Automated Tiered Security for Confidential Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic sharing of confidential information is cumbersome and insecure due to inadequate security measures and inappropriate security requirements, often requiring manual entry of each item and compromising the security of the information.

Innovation Solution

A computer-based system that automates tiered security and authentication by determining the security tier of each item of user-related data, generating authentication requests, and allowing access only after successful authentication, while auto-populating forms with secure data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual entry of confidential information is required for sharing, then data security can be maintained through user control, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improvedata securityVSAvoidinformation sharing process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments confidential information into different security tiers (first tier, second tier, third tier) with varying authentication requirements. This allows the system to apply appropriate security measures to each data item individually, maintaining security while enabling automated sharing for lower-tier data without manual entry.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication and authorization actions before data sharing occurs. User accounts are pre-configured with authentication credentials and security tier assignments, allowing automated form population to proceed without real-time manual intervention while maintaining security controls.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If inadequate security measures are used for information sharing, then the process becomes simpler and faster, but the security of confidential information is compromised

Engineering Contradiction:
Improveinformation sharing processVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements local quality by applying different security measures to different security tiers of data. First tier data uses basic authentication, second tier uses enhanced authentication, and third tier uses the most stringent authentication. This allows automated sharing for less sensitive data while maintaining strong security for highly sensitive information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts authentication requirements based on the security tier of the requested data. The authentication mechanism adapts its complexity and stringency according to the sensitivity of the information being accessed, enabling simplified processes for low-risk operations while maintaining robust security for high-risk operations.

Inventive Principle:
Principle #15Dynamics

3Productivity

If automated form population with secure data is implemented, then productivity increases and manual entry is reduced, but the complexity of security management increases

Engineering Contradiction:
Improveform processing efficiencyVSAvoidsecurity management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication system that handles multiple security tiers and various authentication methods (passwords, biometrics, tokens) through a single integrated framework. This multi-functional system manages automated form population across different data types and security levels, reducing overall system complexity despite the variety of security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary authentication service that mediates between the automated form production application and the secure data sources. This intermediary layer handles the complex security management, authentication verification, and data retrieval operations, allowing the form production system to operate simply while maintaining robust security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple authentication methods are required for different security tiers, then data protection is enhanced, but the authentication process becomes more complex

Engineering Contradiction:
Improvedata protectionVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct modules for different authentication methods (password authentication, biometric authentication, token-based authentication). Each authentication method is implemented as a separate, standardized module that can be independently configured and managed, reducing the overall complexity of handling multiple authentication types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes authentication parameters dynamically based on the security tier of the requested data. Instead of implementing a completely different authentication system for each tier, the system adjusts authentication parameters (such as required authentication strength, multi-factor requirements, session duration) according to the security tier, simplifying the authentication architecture while maintaining differentiated security levels.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12423466B2Automated tiered security for confidential information and confidential information sharing and methods thereof
Publication Date: 2025.09.23 CAPITAL ONE SERVICES LLC
  • US12423466B2 patent drawing
  • US12423466B2 patent drawing
  • US12423466B2 patent drawing

AI summary

Systems and methods of the present disclosure enable automated sharing of confidential information according to tiers of security by receiving an electronic information request from an automated form production application of a computing device associated with a third-party entity. A request security tier associated with the electronic information request is determined according to a security tier of the user-related secure data. At least one authentication requirement associated with the request is determined according to authentication settings of the security tier. An authentication request is generated enabling the user to provide an authentication response to approve the computing device for access to the user-related secure data. The user authentication response is received, the user is authenticated based on the user authentication response and the computing device is allowed to access the user-related secure data to auto-populate each field of an electronic form with associated items of the user-related secure data.