Patent Issued for End-to-end privacy ecosystem (USPTO 11755752): Allstate Insurance Company
2023 SEP 29 (NewsRx) -- By a
The patent’s assignee for patent number 11755752 is
News editors obtained the following quote from the background information supplied by the inventors: “Digital user privacy, consumer data collection and data monetization are becoming ever-more prevalent issues in modern society. Computing devices, software, hardware, and websites continually gather data on users to build profiles, offer advertisements, and plan strategies. Many times, users are not even aware of what data is being gathered and how that data is being used, and software or websites may frequently offer services in exchange for data, such as a “free” search engine or social media site that exchanges services for gathering of user data.
“For a long time, users were willing to accept these services in exchange for the data, believing the data to be limited in scope, the use and business-to-business sharing of the data to be limited in scope, or being unaware of the true value of their personal data in the aggregate. The financial success of these services, predicated largely on data, has revealed some of the true value of user data. At the same time, data gathering and processing has grown much more sophisticated, allowing for the unlocking of significant value in large data sets about individual users and groups of users.
“Problematically, users have already often agreed to have this data gathered and enjoy using the free services. Moreover, users still frequently have no idea as to what data is or was gathered about them. Far more than a simple location or demographic, these data sets can range far and wide, and user behavior itself is often monitored and compiled into complex evaluations of what that user represents in terms of merchant or advertiser opportunity. At the same time, there are limited opportunities to determine what data has been gathered and how the data is being used, and most frequently the impact and scope is observed anecdotally, where a user continually sees advertisements, for example, that appear to be highly targeted. The scope of data is also hinted at when software provides recommendations and seems almost prescient in its understanding of what the user would like.
“While many users may not object to the targeted and precise nature of at least some of these incidents, and may even welcome them in some cases, such as a requested and subsequently on-point recommendation, many users may ultimately be somewhat disturbed at the scope and scale of their own personal information stored and used to assemble these offerings. But, since users can never see the backend data store, and since they typically lack granular control over data, and/or notification when and what data is specifically gathered, people tend to remain somewhat blissfully ignorant, even if they would be distressed if they saw the volume of personal information being gathered, understood the value of what they were exchanging, and understood the full scope of the conclusions that were being drawn about them. Because it may be rare that the user’s data is used exclusively to provide a requested and subsequently on-point recommendation, consumers may ultimately prefer a solution that provides better optics into usage, consumer-centric control and permissioning of such usage and value-sharing opportunities related to a consumer’s personal information.”
As a supplement to the background information on this patent, NewsRx correspondents also obtained the inventors’ summary information for this patent: “In a first illustrative embodiment, a system includes a privacy vault, storing contents associated with a user to whom the privacy vault is assigned. The vault also stores a plurality of access permissions, defined for a plurality of third-parties with whom the user has an agreed-upon sharing relationship, at least one of the access permissions defining, for at least one of the plurality of third parties, procurement and utilization policies for contents accessed by the at least one third-party, and a plurality of user accounts and associated access credentials for the user.
“The system further includes one or more processors, configured to access one or more of the user accounts, using the access credentials, to recover contents, stored by the accessed account and associated with the user and store the recovered contents in the privacy vault. The one or more processors are also configured to receive a request from the at least one third-party, to access the contents stored in the privacy vault, the request identifying which contents are requested and determine if the contents requested are procurable by the at least one third party based on the at least one access permission defined, in the privacy vault, for the at least one third-party. Responsive to the contents being procurable, the one or more processors are configured to provide the contents to the at least one third party along with indication of any constraints on the contents defined by utilization policies of the at least one access permission defined for the at least one third party.
“In a second illustrative embodiment, a system includes a privacy vault, storing contents associated with a user to whom the privacy vault is assigned. The vault also stores a plurality of access permissions, defined for a plurality of third-parties with whom the user has an agreed-upon sharing relationship, at least one of the access permissions defining, for at least one of the plurality of third parties, procurement and utilization policies for contents accessed by the at least one third-party and a plurality of user accounts and associated access credentials.
“The system additionally includes one or more processors, configured to access one or more of the user accounts, using the access credentials, to recover contents, stored by the accessed account and associated with the user. The one or more processors are also configured to categorize the recovered contents as the contents are recovered and store the recovered contents in the privacy vault and associate applicable categories, as indicated by the categorization, with the stored recovered contents. Also, the one or more processors are configured to receive a request from the at least one third-party, to access the contents stored in the privacy vault, the request identifying which contents are requested and determine if the requested contents are procurable by the at least one third party based on the at least one access permission defined, in the privacy vault, for the at least one third-party. Responsive to the contents being procurable, the one or more processors are configured to provide the contents to the at least one third party along with indication of any constraints on the contents defined by utilization policies of the at least one access permission defined for the at least one third party.
“In a third illustrative embodiment, a system includes a privacy vault, storing contents associated with a user to whom the privacy vault is assigned. The vault also stores a plurality of access permissions, defined for a plurality of third-parties with whom the user has an agreed-upon sharing relationship, at least one of the access permissions defining, for at least one of the plurality of third parties, procurement and utilization policies for contents accessed by the at least one third-party and a configuration for default access permission application to a new third-party.”
The claims supplied by the inventors are:
“1. A system comprising: a privacy vault, storing: contents associated with a user to whom the privacy vault is assigned; a plurality of access permissions, defined for a plurality of third-parties with whom the user has an agreed-upon sharing relationship, at least one of the access permissions defining, for at least one of the plurality of third-parties, one or more procurement policies, defining at least contents obtainable by the least one third-party, and one or more utilization policies that define at least one restriction, on use of the contents obtained under the procurement policy for the at least one third party, that applies to the third party, for which it is defined, after the third party obtains the contents; and a plurality of user accounts and associated access credentials for the user; one or more processors, configured to: access one or more of the user accounts, using the access credentials, to recover contents associated with the user, previously gathered and stored by the accessed account; store the recovered contents in the privacy vault; receive a request from the at least one third-party, to access the contents stored in the privacy vault, the request identifying which contents are requested; determine if the contents requested are procurable by the at least one third-party based on the at least one access permission defined, in the privacy vault, for the at least one third-party; and responsive to the contents being procurable, provide the contents to the at least one third-party along with providing any constraints on the contents, the constraints defined by the one or more utilization policies of the at least one access permission defined for the at least one third-party and specifying the at least one restriction on use and sharing of the provided contents by the at least one third party after the third party obtains the contents, the restriction specified specifically for the at least one third party based on the at least one restriction being stored by the vault as specifically applying to the at least one third party.
“2. The system of claim 1, wherein the plurality of access permissions define a plurality of incremental levels of privacy, wherein the at least one access permission for the at least one third party further defines one or more retention policies for the at least one third party, defining at least content retention for the at least one third party for the contents accessed by the at least one third-party, and wherein provision of the contents includes transmission of express indication of any retention constraints for the contents defined by the retention policies of the at least one access permission defined specifically for the at least one third party based the retention constraint being stored by the vault as specifically applying to the at least one third party.
“3. The system of claim 1, wherein at least one of the one or more processors is configured to categorize the contents as the contents are recovered for storage in the privacy vault.
“4. The system of claim 3, wherein the plurality of access permissions are correlated to categories of the contents and wherein at least one more permissive of the plurality of access permissions is correlated to at least one first category that is also correlated to at least one less permissive of the access permissions, in addition to being correlated to at least one second category not correlated to the at least one less permissive of the access permissions and wherein the correlations define access to the categories correlated to a respective access permission.
“5. The system of claim 3, wherein the request identifies one or more content elements, and wherein at least one of the one or more processors is configured to determine one or more categories associated with the one or more content elements, and wherein the determination as to whether the contents are procurable includes determining whether the at least one access permission defined for the at least one third party permits procurement of contents from the determined one or more categories.
“6. The system of claim 3, wherein the categories include types of contents.
“7. The system of claim 3, wherein the categories include sensitivity of contents.
“8. The system of claim 1, wherein the recovered contents include personal data about the user stored by the account.
“9. The system of claim 1, wherein the recovered contents include data about behavior of the user tracked by a party providing the account.
“10. The system of claim 1, wherein the privacy vault further stores a configuration for default access permission application to a new third-party and wherein at least one of the one or more processors is further configured to: receive identification of the new third-party; determine whether any modification, to a default access permission to be applied to the new third-party and indicated by the configuration, applies to the new third-party based on any agreement information determined responsive to identification of the new third-party, the modification at least changing an access right of the new third-party based on the agreement information; and responsive to determining that no modification applies, associate the default access permission with the new third-party based on the configuration.
“11. The system of claim 10, wherein the modification to the default access permission is based on a pre-existing relationship agreement with the new third-party granting permissions to contents correlated to a less restrictive access permission than the default access permission and wherein at least one of the one or more processors is configured to associate the less restrictive permission with the new third-party, responsive to determining that the modification applies.
“12. The system of claim 10, wherein the modification to the default access permission is based on a value-exchange agreement between the user and the new third-party granting permissions to contents correlated to a less restrictive access permission than the default access permission and wherein at least one of the one or more processors is configured to associate the less restrictive permission with the new third-party, responsive to determining that the modification applies.
“13. The system of claim 10, wherein the modification to the default access permission is based on a value-exchange agreement between the user and the new third-party granting permissions to contents correlated to a less restrictive access permission than the default access permission, a scope of the contents correlated to the less restrictive access permission being defined in the value-exchange agreement, and wherein at least one of the one or more processors is configured to: create a hybrid access permission granting access to contents correlated to the default access permission along with contents covered by the scope; and associate the hybrid access permission with the new third-party, responsive to determining that the modification applies.
“14. A system comprising: a privacy vault, storing: contents associated with a user to whom the privacy vault is assigned; a plurality of access permissions, defined for a plurality of third-parties with whom the user has an agreed-upon sharing relationship, at least one of the access permissions defining, for at least one of the plurality of third parties, one or more procurement policies, defining at least contents obtainable by the least one third-party, and one or more utilization policies that define at least one restriction, on use of the contents obtained under the procurement policy for the at least one third party, that applies to the third party, for which it is defined, after the third party obtains the contents; and a plurality of user accounts and associated access credentials; one or more processors, configured to: access one or more of the user accounts, using the access credentials, to recover contents associated with the user, previously gathered and stored by the accessed account; categorize the recovered contents as the contents are recovered; store the recovered contents in the privacy vault and associate applicable categories, as indicated by the categorization, with the stored recovered contents; receive a request from the at least one third-party, to access the contents stored in the privacy vault, the request identifying which contents are requested; determine if the requested contents are procurable by the at least one third-party based on the at least one access permission defined, in the privacy vault, for the at least one third-party; and responsive to the contents being procurable, provide the contents to the at least one third-party along with providing any constraints on the contents, the constraints defined by the one or more utilization policies of the at least one access permission defined for the at least one third-party and specifying the at least one restriction on use and sharing of the provided contents by the at least one third party after the third party obtains the contents, the restriction specified specifically for the at least one third party based on the utilization policy being stored by the vault as specifically applying to the at least one third party.
“15. The system of claim 14, wherein the categories include at least one of: types of contents, sensitivity of contents, or services to which the contents relate.
“16. The system of claim 14, wherein the request identifies one or more content elements and wherein at least one of the one or more processors is configured to determine one or more categories associated with the one or more content elements and wherein the determination as to whether the contents are procurable includes determining whether the at least one access permission defined for the at least one third-party defines procurement of contents from the determined one or more categories.”
For additional information on this patent, see: Gibson, Timothy. End-to-end privacy ecosystem.
(Our reports deliver fact-based news of research and discoveries from around the world.)


Patent Issued for Method for repurposing NDC codes in a pharmaceutical database for allergens (USPTO 11755996): Roca Medical Ltd.
Patent Issued for Systems and methods for homeowner-directed risk of property damage mitigation (USPTO 11756134): State Farm Mutual Automobile Insurance Company
Advisor News
- The missing piece in most retirement plans
- Clients are bringing TikTok insurance advice into advisor meetings
- Embracing a family-centric approach to financial planning
- Family communication: Financial planning’s growing blind spot
- Americans aren’t turning retirement plans into action, LIMRA finds
More Advisor NewsAnnuity News
- Cayman Islands premier to meet with U.S. reinsurance regulators
- Investigation finds deceptive sales, churning of annuities targeting postal workers
- Corebridge annuity sales slip ahead of Equitable marriage
- California teachers settle class-action lawsuit over in-plan annuity fees
- Jackson Financial CEO caps 40-year career with blockbuster Q2
More Annuity NewsHealth/Employee Benefits News
- Arizona, others sue feds over rule many say cuts health care costs
- Healey announces campaign to help residents hold onto their healthcare coverage
- State agency seeks
waiver to reinstate
HIP cost-sharing
- IN NEW ASSAULT ON TRANS YOUTH CARE, TRUMP ADMINISTRATION BARS MEDICAID AND CHIP COVERAGE FOR NECESSARY HEALTH CARE
- PAUL KRUGMAN: US HEALTH CARE IS ALREADY SOCIALIST
More Health/Employee Benefits NewsLife Insurance News
- LIMRA: Individual life sales continue growth trend in Q2, led by whole life and VUL
- New York Life Awards 20 Golden Futures Scholarships, Expanding Student Support Through Financial Education and Career Development
- Built to Last: Winston-Salem—a quiet industrial powerhouse
- The silver economy ushers in a new era of life insurance growth
- Family communication: Financial planning’s growing blind spot
More Life Insurance News