Contract Broker for Secure Personal Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for device-enabled transactions lack the ability to securely and flexibly share only the necessary personal data, exposing sensitive information to unauthorized parties and failing to customize data exchange according to specific transaction needs.

Innovation Solution

A brokering server facilitates transactions by encoding ad-hoc rules as needs metadata, allowing clients to selectively share personal data with external applications without direct exposure, using a contract broker to manage and format data securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personal data is transmitted directly from client to external application, then transaction efficiency is improved, but data security and user control deteriorate

Engineering Contradiction:
Improvetransaction efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

A brokering server is introduced as an intermediary between the client device and external application. The server receives personal data from the client, encodes it according to ad-hoc rules, and relays only the necessary formatted data to the external application. This mediator approach maintains transaction efficiency while enhancing data security and user control over information disclosure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If all personal data is shared with external application, then transaction completeness is improved, but data exposure risk worsens

Engineering Contradiction:
Improvetransaction completenessVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments personal data into distinct fields and applies ad-hoc rules to encode only the specific portions needed for the transaction. The brokering server formats data elements selectively, separating necessary information from sensitive personal details, thereby ensuring transaction completeness while minimizing data exposure risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of personal data are treated differently based on their necessity for the specific transaction. The encoding process applies local quality control by formatting only the required data elements with appropriate precision and detail, rather than uniformly exposing all personal information.

Inventive Principle:
Principle #3Local quality

3Device complexity

If fixed data format is used for personal data transmission, then system simplicity is improved, but adaptability to different transaction needs deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoiddata format flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system employs dynamic data encoding where ad-hoc rules are applied to format personal data according to the specific needs of each transaction. The brokering server adjusts the data format and content based on the external application's requirements, providing adaptability while maintaining a relatively simple overall system architecture.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9407665B2Contract broker for secure ad-hoc personal data sharing
Publication Date: 2016.08.02 SALESFORCE INC
  • US9407665B2 patent drawing
  • US9407665B2 patent drawing
  • US9407665B2 patent drawing

AI summary

The present disclosure is directed to a system and method for sharing sensitive personal data such as personally identifying data and financial data of a user. In an aspect the exchange of data is facilitated by a trusted contract broker, which is in communication with a client device and an external application. The contract broker having access to needs and rules for each of the client device and the external application, and the contract broker brokering the secure exchange of data between the client device and the contract broker according to said needs and rules. In an aspect, an electronic representation of a subset of personal data needed to satisfy an ad-hoc rule of said external application is generated in a client device and delivered to the external application.