Ephemeral Identifier Verification for Secure Privacy Requests
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Client devices face issues with data security and privacy as they transmit requests over public networks, where communications can be intercepted or manipulated by malicious entities, leading to unauthorized data sharing and lack of user control over how their data is used.
Innovation Solution
A data security system generates subscription tokens with encrypted user identifiers and attachment elements for each content platform, allowing users to manage data privacy settings through a central platform, ensuring only eligible entities receive, store, and use their data securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user identification information is transmitted over public networks, then content delivery can be personalized, but communications can be intercepted or manipulated by malicious entities
Solution Approach 1:
A data security system acts as an intermediary between the client device and content providers. The system receives a request for a subscription token including user identification information, generates a subscription token with encrypted user identifier, and transmits it to the publisher computing system. This intermediary approach allows personalized content delivery while protecting user identification information from interception and manipulation over public networks.
Solution Approach 2:
Instead of transmitting the actual user identification information, the system creates an encrypted copy (subscription token) that contains an encrypted user identifier. This copy can be transmitted safely over public networks and used for personalized content delivery without exposing the original user identification information to potential interceptors.
2Productivity
If user identification information is shared with content providers, then content can be delivered to users, but users lack control over how their data is used
Solution Approach 1:
The system provides users with control mechanisms to manage their data privacy settings. Users can specify which entities are eligible to receive, store, and use their data. The data security system incorporates these user preferences into the subscription token generation process, allowing users to control how their data is used while maintaining efficient content delivery through the automated token system.
3Reliability
If encryption is applied to user identifiers, then data security is improved, but computational resources are consumed
Solution Approach 1:
The system extracts only the essential user identifier information needed for content delivery and encrypts only this specific data element within the subscription token. By taking out only the necessary information for identification and personalization rather than encrypting all user data, the system maintains data security while minimizing computational resource consumption.
Data Source
AI summary
This disclosure relates to data security and cryptography. In one aspect, a method includes updating a user interface of a client device to present user interface controls that enable a user to specify data privacy settings that define how entities collect, store, and use data of the user. The data security system receives a request to modify a data privacy setting for one or more entities from the client device based on user interaction with one or more of the user interface controls. The request includes an ephemeral user identifier for the user and an attestation token. The data security system validates the request using at least the ephemeral user identifier and the attestation token. The data security system transmits data instructing the entity to modify usage of the user data based on the modified given data privacy setting to each of the one or more entities.


