M2M Device Consent Resource Management for IoT Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In machine-to-machine (M2M) systems, there is a lack of effective methods to safely handle and confirm user consent for personal data, particularly in IoT devices, which is crucial for compliance with regulations like GDPR and ensuring data privacy.
Innovation Solution
A method and apparatus for M2M devices that obtain user consent information and create consent-related resources with attributes, enabling attribute-based, resource-based, or access control policy (ACP)-based consent management to ensure transparent and unambiguous user consent for processing personal data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If M2M systems process personal data from IoT devices, then system functionality and service capability are improved, but data privacy security and user consent management deteriorate
Solution Approach 1:
The patent segments consent management into distinct attributes (consentOwner, consentTimestamp, consentName, consentAllowedProcessing, consentValidity, consentExpirationTime, consentRightToWithdraw) that can be independently managed and applied to different data processing operations. This allows fine-grained control over personal data processing while maintaining system functionality.
Solution Approach 2:
The patent introduces an M2M device as an intermediary between IoT devices and personal data processing systems. This intermediary obtains consent information from users and manages consent attributes, acting as a mediator that ensures compliant data processing without compromising service capability.
2Device complexity
If traditional data processing methods are used in M2M systems, then system simplicity is maintained, but compliance with regulations like GDPR deteriorates
Solution Approach 1:
The patent creates a universal consent management framework that can be applied across different M2M systems and IoT applications. The consent attributes and management mechanism serve multiple functions including consent tracking, compliance verification, and user rights management, making the system adaptable to various regulatory requirements without redesign.
3Productivity
If user consent is not explicitly managed, then processing efficiency is improved, but data privacy protection and user rights deteriorate
Solution Approach 1:
The patent implements preliminary consent management by obtaining and recording consent information before personal data processing occurs. The consent attributes are established in advance, including consentOwner, consentTimestamp, and consentValidity, ensuring that processing efficiency is maintained while privacy protection is proactively ensured.
4Measurement precision
If detailed consent attributes are tracked, then consent management accuracy and user rights protection are improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent nests consent attributes within a structured framework where consent information is organized hierarchically. The consent attributes (consentOwner, consentTimestamp, consentName, etc.) are nested within the M2M device's data structure, allowing precise tracking while maintaining organized and manageable system architecture.
Data Source
AI summary
The present invention relates to a method and apparatus for handling personal data in a machine-to-machine (M2M) system, and an operation method of an M2M device includes obtaining information related to consent of a user for personal data provided from an Internet of things (IoT) device and creating a consent-related resource based on the information. The resource includes at least one attribute related to the consent.


