Biometric Tag Data Encryption for Privacy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The ease with which electronic content can be uploaded and shared online raises privacy concerns, as individuals may not have control over their biometric information being associated with the content without their consent, potentially violating privacy rights.

Innovation Solution

A system that encrypts tag data associated with individuals in electronic content, requiring the individual's consent before decryption and public availability, using a cryptographic key sent to the individual via secure channels, allowing them to control the use of their biometric information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If tag data is made publicly available without encryption, then accessibility and ease of operation are improved, but privacy and security are worsened

Engineering Contradiction:
Improveaccessibility of tag dataVSAvoidprivacy violation risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encryption mechanism as an intermediary between the tag data and the public. The encryption key acts as a mediator that must be provided to any user who wishes to access tag data, thereby controlling accessibility while maintaining privacy. This resolves the contradiction by allowing public availability only under controlled conditions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption is applied to tag data, then privacy and security are improved, but device complexity and operational difficulty are worsened

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system automatically generates and manages encryption keys without requiring manual intervention. The key management is handled self-service through automated processes, reducing the operational burden on users while maintaining strong encryption. This mitigates the complexity increase by automating what would otherwise be manual tasks.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If consent mechanism is implemented for taggee, then privacy and legal compliance are improved, but process time and operational steps are worsened

Engineering Contradiction:
Improveunauthorized data useVSAvoidconsent process duration
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The encryption key is provided to the taggee in advance before the tagging process completes. This preliminary action allows the taggee to review and consent to the association beforehand, or at least have the opportunity to do so without delaying the final tagging operation. The key is made available prior to public availability of tag data, enabling timely consent.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9560022B1Avoiding collection of biometric data without consent
Publication Date: 2017.01.31 GOOGLE LLC
  • US9560022B1 patent drawing
  • US9560022B1 patent drawing
  • US9560022B1 patent drawing

AI summary

Electronic content, such as an image, video, or audio file, may be tagged as being associated with an individual. When the electronic content contains biometric data related to the individual, the individual's authorization may be required or preferred before the requested association is made or shared. In a method, a request is received from a tagger to associate a taggee with electronic content. Before the association is made (and potentially shared), the tag data is encrypted. The cryptographic key is sent to the taggee. The encrypted tag data is stored and indexed based on an address associated with the taggee, such as the taggee's email address. When the taggee receives and activates the cryptographic key, the tag data is decrypted and an association is made between the taggee and the electronic content. Biometric data of the taggee included in the electronic content may then be collected and shared.