IP Library Granted Patent US 7,401,352
Granted Patent B2
US 7,401,352 · App. 10/233,339 · Granted Jul 15, 2008

Secure system and method for enforcement of privacy policy and protection of confidentiality

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,401,352
App. No.
10/233,339
Granted
Jul 15, 2008
Kind
B2
Abstract

The invention includes various systems, architectures, frameworks and methodologies that can securely enforce a privacy policy. A method is include for securely guaranteeing a privacy policy between two enterprises, comprising: creating a message at a first enterprise, wherein the message includes a request for data concerning a third party and a privacy policy of the first enterprise; signing and certifying the message that the first enterprise has a tamper-proof system with a privacy rules engine and that the privacy policy of the first entity will be enforced by the privacy rules engine of the first enterprise; sending the message to a second enterprise; and running a privacy rules engine at the second enterprise to compare the privacy policy of the first enterprise with a set of privacy rules for the third party.

Claims (23)

1. A method for securely guaranteeing a privacy policy between two enterprises, comprising:

creating a message at a first enterprise, wherein the message includes a request for data concerning a specifically identified third party for data stored by a second enterprise and a privacy policy of the first enterprise;

signing and certifying the message that the first enterprise has a tamper-proof system with a privacy rules engine and that the privacy policy of the first enterprise will be enforced by the privacy rules engine of the first enterprise;

sending the message to the second enterprise; and

running a privacy rules engine at the second enterprise to compare the privacy policy of the first enterprise with a set of privacy rules for the third party, wherein in response to a match between the privacy policy of the first enterprise and the set of privacy rules for the third party: encrypting the data requested by the first enterprise; and sending the encrypted requested data from the second enterprise to the first enterprise.

2. The method of claim 1 , wherein:

the certifying step includes the preliminary act of registering the first enterprise with a trusted agency; and

the second enterprise checks the trusted agency to verify the certification.

3. The method of claim 1 , wherein both the first and second enterprises include a secure co-processor.

4. The method of claim 1 , wherein both the first and second enterprises each includes a hardware device built with a cryptographic identifier that allows the hardware device of the first enterprise and the hardware device of the second enterprise to recognize and certify each other.

5. The method of claim 1 , wherein the first enterprise comprises a merchant system, the second enterprise comprises a financial institution system, and the data comprises credit card information regarding an individual.

6. The method of claim 1 , wherein the first enterprise comprises a service provider, the second enterprise comprises a vehicle, and the data comprises information derived from the vehicle.

7. The method of claim 6 wherein the information comprises identification information and one of location and diagnostic information.

8. A method for securely guaranteeing a privacy policy between two enterprises, comprising:

creating a message at a first enterprise, wherein the message includes a request for data concerning a specifically identified third party for data stored by a second enterprise and a privacy policy of the first enterprise;

signing and certifying the message that the first enterprise has a tamper-proof system with a privacy rules engine and that the privacy policy of the first enterprise will be enforced by the privacy rules engine of the first enterprise, wherein: the certifying step includes the preliminary act of registering the first enterprise with a trusted agency; and the second enterprise checks the trusted agency to verify the certification;

sending the message to the second enterprise; and

running a privacy rules engine at the second enterprise to compare the privacy policy of the first enterprise with a set of privacy rules for the third party.

9. A method for securely guaranteeing a privacy policy between two enterprises, comprising:

creating a message at a first enterprise, wherein the message includes a request for data concerning a specifically identified third party for data stored by a second enterprise and a privacy policy of the first enterprise;

signing and certifying the message that the first enterprise has a tamper-proof system with a privacy rules engine and that the privacy policy of the first enterprise will be enforced by the privacy rules engine of the first enterprise;

sending the message to the second enterprise; and

running a privacy rules engine at the second enterprise to compare the privacy policy of the first enterprise with a set of privacy rules for the third party. wherein both the first and second enterprises each includes a hardware device built with a cryptographic identifier that allows the hardware device of the first enterprise and the hardware device of the second enterprise to recognize and certify each other.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2020
From: DAEDALUS GROUP, LLC
To: SLINGSHOT IOT LLC
Reel/Frame 051733/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2020
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: DAEDALUS GROUP, LLC
Reel/Frame 051710/0445 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: DAEDALUS GROUP LLC
Reel/Frame 051032/0784 →