Tokenized Data Access via SMS and Email

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for obtaining data with personally identifiable information (PII) often require a credentialed login process, exposing security risks and necessitating indirect access through third parties, which introduces time delays and further security vulnerabilities.

Innovation Solution

The system enables requesting, accessing, and delivering data without exposing PII and without a credentialed login process, using email and/or cellular text messaging to send requests and receive links to data, while maintaining PII encryption and eliminating direct exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a credentialed login process is used to access data, then data access is authorized and controlled, but security risks increase due to potential credential discovery and system susceptibility to hackers

Engineering Contradiction:
Improvedata access controlVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts PII from the data access process by using tokenization - replacing sensitive personally identifiable information with non-sensitive tokens. Users authenticate without exposing PII, and data is accessed using these tokens instead of direct PII exposure, thereby maintaining access control while reducing security risks associated with credential management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces an intermediary tokenization layer between the user and the data. Instead of direct authentication with PII exposure, the system uses tokenized identifiers as intermediaries that preserve access control functionality while eliminating the security vulnerabilities of traditional credential-based systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If data is accessed indirectly through a third party, then PII exposure is reduced, but time delay increases while waiting for data retrieval

Engineering Contradiction:
ImprovePII exposureVSAvoiddata retrieval time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system performs preliminary tokenization of PII data during data ingestion or storage, creating tokenized versions beforehand. When data access is requested, the pre-tokenized data can be immediately retrieved and delivered without requiring real-time third-party mediation, thus reducing time delay while maintaining PII protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The tokenization system enables self-service data access where users can retrieve their own tokenized data directly without requiring third-party intervention. The automated token management and data delivery system eliminates the need for manual third-party data retrieval processes, reducing time delays while maintaining security.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If indirect data access through third parties is used, then PII exposure is minimized, but security risks increase due to expanded chain of custody

Engineering Contradiction:
ImprovePII exposureVSAvoiddata security
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent extracts PII from the data chain by replacing it with tokens throughout the entire data lifecycle. This eliminates PII exposure at every stage of the chain of custody while maintaining data integrity and access control, thereby reducing both PII exposure and the security risks associated with expanded data handling chains.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12206636B2Systems and methods for requesting, accessing, and delivering data without exposing personally identifiable information and without a credentialed login process
Publication Date: 2025.01.21 EVERETT DON
  • US12206636B2 patent drawing
  • US12206636B2 patent drawing
  • US12206636B2 patent drawing

AI summary

Systems and methods for requesting, accessing and delivering data in a way that does not require users, or others acting on behalf of users, to log in to a dedicated computer application and does not rely on humans to manually retrieve the data. A Requester (“REQ”) sends an email or cellular text message to a server to request data. The server identifies the REQ based on the REQ's email address or mobile phone number and then deciphers what data to compile after interpreting the REQ's message. The server then returns a link to the REQ's email address or mobile phone number. The REQ can select the link to view the data. The email or text message is sent by the REQ, the link is returned by the server to the REQ's email address or mobile phone number, and the data is displayed, all without revealing any personally identifiable information (“PII”).