Mobile Privacy Risk Assessment via Test Input Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of mobile devices are at risk of privacy invasion and fraud due to applications accessing and transmitting personal data without their knowledge or permission, as existing technologies fail to effectively assess and mitigate these risks.

Innovation Solution

A system comprising a hardware processor that determines a risk indicator for target applications by supplying a test input to a data field holding a private item, assessing whether the application would transmit this data, and employing a security server for risk assessment transactions to identify privacy risks, thereby protecting users from privacy-invasive behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are allowed to access and transmit personal data freely, then application functionality and data utility are improved, but user privacy security deteriorates

Engineering Contradiction:
Improveapplication functionalityVSAvoidprivacy security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary risk assessment by supplying test inputs to applications before they are executed by users. The security server evaluates applications by attempting to extract private items through test executions, identifying privacy risks in advance before the application runs on the user's device.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A security server acts as an intermediary between the application store and the user's mobile device. The server receives applications, performs risk assessments by executing test inputs, and returns risk indicators to the user's device, mediating the interaction between applications and users to protect privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If comprehensive privacy risk assessment is performed on all applications, then user privacy protection is improved, but system complexity and processing time worsen

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The complex privacy risk assessment functionality is extracted from individual user devices and centralized on a dedicated security server. This allows comprehensive privacy protection to be implemented without increasing the complexity of user devices, as the assessment infrastructure is separated and provided as a service.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of performing comprehensive assessments on every user device, the system creates a virtual copy or representation of the assessment process on the security server. The server executes test inputs and generates risk indicators that are then distributed to multiple user devices, avoiding redundant complex processing on each device.

Inventive Principle:
Principle #26Copying

3Measurement precision

If test inputs are supplied to evaluate private item disclosure, then privacy risk detection precision is improved, but application execution time worsens

Engineering Contradiction:
Improverisk detection precisionVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system supplies test inputs targeting specific private item fields rather than exhaustive testing of all possible data paths. By focusing assessment on critical private information fields (such as personal identifiers, contact information, and sensitive data), the system achieves adequate risk detection precision without requiring complete exhaustive testing of every application function.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9830459B2Privacy protection for mobile devices
Publication Date: 2017.11.28 BITDEFENDER IPR MANAGEMENT
  • US9830459B2 patent drawing
  • US9830459B2 patent drawing
  • US9830459B2 patent drawing

AI summary

Described systems and methods allow a mobile device, such as a smartphone or a tablet computer, to protect a user of the respective device from fraud and/or loss of privacy. In some embodiments, the mobile device receives from a server a risk indicator indicative of whether executing a target application causes a privacy risk. Determining the risk indicator includes automatically supplying a test input to a data field used by the target application, the data field configured to hold a private item such as a password or a geolocation indicator. Determining the risk indicator further comprises determining whether a test device executing an instance of the target application transmits an indicator of the test input, such as the test input itself or a hash of the test input, to another party on the network.