Apparatus, system and method for providing personalized privacy information extraction

The system addresses the limitations of existing privacy assistants by extracting and personalizing privacy information from multiple sources, enabling users to understand and act on privacy controls effectively.

JP7779817B2Active Publication Date: 2025-12-03KDDI CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022153261
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-09-27
Publication Date
2025-12-03
Estimated Expiration
2042-09-27

AI Technical Summary

Technical Problem

Existing privacy assistant technologies do not provide users with comprehensive information on why privacy controls are necessary and how to change them, and they lack consideration of additional information sources beyond user opinions.

Method used

A system comprising an analysis module that extracts classified privacy information from various documents, generates user profiles based on user data, and constructs personalized privacy information extracts, providing users with actionable recommendations.

Benefits of technology

Enables users to receive personalized privacy-related information, enhancing their understanding and enabling them to make informed decisions on privacy-related information, regardless of their knowledge level, thus promoting secure use of information services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007779817000001
    Figure 0007779817000001
  • Figure 0007779817000002
    Figure 0007779817000002
Patent Text Reader

Abstract

To provide users with personalized privacy-related information and information about privacy control methods in a unified manner.SOLUTION: In an information processing system, an analysis module 1 as a privacy information analysis device comprises a first database, a profile generation part, a profile analysis part, and a second database. The first database stores classified privacy information. The profile generation part receives user data from a plurality of users and generates a plurality of user profiles based upon the user data. The profile analysis part associates the user profiles with the classified privacy information to analyze privacy information of each user profile and its priority level. The second database stores the results of the analysis by the profile analysis part.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information providing device, an information providing system, and an information providing method for providing a personalized privacy information extract for each user, where the extract is privacy setting information recommended for each individual user. [Background technology]

[0002] Conventionally, as a technique for providing personalized privacy information, for example, the technique disclosed in Non-Patent Document 1 and the technique disclosed in Non-Patent Document 2 have been proposed.

[0003] The technology of Non-Patent Document 1 proposes a personalized privacy assistant for mobile devices, which provides users with recommendations for privacy controls for applications on the mobile device.

[0004] In the technology of Non-Patent Document 1, the recommendation of the privacy assistant is based on the user's privacy profile, which is obtained in advance by analyzing how a sample user sets their privacy controls during actual use. When a new user uses the Privacy Assistant, they first need to answer questions about their privacy control preferences. Based on their answers, the new user is then categorized into one of several privacy profiles. The personalized Privacy Assistant then recommends that the new user set specific privacy controls according to their privacy profile.

[0005] The technology in Non-Patent Document 2 proposes an automated system for extracting personalized privacy policies according to a user's privacy concern profile.

[0006] The automated system in Non-Patent Document 2 includes a user privacy concern profile generation module and a privacy policy extraction module. The user privacy concern profile is obtained by analyzing sample user responses to questions about the privacy aspects of mobile applications that users are most concerned about. The privacy policy extraction module analyzes privacy policies according to privacy aspects. When new users join the system, they must first answer the same questions, and the system will classify them into a privacy concern profile and display an extract of the privacy policy corresponding to that profile and the corresponding regulatory clauses on which that privacy aspect is based. [Prior art documents] [Non-patent literature]

[0007] [Non-Patent Document 1] Bin Liu, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Zhang, Norman Sadeh, Alessandro Acquisti and Yuvraj Agarwal, “Follow My Recommendations: A Personalized Privacy Assistant for Mobile App Permissions”, Proceedings of the Twelfth Symposium on Usable Privacy and Security (SOUPS 2016), June 22-24, 2016, pp.27-41.

[0008] [Non-patent document 2] Cheng Chang, Huaxin Li, Yichi Zhang, Suguo Du, Hui Cao and Haojin Zhu, “Automated and Personalized Privacy Policy Extraction under GDPR Consideration”, International Conference on Wireless Algorithms, Systems, and Applications (WASA 2019), June 24, 2019, pp.43-54. Summary of the Invention [Problem to be solved by the invention]

[0009] In the technology of Non-Patent Document 1, the privacy assistant provides the user with personalized options for privacy control, but does not provide information about why these privacy controls are necessary for the application.

[0010] In the technology of Non-Patent Document 2, the automated system provides users with personalized extracts of privacy policies, but does not provide information on how to change any privacy controls if they find something in the privacy policy that they do not agree with. Furthermore, although the technology in Non-Patent Document 2 uses only privacy policies as information sources, other documents (for example, the FAQ section of a website) may also contain privacy-related information.

[0011] Furthermore, the techniques in Non-Patent Document 1 and Non-Patent Document 2 only consider personalization based on users' opinions regarding specific privacy controls and practices. However, since users may not have sufficient knowledge about these topics, additional information needs to be considered.

[0012] Therefore, an object of the present invention is to analyze a user's privacy-related profile and provide privacy-related information extraction corresponding to the profile. [Means for solving the problem]

[0013] The privacy information analysis device (e.g., "analysis module 1" described later) according to the present invention includes a first database (e.g., "database 3" described later) that stores classified privacy information, a profile generation unit (e.g., "profile generation unit 6" described later) that receives user data from multiple users and generates multiple user profiles based on the user data, a profile analysis unit (e.g., "profile analysis unit 7" described later) that analyzes the privacy information for each user profile and the priority of that information by associating the user profiles with the classified privacy information, and a second database (e.g., "database 8" described later) that stores the results of the analysis by the profile analysis unit.

[0014] Furthermore, the privacy setting information providing device (for example, the "information providing module 2" described later) according to the present invention includes a profile classification unit (for example, the "profile classification unit 9" described later) that receives user data from individual users to whom a personalized privacy information extract is to be provided and classifies the individual users into one of the pre-generated user profiles, and a privacy information construction unit (for example, the "privacy information construction unit 10" described later) that constructs a privacy information extract using the classification results of the profile classification unit and the privacy information for each profile that has been generated and stored in advance and the priority of that information.

[0015] The information providing system according to the present invention also includes a privacy information analysis device comprising: a first database that stores classified privacy information; a profile generation unit that receives user data from a plurality of users and generates a plurality of user profiles based on the user data; a profile analysis unit that analyzes the privacy information for each user profile and the priority of that information by associating the user profiles with the classified privacy information; and a second database that stores the results of the analysis by the profile analysis unit; and a privacy setting information providing device comprising: a profile classification unit that receives user data from individual users to whom a personalized privacy information extract is to be provided and classifies the individual users into one of the user profiles generated by the profile generation unit of the privacy information analysis device; and a privacy information construction unit that constructs a privacy information extract using the classification results of the profile classification unit and the privacy information for each profile and the priority of that information stored in the second database of the privacy information analysis device.

[0016] The constructed privacy information extract may be provided to the individual user, and the individual user's selection based on the provided extract may be fed back to change the association between the user profile and the privacy information.

[0017] Furthermore, the information providing method of the present invention includes a step of storing classified privacy information in a first database, a profile generation step of receiving user data from a plurality of users and generating a plurality of user profiles based on the user data, a profile analysis step of analyzing the privacy information for each user profile and the priority of that information by correlating the user profiles with the classified privacy information, a step of storing the results of the analysis by the profile analysis unit in a second database, a profile classification step of receiving user data from individual users to whom a personalized privacy information extract is to be provided and classifying the individual users into one of the user profiles generated by the profile generation step, and a privacy information construction step of constructing a privacy information extract using the results of the classification in the profile classification step and the privacy information for each profile and the priority of that information stored in the second database.

[0018] The steps of the information providing method may be executed by a computer using a program. [Effects of the Invention]

[0019] According to the present invention, personalized privacy-related information and information on privacy control methods can be provided to users in a unified manner. Furthermore, personalized information can be provided to users regardless of whether they have knowledge of privacy measures. [Brief explanation of the drawings]

[0020] [Figure 1] 1 is a diagram illustrating an example of a configuration of an information providing system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram showing a processing flow in the information providing system according to the embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0021] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. The information providing system of the embodiment shown in Fig. 1 is composed of an analysis module and an information providing module, in which 1 represents the analysis module and 2 represents the information providing module.

[0022] As shown in FIG. 1, the analysis module 1 includes a database 3 of classified privacy information, a profile generation unit 6, a profile analysis unit 7, and a database 8 of privacy information and priority for each profile.

[0023] The analysis module 1 extracts classified privacy information to create a database of classified privacy information 3. Specifically, the classified privacy information is extracted from all documents 4 containing privacy-related information of an information service (e.g., a website) and information 5 about the location of privacy controls.

[0024] For example, the homepage of a typical website contains sections such as "About us," "Privacy Policy," and "Help," and the "Help" section often contains subsections such as "FAQ" and "Privacy Control Manual." The text contained in these sections and subsections is an example of a privacy information document 4 and privacy control information 5.

[0025] The information in each section is categorized with one or more labels corresponding to general privacy aspects (e.g., "Data Permissions"), specific privacy aspects (e.g., "Location Permissions"), and usability / content (e.g., "Readability," "General Description," "Technical Description," etc.) This categorization is explained in more detail below.

[0026] For example, suppose the "About Us" section of a travel information website contains the following statement: "Our commitment to privacy: Your privacy is important to us. That's why we don't share your data with advertisers, police, or insurance companies. You always decide when and where to share your data." In this case, this document (sentence) can be given the label "Sharing" as a "Data" label and the label "Easy" as a "Readability" label.

[0027] Also, suppose the "Privacy Policy" section contains the following sentence: "This site collects your location data to provide accurate and timely information to your friends and family and / or to provide travel-related features, such as trip start date / time, trip end date / time, estimated arrival date / time, live location during your trip, nearby alert information, and emergency live location." In this case, this document (sentence) can be given the labels "Location Information" and "Purpose" as "Data" labels, and the label "Medium" as "Readability."

[0028] Also, suppose the "Help" section contains the following sentence: "If you want to see your trip information again, simply turn off the 'Hide' option. All previous access permissions will be restored without you having to set them up again." In this case, this document (sentence) can be given the labels "Location" and "Sharing" as "Settings" labels and a "Medium" readability label.

[0029] Also, suppose the "Help" section contains the following sentence: "It's also important to note that we only access your location while you're traveling, and not at other times. When onboard sensors detect movement, a GPS location request is sent to your phone." In this case, this document (sentence) can be given the "Data" labels "Location" and "Purpose Restrictions" and the "Readability" label "Easy."

[0030] Furthermore, suppose the "Help" section contains the sentence "Smartphone: Location services must be turned on (OS Settings -> Privacy -> Location Services)." In this case, this document (sentence) can be given the labels "Location" and "Access" as "Settings" labels.

[0031] As described above, the analysis module 1 creates a database 3 of classified privacy information by classifying labeled documents with the labels.

[0032] User data is input to the profile generation unit 6. In this case, it is preferable to collect user data from a plurality of users necessary to generate a sufficient number of profiles, and input the collected data to the profile generation unit 6.

[0033] The user data includes at least information about the user's general personality, knowledge and experience regarding privacy, awareness of privacy, preferences regarding privacy measures, etc. This information can be obtained from responses to a questionnaire given to the user.

[0034] The Profile Generator 6 receives the user data described above and uses it to generate user profiles, which are groups of users with similar characteristics into profiles defined in terms of privacy needs and personality.

[0035] The user profile is used by the profile analysis unit 7 to analyze the privacy information appropriate for the profiled user (i.e., the privacy information for each profile) and the priority of that information. This analysis process is performed by analyzing the privacy information of the information service, generating privacy information categories, and analyzing which privacy information categories are appropriate for the user profile and in what order of priority.

[0036] More specifically, this is done by mapping user profiles to categorized privacy information extracted from database 3 based on privacy needs (mapping to privacy aspects) and personality (mapping to usability / content).

[0037] Note that the mapping is many-to-many, i.e., a user profile can be mapped to multiple privacy information extracts and vice versa, and a priority of information extracts for user profiles can also be set.

[0038] As a result of the analysis in the profile analysis unit 7, the process of creating a user profile, and the privacy information extract (information recommended for each individual user) and its priority order for each user profile are obtained. The extracted portion of the privacy information for each user profile and its priority are stored in the database 8.

[0039] Next, the information providing module 2 will be described. As shown in FIG. 1, the information providing module 2 includes a profile classification unit 9 and a privacy information construction unit 10.

[0040] The profile classifier 9 receives user data from new users (individual users) for whom a personalized privacy information extract is to be provided. Here, the user data that is input information to the profile classification unit 9 is basically the same as the user data received by the profile generation unit 6 of the analysis module 1, and includes at least information such as the user's general personality, knowledge and experience regarding privacy, awareness of privacy, and preferences regarding privacy measures. Note that this information can be obtained from the responses to a questionnaire administered to individual users who are to receive personalized privacy information extracts.

[0041] The profile classification unit 9 receives the user data and uses it to classify the user into one of the profiles generated by the profile generation unit 6 of the analysis module 1. Once the classification result, i.e., the user profile, is determined, the determined user profile is sent to the privacy information construction unit 10.

[0042] When the privacy information construction unit 10 receives a user profile from the profile classification unit 9, it obtains the privacy information and priority information for each profile from the database 8 of the analysis module 1, and constructs recommended privacy setting information for each individual user, i.e., a privacy information extract, using the received user profile and the obtained information. The construction of this privacy information extract will be described in more detail below.

[0043] Let us take the example of the travel information website mentioned above. Assume that the profile classification unit 6 classifies an individual user to whom a personalized privacy information extract is to be provided into a user profile that is concerned about providing location information and has little interest in reading long texts. In this case, the privacy information construction unit 10 constructs the following information as a constructed privacy information extract for the individual user: "Regarding location information, 'It is also important that we only access your location information when you are traveling, and not at other times'. The settings can be found in 'OS Settings -> Privacy -> Location Information Services'. Click here for more information about location information."

[0044] In addition, in the constructed extract, the privacy information construction unit 10 gives a high priority to the information "Regarding location information, 'It is also important that we only access location information while you are traveling, and not at other times'" and gives a low priority to the link information "For more information about location information, click here."

[0045] The constructed privacy information extract is then interactively provided (e.g., displayed on a display device) to an individual user, allowing the user to access more information or follow instructions to change their privacy controls.

[0046] If, after viewing the privacy information extract, the user takes one of the above actions (i.e., accessing more information or changing privacy controls), that choice is used as additional input to the analysis module 1, which can help improve the mapping between user profiles and privacy information.

[0047] Fig. 2 is a diagram showing the processing flow in the system of the embodiment. Although Fig. 2 shows a single flow, the processing from step S101 to step S105 is first performed to create a database of classified privacy information, generate a sufficient number of user profiles, and create a database of privacy information and priority for each profile. After that, the processing from step S101 to step S105 (i.e., the processing performed by analysis module 1) and the processing from step S106 to step S110 (i.e., the processing performed by information provision module 2) can be performed in parallel.

[0048] Furthermore, with this invention, for example, users can receive personalized privacy information regardless of whether they have knowledge of privacy measures, thereby enabling them to use information services safely and securely, which will make it possible to contribute to Goal 4-4 of the United Nations-led Sustainable Development Goals (SDGs) - "By 2030, increase the number of young people and adults with work-related skills and capabilities to find decent work and start new businesses." [Explanation of symbols]

[0049] 1. Analysis Module 2 Information provision module 3. Database storing classified privacy information 4 Privacy Information Document 5. Privacy Control Information 6 Profile Generation Unit 7 Profile Analysis Section 8. Database storing privacy information and priorities for each profile 9 Profile Classification Section 10 Privacy Information Construction Department 11 Constructed Privacy Information Extract

Claims

1. A first database that stores classified privacy information; a profile generator that receives user data from a plurality of users and generates a plurality of user profiles based on the user data; a profile analysis unit that associates the user profile with the classified privacy information, thereby analyzing the privacy information for each user profile and the priority of the information; a second database for storing the results of the analysis by the profile analysis unit; a privacy information analysis device comprising: a profile classification unit that receives user data from an individual user who is to be provided with a personalized privacy information extract, and classifies the individual user into one of the user profiles generated by the profile generation unit of the privacy information analysis device; a privacy information construction unit that constructs a privacy information extract using the classification result of the profile classification unit and the privacy information for each profile and the priority of the information stored in a second database of the privacy information analysis device, and provides the constructed privacy information extract to the individual user; a privacy setting information providing device comprising: Including, An information provision system in which the profile analysis unit of the privacy information analysis device further changes the association between the user profile and the privacy information when the selection of the individual user who has received the privacy information extract is fed back.

2. A computer, storing the classified privacy information in a first database; a profile generation step of receiving user data from a plurality of users and generating a plurality of user profiles based on the user data; a profile analysis step of associating the user profile with the classified privacy information to analyze the privacy information for each user profile and the priority of the information; storing the results of the analysis in the profile analysis step in a second database; a profile classification step of receiving user data from an individual user to whom a personalized privacy information extract is to be provided, and classifying the individual user into one of the user profiles generated by the profile generation step; a privacy information construction step of constructing a privacy information extract using the results of the classification in the profile classification step, and the privacy information for each profile stored in the second database and the priority of the information, and providing the constructed privacy information extract to the individual user; Execute The profile analysis step further includes changing the association between the user profile and the privacy information when feedback is received from the selection of the individual user who has received the privacy information extract.

Citation Information

Patent Citations

  • Information processor and information processing method

    JP2004021923A

  • Safe Logon

    US20220060466A1

  • Information processing system that analyzes personal information, and method for analyzing personal information

    WO2014073214A1