Off-Chain Blockchain Architecture for GDPR Compliant PII Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current blockchain architectures are inadequate for managing personally identifiable information (PII) due to their 'invariability' nature, which conflicts with the General Data Protection Regulation (GDPR) requirements for data deletion and modification, as they do not allow for dynamic changes or user consent-based data handling.

Innovation Solution

An off-chain blockchain architecture is proposed that uses both a local database and a distributed ledger, where PII is stored in the database and its hash is stored on the blockchain, allowing for user consent-based data sharing, deletion, and modification, with a consensus mechanism ensuring compliance with GDPR.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PII is stored in blockchain using traditional architecture, then data immutability and security are improved, but ability to delete or modify data according to GDPR is lost

Engineering Contradiction:
Improvedata securityVSAvoiddata deletion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides data into two categories: PII (personally identifiable information) that requires deletion capability and is stored in traditional databases, and non-PII data that benefits from blockchain immutability. This segmentation allows each type of data to be stored in the most appropriate system, resolving the contradiction between security/immutability and deletion capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hybrid architecture that acts as an intermediary between blockchain and traditional databases. This intermediary layer manages data placement, consent tracking, and deletion operations, allowing the system to maintain both blockchain security benefits and GDPR compliance for PII deletion.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If all user data is collected and stored for business analysis, then business value and user profiling capability are improved, but user privacy control and data security are worsened

Engineering Contradiction:
Improvebusiness valueVSAvoidprivacy risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic consent management where users can control their data sharing preferences at different times. The system adapts to user choices by dynamically adjusting what data is collected and shared with third parties, allowing business value extraction while respecting user privacy control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes feedback mechanisms where users are notified about data collection and sharing activities, and can provide or revoke consent. This feedback loop ensures that data processing aligns with user intentions, reducing privacy risks while maintaining business operations.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If third party services are used for customer authentication, then service functionality is improved, but data breach risk and security vulnerability are increased

Engineering Contradiction:
Improveservice functionalityVSAvoiddata breach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive PII from third-party service dependencies by implementing decentralized authentication mechanisms. Users maintain control of their authentication data locally, and only necessary non-sensitive information is shared with third parties, reducing the attack surface and data breach risks associated with third-party services.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11979504B2Blockchain architecture conforming to general data protection regulation for management of personally identifiable information
Publication Date: 2024.05.07 INJE UNIVERSITY INDUSTRY ACADEMIC COOPERATION FOUNDATION
  • US11979504B2 patent drawing
  • US11979504B2 patent drawing
  • US11979504B2 patent drawing

AI summary

Incidents involving confidentiality and vigilance against user privacy invasions raise doubts as to current third-party data collection procedures. Personally identifiable information (PII) is being abused for medical data breaches, identity theft, spam, phishing, cyber spying, etc. A great amount of data is flowing from users to companies for prediction and analysis of data-centric markets. It is thus difficult to track PII flow and genuineness. Blockchain technology, which is an “immutable” distributed ledger, can efficiently track PII exchange, storing, and distribution. In contrast, the EU general data protection regulation (GDPR) in progress claims “a right to forget” and a right “to delete”. However, the present specification proposes an off-chain blockchain architecture using both a local database and a distributed ledger to guarantee a trustable PII life cycle.