Hierarchical Token Architecture for Granular Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies lack granular control over data access and fail to enable consumers to exercise control over their own data, compromising data security and privacy.
Innovation Solution
A token-based architecture that allows a manufacturer to control data access by issuing digital credentials to trusted entities, with conditions such as time- and location-based restrictions, and requires consumer consent through a visual marker like a QR Code for access to sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is shared with retail partners and employees to provide personalized consumer experiences, then consumer service quality improves, but data security and privacy control deteriorate
Solution Approach 1:
The patent segments data access rights by creating a hierarchical token system where different entities (manufacturer, retail partner, employee) receive different levels of access. The master token held by the manufacturer can delegate subset tokens to retail partners, which can further delegate to employees, creating granular segmented access control that maintains security while enabling personalized service.
Solution Approach 2:
The patent introduces tokens as intermediary digital credentials that mediate between data holders and data users. These tokens act as secure intermediaries that enable controlled data sharing without direct exposure of sensitive information, allowing personalized experiences while maintaining security through the token mediation layer.
2Ease of operation
If broad access to consumer data is granted to enable personalized service, then service personalization improves, but consumer privacy control deteriorates
Solution Approach 1:
The patent implements dynamic access control where consumer consent is required for each data access event. The system dynamically adjusts access rights based on real-time consumer authorization, allowing personalized service when consent is given while automatically restricting access when consent is withdrawn, thus maintaining privacy control.
Solution Approach 2:
The patent requires preliminary consumer consent before any data access occurs. The system obtains authorization in advance through consumer initiation or explicit permission, ensuring privacy control is established before personalized service can be delivered, preventing unauthorized access while enabling service when appropriate.
3Reliability
If granular data access control is implemented to maintain security, then data protection improves, but system complexity increases
Solution Approach 1:
The patent implements a nested token hierarchy where master tokens contain and can delegate to subset tokens, which can further contain employee-specific tokens. This nested structure organizes complex access control relationships in a manageable hierarchical framework, reducing system complexity while maintaining granular security control.
Solution Approach 2:
The patent creates universal token structures that can serve multiple functions across different entities. The same token framework serves the manufacturer, retail partners, and employees with different access levels, providing a unified multi-functional system that reduces complexity compared to separate access control systems for each entity.
4Object-generated harmful factors
If consumer consent mechanisms are required for data access, then privacy control improves, but access speed and efficiency deteriorate
Solution Approach 1:
The patent obtains consumer consent in advance before data access is needed. By requiring consumer initiation or preliminary permission, the system secures authorization beforehand, enabling faster subsequent data access without repeated consent requests, thus reducing time loss while maintaining privacy protection.
Data Source
AI summary
Aspects of the technology described herein provide for controlled access to a secure computing resource. A first device may receive a child token from a second device having a parent token. The child token may grant the first device access to a subset of data accessible to the second device. Based on a degree of physical proximity between the first device and a third device associated with a user satisfying a threshold proximity, an indication of a user identifier for the user may be received from the third device. A request for access to a secure computing resource associated with the user may be sent to the second device. The request may include the indication of the user identifier and an indication of the secure computing resource. Access to the secure computing resource may be granted based on the child token and the indication of the identifier.


