Proximity-Based Authorization for Personal Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face repetitive, time-consuming, and complex processes when interacting with web services, leading to potential security vulnerabilities as multiple web services store personal information, increasing liability and reputational risks for service providers.
Innovation Solution
A method and system that utilize a personal computing device's proximity to authorize data access, allowing users to control the provision of data from a third-party device without repeatedly entering information, using permission data to automatically or optionally authorize requests, and providing feedback to users on data access, thus reducing the burden on both users and service providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If web services collect and store personal information from users to provide personalized services and maintain user accounts, then service functionality and user experience are improved, but security vulnerabilities and liability risks increase
Solution Approach 1:
The patent extracts the personal information storage function from web services and relocates it to a dedicated third-party device. Web services no longer store user data locally but instead access it through authorized requests to the third-party device, thereby eliminating the security vulnerabilities associated with storing sensitive information across multiple service providers.
Solution Approach 2:
The third-party device acts as an intermediary between users and web services. It holds the master copy of personal information and mediates access requests from web services through an authorization system. This intermediary structure allows personalized services to function while centralizing security control and reducing the harmful effects of data storage fragmentation.
2Adaptability or versatility
If users provide their personal information to multiple web services to enable service functionality, then service accessibility is improved, but time consumption and operational complexity increase
Solution Approach 1:
The third-party device serves multiple web services with a single master copy of user information. Instead of users providing data to each service separately, the system uses universal access mechanisms where authorized web services can retrieve information from the third-party device, reducing redundant data entry and time consumption.
Solution Approach 2:
The system implements feedback mechanisms where the third-party device provides authorization status information to web services. This feedback loop allows services to verify user authorization without requiring users to manually provide information to each service, streamlining the access process and reducing time loss.
3Ease of operation
If web services hold copies of personal information to avoid requiring users to re-enter data, then user convenience is improved, but the burden on service providers to manage data storage and security increases
Solution Approach 1:
The patent extracts the data storage and management function from individual web services and consolidates it in a dedicated third-party device. This extraction relieves service providers of the complex burden of managing personal information storage while maintaining user convenience through authorized access to the centralized data source.
Solution Approach 2:
The third-party device serves as an intermediary that handles all data storage and management complexities. It provides web services with simplified access mechanisms, allowing them to maintain user convenience without directly managing the complexity of data storage, security, and synchronization across multiple services.
4Measurement precision
If users repeatedly enter personal information for different web service transactions, then data accuracy is maintained, but operational complexity and user frustration increase
Solution Approach 1:
The system uses feedback from the third-party device to provide web services with verified user information. The authorization mechanism provides feedback that confirms data accuracy while simplifying the user interaction process, eliminating the need for repeated data entry while maintaining precision through centralized verification.
Data Source
AI summary
Techniques for controlling the provision of data to a requester use a local device communicating with a personal computing device. The personal computing device has an authorized state and an unauthorized state. If the personal computing device is proximal to the local device when the local device receives the request for data from the requester, then the personal computing device uses permission data it stores to determine whether the request is or is not a permitted request. If the request is a permitted request, then the personal computing device sends a message to a token issuing device to issue a token request to the requester. The requester then uses this token to access a third party device holding the data to which it seeks access.


