Application Information Risk Management via Selective Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for managing application information risks, such as SMS phishing, result in low efficiency and high user privacy leakage risks due to large data volumes and low user participation in privacy management.
Innovation Solution
A method and device for application information risk management that involves a network device with a target application information acquiring apparatus, validation apparatus, and prompt information sending apparatus, allowing users to autonomously select and validate application information, reducing data transmission, and providing prompt feedback on risk levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all SMS messages are uploaded to the cloud for screening analysis, then the risk management coverage is improved, but the user privacy leakage risk increases and management efficiency decreases
Solution Approach 1:
The patent applies local quality by enabling users to selectively upload only specific SMS messages that they suspect may be phishing messages, rather than uploading all messages. This localized approach allows risk management to focus on potentially harmful content while preserving the privacy of normal communications.
Solution Approach 2:
The patent implements partial action by allowing users to choose a subset of messages for upload based on their own judgment of suspicious content. The system provides tools to assist users in identifying potential phishing messages, but the upload action is performed only on selected messages rather than all messages, balancing privacy protection with risk management.
2Measurement precision
If all SMS messages are uploaded to the cloud for screening analysis, then the risk detection capability is improved, but the data transmission volume increases and processing efficiency decreases
Solution Approach 1:
The patent extracts only the necessary portion of data for risk analysis by allowing users to select and upload only suspicious SMS messages rather than all messages. This extraction principle reduces the volume of data transmitted to the cloud while maintaining the ability to detect phishing risks in the selected subset.
Solution Approach 2:
The patent segments the message processing task by dividing messages into two categories: those uploaded for cloud analysis (suspected phishing messages) and those kept locally (normal messages). This segmentation reduces the overall data transmission volume while ensuring that potential risks are still subjected to comprehensive cloud-based analysis.
3Reliability
If security software is installed to upload and analyze all SMS messages, then the risk management thoroughness is improved, but the user participation level in privacy management decreases
Solution Approach 1:
The patent implements self-service by empowering users to take an active role in selecting which messages to upload for analysis. The system provides user-friendly interfaces and assistance tools that enable users to independently identify and select suspicious messages, thereby increasing their participation in privacy management while maintaining thorough risk analysis through cloud processing.
Solution Approach 2:
The patent introduces an intermediary mechanism that assists users in identifying phishing messages without requiring them to perform complex analysis themselves. The system provides intermediate tools and guidance that bridge the gap between user capability and thorough risk detection, enabling users to make informed selections while the cloud performs the comprehensive analysis.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present application aims to provide a method and device for application information risk management, so as to resolve a problem that because third-party software uploads all SMS messages in user equipment to a network device, SMS message management efficiency is low, and a user privacy leakage risk is relatively high. The method includes: acquiring target application information that a user selects and requests for validation by using user equipment; validating the target application information to obtain corresponding risk information; and returning corresponding prompt information to the user equipment based on the risk information. In comparison with the prior art, in the present application, the user can directly and autonomously determine some or all to-be-uploaded target application information on a corresponding application information interface of the user equipment. Therefore, a user's participation level in user privacy information management is improved, a user's privacy leakage probability is reduced, and a volume of data transmitted between devices is reduced. As such, a volume of validation data that the network device processes is accordingly reduced, and overall application information risk management efficiency is improved.