Cryptographic Token System for PII Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers are hesitant to use third-party services that require sharing personally identifiable information (PII) due to concerns about privacy and identity theft, leading to a dilemma between accessing convenient services and protecting their personal information.
Innovation Solution
A cryptographic system where a service provider generates a cryptographic key pair, with the private key stored on their device, allowing them to contact customers via a processing server that authenticates the service provider using a digital signature, ensuring communication without revealing the customer's PII.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the service provider receives the customer's phone number or PII to enable direct contact, then the service provider can contact the customer directly for questions or assistance, but the customer's privacy is compromised and personally identifiable information is exposed to the service provider
Solution Approach 1:
The patent introduces a processing server as an intermediary between the service provider and the customer. The server receives communication requests from the service provider, validates digital signatures, and forwards communications to the customer's device without disclosing the customer's PII to the service provider. This mediator enables contact capability while preventing PII loss.
Solution Approach 2:
The patent replaces the traditional mechanical information-sharing mechanism (directly providing phone numbers to service providers) with a cryptographic authentication mechanism. Digital signatures and public key infrastructure enable verification of service provider identity without transferring sensitive contact information, substituting information transfer with cryptographic verification.
2Loss of information
If the customer refuses to share personal information with the service provider, then customer privacy is protected, but the customer cannot access convenient third-party services
Solution Approach 1:
The processing server acts as a gateway that allows service providers to contact customers without requiring the customer to share their PII. The server validates authentication credentials and routes communications through itself, enabling service accessibility while maintaining privacy protection.
Solution Approach 2:
The patent substitutes the traditional contact mechanism (requiring PII sharing) with a cryptographic authentication system. Service providers authenticate through digital signatures, and the server establishes communications without exposing customer PII, thereby maintaining both privacy and service accessibility.
3Ease of operation
If the service provider uses traditional contact methods requiring customer PII, then direct communication is enabled, but security risks and identity theft concerns increase
Solution Approach 1:
The patent replaces traditional contact methods with a cryptographic authentication system. Digital signatures provide secure verification of service provider identity, and the processing server encrypts and routes communications to prevent interception or misuse, thereby reducing security risks while maintaining communication efficiency.
Solution Approach 2:
The processing server serves as a secure intermediary that handles all communications between service providers and customers. It validates authentication credentials cryptographically and forwards messages without exposing PII to either party, reducing security risks associated with direct PII sharing.
Data Source
AI summary
A method for facilitating communications while protecting customer privacy through cryptography and withholding of personally identifiable information includes: storing, in a memory of a processing server, contact data and a reference value associated with a first external computing device; receiving, by a receiver of the processing server, a communication request from a second external computing device, the communication request including at least the reference value and a digital signature; validating, by a processor of the processing server, the digital signature using a communicator public key of a cryptographic key pair; receiving, by the receiver of the processing server, a communication message from the second external computing device; and forwarding, by a transmitter of the processing server, the communication message to the first external computing device using the stored contact data following successful validation of the digital signature.


