Dynamic User Authority Configuration via Selective Privacy Consent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for configuring user authorities in online electronic business systems infringe on user privacy, as they collect sensitive information without user consent, leading to potential leaks and unauthorized access to service functions.

Innovation Solution

A method and device that send a privacy information acquisition request to users upon login, allowing them to choose which information is collected, and configuring their authority based on the permitted information, thereby protecting their privacy and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user authority is dynamically configured based on collected user information, then user authority configuration flexibility is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improveuser authority configuration flexibilityVSAvoiduser privacy infringement
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic authority configuration by allowing users to flexibly select which privacy information to provide during login. The system dynamically adjusts user authority based on the selected information type and granularity, enabling both adaptability in authority assignment and user control over privacy exposure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by enabling users to selectively disclose specific portions of their privacy information rather than requiring complete information disclosure. Users can choose to provide only the minimum necessary information for specific service functions, thereby protecting sensitive data while still obtaining required authorities.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If comprehensive user information is collected for authority configuration, then authority configuration accuracy is improved, but information security risk increases

Engineering Contradiction:
Improveauthority configuration accuracyVSAvoidprivacy information leakage
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent implements partial action by collecting only the specific user information necessary for the requested service function rather than comprehensive user data. Users select which information types to provide, and the system collects only that subset, achieving sufficient authority configuration accuracy while minimizing privacy exposure.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the parameter of information collection from fixed comprehensive collection to variable selective collection. The system adapts the amount and type of information collected based on user selections and service requirements, thereby maintaining configuration accuracy while reducing overall information exposure risk.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If static role configuration is used for all users, then system complexity is reduced, but user authority customization deteriorates

Engineering Contradiction:
Improvesystem configuration complexityVSAvoiduser authority customization
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by designing a unified authority configuration mechanism that works for all users regardless of their information selection. The same system infrastructure handles both minimal and extensive information scenarios, eliminating the need for separate static role configurations while maintaining low system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11275823B2Authority configuration method and device
Publication Date: 2022.03.15 GREE ELECTRIC APPLIANCE INC OF ZHUHAI
  • US11275823B2 patent drawing
  • US11275823B2 patent drawing

AI summary

An authority configuration method and device are provided. The method includes: when a user logs in a system, a privacy information acquisition request is sent to the user; and an authority of the user is configured according to response information of the privacy information acquisition request. Prior to acquisition of privacy information of the user, the user chooses whether a system is permitted to collect the privacy information, and an authority of the user is configured according to the privacy information permitted by the user. A user is provided with a corresponding operation authority while privacy of the user can be protected from being infringed, and the privacy of the user can be prevented from being leaked.