PII Protection via Dynamic Trust-Based Header Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users have limited control over the sharing of personally identifiable information (PII) when accessing websites, as third-party sites often collect and aggregate information without users' knowledge or consent, leading to privacy concerns.

Innovation Solution

A mechanism that allows users to control the amount of PII shared with websites based on their trust level, using a negotiation protocol (Prenurâ„¢) that modifies HTTP headers and cookies, and alters JavaScript execution to ensure tailored sharing of information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users share PII with third-party websites, then websites can provide personalized services and functionality, but user privacy is compromised and information is collected without user knowledge or consent

Engineering Contradiction:
Improvewebsite functionalityVSAvoidprivacy loss
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing user trust levels and defining PII sharing policies before any information exchange occurs. The trust level is calculated in advance based on website characteristics, and PII sharing decisions are predetermined based on these trust levels, preventing unauthorized information collection before it happens.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism that mediates between the user and third-party websites. This intermediary evaluates website trustworthiness, determines appropriate PII sharing levels, and enforces sharing policies, acting as a protective layer that enables website functionality while preventing privacy violations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If users avoid visiting websites to protect privacy, then PII is not shared with aggregators, but users lose access to legitimate services and information

Engineering Contradiction:
Improveprivacy protectionVSAvoidservice accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically changes the parameter of information sharing based on the trust level of the website. Instead of a binary approach (share all or share nothing), the system adjusts the degree of PII sharing according to calculated trust levels, allowing users to access services while maintaining appropriate privacy protection levels.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The PII sharing policy is made dynamic rather than static. The system continuously evaluates website trust levels and adjusts sharing decisions in real-time, allowing users to benefit from legitimate services while automatically protecting against privacy violations based on current trust assessments.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If pre-packaged privacy options are provided, then implementation is simple, but users cannot control specific portions of their information or storage duration

Engineering Contradiction:
Improvesystem implementationVSAvoiduser control flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments PII into different categories and applies different sharing policies to different types of information based on trust levels. Instead of treating all information uniformly, the system divides PII into segments that can be shared selectively, allowing granular control over what information is disclosed to which websites.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system provides dynamic control over information sharing by adjusting sharing levels based on website trust levels. Users can control specific portions of their information and storage duration through the calculated trust level, which determines the appropriate sharing policy for each website interaction.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11003782B2Protection of personally identifiable information
Publication Date: 2021.05.11 AT&T INTELLECTUAL PROPERTY I L P
  • US11003782B2 patent drawing
  • US11003782B2 patent drawing
  • US11003782B2 patent drawing

AI summary

Methods, systems, and products protect personally identifiable information. Many websites acquire the personally identifiable information without a user's knowledge or permission. Here, though, the user may control what personally identifiable information is shared with any website. For example, the personally identifiable information may be read from a header of a packet and compared to a requirement associated with a domain name.