Self-Exclusion Platform for Identity Attribute Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in coordinating and enforcing self-exclusion preferences for data access and sharing, particularly in networks where personal identifying information is stored and managed by multiple identity providers.
Innovation Solution
The implementation of a self-exclusion platform that uses tokens to impose rules on data access and sharing, by linking identity attributes to self-exclusion preferences and generating tokens that are redeemed at the self-exclusion platform to enforce these preferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If personal identifying information is stored in centralized or distributed storage and disseminated in response to requests, then data accessibility and sharing efficiency are improved, but data security and user privacy control deteriorate
Solution Approach 1:
The patent segments personal identifying information into multiple identity attributes, each with its own access control rules. Instead of treating PII as a single centralized data structure, the system divides it into discrete attributes (e.g., name, address, phone number) that can be independently controlled and shared. This segmentation allows selective disclosure of only necessary attributes to specific relying parties, improving security while maintaining sharing efficiency.
Solution Approach 2:
The patent introduces self-exclusion preferences as an intermediary mechanism between users and relying parties. These preferences act as pre-defined access control rules that automatically mediate data sharing decisions. When a user sets self-exclusion preferences for specific relying parties or types of relying parties, the system automatically enforces these restrictions without requiring real-time negotiation, thus maintaining efficient data sharing while enhancing security control.
2Reliability
If self-exclusion preferences are enforced through centralized control by identity providers, then data access control is improved, but system complexity and coordination overhead worsen
Solution Approach 1:
The patent implements self-exclusion preferences as preliminary access control rules that are established in advance by users. Instead of requiring complex real-time coordination between multiple identity providers to enforce access control, users pre-define their exclusion preferences for specific relying parties or categories of relying parties. These pre-configured rules are then automatically applied when data access requests occur, eliminating the need for complex runtime coordination and significantly reducing system complexity.
Solution Approach 2:
The patent enables users to self-manage their own data access control through self-exclusion preferences. Users independently configure which relying parties should be excluded from accessing their identity attributes, without requiring intervention or coordination from identity providers. This self-service approach shifts control to the users themselves and eliminates the coordination overhead that would otherwise be required for centralized access control enforcement across multiple providers.
3Adaptability or versatility
If identity attributes are shared with multiple relying parties, then data utility and service accessibility are improved, but risk of information exposure and privacy violations worsen
Solution Approach 1:
The patent applies local quality by allowing different access control rules for different identity attributes and different relying parties. Instead of applying a uniform access control policy to all data sharing scenarios, the system enables users to specify granular self-exclusion preferences for specific attributes (e.g., exclude phone number but allow name sharing) and for specific types of relying parties (e.g., exclude gambling entities but allow healthcare providers). This localized control approach maximizes data utility by allowing selective sharing while minimizing exposure risk through attribute-specific and party-specific restrictions.
Data Source
AI summary
Systems and methods are provided for imposing self-exclusion preferences for data access. One example computer-implemented method includes, in response to a request by a user to impose a self-exclusion preference on a digital identity of the user, requesting a token for the digital identity. The method also includes receiving and storing the token and a secret associated with the token in a record associated with the user and assigning the self-exclusion preference to the token. The method then includes receiving a request to share an identity attribute of the user's digital identity with a relying party, where the request includes the token, and retrieving the self-exclusion preference assigned to the token. And, in response to validation of the request to share the identity attribute, based on the self-exclusion preference, authorizing a mobile device of the user to share the at least one identity attribute with the relying party.


