SERVER-BLIND TRUST CIRCLE-BASED PERSONAL SECURITY SYSTEM
Patent Information
- Application Number
- TR202613825
- Authority / Receiving Office
- TR · TR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-08-14
- Publication Date
- 2026-09-21
Smart Images

Figure 00000051_0000 
Figure 00000052_0000 
Figure 00000053_0000
Abstract
Description
1 TARIFF SERVER-BLIND TRUST CIRCLE-BASED PERSONAL SECURITY SYSTEM TECHNICAL AREA 5 This invention enables computer-assisted personal security systems and secure data sharing. security integrated with mobile communication systems and wearable devices. applications, event-triggered emergency management systems, distributed communications It relates to the technical field of architectures and cryptographic data protection technologies. The invention specifically involves the user's location, status, physiological data, and device status. The data is cryptographically protected so that it cannot be accessed as plain text on the server side. protected and shared among members of the circle of trust, different events Evaluation of trigger information obtained from sources, communication Automatic selection of the appropriate communication channel according to the infrastructure status, 15 integrated operation with wearable devices and authorization processes integrated personal data that enables access control through cryptographic means It is related to the security system and method. STATE OF THE ART Today, mobile applications developed for personal security purposes are wearable. devices and cloud-based communication systems; users' location information sharing information, building a circle of trust, reporting emergencies, health monitoring of data and sending 25 predefined individuals in response to specific events widely used for sending automatic or semi-automatic notifications These systems utilize mobile communication infrastructures and short-range capabilities. wireless communication technologies, wearable sensors, cloud services, and various encryption methods. These methods are used together, addressing various technical problems. Solutions are offered. However, upon examination of the solutions, it is found that these functions number 30. mostly developed as independent systems, user privacy, event triggering mechanisms, access authorization, communication 2 Technical aspects such as continuity and multi-device management are integrated into a single system. It appears that they are not considered together within the context of architecture. Mobile devices that provide family / friend location sharing and danger notification using known technology. Applications are available. These systems include geofencing and hazard sound 5. While features such as detection and context-aware access control are available, the user The data is stored as plain text on central servers or can be decoded by the server. The data is processed in this way; therefore, the server operator technically has the authority to process users' data. They can access location and status data. Additionally, these platforms require member permissions. They are managed as simple access lists maintained at the application layer, and a 10 Modifying or revoking a member's access rights involves any cryptographic... This does not produce any results. Therefore, a member whose access rights have been revoked has previously... the technique of cryptographically blocking access to the data categories it can access They are not experiencing any difficulties. Mass crisis notification features offered on social media platforms, disaster It allows users in the region to report their status. However, this The systems are triggered manually by the user, and there are multiple external Automatic triggering based on verification of disaster data source, recognized by the user. The gradual response window varies from device to device in case of network disconnection. features such as automatic escalation via wireless relay and server-blind encryption guarantee. It does not include these features. Fall detection and emergency features offered by smartwatch and mobile device manufacturers. Situational call systems, on the other hand, detect individual user events at the device level. 25 It sends notifications to pre-determined emergency contacts. In these systems... Assessment of heart rate or similar physiological parameters is often It is based on fixed or device-wide threshold values. Therefore, it is personalized. personalized therapy based on deviations from physiological and behavioral norms Anomaly detection, a multi-party and cryptographically protected circle of trust structure, 30 Automatic triggering integrated with external disaster data sources or disconnected. There is no device-to-device relay network-based communication mechanism. 3 Known solutions regarding device-to-device emergency relay mechanisms, modern key based on sealed encryption to the recipient's public key change, event-triggered group key renewal or age and driver's license status It does not include linked access control. Similarly, multi-key threshold encryption. Solutions that address their containers provide general-purpose secure data storage. 5 It aims to and works with data obtained from wearable devices, disaster triggered emergency escalation or age-graded parental co-membership It is not aimed at automation. In the field of server-blind multi-party trust circle architectures, each member device has 10 It carries a static public / private key pair, per member only on the server side. where the encrypted dynamic circle key and circle policy context are stored, In case of member departure or policy change, the relevant key will be re-encrypted. The systems in which it is distributed are known. However, in these systems; (a) data Multiple independent keys mathematically separated by category 15 (b) role-based permission is used instead of context, a single dynamic circle key is used. The levels are directly related to the cryptographic key contexts belonging to specific data categories. It is not associated, therefore permission changes do not automatically affect data access. (c) these architectures do not affect external disaster data sources at the cryptographic level. automatic triggering, personalized physiological or behavioral anomaly detection, 20 Wireless relay network from unconnected device to device, brand-independent wearable device data. normalization or age-graded parental joint membership automation integrated It does not work in this way. Therefore, in the known technique, precise location and status data is transmitted by the server within 25 days. It remains accessible, with access permissions only at the application layer. Due to its management, the denial of access cannot be cryptographically forced, and especially in scenarios where disaster or communication infrastructure is disabled, the user a connection that can maintain access to members of the circle of trust without requiring intervention. Technical problems such as the lack of a responsive automatic escalation mechanism 30 It continues. 4 "Cloud Provider" with release number US12067119B1, in the known state of the art. Cryptographic information about secure areas used to process user data on the network. The patent titled "Ensuring Verification of Cloud Service Providers" users' user data is not encrypted or otherwise vulnerable 5 trusted providers for processing user data during limited time periods. verifying the use of "secure zones" through cryptographic verification. The techniques that enable this are explained. A cloud service provider uses user data. Requests containing this information are processed at least partially using a safe zone; the safe zone, Isolated information of a host device managed by a cloud provider. It includes a virtual machine running on processing resources. For example, the secure zone is a 10 Decrypting user data included in requests sent to the service (for example, Transport Layer Security established between the service and the client computing device. (User data encrypted as part of a TLS connection), a key management Obtaining user-specific encryption keys from the service or another source, using encryption keys to encrypt user data and store encrypted data 15 It may include an application that performs operations such as forwarding for further processing.” It has been summarized as follows. In conclusion, in the known technique; (i) a fully server-blind, multi-party circle of trust architecture, a single 20 based on an authenticated encryption algorithm, but categorized by data categories. According to [the source], it works with contextually separated cryptographic keys. (ii) based on the consensus of multiple prioritized external disaster data sources automatic triggering, user-approved status notification, and disconnection-sensitive features. the gradual escalation mechanism, 25 (iii) age-appropriate parental co-membership for underage users account verification mechanism based on, (iv) role-based permission levels defined by the circle owner belonging to data categories directly associated with cryptographic key contexts and permission changes a sharing control that automatically affects data access at a cryptographic level 30 There is no integrated system that presents both mechanisms together. DEFINITION OF INVENTION The present invention eliminates the aforementioned disadvantages and the related technical Server-blind trust circle based technology developed to bring new advantages to the field. It is related to the personal security system. The invention solves the above problems under a single, consistent server-blind architecture. It solves it with complementary subsystems. All encryption / decryption takes place on the client device. This is done; the server infrastructure only stores encrypted data blocks and converts them to plain text. cannot access. The circle's shared key is unique to each member's public key. It is distributed after being sealed. 10 Deriving a contextually decoupled key from a circle root key. With this function, general data and sensitive data are mathematically distinct from each other. Two independent key contexts are derived; both are single-authentication encryption. It is processed by the algorithm. Role-based permission level, key 15 that the member can access. It determines its context cryptographically; permission change event-triggered key This triggers a renewal and renders the member whose permission has been revoked cryptographically inaccessible to the data. income. Prioritized multi-source consensus of disaster-risk data source with client-20 biased position comparison or deviation from the user's personal baseline Device-based state deviation detection, a common automatic sharing, state It triggers the notification and response window mechanism. No confirmation can be obtained, and only the network... If there is no connection, the connection-sensitive module is a thin and data-rich layered device. The device initiates a gradual escalation via relay and short message service. Brand-25 Agnostic normalization combines data from different brands of wearable devices into a common schema. It translates. Age-graded verification and parental co-membership enable minors to participate. It provides security; category-based cryptographic consent complements privacy. The user-initiated SOS trigger can reach any paired brand 30 It can also be transmitted via a wearable device and enters the same escalation line as the phone. In cases where it is disconnected or unreachable, its own independent cellular wearable device with connection, cross-device prioritization / takeover module 6 It automatically takes over the transmission via the drop / impact pattern for a circle member. Compound state trigger, notification, which is evaluated together with subsequent inactivity. not the entire circle, but a pre-authorized prioritized notification subset It provides guidance; this assessment is made regardless of the user's age. The purpose of the invention is to collect user's location, status, physiological data and device status. the data and the decryption keys associated with the data were not transferred to the server infrastructure and all encryption and decryption processes are performed on user devices. The goal is to ensure data sharing through a server-blind circle of trust architecture. This allows even the party operating the system to have access to the user's location and status data. inaccessible, user privacy is only governed by application policies or administrative regulations. a personal security system that relies not on access rules, but directly on the cryptographic structure. The system is obtained. Another aim of the invention is to create context identifiers different from the circle root key. 15 general purpose data is used, as well as sensitive data such as location, status, and physiological data. mathematically independent keys for data categories The goal is to enable the derivation of contexts. This allows different data categories to be grouped into a single, unified whole. while protected under a consistent authenticated encryption structure, the key If one of these contexts is revealed or its security is weakened, the other 20 This prevents key contexts from being affected. Another purpose of the invention is to provide the circle owner with a permanent and role-based system for each member. It can assign an access level, and the access level corresponds to the data category that the member can access. 25 a sharing control mechanism that determines the associated cryptographic key context This ensures that member permissions are kept only at the application level. Instead of managing it with access logs, the relevant key context of the permission change renewal and redistribution only to members with ongoing access authorization This results in a structure that is automatically triggered. Thus, access authorization is granted. A member whose access to new data has been reduced or completely removed will be cryptographically protected for 30 days. Blocking and revoking permission is more than just an interface or database change. is being removed. 7 Another purpose of the invention is to enable the key renewal process to utilize all previously stored keys. without requiring the re-encryption of the encrypted data, the relevant data key by renewing and redistributing the key to authorized members after re-encryption This is how it is performed. In this way, the key renewal process load is transferred to the stored data. This prevents the transaction load from increasing depending on the volume, and the transaction load is primarily based on trust. 5 is limited by the number of members in its circle and the system's wide user base It enables scalable operation within the groups. Another purpose of the invention is to collect data from one or more external disaster data sources. and preferably through resource prioritization or consensus among resources 10 Based on the evaluation of verified disaster data, the user's disaster whether or not it is located in the affected area is checked on the user client device. an automated security process based on identification and evaluation This is how it is initiated. This allows the user to also create a manual emergency notification. without needing to create one, it displays information such as location, status indicator, and device battery information. Automatic transmission of data to members of the trust circle and notification of the user's status. A response window is provided where the user can confirm their response. Another purpose of the invention is to obtain confirmation of status from the user within a specified time period. If it cannot be received and it is determined that the primary network connection is unavailable, 20 device-to-device wireless relay network, short message service and other suitable communication It involves activating a gradual escalation mechanism through these pathways. this allows users to function in situations such as disasters or disruptions to communication infrastructure. Emergency data to trust circle members without the need for intervention 25 It is ensured that it does not remain. Another purpose of the invention is to enable communication between unconnected devices within a limited range. a thin layer of broadcast carrying an emergency signal and identification information is connected Following its installation, it carries more comprehensive data such as location, status, and battery information. A layered emergency data transfer system that uses a rich data layer in conjunction with it. The aim is to provide this structure. This allows for a reduction in the size of short-range wireless transmission packets. 8 More detailed emergency information will be provided where communication is possible, while adhering to the restrictions. The transmission of data is made possible. Another aim of the invention is to obtain physiological and motor data from wearable devices. data, user history and user's current activity status 5 by comparing with personal baselines created by taking these into consideration It involves detecting physiological abnormalities. This allows for the application of these methods to all users. Instead of fixed or device-general threshold values, the user's resting, walking, and running... or normal values specific to similar activity levels are taken as a basis and only Reporting of significant and sustained deviations from the personal normal range. 10 This ensures its creation. Another purpose of the invention is to obtain information from the user's location and movement history. evaluation of routine data and any significant and persistent deviation from the routine. The goal is to create a behavioral abnormality signal if this occurs. In this way, 15 only fixed geographical boundaries or predefined unique location rules Instead, the user's own behavioral patterns are taken into account and the usual temporary or minor deviations from movements creating unnecessary notifications This helps to reduce the false alarm rate. Another purpose of the invention is to detect falls or impacts. joint assessment of the immobility following the incident and, if necessary a composite early intervention signal supported by physiological data This allows for the creation of an alarm based on only a single sensor measurement. Instead of creating a system, 25 different sensor and motion data that corroborate each other are combined. assessment is provided, especially for the elderly or those requiring care. This provides a more reliable early intervention mechanism for users. Another purpose of the invention is to treat physiological abnormalities, falls, injuries, or immobility. Instead of sending notifications about the incidents to all members of the trust circle, This involves referring the matter to previously authorized maintenance circle members. In this way, 30 Unnecessarily large amounts of user's sensitive health and status data This prevents the emergency information from being shared with the response team, and only the intervention team is informed. This information is then forwarded to authorized caregivers. 9 Another purpose of the invention is to integrate smartwatches, health bands, and other products from different brands and models. physiological, movement and emergency data obtained from similar wearable devices It involves converting the data into a common data schema. This allows the system to tailor a specific wearable device to a particular user experience. 5. Preventing dependence on a device brand or a closed device ecosystem and different devices are being integrated under a single, unified circle of trust structure. It is made available for use. Another purpose of the invention is to enable user-initiated emergency triggering. not only via mobile phone, but also via a wearable device paired with the user. 10 It can also be created via and triggered by disaster or anomaly triggers. It is included in the same status reporting and gradual escalation line. This allows Emergency situations also occur when the mobile phone is not near the user or is unusable. This enables the initiation of the process. Another purpose of the invention is to restore the mobile phone's network connection in an emergency. that it is not present, that it is switched off, that its battery is dead, or that it is a wearable device If it is determined that the connection has been interrupted, independent cellular communication The wearable device has the feature to automatically transmit emergency data. It is the takeover of emergency transmission. This allows emergency transmission to be linked to a single user device. This prevents the problem from occurring and ensures prioritization between predetermined devices. And communication continuity is ensured through the takeover mechanism. Another purpose of the invention is to provide relief from disasters, physiological abnormalities, behavioral deviations, and falls. or when a user-initiated emergency trigger occurs, 25 The visibility of the user's posts that experienced the trigger is predefined. It is an upgrade for a limited period. This allows for limited use during normal operation. Members with access rights can only use necessary user accounts during the emergency period. to access the data and return to the previous access level at the end of the specified period Automatic rotation is enabled. 30 Another purpose of the invention is to provide temporary visibility enhancement only in the application. It should not be limited to a permission change made at the layer and a preferred one. In the application, the relevant sensitive data key is authorized during the emergency period. cryptographically by re-encrypting with the members' public keys This is to be implemented. In this way, emergency access is ensured alongside the implementation policy. This is also ensured by limiting the distribution of cryptographic keys. Another aim of the invention is to enable young users to participate in the system regardless of age. information is evaluated on the user client device and age level conversion and server infrastructure to only the relevant age instead of the raw date of birth This is accomplished by transmitting the information at each level. In this way, personal information regarding age is provided. This prevents data from being unnecessarily stored on the server side, and saves a small amount of money. Age-appropriate account management is provided for users. Another purpose of the invention is to manage the accounts of users in a specified age group. being linked to a parent or guardian account and participating in the circle of trust. The transactions are subject to parental or guardian consent. A preferred 15 In practice, access to the minor's sensitive data key must be granted by a parent or guardian. parental supervision by basing the account on a cryptographic co-signature. It should be transformed from being merely a confirmation record in the application interface into a cryptographic one. It is ensured that it becomes part of the access process. Another purpose of the invention is to analyze data relating to location, status, and other sensitive data categories. Obtaining explicit consent separately, consent given being for single use only. Confirmed with a verification code and the consent record is protected against alteration. This involves recording the audit summary chain. Verification in a preferred application. The code includes 25 as the cryptographic input when decrypting the relevant sensitive data key. by using it, consent verification does not remain merely an administrative record and It is linked to technical key management. Another purpose of the invention is membership, permission, and key transactions carried out within a circle of trust. Renewal, data sharing, and consent processes must be cryptographically matched to the previous record. 30 The associated insertion is stored in a single audit summary chain. This allows to determine whether past transaction records have been subsequently altered and 11 verifying the integrity of transactions that are important from a security perspective is provided. Another purpose of the invention is server-blind encryption, separated by data category. Key management, role-based cryptographic access control, disaster and anomaly 5 Triggered automatic sharing, gradual escalation depending on connection status, device-to-device wireless relay, wearable device normalization, inter-device takeover, age-based parental co-membership, category-based consent and care circle guidance mechanisms under a single integrated personal security architecture The goal is to ensure that they work together harmoniously. This allows for different security measures to be implemented. Privacy, communication, and user management needs are independent of each other. Instead of being met through applications, a common event processing, encryption, It is integrated and managed through authorization and communication infrastructure. A scalable personal security system is obtained. Drawings The present invention, briefly summarized above and discussed in more detail below, applications of the invention, example applications of which are depicted in the attached drawings. This can be understood by referring to the reference. However, the attached drawings only show typical examples of this invention. It describes the applications and inventions, and therefore, other equally effective ones. Since it may allow applications, it cannot be assumed that it limits its scope. It should be noted. To facilitate understanding, indicate the identical elements that are common to the shapes. 25 Identical reference numbers have been used where possible. Figures are to scale. It is not drawn and can be simplified for clarity. The elements of an application and Its features are useful to other applications without needing further explanation. It is thought that it can be included in this way. Figure 1: Integrated general architecture showing all subsystems of the invention together. diagram. Figure 2: Schematic representation of the overall system architecture (server-blind structure). 12 Figure 3: Circle key replacement based on sealing to the receiver's open key. flowchart. Figure 4: A contextually decoupled key from a circle root key. a single, based on general / precise key contexts obtained with a derivation function Schematic diagram of a two-layer encryption architecture with algorithms. 5 Figure 5: Event-triggered and permission-change enabled key storage environment. Triggered switch reset scheme. Figure 6: Keyed cryptographic hash-based, insert-only control hash-chain diagram. Figure 7: Prioritized multi-source external disaster data source agreement and 10 Flowchart of magnitude / radius step function. Figure 8: Response via automatic sharing trigger and status reporting interface. window flowchart. Figure 9: Flowchart of linkage state detection and conditional escalation decision. Figure 10: Two-layer emergency wireless communication architecture (connectionless thin 15 Schematic of the broadcast / linked rich data) and platform-asymmetric relay structure. Figure 11: Diagram of the short message service backup escalation channel. Figure 12: Schematic diagram of the layered emergency data packet structure. Figure 13: Flowchart for age declaration collection and client-side tier calculation. Figure 14: Mandatory parent / guardian account linking flowchart for users below the first threshold 20 diagram. Figure 15: Circle consent request for sub-threshold users, parent / guardian collaboration. Membership registration, parent / guardian information panel, and disaster notification shared communication flow. diagram. Figure 16: Activity-state-specific personal baseline, deviation test, and continuity 25 State deviation detection and co-escalation pipeline based on verification. The flowchart of its trigger. Figure 17: Role-based, cryptographically implemented permission level by user's person when the selected sharing scope and response window are filled without approval Application-layer / operating-system-layer two-stage trigger-30 Flowchart of the overrun. Figure 18: Category-based separate explicit consent texts, code-verified consent record, and consent. Flowchart for feature deactivation based on rollback. 13 Figure 19: Known technical components of the invention (left column) and the contribution of these components to the invention. Showing unique combinations / application points together (right column), originality general diagram highlighting. Figure 20: Disaster / State Deviation from Wearable Device Data Normalization trigger, status notification and response window, confirmation 5 in the response window When not received, it automatically switches to server-blind sharing and incremental escalation, circle until notification and member permission / consent verification to stop sharing a comprehensive system that unifies the end-to-end workflow of the invention on a single diagram flowchart. Figure 21: Emergency (SOS) trigger interface from wearable device and phone 10 transmission via independent cellular connection of the wearable device in case of disconnection the flow of the cross-device prioritization / failover mechanism it has taken over diagram. Figure 22: Drop / impact pattern and continuity verification for a circle member. A composite status trigger based on inactivity detection will appear in the response window at 15. If approval is not obtained, the notification is sent not to the entire circle, but to a previously authorized person. Flowchart that redirects to a subset of priority notifications. Figure 23: Flash limit and validity period control in device-to-device relay network. Flowchart based on multi-hop transmission and access control. Explanation of Details in the Drawings The corresponding reference numbers shown in the figures are given below. 100 — User client device 105 — Circle switch change module 110 — Server infrastructure 115 — Sealed asymmetric encryption engine 120 — General data key context 30 125 — Sensitive data key context 130 — Secure key storage environment 135 — Periodic key renewal module 14 140 — Event-triggered key reset module 145 — Audit summary chain 150 — Hidden key safe 160 — Key context parsing module 165 — Permission-key rewind trigger 5 200 — External disaster data service interface 205 — Magnitude / radius step function 210 — Location-epicenter comparison module 215 — Automatic sharing trigger 220 — Status reporting interface 10 225 — Response window timer 230 — Connection status detection module 235 — Device-to-device wireless relay network 236 — Jump limit and validity period control module 237 — Meter upgrade and transmission module 15 238 — Access control module 240 — Binary matching subsystem 245 — Short Message Service Gateway 250 — Layered emergency data package 255 — Thin broadcast substrate 20 260 — Multi-source disaster agreement module 265 — Personal Status Baseline Module 270 — Activity / movement status classifier 275 — Deviation decision module 280 — Continuity verification module 25 285 — Behavioral / routine baseline module 300 — Age declaration interface 305 — Level calculation module 310 — Parent / guardian account linking module 315 — Circle approval request engine 30 320 — Parent / Guardian Information Panel 325 — Periodic re-validation module 500 — Device sensor data acquisition module 505 — State deviation detection module 510 — Brand-agnostic data normalization module 600 — Sharing / permission level control module 605 — Role-based permanent permission assignment module 610 — User-selected sharing scope module 5 615 — Application-layer trigger-overflow module 620 — Operating system layer pre-authorization request module 625 — Triggered switch rewind module 630 — Parent / guardian cryptographic co-signature module 635 — Consent-key binding module 10 640 — Priority notification subset definition and routing module 645 — Drop / impact pattern and immobility detection module 700 — Category-based consent presentation module 705 — Approval code production and shipping module 710 — Code verification interface 15 715 — Consent record 820 — Wearable device SOS trigger interface 825 — Device-to-device prioritization / takeover module 830 — Wearable device-independent cellular transmission pathway DETAILED EXPLANATION OF THE INVENTION This detailed explanation includes the preferred alternatives to the design of the invention. purely for the purpose of better understanding the subject and without any limiting influence It is explained in a way that will not create. 25 User client device (100): All encryption / decryption and client-side It is the device on which the processes are carried out. Reason for its criticality: the fundamental technology of the element. It is known that its role in the invention is related to all encryption / decryption and triggering decisions. The only 30% guarantee on which the server-blind warranty is based is that it is executed on this device without exception. It is the point of execution. 16 Circle key exchange module (105): Members of the circle's common key It securely establishes and distributes funds between them. The critical point: the key exchange technique. Although it is known, the role of the circle in the invention was never given to the server. It is the distribution without providing it as plain text; a server-blind of a multilateral circle. Its establishment depends on this distribution method. 5 Server infrastructure (110): Stores only encrypted data blocks; cannot access plain text. (Server-blind). Reason for criticality: the server encrypts the circle membership metadata. Although it can associate with blocks, it cannot under any circumstances access the plain text content of these blocks. The inability to access it is due to cryptography, not the privacy policy in the invention. 10 This is a direct response to the claim on which it is based. Sealed asymmetric encryption engine (115): Circle key public for each member It seals each key separately. The critical reason: sealing is done separately for each member. Since this was done, in the event of a member's expulsion or revocation of their authorization, only 15 Re-sealing the remaining members will suffice; event-triggered key The fact that the refresh rate remains independent of the stored data volume is based on this structure. General data key context (120): Contextualizing general purpose data with an independent key It protects. Reason for being critical: known server-blind circle architectures protect data category 20. It uses a single, independent dynamic circle switch; the general data is in a separate context. the retention of a member with restricted permissions to continue accessing circle metadata It is the structural distinction that prevents cryptographic access to sensitive data. Sensitive data key context (125): Location / status data from general context 25 Protects with an independent key. Reason for being critical: role-based permission assignment module (605) This is the target context to which the level is cryptographically linked; when the permission is dropped. The regenerated key belongs to this context, therefore the permission revocation came from the server. Its ability to be applied independently depends on the separate existence of this context. Secure key storage environment (130): Without removing the private key from the device It stores it securely. The critical reason: the private key is stored in the device's secure hardware. 17 The server-blind guarantee is only valid if the device is kept within its environment and not transferred outside of it. This allows it to withstand not only the limitations of software discipline but also the limitations of hardware. Periodic key renewal module (135): Device keys are predefined It renews in the period. 5 Event-triggered key renewal module (140): Member removal or permission level In the event of a change, the relevant key does not need to wait for the periodic renewal cycle. It instantly recreates the context; the renewal only applies to the remaining part of the new key. This is completed by re-wrapping the members' public keys, past 10 The data is not re-encrypted. Reason for criticality: permission revocation by the server. enabling its implementation without verification, purely cryptographically and without delay. This is the mechanism; the member whose permission has been revoked does not need to take any action from the server. Without this, it becomes impossible to access the data. Audit summary-chain (145): Events cannot be modified, insert-only in the chain It records. The reason it's critical is: each event is chained to the summary value of the previous one. It prevents the retroactive alteration of past records; permission and consent In an architecture where changes are cryptographically enforced, these events recording the information in a verifiable manner allows the claim to be verified later. 20 provides. Secret key safe (150): Protects the secret key of the chain of command Key context parsing module (160): A key from a circle root key With the derivation function, 25 different elements, each carrying a different context identifier, are created. mathematically independent general (120) and precise (125) key contexts It derives. The reason it's critical: even though the same encryption algorithm is used in a single context, it can be used in two contexts. Thanks to the mathematical independence of context, a possible leakage of one context prevents the leakage of another. It does not affect; this is data categories without requiring the use of different algorithms. It is the point that provides cryptographic isolation between them. 30 Permission-key rewind trigger (165): Key rewind trigger for permission level change It cryptographically links to the renewal process. The reason it's critical: permissions are not allowed in known systems. 18 The change is simply a flag update at the application layer and nothing else. It does not produce a cryptographic result. This trigger is event-triggered with a permission change event. It establishes the automatic and mandatory link between the key renewal module (140); permission This is the mechanical basis of the claim that its cancellation can only be forced cryptographically. External disaster data service interface (200): External earthquake magnitude / epicenter information. It gets it from the source. Reason for its critical importance: known mass crisis notification features for the user. It is manually triggered by; this interface allows the trigger to be generated by external and objective data. by connecting to the source, the notification starts without user intervention. It is the entry point that makes it possible. 10 Size / radius step function (205): Impact threshold to size It determines it according to... The reason it's critical: its magnitude is determined not by a single fixed threshold, but by magnitude itself. It matches the band with a graduated radius of influence corresponding to these threshold values. It can be remotely configured on the server side; thus, trigger sensitivity can be adjusted according to the application. 15 It scales according to the severity of the event without needing to be updated. Location-epicenter comparison module (210): Impact on the client Accounts; location data does not go to the server. Reason for being critical: the decision to be affected. The notification must be delivered entirely on the client device; 20 is required for disaster-triggered notification to function. This eliminates the need to transmit the user's location to the server; server- The point that ensures blind architecture remains intact even in the disaster subsystem. This is it. Automatic sharing trigger (215): Location / status indicator / battery on trigger 25 It automatically shares its data. The critical point: two independent triggers. its sole source (external disaster data and client-side personalized state deviation) It is a junction where they converge at a common point of sharing; sharing is user intervention. Since the notification is the only element that initiates it without any prior notification, the user will not be able to respond. It happens even if that's the case. 30 Status reporting interface (220): Provides the user with a "I am fine" confirmation. 19 Response window timer (225): Manages the defined time for confirmation. Critical Reason: The response window is the only gateway between triggering and escalation; confirmation. Receiving it completely prevents sharing, while not receiving it prevents sharing and (disconnection). (provided that) it activates the escalation. The false alarm is silently triggered by the user. Automatic progress in a real emergency with the same timer 5, which can be switched off. It is balanced through this. Connection status detection module (230): Escalation only when no connection is present. It opens. The reason it's critical: the relay and short message escalation is not unconditional, but requires two. The condition (failure to receive confirmation in the response window AND lack of connection) together constitutes 10 It is linked to the occurrence; escalation is not triggered while the link exists, the link When re-established, the ongoing relay broadcast is terminated and the server-blind channel is activated. This dual condition constitutes the distinguishing limit of the claim according to the known technique. Device-to-device wireless relay network (235): Device-to-device data transmission in case of disconnection 15 It transmits a predefined, configurable jump limit (N) and validity period. It operates with (TTL). The critical reason is that the relay network is platform-asymmetric: one operating system one family built a multi-hop relay backbone based on the store-and-forward principle, while the other It functions solely as an end node; this asymmetry is not an arbitrary design choice, but background. It is the embodiment of a real platform limitation arising from broadcast space constraints. Network 20 also from the dual pairing subsystem between the user’s own phone (240) Architecturally, it is separate and independent. Jump limit and validity period control module (236): Packet jump the timer and its validity period (TTL) reach a predefined limit of 25 It checks if it has arrived; it drops the packet that has reached the limit or deadline. It is critical. Reason: Instead of leaving the multi-hop relay network as future work, the hop The limit is included in the scope of the invention as a configurable parameter (N≥1). the inability to expand the scope after sufficient explanation and application It is important in terms of... 30 Meter boosting and transmission module (237): Jumping as long as the jump limit is not exceeded It increments the counter by one and passes the packet to the next intermediary device; the intermediary device receives the packet. It cannot decipher its content. The critical reason: it enables multi-hop transmission while acting as an intermediary. The device's inability to handle the load it carries means that the server-blind guarantee also affects the relay network. It is an expansion; an increase in the number of intermediary devices does not change this feature. Access control module (238): The packet's destination environment, i.e., short message service 5 checks whether the packet has reached the gateway (245); if it has not, forwards the packet to the next one. It transmits the signal back to the device. The reason it's critical: blind transmission in the relay chain. not the act of doing it, but its termination according to the condition of reaching a defined target environment. It provides; thus, with hop limit and validity period control, the network is both finite. This ensures that it remains purposeful. 10 Dual matching subsystem (240): Device-phone matching from relay network It provides it independently. Short message service gateway (245): Two-way (server / device) short message 15 It enables escalation. Critical reason: server-side networking in limited connectivity situations. In a true zero-connection scenario where there are no connections at all, the gateway of the device The native short message capability provided by the operating system as a last resort channel. It is used; the circle even in a scenario where one-way solutions are completely closed. This is the distinction that keeps it accessible to its members. 20 Layered emergency data packet (250): Thin (SOS) and rich (location / status) The indicator / battery) has two layers. The critical reason: without a connection. The detailed payload transmitted after establishing a connection with the minimum payload that can be published is a single unit. Separation in a packet structure, tiered information according to degree of disconnection 25 enables transmission; battery level information for search / rescue prioritization. In this respect, it provides additional context for circle members. Thin broadcast sub-layer (255): Broadcasts an unconnected, size-limited SOS flag. Critical Reason for not being broadcasting: the broadcast is made without waiting for a connection to be established with the other party and within a limited size of 30. This will consist of an emergency flag and a brief identification summary; This ensures that even in cases of complete disconnection where a session / pairing cannot be established, the signal remains close. It can go out into the environment. 21 Multi-source disaster agreement module (260): Prioritized resources It reconciles. The reason it's critical: the same event reported with different magnitudes or from different sources. If provided with a time frame, the information from the highest priority source shall be taken as the basis. and is later updated with information from a higher priority source; single 5 The risk of incorrect or delayed triggering in source-dependent systems is addressed in this agreement. It is reduced according to the rule. Personal status baseline module (265): User-specific standard range calculations. Reason for the criticality: the baseline is not a device-wide constant, but 10 for each activity. an average calculated from the user's own historical data for this situation and It is a measure of variability; it differs from known systems based on a fixed threshold, and This is where it makes personalized triggering possible. Activity / movement status classifier (270): Resting / walking / running status It separates them. The reason it's critical: the baseline is not a single overall average, but every 15 This makes it possible to calculate it separately for each movement state; high altitude while in motion because it prevents a value from being compared with the resting threshold, whether fixed or device- It eliminates the root cause of false alarms in systems based on general thresholds. Deviation decision module (275): Determines the above-threshold deviation. Reason for being critical: deviation 20 The decision is based not on an absolute value, but on the user's relevant activity status. It is based on the statistical distance from the threshold; this threshold varies from individual to individual and situation to situation. It allows for automatic scaling to the situation. Continuity verification module (280): Verifies the continuity of the deviation; false- It reduces the alarm. The reason it's critical: exceeding the threshold alone is not sufficient for triggering; The deviation must also persist for a predefined period of time. This second point... The condition is that instantaneous measurement noise and transient spikes generate notifications. It is discrimination that prevents. 30 Behavioral / routine baseline module (285): From position / movement routine It detects the deviation. The reason it's critical: the same statistical approach applies to the device sensor. 22 By moving the data from the system to the location / movement routine, the system typically allows the user to... It learns its locations and routes from its own historical data; previously a defined, fixed geographical fence rule is not questioned, only the personal norm Notifications are generated in case of significant and sustained deviation. Age declaration interface (300): Receives age declaration from the user. Grade calculation module (305): Converts age to grade on the client side; raw age It doesn't go to the server. The reason it's critical: the age threshold comparison is entirely client-side. The procedure is performed on the device, and only the result stage label is transmitted to the server; naked birth 10 The date is not stored on the server. Age verification thus utilizes a server-blind architecture. It is done without causing any damage. Parent / guardian account linking module (310): The minor must be a mandatory member. It links to the parent / guardian account. The critical reason is: the account cannot be linked until the connection is complete. It does not become active and cannot be added as a member to any circle; parent / guardian 15 This connection is not an optional setting; it must be met for the account to function. It is made a necessary prerequisite. Circle approval request engine (315): Parental approval for minor's circle participation connections. Reason for criticality: the circle is kept in a passive state without approval; approval 20 When given, the parent / guardian account exchanges the same key with other members of the circle. They are added as an active member via the protocol, so that the parent / guardian The information is provided through the circle membership itself, not through a separate management interface. is established. Parent / guardian information panel (320): Parents can access the child's circle list It shows. Periodic re-verification module (325): Periodically re-verification of age declaration He wants it again. 30 Device sensor data reception module (500): Status from paired device It receives indicator and motion data. 23 State deviation detection module (505): The current state / motion value, a personal baseline calculated from the user's own historical data in advance The deviation exceeds a defined threshold with the decision module (275) and this deviation is specific 5 when it is confirmed together with the continuity verification module (280) that it has been running for a while It is triggered. The reason it is critical: instead of general rules like fixed geographic fences or single thresholds. Because it is based on user-specific deviations from the norm, it reduces false alarms. It also establishes a personalized trigger logic that is independent of age / individual. Brand-agnostic data normalization module (510): Common 10 different brand data It converts to a data schema. The critical reason: different manufacturers have their own platform interfaces. Because the data it presents in different forms is transformed into a common schema, one Even if the members of the circle use different brands of devices, each member's data is stored on the same server. It enters the blind channel and is evaluated using the same detection logic; wearable device brand It does not affect the integrated functioning of the circle. 15 Sharing / permission level control module (600): Selected by the user on a per-person basis. It manages the scope of sharing and permission status. The critical reason: each member has their own... It retrieves encrypted data with a key context corresponding to the permission level; the scope is a It's not an interface filter, but rather a result of which key can be used to access the encrypted data. 20 When consent is withdrawn on a category basis, the relevant data category is processed through this module. It switches off automatically. Role-based permanent permission assignment module (605): Permanent, role-based permission level assigned to a member. It assigns. In a preferred application, the permission level set is at least three levels. 25 (Limited / Standard / Full) and each level, the key context accessible to the member. (120 / 125) determines. Reason for being critical: the element's basic technique (role / access list) However, it is known that the level of permission assigned in the invention is not an access list record, but rather the member's It is a cryptographic parameter that determines which key context can be opened; The distinction between known technology and invention arises precisely at this point of connection. 30 User-selected sharing scope module (610): Location / status data It shares content at the level and scope selected by the user for that member. 24 Application-layer trigger-overflow module (615): Visibility on trigger It upgrades temporarily. The critical reason: the upgrade is not a permanent permission change; for a predefined period and regardless of the current permit status. It is applied as is, and automatically returns to the previous state at the end of the period. In case of emergency, 5 It strikes a balance between visibility and privacy under normal circumstances, and is time-limited. And this is the reversible mechanism. Operating system layer pre-authorization request module (620): Pre-authorization of emergency location He requests. 10 Triggered switch rewind module (625): For triggering the sensitive switch It enhances cryptography. The reason it's critical: visibility at the moment of triggering. Instead of leaving the upgrade as a visibility flag at the application layer, the relevant Re-sealing of sensitive data key context (125) for circle members 15 It is based on the process; thus, the upgrade can be performed even if the application layer is bypassed. It becomes cryptographically valid. Parent / guardian cryptographic co-signature module (630): Minor user Opening the sensitive data key context (125), linked parent / guardian account 20 It makes it dependent on a cryptographic co-signature. The critical reason: age verification. not only at the interface / permission control level, but also at the key unlocking process itself. By cryptographically linking it, a minor's sensitive data can be accessed without parental consent. This makes it technically impossible to open. Consent-key binding module (635): Code verification interface (710) Successful entry of the verification code requires only a consent record (715) not limited to producing, but opening the relevant sensitive data key context (125) It is also used as a cryptographic input in the process. The reason it is critical: consent. It moves away from being just an interface-level checkbox for verification and makes the data actually 30 It becomes part of the cryptographic material required for it to be unlocked; consent Without this, the data would also be technically inaccessible. Priority notification subset definition and routing module (640): Status And it only forwards the fall notification to the authorized subset. Reason for it being critical: redirection, from the circle owner's role-based permission level assignment mechanism It relies on a separate and separately defined subset marking; thus a Instead of informing the entire circle about the fall / impact event, only this situation affects 5 It reaches out to previously authorized members to handle the matter. Fall / impact pattern and immobility detection module (645): With fall pattern It considers the subsequent immobility together. The reason for it being critical: the fall. The perception itself is a known technique; what is unique to the invention is that it is achieved with a fall / impact pattern. immobility that follows and lasts for a predefined period of time Compound triggering, based on being met TOGETHER, personal baseline-based It generates a signal independent of and separate from the detection and from the common response window. By passing through, only a priority subset of notifications are defined and directed. It is redirected to module (640). 15 Category-based consent presentation module (700): Status and location consent separately. It presents. The reason it's critical: consent is not a single collective approval, but per data category. It is obtained through separate and independent texts; the possibility of withdrawing consent on a category basis is also included in this. It is based on discrimination and only when the relevant automatic sharing mechanism is disabled. 20 It ensures it stays put. Confirmation code production and shipping module (705): One-time verification code It produces and ships. Code verification interface (710): Verifies the entered verification code. Consent record (715): Cryptographically record consent to the audit summary chain (145). The author points out the critical importance: the consent record is a database row that can be modified later. It is kept not as an add-only audit summary chain (145); Thus, the text for which consent was given and when it was given can be retrospectively determined. It is recorded in an unalterable manner. 26 Wearable device SOS trigger interface (820): SOS from any brand of watch It receives the trigger. The critical reason: the trigger from the wearable device is a separate... Brand-agnostic data normalization module (510) instead of establishing a notification line through disaster and situation deviation triggers, the same common situation reporting and The incremental escalation enters the pipeline; all triggers of a single escalation logic are 5. It ensures that it remains valid for its sources. Device-to-device prioritization / takeover module (825): If phone is unreachable It transfers the transmission to the wearable device (failover). The critical reason: failover only works on the network. Not due to lack of connection, but because the phone is off, the battery is dead, or the pairing connection is 10. It is also triggered if it is broken, and the transmission paths follow a predefined sequence. It is tested accordingly; minimizing emergency data load by eliminating dependence on a single device. It aims to exit through a limited number of channels. Wearable device independent cellular transmission path (830): The watch's own cellular 15 It transmits the urgent data payload via its connection. The critical reason: the wearable device transmits data from the phone. Having an independent cellular connection, the phone is unreachable This ensures that the escalation chain is not broken in the scenario; such a connection In applications where it is not present, the takeover step is skipped and existing escalation paths are used. It remains valid. 20 The functions performed by the invention are: The invention is an integrated system composed of interconnected units (see Figure 1, Figure 1). 2, Figure 7 and Figure 20). At one end, user client devices (100) and to them paired wearable devices from different brands; in the middle, only encrypted data blocks 25 server-blind cloud server infrastructure (110); outside Prioritized external disaster data services interface (200); and in case of disconnection Wireless relay network (235) from device to device and short message service network that comes into play gateway (245) is included. All subsystems (cryptography core, disaster / anomaly triggering, escalation, sharing control, normalization, age-level / parent, 30 (Consent / control) operates under a single consistent server-blind architectural principle. 27 Hardware components: user client device (100) (typically a smartphone), wearable device(s) paired by the user, cloud-based server infrastructure (110), (server-blind; a cloud / database layer that stores only encrypted data blocks), device's secure key storage environment (130) hardware and external disaster data service providers. Specific algorithm / standard names and numerical values in this section are 5 It serves only as an example in a preferred application and does not limit the scope of the invention. When a circle is formed, the circle key change module (105), each user Generates a public / private key pair for the client device (100), private secure key is kept in the storage medium (130) and the common key of the circle is sealed asymmetric 10 It distributes each member’s public key by encrypting it separately with the encryption engine (115); In a preferred application, this is the elliptic curve open-key technique (for example). Curve25519 / X25519) is based on. Key context parsing module (160), circle a general key derivation function (preferably HKDF-SHA256) from the root key derives the data key context (120) and sensitive data key contexts (125); each 15 Both use a single authentication encryption algorithm (preferably XChaCha20- Poly1305-IETF) is processed. The server infrastructure (110) stores these encrypted blocks but plain He cannot access the text. Role-based permanent permission assignment module (605), circle owner can assign one permission to each member 20 Provides level assignment; sharing / permission control module (600) sharing scope User-selected sharing scope module (610) allows the user to select a person-by-person scope. It maintains the level. When the permission level changes, the permission-key rewind triggers. (165) activates the event-triggered key renewal module (140); permission is revoked The member cannot access the relevant key context. Entire circle, key, permission and sharing 25 The events are written to the keyed cryptographic hash-based audit hash-chain (145); chain The secret key is kept in the safe (150). Multi-source disaster consensus module (260), from external disaster data service interface (200) receives magnitude / epicenter information in a prioritized order; magnitude / impact 30 radius step function (205) and position-center comparison module (210) The impact is calculated entirely on the client device (location is not transmitted to the server). In the alternative triggering method; the device sensor data acquisition module (500) with the brand- 28 Personal status baseline fed by agnostic data normalization module (510) module (265), activity / movement status classifier (270), deviation decision module (275), continuity verification module (280) and behavioral / routine baseline module (285) modules allow the user to experience a meaningful and sustained deviation from their normal, i.e. Detects the state deviation detection module (505). Both paths are automatic sharing 5 activates its trigger (215): position, status indicator and battery data server-blind transmitted from the channel to the circle members, status reporting interface (220) and response window The timer (225) is started. Confirmation cannot be obtained in the response window AND connection status detection module (230) 10 If it determines that there is no network connection, then a two-layer escalation begins: subtle. The broadcast sub-layer (255) broadcasts an unconnected SOS flag; when a connection is established rich layer of layered emergency data packet (250) (location / status (indicator / battery) is transferred. Wireless relay network (235) platform- from device to device. It is asymmetrical and the dual 15 between the user's own phone and the wearable device It is independent of the matching subsystem (240). Short message service gateway (245) It is a supplementary channel: if connectivity is limited, it can be used from the server-side gateway, or at all. If connectivity is unavailable, the device-side local short message capability can be used as a last resort. It sends. The user can also initiate an SOS directly from the paired wearable device; If the phone is unreachable, wearable devices with their own cellular connection (devices-20) The relay network takes over the transmission via the inter-prioritization / takeover module (825). a validity period with a defined and configurable jump limit (N, N≥1) It operates with the (TTL) parameter. Jump limit and validity period control module (236), It checks whether the packet's skip counter and validity period have reached their limits; The package will be dropped if it reaches the limit or the end of the time limit. If the limit has not been exceeded, the counter will be increased by 25. and the transmission module (237) increments the hop counter by one and sends the packet to the next vehicle device. It transmits; each intermediate device only carries the packet, it cannot decrypt its contents. Access control module (238) sends the packet to the target environment, namely the short message service gateway (245) It checks if it has arrived; if not, the packet is sent to the next available device. is transmitted. In a preferred application, the hop limit is two (single intermediary device 30). (transmission via) is configured; in another application, three or higher values is used; the jump limit and validity period depend on device density, energy budget, and Depending on the severity of the incident, it can be configured by the application. 29 These are the parameters. The increase in the number of intermediary devices and the inability of the intermediary devices to decode the content. It does not change its properties. In the event of a trigger, the application-layer trigger-overflow module (615) and preference In an application, the triggered switch rewind module (625) triggers 5 The visibility of the living user is temporary (W), regardless of the current permission. It increases; at the end of the period it returns to the previous state. Age declaration interface (300) and level Calculation module (305) converts age into a tier on the client; for below the first threshold Parent / guardian account linking module (310), circle approval request for second threshold below engine (315) and parent / guardian cryptographic co-signature in a preferred application 10 Module (630) is activated. Fall / impact and immobility for a circle member. The detection module (645) only detects a composite status signal if it is previously authorized. The priority notification subset redirects to the definition and routing module (640). Category-based consent presentation module (700) presents status and location consent separately; approval Code generation and sending module (705) and code verification interface (710), consent approval 15 It writes the record (715) to the chain of control and consent-key in a preferred practice. Opening the sensitive key context via the binding module (635) It constitutes cryptographic input. Referring to Figure 1; the integrated architecture of the invention consists of 20 interconnected subsystems. It consists of a core subsystem, server-blind between user client devices (100). only with a circle key exchange module (105) that works with encryption Data sharing that runs through a server infrastructure (110) that stores data blocks is its architecture; in this subsystem, the sealed asymmetric encryption engine (115) circle It seals its key separately to each member's public key, key context 25 Parsing module (160) from circle root key to public data key context (120) and derives sensitive data key context (125), secure device private keys with key storage environment (130) and hidden key safe (150) mechanism protected, event-triggered switch with periodic key renewal module (135) Refresh module (140) refreshes key contexts, permission-key rewind 30 trigger (165) permission level and trigger-induced rewind operations It initiates and all these events are recorded in the audit summary-chain (145). Age Category-based consent presentation with declaration-based tier calculation module (305) module (700) sets the conditions for the user's entry into circle membership and data processing. It acts as two separate gateways determining the state deviation caused by disaster and device. The triggered automated notification subsystem can receive notifications from an external disaster-risk data source or triggered by a state deviation detected by the client device Automatic sharing via automatic sharing trigger (215) and incremental 5 It provides escalation and operates through the server-blind channel of the core subsystem; same The trigger is a wearable device SOS signal on a wearable device paired with the user. It can also be given from the trigger interface (820). Role-based sharing control and two The phased trigger-override subsystem allows data flow sharing / permission under normal conditions. Permanent permission assigned by the circle owner via the level control module (600) 10 It manages it at a level and within the scope selected by the user on an individual basis; a trigger. sharing in case of signal and only when confirmation is not received in the response window. Its visibility is enhanced for a limited time. All of these subsystems are part of a single coherent system. It operates integrally under the server-blind architecture principle. Referring to Figure 2; the system consists of one or more user client devices (100), forming a circle key exchange module (105) and a module that stores only encrypted data blocks Server infrastructure (110) includes. Server infrastructure (110), circle membership meta It can associate data with encrypted blocks, but not with the plaintext content of those blocks. No access is possible under any circumstances. All encryption and decryption processes are handled by user 20. It is performed on client devices (100). Referring to Figure 3; the circle switch change module (105) has a corresponding module for each user device. It generates a public / private key pair, and when a new circle is created, the circle's common key... circle key, through sealed asymmetric encryption engine (115) each member 25 It distributes the public key by encrypting it separately; in a preferred implementation, this open- key-key exchange to an elliptic curve open-key algorithm (for example It is based on the Curve25519 / X25519 curve. Thus, the server generates the encrypted key blocks. He is responsible for transmitting it, but the circle switch never reaches him directly. It is not accessible as text. 30 Referring to Figure 4; the key context parsing module (160) from the circle root key, a key derivation function (KDF, Key Derivation Function; a preferred one) 31 In practice, HKDF-SHA256 is used, and a different context is given for each. By applying the identifier, two mathematically independent keys It derives the context. A global data key context for general-purpose database records. (120) and for sensitive data categories such as location, status indicator and battery level There is a separate sensitive data key context (125). Both key contexts are 5 preferably with the same authenticated encryption algorithm (e.g., XChaCha20- An authenticated symmetric encryption algorithm (such as Poly1305-IETF) is used; However, due to the mathematical independence of the keys, a possible context One leak does not affect the other. This structure necessitates the use of different algorithms. It provides cryptographic isolation between data categories without compromising them. 10 Referring to Figure 5; each user client device's (100) private key is a secure key is stored in the storage medium (130); in a preferred application this medium is the device is a secure hardware environment (for example, a trusted execution environment), an alternative In practice, the private key is generated on the client processor and the device's operating system... is written to the secure storage interface provided by the system; both In practice, the private key is not transferred outside the device. The system, preferably, transfers the key outside the device. their keys automatically within a predefined period (preferably ninety days) with a periodic key renewal module (135) which renews as a circle member removed from circle OR role-based 20 assigned by circle owner Periodically adjust the relevant key context depending on the permission level change event. An event-triggered switch that instantly refreshes regardless of the refresh status. Includes a refresh module (140). Key refresh, stored historical data. It does not require re-encryption; it simply requires the new key context to be entered into the circle. Re-wrapping the public keys of the relevant members is sufficient; this 25 Therefore, the complexity of the operation is independent of the volume of data stored in the circle member. It is proportional to the number of role-based permission levels assigned by the circle owner. If changed, a permission-key rewind trigger (165), permission level By detecting the change event, the key belonging to the data category affected by the change. It generates a demand for the context to be re-wrapped; upon this demand, a trigger switch 30 The rewind module (625) reconstructs the relevant key context and only public keys of members authorized to access that context after the change It reseals the public key of the member whose permission level has been downgraded. 32 Since no sealing was done, this member can go forward with the relevant data category. It becomes cryptographically inaccessible. Permission-key rewind trigger. (165) In addition, a trigger signal is detected and the response window is defined in Figure 17. If no confirmation is received in the timer (225), the sensitive data key context (125) re-enhanced visibility for a predefined period of time. It also triggers the winding via the key rewind module (625); At the end of the period, the key context is rewound to match the previous permission status. Referring to Figure 6; all circle, key, permission level and implemented in the system. sharing events, a key-based cryptographic hash function (HMAC, Hash-based 10 Message Authentication Code; HMAC-SHA256 in the preferred application) based on, append-only, record in an audit summary chain (145) The secret key, which ensures the integrity of the chain, is taken in a separate secret key box (150) It is protected within the mechanism; thus, past records can be retrospectively accessed. It is immutable, and each event is chained based on the summary value of the previous one. 15 Referring to Figure 7; multi-source disaster consensus module (260), external disaster data service Periodically obtains earthquake magnitude and epicenter location information from the interface (200). It queries as follows; this interface preferably uses an official national source (primary), regional a real-time resource (secondary) and a global resource (tertiary) 20 It combines in a prioritized order; the primary source in a preferred application, related. It is the country's official disaster management data service (for example, AFAD for Türkiye) and the system, tertiary / complementary global resources for different countries in international expansion configurable interface definitions that allow the addition of (e.g., USGS) It uses; these specific source names are illustrative and do not limit the scope. The same seismic 25 the event being reported from multiple sources with varying magnitudes or timing information In that case, information from the highest priority source is taken as the basis, and subsequent information is used. It is updated with information from a high-priority source. The information received is, in advance... A defined magnitude / radius step function is compared with (205); In a sample configuration, signals below M4.0 are not considered; 30 for M4.0–4.9. approximately 25 km, approximately 75 km for M5.0–5.9, approximately 200 km for M6.0–6.9 and For M7.0 and above, an effective radius of approximately 500 km or more applies. This 33 The threshold values for the step function can be remotely configured on the server side. These are parameters. Referring to Figure 8; the magnitude / radius of influence of the user's position in the step function. (205) client-side location-center that remains within the defined radius of influence If detected by the comparison module (210) (this comparison 5 because it is done entirely on the client device and the user is for comparison Since the location information was not transmitted to the server infrastructure (110) at any stage, the server (cannot know if the user is within the radius of influence), on the user's device screen a status reporting interface (220) "I'm fine, forward to circle" is displayed and a response The window timer (225) is started; in preferred applications this window, 10 Depending on the trigger type, it can be configured between ten seconds and one hundred and twenty seconds. It is defined as a time period. If the user confirms their status within this window, the data will be released. It is not sent to circle members. If the response window fills up without confirmation, the application- Layer trigger-overflow module (615) is activated and automatic sharing trigger (215), user's current location, status indicator and battery level 15 It transmits its data to circle members via a server-blind channel. Referring to Figure 9; until the response window timer (225) expires If the user's consent cannot be obtained, the system detects the connection status. queries module (230). Only primary cellular or wireless local area network 20 automatic if it is determined that the connection is not currently available Escalation is activated; escalation is not triggered while a connection exists, and the system... The server continues notification via the blind channel. After escalation is initiated... Connection status detection module (230), primary cellular or wireless local network It continues to check for the connection; 25 when the primary connection is found to be available again. If detected, the system will activate the currently ongoing device-to-device wireless relay. terminates the network (235) broadcast and continues the notification via server-blind channel. It then returns to the primary channel; thus, the same status information is transmitted through both channels. This prevents repetition and unnecessary energy consumption. Referring to Figure 10; when escalation is activated, the state information is a two-layered system. It is transmitted through architecture. In a thin broadcast substrate (255), without establishing a connection, its size a limited (preferably around 28 bytes) emergency flag and a short identification summary nearby 34 It is broadcast to nearby devices. A rescuer or a nearby device receives this broadcast. When detected, a connection is established, displaying the location, status indicator, and battery level. The rich data layer of the layered emergency data package (250) is transmitted. Relay Its architecture is platform-asymmetric: it runs a family of operating systems (preferably Android). The devices receive the broadcast with a limited time-to-live (TTL) and store-and-forward 5 data. By essentially re-broadcasting it, it could create a multi-hop transmitter backbone; otherwise Devices running an operating system family (preferably iOS) have the operating system's background... Due to broadcasting restrictions, the plan only broadcasts itself as an end node and It detects nearby signals but does not re-transmit signals from another device. This device-to-device wireless relay network (235) connects the device with the user’s own mobile 10 architecture from the connection provided by the dual pairing subsystem (240) between the phone It is a separate and independent subsystem. It is only the endpoint of an operating system family. Its function as a node is not an arbitrary design choice; it's part of the operating system's backend. The plan is for the wireless broadcast interface to carry a relay payload that will be rebroadcast. 15 This stems from a genuine platform limitation; the other platform that does not have this limitation is... It can form the backbone of a multi-hop transfer system. Referring to Figure 11; as part of the escalation process, state information is also a Short message service can be transmitted to circle members via gateway (245). Short message 20 Service transmission can occur via two separate paths: (a) the user device In situations where there is a network connection, albeit a limited one, the state information is a a server-side short message network that operates through a messaging infrastructure provider (b) transmitted via gateway; (b) true zero-link where no network connection exists In this scenario, since the server-side gateway is inaccessible, the status information is 25. device-side local provided directly by the user device's operating system It is transmitted as a last-resort channel through the ability to send short messages. Short Message service gateway (245), on both paths, device-to-device wireless relay network (235) as a supplementary channel to reach members outside the coverage area It functions. 30 Referring to Figure 12; layered emergency data packet (250), unlinked broadcast at this stage, only the emergency flag is displayed via the thin broadcast substrate (255). 35 and includes a brief identity summary; in the rich data phase after the connection is established. This includes the user's location information, status indicators, and the current state of the user's device. Includes battery level data; battery level information is used for search / rescue prioritization. In this respect, it provides additional context for circle members. Referring to Figure 13; an age declaration interface is presented to the user during account creation. Date of birth / age information is requested via (300). Level calculation module (305), The declared age has a predefined first threshold (preferably thirteen) and a second threshold. It compares the value (preferably eighteen) on the client device and only the result The rank tag is transmitted to the server; the bare date of birth is not stored on the server. 10 Referring to Figure 14; if the level label is below the first threshold, The parent / guardian account linking module (310) is activated and the independent account The creation of the account is prevented and it is forcibly linked to a parent / guardian account. This is provided. The account will not become active until this connection is completed, and nothing will happen. Cannot be added as a member to the circle. 15 Referring to Figure 15; the level label is between the first and second thresholds. In this case, the user's request to create a circle or join a circle is accepted by the circle. The request is forwarded to the linked parent / guardian account by the request engine (315); without obtaining approval The circle is kept in a passive state. Once approval is received, the parent / guardian account will be activated as shown in Figure 3, 20. an active member in the same way as other members of the circle through the defined protocol added as and through a parent / guardian information panel (320) the minor becomes a member You can view a list of the circles in which it occurs. The same flow is described in Figures 7–12. disaster-triggered notification and status reporting data for users at this level By default, the system also simultaneously connects to the parent / guardian account with 25 It enables transmission. For users at this level, the small, sensitive data key opening of the context (125), connected parent / guardian in a preferred practice This is linked to the submission of the account's cryptographic co-signature; co-signature When not presented, the child's device cannot open this context. A periodic re-enactment. The verification module (325) requests the age declaration again at regular intervals and discrepancies 30 This puts the account under review. 36 Referring to Figure 16; the user device's device sensor data acquisition module (500), status indicator and motion data, when the user is using a compatible wearable device In these cases, it is received periodically or recently on the client device. Activity / motion status classifier (270) analyzes the user's current state from accelerometer data. activity level (preferably one of the following categories: resting, walking, or running) 5 (as). Personal status baseline module (265), each activity status for the user's own historical data, an average and a measure of variability. Calculates. State deviation detection module (505), the current value of the relevant activity Deviation from the baseline of the situation is determined in advance by the decision module (275). that it exceeds a defined threshold (preferably three standard deviations from the mean) AND that this 10 the deviation is predefined by the continuity verification module (280) When you determine that it lasted for a certain amount of time (preferably sixty seconds), this Detection of disaster-triggered automated sharing and status reporting as defined in Figures 7–11. the same common escalation pipe as interface (220) and response window timer (225) It triggers the line and the automatic sharing trigger (215). This evaluation is 15 This is done regardless of the user's age; thus, two different trigger sources. (external disaster data and client-side personalized state deviation) same situation It shares a notification and escalation mechanism. Referring to Figure 16 and in a preferred application, the device sensor data acquisition module 20 (500) is limited to receiving data directly from the user device’s own sensor. not, but the sensor data interface of the client device's operating system platform (for example (sensor / status data interface provided by the relevant mobile operating system platform) via an external wearable device paired with the user (preferred (from wearable devices such as smartwatches, smart bracelets or smart rings in applications) 25 It can also read. This reading is a brand-agnostic data normalization module (510) This module is implemented by different wearable device manufacturers; sensor and motion data presented in various formats through platform interfaces, personal status baseline module (265) and behavioral / routine baseline module (285) converts it into a common data schema that can be consumed by. Thus, a 30 Even if different members of the circle use different brands of wearable devices, each member's data... It enters the same server-blind channel via the same normalized scheme and the same situation occurs. 37 The deviation is evaluated using detection logic; the wearable device brand, the circle's It does not affect its integrated operation. Referring again to Figure 16, in a preferred application, the personal status baseline module (265), deviation decision module (275) and continuity verification module (280) 5 The same statistical approach applied by [company name] is limited to device sensor data. not, but a behavioral / routine baseline module (285) by the user It can also be applied to position and movement pattern data. In this application, the system, the locations the user was typically in and the distances they covered within a specific time interval. It learns routes and mobility levels from its own historical data; previously 10 Unlike notices that are based on a defined, fixed geographic fence rule, the notice only a meaningful and sustained deviation from the user's own learned normal It is generated when detected ("silent trust" mode). This approach is based on fixed rules. the high false-alarm rate frequently observed in systems and the related notifications to reduce fatigue and ensure that circle members, with each movement of the user, are constantly 15 instead of a form of sharing in which it is transmitted, only in the case of a genuine deviation from the norm It aims to provide an informed sharing experience. Referring to Figure 17; the role-based permanent permission assignment module (605) assigns permissions to each circle owner. a circle member can be given a predefined set of permission levels (preferably 20) assigning a permanent permission level (at least three levels: limited / standard / full) It provides; each permission level determines which key context the relevant member belongs to, as defined in Figure 4. (K_general, K_sensitive) cryptographically specifies who can access it. Sharing / permission Level control module (600), sharing scope, user-selective sharing The scope module (610) allows the user to select the permission level on a per-person basis. It manages according to; each member with the key context corresponding to their permission level. It receives encrypted data within this scope. The circle owner determines the permission level of a member. when changed, the event-triggered key reset module described in Figure 5 (140) takes effect and the member whose permission has been revoked cannot access the relevant data cryptographically. It becomes a 30-minute trigger signal, as described in Figures 7–11 or 16. Response window via the status reporting interface (220) presented to the user When no confirmation is received in the timer (225), the automatic sharing trigger (215) together with the application-layer trigger-overflow module (615), the trigger is experienced 38 the visibility of the user's posts for a predefined period of time (W), an emergency visibility set regardless of current permit status (preferably including precise location, status indicator and battery level) enhances; this The upgrade automatically reverts to its previous state at the end of the upgrade period (W). This As a complement to the application-layer overshoot, the operating system layer pre-permission request 5 module (620), during user registration, emergency to the extent permitted by the operating system. a privileged status to maintain location access in case of a triggered event. The operating system requests permission in advance; the user may refuse or withdraw this permission. If it does, the application-layer overflow will only occur if the system has the maximum access at that moment. It operates based on current data only. 10 Referring to Figure 18; the category-based consent presentation module (700) is used for processing state data. the explicit consent text regarding the processing of location data and the explicit consent text regarding the processing of location data It presents these to the user separately and independently. The user provides an explicit consent form. When approved, the approval code production and shipping module (705) is registered with the user. a one-time, time-limited six-digit number to the communication channel (telephone or email) sends a verification code. The user enters this code into the code verification interface (710) upon entry, the relevant explicit consent text is read and approved, consent record (715) It is added to the control summary chain (145) as defined in Figure 6. A preferred one In practice, the verification code entered into the code verification interface (710) is successfully 20 The verification is not limited to producing a consent record (715); it also Opening of the sensitive data key context (125) belonging to the relevant data category at time A consent-key binding is also used as a cryptographic input to the (unwrap) operation. module (635) is triggered. When the user withdraws the status data consent, as shown in Figure 17. The defined sharing / permission level control module (600) status data category is 25 It shuts down automatically and is triggered by the state deviation described in Figure 16. Sharing is disabled; however, if location data consent is withdrawn, the figure shows the following: The disaster-triggered automated sharing mechanism and automatic system defined in sections 7–9. The sharing trigger (215) is disabled for the user. Referring to Figure 19; for each of the subsystems of the invention, the subsystem upon which the respective subsystem is based the known technical component and the invention-specific combination / application point separately It has been shown. The known component for the server-blind core is the receiver's public key. 39 Asymmetric key exchange and authenticated encryption based on sealing that is, sealed asymmetric encryption engine (115), invention-specific point, circle root contextually decoupled dual-context (public / sensitive) key The key context parsing module that performs the derivation is (160). Disaster and Known components for the state deviation subsystem: short-range wireless 5 broadcast / connection protocols namely device-to-device wireless relay network (235) and multi- This is an external inquiry based on the source, and the invention-specific points are two-tiered and platform- Deviation and continuity from personal baseline with asymmetric relay architecture. the case that applies a personalized deviation algorithm based on verification It is a deviation detection module (505). Known component 10 for age and parent subsystem. general age declaration / parental permission concept, i.e., parent / guardian account linking module (310), the point specific to the invention is the opening of the minor’s sensitive data key context (125). parent / guardian linking the linked parent / guardian account to the cryptographic co-signature It is a cryptographic co-signature module (630). It is known for the share control subsystem. Component general role / access-list based permission concept, i.e. role-based persistent permission assignment 15 module (605), invention-specific point, permission level change in the core subsystem automatically triggers the cryptographic reconstruction of the key context and upon triggering, this key context is encrypted for a limited period of time. It is the event-triggered key renewal module that establishes the chain to which it is upgraded (140). Consent The known component for the subsystem is the general one-time code validation concept, namely 20 The approval code is the production and dispatch module (705), and the invention-specific point is category based. separate consent presentation and verification code cryptographic key decryption process It is a consent-key binding module that enables its use as a direct input. (635). The points specific to the invention are shown above on a subsystem basis. This specific combination of known components was found in 25 during the literature review. no known components were found; the novelty and inventive step defense of the invention was based on the known components. not that it is, but this combination and the algorithmic embodied in each of them It is based on the fact that the practice is unknown. Referring to Figure 20; the end-to-end workflow of the invention is as follows, with 30 preferred steps: It can be summarized. Brand-agnostic data normalization module (510), wearable sensor and motion data read from devices or phone sensors are combined into a common system. converts the data into a schema and this data is one of the external disaster data service interfaces (200) and 40 Magnitude / Radius of Impact Step with multi-source disaster consensus module (260) via function (205) and position-center comparison module (210), The other is the personal status baseline module (265) and behavioral / routine baseline. module (285), deviation decision module (275) and continuity verification module (280) It enters into two parallel evaluations, one of which is the path; this second path is device-related 5 Behavioral deviations such as postural deviation and sudden immobility indicating a fall. It evaluates their patterns under the same generalized algorithm. In these two ways... in any of them, by the state deviation detection module (505) beforehand If it is determined that the defined threshold or deviation condition is met, a message will be sent to the user. status reporting interface (220) and response window timer (225) are presented; 10 If the condition is not met, the system will use the sharing / permission level control module (600). staying within the scope determined by the user-selected sharing scope module (610) It continues. If confirmation is received in the response window, sharing will not take place; confirmation If it cannot be received, the automatic sharing trigger (215) is activated and the location, status The indicator and battery data are transmitted to the circle members via the server-blind channel. 15 If the connection status detection module (230) finds a network connection to be available The system continues to receive notifications via the normal server-blind channel, and the connection remains active. If not, two-layer wireless relay network (235) from device to device The phased escalation begins via the transmission and short message service gateway (245). In both cases, a notification is sent to the circle members, and the 20 who experienced the trigger are notified. User sharing visibility, sensitive data in a preferred application. By cryptographically resealing the key context (125), In an alternative implementation, the application-layer trigger-overflow module (615) By way of, it is temporarily (W) upgraded. The circle member, after receiving this notification or At any time, you can restrict your own level of consent or withdraw your explicit consent. can pull; both of these operations are event-triggered key renewal module (140) By triggering it, it cryptographically disables the relevant sharing. However, if necessary... key renewal or the end of the timed (W) cryptographic upgrade, only with regard to future payloads that will be encrypted with the relevant key context. determines access; a member must be on the verge of 30 days from the end of renewal or the expiration of a timed upgrade. first, decrypting it with the relevant key and then transferring the data it already obtained to its own device. It does not make it backward inaccessible. This is a general characteristic of end-to-end encryption. 41 It has a limit, is "cryptographically inaccessible", and at the end of the period it "reverts to previous state". The term "rotating" applies only to forward data payloads. Referring to Figure 21; the wearable device SOS trigger interface (820), the user an emergency signal directly from any brand of wearable device it is paired with. receives the trigger and this trigger is the brand-agnostic data normalization module (510) 5 through disaster and situation deviation triggers, the same common situation reporting interface (220) and enters the stepped escalation pipeline. Inter-device Prioritization / Takeover Module (825), User Client at a Trigger Time the device (100), the user's mobile phone in a preferred application, primary no network connection or the phone is unreachable (switched off, battery dead 10 (or if the pairing connection is broken) and detects the wearable device independently If a cellular transmission path (830) is available, the transmission of the emergency payload can be done directly. It automatically takes over via the wearable device; the transmission path is preferably phone- internet, wearable device-cellular, device-to-device wireless relay network (235) and short The message service gateway (245) is tried in sequence. The wearable device's independent cellular 15 In applications where there is no connection, this takeover step is skipped and the existing Escalation routes remain valid. Referring to Figure 22; fall / impact pattern and immobility detection module (645), device sensor data acquisition module (500) and brand-agnostic data normalization 20 A sudden drop or impact pattern in the acceleration data fed from module (510), this is followed by a predefined period of time (preferably ninety seconds) It is assessed together with a prolonged state of immobility; these two conditions TOGETHER the meeting, personal baseline-based state deviation defined in Figure 16. It generates a separate and composite status trigger, independent of its detection. This trigger is 25 When this happens, a status notification interface (220) and a response window are provided to the user. It is presented to the timer (225); if the user confirms the status, a notification is given It will not be sent. If the response window fills up without confirmation, the application layer will be disabled. The trigger-overshoot module (615) is activated and the priority notification subset Identification and routing module (640), status reporting as defined in Figures 8-12, 30 By activating the response window and the gradual escalation mechanism, the notification, not to all members of the circle owner, but to a pre-authorized priority notice. subset (preferably one marked as the member's primary priority notification recipient) 42 (or more members) directs. This direction is shown in Figure 17 by the circle owner. Apart from the defined role-based permission level assignment mechanism, also It relies on a defined subset marking; thus, a member's fall / impact focusing only on this specific situation instead of informing the entire circle. It is forwarded to authorized members. 5 Referring to Figure 23; device-to-device wireless relay network (235), layered emergency data package (250) with a predefined and configurable jump limit (N, N≥1) It transmits a validity period (TTL) parameter. The time limit and validity period are specified. The control module (236) checks whether the packet skip counter and validity period reach the limit. It checks if it has arrived; packets that reach the limit or deadline are dropped. The limit is 10. If not exceeded, the counter boosting and transmission module (237) increments the jump counter by one and The packet is passed to the next intermediate device; each intermediate device only carries the packet, its contents. It cannot solve. The access control module (238) cannot solve the packet's target environment, i.e., the short message. The service checks whether the packet has reached the gateway (245); if it has not, the packet is returned. The next device is retransmitted via a wireless relay network (235) from device to device. Preference 15 In a given application, the hop limit is two (transmission via a single medium device) It is configured; in another application, the jump limit is three, four, or five. is configured; greater than five in applications with high device density. Other values that can be used include: jump limit and validity period, device load, energy. It can be configured by the application depending on the budget and the severity of the incident. 20 These are the parameters. The increase in the number of intermediary devices and the inability of the intermediary devices to decode the content. It does not change its properties. 30
Claims
43 REQUESTS 1- The invention relates to a server-blind circle of trust-based personal security system. its feature is that the receiver is open between the user client devices (100). an asymmetric open key key exchange, each key separately sealed. 5 using this technique to establish a common circle switch and shared location and status by encrypting the device status data on the client device using the indicator the server infrastructure (110) which stores only encrypted data blocks a server-blind encryption and distribution layer that does not have access to the text; circle Deriving a key contextually parsed from the root key 10 derived through the function and mathematically independent of each other a sensitive data key with at least one public data key context (120) with a single authenticated encryption algorithm including context (125) a multi-contextual key architecture being processed; removal of a circle member or role-based permission level 15 assigned by the circle owner reconstructing the relevant key context based on the modification event. an event-triggered key renewal module (140); permanent and for each member assigning a cryptographically implemented permission level and the scope of sharing. This is a sharing and permission level control system that manages according to permission level. module (600); external 20 via an external disaster data service interface (200) a trigger signal received from a disaster risk data source or client the device, from the user's past data and current activity status Device-related issues detected based on calculated personal baseline. a request that the user confirm their status based on the deviation status reporting interface (220) and the specified response window for this confirmation 25 If not included, the user's location, status indicator and battery automatically transmits data to circle members via a server-blind channel an automatic sharing trigger (215); no response from the user and a connection status detection module that only detects when there is no network connection. (230) At least one intermediary device that comes into play if determined by transmission over a predefined hop limit and validity period implementing a short range device-to-device wireless relay network (235) 44 and / or a phased escalation including the short message service gateway (245) It includes the mechanism. 2- According to Claim 1, it is a personal security and trust circle system, characterized by its multi- contextual key architecture differs from circle root key in context 5 at least one of the following is cryptographically independent of each other using their identifiers general data key context (120) and at least one sensitive data key parsing a key context that enables the derivation of context (125) It includes module (160). 3- According to Claim 2, it is a personal safety and security circle system, the characteristic of which is; incident- triggered key renewal module (140), in trust circle membership or a permission that detects a change occurring at the role-based permission level. only affected via key rewind trigger (165) recreate the key context and authorize access to the key context 15 by using the public keys of the active member devices again It is a sealing process. 4- According to Claim 3, it is a personal security and trust circle system, the characteristic of which is; permission- 20 upon triggering from key rewind trigger (165) a that performs only the re-encryption of the relevant key context It contains a trigger switch rewind module (625). 5- According to Claim 1, it is a personal security and safety circle system, the characteristic of which is; external. To verify disaster information obtained from disaster data sources, more than 25 By comparing data obtained from disaster data sources, a common disaster event can be identified. multi-source disaster agreement that determines whether or not it has been created It includes module (260). 6- According to Claim 5, it is a personal security and trust circle system, characterized by; multiple-30 source disaster agreement module (260), regarding the verified disaster event the epicenter location and the location information of the user client device (100) by comparing whether the user is located within the disaster impact zone. 45 determining and this comparison is entirely user client device (100) the user who performed this comparison and used it within the scope of this comparison a location-center that prevents location information from being transmitted to the server It includes a comparison module (210). 7- According to Claim 1, it is a personal safety and security circle system, the characteristic of which is; device the resulting state deviation from the user's past sensor data a personal status baseline that forms the personal status baseline created line module (265), instant sensor data from the user's activity status an activity / movement status classifier (270), instantaneous sensor 10 by comparing the data to the personal status baseline to check for discrepancies. a deviation decision module (275) and the determined deviation beforehand a continuity that verifies whether it continues for a defined period of time It includes the verification module (280). 8- According to claim 7, the system's feature is; the user's past location and movement. by processing data and establishing behavioral / routine baselines. behavioral / routine baseline device-induced state deviation at least one behavioral / routine baseline module that leads to its determination (285) It includes. 20 9- The system is defined as follows according to Claim 1: emergency, as determined by the application. permission level for sharing visibility depending on the situation conditions an application-layer trigger-override configured to change module (615) and permission level sharing / permission level control module 25 (600) It includes a sharing control mechanism that enables its implementation. 10- Personal security and trust circle system according to claim 1 or 9, characterized by: Each permission level requires at least one key accessible to the relevant circle member. context, general data key context (120) and sensitive data key 30 cryptographically defining its context (125) in such a way as to separate it from each other It includes the sharing / permission level control module (600). 46 11- Server-blind circle of trust based personal security system according to Claim 1. its feature is; the user's age data on the user client device (100) an age range by comparing it to predefined age thresholds at least one level calculation module configured to generate (305), depending on the specified age level, the user account is a 5 at least one configured to be associated with a parent / guardian account Parent / guardian account linking module (310), user's circle of trust It is configured to link participation to parent / guardian account approval. at least one circle approval request engine (315), and user's sensitive data The opening of the key context (125) is done by cryptographically 10 to the parent / guardian account. At least one parent / guardian cryptographically configured to link to co-signature It includes the co-signature module (630) and the server infrastructure (110) users' raw data. This involves communicating the age range instead of the age or date of birth. 12- Server-blind circle of trust based personal security system according to claim 15 Its feature is that it creates a personal database from the user's past location and movement data. to establish a routine and detect deviations from the routine that are predefined. at least one behavioral / routine baseline module structured to (285), and sensors and motion signals from wearable devices from different manufacturers at least one 20-bit system structured to transform data into a common data schema It includes a brand-agnostic data normalization module (510). 13- Server-blind circle of trust based personal security system according to Claim 1. Its feature is that it separates the consent texts belonging to the location and status data categories. at least one category-based consent submission module structured to provide consent 25 (700), to generate and send a one-time verification code. At least one configured approval code production and shipping module (705), a code validation configured to verify the verification code interface (710), adding the verified consent record to the audit summary chain (145) at least one consent record structured for (715), and verification code 30 successful verification of the relevant sensitive data key context (125) at least configured to be passed as cryptographic input to the decryption process It includes a consent-key binding module (635). 47 14- Server-blind circle of trust based personal security system according to Claim 1. and its feature is; by the user with the user client device (100) emergency signal generated via a paired wearable device to receive and transmit this signal to the automatic sharing trigger (215) at least one structured wearable device SOS trigger interface (820), 5 The user client device (100) has no network connection, it is closed that the battery level is insufficient for data transmission and / or Emergency alert upon determining that the wearable device has been disconnected. at least one configured to delegate data transmission to the wearable device Inter-device prioritization / takeover module (825), and wearable device 10 enabling the user to transmit data independently from the client device (100) at least one wearable device must contain an independent cellular transmission pathway (830). 15- Server-blind circle of trust based personal security system according to Claim 1. and its characteristic is; the fall and / or impact pattern and the fall and / or impact 15 immobility that follows a pattern for a predefined period of time at least one structured to determine whether it continues or not Fall / impact pattern and immobility detection module (645), and fall and / or on the simultaneous occurrence of shock pattern and immobility conditions Notification of the generated trigger signal is sent to all members of the trust circle. instead of devices, at least one previously authorized priority notification At least one priority notification sub-set configured to redirect to the cluster. It includes the cluster definition and routing module (640). 16- The invention is a server-blind circle of trust-based personal security method, 25 The feature is that a circle key belonging to the trust circle is used by the client device. (100) is created on each circle key in the circle of trust. using the public key of a member device in a manner specific to that member device encryption using context identifiers different from the circle key at least one cryptographically independent public data key 30 context (120) and at least one sensitive data key context (125) derivation, user-specific location, status indicator, device sensor data and At least one of the device status data points is a key associated with the relevant data category. 48 Encryption on the user client device (100) using context, without transmitting the decryption key of the encrypted data to the server infrastructure (110) stored via server infrastructure (110) and / or having access authorization redirection to member devices, role-based permissions for trust circle members. assignment of levels and the relevant data for those permission levels 5 associating with categories, removing trust circle member and / or Renewing the relevant key context upon changing the permission level. and by using the public keys of member devices that have ongoing access authorization re-encryption of disaster data obtained from an external disaster data source and / or from user client device (100) or user client device (100) 10 sensor data obtained from a wearable device paired with Generating a trigger signal by evaluating it, triggering Upon generation of the signal, a status appears on the user client device (100). creation of the reporting interface (220) and a predefined response The window is launched, and user confirmation is required in the response window. If this is not possible, the user's location, status indicator, and device battery will be affected. at least one of the level data points is transmitted via a server-blind communication channel. Automatic transmission to circle members with access rights, user Failure to obtain approval and determination that there is no network connection. on which the data in question is transmitted wirelessly via a device-to-device relay network (235) and / or 20 The process of transmitting the short message service gradually through the gateway (245) It includes the steps. 17- The method according to claim 16, its characteristic is that the triggering signal is more than one. 25 disaster data obtained from external disaster data sources, prioritized according to their importance. reconciliation, with the user's information on the epicenter of the verified disaster event. Comparison of location on user client device (100), the process of determining whether the user is located within the disaster impact area a disaster assessment pathway including steps and / or device sensors Determining the user's activity status from their data, user 30 personal status baseline from historical sensor and behavioral data the creation of existing sensor data from that baseline 49 determining the deviation, the determined deviation within a predefined time Verification that it has continued throughout involves the process steps. 18- This method, according to Request 16, is characterized by the user's confirmation in the response window. Due to the inability to obtain it; the user who experienced the trigger shared 5 its visibility beforehand, regardless of the current permission level Upgrading for a defined period, sharing at the end of the period. Restoring visibility to its previous permission level, the role of the circle member changing the permission level based on category and / or withdrawing explicit consent based on category Event-triggered renewal of the relevant key context upon its withdrawal 10 and the related sharing authorization is cryptographically disabled for future use. The process of abandoning it involves the following steps. 19- This method is based on claim 16 and its characteristic is the absence of a network connection. In this case; without establishing a connection between the devices, an emergency signal and a short 15 thin broadcast sublayer containing at least one of the identity information (255) Location, status indicator, and battery upon publication and connection establishment. Transmission of a rich data layer containing at least one of the level data, layered emergency data packet (250) jump counter and validity period monitoring, ensuring the jump limit is not exceeded and the validity period continues 20 If this happens, the data packet will not be decoded by the intermediate device. The next step involves transmitting the data to the receiving device. 20- Method according to claim 16, characterized by; short message in gradual escalation. the service requires the user device to have a data communication connection. 25 in case of a short message service gateway via server infrastructure (110) (245) in case of lack of data communication link the user client device's (100) local short message sending capability using it as a last resort communication channel It includes. 30 21- Method according to Request 16, its feature is; user client device (100) the same emergency trigger received from a paired wearable device 50 reporting the situation and inclusion in the phased escalation process and mobile If the client device is unreachable, it will continue its independent communication. emergency data transmission by the wearable device in advance the process of taking over according to a defined cross-device prioritization order. It includes step 5. 15 25