Verifiable Credential Contracts for Cross-Network Data Portability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data portability systems across multiple disparate networks lack security, user control, and automated verification of data usage, failing to comply with regulations like GDPR and PSD2, and are prone to unauthorized data access and misuse.
Innovation Solution
A system employing JSON-LD link contracts and PKI public/private key pairs for secure, automated data transfers, enabling users to set access controls and permissions, and ensuring compliance with GDPR and PSD2 through cryptographically signed agreements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is transferred across multiple disparate networks without centralized control, then data portability and user autonomy are improved, but security and compliance verification deteriorate
Solution Approach 1:
The patent introduces a distributed network of Notary Servers as intermediaries between data subjects and data controllers. These notaries verify digital signatures and credentials without centralizing control, enabling secure verification across disparate networks while maintaining data portability and user autonomy.
Solution Approach 2:
The system implements feedback mechanisms where notary servers provide verification results and compliance status back to the data transfer process. This enables real-time validation of digital signatures and credentials, ensuring security and compliance while maintaining decentralized data portability.
2Ease of operation
If traditional authentication methods are used, then ease of operation is improved, but compliance with GDPR and PSD2 deteriorates
Solution Approach 1:
The patent implements preliminary action by requiring data subjects to obtain verifiable credentials and digital signatures before data transfer occurs. This advance preparation ensures GDPR and PSD2 compliance is built into the authentication process itself, maintaining ease of operation while guaranteeing regulatory adherence.
Solution Approach 2:
The system replaces traditional mechanical authentication methods with cryptographic digital signatures and verifiable credentials. This substitution maintains user-friendly operation while ensuring compliance with GDPR and PSD2 through mathematically secure verification mechanisms.
3Measurement precision
If manual verification of data usage permissions is performed, then measurement precision is improved, but productivity deteriorates
Solution Approach 1:
The patent implements self-service through automated verification of digital signatures and verifiable credentials by notary servers. The system automatically validates data usage permissions without manual intervention, achieving both high measurement precision in permission verification and high productivity in data transfer efficiency.
Solution Approach 2:
Manual verification processes are replaced with automated cryptographic verification mechanisms. Digital signatures and verifiable credentials enable machine-to-machine validation of data usage permissions, achieving both precise permission verification and high data transfer productivity through automation.
4Reliability
If centralized data control is implemented, then security is improved, but adaptability across disparate networks deteriorates
Solution Approach 1:
The patent segments the verification function from data control, distributing notary servers across multiple networks while maintaining security through cryptographic verification. This segmentation enables both high security through distributed verification and high adaptability across disparate networks through standardized digital signature validation.
Solution Approach 2:
The system implements universality through standardized digital signature and verifiable credential mechanisms that work across disparate networks. The notary servers provide multi-functional verification services that maintain security while enabling broad network interoperability and data portability.
Data Source
AI summary
A method for seamlessly and automatically granting tailored permission for use and transference of internet data between databases with comprehensive consent is described. The method employs a graph language such as JSON-LD to integrate and employ cryptographically signed Information Sharing Agreements (ISAs) between parties. Data is serialized to be easily transferred between databases when appropriate permission is obtained. Granular data exchange under usage control contacts can be automated among any number of parties on the internet. As such, the method provides a means by which users may control not only what may be done with their data, but to what entity or entities the data may be transferred. Advertisements may then be served to the user according to his or her preferences as defined within a web or desktop app, which is then applied to all related ad publishers publishing to the domains visited by the user.


