Secure PII Transfer via Direct User-to-Server Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital platforms pose security concerns for users and third-party businesses when sharing Personal Identifiable Information (PII), as messages are often routed through backend servers, risking unauthorized access and storage of sensitive data.

Innovation Solution

Implementing a system that enables users to submit PII directly to third-party businesses without routing through the digital platform's backend servers, using a secure connection and encryption to ensure only the intended recipient has access to the information, thereby reducing the risk of data exposure and storage by the platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If messages are routed through backend servers of the digital platform, then the platform can access and store PII information, but security and privacy of the PII transfer is compromised

Engineering Contradiction:
Improvesecurity of PII transferVSAvoidPII access by digital platform
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the PII data transfer path from the digital platform's backend servers by establishing a direct peer-to-peer connection between the user's computing device and the third-party business server. This removes the intermediary server that would otherwise access and store the PII, thereby resolving the contradiction between platform accessibility and security/privacy concerns.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a secure connection protocol that enables direct communication between the user's device and the third-party server without routing through the digital platform's servers. This intermediary secure channel maintains security while eliminating the harmful intermediary (platform server) that would access the data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If direct connection between user and third-party business is established, then security and privacy of PII is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity of PII transferVSAvoidcommunication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing messaging service infrastructure and digital platform for authentication, message delivery, and session management. By making the digital platform serve multiple functions (communication channel + security gateway), the system achieves secure direct transfer without significantly increasing device complexity, as the complex infrastructure already exists in the platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If PII is transferred through messaging service, then ease of operation is maintained, but security concerns arise due to platform access and storage

Engineering Contradiction:
Improveuser interaction simplicityVSAvoidplatform access to PII
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses the messaging service as a secure intermediary channel that facilitates direct peer-to-peer communication. The messaging service remains an intermediary in terms of message routing, but the actual PII transfer occurs through a secure direct connection initiated within the messaging interface, maintaining ease of operation while eliminating platform storage of the data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11615197B1Secure information transfer
Publication Date: 2023.03.28 META PLATFORMS INC
  • US11615197B1 patent drawing
  • US11615197B1 patent drawing
  • US11615197B1 patent drawing

AI summary

Techniques are described for providing secure and direct communication between two parties. In some examples, a business server (e.g., a first party), may send a request to a social networking system. The request may include an identifier associated with an end user (e.g., a second party) and an indication of one or more types of information to be requested from the user. In some examples, the user may submit user information to the business server. The user information may include sensitive and/or personal information of the user. The user information may be input by the user into an application associated with the social networking system. The user information may be sent securely and directly from the application on the user's device to the business server and is not accessible by the social networking system.