Reverse Authorization Identity Control via Segmented Data Release

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for associating user identity with mobile devices do not provide adequate control over how identity information is used by third parties, leading to potential over-exposure of personal information during transactions.

Innovation Solution

A method and apparatus for reverse authorization using Near Field Communication (NFC) that involves an identity device, an authorization server, and a white list system, where the identity device transmits a request for authorization to the server, and upon approval, releases specific categories of identity information to third parties for transaction completion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity information is transmitted to third parties for transaction completion, then transaction functionality is improved, but user privacy and security deteriorate due to potential over-exposure of personal information

Engineering Contradiction:
Improvetransaction functionalityVSAvoidprivacy exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments identity information into multiple categories (e.g., basic information, financial information, personal details) and implements granular authorization controls for each category. The authorization server divides access rights by information type, allowing users to selectively permit access to specific segments rather than all information at once, thus enabling transactions while protecting sensitive segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authorization server acts as an intermediary between the user's identity device and third parties. It receives transaction requests, verifies user authorization decisions, and selectively releases appropriate identity information categories to third parties. This mediator prevents direct unauthorized access while enabling legitimate transactions through controlled information disclosure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If all identity information is made available to third parties, then transaction completeness is improved, but security control deteriorates due to lack of user oversight

Engineering Contradiction:
Improvetransaction completenessVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements dynamic authorization where users can real-time control which identity information categories are accessible during transactions. Authorization levels can be adjusted based on transaction context, user preferences, and risk assessment. This dynamic control allows comprehensive information availability when needed while maintaining security oversight through user-manageable authorization settings.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of information accessibility from a binary state (all or nothing) to a multi-level parameter system where different categories of identity information can be independently controlled. Users can adjust authorization parameters for each information category, enabling transaction completeness for necessary categories while maintaining security control by restricting access to sensitive categories.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If identity information access is restricted to protect privacy, then security is improved, but transaction functionality deteriorates due to limited information availability

Engineering Contradiction:
Improveprivacy protectionVSAvoidtransaction functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authorization setup where users pre-configure which identity information categories can be shared with third parties under specific conditions. Before transactions occur, authorization policies are established in advance, allowing users to define their privacy preferences and transaction conditions beforehand. This preliminary action enables smooth transactions within authorized boundaries while maintaining privacy protection for restricted categories.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authorization server provides universal access control functionality that works across different transaction types and third parties. A single authorization framework manages multiple information categories and various transaction scenarios, making the system adaptable to diverse transaction needs while consistently enforcing privacy protections. This multi-functional approach ensures both privacy protection and transaction enablement across different contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11436594B2Apparatus and method for reverse authorization
Publication Date: 2022.09.06 SAMSUNG ELECTRONICS CO LTD
  • US11436594B2 patent drawing
  • US11436594B2 patent drawing
  • US11436594B2 patent drawing

AI summary

An apparatus and method for user identity control are provided. The apparatus includes a communication unit, a storage unit including a unique ID and a plurality of sections, each section including different identity information, and a controller for, in response to a transaction request, transmitting a request for identity information to an authorization server via the communication unit, and for, in response to authorization information received from the authorization server, transmitting identity information to a third party to complete the transaction according to the received authorization information.