Application Access Notification System for User Data Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face risks when granting applications access to their private information, as these applications may misuse access rights for unintended purposes, including data mining or malicious activities, potentially compromising personal information.
Innovation Solution
A system that detects an application's access to user information and sends notifications to the user, allowing them to approve or deny access, modify permissions, and receive additional information about the application's activity, ensuring timely awareness and control over their data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If an application is granted permission to directly retrieve user information from storage, then the application can access the information for its intended purpose, but the user's personal information may be compromised through misuse or malicious activities
Solution Approach 1:
The system implements a notification mechanism that provides feedback to users when applications access their stored information. The notification system monitors application access events and communicates them to users, enabling users to maintain awareness of who is accessing their data and for what purpose. This feedback loop allows users to revoke permissions if an application misuses access rights.
Solution Approach 2:
The patent introduces an intermediary notification system between the application and user information storage. This intermediary monitors and controls access by alerting users before or during data retrieval operations. The notification system acts as a mediator that can prevent unauthorized or malicious access while allowing legitimate application functionality.
2Reliability
If the user is notified of every application access event, then the user can maintain control and awareness of their information, but the user may experience notification fatigue or disruption
Solution Approach 1:
The notification system implements local quality by providing different notification characteristics based on the specific access context. Rather than uniform notifications for all access events, the system can vary notification prominence, timing, and detail based on factors such as the type of application, sensitivity of accessed information, and user current state. This allows important security-related notifications to stand out while less critical ones are handled more subtly.
3Productivity
If the application is allowed to access information for an extended period, then the application can perform comprehensive data analysis or mining, but the user's information security risk increases significantly
Solution Approach 1:
The notification system implements periodic action by notifying users at regular intervals or at specific milestones during application access sessions. Rather than requiring continuous user monitoring, the system provides periodic status updates that inform users of ongoing access activities. This allows applications to perform extended data processing while maintaining periodic user awareness and control.
Data Source
AI summary
Functionality is described for detecting an application's access to a user's information (or the application's request to access the user's information). The functionality sends a notification to the user which alerts the user to the access that has already taken place (or is pending approval). The functionality detects the current point of presence of the user, and based thereon, sends the notification to the user in an appropriate manner. Upon receipt of the notification, the user may optionally retrieve additional information regarding the application's access activity, modify the access rights of the application, and so on.


