Remote Profile Security System with Session-Based Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face privacy and security concerns regarding the creation and use of user profile information by software service providers, as they may not have control over how their interactions are recorded and used for customization, especially in situations where they do not want certain activities to be associated with their profiles.
Innovation Solution
A system that allows users to manage their user profile information by providing authorization information on a session-by-session basis, enabling them to control access and encryption of their profile data, ensuring that restricted information is only accessible with their consent and temporarily decrypted for authorized interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user profile information is automatically generated and stored by service providers, then service customization and personalization are improved, but user privacy and security control are worsened
Solution Approach 1:
The patent segments user profile information into multiple categories (e.g., demographic information, browsing history, purchase behavior) and applies different access control policies to each segment. This allows the system to provide customized services using certain profile segments while restricting access to sensitive segments, thereby resolving the contradiction between service personalization and privacy protection.
Solution Approach 2:
The patent introduces an access control module as an intermediary between the service provider system and user profile information. This intermediary enforces access control policies that determine which parts of the profile can be accessed for service customization, thus enabling personalized services while maintaining user privacy and security control.
2Productivity
If service providers access user profile information for customization, then service quality is improved, but user security control is worsened
Solution Approach 1:
The patent implements preliminary action by requiring users to pre-configure their access control policies and preferences before service providers access their profile information. Users can define in advance which parts of their profile can be accessed and under what conditions, thus maintaining ease of control while enabling high-quality customized services.
Solution Approach 2:
The patent incorporates feedback mechanisms that allow users to review and adjust access control policies based on their service experiences. The system provides feedback about how profile information is being used for customization, enabling users to maintain control while benefiting from improved service quality.
3Adaptability or versatility
If search history is permanently stored on servers, then service personalization is improved, but user privacy control is worsened
Solution Approach 1:
The patent applies dynamics by making search history storage and access dynamic rather than static. The system can adjust the retention period, access permissions, and visibility of search history based on user preferences and contextual factors. This allows the system to maintain accurate user profiles for personalization while limiting privacy exposure through time-based and context-based access control.
Data Source
AI summary
A method comprises storing, at the server computer system, user profile information for the remote user. The user profile information for the remote user (or a link to the user profile information) is encrypted using authentication information. The user profile information is associated with user identification information, at the server computer system, using the authentication information, which is selectively made available by the remote user via the network to the server computer system in order to enable the server computer system to associate the user profile information with the user identification information.


