Patent Issued for End-to-end privacy ecosystem (USPTO 11599652): Allstate Insurance Company
2023 MAR 28 (NewsRx) -- By a
The assignee for this patent, patent number 11599652, is
Reporters obtained the following quote from the background information supplied by the inventors: “Digital user privacy, consumer data collection and data monetization are becoming ever-more prevalent issues in modern society. Computing devices, software, hardware, and websites continually gather data on users to build profiles, offer advertisements, and plan strategies. Many times, users are not even aware of what data is being gathered and how that data is being used, and software or websites may frequently offer services in exchange for data, such as a “free” search engine or social media site that exchanges services for gathering of user data.
“For a long time, users were willing to accept these services in exchange for the data, believing the data to be limited in scope, the use and business-to-business sharing of the data to be limited in scope, or being unaware of the true value of their personal data in the aggregate. The financial success of these services, predicated largely on data, has revealed some of the true value of user data. At the same time, data gathering and processing has grown much more sophisticated, allowing for the unlocking of significant value in large data sets about individual users and groups of users.
“Problematically, users have already often agreed to have this data gathered and enjoy using the free services. Moreover, users still frequently have no idea as to what data is or was gathered about them. Far more than a simple location or demographic, these data sets can range far and wide, and user behavior itself is often monitored and compiled into complex evaluations of what that user represents in terms of merchant or advertiser opportunity. At the same time, there are limited opportunities to determine what data has been gathered and how the data is being used, and most frequently the impact and scope is observed anecdotally, where a user continually sees advertisements, for example, that appear to be highly targeted. The scope of data is also hinted at when software provides recommendations and seems almost prescient in its understanding of what the user would like.
“While many users may not object to the targeted and precise nature of at least some of these incidents, and may even welcome them in some cases, such as a requested and subsequently on-point recommendation, many users may ultimately be somewhat disturbed at the scope and scale of their own personal information stored and used to assemble these offerings. But, since users can never see the backend data store, and since they typically lack granular control over data, and/or notification when and what data is specifically gathered, people tend to remain somewhat blissfully ignorant, even if they would be distressed if they saw the volume of personal information being gathered, understood the value of what they were exchanging, and understood the full scope of the conclusions that were being drawn about them. Because it may be rare that the user’s data is used exclusively to provide a requested and subsequently on-point recommendation, consumers may ultimately prefer a solution that provides better optics into usage, consumer-centric control and permissioning of such usage and value-sharing opportunities related to a consumer’s personal information.”
In addition to obtaining background information on this patent, NewsRx editors also obtained the inventors’ summary information for this patent: “In a first illustrative embodiment, a system includes one or more privacy vaults, wherein at least one of the one or more privacy vaults is associated with at least one individual user, stores contents associated with the associated at least one individual user, and stores specific identification of a plurality of third-party entities, authorized to access at least a portion of the contents stored by the one or more privacy vaults, along with access permissions, one or more of the access permissions defined for each of the plurality of third-party entities, at least one of the access permissions defining accessibility of the contents for at least one of the plurality of third-party entities for which the at least one access permission is defined.
“The system further includes one or more processors configured to provide gateway services for accessing contents stored by the one or more privacy vaults, including handling access requests, for contents from the one or more privacy vaults, wherein an access request, from the at least one third-party entity, is handled in accordance with at least one of the access permissions defined for the at least one third-party entity in each of a plurality of target privacy vaults from which the at least one third party entity requests information, to fulfil the access request for the information from a respective target privacy vault according to the policy defined for the at least one third-party entity by the respective target privacy vault.
“In a second illustrative embodiment, a system includes one or more privacy vaults, wherein at least one of the one or more privacy vaults is associated with at least one individual user, stores contents associated with the associated at least one individual user, and stores specific identification of a plurality of third-party entities, authorized to access at least a portion of the contents stored by the one or more privacy vaults, along with access permissions, one or more of the access permissions defined for each of the plurality of third-party entities, at least one of the access permissions defining accessibility of the contents for at least one of the plurality of third-party entities for which the at least one access permission is defined.
“The system also includes one or more processors configured to provide gateway services for accessing the contents stored by the one or more privacy vaults, including handling access requests, including at least access requests from at least one third-party entity of the plurality of third-party entities. The one or more processors are also additionally configured to provide audit services including obtaining content-retention information, identifying what contents, of outbound contents from at least one audit-target privacy vault and that were provided responsive to an access request from a requesting third-party entity, were retained remotely by the requesting third-party entity, and comparing the identified contents to the access permission of the at least one audit-target privacy vault defined for the requesting third-party entity to determine if the identified contents were permissibly retained in accordance with the access permission.
“In a third illustrative embodiment, a system includes one or more privacy vaults, wherein at least one of the one or more privacy vaults is associated with at least one individual user, stores contents associated with the associated at least one individual user, and stores specific identification of a plurality of third-party entities, authorized to access at least a portion of the contents stored by the one or more privacy vaults, along with access permissions, one or more of the access permissions defined for each of the plurality of third-party entities, at least one of the access permissions defining accessibility of the contents for at least one of the plurality of third-party entities for which the at least one access permission is defined.”
The claims supplied by the inventors are:
“1. A system comprising: one or more privacy vaults, wherein at least one of the one or more privacy vaults: is associated with at least one individual user; stores contents associated with the associated at least one individual user; and stores specific identification of a plurality of third-party entities, authorized to access at least a portion of the contents stored by the one or more privacy vaults, along with access permissions, one or more of the access permissions defined for each of the plurality of third-party entities, wherein at least one of the access permissions defines accessibility of the contents, for at least one of the plurality of third-party entities, including a content retention policy defining the right to retain at least a portion of the contents, subsequent to downloading the at least the portion of the contents and defining a condition after which the at least the portion of the contents downloaded and stored by the third party are to be deleted; and one or more processors configured to: provide gateway services for accessing contents stored by the one or more privacy vaults, including handling access requests, for contents from the one or more privacy vaults, wherein an access request, from the at least one third-party entity, is handled in accordance with at least one of the access permissions defined for the at least one third-party entity in each of a plurality of target privacy vaults from which the at least one third-party entity requests information, to fulfil the access request for the contents from a respective target privacy vault according to the access permission defined for the at least one third-party entity by the respective target privacy vault; obtain content-retention information, identifying what contents, of outbound contents from at least one privacy vault of the plurality of target privacy vaults, and that were provided responsive to the access request from the at least one third-party entity, were retained remotely by the at least one third-party entity; and compare the identified contents to the content retention policy of the at least one privacy vault and defined for the at least one third-party entity to determine if the identified contents were permissibly retained in accordance with the content retention policy.
“2. The system of claim 1, wherein the specific identification in the at least one privacy vault includes identification of each of the plurality of third-party entities.
“3. The system of claim 1, wherein the accessibility includes the right to use at least a portion of the contents for a predefined purpose or the right to download at least a portion of the contents, as indicated as part of the at least one access permission defined for the at least one third-party entity by the at least one privacy vault.
“4. The system of claim 1, wherein the condition includes a time duration.
“5. A system comprising: one or more privacy vaults, wherein at least one of the one or more privacy vaults: is associated with at least one individual user; stores contents associated with the associated at least one individual user; and stores specific identification of a plurality of third-party entities, authorized to access at least a portion of the contents stored by the one or more privacy vaults, along with access permissions, one or more of the access permissions defined for each of the plurality of third-party entities, at least one of the access permissions defining accessibility of the contents, for at least one of the plurality of third-party entities, including a content retention policy defining the right to retain at least a portion of the contents, subsequent to downloading the at least the portion of the contents and defining a condition after which the at least the portion of the contents downloaded and stored by the third party are to be deleted; and one or more processors configured to: provide gateway services for accessing the contents stored by the one or more privacy vaults, including handling access requests, including at least access requests from the at least one third-party entity; and provide audit services comprising: obtaining content-retention information; identifying what contents, of outbound contents from at least one audit-target privacy vault, of the one or more privacy vaults, and that were provided responsive to an access request from the at least one third-party entity, were retained remotely by the at least one third-party entity; and evaluating the identified contents based on the content retention policy of the at least one audit-target privacy vault and defined for the at least one third-party entity to determine if the identified contents were permissibly retained in accordance with the content retention policy.
“6. The system of claim 5, at least one of the one or more processors is further configured to provide content gathering services for the at least one individual user, including tracking digital actions of the at least one individual user, gathering contents generated by the digital actions, and storing the gathered contents in the at least one privacy vault associated with the at least one individual user for whom content gathering services were provided.
“7. The system of claim 5, wherein at least one of the one or more processors is further configured to provide value-handling services defined for the at least one privacy vault, enabling the exchange of value from one or more of the plurality of third-party entities for at least a portion of contents stored in the at least one privacy vault.
“8. The system of claim 5, wherein accessibility includes the right to download at least a portion of the contents identified by the at least one access permission defined for the at least one third-party entity.
“9. The system of claim 5, wherein the accessibility includes the right to use at least a portion of the contents for a predefined purpose that is included as part of the at least one access permission defined for the at least one third-party entity.
“10. The system of claim 5, wherein the condition includes a time duration from a time of download.
“11. A system comprising: one or more privacy vaults, wherein at least one of the one or more privacy vaults: is associated with at least one individual user; stores contents associated with the associated at least one individual user; and stores specific identification of a plurality of third-party entities, authorized to access at least a portion of the contents stored by the one or more privacy vaults, along with access permissions, one or more of the access permissions defined for each of the plurality of third-party entities, at least one of the access permissions defining accessibility of the contents, for at least one of the plurality of third-party entities, including a content retention policy defining the right to retain at least a portion of the contents, subsequent to downloading the at least the portion of the contents and defining a condition after which the at least the portion of the contents downloaded and stored by the third party are to be deleted; and one or more processors configured to: provide gateway services for accessing contents stored by the one or more privacy vaults, including handling access requests, for contents from the one or more privacy vaults, wherein an access request, from the at least one third-party entity, is handled in accordance with at least one of the access permissions defined for the at least one third-party entity in each of a plurality of target privacy vaults from which the at least one third party entity requests information, to fulfil the access request for the information from a respective target privacy vault according to the access permission defined for the at least one third-party entity by the respective target privacy vault; provide content gathering services for the at least one individual user, including tracking digital actions of the at least one individual user, gathering contents generated by the digital actions, and storing the gathered contents in the at least one privacy vault associated with the at least one individual user for whom content gathering services were provided; obtain content-retention information, identifying what contents, of outbound contents from at least one privacy vault of the plurality of target privacy vaults, and that were provided responsive to the access request from the at least one third-party entity, were retained remotely by the at least one third-party entity; and compare the identified contents to the content retention policy of the at least one privacy vault and defined for the at least one third-party entity to determine if the identified contents were permissibly retained in accordance with the content retention policy.
“12. The system of claim 11, wherein at least one of the one or more processors is further configured to provide value-handling services defined for the at least one privacy vault, enabling the exchange of value from one or more of the plurality third-party entities for at least a portion of contents stored in the at least one privacy vault.
“13. The system of claim 11, wherein accessibility includes the right to download at least a portion of the contents.
“14. The system of claim 11, wherein the accessibility includes the right to use at least a portion of the contents for a predefined purpose, included as part of the at least one access permission defined for the at least one third-party entity.
“15. The system of claim 11, wherein the condition includes a time duration.”
For more information, see this patent: Gibson, Timothy. End-to-end privacy ecosystem.
(Our reports deliver fact-based news of research and discoveries from around the world.)


Patent Issued for Driving cues and coaching (USPTO 11597389): Allstate Insurance Company
Patent Issued for Systems and methods for generating an inventory of personal possessions of a user for insurance purposes (USPTO 11599847): BlueOwl LLC
Advisor News
- Flourish brings private-bank-like cash solution to MassMutual’s network
- Majority of Americans concerned recent market highs are unsustainable
- GLP-1 users choose between medication and retirement saving
- Gen X and millennials seek new retirement model
- Are families ready for the costs of aging at home?
More Advisor NewsAnnuity News
- A client remarried: Does their annuity still fit?
- Gen X and millennials seek new retirement model
- Global Atlantic names Dan Farrelly head of IMO and IBD channels
- A rising retirement challenge: The license to spend
- What lower interest rates mean to annuity payouts
More Annuity NewsHealth/Employee Benefits News
Life Insurance News