Tokenized Data Access via SMS and Email
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for obtaining data with personally identifiable information (PII) often require a credentialed login process, exposing security risks and necessitating indirect access through third parties, which introduces time delays and further security vulnerabilities.
Innovation Solution
The system enables requesting, accessing, and delivering data without exposing PII and without a credentialed login process, using email and/or cellular text messaging to send requests and receive links to data, while maintaining PII encryption and eliminating direct exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a credentialed login process is used to access data, then data access is authorized and controlled, but security risks increase due to potential credential discovery and system susceptibility to hackers
Solution Approach 1:
The patent extracts PII from the data access process by using tokenization - replacing sensitive personally identifiable information with non-sensitive tokens. Users authenticate without exposing PII, and data is accessed using these tokens instead of direct PII exposure, thereby maintaining access control while reducing security risks associated with credential management.
Solution Approach 2:
The system introduces an intermediary tokenization layer between the user and the data. Instead of direct authentication with PII exposure, the system uses tokenized identifiers as intermediaries that preserve access control functionality while eliminating the security vulnerabilities of traditional credential-based systems.
2Object-affected harmful factors
If data is accessed indirectly through a third party, then PII exposure is reduced, but time delay increases while waiting for data retrieval
Solution Approach 1:
The system performs preliminary tokenization of PII data during data ingestion or storage, creating tokenized versions beforehand. When data access is requested, the pre-tokenized data can be immediately retrieved and delivered without requiring real-time third-party mediation, thus reducing time delay while maintaining PII protection.
Solution Approach 2:
The tokenization system enables self-service data access where users can retrieve their own tokenized data directly without requiring third-party intervention. The automated token management and data delivery system eliminates the need for manual third-party data retrieval processes, reducing time delays while maintaining security.
3Object-affected harmful factors
If indirect data access through third parties is used, then PII exposure is minimized, but security risks increase due to expanded chain of custody
Solution Approach 1:
The patent extracts PII from the data chain by replacing it with tokens throughout the entire data lifecycle. This eliminates PII exposure at every stage of the chain of custody while maintaining data integrity and access control, thereby reducing both PII exposure and the security risks associated with expanded data handling chains.
Data Source
AI summary
Systems and methods for requesting, accessing and delivering data in a way that does not require users, or others acting on behalf of users, to log in to a dedicated computer application and does not rely on humans to manually retrieve the data. A Requester (“REQ”) sends an email or cellular text message to a server to request data. The server identifies the REQ based on the REQ's email address or mobile phone number and then deciphers what data to compile after interpreting the REQ's message. The server then returns a link to the REQ's email address or mobile phone number. The REQ can select the link to view the data. The email or text message is sent by the REQ, the link is returned by the server to the REQ's email address or mobile phone number, and the data is displayed, all without revealing any personally identifiable information (“PII”).


