Information Management Module for Confidential Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electronic-enabled economies, the transmission of confidential information between parties often results in unauthorized access and exposure, leading to potential exploitation and detrimental consequences for both the subject and relying parties, due to the lack of control and accuracy in information sharing.
Innovation Solution
A method and apparatus that allow a subject entity to define and approve requests for confidential information, ensuring that only approved and accurate information is shared with a relying entity through an information management module, which manages the processing, transmission, and updating of confidential data, incorporating predefined queries and policies for privacy and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If confidential information is made widely available through purchase or third-party providers, then transaction facilitation and information accessibility are improved, but security and privacy protection deteriorate
Solution Approach 1:
The patent introduces an information management module as an intermediary between the subject entity, information providers, and relying parties. This module acts as a controlled gateway that manages information requests, enforces access policies, and coordinates approval workflows, thereby enabling information sharing while preventing unauthorized access through centralized control and policy enforcement
Solution Approach 2:
The system performs preliminary actions by establishing access policies, authentication mechanisms, and approval workflows before any confidential information is shared. Subject entities can pre-configure what information is accessible, to whom, and under what conditions, preventing unauthorized access before it can occur rather than reacting after breaches
2Productivity
If information is shared without subject entity approval, then transaction efficiency is improved, but accuracy and reliability of information sharing deteriorate
Solution Approach 1:
The patent implements feedback mechanisms where subject entities receive notifications about information requests and can approve or deny sharing decisions. The system tracks and communicates the status of information requests throughout the approval process, ensuring that only verified and authorized information is shared, thereby maintaining reliability while enabling efficient transactions through streamlined workflows
3Loss of information
If comprehensive confidential information is collected, then information completeness is improved, but risk of exploitation and breaches deteriorate
Solution Approach 1:
The patent segments confidential information into different categories and types (e.g., personally identifiable information, financial information, medical information) and applies granular access controls to each segment. Subject entities can control which specific segments are shared with which relying parties, ensuring information completeness for legitimate transactions while minimizing the risk surface by not exposing all information universally
Data Source
AI summary
In one embodiment, a method includes defining a request for confidential information from a domain of confidential information based on an input from a relying entity. The domain of confidential information can be associated with a subject entity. A response to the request can be defined at an information provider. The method can also include sending the response to the relying entity when the response has been approved by the subject entity.


