Blockchain Consent Registration with Policy Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for administering consent lack flexibility and verifiability, making it difficult to prove that consent was given properly, especially in multi-party scenarios and under time-limited conditions, and are vulnerable to tampering and identity theft.
Innovation Solution
A blockchain-based system for registering and managing dynamic consent, allowing multiple parties to freely approve or withdraw consent, with a consent policy engine that includes a policy lookup table, consent state table, and consent history table, enabling unequal consent weighting and hierarchical consent mechanisms, and providing irrefutable records of consent provenance and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If consent records are stored in a traditional database, then the system is simple to implement, but the records are vulnerable to tampering, backdating, and faking
Solution Approach 1:
The patent replaces traditional database storage with a blockchain-based distributed ledger system. This substitution of the storage mechanism provides cryptographic immutability and tamper-evidence for consent records, eliminating the vulnerability to backdating and faking while maintaining system reliability.
Solution Approach 2:
The patent introduces a consent policy engine as an intermediary component that manages consent requests, evaluations, and registrations. This intermediary layer coordinates between multiple parties (data subjects, data processors, auditors) and maintains a centralized policy framework that ensures consistent and reliable consent management across the system.
2Reliability
If multi-party consent is required, then compliance with regulations like HIPAA and GDPR is improved, but the complexity of managing and verifying consent increases
Solution Approach 1:
The patent segments the consent management system into distinct functional components: a policy lookup table for storing consent policies, a consent state table for tracking current consent status, and a consent history table for maintaining audit trails. This segmentation allows each component to handle specific aspects of multi-party consent management independently, reducing overall system complexity.
Solution Approach 2:
The blockchain-based consent registration system serves multiple functions simultaneously: it provides tamper-proof record storage, enables multi-party consent tracking, maintains audit histories, and supports regulatory compliance verification. This multi-functionality reduces the need for separate systems and simplifies the overall architecture despite the complexity of multi-party consent requirements.
3Adaptability or versatility
If time-limited consent windows are implemented, then flexibility in consent management is improved, but the difficulty of tracking and verifying consent within time constraints increases
Solution Approach 1:
The patent implements feedback mechanisms through the consent state table that continuously tracks the current state of consent for each data subject and processor. The system provides real-time feedback on consent status, expiration times, and verification results, making it easier to monitor time-limited consent windows and ensure compliance without increasing verification difficulty.
Data Source
AI summary
Multi-party consent to performance of an action is securely registered by receiving from at least one consent requesting entity (CRE) a consent action request (CAR), which is matched with a consent policy. The policy may specify a plurality of consent voting entities (CVE), and direct confirmation of registration of an identity of each CVE in a blockchain. A consent request (CR) may then be issued to the CVEs. Consent request responses (CRRs) from the CVEs are then compared with at least one condition in the consent policy. A representation of a state of the CRRs is relative to the consent policy is registered in the blockchain. If the policy condition(s) is satisfied, a subject entity may be signaled to perform the action corresponding to the CAR, and a state indication of performance of the action may also be registered in the blockchain.
