Electronic Device Privacy Verification Across Policy, Code, and Runtime
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices lack a method to intuitively provide the content of a privacy policy to users and verify if the device's operations align with the policy, leading to potential misuse of personal information without user consent.
Innovation Solution
An electronic device analyzes policy data to identify first personal information from the privacy policy, compares it with second and third personal information from the application's code and execution, and determines operations to protect user data by notifying, obfuscating, or restricting data usage when discrepancies are found.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user receives a service using an electronic device, then the service can be provided, but the party may collect or share personal information without permission violating privacy policies
Solution Approach 1:
The electronic device continuously monitors the application's actual operations and compares them against the privacy policy to provide real-time feedback. When discrepancies are detected, the system notifies the user, creating a closed-loop feedback mechanism that ensures privacy protection while maintaining user awareness without complicating device operation.
2Reliability
If the electronic device analyzes and compares policy data with application code and execution operations, then privacy compliance is verified, but device complexity increases
Solution Approach 1:
The electronic device leverages existing multi-functional components (processor, memory, communication unit) to perform privacy verification. The same hardware that executes applications and stores data is also utilized to analyze policy compliance, eliminating the need for separate dedicated verification hardware and thus avoiding increased device complexity while maintaining reliable privacy compliance verification.
3Loss of information
If the electronic device provides detailed privacy policy content to users, then user awareness is improved, but the complexity of presenting and verifying policy information increases
Solution Approach 1:
The system extracts and presents only the critical privacy information from the comprehensive policy documents. By identifying and highlighting key personal information collection points and compliance status, the device provides necessary transparency without overwhelming users with detailed policy content, thus avoiding increased presentation complexity while maintaining information accessibility.
Data Source
AI summary
An example electronic device for protecting personal information for protecting a user's personal information may include a communicator, an output unit, a memory storing one or more instructions, and a processor configured to execute the one or more instructions stored in the memory to obtain policy data indicating a user privacy policy related to a service provided by the electronic device, identify, from the obtained policy data, first personal information to be used to provide the service, identify, from an execution file of the application providing the service, second personal information configured to be used by the application, identify third personal information used by the application while the application is executed, compare the first personal information identified from the policy data, the second personal information identified from the execution file of the application, and the third personal information used by the application, and determine, based on a result of the comparing, an operation of the electronic device for protecting the user's personal information.


