IoT Device Cookie System for Secure Third-Party Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a system that enables secure and controlled communication between portable personal devices and third-party entities in a retail environment, ensuring user privacy while allowing for personalized interactions and incentives, as existing technologies lack effective mechanisms for managing user data and privacy in Internet of Things (IoT) devices.

Innovation Solution

The implementation of an IoT device cookie system that allows users to grant permission for third-party entities to interact with their devices, with customizable security levels and data sharing options, using a non-browser and non-internet based communication method, including a cookie structure with security profiles and whitelist databases to manage access and data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users share personal information with third-party entities for personalized interactions, then user experience and revenue opportunities improve, but user privacy and data security are compromised

Engineering Contradiction:
Improvepersonalized interactionsVSAvoiduser privacy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments user data into different categories (identifiable vs. anonymized information) and implements tiered access controls where third-party entities can only access anonymized data unless explicit permission is granted. This segmentation allows personalized interactions using anonymized data while protecting identifiable personal information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary cookie management system that acts as a mediator between users and third-party entities. The cookie contains anonymized device information that enables third parties to provide personalized services without directly accessing identifiable user data, thus protecting privacy while enabling personalization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If third-party entities access user data for targeted marketing, then revenue opportunities increase, but user control over data sharing is reduced

Engineering Contradiction:
Improverevenue opportunitiesVSAvoiduser control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements dynamic cookie management where users can modify their data sharing preferences at any time. The system dynamically updates cookie permissions based on user choices, allowing users to grant or revoke access to different types of data (location, device info, browsing history) independently, thus maintaining user control while enabling targeted marketing when permitted.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms where users are notified when cookies are placed or modified, and can review and adjust their data sharing preferences. This feedback loop ensures users maintain awareness and control over their data sharing decisions while third-party entities can access necessary information for marketing purposes.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If comprehensive data collection is implemented for personalized services, then service personalization improves, but system complexity and data management burden increase

Engineering Contradiction:
Improveservice personalizationVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates anonymized copies of user device information in the form of cookies, which contain sufficient data for personalization (device type, location, browsing behavior patterns) without replicating sensitive personal identifiers. This copying approach enables service personalization while simplifying data management by working with standardized anonymized data structures rather than complex raw data sets.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3157227B1Method, apparatus and computer program product for a cookie used for an internet of things device
Publication Date: 2020.04.08 NOKIA TECHNOLOGIES OY
  • EP3157227B1 patent drawingFigure 1
  • EP3157227B1 patent drawingFigure 2
  • EP3157227B1 patent drawingFigure 3

AI summary

Provided herein is a method, apparatus, and computer program product for a system to facilitate local communication between a plurality of portable personal devices and a third party entity using an internet of things. An apparatus may be provided including at least one processor and at least one memory including computer program code. The apparatus may be caused to: receive a cookie from a third party entity; compare the cookie to a database of trusted cookies; initiate a user interface for accepting or rejecting the cookie in response to the cookie not corresponding to a trusted cookie; receive a selection to either accept or reject the cookie; receive a security profile to apply to the cookie in response to the receiving a selection to accept the cookie; apply the security profile to the cookie; and store the cookie in the database of trusted cookies.