Data-driven hazard risk control

A data-controlled risk monitoring method for smartphones generates a risk data record from usage data, enabling efficient and privacy-preserving risk management for children, addressing the challenge of detecting and managing smartphone-related dangers without violating user privacy.

DE102024102489A1Pending Publication Date: 2025-07-31DIE KAISER GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102024102489
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-29
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

Existing smartphone usage poses risks to children and juveniles due to lack of effective monitoring and privacy concerns, making it difficult for parents to detect and manage potential dangers such as health, legal, and psychological issues without violating their privacy.

Method used

A data-controlled risk monitoring method that generates a risk data record based on user terminal usage data, allowing automated assessment and control without direct access to sensitive data, enabling efficient and reliable risk management through a risk data record transmitted between devices for spatial and temporal independence.

Benefits of technology

Enables efficient, reliable, and privacy-preserving risk management by allowing parents to monitor and manage smartphone usage risks in children, detecting potential dangers quickly and effectively while protecting user privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method for data-driven hazard risk control comprises at least the following steps: capturing usage data (14) of a user terminal (E1); and generating at least one risk data record (22, 28, 34) on the basis of the usage data (14), wherein the at least one risk data record (22, 28, 34) represents a hazard risk for a user of the user terminal (E1).
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to methods, computer programs and devices for data-controlled control of risk risks for users of terminals.Smartphones and similar mobile terminals open their users communication paths that are no example in terms of flexibility, scope, and speed in human history, and are generally regarded as a great progress. However, the exchange of medial contents of all kinds also causes a wide variety of risks for the users. The risks are virulent in particular for users in need of protection, such as children and juveniles, because smartphones are becoming increasingly widespread for these user circles and are generally accepted.The risks can be, on the one hand, a health type, for example in the form of stress, psychic dependencies or also physical damage which occurs as a result of the use. For example, physical and psychic efforts today are typically closely associated with communicative exchange via smartphones.The risks may also be legal in nature and relate, for example, to an violation of personality rights associated with the use of smartphones. Furthermore, today, the smartphone is also quite generally an entrance gate for undesired interventions in the personal development of the user. These may be characterized, for example, by extreme political positions, discriminating behaviors or fraud tests and may sometimes have lawful relevance. Beyond the victim role, it must be taken into account that today the smartphone is also an important tat tool for creating and developing risk risks.The risks of danger have increased due to the practically unlimited number of communication partners. Communication partners include not only trusted friends, however, but also loose acquainters or organizations that can track commercial or fraudulent intent.The risk risks are severe in particular for children and juveniles, since these generally do not yet have fully developed risk awareness. According to data of the statistical federal system, 95 percent of the 13 to 15 year old children, 86 percent of the 10 to 12 year old children and 21.6 percent of the 6 to 9 year old children in Germany are nevertheless estimated to have a smartphone.It is increasingly difficult for the responsible parents to fulfil their protective function to a sufficient extent. Due to the multiple communication possibilities of current smartphones, it has become difficult to detect risk risks reliably and in good time at all times. Besides the practical problems involved in monitoring comprehensive and continuously changing usage data, content verification is also problematic because the privacy right of the person to be protected is violated. This also applies to parents who wish to control the use data of their child for checking the risk. Further problems arise from the fact that the usage time during a personal check is limited.It is an object of the invention to specify a method for efficient, reliable and data protection-oriented risk risk control.The object is achieved by a method for data-controlled risk risk monitoring, which comprises at least the following steps: recording usage data of a user terminal; and generating a risk data record on the basis of the usage data, wherein the risk data record represents a risk for a user of the user terminal.The method is distinguished, among other things, in that a direct disclosure of the usage data for monitoring purposes is not necessary. The automated or person-bound assessment of the risk risks can instead be carried out on the basis of a risk data record which is generated on the basis of the usage data, i.e. under data control, and enables efficient and reliable risk risk control.The risk data record can be transmitted in particular flexibly by electronic means between different communication devices. The risk control can therefore advantageously be carried out spatially and temporally independently of the user terminal. A transmission of the sensitive and comprehensive usage data, on the other hand, can be dispensed with.In addition, one or more monitoring persons can be advantageously involved in the risk monitoring without direct and uncontrolled access to the usage data having to be granted to these persons. The usage data are therefore used specifically for data-controlled risk control, but are otherwise protected from access by third parties.The method according to the invention can therefore be used on the one hand to efficiently and reliably detect and monitor the risk risks ascertained on the basis of the usage data. On the other hand, the scope of control itself can also be controlled or controlled better. In particular, indirect access to the usage data can be controlled via the risk dataset in order to realize data access control for one or more control persons.A particular advantage of the method is that it can be carried out quickly and reliably by means of powerful data processing means. This applies even to large amounts of data, which extend e.g. to text, audio, image and video signals and are exchanged, i.e. received, processed, generated and / or transmitted via a respective user terminal.With the method according to the invention, it is not necessary to completely analyze the content of the usage data by an inspector and thereby to violate the privacy of the user.The method according to the invention is particularly suitable for parents who wish to accompany the digital growth of their child in a structurally and paedagogically valuable manner. It also opens up new ways to understand the digital world from the perspective of persons in need of protection and to identify risk risks in good time without damaging their privacy.Embodiments of the invention are disclosed in the claims, the description and the figures.According to one embodiment, the risk data record is provided at a control entity which, for further realization of the risk risk control, has at least one data processing device, e.g. a control terminal and / or a central server. The control entity can also be assigned one or more control persons who receive risk datasets via respective control terminals and / or transmit control commands for reducing risk risks. The control entity is generally used for examining the risk dataset and can, if necessary, prompt measures for reducing the risk of risk.The risk dataset may be transmitted and processed in various ways. For example, the risk dataset can first be provided at a central server, which evaluates the risk dataset using a computer-implemented control rule. The risk data record can then be forwarded to a predetermined control terminal which is assigned to a control person (e.g. a parent). Forwarding to a plurality of control terminals, which are assigned to a plurality of care persons, for example, is also conceivable. A respective risk data record can alternatively also be transmitted directly from the user terminal to be checked to one or more check terminals.The control person can check the content of the risk data record and decide whether there is a need for action and if necessary measures for reducing risks should be initiated. Such measures can also be carried out under data control, for example by generating and transmitting notification or control datasets to the user terminal. A central server can participate in this by generating an intervention data record adapted to the user terminal for a control data record received from the control terminal. The intervention data record preferably contains technical implementation data which are required for the implementation of the control data record at the user terminal.According to a further embodiment, a risk data record can also be provided at the user terminal. This is particularly useful for self-monitoring of the user. The user may be interested in being able to be alerted to risk risks on the basis of the risk data record and, if necessary, to reduce his own risks. Moreover, the user can check whether and to what extent risk data are drained from the user's own terminal. The user is thus not only a passive control subject, but can be actively included in the risk risk control. The frequency with which risk datasets are transmitted to the control entity can be lowered in the case of an additional self-control.The risk control can be carried out particularly efficiently from a distance point of view if the risk data record is made compact in comparison with the usage data and can therefore be transmitted at high speed. This is based on the realization that the usage data only contain to a small extent risk data which are associated with one or more risk risks. However, it is unlikely that risk risks arise from all usage data.According to a further embodiment, the usage data are at least substantially not contained in the risk data record. For example, the size of the risk data record is less than 5 percent of the size of the usage data, preferably less than 1 percent. In this way, on the one hand, efficient transmission and processing of the risk dataset is made possible. Secondly, those usage data which are irrelevant for the assessment of the risk need not be mapped in the risk data record.Preferably, the risk data record does not comprise any usage data at all, but only information about the usage-related risk risks. The risk data record therefore preferably does not allow immediate insight into the usage data as such. However, it is possible to include one or more selected elements of the usage data in the risk data record, which occupy a risk and / or allow the control entity to more accurately assess the specific risk. However, comprehensive insight into the usage data is also avoided in this case. This can be achieved by the risk dataset for the selected usage data elements not containing a data context.According to a further embodiment, the risk data record is generated using at least one data processing means of the user terminal. In this case, the use data can be not transmitted to a server or another device. In addition, the user can optionally suspend the risk-risk control by switching off the terminal. Risk monitoring is effected in this way as a function of active use of the terminal.According to a further embodiment, at least one risk class is determined for the risk data record, said risk class representing a risk type for at least part of the usage data. The risk class enables a particularly efficient assessment of the risk. The risk datasets can also be designed to be particularly compact in order to conserve transmission resources and to ensure reliable transmission even in areas with poor network coverage.By means of risk classes, it is possible to distinguish between passive risk risks and active risk risks, for example. It is also possible to distinguish between physical risk risks and psycho risk risks at the level of the risk data record by grouping these risk types by risk classes.According to a further embodiment, at least one risk level is determined for the risk data record, said risk level representing a risk intensity for at least part of the usage data. The risk level can be considered an urgency to check the risk of risk and take countermeasures. The degree of risk can be expressed, for example, on a numerical scale that enables intuitive assessment by an inspector and advantageously machine-based analyses.Preferably, at least one element of the risk data set is defined with reference to a multi-level reference, which is designed to assess a relative risk of risk. The reference may have, for example, at least three stages. An example of such a reference is the school grade scale with integer levels 1 to 6. Each level may be assigned a risk level, for example such that a risk level of 1 indicates a very low risk risk, but a risk level of 6 indicates a possible penalty. Intermediate risk levels may represent graded risk risks, being at the discretion of the control person when and how to respond to the risk displayed.According to a further embodiment, the risk data record has a plurality of elements which are assigned to different parts of the usage data and represent a respective risk of risk. For example, a first element of the risk data record can be assigned to a first part of the usage data, wherein a second element of the risk data record is assigned to a second part of the usage data, which is different from the first part of the usage data. The risk data record enables a differentiation within the usage data, which can be composed of a wide variety of data types and / or data sources.The elements of the risk data record can be assigned in particular to different applications of the terminal. The "virtual location" of a detected risk of risk can therefore be identified quickly. The risk of risk can also advantageously be prioritized in an application-related manner. Preferably, the elements are formed by respective numerical values.A further possibility is to assign at least some of the plurality of elements of the risk data record to different communication partners of the user. The communication partners can be formed by real or virtual persons, organizations or providers with which the user is in contact, as distinguished from the usage data.For efficient processing of a risk dataset with a plurality of elements, it is advantageous to combine these into a summary element. The overview element represents a risk combined for a plurality of parts of the usage data. The risk risks can thereby be assessed in a structured manner, in particular hierarchically. Thus, the monitoring person can first determine, on the basis of the overview element, which danger situation exists over all drawn-on parts of the usage data. In a second step, the monitoring person can determine, on the basis of the individual elements, whether a particular risk situation exists for a specific component of the usage data and, if appropriate, measures for reducing the risk of risk are to be taken into consideration.The overview element preferably comprises a numerical value representing an average value or an extreme value of the plurality of elements.According to a further embodiment, the risk data record represents a technical usage behavior at the user terminal. For example, the risk dataset may comprise information about at least one of the following aspects, which may be attributed to the technical usage behavior: usage times and / or usage durations; number of input commands of the user; number of activated applications; number of web sites called; position data of the terminal; operating data of the terminal. These data can form components of the usage data.The technical usage behavior can be detected comparatively easily at the terminal by using the control commands detected in any case as usage data for generating the risk data record. Moreover, the technical usage behavior generally does not allow any immediate conclusions to be drawn about the data content. Therefore, data protection aspects can be taken into account particularly well if desired if the risk data record is supported exclusively on technical usage data. The technical usage data are very compact in comparison to other usage data, e.g. high-resolution image data, and are therefore particularly suitable for rapid generation and transmission of risk datasets.According to a further embodiment, the risk data record represents a content-related use behavior of the user. For example, the risk dataset may comprise information about at least one of the following usage data types: text, image, video and / or audio data which are input and / or received at the user terminal; a function type of an activated and / or installed application on the user terminal, e.g. for distinguishing between social media apps, contact switching apps, shopping apps, game apps, etc. Content usage data may also have properties of one or more communication partners, in particular interest alignments, e.g. in a commercial and / or political aspect.The risk risks arising from modern communication media can be very varied. Examples of risk risks are possible penalty records, addiction behavior, discrimination, discreditization, mobbing, political extremeism, pornography, abuse, handling incorrect digital identities and organizations ("auth Accounts"), purchase of access-restricted goods, e.g. drugs, alcohol and other drugs. Such risk risks can be detected by content usage data.The risk data record is preferably generated as a function of a predetermined data processing rule which can be modified by a control entity and / or the user. However, different modification rights can be provided for the control entity and the user. A modification can also be entirely excluded for the user.The data processing rule is preferably used to define the scope and the test depth of the risk risk control. Thus, for example, adaptations can be made in order to adapt the risk datasets to be generated to the control requirements. For example, it can be set whether, and if so, which parts of the usage data are to be included in a risk data record for better assessment of the risk risks. Portions of the usage data associated with negligible risk may also be totally excluded from processing. The data processing rule can optionally also have a parameter which controls the frequency with which a risk data record is to be generated.The data processing rule is preferably computer-implemented and comprises in particular a model of machine learning. Such models have proven to be extremely efficient for the processing of complex media information and a wide variety of usage data. Nevertheless, it is possible to make these models compact in order to enable execution even on less powerful user terminals. Machine-learned models are also well-adaptable by new training data. The data processing rule is updated accordingly for this purpose.To further improve the risk-risk control, it is possible to control the execution of the data processing rule by a central (control) server. However, the data processing rule is preferably stored on the user terminal and is executed on the user terminal. Alternatively, the usage data can be transmitted at least in part from the user terminal to a central server, which generates the risk data record.According to a further embodiment, the usage data are acquired using an operating system of the user terminal. For this purpose, a capture application can be stored on the user terminal.The risk data record is optionally generated as a function of an active input at the user terminal. In this way, the user can activate the risk-risk control separately, for example by inputting authentication data. In addition, the user can optionally be granted further control rights, for example by specifying one or more authorized control persons who are allowed to receive risk datasets.According to a further embodiment, the risk data record is generated and / or provided at the control entity as a function of validity data which represent a temporarily limited validity of the risk data record. An unnecessary transmission of old risk datasets can be prevented in this way.To further improve the data protection, the risk data record can be generated in a non-storable data format. In addition, the risk data record is preferably not modifiable.According to a further embodiment, the protection of the data is increased by providing the risk data record in encrypted form, in particular at at least one central server, the user terminal and / or at least one control terminal.According to a further embodiment, the risk data record is provided as a function of authorisation data. For example, it can be required that a recipient of the risk dataset must be identified by valid authorisation data in order to obtain the risk dataset. Unauthorized control persons can thus be excluded from risk risk control.The trust in the method can be further increased in that the authorisation data can be seen by the user to be checked. The user can thus take an image who is allowed to participate in his own risk risk control.According to a further embodiment, the risk dataset is generated as a function of at least one data profile which can be selectively activated and / or modified by the user and / or the control entity. The data profile can define, for example, a subset of the usage data which is used as the basis for generating the risk data record. Alternatively or additionally, the data profile can define which risk information is to be contained in the risk data record, for example whether the risk data record is to inform about risk risks relating to the technical and / or content-related usage behavior.Preferably, the data profile is selected from a number of predetermined data profiles. The practical configuration of the risk risk control is thereby simplified. For example, a control person at a control terminal can select a data profile on which the generation of risk datasets is based. For this purpose, a corresponding control command can be transmitted to the user terminal, which command modifies the data processing rule according to the selected data profile.According to a further embodiment, the risk dataset is evaluated using previously provided risk datasets. This enables an objective assessment of changes in the risk of risk. Information about a change in the risk can be added to the risk dataset.According to a further embodiment, parts of the usage data are compared with a plurality of predetermined usage datasets stored in a database. The differences determined in this case can advantageously be incorporated into the generation of the risk dataset, in particular in order to achieve a higher accuracy and reliability for the risk dataset. For example, a usage data record stored in the database can be representative of an expected user behavior. An increased risk may be assumed in particular if the deviations from the current usage data violate a predetermined threshold value criterion. Deviations between a current risk dataset and reference risk datasets stored in a database can also be determined in a corresponding manner and taken into account in the current risk dataset.According to a further embodiment, an intervention data record is provided at the user terminal. The intervention data record represents a data-controlled measure for reducing the risk of risk. For example, the intervention data record can have at least one control command for the user terminal, which is processed by the user terminal. According to the control command, it can be provided, for example, that a warning message is displayed on the user terminal. This display process is preferably implemented automatically, i.e. the user is automatically informed of potential risk risks without further measures. This can be effected, for example, by means of a push message to the terminal.According to a further embodiment, the method is fully or partially computer-implemented. In this case, a distributed execution of the method steps is possible in such a way that the usage data acquisition takes place, as indicated above, at least partially on the user terminal, in particular using the data processing means of the terminal, such as the processor, the platform (e.g. operating system) and / or the user interface, which is preferably designed graphically. Use data stored internally on the terminal can also be acquired, which are obtained, for example, by using installed software applications.The user terminal is preferably formed by a mobile terminal, e.g. a smartphone, smart watch, tablet, laptop or another compact data terminal. It is preferably equipped with a display device which has a graphical user interface for control, for example in the form of a touch-sensitive display surface. A control terminal can be designed in a manner corresponding to the user terminal.According to a further aspect, the invention relates to a second method for data-controlled risk risk control. It relates to the control entity and comprises at least the following steps: receiving a risk dataset representing a risk risk on the basis of usage data of a user terminal; and generating at least one intervention dataset on the basis of the risk dataset, wherein the intervention dataset has at least one control command for the user terminal. The method preferably also comprises the intervention data record being provided at the user terminal, for example by transmission from a control server or a control terminal to the user terminal.According to a further aspect, the invention relates to a third method for data-controlled risk risk monitoring, which method comprises at least the following steps: receiving a first risk data record which represents a risk of risk for a user of a user terminal on the basis of usage data of the user terminal; generating a second risk data record on the basis of the first risk data record, wherein the second risk data record contains at least parts of the first risk data record and data for processing the first risk data record; and providing the second risk data record at a monitoring entity and / or an inspection entity.The third method can be executed in particular by a central server, which forwards the information of the first risk data record from the user terminal to a control terminal and supplements the first risk data record with further data, which control the further processing of the first risk data record. The forwarding can be made dependent on a previous checking of authentication data of the control terminal. The forwarding can also be made dependent on further criteria, e.g. the temporal validity of the first risk data set.According to one embodiment of the third method, an intervention data record is generated on the basis of the second risk data record. The intervention data record contains at least one control command for the user terminal and can be provided, for example, by a control terminal directly at the user terminal and / or first at a central server, which transmits the intervention data record to the user terminal unchanged or in modified form.It is to be understood that the described methods can each be designed as computer-implemented methods, i.e. all or at least part of the method steps are executed by a computer. The respective computer or computer-like unit can generally be formed by a server or a part thereof. The user terminal and any control terminal also each represent a computer which can execute the assigned method steps in a computer-implemented manner.It is also to be understood that each of the described methods may be embodied by a computer program, wherein the instructions of the computer program, when executed on a computer, cause the computer program to carry out the steps of a method according to at least one of the embodiments disclosed above.A further aspect of the invention relates to a device connected to at least one electronic data processing means and a non-volatile memory. The memory stores a computer program, the instructions of which, when executed by the at least one data processing means, cause the at least one data processing means to execute the steps of a method according to at least one of the embodiments disclosed above. The device can be formed in particular by the use or control terminal or a server. If the method steps are carried out in a distributed manner on different devices, these can form a system which implements the data-controlled risk-risk control. In particular, a user terminal, a central server and a control terminal together can form a control system which carries out and controls the method steps.The described methods are preferably each configured to be capable of real time. For example, the time interval between the generation of the risk data record and the subsequent provision at the control entity can be less than 500 milliseconds. A customary data transmission speed of a mobile radio network is assumed here.Furthermore, it is preferred that a risk dataset provided at a control terminal is displayed at the control terminal. Similarly, it is preferable that an intervention record provided on the user terminal is displayed so that the user can know it.The features disclosed in connection with the first method, in particular in connection with the individual embodiments, can also be realized in a corresponding manner in the second or third method. In other words, the features of the embodiments of the first method can be realized in a corresponding manner in the second method and / or third method.The described aspects of the invention will be described below purely by way of example with reference to the drawings, in which: FIG. 1 shows a first diagram for illustrating aspects of a method for data-controlled risk-risk control; FIG. 2 shows a second diagram to illustrate further aspects of risk risk control; FIG. 3 shows a third diagram for illustrating aspects of risk risk control; FIG. 4 shows a fourth diagram for illustrating aspects of risk risk control; and FIG. 5 is a diagram illustrating aspects of a risk dataset.Functionally identical elements are identified by the same reference numerals.A method of data-controlled risk risk control will first be described with reference to FIG. 1.The method comprises the exchange of data between a usage entity 10 and a control entity 12. The usage entity 10 has a user terminal E 1, which is used as a communication means by a user, not shown, in particular a minor child, at various locations without direct supervision. The user terminal E1 is connected to a public network which allows access to the Internet. The user terminal E 1 also stores a first application which is adapted for participation in the risk risk control.The control entity 12 has a control terminal E 2 which is used by a not-shown control person, for example a parent part of the child, for controlling the risk risks of the child. A second application is stored on the terminal E 2, which is adapted for participation in the risk risk control.The risk risks to be checked result from the usage data 14 which arise in connection with the usage of the terminal E 1. This includes in particular technical usage data, for example the frequency of use and duration of use of the terminal E 1. In addition, the usage data 14 comprises content-related usage data, e.g. texts exchanged by the terminal E 1.The usage data 14 is processed by means of a data processing rule 20 in order to generate a first risk data record 22. The first risk data record 22 contains information about any risk risks for the user of the terminal E 1. Possible embodiments of the risk data set 22 are described further below in connection with FIG. 5.The data processing rule 20 is implemented by a machine-learned model, in particular by a neural network. The data processing rule 20 is stored on the user terminal E 1 and is preferably executed automatically at regular time intervals, i.e. without separate input by the user of the terminal E 1. Optionally, however, it can be provided that the user must activate the data processing rule 20 separately. For this purpose, the user can input input data 16 at the terminal E 1 in order to release the data processing rule 20 and / or the associated first application at the terminal E 1.The risk data record 22 generated by means of the data processing rule 20 is provided at the control entity 12 by being electronically transmitted from the use entity 10 to the control entity 12 via a communication connection, not shown in more detail. The transmission is carried out in particular using private and / or public data transmission networks, e.g. by encrypted transmission over the Internet. The use entity 10 and the control entity 12 can in this way be arranged at a greater spatial distance from one another, so that the user and a control person can move spatially independently of one another.The risk data record 22 can be transmitted to the control terminal E 2 in the form of an e-mail or a push message, for example, and can be processed there by the second application and displayed. The second application can be automatically activated in response to the receipt of a risk dataset 22 in order to indicate to the monitoring person the risk risks contained in the risk dataset 22.Additionally or alternatively to automatic activation, the control person can selectively activate the application for risk control, in particular by inputting input data 26.In general, the receipt and the processing of a respective risk dataset 22 are controlled by a control rule 18. According to the control rule 18, it is provided, for example, that access to the risk data record 22 is possible only after previous input of authentication data. The authentication data is included in the input data 26.After receiving and displaying the risk data record 22, the control entity 12 has information which enables assessment of the risk risks without exposing or transmitting the usage data 14. Violation of the personality rights of the user is accordingly minimized. Moreover, the use time for the terminal E1 is maximized because the control person does not have to operate the terminal E1 to control the use data 14. A respective risk data record 22 is thus generated substantially independently of the current use of the terminal E 1 and transmitted to the control entity 12. For this purpose, the first application can run in the background to other applications used on the terminal E 1.However, the usage data 14 are not transmitted to the control entity 12. The data transmission resources of the utilization entity 10 and of the control entity 12 are accordingly saved, in particular with regard to the data volume conditions of the terminals E 1 and E 2.After the monitoring entity 12 has evaluated the risk on the basis of the first risk data record 22, an intervention data record 24 can optionally be generated and transmitted to the use entity 10. The intervention data record 24 preferably has at least one warning message which is displayed on the user terminal E 1 and informs it about current risk risks. If the control entity 12 does not determine any relevant risk risks, preferably no intervention data record 24 is transmitted to the terminal E 1.With reference to Fig. 2, possible extensions and modifications of the method of Fig. 1 will be described.In addition to the entities 10 and 12 of FIG. 1, according to FIG. 2 a survey entity 30 is provided which further develops the data-controlled risk risk control. The inspection entity 30 comprises in particular a central control server (not shown) which receives a second risk data record 28 from the usage entity 12 and evaluates the latter.The second risk data record 28 comprises the first risk data record 22 and further information which is added by the control entity 12, for example a proof of authorisation.For the evaluation of the second risk data record 28, risk data records provided previously at the control entity 12 are preferably used, which provide information about changes in the risk.The second risk data record 28 preferably comprises instructions of a monitoring person for examining the first risk data record 22 and / or authorisation data. This data can be part of the input data 26 and can contain, for example, a request for machine-assisted assessment of risk risks by the inspection entity 30. Alternatively or additionally, the second risk data record 28 can have a request for forwarding the risk data record 28 to an inspection point to which a trained person for inspecting risk risks is assigned. For example, the inspection center can be asked to assess any law-related relevance of hazardous condition circumstances.In response to the receipt of the second risk dataset 28, the inspection entity 30 generates an inspection dataset 32, which is transmitted to the control entity 12. The survey data record 32 contains a result of the machine-assisted assessment of the second risk data record 28 and / or assessment performed by the survey site. The control entity 12 can use the survey data record 32 alternatively or additionally to a separate assessment of the risk data record 22 in order to decide on any measures for reducing the risk risks. In this way, one or more control persons of the control entity 12 can be supported in the risk-risk control.The support by the inspection entity 30 can be limited by an inspection person in particular to those cases in which the inspection person cannot perform the assessment of the risk risks itself or wishes to reduce the own risk of an erroneous assessment. For this purpose, the second risk data set 28 is transmitted to the inspection entity 30 as a function of the input data 26.The control entity 12 can comprise a server, not shown, which supports the control person in the sense of machine-assisted automated risk control. In particular, a respective intervention data record 24 can also be transmitted to the utilization entity 10 without direct initiation by a control person. This is useful, for example, if a respective control person is not available or the control terminal E 2 is not switched on. In such a case, the user can nevertheless be protected by a respective intervention data record 24 being generated by the server and transmitted to the user terminal E 1.With reference to FIG. 3, further modification possibilities for risk risk control are described below.Deviating from FIGS. 1 and 2, it is emphasized in FIG. 3 that the first risk dataset 22 can be generated using data profiles A, B, C or D. The data profiles enable risk control to be restricted to specific types of usage data. They can be designed as follows.The command data profile A is adapted to support the detection of risk risks on command data of the user. Command data are in particular usage data 14 which represent a technical usage behavior and indicate, for example, the number of commands, called websites or applications input at the user terminal E 1. The command data may be completely independent of the content that has been processed in conjunction with the input commands. The command data is therefore comparatively compact in size and allows a high degree of data protection.When selecting the content data profile B, the risk-risk control extends to the content of the usage data 14, which includes in particular the content of text messages, websites or activated applications at the terminal E 1. Corresponding usage data 14 can also be present in the form of image, video or audio data. The content is automatically analyzed by the data processing rule 20 and evaluated for any risk risks. The control person does not have a direct view of the usage data 14.The application data profile C is adapted to process the usage data 14 with respect to one or more applications (apps) installed on the user terminal E 1. For example, when selecting the application data profile C, the risk data record 22 is structured in an application-related manner and allows an overview of which risk is to be drawn for a respective application of the terminal E 1. Measures for reducing the risk of risk can be implemented very efficiently in this way, for example by transmitting an intervention data record 24 to the user terminal E 1 with the content that an application classified as dangerous is automatically deleted or the user is instructed to delete or deactivate the application on his terminal E 1.The application data profile C further allows the usage data 14 to be restricted to one or more selected applications of the terminal E 1. Total control of all applications can be dispensed with for efficiency reasons. However, newly installed apps may be acquired from the application data profile C. Only applications that are classified as harmless by the control entity 12 are not captured by the application data profile C.As a further selection possibility, the position data profile D is available, which supports the evaluation of the usage data 14 on position data of the terminal E 1, in particular exclusively. The position data profile D assumes that risk risks frequently result from the location of the person in need of protection. For example, in the case of unusual or completely new locations, a higher risk may be assumed, which risk is identified separately in the risk data record 22 and may be included in addition to further risk risks.A respective risk data record 22 can be generated using only one of the data profiles A, B, C or D, wherein then only the part of the usage data 14 selected according to the data profile is included in the generation of the risk data record 22. However, it is preferably possible to simultaneously select a plurality of data profiles in order to make the risk data record 22 more meaningful. The risk data record 22 enables a particularly differentiated risk assessment when selecting a plurality of data profiles.With reference to FIG. 4, a further embodiment of the method for risk risk control is described below. In contrast to FIGS. 2 and 3, the inspection entity 30 is not shown in FIG. 4. However, it can optionally also be involved in the method, as described in connection with FIG. 2.The embodiment according to FIG. 4 is characterized in that the control entity 12 comprises a central server S and a control terminal E 2, which communicate with one another and with the use entity 10, as described below.The first risk data record 22 is transmitted from the terminal E 1 of the use entity 10 to the central server S for the purpose of further processing and forwarding to the control terminal E 2. The risk data record 22 can be transmitted in unchanged form as a second risk data record 34 to the ready-to-receive control terminal E 2. Optionally, however, the server S can add further information to the first risk data record 22, which allows the control person, i.e. the user of the control terminal E 2, to better assess the risk.The server S ensures that the second risk data record 34 is transmitted only to an authenticated control terminal E 2. For this purpose, the transmission of the second risk data set 34 can be made dependent on the reception and the checking of authentication data of the control terminal E 2 (not shown).After the second risk data record 34 has been received at the monitoring terminal E 2, the latter is displayed on a display device, not shown, of the terminal E 2 of the monitoring person. The control person can then decide whether and in what form measures should be taken to counteract the risk of risk. One possibility is for the control person to generate a control data record 36 with the aid of the terminal E 2 and to transmit it to the server S.The control data record 36 contains one or more commands for the server S, so that the latter generates a desired intervention data record 24 and transmits it to the terminal E 1. For example, the control person can instruct the server S via the control data record 36 that one or more warning messages for specific parts of the usage data 14 are transmitted to the terminal E 1. The warning messages are automatically displayed on the terminal E 1 after the control data record 36 has been received, in order to sensitize the user to the hazardous situation.The control data record 36 also gives the control person the option of modifying the data processing rule 20 stored at the terminal E 1. For this purpose, the server S can generate a suitable intervention data record 24 and transmit it to the terminal E 1. The control person can thus adapt the control profile embodied by the data processing rule 20, for example by selecting at least one data profile A, B, C or D (cf. FIG. 3 ).The control data record 36 can contain a risk assessment of the monitoring person, which deviates from the risk data record 34. This discrepancy is exploited to improve risk risk control. For example, the server S can perform an adaptation of the data processing rule 20 on the basis of the deviating risk assessment in order to increase the accuracy of the risk danté sets 34 generated in the future. This can be done in such a way that the server S with the deviating risk assessment initiates a retraining of the machine-learned model of the data processing rule 20 and updates it on the user terminal E 1.As a further measure for reducing the risk risks, a second intervention data record 38 is generated at the control terminal E 2 and transmitted to the user terminal E 1. The second intervention data record 38 can contain, in particular, an individual message of the control person to the user terminal E 1. The message indicates, for example, certain risk risks and contains proposals for reducing the risk.With reference to FIG. 5, an exemplary embodiment of a risk dataset is described below. The risk dataset comprises five data elements D 1, D 2, D 3, D 4 and D 5.The data elements D 1 to D 4 are each expressed on a multi-level scale that is identical for the data elements D 1 to D 4 respectively and are denoted by the reference symbols I, II, III and IV in FIG. 5. Each of the scales I to IV has six stages 1 to 6.The data elements D 1 to D 4 each relate to an aspect of the usage data 14 that is acquired by the risk-risk control. For example, when selecting the application data profile C, the data elements D 1 to D 4 can each relate to one of four communication applications of the user terminal E 1. The risk of risk for each of these applications is expressed separately on the associated scale I to IV by the data elements D 1 to D 4.The significance of the individual scale stages 1 to 6 can be different in each case. For example, the scale I may represent a content-related hazard type as follows: 6 penalty 5 damage 4 non-age 3 interest 2 age 1 yieldIn another example, scale II may represent a hazard type related to technical usage behavior. In particular, the scale may express a usage intensity as follows: 6 Pathologically 5 Loss of control 4 Limity 3 Satisfactory 2 Discidinator 1 Very discidinatorWith a view to evaluating the risk risks as regards the content, the scale III can be defined with respect to one or more communication partners of the user. For example, the scale III may express a degree of trust or risk as follows: 6 Dangerous communication partner 5 Negative communication partner 4 Critical communication partner 3 Positive communication partner 2 Very good communication partner 1 Perfect communication partnerThe respective communication partner can be a person with direct contact. Persons following the user and may be considered associated persons or organizations are also conceivable, however.In another example, the content evaluation of particular usage data 14, in particular text, audio, image or video data, may be directed to urgency for intervention. A corresponding scale IV can be defined as follows: 6 penalty 5 very critically 4 checks 3 need for action 2 sense 1 nois of concernIn one example, a text message received at terminal E1 may be analyzed by data processing rule 20. In the case that the text message has accompanying comments which are marked by Hass ("Hat Speech"), a corresponding data element of the risk dataset 22 can have a degree of risk of 4, cf. e.g. D 2 in FIG. 5 ; on the other hand, a maximum degree of risk of 6 can be established when a call is made to the force.In order to facilitate the rapid processing of a risk data record, in particular by a control person, the individual data elements D 1 to D 4 can be merged to form an overview data element D 5. As illustrated in FIG. 5, the data item D 5 may indicate an arithmetic mean of the data items D 1 to D 4. The average value D5 can be well acquired, so that if the average value is abnormally increased, the control person could be made to view the individual values D1 to D4 on the scales I to IV in order to analyze the specific cause of the increased risk of risk.The described methods for risk risk monitoring make possible efficient and reliable monitoring of the digital usage data 14 which are produced at the user terminals E 1 of children and other persons in need of protection. Thus, in particular parents are effectively supported to freely provide their child with the potential of present-day communication media and at the same time keep the risk risks associated therewith in hand.LIST OF REFERENCE CHARACTERS10 Usage entity 12 Control entity 14 Usage data 16 Input data 18 Control rule 20 Processing rule 22 First risk data record 24 First intervention data record 26 Input data 28 Second risk data record 30 Survey entity 32 Survey data record 34 Second risk data record 36 Control data record 38 Second intervention data record A Command data profile B Content data profile C Application data profile D Position data profile E1 User terminal E2 Control terminal D1 Individual data element D2 Individual data element D3 Individual data element D4 Individual data element D5 Overview data element I Risk scale II Risk scale III Risk scale IV Risk scale S Central server

Claims

Method for data-controlled risk risk control, which comprises at least the following steps: - acquisition of usage data (14) of a user terminal (E1); and - generation of a risk data record (22, 28, 34) on the basis of the usage data (14), wherein the risk data record (22, 28, 34) represents a risk for a user of the user terminal (E1).Method according to claim 1, wherein the risk data record (22, 28, 34) is provided at a control entity (12), in particular a central control server (S) and / or a control terminal (E2).The method according to claim 1 or 2, wherein the usage data (14) is at least substantially not included in the risk dataset (22, 28, 34), in particular wherein a size of the risk dataset (22, 28, 34) is less than 1 percent of a size of the usage data (14).Method according to at least one of the preceding claims, wherein a risk class is determined for the risk data record (22, 28, 34), said risk class representing a risk type for at least part of the usage data (14).Method according to at least one of the preceding claims, wherein a degree of risk is determined for the risk data set (22, 28, 34), said degree representing a risk intensity for at least part of the usage data (14).Method according to at least one of the preceding claims, wherein at least one element (D1, D2, D3, D4) of the risk data set (22, 28, 34) is defined in relation to a multistage reference (I, II, III, IV) which is designed for assessing a relative risk of risk, in particular wherein the reference (I, II, III, IV) has at least three stages.Method according to at least one of the preceding claims, wherein the risk data record (22, 28, 34) has a plurality of elements (D1, D2, D3, D4) which are assigned to different parts of the usage data (14) and represent a respective risk.Method according to claim 7, wherein at least some of the plurality of elements (D1, D2, D3, D4) are assigned to different applications of the user terminal (E1), and / or wherein at least some of the plurality of elements (D1, D2, D3, D4) are assigned to different communication partners with which the user is connected as an identity card for the usage data (14).Method according to at least one of the preceding claims, wherein a plurality of elements (D1, D2, D3, D4) of the risk data record (22, 28, 34) are merged to form an overview element (D5), which represents a risk merged for a plurality of parts of the usage data (14).The method of claim 9, wherein the overview element (D5) comprises a numerical value representing an average or extreme of the plurality of elements (D1, D2, D3, D4).Method according to at least one of the preceding claims, wherein the risk data record (22, 28, 34) represents a technical use behavior of the user, in particular wherein the risk data record (22, 28, 34) comprises information about at least one of the following: - use times and / or use durations; - number of input commands; - number of activated applications; - number of called websites; - position data of the user terminal (E1); - operating data of the user terminal (E1).Method according to at least one of the preceding claims, wherein the risk data record (22, 28, 34) represents a user's content-related usage behavior, in particular wherein the risk data record (22, 28, 34) comprises information about at least one of the following: - text, image, video and / or audio data which are input and / or received at the user terminal (E1); - function type of an activated or installed application on the user terminal (E1); - properties of one or more communication partners, in particular an interest alignment, for example in a commercial and / or political aspect.Method according to at least one of the preceding claims, wherein the risk dataset (22, 28, 34) is generated as a function of a predetermined data processing rule (20), which can be modified by a control entity (12) and / or the user.The method of claim 13, wherein the data processing rule (20) comprises a machine learning model.Method according to at least one of the preceding claims, wherein the user data (14) is recorded at the user terminal (E1) using an operating system of the user terminal (E1) and transmitted at least in part from the user terminal (E1) to a central server (S), and wherein the risk dataset (28, 34) is generated at the central server (S).Method according to at least one of the preceding claims, wherein the risk data record (22) is generated as a function of an active input (16) of the user at the user terminal (E1), in particular wherein the input (16) comprises authentication data.Method according to at least one of the preceding claims, wherein the generation of the risk data record (22) and / or provision of the same at a control entity (12), in particular a control terminal (E1), takes place as a function of validity data which represent a temporarily limited validity of the risk data record (22); and / or wherein the risk data record (22) is generated in a non-storable data format and is preferably not modifiable.Method according to at least one of the preceding claims, wherein the risk data record (22) is provided in encrypted form, in particular at at at least one central server (S), the user terminal (E1) and / or a control terminal (E2).Method according to at least one of the preceding claims, wherein the risk data record (28) is provided as a function of authorisation data (26), in particular at at at least one central server (S) or a control terminal (12).Method according to at least one of the preceding claims, wherein the risk dataset (22) is generated as a function of at least one data profile (A, B, C, D) which can be selectively activated and / or modified by the user and / or a control entity (12), in particular wherein the data profile is selected from a number of predetermined data profiles (A, B, C, D).Method according to claim 20, wherein the data profile (A, B, C, D) defines a subset of the usage data (14) on which the generation of the risk dataset (22) is based.Method according to at least one of the preceding claims, wherein the risk dataset (22, 28, 34) is evaluated using previously provided risk datasets in order to add information about a change in the risk risk dataset (22, 28, 34).Method according to at least one of the preceding claims, wherein parts of the usage data (14) and / or the risk data record (22, 28, 34) are compared with a plurality of predetermined usage and / or risk data records (22, 28, 34) which are stored in a database.Method according to at least one of the preceding claims, wherein an intervention data record (24, 38) is provided at the user terminal (E1), in particular wherein the intervention data record (24, 38) has at least one control command for the user terminal (E1).Method for data-controlled risk risk control, comprising at least the following steps: - receiving a risk data record (22, 28, 34) which represents a risk of risk for a user of a user terminal (E1) on the basis of usage data (14) of the user terminal (E1); - generating an intervention data record (24, 38) on the basis of the risk data record (22, 28, 34), wherein the intervention data record (24, 38) has at least one control command (36) for the user terminal (E1), in particular wherein the intervention data record (24, 38) is provided at the user terminal (E1).Method for data-controlled risk risk monitoring, comprising at least the following steps: - receiving a first risk data record (22) representing a risk for a user of a user terminal (E1) on the basis of usage data (14) of the user terminal (E1); - generating a second risk data record (28, 34) on the basis of the first risk data record (22), wherein the second risk data record (28, 34) contains at least parts of the first risk data record (22) and data for processing the first risk data record (22); - providing the second risk data record (28, 34) at a control entity (12) and / or an inspection entity (30).Method according to claim 26, wherein an intervention data record (24, 38) and / or a survey data record (32) is generated on the basis of the second risk data record (28, 34), wherein the intervention data record (24, 38) has at least one control command (36) for the user terminal (E1), in particular wherein the intervention data record (24, 38) is provided at the user terminal (E1) and / or a central server (S).A computer program for data-controlled risk risk control comprising instructions which, when executed by a computer, cause the computer to carry out the steps of a method according to any one of the preceding claims.Device for data-controlled risk risk control, wherein the device is connected to at least one data processing means and a nonvolatile memory in which at least one computer program is stored, wherein the computer program comprises instructions which, when executed by the at least one data processing means, cause the latter to carry out the steps of a method according to one of Claims 1 to 27.

Citation Information

Patent Citations

  • Systems and methods for monitoring communications

    US20120196629A1

  • Devices and methods for improving web safety and deterrence of cyberbullying

    US20150180746A1

  • Application download notification in hierarchical groups of consumer users of mobile devices

    US20160119764A1

  • Supervising user interaction with online services

    US7640336B1