Context-Based Personal Data Access Control via Filtering Layer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing personal data protection systems fail to effectively manage context-sensitive information access, leading to unauthorized disclosure of sensitive data across different user contexts on computing devices, particularly in multi-purpose devices like smartphones and tablets.
Innovation Solution
Implementing a context-sensitive data management system that uses context identifiers and schema identifiers to control access to personal data through a filtering layer module, allowing access only when the context identifier is associated with the relevant schema identifier in a rules data storage, and prompting users for permission during initial access with subsequent decisions made automatically based on stored rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If personal data is made accessible across multiple contexts for personalized marketing and services, then user convenience and personalization improve, but data security and privacy control deteriorate
Solution Approach 1:
The patent segments personal data into context-specific groups (e.g., gardening context, gambling context) and implements context-specific access control rules. Each context has its own firewall rules that determine which applications can access which data elements, preventing unauthorized cross-context data access while allowing legitimate context-specific access.
Solution Approach 2:
The patent introduces a filtering layer module that acts as an intermediary between applications and personal data storage. This module evaluates context identifiers, application identifiers, and data element identifiers against stored firewall rules to mediate access requests, blocking unauthorized access while permitting legitimate access without requiring user intervention for each request.
2Object-affected harmful factors
If context-specific access control rules are implemented to prevent unauthorized data access, then data security improves, but system complexity increases
Solution Approach 1:
The patent implements a universal filtering layer module that handles all context-specific access control requests through a single mechanism. The module uses a standardized rule evaluation process that works across all contexts and data types, managing diverse context-specific rules through a unified interface that prevents data access across multiple contexts while maintaining manageable complexity.
3Ease of operation
If user permission prompts are displayed for each data access request, then user control over privacy improves, but user experience and operational efficiency deteriorate
Solution Approach 1:
The patent implements preliminary user consent mechanisms where users provide broad context-level permissions in advance (e.g., allowing a context to access certain data types). The filtering layer module then automatically evaluates subsequent access requests against these pre-established rules without requiring repeated user prompts, reducing interaction time while maintaining user control over their data sharing preferences.
Data Source
AI summary
Systems and methods are described for providing user control over access to private data. An exemplary embodiment is performed on a client computing device in which separate computing environments referred to as context modules are installed. Each context module has a context identifier. An application is installed in a context module. The client computing device receives a request for data from the application, where the request for data includes a schema identifier that identifies the data. If the schema identifier is associated with the context identifier in a rules data storage, then the data is provided to the application. Otherwise, a user is prompted as to whether to permit the data request.


