Electronic Device Privacy Verification Across Policy, Code, and Runtime

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices lack a method to intuitively provide the content of a privacy policy to users and verify if the device's operations align with the policy, leading to potential misuse of personal information without user consent.

Innovation Solution

An electronic device analyzes policy data to identify first personal information from the privacy policy, compares it with second and third personal information from the application's code and execution, and determines operations to protect user data by notifying, obfuscating, or restricting data usage when discrepancies are found.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user receives a service using an electronic device, then the service can be provided, but the party may collect or share personal information without permission violating privacy policies

Engineering Contradiction:
Improveprivacy protectionVSAvoiduser awareness of privacy policy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The electronic device continuously monitors the application's actual operations and compares them against the privacy policy to provide real-time feedback. When discrepancies are detected, the system notifies the user, creating a closed-loop feedback mechanism that ensures privacy protection while maintaining user awareness without complicating device operation.

Inventive Principle:
Principle #23Feedback

2Reliability

If the electronic device analyzes and compares policy data with application code and execution operations, then privacy compliance is verified, but device complexity increases

Engineering Contradiction:
Improveprivacy compliance verificationVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The electronic device leverages existing multi-functional components (processor, memory, communication unit) to perform privacy verification. The same hardware that executes applications and stores data is also utilized to analyze policy compliance, eliminating the need for separate dedicated verification hardware and thus avoiding increased device complexity while maintaining reliable privacy compliance verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If the electronic device provides detailed privacy policy content to users, then user awareness is improved, but the complexity of presenting and verifying policy information increases

Engineering Contradiction:
Improveprivacy policy information transparencyVSAvoidpolicy presentation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system extracts and presents only the critical privacy information from the comprehensive policy documents. By identifying and highlighting key personal information collection points and compliance status, the device provides necessary transparency without overwhelming users with detailed policy content, thus avoiding increased presentation complexity while maintaining information accessibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12417307B2Electronic device for protecting personal information and operation method thereof
Publication Date: 2025.09.16 SAMSUNG ELECTRONICS CO LTD
  • US12417307B2 patent drawing
  • US12417307B2 patent drawing
  • US12417307B2 patent drawing

AI summary

An example electronic device for protecting personal information for protecting a user's personal information may include a communicator, an output unit, a memory storing one or more instructions, and a processor configured to execute the one or more instructions stored in the memory to obtain policy data indicating a user privacy policy related to a service provided by the electronic device, identify, from the obtained policy data, first personal information to be used to provide the service, identify, from an execution file of the application providing the service, second personal information configured to be used by the application, identify third personal information used by the application while the application is executed, compare the first personal information identified from the policy data, the second personal information identified from the execution file of the application, and the third personal information used by the application, and determine, based on a result of the comparing, an operation of the electronic device for protecting the user's personal information.