App Permission Role Analysis for Installation File Mismatch
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing applications can collect sensitive personal information without accurately reflecting the permissions notified in electronic documents, leading to potential privacy breaches.
Innovation Solution
An electronic device and method to analyze permissions by comparing data from an installation file with an electronic document, providing notifications when categories differ, and generating a call flow graph to identify and compare roles of permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an application collects sensitive information using an installation file, then the application can access personal information stored in the electronic device, but the application may collect information differently from the notice in the electronic document, causing privacy protection problems
Solution Approach 1:
The system segments the permission analysis into distinct components: extracting permissions from the installation file, extracting notified permissions from the electronic document, and comparing the two sets. This segmentation allows for systematic verification of permission accuracy without overwhelming complexity.
Solution Approach 2:
The electronic device acts as an intermediary between the installation file and the electronic document, performing the comparison operation to verify whether the collected information matches the notified permissions. This intermediary role ensures accuracy while managing system complexity through automated verification.
2Loss of information
If the application running on the electronic device collects sensitive information, then personal information can be processed for various purposes, but the collected information may not match the notified permissions, leading to information loss
Solution Approach 1:
The system provides feedback by comparing the permissions extracted from the installation file with those from the electronic document and notifying the user of any discrepancies. This feedback mechanism prevents information loss by ensuring permissions are accurately reflected, while maintaining full application functionality.
3Measurement precision
If a comparison operation is performed between installation file data and electronic document data, then permission accuracy can be verified, but additional processing time and resources are required
Solution Approach 1:
The system performs preliminary extraction and organization of permission data from both the installation file and electronic document before comparison. This preliminary action structures the data to facilitate efficient comparison, reducing overall processing time while maintaining measurement precision.
Data Source
AI summary
According to various embodiments, a method of performed by an electronic device may include identifying a first permission associated with a function included in an installation file of an application, and a first category of a role associated with the first permission, identifying a second category of the role associated with the first permission, based on a document associated with the application, and in case the first category is different from the second category, providing a notification. Various other embodiments are available.


