Application Hub for Privacy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are concerned about the privacy of their data stored in devices and wish to control how and when this data is accessed and shared, especially when using applications that require data access for analysis or services, without relinquishing control to third-party vendors.

Innovation Solution

An application hub system that allows users to manage the lifecycle of applications seeking data access, including review and approval processes, ensuring transparency and control over data access and transmission, by integrating application reviews and user authorization to execute applications on a user-controlled hub.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are allowed to access user data for analysis and services, then data utility and service value are improved, but user privacy control and data security deteriorate

Engineering Contradiction:
Improvedata utilityVSAvoidprivacy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an application hub as an intermediary layer between user devices and applications. The hub receives applications, generates executable code with controlled data access capabilities, and manages the execution environment. This intermediary structure allows applications to access data for analysis while the hub maintains privacy controls, digitally signs executable code to ensure integrity, and prevents direct application access to raw user data, thus resolving the contradiction between data utility and privacy protection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users maintain full control over their data, then privacy security is improved, but application functionality and data analysis capabilities deteriorate

Engineering Contradiction:
Improveprivacy securityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the application execution process into distinct components: the application package received by the hub, the generated executable code that runs in the hub's controlled environment, and the data access protocols managed by the hub. This segmentation allows users to maintain control through the hub's authorization mechanisms while applications retain their functional capabilities through the executable code interface, resolving the contradiction between privacy security and application functionality

Inventive Principle:
Principle #1Segmentation

3Productivity

If third-party vendors process user data directly, then service delivery efficiency is improved, but user autonomy and informed consent deteriorate

Engineering Contradiction:
Improveservice delivery efficiencyVSAvoiduser autonomy
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the application hub provides users with information about applications seeking access to their data, including what data will be accessed and how it will be used. Users can review this information and provide informed consent before authorizing application execution. This feedback loop maintains user autonomy while still enabling efficient service delivery through the hub's automated code generation and execution management

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3443503B1Application approval
Publication Date: 2022.06.01 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • EP3443503B1 patent drawingFigure 1
  • EP3443503B1 patent drawingFigure 2
  • EP3443503B1 patent drawingFigure 3

AI summary

Examples associated with application approval are described. One example includes receiving an application package. The application package contains an application from a service provider and a privacy description for the application from a review provider. The application operates on private data controlled by a user. The application package is validated to ensure components of the application package is properly credentialed. An application summary for the user is generated from the privacy description. The application summary describes what portions of private data will be accessed by the application and how portions of the private data will be transmitted. An authorization is received from the user, and execution of the application is controlled based on the authorization of the user.