Transaction Record Repository With User-Defined Processor Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies, such as HTTP cookies, pose security risks to user devices and lack user control over their transaction information, as they are stored on user devices and inaccessible to other transaction processors without user consent.
Innovation Solution
A transaction record repository system that stores user transaction information in an immutable data structure, allowing users to define access rules for different transaction processors, enabling secure and controlled sharing of transaction data across multiple platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If HTTP cookies are stored on user devices to support stateful transaction sessions, then transaction data can be accessed by transaction processors, but security risks to user devices and confidential information increase
Solution Approach 1:
The patent extracts transaction data from user devices and stores it in a distributed ledger system instead. Users have their transaction information stored externally in an immutable ledger, and processors can access this data without it being present on the user's device, thereby reducing security risks while maintaining accessibility.
Solution Approach 2:
The distributed ledger acts as an intermediary between users and transaction processors. Instead of processors directly accessing data on user devices or users manually sharing information, the ledger mediates by providing a secure, standardized interface for data access that both parties can trust without compromising security.
2Ease of operation
If HTTP cookies are stored on user devices, then transaction data is accessible to creating processors, but user control over transaction data access is lost
Solution Approach 1:
The patent implements dynamic access control where users can adjust their privacy settings and control which processors can access their transaction data. The system allows users to change their preferences over time, enabling or disabling access to specific processors based on current needs, rather than having fixed access permissions.
Solution Approach 2:
Instead of processors controlling access to transaction data as with traditional cookies, the system inverts control by giving users the authority to grant or revoke access permissions. Users actively manage which processors can view their data, flipping the traditional access control model.
3Adaptability or versatility
If transaction data is shared across multiple processors, then broader access to transaction information is achieved, but privacy protection becomes more difficult
Solution Approach 1:
The patent applies different access permissions to different processors based on user preferences. Instead of a blanket approach where all processors have equal access or no access, the system allows users to grant specific processors specific levels of access to their transaction data, enabling broader overall access while maintaining granular privacy protection for each processor-user relationship.
Data Source
AI summary
A method of storing and managing access to information about electronic transactions completed by users collected from a plurality of transaction processors. The method comprises storing information associated with transactions by an application; receiving a first user information management request by the application from a user; sending a user management report by the application to the user; receiving a second user information management request message by the transaction record repository application from the user; and responsive to receiving the second user information management request message, restricting access by the application to one or more of the types of information on electronic transactions associated with the user that can be accessed by one or more of the transaction processors.


