Consent Management via Blockchain and Neutral Proxy Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Protecting user data privacy and managing access rights between data subjects, data providers, and data consumers in a way that maintains anonymity while enabling secure data sharing and access, is a significant technical challenge due to conflicting objectives and the need for compliance with privacy policies and regulations.

Innovation Solution

A consent management system utilizing a cryptographic ledger (blockchain) and a neutral proxy server to record and manage consent requests and responses, ensuring data privacy and security by maintaining the anonymity of data consumers and subjects, while allowing data consumers to access data from data providers in compliance with regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional centralized consent management system is used, then data access control can be implemented, but data subject privacy and consumer anonymity cannot be protected

Engineering Contradiction:
Improvedata access controlVSAvoidprivacy and anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

A neutral proxy server is introduced as an intermediary component that sits between data consumers and data providers. The proxy server receives data access requests from consumers, verifies consent status by querying the blockchain ledger, and forwards approved requests to the data provider. This intermediary architecture enables centralized access control while preserving the anonymity of both data subjects and consumers, as the proxy server communicates with parties using pseudonymous identifiers from the blockchain without revealing their real identities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional centralized consent management databases with a decentralized blockchain ledger. Instead of relying on a single administrative entity to manage and verify consent records, the system uses a distributed immutable ledger where consent transactions are cryptographically recorded and verified by multiple nodes. This substitution eliminates the need for trust in a central authority while maintaining reliable access control, and the cryptographic nature of blockchain ensures privacy and anonymity of participants.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If data consumers directly access data from data providers, then data sharing efficiency is improved, but unauthorized access and privacy violations increase

Engineering Contradiction:
Improvedata sharing efficiencyVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary consent verification before allowing any data access. Data subjects can pre-grant consent to specific data consumers for specific data types and purposes, and these consent decisions are recorded on the blockchain ledger in advance. When a data consumer requests access, the neutral proxy server queries the blockchain to verify whether consent has been previously granted, eliminating the need for real-time authorization negotiations and enabling efficient access while ensuring compliance with data subject wishes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The neutral proxy server acts as a security intermediary that filters and validates all data access requests. It queries the blockchain ledger to verify consent status before allowing the data provider to share data with the consumer. This intermediary layer prevents unauthorized access by blocking requests that lack valid consent verification, while still enabling efficient authorized access through automated blockchain-based verification, thus resolving the contradiction between access efficiency and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If consent management is manual and centralized, then coordination between parties is simplified, but system complexity and compliance burden increase

Engineering Contradiction:
Improvecoordination simplicityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables self-service consent management where data subjects can independently view, manage, and revoke their consent decisions through a user interface that queries the blockchain ledger. The automated smart contracts on the blockchain automatically verify consent status and enforce access control policies without requiring manual intervention from administrators or coordination between multiple parties. This self-service approach simplifies coordination for users while the underlying blockchain automation reduces overall system complexity by eliminating manual consent tracking and verification processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20210099313A1Method, apparatus, and system for providing a consent management system on a crytographic ledger
Publication Date: 2021.04.01 HERE GLOBAL BV
  • US20210099313A1 patent drawing
  • US20210099313A1 patent drawing
  • US20210099313A1 patent drawing

AI summary

An approach is provided for a consent management using a cryptographic ledger (e.g., a blockchain). The approach, for example, involves providing a cryptographic ledger. The cryptographic ledger includes one or more data records that store metadata indicating a consent request from a data consumer to provide an access to data owned by a data subject, a consent response from the data subject to the consent request, or a combination thereof. The approach also comprises providing a neutral server to read the data from a database of a data provider on behalf of the data consumer based on the cryptographic ledger.