Application Purpose Certificate for Data Usage Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users have no effective way to verify that their personal data is used by applications and services only for the declared and consented purposes, as data is often shared with third parties and used beyond intended uses.

Innovation Solution

A method and system for creating an application purpose certificate, which involves analyzing the usage of data types by the application, verifying compliance with declared usage purposes, and generating an encrypted digital purpose certificate that is unique to the application code, ensuring data is used only for approved purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is shared with third parties for outsourcing, data sharing or profit, then data collectors can achieve business goals and revenue, but users cannot verify that data is used only for consented purposes

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidpurpose verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent embeds purpose certification information into the application code before distribution. A trusted authority certifies the application's declared purposes in advance, and this certification is included in the application bundle. When the application runs, the purpose certificate is automatically verified, ensuring data is used only for certified purposes before any data sharing occurs with third parties.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a trusted authority as an intermediary between users and data collectors. This authority issues purpose certificates that bind the application to specific declared purposes. The certificate acts as a mediator that provides verifiable proof of intended data usage, enabling users to trust third-party data sharing arrangements without direct verification capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If application code is distributed without purpose verification, then ease of distribution is maintained, but data misuse cannot be prevented

Engineering Contradiction:
Improveapplication distributionVSAvoiddata misuse
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The purpose certificate is embedded in the application code during the build process, before distribution. This preliminary certification step does not complicate the distribution process itself, as the certificate becomes an integral part of the application bundle that is distributed in the same manner as before. The verification occurs automatically at runtime without additional user action.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The application automatically verifies its own purpose certificate at runtime without requiring user intervention. The system self-regulates by checking whether the application's data usage aligns with its certified purposes, preventing data misuse without adding complexity to the distribution process or requiring continuous user oversight.

Inventive Principle:
Principle #25Self-service

3Reliability

If purpose verification is implemented at runtime, then data usage compliance is ensured, but system complexity increases

Engineering Contradiction:
Improvepurpose compliance verificationVSAvoidverification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The runtime verification system operates automatically without requiring complex user-facing interfaces or manual processes. The application code itself contains the verification logic that automatically checks data usage against certified purposes. This self- verifying approach ensures compliance while minimizing the complexity burden on users and deploying systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The purpose verification functionality is merged into the application code itself rather than being implemented as a separate external system. The certificate validation logic is integrated within the application bundle, allowing compliance verification to occur as part of the application's normal operation without requiring additional complex infrastructure or user-facing verification mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Ensures that data is used only for declared purposes, preventing misuse and ensuring transparency and trust between users and data collectors, with real-time verification during runtime.

Implementation Method 1

creating an encrypted digital purpose certificate, the digital purpose certificate is unique for the application code

Methodology Applied
Scientific EffectPublic-key cryptography:

Data Source

PatentUS10616206B2Digital certificate for verifying application purpose of data usage
Publication Date: 2020.04.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10616206B2 patent drawing
  • US10616206B2 patent drawing
  • US10616206B2 patent drawing

AI summary

A method of creating an application purpose certificate, comprising: receiving from a software publisher an application code and declared privacy information, the declared privacy information includes at least one allowed usage purpose for each of a plurality of data types; analyzing the application's usage of data of each of the plurality of data types; verifying the usage is compliant with the least one allowed usage purpose according to the analysis; creating an encrypted digital purpose certificate, the digital purpose certificate is unique for the application code; and sending the digital purpose certificate to the software publisher to be bundled with the application code and a publisher authentication certificate.