IP Library › Granted Patent US 12,212,685
Granted Patent B2
US 12,212,685 · App. 17/539,804 · Granted Jan 28, 2025

Consent management

Inventors: Wayne Lloyd (London, GB); James Radley (London, GB); Neelam Patel (London, GB); Ben Sheedy (London, GB)
Assignee: Smarter Contracts Ltd.
H04L9/3247G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,685
App. No.
17/539,804
Granted
Jan 28, 2025
Kind
B2
Abstract

There is provided a computer-implemented method for a first party to control permission for access to first party information to a second party while preserving privacy, the method comprising the following steps taken by the first party at first party computing apparatus: establishing with the second party a set of information classes for first party information to be provided to the second party and establishing permitted use for the first party information in the set of information classes; providing a first party consent to the permitted use for the first party information in the set of information classes, encrypting the first party consent for inspection limited to the first party and the second party, and providing the first party consent to the second party in a first party digitally signed consent grant structure for the second party to decrypt, validate and sign the first party consent and for a consent validating party to store the first and second party digitally signed consent grant structure on a blockchain. There is also provided a computer-implemented method for a second party to obtain permission from a first party for access to first party information while preserving privacy. There is also provided a computer-implemented method for a consent validating party to manage permissions given by a first party for access to first party information to a second party while preserving privacy.

Claims (25)

1. A computer-implemented method for a grantor to control permission for access to grantor information to a grantee while preserving privacy and enabling grantor control of grantor information to be processed, the method comprising the following steps taken by the grantor at a computing apparatus of the grantor:

establishing with the grantee a set of information classes for grantor information to be provided to the grantee and establishing permitted use for the grantor information in the set of information classes;

providing a grantor consent to the permitted use for the grantor information in the set of information classes;

encrypting the grantor consent for inspection limited to the grantor and the grantee; and

providing the encrypted grantor consent to the grantee in a grantor digitally signed consent grant structure for the grantee to decrypt, validate and sign the grantor consent and for a consent validating party to store the grantor and grantee digitally signed consent grant structure on a blockchain, wherein the consent grant structure comprises the consent to the permitted use for the grantor information in the set of information classes.

2. The method of claim 1 , wherein the set of information classes and the permitted use are established in an application on the grantor computing device relating to provision of goods or services by the grantee.

3. The method of claim 2 , wherein the application on the grantor computing device relates to provision of goods or services by multiple grantees, and the determination of the set of information classes and the permitted use relates to use by multiple grantees.

4. The method as claimed in claim 1 , further comprising the grantor providing a revoke grant structure revoking the consent grant structure, wherein the revoke grant structure identifies the consent grant structure and is encrypted by the revoking party for inspection limited to the grantor and the grantee and is digitally signed by the revoking party.

5. The method as claimed in claim 1 , wherein encrypting data for inspection limited to the grantor and grantee comprises establishing a symmetric key for use by the grantor and the grantee using elliptic curve Diffie-Hellman key exchange.

6. The method as claimed in claim 1 , wherein the grantor uses a plurality of private keys for encrypting and digital signing.

7. The method of claim 6 , wherein each of the plurality of private keys is generated by an iterative process from an original master private key.

8. The method of claim 7 , wherein a private key is generated from a preceding private key by splitting the preceding private key into a first part and a second part, and by performing a first process to generate the first part of the private key and a second process to generate the second part of the private key.

9. The method of claim 8 , wherein one of the first process and the second process is an XOR of the first part and the second part of the preceding master private key followed by a hash of the XOR, and wherein the other of the first process and the second process is a hash of the first part or the second part of the preceding master private key.

10. The method of claim 5 , further comprising regenerating private keys after the consent event, determining corresponding public keys from the private keys, and using the determined public keys to identify consent events.

11. The method of claim 1 , wherein the consent grant structure further comprises a time of the provision of grantor consent.

12. The method of claim 1 , wherein the consent grant structure further comprises a period of time of validity of the grantor consent.

13. A computer-implemented method for a grantee to obtain permission from a grantor for access to grantor information while preserving privacy and enabling grantor control of grantor information to be processed, the method comprising the grantee at a computing apparatus of the grantee:

establishing with the grantor a set of information classes for grantor information to be provided to the grantee and establishing with the grantor permitted use for the grantor information in the set of information classes;

receiving from the grantor a grantor consent to the permitted use for the grantor information in the set of information classes, wherein the grantor consent is encrypted by the grantor for inspection limited to the grantor and the grantee, the encrypted grantor consent being provided in a grantor digitally signed consent grant structure;

decrypting and validating the encrypted grantor consent, and providing the grantor consent to a consent validating party in a grantor and grantee digitally signed consent grant structure, wherein the consent validating party is able to determine that the grantor and grantee digitally signed consent structure is valid, and is further able to store the grantor and grantee digitally signed consent grant structure on a blockchain, wherein the consent grant structure comprises the consent to the permitted use for the grantor information in the set of information classes.

14. The method as claimed in claim 13 , further comprising the grantee providing a revoke grant structure revoking the consent grant structure, wherein the revoke grant structure identifies the consent grant structure and is encrypted by the revoking party for inspection limited to the grantor and the grantee and is digitally signed by the revoking party.

15. The method as claimed in claim 13 , wherein encrypting data for inspection limited to the grantor and the grantee comprises establishing a symmetric key for use by the grantor and the grantee using elliptic curve Diffie-Hellman key exchange.

16. The method as claimed in claim 13 , wherein the grantee uses a plurality of private keys for encrypting and digital signing, the method further comprising regenerating private keys after the consent event, determining corresponding public keys from the private keys, and using the determined public keys to identify consent events.

17. The method of claim 13 , wherein the consent grant structure further comprises a time of the provision of grantor consent.

18. The method of claim 13 , wherein the consent grant structure further comprises a period of time of validity of the grantor consent.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2024
From: LLOYD, WAYNE; RADLEY, JAMES; PATEL, NEELAM; SHEEDY, BEN
To: SMARTER CONTRACTS LTD.
Reel/Frame 068755/0674 →
Priority Claims (1)
GB 2018919 · Dec 1, 2020 · national
Continuity (1)
Related Publication 20220173913A1 · Jun 2, 2022
References Cited (13)
US 11063760B2 · Subba · 2021 [cited by examiner]
US 11138598B2 · Yadav · 2021 [cited by examiner]
US 11210426B2 · Yan · 2021 [cited by examiner]
US 11238170B2 · Murdoch · 2022 [cited by examiner]
US 11449585B2 · Lindeman · 2022 [cited by examiner]
US 11483143B2 · Tola · 2022 [cited by examiner]
US 20190199531A1 · Staples · 2019 [cited by examiner]
US 20190220859A1 · Weight · 2019 [cited by examiner]
WO 2020071978A1 · 2020 [cited by applicant]
European Search Report in reference to co-pending European Application No. 21211827.7 filed Dec. 1, 2020. [cited by applicant]
Grishin, et al., “Data privacy in the age of personal genomics”, Nature Biotechnology, Nature Publishing Group, vol. 37, No. 10, pp. 1115-1117, XP36897241, Sep. 19, 2019. [cited by applicant]
Rantos, et al., “ADvoCATE: A Consent Management Platform for Personal Data Processing in the IoT Using Blockchain Technology”, SecITC, pp. 300-313, 2019. [cited by applicant]
Faber, et al., “BPDIMS: A Blockchain-based Personal Data and Identity Management System”, Proceedings of the 52nd Hawaii International Conference on System Sciences, pp. 6855-6864, 2019. [cited by applicant]