government agency).

[0022] As shown in FIG. 1, the platform device 120, one or more user devices 110, and the plurality of service providers may be communicatively coupled to one or more networks 170 via one or more wired communication links or wireless communication links. The one or more networks 170 may include a wired network, a wireless communication network, a cellular network, a cable transmission system, a local area network (LAN), a wireless LAN (WLAN), a metropolitan area network (MAN), a wide area network (WAN), the Internet, a public switched telephone network (PSTN), a cellular data network, a cellular voice network, the Internet, and the like. The platform device 120, one or more user devices 110, and the plurality of service providers may be communicatively coupled to a blockchain network 172. The blockchain network 172 may implement the blockchain technology and execute functionality provided by a blockchain platform such as Ethereum, Hyperledger Fabric, IBM Blockchain, Multichain, and / or any other blockchain platform. It should be noted that the system implemented according to the aspects of the present disclosure may not select a blockchain-platform, and any consideration of a particular blockchain example is for illustrative purposes only and should not be construed as limiting.

[0023] The user device 110 includes one or more processing units 112, a memory 114, and one or more communication interfaces 118. Each of the one or more processing units 112 may be a central processing unit (CPU) or other arithmetic circuits (e.g., a microcontroller, one or more application-specific integrated circuits (ASICs), and the like), and may have one or more processing cores. The memory 114 may include a read-only memory (ROM) device, a random access memory (RAM) device, one or more hard disk drives (HDDs), flash memory devices, solid-state drives (SSDs), other devices configured to store persistent or non-persistent state data, or a combination of different memory devices. The memory 114 may store instructions 116 that, when executed by the one or more processing units 112, cause the one or more processing units 112 to perform the operations described in relation to the user device 110 with reference to Figures 1 to 3. In addition to storing the instructions 116, the memory 114 may store a digital wallet 117. The digital wallet 117 may be configured to store information associated with the user corresponding to the user device 110, such as all data the user has stored in the distributed ledger. The digital wallet 117 may connect to or be included in an application (e.g., a web application) provided by the entity operating the platform device. The application may provide the user with the control unit for sharing the user's data stored in the distributed ledger with other users or systems, for example, by changing (or customizing) the permissions for sharing the data from the distributed ledger. The application may be configured to provide the user with a snapshot of the data the user has stored in the distributed ledger. The application may be configured to provide the user with a snapshot of the data protected by the platform (from third-party systems (e.g., laboratory testing service providers)) onto the distributed ledger.

[0024] The user device 110 may be configured to provide an interface for facilitating user input / output operations in aspects of this disclosure. The interface may include a graphical user interface (GUI). In an embodiment, the GUI may be configured and generated by a GUI system (e.g., GUI121) of the platform device 120. In another embodiment, the GUI may be configured and generated by a GUI system (not shown in Figure 1) of the user device 110. In any case, the GUI may be configured to configure and generate a GUI for facilitating user input / output operations. The GUI may be configured to include various GUI control units that enable the user to input information such as driver's license information, passport information, or other relevant information with any qualification or identification assurance, personal details (e.g., name and contact information), or output information to the user, such as information related to their laboratory tests (e.g., STD or COVID-19 test and / or vaccination status). In embodiments, such information obtained from third parties (e.g., third-party dating platforms or third-party dating services) may be available via the GUI. Essentially, any information related to the protection, access, and sharing of laboratory test information and laboratory results can be managed and controlled by the user using the GUI. In some embodiments, the GUI may include GUI control units for controlling various aspects of the process. For example, GUI control units may be provided for logging into the system, enabling the verification process, initiating a connection with a third-party system (e.g., a laboratory test service provider system), accessing data collected from the third-party system and stored in the distributed ledger, and authenticating data sharing. In embodiments, users may use the GUI to input or share information about themselves, including verification information.

[0025] In an aspect, the user device 110 may be implemented as a mobile device, smartphone, tablet computer device, personal computer device, laptop computer device, desktop computer device, wearable computer device, in-vehicle computer system, personal digital assistant (PDA), smartwatch, another type of wired and / or wireless computer device, and any part thereof.

[0026] In an embodiment, the user device 110 may include an application provided by the entity operating the platform device 120, the application may be configured to present the user with a GUI that enables the user to view and use the services provided. The application may further be configured to provide access to smart contracts (or customizable permissions) that may be used by the user to modify currently issued smart contracts and / or permissions that control the distribution of the data associated with the user stored in the distributed ledger. The application may further be configured to view one or more pre-viewable pieces of information about the user by revoking permissions from third parties via smart contracts and blocking those third parties. Furthermore, the application may further be configured to connect to or include a digital wallet (or key manager) that stores the keys associated with the user, such as the user's private key. In an embodiment, the application uses the keys stored in the digital wallet to decrypt the data and presents the decrypted version of the data (e.g., data associated with the user stored in the distributed ledger) to the user. The application may be a mobile application, a browser-based application (for example, an application accessible via the Internet through a web browser), or another type of application that runs on a smartphone, tablet computer device, desktop computer device or laptop computer device, personal digital assistant, or other type of electronic device adapted to perform the operations of the user device 110.

[0027] The platform device 120 may include a GUI 121, one or more processing units 122, a memory 124, and one or more communication interfaces 130. Each of the one or more processing units 122 may be a CPU or other computer circuit (e.g., a microcontroller, one or more ASICs and the like), and may have one or more processing cores. The memory 114 may include a ROM device, a RAM device, one or more HDDs, a flash memory device, a solid-state drive SSD, another device configured to store data in a persistent or non-persistent state, or a combination of different memory devices. The memory 124 may store instructions 126 that cause the one or more processing units 122 to perform operations described in relation to the platform device 120 with reference to Figures 1 to 3 when executed by one or more processing units 122.

[0028] Figure 1 shows a single platform device 120, but it goes without saying that the platform device 120 and its individual functional blocks may be implemented as a single device or distributed across multiple devices having their own processing resources, which may be configured to perform the operations relating to this disclosure. In some embodiments, the platform device 120 may be implemented entirely or partially in an on-site system or a cloud-based system.

[0029] A brief reference is made to Figure 2, which shows the platform device 120 in more detail. The instruction 126 may include instructions related to verification management 122e, key management 122c, and smart contract management 122d. In the embodiment in which the system securely collects data from a laboratory service provider, the instruction 126 may further include laboratory test management 122b and dating profile and platform management 122a. The platform device 120 may further include a GUI system 121. In some embodiments, each of the instruction instances (e.g., 122a to 122e) may have one or more application programming interfaces (APIs) associated with them. For example, each of the dating profile and platform management 122a, laboratory test management 122b, key management 122c, smart contract management 122d, and verification management 122e may have one or more APIs associated with them. In some embodiments, the APIs do not have to be distributed among the several instruction instances, and one or more APIs may perform the functions of the instruction instances. Referring back to Figure 1, the one or more communication interfaces 130 may be configured to communicatively connect the platform device 120 to the one or more networks 170 and the blockchain network 172 via a wired communication link or a wireless communication link, in accordance with one or more communication protocols or communication standards (for example, the one or more communication standards described above with reference to the one or more networks 170).

[0030] Multiple service providers, namely an identity verification service provider, a third-party service provider, and a laboratory service provider, are further shown in Figure 1. These service providers provide different services to the user through the platform device 120. For example, the identity verification service provider provides identity verification services to the platform device. Similarly, a laboratory service provider 144 may provide laboratory testing services to the user with the help of the platform device 120. A dating service provider 142 may provide protected dating services to the user through the platform device 120. Each of the multiple service providers may be operable in its own computer system, each including its own processing unit, memory, and one or more communication interfaces. In embodiments, the instructions stored in the memory 124 of the platform device 120 may facilitate the interaction of the platform device 120 with one or more of the multiple service providers.

[0031] The functionality provided by each of these command instances is described below. The platform device 120 may request a command related to the verification manager 122e when a user attempts to register to access the services provided by the platform device 120. In an embodiment, the verification manager 122e may provide functionality including invoking a GUI control unit (e.g., on the user device 110) that enables the user to submit personal details, such as name, contact information, and status identification information (e.g., driver's license number, passport number). In an embodiment, the verification manager 122e may invoking a GUI control unit that requires the user to scan and / or share photos of their status identification or passport along with other government-issued identification documents. The user's input may be sent directly to the identity verification service provider 140 (e.g., ACUANT®) via one or more networks 170 without storing any information in the memory 124. For example, the API corresponding to the verification manager 122e may be used to notify the identity verification technology service provider of the information submitted by the user. In an embodiment, during or after submitting the information to the service provider, the verification manager 122e may notify the key manager 122c to generate a unique ID corresponding to the verification request.

[0032] In an embodiment, the verification manager 122e may provide a function that includes invoking a GUI control unit (e.g., on the user device 110) that provides a link (e.g., a website link) to the verification service provider 140 when the user attempts to register to access the services provided by the platform device 120. If the user expresses interest in verifying themselves, for example by clicking the link to the verification service provider, the verification manager 122e may direct the user to the verification service provider 140 and indicate the user's interest in verification to the key manager 122c (as further described below). The key manager 122c may then generate a unique ID corresponding to the indication. In the latter scenario, the user directly provides identification verification information to the verification provider system, thereby avoiding the need to provide identification verification information to the platform device 120.

[0033] Once the verification is complete, the result may be sent back to the platform device 120 via the API and associated with the user using the unique ID. The result may then be provided to the user. The result may include information that the user has been successfully verified, i.e., the identity verification service provider has successfully verified the user's real-world identity online, and the service provider has inferred who the user is based on the information and / or documents provided by the user. Upon successful verification, the verification manager 122e may prompt the platform device 120 to generate a profile or platform ID for the user using the key management system 122c, or may provide functionality to notify the platform device 120 of the successful verification (e.g., by transmitting an internal notification). In an embodiment, the smart contract manager 120d or the key management system 122c may be used to prompt the platform device 120 to provide the user with a digital wallet (e.g., a key manager). In an embodiment, the platform device 120 associates the platform ID with the digital wallet.

[0034] For further illustrative purposes, if a user is successfully verified by the identity verification service provider, the platform device 120 may request (and execute) instructions related to the key manager 122c. In this case, the key manager 122c may generate a platform ID for the user (e.g., an identifier for the user within the platform device 120) and generate a public key and a corresponding private key for the verified user. The key manager 122c may store a copy of the public key issued to the user in memory 124, but not the private key provided to the user in memory 124. In an embodiment, the key manager 122c may associate the platform ID with the user's public key and store that association information in the platform device 120. In an embodiment, if provided, the user may store those private keys generated for them in the digital wallet 117 or in a cold storage wallet (e.g., somewhere offline, e.g., on a memory stick or in a personal journal).

[0035] In some embodiments, the key management system 115 may provide the user with the keys using a key management system such as Amazon Web Services® (AWS) Key Management Service, BellID® Key Manager, IBM® Security Key Manager, and the like. The key management system 122c may further provide functions related to key exchange, crypto shredding (destroying keys), and substitution. The key management system 122c may include cryptographic protocol designs, key servers, user procedures, and other appropriate protocols. The key management system 122c may be configured to provide the user-level keys between either the user or a system (e.g., a third-party system such as a dating service provider or a laboratory service provider 144).

[0036] In an embodiment, the key manager 122c may be configured to provide keys, such as user-level tokens or unique IDs, between users or systems. For example, if a user expresses interest in verifying themselves or scheduling STD-related or COVID-related tests from a laboratory service provider, the key manager 122c may generate a unique ID corresponding to the request and associate the unique ID with a copy of the user's public key. In an embodiment, the key manager 122c may associate the unique ID with the public key address (which is a hash of the user's public key). In an embodiment, the key manager 122c may associate the unique ID with the user's asset ID, which may be generated by the key manager 122c upon successful verification of the user. The asset ID may be associated with the user's digital wallet. In an embodiment, the data stored in the distributed ledger may be associated with the user using the user's asset ID. In one embodiment, when a user sends personal details to the laboratory service provider 144, the key manager 122c generates a set of keys (another set of asymmetric keys, e.g., a public key and a private key). In another embodiment, when a user sends personal details to the dating service provider 142, the key manager 122c generates a different set of keys (another set of asymmetric keys, e.g., a public key and a private key).

[0037] Furthermore, if the user is successfully verified and expresses interest in scheduling a laboratory test (e.g., an STD-related test or a COVID-related test) from a laboratory service provider, the platform device 120 may request instructions related to the laboratory test management 122b. For example, once the user is verified and a set of keys is provided, the laboratory test management 122b invokes the GUI system to provide the user with the ability to request a laboratory test, for example, by providing a link (e.g., a website link) to the laboratory service provider 144. If the user expresses interest in scheduling a laboratory test, for example by clicking the link, the laboratory test management 122b may direct the user to the website corresponding to the laboratory service provider 144 and notify the key management 122c of the user's interest in scheduling a laboratory test. As described above, if a user expresses interest in scheduling a laboratory test from a laboratory service provider, the key management 122c may generate a unique ID corresponding to the laboratory test request, transmit the unique ID to the laboratory service provider (or its system) via the API of the laboratory test management 122b, and associate the user with the unique ID on the platform device 120 (for example, using the user's platform ID or public key). In an embodiment, the association between the unique ID and the user may be stored in memory 124. As described above, the unique ID is transmitted to the laboratory test provider and internally associated with the user, and at least in that sense, the platform device 120 initiates a connection with the laboratory test provider.

[0038] Upon completion of the laboratory test (for example, after the user submits the sample and the laboratory has the results), the laboratory test management 122c may receive notification, for example, in the form of an API call from the API of the laboratory service provider 144. For example, if the laboratory test management 122c receives the notification from the laboratory service provider 144, the laboratory test management 122c may instruct the key management 122c to store the laboratory results in the distributed ledger. The instruction from the key management 122c may, upon returning to the API call, include providing the unique ID and the association information between the user to facilitate the storage of the results in the distributed ledger. In this sense, the test results are never stored locally in memory 124. The user may then securely access (e.g., view) the results using the application provided by the platform device 120 and / or their digital wallet 117 (for example, by providing decryption using the key stored therein). In one embodiment, the laboratory test results are encrypted before being stored in the distributed ledger. This encryption may occur in the blockchain network 172 (for example, in the case of a hyperledger fabric). In another embodiment, the decryption of the laboratory test results may be performed by the blockchain network 172 without providing any decryption key associated with the encryption.

[0039] Furthermore, the platform device 120 may request instructions related to smart contract management 122d when the user has received the test results from the laboratory service provider 144. Smart contract management 122d may provide function-related sharing of the received laboratory test and / or any other data (e.g., dating profile, name, photo, social media operation functions, etc.) stored in the distributed ledger accessible to the user. Such sharing may be done together with other users (e.g., any user in the dating service provider 142) using the application provided by the platform device 120. That is, the user may use the application provided by the platform device 120 to control the sharing of the data related to the user stored in the distributed ledger. Smart contract management 122d may include criteria that the user must select before sharing that data with other users. These criteria may include the amount of data being shared. For example, a user may simply choose to use a smart contract to send only a portion of their test results (e.g., only their STD status related to a specific disease (e.g., herpes type 1) instead of the full test results, e.g., status related to other diseases). As another example, and as further described below, the user may choose to share their full profile, including name and contact information (e.g., in an application on a dating platform where the sharing is made to determine whether the user is sexually involved with someone), and their full STD profile, including the date the test was taken. The type of data shared may include data derived from the information stored in the distributed ledger. For example, if a user does not wish to explicitly inform other users on the dating service provider of the STDs they have, the user may simply choose to place a badge on their third-party dating profile.The badge may indicate that the user has undergone STD testing or has received the results of such STD tests, and that the user either does not have any of the tested STDs or has tested positive for at least one of the STDs. The badge may be of a different color or shape depending on the user's STD status. For example, a green badge or a green "check" sign may indicate that the user has been tested and does not have any of the STDs. In another example, the badge may be a yellow "check" sign which may indicate that the user has been tested and has at least one STD. In yet another example, the badge may be a red "cross" sign which may indicate that the user has not been tested.

[0040] As described above, the user may share the derived information with other users or systems. In embodiments, the smart contract may be used by the platform of this disclosure to provide the user with the ability to 1) derive results from user data stored in the distributed ledger, and 2) share the derived results. For example, the smart contract may be used to apply one or more protocols (or rules) to the user data stored in the distributed ledger in order to provide the user with the derived results and the ability to share the results with other users or systems. For illustrative purposes, the user data stored in the distributed ledger may include the user's age, the user's COVID test results, vaccination-related information (e.g., whether the user has been vaccinated, the date of vaccination, proof of vaccination, etc.), and the user's STD results. The smart contract may be configured or designed to apply a protocol that derives a “green” badge, which may indicate that the user does not have an STD, is COVID negative, and is above a certain threshold age. The smart contract may provide the user with the ability to share its badge with other users or systems, thereby eliminating the need to share the data stored in the distributed ledger. In an embodiment, the smart contract may provide permission for other users to view the user data in the distributed ledger but not to share that data (e.g., make a copy). The user may revoke the granted permission.

[0041] The dating profile and platform management 122a may be configured to provide the functionality to create dating profiles for users, or, generally speaking, to create a dating environment that can be accessed by the user using the GUI. The dating profile and platform management 122a may also include providing the user with an interface (configured by the GUI system 117) that displays their own dating profiles and the dating profiles of other users. In an embodiment, when the user is verified, the dating profile and platform management 122a may suggest to the user that they create those dating profiles. To create the dating profiles, the dating profile and platform management 122a may allow the user to add a person profile, one or more photographs, information related to their sexual interests, and other dating-related details. The information provided by the user in those dating profiles may be encrypted and stored in the distributed ledger (for example, a modification record having the dating profile information may be stored in the distributed ledger). In one embodiment, since all information relating to the user is placed on the blockchain, the user may choose to disclose any information they wish to share. For example, the dating profile and platform management 122a may be configured to provide the user with the ability to share their personal data with other dating platforms (or dating service providers) at the user's discretion (e.g., using smart contracts). Examples of third-party dating platforms include Bumble, Tinder, Shaadi.com, and Match.com. In another embodiment, the user may choose to retain some of the information provided in the dating profile that is hidden from other users by using smart contracts, as described above with respect to smart contract management 122d.

[0042] In operation, the platform device 120, one or more user devices 110, and the multiple service providers and their individual components may work together to provide the functionality described herein. In some embodiments, the functionality provided by the system 100 may be provided, at least in part, as a web-based program, a standalone application (e.g., mobile and / or desktop-based), a cloud-based application, an application programming interface (API), etc. For example, user devices 110 may be used by users to provide information about themselves. Such information may be communicated to the platform device 120 via one or more networks 170. The platform device 120 may include functionality that enables the user, via the user device 110, to verify and then initiate a connection with the laboratory testing service provider, to store the information relating to their health monitoring test results after the laboratory testing in a blockchain network 172, and to share their health monitoring test results (e.g., STD test date and STD test status) with others. Furthermore, as described above, the platform device 120 may include functions that enable the user, via the user device 110, to verify and then initiate laboratory tests, access information related to those laboratory tests after the tests are performed, and share those test results (e.g., STD status) with others. Some of these functions may be performed, at least in part, using APIs associated with the instruction instances (e.g., 122a-122e).

[0043] Figure 3 shows a flowchart illustrating the functionality of the system in Figure 1 in an aspect of this disclosure. Here, Figure 3 describes an application that requires a user to decide with whom the user wishes to relate to, talk to, message, or meet and engage in sexual activity. Thus, the functionality of the system in Figure 1 as described herein assists the user in securely collecting up-to-date information about their STD status stored in the laboratory testing service provider system and sharing details with the dating service provider relating to their STD status and / or personal details (e.g., dating profile, photos, STD test results, or whether the user has an STD and / or an indication of the most recent date the user was tested).

[0044] As shown in Figure 3, the method 300 may include verifying the user's real-world identity in block 310. In embodiments, the user may be verified using an identity verification service provider. As described above, when a user attempts to access the services provided by the platform device 120 (for example, the services described with respect to Figure 1), the user may first be asked to register with the platform device 120. The registration may include verifying the user. In embodiments, the verification may include a background check. These background checks may only enable people who are registered and claimed by the government to use the services provided by the platform device 120. Thus, verifying users before allowing them access to the services reduces the likelihood of fraud, identity theft, violence, and crime. In embodiments, the verification may take personal details of the user, such as name, contact information, and some type of status identification information (e.g., driver's license number, passport number). In embodiments, the platform device 120 may require the user to scan and share their status identification or passport photos along with other personal details. The personal details provided by the user during registration may be sent to the identity verification service provider via network 170 using one or more of the above API and instruction instances. Once the verification is complete, the result is sent back to the platform device 120 via the API associated with the identity verification service provider. If the result is good, i.e., the user is the claimant, the user may be made able to use the services provided by the platform device 120.

[0045] Next, in block 320, the method 300 may include providing the user with one or more identifications associated with the user's profile on the platform device 120, in response to successful verification (or registration). As described above, the one or more identifications may be a personal key and a corresponding private key, and in some embodiments, the user may be issued a platform ID. The platform device 120 in its local memory (e.g., memory 124) may only store the user's platform ID, a copy of the user's public key, and the association between the two. The platform device 120 does not have to store the user's private key and any personal information that could identify the user in its local memory. In some embodiments, successful registration enables the user to create a dating profile using the platform device 120. Thus, the user may provide dating-related information (e.g., dating profile, dating preferences, social media interaction functions, photos, etc.). In an embodiment, the platform device 120 may store the remainder of the information provided to the platform device 120 by the personal device 120 in a distributed ledger (e.g., personal information, including confirmation information provided during confirmation, such as name, date of birth, gender, dating profile information, etc.). In an embodiment, the information provided by the user (e.g., dating profile, dating preferences, etc.) may be encrypted using the user's public key before being stored in the distributed ledger (or placing or creating a transactional record). In an embodiment, to comply with local data protection laws (e.g., GDPR), the platform device 120 may be configured to store an encrypted version of the personally identifiable information (PII) related to the user in an off-chain storage device (e.g., a private data collection storage device separate from the local memory).In such an embodiment, the platform device may be configured to store the user's public key and / or public key address in the off-chain storage device. In this embodiment, the platform device 120 may be configured to use the user's public key (or public key address) to retrieve and / or identify the information stored in the off-chain storage device.

[0046] Next, the method 300 may also include enabling the user to use the services provided by the platform device 120 in block 330. For example, after the set of keys is provided, the platform device 120 enables the user to initiate a laboratory test request from the laboratory service provider (e.g., laboratory service provider 144) by, for example, initiating a connection with the laboratory service provider 144. Once the user is verified and a set of keys is provided as described above, the platform device 120 may provide the user with the ability to request a laboratory test by, for example, providing a link (e.g., a website link) to the laboratory service provider 144. If the user shows interest in scheduling a laboratory test by, for example, clicking the link, the platform device 120 directs the user to the laboratory service provider 144 to generate a unique ID corresponding to the laboratory test request and transmits the unique ID to the laboratory service provider via one or more APIs. Next, the platform device 120 may associate the user with the unique ID (for example, by associating the public key with the unique ID, or by associating the user's public key address).

[0047] Next, the method 300 may include, upon completion of the laboratory test corresponding to the laboratory test request, facilitating the storage of the laboratory results corresponding to the laboratory test in the distributed ledger in block 340. For example, after the completion of the laboratory test, the platform device 120 may enable the laboratory service provider to map the laboratory test results to the exact user and store the laboratory test results directly in the distributed ledger. For illustrative purposes, when the laboratory results are ready to be viewed, the platform device 120 may receive notification, such as the form of an API call from the laboratory service provider's API. In response to the API call, the platform device 120 may provide the association information between the unique ID and the user, thereby directing the test results to the blockchain network 172 and causing the test results to be stored directly in the distributed ledger, although the platform device does not have to store the test results in its local memory (e.g., memory 124). As described above, the laboratory test results may be encrypted before they are stored in the distributed ledger. The user may be able to view all the information stored in the distributed ledger using the application provided by the platform device 120 and the key stored in the digital wallet.

[0048] Next, the method 300 may include, in block 350, enabling the user to control the distribution of the data stored in the distributed ledger. For example, by using a smart contract and by customizing / changing permissions, the user may share one or more details from their personal details (e.g., name, contact information, location, dating person referral, dating preferences, STD test results) to the other profiles present on, for example, the platform of a dating service provider (e.g., dating service provider 142). The shared details may include the date the test was conducted or the date the results were received, the test results, the type of STD they have (if any), etc. The user may have the option to indicate that they have been tested without explicitly indicating whether they have an STD or not. In that scenario, the user's profile may inform other users that the user has been tested, encouraging other users to reach out to the person and inquire about their STD status. In embodiments, the user does not have to share information about their STD status in their profile; the user may also share their STD test results with other users by smart contract.

[0049] Here, Figure 3 describes the application which requires the user to send the user's COVID-19 status to one or more third parties so that the third parties can determine whether to allow the user to use their facilities. The description of Figure 3 provided in blocks 310 and 320 remains substantially the same, namely the platform device 120 may be required to verify the user and provide the user with a set of keys. In block 330, instead of allowing the user to request laboratory testing related to STDs, the platform device 120 may enable the user to undergo COVID-19 testing. The platform device 120 may enable the user to undergo COVID testing in a similar manner as described above. In embodiments, the platform device 120 may prompt the user to be interested in undergoing the COVID-19 testing in order to submit answers to several questions related to their travel information, such as whether they were around someone who was tested for COVID, etc. The answers to these questions may be stored by the platform device 120 in the distributed ledger. In one embodiment, if the user indicates that they have received a COVID-19 vaccine, the platform device 120 may prompt the user to provide details of the vaccine, such as the date of administration and the type of vaccine administered. All information provided in relation to the vaccine may be stored in the distributed ledger.

[0050] Similar to the methods described in block 340, the platform device 120 may facilitate the storage of the COVID-19 test results in the distributed ledger. The user may control the distribution of the laboratory results data stored in the distributed ledger by providing the user with access to customizable permissions (e.g., via smart contracts) in the application provided by the platform device 120, as described in block 350. For illustrative purposes, using the application provided by the platform device 120, the user may customize or change the smart contract permissions / criteria. The selection of criteria / permissions may control the sharing / distribution of their personal information, including COVID-19 status. These criteria / permissions may control the amount of data being shared, as described above. For example, the user may choose to send only a portion of their test results using smart contracts (e.g., only their COVID-19 status in the form of a badge that may indicate, for example, that the user was tested positive or negative, or recovered after being tested positive, or received a vaccine). Depending on the status, the badge may exhibit different colors or shapes. For example, a green badge or green “check” sign may indicate that the user has been tested and does not have COVID-19. In another example, the badge may display a yellow “check” sign which may indicate that the user has contracted the virus but has recovered. In yet another example, the badge may display a red “cross” sign which may indicate that the user has been tested for COVID-19. In an embodiment, sharing COVID-19 related data may trigger a response in the third-party system (i.e., the system from which the COVID-19 related data was shared). The response may include activating a door that allows the user to enter the facilities of the third-party system. For example, after being tested and having the data secured in the distributed ledger from the laboratory service provider, the user may attempt to enter the third-party real-world facility.To do so, the user may use the smart contract to share a green badge with the third-party system indicating that the user does not have COVID-19. As a result of the sharing of the green badge, the third-party system may activate the door that allows the user to enter the third-party system's facilities.

[0051] The above disclosures may be applicable to systems used to share personal data, including: first and last names; social security numbers; driver's license numbers and information; employers and employment status; salary; financial records and information; marital status; home address; email addresses such as name.surname@company.com; health records; identification card numbers; location data (e.g., location data function on a mobile phone); Internet Protocol (IP) addresses; cookie IDs; telephone advertising identifiers; data held by hospitals or physicians that could be symbols that uniquely identify a person; and personal details related to smart (e.g., IoT) devices (thermostat settings, payment information, preferred door lock codes, preferred security codes, water temperature, Bluetooth, lighting settings, streaming music and entertainment services, shades, wake words). (The list disclosed above is not exhaustive and is not limited.) One or more of the above personal data may be shared in different environments or settings or service providers.

[0052] In one example, details relating to the user could be linked to a controlled user profile by the application provided by the platform device, which could be used further, for example, in different settings (e.g., in a hotel room). In such a scenario, the user's preferences for each smart device in the hotel room would be activated by a smart contract upon check-in and deactivated each time the user leaves the room. In such a scenario, the hotel would have no access to the personal data or user preferences described in this example, or these preferences would not be stored in any hackable centralized database owned or maintained by the hotel, and the user would thus maintain complete control over what they want, how they want it, and who and what they want to share, for as long as they wish to share it. Therefore, the foregoing considerations in this specification regarding users accessing, protecting, and sharing personal medical data in a dating environment should not be construed as limiting in any way.

[0053] The above disclosure describes the protection, access, and sharing of medical data (e.g., STD status). Embodiments of the disclosure are configured such that the system described herein may be configured to comply with various regulatory schemes, such as the Health Insurance Portability and Accountability Act (HIPAA). In other cases where personal data is shared, the system may be configured to comply with regulations relating to the shared data, such as the General Data Protection Regulation (GDPR). Needless to say, the system may also be configured to comply with other regulations relating to the sharing of personal data.

[0054] A person skilled in the art will further recognize that storing data in the distributed ledger includes creating transactional records in the distributed ledger. A person skilled in the art will further recognize that the various exemplary logic blocks, modules, circuits, and algorithmic steps described herein in connection with the present disclosure may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interoperability between hardware and software, various exemplary components, blocks, modules, circuits, and steps have been generally described above with respect to their functions. Whether such functions are implemented as hardware or software depends on the specific application and design constraints imposed on the overall system. A person skilled in the art may implement the functions described above in a varied manner for each specific application, but such implementation decisions should not be construed as causing a departure from the scope of the present disclosure. A person skilled in the art will also readily recognize that the order or combination of components, methods, or interactions described herein is merely illustrative, and that components, methods, or interactions of various aspects of the present disclosure may be combined or performed in ways other than those exemplified and described herein.

[0055] The functional blocks and modules in Figures 1 and 2 may include processing units, electronic devices, hardware devices, electronic components, logic circuits, memories, software code, firmware code, etc., or any combination thereof. In accordance with the foregoing, the various exemplary logic blocks, modules, and circuits described herein in connection with this disclosure may be implemented by general-purpose processing units, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, or any combination thereof, designed to perform the functions described herein. The general-purpose processing unit may be a microprocessor, but in other ways, the processing unit may be any conventional processing unit, controller, microcontroller or state machine. The processing unit may be implemented as a combination of computer devices, for example, a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in combination with a DSP core, or any other such configuration.

[0056] The functional blocks and their components in the system 100 in embodiments of the present invention may be implemented using a processing unit, an electronic device, a hardware device, an electronic component, a logic circuit, a memory, a data storage device, software code, firmware code, etc., or any combination thereof. For example, one or more functional blocks, or parts thereof, may be implemented as discrete gate or transistor logic, discrete hardware components, or a combination thereof, configured to provide a logic circuit for performing the functions described herein. Additionally or alternatively, if implemented in software, one or more of the functional blocks, or parts thereof, may include code segments operable in a processing unit to provide a logic circuit for pre-forming the functions described herein.

[0057] Furthermore, the various components of system 100 are shown as single, separate components. However, each of the various components shown may be implemented as a single component (e.g., a single application, a server module, etc.), or as a functional component of a single component, or the functions of these various components may be distributed across multiple devices / components. In such a configuration, the functions of each component may be aggregated from the functions of multiple modules present in a single device or multiple devices.

[0058] Steps of methods or algorithms described in connection with this disclosure may be implemented directly in hardware, in a software module executed by a processing unit, or in a combination of the two. The software module may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disks, removable disks, CD-ROMs, cloud-based storage devices, or any other form of storage media known in the art. An exemplary storage medium is coupled to the processing unit so that the processing unit can read information from and write information to the storage medium. In other cases, the storage medium may be integrated into the processing unit. The processing unit and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal, base station, sensor, or any other communication device. In other cases, the processing unit and the storage medium may reside as discrete components in a user terminal.

[0059] In one or more exemplary designs, the described functions may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored or transmitted as one or more instructions or codes in a computer-readable medium. Computer-readable media include both computer storage media and communication media, including any media that facilitate the transmission of computer programs from one location to another. The computer-readable storage media may be any available media accessible by a general-purpose computer or a dedicated computer. Such computer-readable media may include, but are not limited to, RAM, ROM, EEPROM, CD-ROM, or other optical disk storage devices, magnetic disk storage devices, or any other media that can be used to carry or store desired program code means in the form of instructions or data structures, and that can be accessed by a general-purpose computer or a dedicated computer, or by a general-purpose or dedicated processing unit. Connections may also be appropriately referred to as computer-readable media. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, or digital subscriber line (DSL), then the coaxial cable, fiber optic cable, twisted pair, or DSL is included in the definition of media. As used herein, disks and discs include compact discs (CDs), laser discs, optical discs, digital multipurpose discs (DVDs), floppy discs, and Blu-ray discs, where a disk typically reproduces data magnetically, and a disc reproduces data optically using a laser. The above combinations should also be included in the scope of computer-readable media.

[0060] While the present invention and its advantages have been described in detail, it should be understood that various changes, substitutions, and modifications can be made herein without departing from the spirit and scope of the invention as defined in the appended claims. Furthermore, the scope of this application is not intended to be limited to specific embodiments of the processes, machines, manufactures, compositions, means, methods, and steps described herein. As those skilled in the art will readily recognize from the disclosure of the invention, existing or subsequently developed processes, machines, manufactures, compositions, means, methods, or steps that perform substantially the same functions or achieve substantially the same results as the corresponding embodiments described herein may be utilized in accordance with the invention. Accordingly, the appended claims are intended to include within their scope such processes, machines, manufactures, compositions, means, methods, or steps.

Claims

1. Access an external identity verification service to verify the real-world identity of the platform device user. In response to the successful verification resulting from the external identity verification service, the user is provided with a public key and a private key corresponding to the public key, wherein the private key provided to the user is not stored in the local storage device of the platform device. Initiate a connection with a third-party system where user data is stored. Using the public key, the user data is encrypted to create encrypted data. By directly storing the encrypted data mapped to the user in the distributed ledger, the storage of the encrypted data in the distributed ledger is made easier. By providing the user with access to a customizable set of permissions, the sharing of the first data retrieved from the encrypted data stored in the distributed ledger is controlled, and A system for controlling the sharing of user data, including a platform device configured to share the first data obtained from the encrypted data with another third-party system based on the set of customizable permissions, wherein the set of customizable permissions includes at least one permission that causes the other third-party system to take action based on the first data.

2. In response to the successful verification, the platform device generates a platform ID specific to the user. Provide the user with access to the aforementioned set of customizable permissions, The system according to claim 1, further configured to associate the platform ID with the user's public key, and to identify the user from the platform ID within the platform device based on the association.

3. In initiating the connection, the platform generates a unique ID corresponding to the initiation of the connection, associates the user's public key with the unique ID, identifies the user from the unique ID within the platform device based on the association, and The system according to claim 1, further configured to transmit the unique ID to the third-party system.

4. The system according to claim 1, wherein the platform device is further configured to provide the user with a graphic user interface, and the graphic user interface provides functions to enable the user to initiate the connection with the third-party system.

5. Facilitating the storage of the encrypted data includes storing the encrypted data in the distributed ledger according to instructions, and the instructions are Receiving notification from the third-party system that the encrypted data is available, The system according to claim 1, further comprising providing the distributed ledger with association information between a unique ID corresponding to a request from the third-party system and the user's public key in response to the notification.

6. The system according to claim 1, wherein the platform device is configured to facilitate the storage of the encrypted data corresponding to the user in the distributed ledger by directly storing the encrypted data mapped to the user in the distributed ledger after receiving notification from the third-party system that the encrypted data is available.

7. The system according to claim 6, wherein the notification includes a notification in the form of an application programming interface (API) call.

8. The system according to claim 1, further comprising a digital wallet corresponding to the user, wherein the digital wallet is configured to store the private key.

9. A device for controlling the protection and sharing of user data, Includes a memory and at least one processing unit connected to the memory, The at least one processing unit accesses an external identity verification service to verify the real-world identity of the platform device user, In response to the successful verification resulting from the external identity verification service, the user is provided with a public key and a private key corresponding to the public key, wherein the private key provided to the user is not stored in the local storage device of the platform device. Initiate a connection with the third-party system where the user data is stored. Using the public key, the user data is encrypted to create encrypted data. By directly storing the encrypted data mapped to the user in the distributed ledger, the storage of the encrypted data in the distributed ledger is made easier. By providing the user with access to a customizable set of permissions, the sharing of the first data retrieved from the encrypted data stored in the distributed ledger is controlled, and A device configured to share the first data obtained from the encrypted data with another third-party system based on the set of customizable permissions, wherein the set of customizable permissions includes at least one permission that causes the other third-party system to perform an action based on the first data.

10. In response to the successful verification, at least one processing unit generates a user-specific platform ID. Provide the user with access to the aforementioned set of customizable permissions, The apparatus according to claim 9, further configured to associate the platform ID with the user's public key and to identify the user from the platform ID within the platform device based on the association.

11. At the start of the connection, the at least one processing unit generates a unique ID corresponding to the start of the connection. The apparatus according to claim 9, further configured to associate the user's public key with the unique ID, to identify the user from the unique ID within the platform device based on the association, and to transmit the unique ID to the third-party system.

12. The apparatus according to claim 9, wherein the at least one processing unit is further configured to provide the user with a function that enables the user to initiate the connection with the third-party system via a graphical user interface.

13. Facilitating the storage of the encrypted data includes storing the encrypted data in the distributed ledger according to instructions, and the instructions are Receiving notification from the third-party system that the encrypted data is available, The apparatus according to claim 9, further comprising providing the distributed ledger with association information between a unique ID corresponding to a request from the third-party system and the user's public key in response to the aforementioned notification.

14. The apparatus according to claim 9, wherein the at least one processing device is configured to facilitate the storage of the encrypted data corresponding to the user in the distributed ledger by directly storing the encrypted data mapped to the user in the distributed ledger after receiving notification from the third-party system that the encrypted data is available.

15. The apparatus according to claim 14, wherein the notification includes a notification in the form of an application programming interface (API) call.

16. The apparatus according to claim 9, wherein the at least one processing device is configured to provide a digital wallet, and the digital wallet is configured to store the private key.