Access Manager for User Data Privacy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users lack transparency and control over how their data is accessed and used by third-party applications, as they are unaware of which information is being accessed and when.

Innovation Solution

Implementing a system where users can define service profiles that specify which categories of data can be accessed by which applications, with an access manager intercepting requests and granting or denying access based on these profiles, providing users with transparency and control over their data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users share data with third-party applications, then the user benefits from data sharing (e.g., shopping promotions), but the user loses transparency and control over how their data is accessed and used

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidtransparency of data access
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system provides feedback to users about data access requests by third-party applications. The access manager intercepts requests, checks them against user-defined service profiles, and provides notifications to users about what data is being accessed and by whom, enabling informed control over data sharing

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access manager acts as an intermediary between third-party applications and user data. It intercepts data access requests, validates them against service profiles, and either grants or denies access, thereby providing transparency and control without preventing beneficial data sharing

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users share data with third-party applications, then the user benefits from data sharing, but the user cannot control which specific data is accessed or when

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidcontrol over data access
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system segments user data into different categories and services (e.g., shopping data, social network data, email data). Users can define service profiles that specify which categories of data can be accessed by which applications, providing granular control over data sharing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service profiles are dynamic and can be modified by users at any time. Users can add, remove, or modify data access permissions for different applications and data categories, allowing flexible control over data sharing as needs change

Inventive Principle:
Principle #15Dynamics

3Reliability

If an access manager intercepts data access requests, then the user gains control and transparency over data access, but the system complexity increases

Engineering Contradiction:
Improvedata access controlVSAvoidaccess management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access manager is designed as a universal system that can handle multiple types of data access requests from different third-party applications. It uses a standardized service profile framework that can accommodate various data categories and application types, reducing overall system complexity through consolidation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9449181B1Control and enforcement of access of user data
Publication Date: 2016.09.20 GOOGLE LLC
  • US9449181B1 patent drawing
  • US9449181B1 patent drawing
  • US9449181B1 patent drawing

AI summary

Control and enforcement of access of user data are described, including receiving a request from an application to access data associated with a user; determining that a service profile and another service profile are associated with the user, the service profile includes at least one data service specified by the user and the another service profile includes at least another data service specified by the user; identifying the service profile being associated, by the user, with at least the application; determining whether the data requested by the application are provided by the at least one data service included in the service profile; and performing an action with respect to access by the application to the data requested, based on a result of the determining.