Blockchain Consent Management with Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing consent for services and disclosing confidential information are inefficient and prone to errors, particularly in scenarios requiring multiple consents and secure record-keeping, such as medical services and law enforcement agencies, often relying on paper documents and manual processes.

Innovation Solution

A computer-implemented method using distributed ledger technology, such as blockchain, Hedera Hashgraph, or IOTA Tangle, for secure and immutable record-keeping, combined with a consent management service API, consent requesting API, and consent authorizing application to authenticate and manage signatures for consent, utilizing QR codes and biometric data for secure and tamper-proof consent records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If paper documents and manual processes are used for consent management, then ease of operation is maintained, but reliability and security of consent records deteriorate

Engineering Contradiction:
Improvesecurity of consent recordsVSAvoidcomplexity of consent management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual paper-based consent management with an automated digital system using blockchain technology. The mechanical process of signing physical documents is substituted with electronic signature capture via mobile devices, and the manual verification process is replaced with automated cryptographic verification on the blockchain network, thereby improving reliability while managing complexity through automation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a blockchain network as an intermediary between consenting parties and service providers. This decentralized ledger acts as a neutral mediator that securely stores and verifies consent records without requiring direct trust between parties, thereby enhancing security while distributing system complexity across multiple nodes rather than concentrating it in a single centralized system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distributed ledger technology is implemented for consent management, then reliability and tamper-proof record-keeping are improved, but device complexity and implementation difficulty worsen

Engineering Contradiction:
Improvetamper-proof record-keepingVSAvoidcomplexity of distributed ledger implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a multi-functional consent management system that combines mobile device interfaces, electronic signature capture, blockchain transaction processing, and automated verification capabilities into a single integrated platform. This universal system handles multiple functions (consent collection, verification, storage, and sharing) through a unified architecture, reducing the perceived complexity for users while maintaining the robustness of distributed ledger technology.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If manual consent processes are used, then ease of operation is maintained, but productivity and efficiency of consent management deteriorate

Engineering Contradiction:
Improveefficiency of consent managementVSAvoidease of consent process
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements a self-service consent management system where individuals can independently create, store, and share their own consent records through mobile devices. The system automatically handles signature capture, blockchain transaction submission, and verification processes without requiring manual intervention from administrators or service providers, thereby significantly improving productivity while maintaining ease of operation through intuitive user interfaces.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If electronic signature capture with biometric data is implemented, then authenticity and non-repudiation of consent are improved, but device complexity and processing requirements worsen

Engineering Contradiction:
Improveauthenticity verification of signatureVSAvoidcomplexity of biometric processing system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces traditional signature verification methods with biometric authentication using mobile device sensors. Instead of manually verifying signatures against stored samples, the system uses fingerprint scanners, facial recognition, or other biometric sensors built into modern smartphones to automatically verify the identity of the consenting individual, thereby improving measurement precision of authenticity while leveraging existing device capabilities to minimize additional complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10949636B2Consent management apparatus and system
Publication Date: 2021.03.16 CONSENTS ANYWHERE LLC
  • US10949636B2 patent drawing
  • US10949636B2 patent drawing
  • US10949636B2 patent drawing

AI summary

A computer implemented apparatus and method is provided for authenticating a signature for a consent requiring permission of a person (i.e., a client) to be given for a service by a service provider. In the apparatus, the service provider requests a physical signature from the person. The request is made with a text message or QR code linking to a method for the person to create a signature (for example, a touch screen). The signature and related account and identifying information about the person is entered into a distributed ledger database (DLTD) (e.g., a blockchain database) where it is archived. The service provider can query the DLTD for the signature for consent for the service. Consent can also be provided to third party agencies with a need for consent for information the service provider.