Data Management Mechanism for Cross-Context Privacy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices share various identifiers during communication, leading to cross-context analysis that can result in aggressive and complete user profiling, compromising user privacy by allowing unauthorized access to shared activities across different user accounts.

Innovation Solution

A data management mechanism that creates separate privacy profiles for each user account, identifies and manages identifiers associated with activities, and provides risk assessments and notifications before allowing access to common activities, ensuring that identifiers are not shared unless explicitly approved by the user.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices share identifiers during communication with multiple services, then service functionality and connectivity are improved, but user privacy is compromised due to cross-context analysis and unauthorized profiling

Engineering Contradiction:
Improveservice connectivityVSAvoiduser privacy compromise
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments identifiers into different types (hardware identifiers, activity identifiers, location identifiers) and assigns different sharing policies to each type. User accounts are divided into multiple contexts (personal, business, shared) with separate identifier sets. This segmentation allows selective sharing of specific identifier types with specific user accounts, enabling service connectivity while preventing comprehensive cross-context profiling.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different privacy protection levels to different identifier types and different user accounts. Each user account receives customized access rights to specific identifier sets based on contextual needs. For example, a business account may access business-related activity identifiers while a personal account accesses personal identifiers, allowing tailored privacy protection for each context.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If multiple user accounts share common identifiers for convenience, then ease of operation is improved, but reliability of privacy protection deteriorates due to unauthorized access across contexts

Engineering Contradiction:
Improveaccount accessibilityVSAvoidprivacy protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary action by pre-configuring disjoint sets of identifiers for each user account before any cross-account access attempts occur. The system establishes identifier ownership and access rights in advance, creating a privacy policy framework that automatically enforces access control. This preliminary setup enables convenient multi-account operation while maintaining reliable privacy boundaries without requiring real-time user intervention.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the system performs cross-context analysis using shared identifiers, then user profiling capability is improved, but data security deteriorates due to unauthorized access to personal information

Engineering Contradiction:
Improveuser profiling accuracyVSAvoidunauthorized data access
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts and isolates personally identifiable information and sensitive activity identifiers into protected sets that are excluded from cross-context analysis. By taking out these sensitive identifiers from the general pool of shareable data, the system enables legitimate user profiling for service functionality while preventing unauthorized construction of complete user profiles across different contexts and accounts.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10002241B2Managing data to diminish cross-context analysis
Publication Date: 2018.06.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10002241B2 patent drawing
  • US10002241B2 patent drawing
  • US10002241B2 patent drawing

AI summary

A mechanism is provided for managing user accounts used on the data processing system. A first user account and second user account are initialized. Responsive to a user attempting to perform an activity from a user account in a set of user accounts under which the user is currently logged in, a determination is made as to whether an identifier associated with the activity is associated with a set of identifiers of the user account under which the user is currently logged in. Responsive to the identifier associated with the activity being associated with the set of identifiers of the user account under which the user is currently logged in, the user is allowed access to perform the activity. Responsive to the identifier associated with the activity being associated with a set of identifiers of another user account on the data processing system, the activity is denied.