Blockchain Mobility-as-a-Service Data Separation for GDPR Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing MaaS solutions face challenges in protecting personal data privacy while maintaining accurate journey records, as personal data is often openly recorded and immutable in distributed ledgers, conflicting with regulations like GDPR.
Innovation Solution
Implementing a communication network with nodes that separate sensitive and non-sensitive user data, using pseudonymization and anonymization techniques, and employing permissioned blockchains to ensure only authorized parties access and manage user data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If personal data is recorded in distributed ledger, then journey record accuracy is improved, but user privacy is worsened
Solution Approach 1:
The patent segments user data into two distinct categories: sensitive personal data (stored locally in user devices) and non-sensitive journey data (stored in the distributed ledger). This segmentation allows the system to maintain accurate journey records in the blockchain while protecting sensitive information, directly resolving the contradiction between record accuracy and privacy protection.
Solution Approach 2:
The patent extracts sensitive personal data from the distributed ledger system and stores it separately in user-controlled local storage. Only non-sensitive journey data is extracted and stored in the blockchain. This extraction approach enables accurate journey tracking while removing the privacy risk associated with storing sensitive data in the distributed ledger.
2Reliability
If data is stored immutably in distributed ledger, then data integrity is improved, but compliance with GDPR right to erasure is worsened
Solution Approach 1:
The patent applies segmentation by storing only non-sensitive, GDPR-compliant journey data in the immutable blockchain, while keeping sensitive data that requires erasure rights in mutable local storage. This resolves the contradiction by ensuring that the immutable ledger contains only data that should permanently exist, while sensitive data subject to erasure rights remains outside the blockchain.
Solution Approach 2:
The patent extracts sensitive personal data from the distributed ledger system entirely, storing it only in user-controlled local storage where it can be erased when needed. This extraction allows the blockchain to maintain its immutable integrity while the system as a whole complies with GDPR erasure requirements through local data management.
3Device complexity
If centralized gateway is used for MaaS, then system complexity is reduced, but single point of failure risk is increased
Solution Approach 1:
The patent extracts the central gateway functionality and distributes it across multiple blockchain nodes. Each node independently validates and stores journey data, eliminating the single point of failure while maintaining system functionality. The distributed nature of blockchain provides redundancy and continued operation even when individual nodes fail.
Solution Approach 2:
The patent merges the functions of multiple independent service providers into a unified distributed ledger system. Different mobility providers can independently write to the same blockchain, creating a consolidated journey record system without requiring a central coordinating gateway. This merging approach reduces complexity by eliminating the gateway layer while improving reliability through distributed consensus.
Data Source
AI summary
The present disclosure provides a communication network node for providing data to a distributed ledger, wherein the node has circuitry configured to:provide a user data management part for separating sensitive user data and non-sensitive user data, andprovide the non-sensitive user data to the distributed ledger.


