Protected Data Access Dashboard for Relationship-Based Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing access to protected data resources for care recipients are limited in functionality, require substantial input from care recipients who may be incapacitated or lack digital literacy, and provide little flexibility for setting individual user rights, leading to improper handling of private information and logistical challenges.

Innovation Solution

A dashboard tool that enables care providers to access protected data through a simple interface, allowing configuration of transaction and spend thresholds, and provides recommendations for user permissions based on relationship analysis across multiple data sources, including historical account records and transaction history.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual assignment of user rights is used, then security control is maintained, but flexibility and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidflexibility in setting user rights
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service through automated relationship detection and permission recommendation. The system automatically detects relationships between care providers and care recipients using multiple data sources, generates permission recommendations, and allows care recipients to approve or modify these recommendations without manual administrator intervention. This maintains security through recipient approval while dramatically improving ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary layer between manual security control and automated access. The relationship detection module analyzes multiple data sources (transaction history, account records, communication patterns) to generate relationship probability scores, which then inform permission recommendations. This intermediary automated analysis reduces the burden of manual assignment while maintaining security through the recommendation-approval workflow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If substantial input from care recipients is required, then access control security is maintained, but productivity and ease of operation deteriorate when recipients are incapacitated or lack digital literacy

Engineering Contradiction:
Improveaccess control securityVSAvoidspeed of providing access
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by automatically detecting relationships and generating permission recommendations before care recipients need to provide input. The relationship detection module proactively analyzes data sources and prepares permission recommendations in advance, so when care recipients do need to approve, the work is already done - they only need to review and confirm, dramatically speeding up the process while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing care recipients to review and approve pre-generated permission recommendations without needing digital literacy or complex interactions. The simplified approval process, combined with automated relationship detection, allows recipients to maintain security control while requiring minimal input, solving the problem when they are incapacitated or lack digital skills.

Inventive Principle:
Principle #25Self-service

3Device complexity

If limited functionality tools are used, then system complexity is reduced, but adaptability and versatility deteriorate

Engineering Contradiction:
Improvesystem simplicityVSAvoidfunctionality for managing personal accounts
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system achieves universality by using a single dashboard interface that performs multiple functions: relationship detection, permission recommendation, access control, and account management. The relationship detection module analyzes multiple data sources (transaction history, account records, communication patterns) to provide comprehensive relationship assessment, while the same interface handles permission management. This multi-functional approach provides extensive adaptability without increasing apparent system complexity for users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments complex functionality into modular components: relationship detection module, permission recommendation module, approval workflow, and access control module. Each module handles a specific aspect of the access management process, allowing the system to provide comprehensive functionality while maintaining simplicity through clear separation of concerns. The dashboard presents these segmented functions in an integrated, user-friendly interface.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250307454A1System and methods for managing access to a protected data resource
Publication Date: 2025.10.02 THE TORONTO DOMINION BANK
  • US20250307454A1 patent drawing
  • US20250307454A1 patent drawing
  • US20250307454A1 patent drawing

AI summary

A computer-implemented method is disclosed. The method includes: receiving, via a user interface on a first computing device at a first time, an access request for accessing a specified account; obtaining data capturing account activity of the specified account prior to the first time; determining a first status of a first requesting account associated with the access request based on the obtained data, the first status indicating a determined relationship between the specified account and the first requesting account; and configuring the user interface to selectively enable account features of the specified account based on the first status of the first requesting account.