Cryptographic Token System for PII Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers are hesitant to use third-party services that require sharing personally identifiable information (PII) due to concerns about privacy and identity theft, leading to a dilemma between accessing convenient services and protecting their personal information.

Innovation Solution

A cryptographic system where a service provider generates a cryptographic key pair, with the private key stored on their device, allowing them to contact customers via a processing server that authenticates the service provider using a digital signature, ensuring communication without revealing the customer's PII.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the service provider receives the customer's phone number or PII to enable direct contact, then the service provider can contact the customer directly for questions or assistance, but the customer's privacy is compromised and personally identifiable information is exposed to the service provider

Engineering Contradiction:
Improvecontact capabilityVSAvoidcustomer PII
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces a processing server as an intermediary between the service provider and the customer. The server receives communication requests from the service provider, validates digital signatures, and forwards communications to the customer's device without disclosing the customer's PII to the service provider. This mediator enables contact capability while preventing PII loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical information-sharing mechanism (directly providing phone numbers to service providers) with a cryptographic authentication mechanism. Digital signatures and public key infrastructure enable verification of service provider identity without transferring sensitive contact information, substituting information transfer with cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If the customer refuses to share personal information with the service provider, then customer privacy is protected, but the customer cannot access convenient third-party services

Engineering Contradiction:
Improvecustomer PIIVSAvoidservice accessibility
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The processing server acts as a gateway that allows service providers to contact customers without requiring the customer to share their PII. The server validates authentication credentials and routes communications through itself, enabling service accessibility while maintaining privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent substitutes the traditional contact mechanism (requiring PII sharing) with a cryptographic authentication system. Service providers authenticate through digital signatures, and the server establishes communications without exposing customer PII, thereby maintaining both privacy and service accessibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If the service provider uses traditional contact methods requiring customer PII, then direct communication is enabled, but security risks and identity theft concerns increase

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional contact methods with a cryptographic authentication system. Digital signatures provide secure verification of service provider identity, and the processing server encrypts and routes communications to prevent interception or misuse, thereby reducing security risks while maintaining communication efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The processing server serves as a secure intermediary that handles all communications between service providers and customers. It validates authentication credentials cryptographically and forwards messages without exposing PII to either party, reducing security risks associated with direct PII sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11301583B2Method and system for protection of customer PII via cryptographic tokens
Publication Date: 2022.04.12 MASTERCARD INT INC
  • US11301583B2 patent drawing
  • US11301583B2 patent drawing
  • US11301583B2 patent drawing

AI summary

A method for facilitating communications while protecting customer privacy through cryptography and withholding of personally identifiable information includes: storing, in a memory of a processing server, contact data and a reference value associated with a first external computing device; receiving, by a receiver of the processing server, a communication request from a second external computing device, the communication request including at least the reference value and a digital signature; validating, by a processor of the processing server, the digital signature using a communicator public key of a cryptographic key pair; receiving, by the receiver of the processing server, a communication message from the second external computing device; and forwarding, by a transmitter of the processing server, the communication message to the first external computing device using the stored contact data following successful validation of the digital signature.