Reverse Authorization Identity Control via Segmented Data Release
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for associating user identity with mobile devices do not provide adequate control over how identity information is used by third parties, leading to potential over-exposure of personal information during transactions.
Innovation Solution
A method and apparatus for reverse authorization using Near Field Communication (NFC) that involves an identity device, an authorization server, and a white list system, where the identity device transmits a request for authorization to the server, and upon approval, releases specific categories of identity information to third parties for transaction completion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If identity information is transmitted to third parties for transaction completion, then transaction functionality is improved, but user privacy and security deteriorate due to potential over-exposure of personal information
Solution Approach 1:
The patent segments identity information into multiple categories (e.g., basic information, financial information, personal details) and implements granular authorization controls for each category. The authorization server divides access rights by information type, allowing users to selectively permit access to specific segments rather than all information at once, thus enabling transactions while protecting sensitive segments.
Solution Approach 2:
The authorization server acts as an intermediary between the user's identity device and third parties. It receives transaction requests, verifies user authorization decisions, and selectively releases appropriate identity information categories to third parties. This mediator prevents direct unauthorized access while enabling legitimate transactions through controlled information disclosure.
2Productivity
If all identity information is made available to third parties, then transaction completeness is improved, but security control deteriorates due to lack of user oversight
Solution Approach 1:
The system implements dynamic authorization where users can real-time control which identity information categories are accessible during transactions. Authorization levels can be adjusted based on transaction context, user preferences, and risk assessment. This dynamic control allows comprehensive information availability when needed while maintaining security oversight through user-manageable authorization settings.
Solution Approach 2:
The patent changes the parameter of information accessibility from a binary state (all or nothing) to a multi-level parameter system where different categories of identity information can be independently controlled. Users can adjust authorization parameters for each information category, enabling transaction completeness for necessary categories while maintaining security control by restricting access to sensitive categories.
3Reliability
If identity information access is restricted to protect privacy, then security is improved, but transaction functionality deteriorates due to limited information availability
Solution Approach 1:
The system performs preliminary authorization setup where users pre-configure which identity information categories can be shared with third parties under specific conditions. Before transactions occur, authorization policies are established in advance, allowing users to define their privacy preferences and transaction conditions beforehand. This preliminary action enables smooth transactions within authorized boundaries while maintaining privacy protection for restricted categories.
Solution Approach 2:
The authorization server provides universal access control functionality that works across different transaction types and third parties. A single authorization framework manages multiple information categories and various transaction scenarios, making the system adaptable to diverse transaction needs while consistently enforcing privacy protections. This multi-functional approach ensures both privacy protection and transaction enablement across different contexts.
Data Source
AI summary
An apparatus and method for user identity control are provided. The apparatus includes a communication unit, a storage unit including a unique ID and a plurality of sections, each section including different identity information, and a controller for, in response to a transaction request, transmitting a request for identity information to an authorization server via the communication unit, and for, in response to authorization information received from the authorization server, transmitting identity information to a third party to complete the transaction according to the received authorization information.


