Anonymized Identifier Authentication for PII Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems for securing electronic data exchanges, such as online transactions and point-of-sale systems, face challenges in protecting personally identifiable information (PII) from hackers and inefficiencies in transaction processing, including the need for users to transmit account information to verify website legitimacy and the complexity of payment ecosystems that slow down transactions and increase security vulnerabilities.
Innovation Solution
A computer-implemented method and system that uses anonymized identifiers to authenticate users and entities during electronic data exchanges, preventing the transmission of personally identifiable information, by extracting information from digital representations encoded in barcodes or wireless data streams, and utilizing a centralized intermediary for authentication and authorization, thereby ensuring secure and efficient transactions without exposing sensitive user data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional systems transmit personally identifiable information for authentication, then website legitimacy can be verified, but PII becomes vulnerable to interception by hackers
Solution Approach 1:
The patent extracts the authentication function from personally identifiable information and implements it through anonymized identifiers. Users authenticate with pseudonymous tokens that do not contain PII, separating the verification capability from sensitive data transmission. This allows legitimacy verification while eliminating PII exposure to hackers.
Solution Approach 2:
The patent introduces anonymized identifiers as an intermediary between users and websites for authentication. These pseudonymous tokens mediate the verification process, allowing users to prove their identity without transmitting actual PII. The intermediary layer protects user data while maintaining authentication reliability.
2Reliability
If users set up security information beforehand with specific websites, then spoofed websites can be identified, but the process is too cumbersome for new websites and e-commerce transactions
Solution Approach 1:
The patent creates a universal authentication system using anonymized identifiers that works across all websites and transaction types. Instead of requiring separate setup for each website, users authenticate with the same pseudonymous tokens universally. This multi-functional approach enables spoofed website detection while simplifying the process for new websites and e-commerce transactions.
Solution Approach 2:
The patent performs preliminary authentication setup by generating anonymized identifiers before transactions occur. Users receive pseudonymous tokens in advance that can be used immediately for authentication without on-the-spot setup. This preliminary action eliminates the need for cumbersome per-website configuration while maintaining security.
3Productivity
If conventional POS systems transmit PII for transactions, then payment processing can be completed, but security vulnerabilities increase and transaction efficiency decreases
Solution Approach 1:
The patent extracts PII from the transaction processing flow and replaces it with anonymized identifiers. Payment transactions are completed using pseudonymous tokens that do not contain sensitive user information. This separation allows efficient transaction processing while eliminating PII transmission vulnerabilities in POS systems.
Data Source
AI summary
The disclosed computer-implemented method for protecting personally identifiable information during electronic data exchanges may include (i) receiving, from a computing device, an authentication token for a proposed electronic data exchange, (ii) preventing the user's personally identifiable information from entering the proposed electronic data exchange by identifying the user using the anonymized identifier rather than using the user's personally identifiable information, (iii) authenticating the user identified in the data exchange information, and (iv) in response to authenticating the user, authorizing completion of the proposed electronic data exchange. Various other methods, systems, and computer-readable media are also disclosed.


