Data-driven threat risk control

A data-driven method generates a compact risk data set from smartphone usage, addressing inefficiencies in existing monitoring methods by enabling automated and privacy-respecting hazard risk assessment, facilitating timely risk identification for vulnerable users.

WO2025162962A1PCT designated stage Publication Date: 2025-08-07DIE KAISER GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/052183
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-29
Filing Date
2025-01-29
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing methods for monitoring smartphone usage by parents are inefficient, violate user privacy, and are difficult to implement due to the vast amount of data involved, making it challenging to identify and mitigate potential hazards faced by vulnerable users such as children.

Method used

A data-driven method for hazard risk control that generates a compact risk data set based on user terminal usage data, allowing automated and personalized risk assessment without direct access to sensitive information, enabling efficient and reliable monitoring through a risk data set that can be transmitted and processed independently of the user's device.

Benefits of technology

Enables efficient and reliable hazard risk monitoring for vulnerable users by minimizing privacy violations and optimizing data transmission, allowing parents to support their children's digital development while identifying risks promptly and effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025052183_07082025_PF_FP_ABST
    Figure EP2025052183_07082025_PF_FP_ABST
Patent Text Reader

Abstract

A method for data-driven threat risk control comprises at least the following steps: detecting usage data (14) of a user terminal (E1); and generating at least one risk data record (22, 28, 34) on the basis of the usage data (14), the at least one risk data record (22, 28, 34) representing a threat risk for a user of the user terminal (E1).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Data-driven hazard risk control

[0002] The present invention relates to methods, computer programs and devices for data-driven control of hazard risks for users of terminal devices.

[0003] Smartphones and similar mobile devices offer their users communication channels that, in terms of flexibility, scope, and speed, are unprecedented in human history and are generally considered a major advance. However, the exchange of all kinds of media content also creates a variety of risks for users. These risks are particularly acute for vulnerable users, such as children and young people, because smartphones are becoming increasingly widespread and generally accepted among these user groups.

[0004] The risks can be health-related, for example, in the form of stress, psychological addiction, or even physical harm that occurs as a result of use. For example, physical and psychological violence are typically closely linked to communication via smartphones.

[0005] The risks can also be of a legal nature and concern, for example, the violation of personal rights associated with the use of smartphones. Furthermore, the smartphone today is also a gateway for unwanted interference with the user's personal development. This can be characterized, for example, by extreme political positions, discriminatory behavior, or attempted fraud, and can sometimes have criminal relevance. Beyond the role of victim, it must be considered that the smartphone today also represents an important tool for the emergence and development of risks of danger. The risks of danger have increased due to the virtually unlimited number of communication partners. However, these communication partners include not only trusted friends, but also casual acquaintances or organizations that may pursue commercial or fraudulent intentions.

[0006] The risks are particularly serious for children and young people, as they generally do not yet have a fully developed awareness of the risks. According to data from the Federal Statistical Office, an estimated 95 percent of 13- to 15-year-old children, 86 percent of 10- to 12-year-old children, and 21.6 percent of 6- to 9-year-old children in Germany own a smartphone.

[0007] It is becoming increasingly difficult for parents responsible for their children to adequately fulfill their protective role. Due to the diverse communication capabilities of modern smartphones, it has become virtually impossible to reliably and promptly identify potential threats. In addition to the practical problems associated with monitoring extensive and constantly changing usage data, content review is also problematic because it violates the right to privacy of the person being protected. This also applies to parents who wish to monitor their child's usage data for risk assessment purposes. Further problems arise from the fact that usage time is restricted during a personal review.

[0008] It is an object of the invention to provide a method for efficient, reliable and data protection-oriented hazard risk control.

[0009] The task is solved by a method for data-driven

[0010] Hazard risk control comprising at least the following steps: collecting usage data of a user terminal; and generating a risk data set based on the usage data, wherein the risk data set represents a hazard risk for a user of the user terminal.

[0011] One of the advantages of this procedure is that direct disclosure of usage data for monitoring purposes is not necessary. Instead, the automated or personalized assessment of hazard risks can be performed using a risk dataset generated based on the usage data, i.e., data-driven, enabling efficient and reliable hazard risk monitoring.

[0012] In particular, the risk data set can be flexibly transmitted electronically between different communication devices. This advantageously allows risk control to be carried out independently of the user's device, both spatially and temporally. However, the transmission of sensitive and extensive usage data can be dispensed with.

[0013] Furthermore, one or more control persons can be advantageously involved in hazard risk control without having to grant these persons direct and uncontrolled access to the usage data. The usage data is therefore specifically used for data-driven hazard control, but otherwise protected from third-party access.

[0014] Thus, the method according to the invention allows, on the one hand, the hazard risks identified based on the usage data to be efficiently and reliably recorded and controlled. On the other hand, the scope of control itself can also be better managed and controlled. In particular, indirect access to the usage data can be controlled via the risk data set in order to implement data access control for one or more control persons.

[0015] A particular advantage of the method is that it can be carried out quickly and reliably using powerful data processing tools. This applies even to large amounts of data, including text, audio, image, and video signals, which are exchanged, i.e., received, processed, generated, and / or sent, via a respective user terminal.

[0016] With the method according to the invention, it is not necessary for a control person to fully analyze the content of the usage data and thereby violate the privacy of the user.

[0017] The method according to the invention is particularly suitable for parents who want to support their child's digital development in a constructive and educationally valuable way. It also opens up new ways to understand the digital world from the perspective of vulnerable individuals and to identify risks in a timely manner without violating their privacy.

[0018] Embodiments of the invention are disclosed in the claims, the description and the figures.

[0019] According to one embodiment, the risk data set is provided to a control authority, which has at least one data processing device, e.g., a control terminal and / or a central server, for further implementation of hazard risk control. One or more control personnel can also be assigned to the control authority, who receive risk data sets via respective control terminals and / or transmit control commands to reduce hazard risks. The control authority generally serves to assess the risk data set and, if necessary, initiate measures to reduce the hazard risk.

[0020] The risk data set can be transmitted and processed in various ways. For example, the risk data set can first be made available to a central server, which evaluates the risk data set using a computer-implemented control rule. The risk data set can then be forwarded to a predetermined control device assigned to a control person (e.g., a parent). Forwarding to multiple control devices, e.g., assigned to multiple caregivers, is also conceivable. Alternatively, a respective risk data set can also be transmitted directly from the user device to be controlled to one or more control devices.

[0021] The controller can review the content of the risk data record and decide whether action is required and, if necessary, whether measures to reduce the risk should be initiated. Such measures can also be implemented data-driven, for example, by generating and transmitting warning or control data records to the user terminal. A central server can participate in this process by generating an intervention data record adapted to the user terminal for a control data record received from the controller terminal. The intervention data record preferably contains technical implementation data required for implementing the control data record on the user terminal.

[0022] According to another embodiment, a risk data set can also be provided on the user's device. This is particularly useful for self-monitoring by the user. The user may be interested in being informed of hazard risks based on the risk data set and, if necessary, mitigating their own risks. Furthermore, the user can monitor whether and to what extent risk data is being transferred from their own device. The user is thus not merely a passive control subject, but can be actively involved in hazard risk monitoring. The frequency with which risk data sets are transmitted to the control authority can be reduced with additional self-monitoring.

[0023] Hazard control can be carried out particularly efficiently from a distance if the risk data set is compact compared to the usage data and can therefore be transmitted at high speed. This is based on the realization that only a small portion of the usage data contains risk data associated with one or more hazards. However, it is unlikely that all usage data poses hazard risks.

[0024] According to a further embodiment, the usage data is at least substantially not included in the risk dataset. For example, the size of the risk dataset is less than 5 percent of the size of the usage data, preferably less than 1 percent. This enables efficient transmission and processing of the risk dataset. Furthermore, usage data that is irrelevant for assessing the hazard risk need not be included in the risk dataset.

[0025] Preferably, the risk dataset contains no usage data at all, but only information about the usage-related hazard risks. Therefore, the risk dataset preferably does not allow direct insight into the usage data itself. However, it is possible to include one or more selected usage data elements in the risk dataset that demonstrate a hazard risk and / or allow the controller to more precisely assess the specific hazard risk. However, even in this case, comprehensive insight into the usage data is avoided. This can be achieved by not including any data context in the risk dataset for the selected usage data elements.

[0026] According to a further embodiment, the risk data record is generated using at least one data processing means of the user terminal. In this case, transmission of the usage data to a server or another device is dispensed with. Furthermore, the user can optionally suspend the hazard risk control by switching off the terminal. In this way, the hazard risk control is dependent on active use of the terminal.

[0027] According to a further embodiment, at least one risk class is determined for the risk data set, representing a hazard type for at least part of the usage data. This risk class enables a particularly efficient assessment of the hazard risk. Furthermore, the risk data sets can be designed to be particularly compact in order to conserve transmission resources and ensure reliable transmission even in areas with poor network coverage.

[0028] Risk classes can be used, for example, to distinguish between passive and active hazards. Furthermore, it is possible to distinguish between physical hazards and psychological hazards at the risk data set level by grouping these hazard types into risk classes. According to a further embodiment, at least one risk level is determined for the risk data set, representing a hazard intensity for at least part of the usage data. The risk level can be viewed as the urgency of reviewing the hazard and taking countermeasures. The risk level can be expressed, for example, on a numerical scale, which enables intuitive assessment by a controller and, advantageously, machine-assisted analyses.

[0029] Preferably, at least one element of the risk data set is defined with reference to a multi-level reference designed to assess a relative risk of danger. The reference can, for example, have at least three levels. An example of such a reference is the school grading scale with the integer levels 1 to 6. Each level can be assigned a risk level, for example, such that a risk level of 1 indicates a very low risk of danger, while a risk level of 6 indicates a possible criminal offense. Intermediate risk levels can represent graduated risks of danger, whereby it is at the discretion of the controller when and how to respond to the indicated risk of danger.

[0030] According to a further embodiment, the risk data set comprises a plurality of elements that are assigned to different parts of the usage data and represent a respective hazard risk. For example, a first element of the risk data set can be assigned to a first part of the usage data, with a second element of the risk data set being assigned to a second part of the usage data that is different from the first part of the usage data. In this way, the risk data set enables differentiation within the usage data, which can be composed of a wide variety of data types and / or data sources. The elements of the risk data set can, in particular, be assigned to different applications of the terminal device. The "virtual location" of a detected hazard risk can therefore be quickly identified. The hazard risk can also advantageously be prioritized based on the application.Preferably, the elements are formed by respective numerical values.

[0031] Another possibility is to assign at least some of the multiple elements of the risk data set to different communication partners of the user. The communication partners can be real or virtual persons, organizations, or providers with whom the user is in contact, as evidenced by the usage data.

[0032] For efficient processing of a risk data set with multiple elements, it is advantageous to combine them into an overview element. The overview element represents a summarized hazard risk for several pieces of usage data. The hazard risk assessment can thus be carried out in a structured manner, particularly hierarchically. Using the overview element, the controller can first determine the hazard situation across all pieces of usage data used. In a second step, the controller can use the individual elements to determine whether a particular hazard situation exists for a specific component of the usage data and, if necessary, whether measures to reduce the hazard risk should be considered.

[0033] The overview element preferably comprises a numerical value representing a mean or an extreme value of the multiple elements. According to a further embodiment, the risk data set represents a technical usage behavior on the user terminal.

[0034] For example, the risk dataset may contain information about at least one of the following aspects that can be traced back to technical usage behavior: usage times and / or usage durations; number of input commands by the user; number of activated applications; number of websites accessed;

[0035] Position data of the device; operating data of the device. This data may form part of the usage data.

[0036] Technical usage behavior is relatively easy to capture on the device by using the already recorded control commands as usage data for generating the risk dataset. Furthermore, technical usage behavior generally does not allow for direct conclusions about the data content. Data protection aspects can therefore be particularly well considered, if desired, if the risk dataset is based exclusively on technical usage data. Compared to other usage data, such as high-resolution image data, technical usage data is very compact and therefore particularly suitable for the rapid generation and transmission of risk datasets.

[0037] According to a further embodiment, the risk data set represents the user's content-related usage behavior. For example, the risk data set can include information about at least one of the following usage data types: text, image, video, and / or audio data entered and / or received on the user terminal; a function type of an activated and / or installed application on the user terminal, e.g., to distinguish between social media apps, dating apps, shopping apps, gaming apps, etc. Content-related usage data can also contain characteristics of one or more communication partners, in particular interests, e.g., in commercial and / or political terms.

[0038] The risks posed by modern communication media can be very diverse. Examples of risks include potential criminal offenses, addictive behavior, discrimination, discrediting, bullying, political extremism, pornography, abuse, dealing with false digital identities and organizations ("fake accounts"), and purchasing restricted goods, e.g.

[0039] Medicines, alcohol, and other drugs. Such risks can be captured through content usage data.

[0040] Preferably, the risk data set is generated based on a predetermined data processing rule that can be modified by a control authority and / or the user. However, different modification rights can be provided for the control authority and the user. Modification can also be completely excluded for the user.

[0041] The data processing rule preferably defines the scope and depth of the hazard risk control. For example, adjustments can be made to adapt the risk data sets to be generated to the control requirements. For example, it can be configured whether, and if so, which parts of the usage data should be included in a risk data set to better assess hazard risks. Parts of the usage data associated with a negligible risk can also be completely excluded from processing. The data processing rule can optionally also contain a parameter that controls the frequency with which a risk data set should be generated. The data processing rule is preferably computer-implemented and, in particular, includes a machine learning model.Such models have proven extremely powerful for processing complex media information and a wide variety of usage data. Nevertheless, it is possible to make these models compact enough to allow them to run on less powerful user devices. Machine-learned models are also highly adaptable to new training data. The data processing rule will be updated accordingly.

[0042] To further improve hazard risk control, it is possible to control the execution of the data processing rule from a central (control) server. However, the data processing rule is preferably stored and executed on the user device. Alternatively, at least some of the usage data can be transferred from the user device to a central server, which generates the risk dataset.

[0043] According to a further embodiment, the usage data is collected using an operating system of the user terminal. A collection application can be stored on the user terminal for this purpose.

[0044] The risk data record is optionally generated based on an active input on the user's device. This allows the user to separately activate hazard risk control, for example, by entering authentication data. Furthermore, the user can optionally be granted additional control rights, for example, by specifying one or more authorized controllers who are authorized to receive risk data records.

[0045] According to a further embodiment, the generation of the

[0046] Risk data sets and / or making them available to the control authority based on validity dates that represent a time-limited validity of the risk data sets. This prevents unnecessary transfer of outdated risk data sets.

[0047] To further improve data protection, the risk dataset can be generated in a non-storable data format. Furthermore, the risk dataset is preferably non-modifiable.

[0048] According to a further embodiment, the protection of the data is increased by providing the risk data set in encrypted form, in particular to at least one central server, the user terminal and / or at least one control terminal.

[0049] According to another embodiment, the risk data set is provided based on authorization data. For example, a recipient of the risk data set can be required to provide valid authorization data in order to receive the risk data set. This allows unauthorized control personnel to be excluded from the hazard risk control process.

[0050] Confidence in the process can be further increased by allowing the user to view the authorization data. This allows the user to get an idea of ​​who is authorized to participate in their own hazard risk assessment.

[0051] According to a further embodiment, the risk data set is generated based on at least one data profile that can be selectively activated and / or modified by the user and / or the control authority. The data profile can, for example, define a subset of the usage data that forms the basis for generating the risk data set. Alternatively or additionally, the data profile can specify which hazard information should be included in the risk data set, for example, whether the risk data set should provide information about hazards related to technical and / or content-related usage behavior.

[0052] Preferably, the data profile is selected from a number of predetermined data profiles. This simplifies the practical configuration of the hazard risk control. For example, an inspector can select a data profile on a control terminal that will serve as the basis for generating risk data records. For this purpose, a corresponding control command can be transmitted to the user terminal, which modifies the data processing rule according to the selected data profile.

[0053] According to another embodiment, the risk data set is evaluated using previously provided risk data sets. This enables an objective assessment of changes in the hazard risk. Information about a change in the hazard risk can be added to the risk data set.

[0054] According to a further embodiment, portions of the usage data are compared with a plurality of predetermined usage data sets stored in a database. The differences identified in this process can advantageously be incorporated into the generation of the risk data set, in particular to achieve greater accuracy and reliability for the risk data set. For example, a usage data set stored in the database can be representative of expected user behavior. An increased risk of danger can be assumed, in particular, if the deviations from the current usage data violate a predetermined threshold criterion. In a corresponding manner, deviations between a current risk data set and reference risk data sets stored in a database can also be determined and taken into account in the current risk data set.

[0055] According to a further embodiment, an intervention data record is provided on the user terminal. The intervention data record represents a data-driven measure for reducing the risk of danger. For example, the intervention data record can contain at least one control command for the user terminal, which is processed by the user terminal. According to the control command, it can be provided, for example, that a warning is displayed on the user terminal. This display process is preferably implemented automatically, i.e., the user is automatically informed of potential danger risks without any further action. This can be done, for example, by means of a push message to the terminal.

[0056] According to a further embodiment, the method is fully or partially computer-implemented. A distributed execution of the method steps is possible in such a way that the usage data collection, as indicated above, takes place at least partially on the user terminal, in particular using the data processing means of the terminal, such as the processor, the platform (e.g., operating system), and / or the user interface, which is preferably graphical. Usage data stored internally on the terminal, which arises, for example, through the use of installed software applications, can also be collected.

[0057] The user terminal is preferably a mobile device, e.g., a smartphone, smartwatch, tablet, laptop, or other compact data terminal. It is preferably equipped with a display device that has a graphical user interface for control, for example, in the form of a touch-sensitive display surface. A control terminal can be configured to correspond to the user terminal.

[0058] According to a further aspect, the invention relates to a second method for data-driven hazard risk control. It relates to the control entity and comprises at least the following steps: receiving a risk data record representing a hazard risk based on usage data of a user terminal; and generating at least one intervention data record based on the risk data record, wherein the intervention data record comprises at least one control command for the user terminal. The method preferably also comprises providing the intervention data record to the user terminal, e.g., by transmission from a control server or a control terminal to the user terminal.

[0059] According to a further aspect, the invention relates to a third method for data-driven hazard risk control, comprising at least the following steps: receiving a first risk data set representing a hazard risk for a user of a user terminal based on usage data of the user terminal; generating a second risk data set based on the first risk data set, wherein the second risk data set contains at least parts of the first risk data set as well as data for processing the first risk data set; and providing the second risk data set to a control authority and / or an assessment authority.

[0060] The third method can, in particular, be carried out by a central server that forwards the information of the first risk data record from the user terminal to a control terminal and supplements the first risk data record with further data that controls the further processing of the first risk data record. The forwarding can be made dependent on a prior verification of authentication data from the control terminal. The forwarding can also be made dependent on further criteria, e.g., the validity period of the first risk data record.

[0061] According to one embodiment of the third method, an intervention data set is generated based on the second risk data set. The intervention data set contains at least one control command for the user terminal and can, for example, be provided by a control terminal directly to the user terminal and / or initially to a central server, which transmits the intervention data set to the user terminal either unchanged or in a modified form.

[0062] It should be understood that the described methods can each be embodied as computer-implemented methods, i.e., all or at least some of the method steps are executed by a computer. The respective computer or computer-like unit can generally be formed by a server or a part thereof. The user terminal and any control terminal also each represent computers that can execute the assigned method steps in a computer-implemented manner.

[0063] It is also to be understood that each of the described methods can be embodied by a computer program, wherein the instructions of the computer program, when executed on a computer, cause the computer to carry out the steps of a method according to at least one of the embodiments disclosed above. A further aspect of the invention relates to a device connected to at least one electronic data processing means and a non-volatile memory. A computer program is stored in the memory, the instructions of which, when executed by the at least one data processing means, cause the data processing means to carry out the steps of a method according to at least one of the embodiments disclosed above. The device can in particular be formed by the usage or control terminal or a server.When the process steps are executed in a distributed manner on different devices, these can form a system that implements data-driven hazard risk control. In particular, a user device, a central server, and a control device can together form a control system that executes and controls the process steps.

[0064] The described methods are preferably designed to be real-time capable. For example, the time between the generation of the risk data set and its subsequent provision to the control authority can be less than 500 milliseconds. This assumes a typical data transmission speed of a mobile network.

[0065] Furthermore, it is preferred that a risk data record provided on a control terminal be displayed on the control terminal. Similarly, it is preferred that an intervention data record provided on the user terminal be displayed so that the user can be aware of it.

[0066] The features disclosed in connection with the first method, in particular in connection with the individual embodiments, can also be implemented in a corresponding manner in the second or third method. In other words, the features of the embodiments of the first method can each be implemented in a corresponding manner in the second method and / or third method.

[0067] The described aspects of the invention are described below purely by way of example with reference to the drawings, in which:

[0068] Fig. 1 shows a first diagram illustrating aspects of a method for data-driven hazard risk control;

[0069] Fig. 2 a second diagram to illustrate further aspects of hazard risk control;

[0070] Fig. 3 a third diagram to illustrate aspects of hazard risk control;

[0071] Fig. 4 shows a fourth diagram illustrating aspects of hazard risk control; and

[0072] Fig. 5 shows a diagram illustrating aspects of a risk dataset.

[0073] Functionally identical elements are marked with the same reference symbols.

[0074] A method of data-driven hazard risk control is first described with reference to Fig. 1.

[0075] The method comprises the exchange of data between a user instance 10 and a control instance 12. The user instance 10 has a user terminal E1, which is used as a means of communication by a user (not shown), in particular a minor child, at various locations without direct supervision. The user terminal E1 is connected to a public network that provides access to the Internet. A first application adapted for participation in hazard risk control is also stored on the user terminal E1.

[0076] The control unit 12 has a control terminal E2, which is used by a control person (not shown), such as a parent of the child, to monitor the child's hazard risks. A second application adapted for participation in the hazard risk monitoring is stored on the terminal E2.

[0077] The hazard risks to be monitored arise from the usage data 14 generated in connection with the use of the terminal device E1. This includes, in particular, technical usage data, such as the frequency and duration of use of the terminal device E1. In addition, the usage data 14 includes content-related usage data, such as texts exchanged via the terminal device E1.

[0078] The usage data 14 is processed using a data processing rule 20 to generate a first risk data set 22. The first risk data set 22 contains information about potential hazards for the user of the terminal device E1. Possible configurations of the risk data set 22 are described further below in connection with Fig. 5.

[0079] The data processing rule 20 is implemented by a machine-learned model, in particular by a neural network. The data processing rule 20 is stored on the user terminal E1 and is preferably executed automatically at regular intervals, i.e., without any separate input from the user of the terminal E1. Optionally, however, it can be provided that the user must separately activate the data processing rule 20. For this purpose, the user can enter input data 16 on the terminal E1 to enable the data processing rule 20 and / or the associated first application on the terminal E1.

[0080] The risk data set 22 generated by the data processing rule 20 is made available to the control entity 12 by being transmitted electronically from the user entity 10 to the control entity 12 via a communication link (not shown in detail). The transmission is carried out, in particular, using private and / or public data transmission networks, e.g., by encrypted transmission over the Internet. In this way, the user entity 10 and the control entity 12 can be located at a greater spatial distance from each other, so that the user and a control person can move spatially independently of each other.

[0081] The risk data set 22 can be transmitted, for example, in the form of an email or a push message to the control terminal E2, where it can be processed and displayed by the second application. The second application can be automatically activated in response to the receipt of a risk data set 22 to display the hazards contained in the risk data set 22 to the control person.

[0082] In addition to or as an alternative to automatic activation, the controller may selectively activate the hazard risk control application, in particular by entering input data 26.

[0083] In general, the receipt and processing of a respective risk data set 22 is controlled by a control rule 18. According to control rule 18, for example, access to risk data set 22 is only possible after prior entry of authentication data. The authentication data is contained in input data 26.

[0084] After receiving and displaying the risk data set 22, the control authority 12 has information that enables an assessment of the hazard risks without disclosing or transmitting the usage data 14. Violations of the user's personal rights are accordingly minimized. Furthermore, the usage time for the terminal device E1 is maximized because the control authority does not have to operate the terminal device E1 to check the usage data 14. A respective risk data set 22 is thus generated and transmitted to the control authority 12 essentially independently of the current use of the terminal device E1. For this purpose, the first application can run in the background of other applications used on the terminal device E1.

[0085] However, the usage data 14 is not transmitted to the control instance 12. The data transmission resources of the usage instance 10 and the control instance 12 are accordingly conserved, particularly with regard to the data volume quotas of the terminal devices E1 and E2.

[0086] After the control entity 12 has assessed the hazard risk based on the first risk data set 22, an intervention data set 24 can optionally be generated and transmitted to the user entity 10. The intervention data set 24 preferably includes at least one warning message, which is displayed on the user terminal E1 and informs about current hazard risks. If the control entity 12 does not identify any relevant hazard risks, preferably no intervention data set 24 is transmitted to the terminal E1. Possible extensions and modifications of the method of Fig. 1 are described with reference to Fig. 2.

[0087] In addition to instances 10 and 12 of Fig. 1, an assessment instance 30 is provided according to Fig. 2, which further develops the data-driven hazard risk control. The assessment instance 30 comprises, in particular, a central control server (not shown), which receives a second risk data set 28 from the usage instance 12 and evaluates it.

[0088] The second risk data record 28 comprises the first risk data record 22 as well as further information added by the control authority 12, e.g. proof of authorization.

[0089] For the evaluation of the second risk data set 28, risk data sets previously provided to the control authority 12 are preferably used, which provide information on changes in the hazard risk.

[0090] The second risk data set 28 preferably includes instructions from a control person for the assessment of the first risk data set 22 and / or authorization data. This data can be part of the input data 26 and, for example, contain a request for a machine-assisted assessment of hazard risks by the assessment authority 30. Alternatively or additionally, the second risk data set 28 can include a request to forward the risk data set 28 to an assessment body to which a trained person is assigned to assess hazard risks. For example, the assessment body can be commissioned to assess any criminal relevance of hazard offenses. In response to receiving the second risk data set 28, the assessment authority 30 generates an assessment data set 32, which is transmitted to the control authority 12.The assessment data set 32 ​​contains the result of the machine-assisted and / or assessment by the assessment body of the second risk data set 28. The control body 12 can use the assessment data set 32 ​​as an alternative or in addition to its own assessment of the risk data set 22 to decide on possible measures to reduce the hazard risks. In this way, one or more control personnel of the control body 12 can be supported in the hazard risk control process.

[0091] The support provided by the assessment body 30 can be limited by an inspector, in particular, to cases in which the inspector cannot perform the hazard risk assessment themselves or wishes to reduce their own risk of making an incorrect assessment. For this purpose, the second risk data set 28 is transferred to the assessment body 30 based on the input data 26.

[0092] The control instance 12 can comprise a server (not shown) that supports the control person in the sense of machine-assisted, automated hazard risk control. In particular, a respective intervention data record 24 can also be transmitted to the user instance 10 without direct instigation by a control person. This is useful, for example, if a respective control person is unavailable or the control terminal E2 is not switched on. In such a case, the user can still be protected by having a respective intervention data record 24 generated by the server and transmitted to the user terminal E1. Further modification options for hazard risk control are described below with reference to Fig. 3.

[0093] In contrast to Figs. 1 and 2, Fig. 3 highlights that the first risk data set 22 can be generated using data profiles A, B, C, or D. The data profiles allow for limiting the hazard risk control to specific types of usage data. They can be configured as follows.

[0094] Command data profile A is adapted to base the detection of threat risks on the user's command data. Command data includes, in particular, usage data 14 that represents technical usage behavior and, for example, indicates the number of commands entered on the user terminal E1, websites accessed, or applications accessed. The command data can be completely independent of the content processed in connection with the entered commands. The command data is therefore comparatively compact in scope and allows for a high degree of data protection.

[0095] If content data profile B is selected, the threat risk control extends to the content of the usage data 14. This includes, in particular, the content of text messages, websites, or activated applications on the terminal device E1. Corresponding usage data 14 can also be in the form of image, video, or audio data. The content is automatically analyzed by data processing rule 20 and evaluated for any potential threat risks. The controller does not have direct access to the usage data 14. The application data profile C is adapted to process the usage data 14 with reference to one or more applications (apps) installed on the user terminal E1. For example, if application data profile C is selected, the risk data record 22 is structured application-specifically and provides an overview of the threat risk for a particular application on the terminal device E1.Measures to reduce the risk of danger can be implemented very efficiently in this way, e.g. by transmitting an intervention data record 24 to the user terminal E1 with the content that an application classified as dangerous is automatically deleted or the user is instructed to delete or deactivate the application on his terminal E1.

[0096] The application data profile C further allows for the restriction of usage data 14 to one or more selected applications of the terminal device E1. For reasons of efficiency, total control of all applications can be omitted. Nevertheless, it is possible for newly installed apps to be recorded by the application data profile C. Only those applications classified as harmless by the control authority 12 are not recorded by the application data profile C.

[0097] Another selection option is position data profile D, which bases the evaluation of usage data 14 on position data of the terminal device E1, in particular exclusively. Position data profile D assumes that danger risks often arise from the location of the person in need of protection. For example, in the case of unusual or completely new locations, a higher danger risk can be assumed, which is identified separately in risk data record 22 and can be included in addition to other danger risks. A respective risk data record 22 can be generated using exclusively one of data profiles A, B, C, or D, whereby only the part of usage data 14 selected according to the data profile is then included in the generation of risk data record 22. However, it is preferably possible to select multiple data profiles simultaneously in order to make risk data record 22 more meaningful.Risk data set 22 enables a particularly differentiated risk assessment when selecting several data profiles.

[0098] With reference to Fig. 4, a further embodiment of the hazard risk control method is described below. Unlike Figs. 2 and 3, the assessment body 30 is not shown in Fig. 4. However, it can optionally also be involved in the method, as described in connection with Fig. 2.

[0099] The embodiment according to Fig. 4 is characterized in that the control instance 12 comprises a central server S and a control terminal E2, which communicate with each other and with the user instance 10, as described below.

[0100] The first risk data set 22 is transmitted from the terminal E1 of the user instance 10 to the central server S for further processing and forwarding to the control terminal E2. The risk data set 22 can be transmitted in unchanged form as a second risk data set 34 to the receiving control terminal E2. Optionally, however, the server S can add further information to the first risk data set 22, which allows the control person, i.e. the user of the control terminal E2, to improve the assessment of the hazard risk. The server S ensures that the second risk data set 34 is only transmitted to an authenticated control terminal E2. For this purpose, the transmission of the second risk data set 34 can be made dependent on the receipt and verification of authentication data from the control terminal E2 (not shown).

[0101] After the second risk data record 34 is received at the control terminal E2, it is displayed on a display device (not shown) of the terminal E2 for the control officer. The control officer can then decide whether and in what form measures should be taken to counteract the risk. One possibility is for the control officer to generate a control data record 36 using the terminal E2 and transmit it to the server S.

[0102] The control data record 36 contains one or more commands for the server S to generate a desired intervention data record 24 and transmit it to the terminal E1. For example, the controller can use the control data record 36 to instruct the server S to transmit one or more warnings for specific portions of the usage data 14 to the terminal E1. Upon receipt of the control data record 36, the warnings are automatically displayed on the terminal E1 to sensitize the user to the hazardous situation.

[0103] The control data record 36 also provides the control person with the option of modifying the data processing rule 20 stored on the terminal E1. For this purpose, the server S can generate a suitable intervention data record 24 and transmit it to the terminal E1. In this way, the control person can adapt the control profile embodied by the data processing rule 20, for example, by selecting at least one data profile A, B, C, or D (see Fig. 3).

[0104] The control data record 36 may contain a risk assessment of the control person that differs from the risk data record 34. This discrepancy is exploited to improve hazard risk control. For example, the server S can adapt the data processing rule 20 based on the differing risk assessment in order to increase the accuracy of the future risk data records 34 generated. This can be done by the server S initiating a retraining of the machine-learned model of the data processing rule 20 with the differing risk assessment and updating it on the user terminal E1.

[0105] As a further measure to reduce the risk of danger, a second intervention data record 38 is generated on the control terminal E2 and transmitted to the user terminal E1. The second intervention data record 38 can, in particular, contain a personalized message from the control person to the user terminal E1. The message, for example, points out specific danger risks and contains suggestions for reducing the risk of danger.

[0106] With reference to Fig. 5, an exemplary design of a risk data set is described below. The risk data set comprises five data elements D1, D2, D3, D4, and D5.

[0107] The data elements D1 to D4 are each expressed on a multi-level scale, which is identical for each of the data elements D1 to D4 and is designated in Fig. 5 by the reference symbols I, II, III and IV. Each of the scales I to IV has six levels 1 to 6. The data elements D1 to D4 each relate to an aspect of the usage data 14 recorded by the hazard risk control. For example, when the application data profile C is selected, the data elements D1 to D4 can each relate to one of four communication applications of the user terminal E1. The hazard risk is expressed separately for each of these applications by the data elements D1 to D4 on the associated scale I to IV.

[0108] The meaning of the individual scale levels 1 to 6 can vary. For example, scale I can represent a content-related hazard type as follows:

[0109] 6: Punishable

[0110] 5: Harmful

[0111] 4: Not age-appropriate

[0112] 3: Of interest

[0113] 2: Age-appropriate

[0114] 1 : Conducive

[0115] In another example, Scale II can represent a hazard type related to technical usage behavior. Specifically, the scale can express usage intensity as follows:

[0116] 6: Pathologically addicted

[0117] 5: Loss of control

[0118] 4: Borderline

[0119] 3: Satisfactory

[0120] 2: Disciplined

[0121] 1: Very disciplined. With regard to a substantive assessment of the risks, Scale III can be defined with reference to one or more of the user's communication partners. For example, Scale III can express a degree of trust or risk as follows:

[0122] 6: Dangerous communication partner

[0123] 5: Negative communication partner

[0124] 4: Critical communication partner

[0125] 3: Positive communication partner

[0126] 2: Very good communication partner

[0127] 1 : Perfect communication partner

[0128] The respective communication partner can be a person with direct contact. However, it is also conceivable that they could be people who follow the user and could be considered associated persons or organizations.

[0129] In another example, the content evaluation of certain usage data 14, particularly text, audio, image, or video data, can be based on the urgency of intervention. A corresponding scale IV can be defined as follows:

[0130] 6: Punishable

[0131] 5: Very critical

[0132] 4: Check

[0133] 3: Need for action

[0134] 2: Sensitive

[0135] 1 : Without hesitation

[0136] In one example, a text message received at terminal E1 can be analyzed by data processing rule 20. If the text message contains offensive comments characterized by hate speech, a corresponding data element of risk data set 22 can indicate a risk level of 4, see, for example, D2 in Fig. 5. In the case of a call to violence, however, a maximum risk level of 6 can be determined.

[0137] To facilitate the rapid processing of a risk data set, especially by a control person, the individual data elements D1 to D4 can be combined into a summary data element D5. As shown in Fig. 5, the data element D5 can provide an arithmetic mean of the data elements D1 to D4. The average value D5 is easily recorded, so that in the event of an unusual increase in the average value, the control person could be prompted to examine the individual values ​​D1 to D4 on scales I to IV to analyze the specific reason for the increased hazard risk.

[0138] The described risk control procedures enable efficient and reliable monitoring of digital usage data 14 generated on the user devices E1 of children and other vulnerable persons. This effectively supports parents, in particular, in freely providing their children with access to the potential of today's communication media while simultaneously keeping the associated risks under control.

[0139] LIST OF REFERENCE SYMBOLS

[0140] 10 Usage instance

[0141] 12 Control authority

[0142] 14 Usage data

[0143] 16 input data

[0144] 18 Control rule

[0145] 20 Processing rule

[0146] 22 First risk data set

[0147] 24 First intervention data set

[0148] 26 input data

[0149] 28 Second risk data set

[0150] 30 Assessment body

[0151] 32 Assessment data set

[0152] 34 Second risk data set

[0153] 36 Control data record

[0154] 38 Second intervention data set

[0155] A Command data profile

[0156] B Content data profile

[0157] C Application data profile

[0158] D Position data profile

[0159] E1 User terminal

[0160] E2 control terminal

[0161] D1 Single data element

[0162] D2 Single data element

[0163] D3 Single data element

[0164] D4 Single data element

[0165] D5 Overview data element

[0166] I Risk scale

[0167] 11 Risk scale

[0168] III risk scale IV risk scale

[0169] Central server

Claims

PATENT CLAIMS 1 . A data-driven hazard risk control process comprising at least the following steps: - collecting usage data (14) of a user terminal (E1); and - generating a risk data record (22, 28, 34) on the basis of the usage data (14), wherein the risk data record (22, 28, 34) represents a danger risk for a user of the user terminal (E1).

2. The method according to claim 1, wherein the risk data set (22, 28, 34) is provided to a control instance (12), in particular a central control server (S) and / or a control terminal (E2).

3. The method according to claim 1 or 2, wherein the usage data (14) is at least substantially not contained in the risk data set (22, 28, 34), in particular wherein a size of the risk data set (22, 28, 34) is less than 1 percent of a size of the usage data (14).

4. Method according to at least one of the preceding claims, wherein a risk class is determined for the risk data set (22, 28, 34) which represents a hazard type for at least part of the usage data (14).

5. Method according to at least one of the preceding claims, wherein a risk degree is determined for the risk data set (22, 28, 34), which represents a hazard intensity for at least part of the usage data (14).

6. Method according to at least one of the preceding claims, wherein at least one element (D1, D2, D3, D4) of the risk data set (22, 28, 34) is defined with respect to a multi-level reference (I, II, III, IV) which is designed to assess a relative hazard risk, in particular wherein the reference (I, II, III, IV) has at least three levels.

7. Method according to at least one of the preceding claims, wherein the risk data set (22, 28, 34) comprises a plurality of elements (D1, D2, D3, D4) which are assigned to different parts of the usage data (14) and represent a respective hazard risk.

8. The method according to claim 7, wherein at least some of the plurality of elements (D1, D2, D3, D4) are assigned to different applications of the user terminal (E1), and / or wherein at least some of the plurality of elements (D1, D2, D3, D4) are assigned to different communication partners with which the user is in contact according to the usage data (14).

9. Method according to at least one of the preceding claims, wherein several elements (D1, D2, D3, D4) of the risk data set (22, 28, 34) are combined to form an overview element (D5) which represents a hazard risk summarized for several parts of the usage data (14).

10. The method according to claim 9, wherein the overview element (D5) comprises a numerical value representing a mean value or an extreme value of the plurality of elements (D1, D2, D3, D4).

11. Method according to at least one of the preceding claims, wherein the risk data set (22, 28, 34) represents a technical usage behavior of the user, in particular wherein the risk data set (22, 28, 34) comprises information about at least one of the following: - times of use and / or duration of use; - Number of input commands; - Number of activated applications; - Number of websites visited; - Position data of the user terminal (E1); - Operating data of the user terminal (E1).

12. Method according to at least one of the preceding claims, wherein the risk data set (22, 28, 34) represents a content-related usage behavior of the user, in particular wherein the risk data set (22, 28, 34) comprises information about at least one of the following: - text, image, video and / or audio data input and / or received at the user terminal (E1); - Functional type of an application activated or installed on the user terminal (E1); - Characteristics of one or more communication partners, in particular an orientation of interests, e.g. in commercial and / or political terms.

13. Method according to at least one of the preceding claims, wherein the risk data set (22, 28, 34) is generated as a function of a predetermined data processing rule (20) which can be modified by a control authority (12) and / or the user.

14. The method of claim 13, wherein the data processing rule (20) comprises a machine learning model.

15. Method according to at least one of the preceding claims, wherein the user data (14) is recorded on the user terminal (E1) using an operating system of the user terminal (E1) and is at least partially transmitted from the user terminal (E1) to a central server (S), and wherein the risk data record (28, 34) is generated on the central server (S).

16. Method according to at least one of the preceding claims, wherein the risk data record (22) is generated as a function of an active input (16) of the user at the user terminal (E1), in particular wherein the input (16) comprises authentication data.

17. The method according to at least one of the preceding claims, wherein the risk data record (22) is generated and / or provided to a control instance (12), in particular a control terminal (E1), depending on validity data representing a time-limited validity of the risk data record (22); and / or wherein the risk data record (22) is generated in a non-storable data format and is preferably non-modifiable.

18. Method according to at least one of the preceding claims, wherein the risk data record (22) is provided in encrypted form, in particular to at least one central server (S), the user terminal (E1) and / or a control terminal (E2).

19. Method according to at least one of the preceding claims, wherein the risk data record (28) is provided as a function of authorization data (26), in particular on at least one central server (S) or a control terminal (12).

20. Method according to at least one of the preceding claims, wherein the risk data record (22) is generated as a function of at least one data profile (A, B, C, D) which can be selectively activated and / or modified by the user and / or a control authority (12), in particular wherein the data profile is selected from a number of predetermined data profiles (A, B, C, D).

21. Method according to claim 20, wherein the data profile (A, B, C, D) defines a subset of the usage data (14) on which the generation of the risk data set (22) is based.

22. Method according to at least one of the preceding claims, wherein the risk data set (22, 28, 34) is evaluated using previously provided risk data sets in order to add information about a change in the hazard risk to the risk data set (22, 28, 34).

23. Method according to at least one of the preceding claims, wherein parts of the usage data (14) and / or the risk data set (22, 28, 34) are compared with a plurality of predetermined usage and / or risk data sets (22, 28, 34) stored in a database.

24. Method according to at least one of the preceding claims, wherein an intervention data record (24, 38) is stored on the user terminal (E1) is provided, in particular wherein the intervention data record (24, 38) has at least one control command for the user terminal (E1).

25. A data-driven hazard risk control process comprising at least the following steps: - receiving a risk data record (22, 28, 34) representing a risk of danger for a user of a user terminal (E1) on the basis of usage data (14) of the user terminal (E1); - generating an intervention data record (24, 38) on the basis of the risk data record (22, 28, 34), wherein the intervention data record (24, 38) has at least one control command (36) for the user terminal (E1), in particular wherein the intervention data record (24, 38) is provided at the user terminal (E1).

26. A data-driven hazard risk control process comprising at least the following steps: - receiving a first risk data set (22) representing a risk of danger for a user of a user terminal (E1) on the basis of usage data (14) of the user terminal (E1); - generating a second risk data set (28, 34) on the basis of the first risk data set (22), wherein the second risk data set (28, 34) contains at least parts of the first risk data set (22) as well as data for processing the first risk data set (22); - Providing the second risk data set (28, 34) to a control body (12) and / or an assessment body (30).

27. The method according to claim 26, wherein an intervention data record (24, 38) and / or an assessment data record (32) is generated on the basis of the second risk data record (28, 34), wherein the intervention data record (24, 38) has at least one control command (36) for the user terminal (E1), in particular wherein the intervention data record (24, 38) is provided on the user terminal (E1) and / or a central server (S).

28. A computer program for data-driven hazard risk control, comprising instructions which, when executed by a computer, cause the computer to carry out the steps of a method according to any one of the preceding claims.

29. A device for data-driven hazard risk control, the device being connected to at least one data processing means and a non-volatile memory in which at least one computer program is stored, the computer program comprising instructions which, when executed by the at least one data processing means, cause the latter to carry out the steps of a method according to any one of claims 1 to 27.

Citation Information

Patent Citations

  • Parental Control Systems and Methods For Detecting An Exposure of Confidential Information

    US20200233974A1

  • Management and control of mobile computing device using local and remote software agents

    US20230161893A1