Proximity-Based Authentication for Personal Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Individuals face challenges in managing and securing their personal data, particularly in ensuring that sensitive information is only accessed by authorized entities, as existing solutions fail to prevent unauthorized access and determine the entitlement of data requesters.

Innovation Solution

A proximity-based authentication system that uses an access controller to manage personal data access by determining the location of an authentication device and a data access device, allowing data release only if they are within a threshold distance, thereby inferring the owner's permission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal information is shared directly with third parties, then the ease of operation is improved, but the reliability of data security deteriorates

Engineering Contradiction:
Improveease of data sharingVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a proximity authentication system as an intermediary between the user and third-party data requests. The system uses location data from GPS, cell towers, and Wi-Fi to verify that the requesting device is physically close to the user before allowing data access. This mediator layer maintains ease of data sharing while enforcing security through proximity verification, resolving the contradiction between operational convenience and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user mechanisms are used to store private information, then the ease of operation is improved, but the ability to prevent unauthorized access deteriorates

Engineering Contradiction:
Improveease of data managementVSAvoidunauthorized access prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing proximity-based authentication rules in advance. Before any data access occurs, the system pre-configures which third-party applications can request data and under what proximity conditions. When a data request comes in, the system has already determined the authorized locations and can quickly verify whether the requesting device is in an approved location, preventing unauthorized access while maintaining user-friendly data management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If proximity-based authentication is implemented, then the reliability of data security is improved, but the device complexity increases

Engineering Contradiction:
Improvedata access securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by making the existing mobile device perform multiple functions: it serves as both the user's personal data store and the authentication device. The same device that contains the user's information also captures location data through built-in GPS, cell tower triangulation, and Wi-Fi positioning. This eliminates the need for separate authentication hardware, reducing overall system complexity while maintaining strong security through proximity verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8693988B2System, method, and apparatus for proximity-based authentication for managing personal data
Publication Date: 2014.04.08 HCL TECH LTD
  • US8693988B2 patent drawing
  • US8693988B2 patent drawing
  • US8693988B2 patent drawing

AI summary

A computer program product that includes a computer useable storage medium to store a computer readable program for proximity-based authentication for managing personal data that, when executed on a computer, causes the computer to perform operations. The operations include receiving a request for personal data from a data access device, determining a first location corresponding to a location of the data access device, and determining a second location corresponding to a location of an authentication device. The operations also include transmitting the personal data to the data access device if the first location is within a threshold distance of the second location.