Consent Management via Granular Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional consent management systems are computationally expensive, time-consuming, and lack sufficient security for user data protection, as they fail to provide fine-scale distinctions in access control and often rely on third-party compliance for revoking permissions, leading to potential unauthorized data sharing and use.

Innovation Solution

A computer-implemented method and system that allows users to specify granular consent information, enabling real-time access control by encrypting user data based on consent status and associated metadata, ensuring only authorized parties access the data for permitted purposes, using techniques like Merkel trees for secure and context-aware encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional consent management systems are used to store user consent information and track data sharing, then basic consent tracking is achieved, but the systems are computationally expensive and time-consuming to implement

Engineering Contradiction:
Improvedata protectionVSAvoidimplementation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system uses self-service mechanisms where the encryption system automatically manages consent verification and data protection without requiring manual intervention from users or third parties, reducing implementation time and computational overhead

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the fundamental parameter of consent management from centralized tracking to decentralized encryption-based control, where consent status is embedded in encryption keys rather than stored in centralized databases, dramatically improving efficiency

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional consent management systems make coarse distinctions about data access, then implementation is simpler, but they do not provide sufficient security or fine-scale control over third-party access

Engineering Contradiction:
Improvedata securityVSAvoidaccess control granularity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments consent control into fine-grained categories including specific third parties, data types, purposes, and time periods. Each segment is independently controllable through the encryption system, allowing precise management of data access rights without overwhelming complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds multiple dimensions to access control by incorporating spatial (which third party), temporal (when), functional (for what purpose), and categorical (which data type) dimensions, enabling fine-scale control while maintaining system manageability

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If users manually update security preferences to revoke consent in conventional systems, then consent revocation is achieved, but it takes time and relies on third-party compliance to erase data

Engineering Contradiction:
Improveconsent revocationVSAvoidrevocation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring automatic revocation mechanisms where consent withdrawal immediately invalidates the encryption keys, preventing further access without requiring manual data erasure by third parties

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption system acts as an intermediary between users and third parties, where the system automatically enforces consent revocation by key invalidation, eliminating reliance on third-party compliance and reducing revocation time

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If detailed tracking of data sharing and usage is implemented, then consent management is more comprehensive, but the system becomes more computationally expensive

Engineering Contradiction:
Improveconsent trackingVSAvoidcomputational cost
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive tracking function from centralized systems and embeds it in the encryption mechanism itself, where consent verification is performed locally through cryptographic operations rather than continuous centralized monitoring

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11983284B2Consent management methods
Publication Date: 2024.05.14 ARM CLOUD TECH INC
  • US11983284B2 patent drawing
  • US11983284B2 patent drawing
  • US11983284B2 patent drawing

AI summary

The present disclosure relates to a computer-implemented method for controlling access to user data of a user. The method comprises: receiving, by a data controller, an access request requesting access to the user data; determining, by the data controller, a consent status and one or more item of information associated with the user data; encrypting, by the data controller, the user data in an encrypted data package encrypted based on the consent status and one or more item of information; and sending, by the data controller, the encrypted data package in response to the access request.