Temporary Identifier Data Access for Secure Third-Party Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing data access in online transactions face significant security risks due to the need to share personal data with potentially untrustworthy third parties and the regulatory burden of securely storing and deleting data, particularly when multiple transactions are involved.
Innovation Solution
A method utilizing temporary identifiers and share keys enables secure and reliable data access, where data is stored at a data host, allowing clients to access data without storing it locally, with features like unique identifiers and contract flags ensuring data security and owner control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If personal data is transmitted to multiple third parties over a network, then online transactions can be conducted, but security risks increase due to potential data breaches and unauthorized access
Solution Approach 1:
The patent introduces a data host as an intermediary between data owners and data clients. The data host stores data securely and provides controlled access without requiring direct transmission between parties. This mediator architecture enables data sharing while maintaining security, as the data host manages authentication and authorization, preventing unauthorized access and data breaches that would occur in direct peer-to-peer transmission.
Solution Approach 2:
The patent extracts the data storage and management function from the data client and places it at the data host. By separating data storage from data processing, the system allows clients to access data without storing it locally, reducing security risks. The data host holds the data in a secure environment while clients receive only the necessary information for transactions, minimizing exposure to security threats.
2Reliability
If data is stored securely with a trusted entity, then data security is improved, but data clients cannot access data without complex authentication and transmission processes
Solution Approach 1:
The patent implements self-service mechanisms where the data host automatically handles authentication, authorization, and data retrieval processes. Once a client is authorized by the data owner, the data host manages the entire access process without requiring complex manual authentication steps. The system automatically verifies credentials, manages session tokens, and retrieves data, simplifying the user experience while maintaining security through automated controls.
Solution Approach 2:
The patent performs preliminary authentication and authorization actions before data access. The data owner pre-authorizes clients in advance, and the data host pre- establishes secure access channels and credentials. This preliminary setup eliminates the need for complex real-time authentication during data access, as the security framework is already in place and ready to facilitate straightforward data retrieval when needed.
3Productivity
If data is transmitted to multiple third parties, then transaction capability is enhanced, but regulatory burden increases due to requirements for secure storage and data deletion
Solution Approach 1:
The patent merges multiple data storage and management functions into a single data host platform. Instead of each third-party client maintaining separate secure storage systems and deletion protocols, all data is centralized at the data host with unified security management. This consolidation enables multiple transactions to occur through one secure platform, reducing the overall regulatory burden by eliminating redundant security infrastructure across multiple organizations while maintaining transaction efficiency.
Solution Approach 2:
The data host is designed as a universal platform that can serve multiple data owners and data clients simultaneously. It provides multi-functional capabilities including secure storage, authentication, authorization, data retrieval, and compliant deletion for various types of data and transactions. This universal architecture allows the system to handle diverse transaction requirements through a single standardized interface, reducing complexity compared to implementing separate data management systems for each transaction partner.
4Speed
If data clients store data locally for quick access, then access speed is improved, but security risks and storage requirements increase
Solution Approach 1:
The data host acts as an intermediary that provides fast data access without requiring local storage at client sites. It maintains optimized data structures and indexing systems that enable rapid retrieval, then delivers data over the network when clients need it. This mediator approach eliminates the security risks of local storage while maintaining access speed through the host's optimized infrastructure and efficient data delivery mechanisms.
Solution Approach 2:
The patent replaces the mechanical approach of local data storage with a network-based retrieval system. Instead of physically storing data copies at client locations, the system uses electronic data access through the network with the data host. This substitution maintains fast access through optimized data retrieval protocols while eliminating the security vulnerabilities associated with distributed local storage, as all data remains centralized in a controlled environment.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods of enabling data access for a transaction between a data client and at least one data owner are described, wherein the data is stored at a data host. A method implemented at the data host includes storing data associated with the data owner in a data owner profile, the profile including a static identifier associated with the data owner and receiving from the data owner a request for a temporary identifier to enable access to the data by a data client. The temporary identifier is generated and transmitted to the data owner as well as being stored in the data owner profile. An access request for at least a portion of the stored data is received from the data client, the access request comprising the temporary identifier, an identifier of the data client, an indication of the scope of the request, and a duration associated with the request. It is first verified that access to the data can be enabled for the data client based on the information in the access request and a share key is transmitted to the data client for the requested data.