Dynamic User Authority Configuration via Selective Privacy Consent
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for configuring user authorities in online electronic business systems infringe on user privacy, as they collect sensitive information without user consent, leading to potential leaks and unauthorized access to service functions.
Innovation Solution
A method and device that send a privacy information acquisition request to users upon login, allowing them to choose which information is collected, and configuring their authority based on the permitted information, thereby protecting their privacy and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user authority is dynamically configured based on collected user information, then user authority configuration flexibility is improved, but user privacy protection deteriorates
Solution Approach 1:
The patent implements dynamic authority configuration by allowing users to flexibly select which privacy information to provide during login. The system dynamically adjusts user authority based on the selected information type and granularity, enabling both adaptability in authority assignment and user control over privacy exposure.
Solution Approach 2:
The patent applies local quality by enabling users to selectively disclose specific portions of their privacy information rather than requiring complete information disclosure. Users can choose to provide only the minimum necessary information for specific service functions, thereby protecting sensitive data while still obtaining required authorities.
2Measurement precision
If comprehensive user information is collected for authority configuration, then authority configuration accuracy is improved, but information security risk increases
Solution Approach 1:
The patent implements partial action by collecting only the specific user information necessary for the requested service function rather than comprehensive user data. Users select which information types to provide, and the system collects only that subset, achieving sufficient authority configuration accuracy while minimizing privacy exposure.
Solution Approach 2:
The patent changes the parameter of information collection from fixed comprehensive collection to variable selective collection. The system adapts the amount and type of information collected based on user selections and service requirements, thereby maintaining configuration accuracy while reducing overall information exposure risk.
3Device complexity
If static role configuration is used for all users, then system complexity is reduced, but user authority customization deteriorates
Solution Approach 1:
The patent applies universality by designing a unified authority configuration mechanism that works for all users regardless of their information selection. The same system infrastructure handles both minimal and extensive information scenarios, eliminating the need for separate static role configurations while maintaining low system complexity.
Data Source
AI summary
An authority configuration method and device are provided. The method includes: when a user logs in a system, a privacy information acquisition request is sent to the user; and an authority of the user is configured according to response information of the privacy information acquisition request. Prior to acquisition of privacy information of the user, the user chooses whether a system is permitted to collect the privacy information, and an authority of the user is configured according to the privacy information permitted by the user. A user is provided with a corresponding operation authority while privacy of the user can be protected from being infringed, and the privacy of the user can be prevented from being leaked.

