Self-Exclusion Platform for Identity Attribute Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in coordinating and enforcing self-exclusion preferences for data access and sharing, particularly in networks where personal identifying information is stored and managed by multiple identity providers.

Innovation Solution

The implementation of a self-exclusion platform that uses tokens to impose rules on data access and sharing, by linking identity attributes to self-exclusion preferences and generating tokens that are redeemed at the self-exclusion platform to enforce these preferences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personal identifying information is stored in centralized or distributed storage and disseminated in response to requests, then data accessibility and sharing efficiency are improved, but data security and user privacy control deteriorate

Engineering Contradiction:
Improvedata sharing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments personal identifying information into multiple identity attributes, each with its own access control rules. Instead of treating PII as a single centralized data structure, the system divides it into discrete attributes (e.g., name, address, phone number) that can be independently controlled and shared. This segmentation allows selective disclosure of only necessary attributes to specific relying parties, improving security while maintaining sharing efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces self-exclusion preferences as an intermediary mechanism between users and relying parties. These preferences act as pre-defined access control rules that automatically mediate data sharing decisions. When a user sets self-exclusion preferences for specific relying parties or types of relying parties, the system automatically enforces these restrictions without requiring real-time negotiation, thus maintaining efficient data sharing while enhancing security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If self-exclusion preferences are enforced through centralized control by identity providers, then data access control is improved, but system complexity and coordination overhead worsen

Engineering Contradiction:
Improveaccess control enforcementVSAvoidsystem coordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-exclusion preferences as preliminary access control rules that are established in advance by users. Instead of requiring complex real-time coordination between multiple identity providers to enforce access control, users pre-define their exclusion preferences for specific relying parties or categories of relying parties. These pre-configured rules are then automatically applied when data access requests occur, eliminating the need for complex runtime coordination and significantly reducing system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables users to self-manage their own data access control through self-exclusion preferences. Users independently configure which relying parties should be excluded from accessing their identity attributes, without requiring intervention or coordination from identity providers. This self-service approach shifts control to the users themselves and eliminates the coordination overhead that would otherwise be required for centralized access control enforcement across multiple providers.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If identity attributes are shared with multiple relying parties, then data utility and service accessibility are improved, but risk of information exposure and privacy violations worsen

Engineering Contradiction:
Improveservice accessibilityVSAvoidinformation exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by allowing different access control rules for different identity attributes and different relying parties. Instead of applying a uniform access control policy to all data sharing scenarios, the system enables users to specify granular self-exclusion preferences for specific attributes (e.g., exclude phone number but allow name sharing) and for specific types of relying parties (e.g., exclude gambling entities but allow healthcare providers). This localized control approach maximizes data utility by allowing selective sharing while minimizing exposure risk through attribute-specific and party-specific restrictions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12278903B2Systems and methods for use in implementing self-exclusion preferences
Publication Date: 2025.04.15 MASTERCARD INT INC
  • US12278903B2 patent drawing
  • US12278903B2 patent drawing
  • US12278903B2 patent drawing

AI summary

Systems and methods are provided for imposing self-exclusion preferences for data access. One example computer-implemented method includes, in response to a request by a user to impose a self-exclusion preference on a digital identity of the user, requesting a token for the digital identity. The method also includes receiving and storing the token and a secret associated with the token in a record associated with the user and assigning the self-exclusion preference to the token. The method then includes receiving a request to share an identity attribute of the user's digital identity with a relying party, where the request includes the token, and retrieving the self-exclusion preference assigned to the token. And, in response to validation of the request to share the identity attribute, based on the self-exclusion preference, authorizing a mobile device of the user to share the at least one identity attribute with the relying party.