Hash-Based Consent Protocols for Dynamic Third-Party Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing environments face challenges in managing and implementing secure, dynamic consent and permissioning protocols for third-party applications accessing confidential data across network-connected devices and systems, particularly in open banking environments.

Innovation Solution

A system and method that utilize a consent and permissioning engine to generate consent documents, compute hash values, and transmit permissioning data to devices, enabling secure storage and association of consent hash values with access tokens, while allowing dynamic management of data access permissions based on user consent.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional consent management systems are used, then data access control is maintained, but system complexity and manual management overhead increase

Engineering Contradiction:
Improveconsent management easeVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables self-service consent management by allowing users to automatically grant, revoke, and manage permissions for third-party applications through automated hash generation and verification. The consent engine automatically processes requests without requiring manual intervention, reducing operational complexity while maintaining secure access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms consent management from manual parameter-based control to automated hash-based verification. By converting consent documents into cryptographic hashes and storing them in decentralized ledgers, the system changes the fundamental parameters of how consent is recorded, verified, and managed, reducing system complexity while improving operational ease.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If centralized consent management is implemented, then access control is maintained, but decentralization and immutability are compromised

Engineering Contradiction:
Improveconsent verification reliabilityVSAvoiddecentralization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments consent management functionality across multiple decentralized ledgers rather than concentrating it in a single centralized system. Each ledger maintains independent copies of consent hashes, enabling distributed verification while ensuring reliability. This segmentation allows the system to achieve both decentralized versatility and reliable consent verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic hash values as intermediary elements that bridge centralized authorization decisions with decentralized verification. The hash function acts as an intermediary that transforms consent documents into immutable, verifiable identifiers that can be stored across multiple ledgers, enabling both reliability and decentralization simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive consent tracking is implemented, then permission accuracy is improved, but data processing time increases

Engineering Contradiction:
Improvepermission accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts the essential verification information from comprehensive consent documents by generating cryptographic hashes. Instead of processing entire consent documents during verification, the system extracts and verifies only the hash values, which contain all necessary permission accuracy information. This extraction dramatically reduces data processing time while maintaining measurement precision.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates efficient copies of consent information through cryptographic hashing. The hash values serve as compact, verifiable copies that preserve all necessary permission details without requiring the full original documents. This copying approach enables comprehensive consent tracking with minimal data processing time, as the system only needs to verify hash values rather than process complete consent documents.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If dynamic permission updates are implemented, then adaptability is improved, but system stability and consistency are compromised

Engineering Contradiction:
Improvepermission dynamic update capabilityVSAvoidsystem consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system implements dynamic permission updates by enabling real-time generation and propagation of new consent hashes across decentralized ledgers. When user permissions change, the system dynamically creates new hash values and updates them across the network, maintaining adaptability while preserving consistency through cryptographic verification and consensus mechanisms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously verifies hash consistency across multiple ledgers and notifies relevant parties of permission changes. This feedback loop ensures that dynamic updates maintain system stability by confirming consistency across all copies before accepting changes, thereby preserving both adaptability and stability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12407511B2Dynamic implementation and management of hash-based consent and permissioning protocols
Publication Date: 2025.09.02 THE TORONTO DOMINION BANK
  • US12407511B2 patent drawing
  • US12407511B2 patent drawing
  • US12407511B2 patent drawing

AI summary

Computer-implemented systems, apparatuses, and processes that dynamically implement and manage hash-based consent and permissioning protocols. By way of example, an apparatus may obtain consent data that identifies one or more elements of data accessible to an application program executed by a device. The apparatus may generate a consent document for the application program based on at least a portion of the consent data, and may compute a consent hash value representative of the consent document. The apparatus may also generate and transmit permissioning data that includes at least the consent hash value to the device. The permissioning data may, for example, include information that instructs the executed application program to store the consent hash value within a local memory of the device and to associate the consent hash value with an access token of the executed application program.