Tokenized PII Access With Scoped Authorization Parameters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for providing personally identifiable information (PII) to service providers are tedious, redundant, and vulnerable to unauthorized access, lacking centralized data sources and leading to discrepancies and inefficiencies.

Innovation Solution

A data security system that enables tokenized access to PII through a token provisioning computing device, allowing individuals to authorize and generate access tokens for service providers, defining data elements and authorization parameters, and securely transmitting these tokens for access to stored PII.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individuals provide sensitive PII data directly to service providers, then data access is straightforward, but security vulnerability and unauthorized access risk increase

Engineering Contradiction:
Improvedata securityVSAvoiddata provision process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a token as an intermediary that mediates between the individual's PII data and service providers. Instead of direct data provision, the token acts as a secure proxy that grants controlled access to specific data elements, thereby enhancing security while maintaining operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy or representation of access rights through the token, which mirrors the individual's authorization to share specific PII data. This token copy enables service providers to access necessary data without directly handling the sensitive PII itself, reducing security risks.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If individuals provide PII data to multiple service providers, then service coverage increases, but redundancy and user effort increase

Engineering Contradiction:
Improveservice provider accessVSAvoidrepeated data provision
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent creates a universal token that can be used across multiple service providers and data elements. This single token provides multi-functional access, allowing individuals to share their PII data with multiple service providers without repeatedly providing the same information, thereby saving time and effort.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables individuals to pre-configure their data sharing preferences and generate tokens in advance. This preliminary action establishes authorization parameters beforehand, so when service providers need access, the token is already prepared and configured, eliminating the need for repeated data provision setup.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If centralized PII storage is implemented, then data accuracy improves, but access control complexity increases

Engineering Contradiction:
Improvedata accuracyVSAvoidaccess control system
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments the access control into two distinct components: the centralized PII storage system and the token-based access control mechanism. This segmentation allows the storage system to maintain high data accuracy while the token system independently manages access control complexity, preventing the two functions from complicating each other.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250278515A1Systems and methods for tokenization of personally identifiable information (PII)
Publication Date: 2025.09.04 MASTERCARD INT INC
  • US20250278515A1 patent drawing
  • US20250278515A1 patent drawing
  • US20250278515A1 patent drawing

AI summary

Described herein is a data security system for enabling tokenized access to sensitive data, including a token provider configured to connect to a remote client computing device over a secure communication channel, and cause display, at the remote client computing device, of a token request user interface including a selection form listing sensitive data elements associated with a first data subject. The token provider is also configured to receive a request for an access token, including a user selection of a subset of the sensitive data elements and one or more access authorization parameters, and generate an access token that enables access to only the subset of the sensitive data elements according to the authorization parameters. The token provider also stores the access token in a token database with the one or more authorization parameters, and transmits, to the remote client computing device, a response including the access token.