Consent Management via Granular Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional consent management systems are computationally expensive, time-consuming, and lack sufficient security for user data protection, as they fail to provide fine-scale distinctions in access control and often rely on third-party compliance for revoking permissions, leading to potential unauthorized data sharing and use.
Innovation Solution
A computer-implemented method and system that allows users to specify granular consent information, enabling real-time access control by encrypting user data based on consent status and associated metadata, ensuring only authorized parties access the data for permitted purposes, using techniques like Merkel trees for secure and context-aware encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional consent management systems are used to store user consent information and track data sharing, then basic consent tracking is achieved, but the systems are computationally expensive and time-consuming to implement
Solution Approach 1:
The system uses self-service mechanisms where the encryption system automatically manages consent verification and data protection without requiring manual intervention from users or third parties, reducing implementation time and computational overhead
Solution Approach 2:
The patent changes the fundamental parameter of consent management from centralized tracking to decentralized encryption-based control, where consent status is embedded in encryption keys rather than stored in centralized databases, dramatically improving efficiency
2Reliability
If conventional consent management systems make coarse distinctions about data access, then implementation is simpler, but they do not provide sufficient security or fine-scale control over third-party access
Solution Approach 1:
The patent segments consent control into fine-grained categories including specific third parties, data types, purposes, and time periods. Each segment is independently controllable through the encryption system, allowing precise management of data access rights without overwhelming complexity
Solution Approach 2:
The system adds multiple dimensions to access control by incorporating spatial (which third party), temporal (when), functional (for what purpose), and categorical (which data type) dimensions, enabling fine-scale control while maintaining system manageability
3Reliability
If users manually update security preferences to revoke consent in conventional systems, then consent revocation is achieved, but it takes time and relies on third-party compliance to erase data
Solution Approach 1:
The system performs preliminary action by pre-configuring automatic revocation mechanisms where consent withdrawal immediately invalidates the encryption keys, preventing further access without requiring manual data erasure by third parties
Solution Approach 2:
The encryption system acts as an intermediary between users and third parties, where the system automatically enforces consent revocation by key invalidation, eliminating reliance on third-party compliance and reducing revocation time
4Reliability
If detailed tracking of data sharing and usage is implemented, then consent management is more comprehensive, but the system becomes more computationally expensive
Solution Approach 1:
The patent extracts the computationally intensive tracking function from centralized systems and embeds it in the encryption mechanism itself, where consent verification is performed locally through cryptographic operations rather than continuous centralized monitoring
Data Source
AI summary
The present disclosure relates to a computer-implemented method for controlling access to user data of a user. The method comprises: receiving, by a data controller, an access request requesting access to the user data; determining, by the data controller, a consent status and one or more item of information associated with the user data; encrypting, by the data controller, the user data in an encrypted data package encrypted based on the consent status and one or more item of information; and sending, by the data controller, the encrypted data package in response to the access request.


