Hierarchical Token Architecture for Granular Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies lack granular control over data access and fail to enable consumers to exercise control over their own data, compromising data security and privacy.

Innovation Solution

A token-based architecture that allows a manufacturer to control data access by issuing digital credentials to trusted entities, with conditions such as time- and location-based restrictions, and requires consumer consent through a visual marker like a QR Code for access to sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is shared with retail partners and employees to provide personalized consumer experiences, then consumer service quality improves, but data security and privacy control deteriorate

Engineering Contradiction:
Improvepersonalized consumer experienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments data access rights by creating a hierarchical token system where different entities (manufacturer, retail partner, employee) receive different levels of access. The master token held by the manufacturer can delegate subset tokens to retail partners, which can further delegate to employees, creating granular segmented access control that maintains security while enabling personalized service.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces tokens as intermediary digital credentials that mediate between data holders and data users. These tokens act as secure intermediaries that enable controlled data sharing without direct exposure of sensitive information, allowing personalized experiences while maintaining security through the token mediation layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If broad access to consumer data is granted to enable personalized service, then service personalization improves, but consumer privacy control deteriorates

Engineering Contradiction:
Improveservice personalizationVSAvoidprivacy loss
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent implements dynamic access control where consumer consent is required for each data access event. The system dynamically adjusts access rights based on real-time consumer authorization, allowing personalized service when consent is given while automatically restricting access when consent is withdrawn, thus maintaining privacy control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent requires preliminary consumer consent before any data access occurs. The system obtains authorization in advance through consumer initiation or explicit permission, ensuring privacy control is established before personalized service can be delivered, preventing unauthorized access while enabling service when appropriate.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If granular data access control is implemented to maintain security, then data protection improves, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested token hierarchy where master tokens contain and can delegate to subset tokens, which can further contain employee-specific tokens. This nested structure organizes complex access control relationships in a manageable hierarchical framework, reducing system complexity while maintaining granular security control.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent creates universal token structures that can serve multiple functions across different entities. The same token framework serves the manufacturer, retail partners, and employees with different access levels, providing a unified multi-functional system that reduces complexity compared to separate access control systems for each entity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Object-generated harmful factors

If consumer consent mechanisms are required for data access, then privacy control improves, but access speed and efficiency deteriorate

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata access time
Core Design Contradiction:
Object-generated harmful factorsVSLoss of time

Solution Approach 1:

The patent obtains consumer consent in advance before data access is needed. By requiring consumer initiation or preliminary permission, the system secures authorization beforehand, enabling faster subsequent data access without repeated consent requests, thus reducing time loss while maintaining privacy protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250036807A1Controlling access to a secure computing resource
Publication Date: 2025.01.30 NIKE INC
  • US20250036807A1 patent drawing
  • US20250036807A1 patent drawing
  • US20250036807A1 patent drawing

AI summary

Aspects of the technology described herein provide for controlled access to a secure computing resource. A first device may receive a child token from a second device having a parent token. The child token may grant the first device access to a subset of data accessible to the second device. Based on a degree of physical proximity between the first device and a third device associated with a user satisfying a threshold proximity, an indication of a user identifier for the user may be received from the third device. A request for access to a secure computing resource associated with the user may be sent to the second device. The request may include the indication of the user identifier and an indication of the secure computing resource. Access to the secure computing resource may be granted based on the child token and the indication of the identifier.