Data Access Rights Manager for Transparent User Privacy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting user data privacy, such as those employed by Google's Firebase and Apple's Security Framework, are not transparent and provide weak protection against data tracking by third-party applications, leading to potential misuse of user data.

Innovation Solution

A system and method that block data processing by external devices, redirecting requests through a storage device to determine and manage data access rights, using a blocker, data access rights manager, modifier, and anonymizer to ensure secure and transparent data exchange between user devices and interested parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is collected and distributed around the network without clear consent, then the volume and variety of collected data increases, but user privacy and security deteriorate

Engineering Contradiction:
Improvevolume of collected dataVSAvoiduser privacy harm
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data rights manager as an intermediary component that sits between data collectors and user data. This manager establishes and enforces access rights policies, controlling how third-party applications can request and access user data. The intermediary prevents direct unauthorized access while allowing controlled data sharing, thus resolving the contradiction between data collection volume and user privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device manufacturers implement data protection mechanisms like Firebase or Apple Security Framework, then data security is improved, but transparency and user control deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiduser transparency and control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism where the data rights manager communicates with user devices and third-party applications about data access requests and decisions. The system provides transparency by allowing users to view and control data access rights, and by notifying applications about access denials or approvals. This feedback loop maintains security while improving user transparency and control.

Inventive Principle:
Principle #23Feedback

3Reliability

If data access rights are established and enforced through a storage device, then unauthorized processing is prevented, but data access complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoiddata access system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data rights manager is designed as a universal component that can be integrated into various device architectures and data collection systems. It provides multi-functional capabilities including establishing access rights, enforcing policies, managing third-party application permissions, and providing transparency mechanisms. This universal design allows the system to maintain security across different platforms without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11556670B2System and method of granting access to data of a user
Publication Date: 2023.01.17 AO KASPERSKY LAB
  • US11556670B2 patent drawing
  • US11556670B2 patent drawing
  • US11556670B2 patent drawing

AI summary

Disclosed herein are systems and methods for granting access to data of a user. In one aspect, an exemplary method comprises, blocking the processing of data of a user, transferring the data of the user to a storage device, receiving a request for data processing from a collected data processor of a device, redirecting the received request to the storage device, determining, by the storage device, data access rights for the collected data processor of the device from which the request for data processing is received in accordance with data access rights established by a data access rights manager, and providing access to the data in accordance with the determined data access rights.