Throttled Personal Information Sharing via Trusted Entity Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers face risks of personal information compromise when providing data to merchants, as current identity verification mechanisms reveal more information than necessary for transactions.
Innovation Solution
A system and method for throttled sharing of personal information, where a trusted entity receives customer personal information and, based on requirements from a third party system, creates a payload with only the necessary information for a transaction, ensuring real-time customer consent and minimizing data exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current identity verification mechanisms are used, then customer identity can be verified, but more personal information is revealed than necessary for the transaction
Solution Approach 1:
The system segments personal information into distinct fields and allows selective disclosure based on transaction requirements. The trusted entity divides the customer's personal information profile into individual fields (name, address, phone, DOB, etc.) and only transmits the specific fields needed for the transaction to the third party, rather than providing complete information.
Solution Approach 2:
The invention extracts only the necessary personal information fields from the customer's complete profile and separates them from the rest of the data. The trusted entity extracts specific fields based on the third party's requirements and creates a minimal payload containing only those extracted fields, removing unnecessary information from the transmission.
2Reliability
If a trusted entity controls personal information sharing, then data security is improved, but system complexity increases
Solution Approach 1:
The trusted entity acts as an intermediary between the customer and the third party system. It receives personal information from the customer, processes requests from third parties, determines what information can be shared, and transmits only necessary data. This intermediary role centralizes security control while managing complexity through a single coordinated system.
Solution Approach 2:
The system performs preliminary actions by pre-establishing customer profiles with their personal information at the trusted entity before transactions occur. The trusted entity pre-processes and stores information in an organized manner, so that during actual transactions, it can quickly retrieve and transmit only the necessary fields without requiring complex real-time processing.
3Reliability
If real-time customer consent is required, then privacy control is improved, but transaction speed decreases
Solution Approach 1:
The system performs preliminary consent management by establishing customer profiles and information sharing preferences in advance. The trusted entity pre-determines which information fields are necessary for different transaction types and prepares them in advance, so that during actual transactions, consent can be obtained quickly and information can be transmitted without significant delays.
Data Source
AI summary
Systems and methods for throttled sharing of personal information are disclosed. A method for throttled sharing of personal information may include: (1) receiving, by a computer program at a trusted entity and from a customer, customer personal information; (2) receiving, by the computer program at the trusted entity and from a third party system, an identification of personal information fields required for a transaction; (3) receiving, by the computer program at the trusted entity and from the third party system, a request for personal information verification for a transaction involving the customer; (4) retrieving, by the computer program, the personal information fields required by the third party system; (5) creating, by the computer program, a payload comprising the customer personal information for the personal information fields required by the third party system; and (6) returning, by the computer program, the payload to the third party system.


