Data Host Access Control With Temporary Identifiers and Share Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing need for sharing personal data with third parties in online transactions poses significant security risks due to trustworthiness assessment challenges and network transmission vulnerabilities, along with regulatory burdens on service providers for managing and securing data.
Innovation Solution
A method and system for controlling data access where personal data is stored at a data host, using temporary identifiers and share keys to enable secure and reliable access by data clients, ensuring data is not directly shared and stored with clients, with features like time-limited access and unique identifiers to enhance security and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is shared directly with third parties for online transactions, then transaction convenience is improved, but security risks and trustworthiness assessment difficulties worsen
Solution Approach 1:
The patent introduces a data host as an intermediary between the data owner and data client. The data host stores data securely and provides controlled access through temporary identifiers and share keys, eliminating the need for direct data sharing while maintaining transaction convenience. This mediator approach resolves the contradiction by enabling secure data access without exposing raw data to third parties.
Solution Approach 2:
The patent uses temporary identifiers and share keys as copies or references to access data without transferring the actual data itself. The data client receives a share key that allows access to the data host's stored data, rather than receiving a copy of the data. This copying mechanism maintains security while enabling convenient data access for transactions.
2Adaptability or versatility
If data is stored with multiple third parties, then service provision capability is improved, but regulatory burden and data management complexity worsen
Solution Approach 1:
The patent consolidates data storage in a single data host rather than distributing it across multiple third parties. This merging approach reduces the regulatory burden and management complexity while maintaining the ability to provide various services through controlled data access mechanisms. The data host acts as a centralized authority that manages all data access requests.
Solution Approach 2:
The data host provides universal access to multiple data clients through a standardized mechanism involving temporary identifiers and share keys. This multi-functional system allows any authorized client to access data without requiring separate data management arrangements for each client, reducing overall system complexity while maintaining service versatility.
3Productivity
If data is transmitted over networks to multiple third parties, then transaction functionality is improved, but data transmission security risks worsen
Solution Approach 1:
The data host serves as a secure intermediary that receives data from the data owner and provides controlled access to data clients. This eliminates direct data transmission between multiple third parties over potentially insecure networks, reducing transmission security risks while maintaining transaction functionality through the mediator's secure access mechanisms.
Solution Approach 2:
The patent extracts the actual data from the transmission process by using temporary identifiers and share keys as placeholders. Only these lightweight identifiers and keys are transmitted over networks, not the actual data itself. This extraction of sensitive data from transmission reduces security risks while preserving transaction functionality through the share key access mechanism.
Data Source
AI summary
Systems and methods of enabling data access for a transaction between a data client and at least one data owner are described, wherein the data is stored at a data host. A method implemented at the data host includes storing data associated with the data owner in a data owner profile, the profile including a static identifier associated with the data owner and receiving from the data owner a request for a temporary identifier to enable access to the data by a data client. The temporary identifier is generated and transmitted to the data owner as well as being stored in the data owner profile. An access request for at least a portion of the stored data is received from the data client, the access request comprising the temporary identifier, an identifier of the data client, an indication of the scope of the request, and a duration associated with the request. It is first verified that access to the data can be enabled for the data client based on the information in the access request and a share key is transmitted to the data client for the requested data.


