Secure Token System for Personal Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of ensuring payment device security and the unauthorized use of personal data by network sites pose challenges in controlling sensitive information, especially as fraud becomes more sophisticated and data collection becomes widespread without user consent.

Innovation Solution

A system that allows entities to create permission rules for sharing sensitive data through a secure computing environment, using tokens to control access and communication with various sensors and networks, ensuring data is shared only with authorized parties and for specific purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network sites collect data on users to target communications, then marketing effectiveness is improved, but user control over personal data is lost

Engineering Contradiction:
Improvemarketing effectivenessVSAvoiduser control over data
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent introduces a personal information system as an intermediary between users and network sites. This system includes a central storage area that securely holds personal information and releases it only according to user-defined access rules, thereby mediating data access while maintaining user control and enabling targeted marketing communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a central storage area is provided for secure data access, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The personal information system enables users to independently manage their own data security through self-service mechanisms. Users can define access rules, authenticate themselves using biometric recognition devices, and control who accesses their information without requiring complex centralized management infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If user authentication devices with biometric recognition are deployed, then access control is improved, but device complexity and cost increase

Engineering Contradiction:
Improveaccess controlVSAvoidauthentication device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical authentication methods (such as physical cards or passwords) with biometric recognition technology. This substitution uses biological characteristics (fingerprints, facial recognition, etc.) to authenticate users, providing more reliable access control while reducing the need for complex mechanical security systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3149626B1Personal area network
Publication Date: 2019.07.03 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3149626B1 patent drawingFigure 1
  • EP3149626B1 patent drawingFigure 2
  • EP3149626B1 patent drawingFigure 3

AI summary

An entity may store various levels of sensitive and personal data in a secure computing environment. The entity may create permission rules which allow the data to be shared or not shared depending on the circumstances and situation. As an entity such as a human moves through life, the entity may be in touch with numerous electronic devices that act like sensors. The entity may share a token which may allow a sensor or operator of the sensor to access various levels of the sensitive data stored in the secure computing environment.