Online Service Data Policies for Purpose-Based Access and Trust Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online services lack sufficient control over how user data is used, allowing entities to use data for unintended purposes, and users have limited visibility into the trust relationships of other users with these entities.

Innovation Solution

A system that allows users to categorize their data and specify who can use it and for what purpose, with the option to share trust information with other users, and provides interfaces to manage these permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to share data with entities, then service functionality and user convenience are improved, but user privacy and data control are worsened due to lack of fine-grained permission control

Engineering Contradiction:
Improveuser convenienceVSAvoiddata control complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The permission model is segmented into multiple independent dimensions: data categories (contact info, health info, etc.), entity types (companies, organizations), and purposes (service provision, marketing, etc.). Users can independently control each dimension, allowing fine-grained data sharing control without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds new dimensions to the traditional permission model by introducing purpose-based control and trust relationship visibility. Instead of simple allow/deny permissions, the system operates in a multi-dimensional space encompassing data type, entity, purpose, and trust level.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If users can see trust information of other users, then decision-making capability is improved, but privacy control is worsened due to additional data sharing requirements

Engineering Contradiction:
Improvedecision-making reliabilityVSAvoidprivacy control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trust information itself becomes a controlled data category that can be shared or protected based on user preferences. The same permission infrastructure that controls data sharing also controls trust information sharing, allowing users to decide whether to reveal their trust relationships to others.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Users receive feedback about which entities other users trust, enabling informed decision-making. This feedback mechanism is itself subject to permission control, allowing users to choose whether to receive or display trust information from other users.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If permission control is made more granular, then data protection is improved, but user interface complexity is worsened

Engineering Contradiction:
Improvedata misuse protectionVSAvoidinterface complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The complex permission control is segmented into manageable categories and purposes. Users interact with simplified interfaces for each category (contact info, health info, etc.) and each purpose (service provision, marketing, etc.), making the overall system more manageable despite the fine-grained control available.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12386983B2Data policies for online services
Publication Date: 2025.08.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12386983B2 patent drawing
  • US12386983B2 patent drawing
  • US12386983B2 patent drawing

AI summary

An online service may maintain or create data for a user, and a user may be allowed to exert control over how the data are used. In one example, there may be several categories of data, and the user may be able to specify who may use the data, and the purpose for which the data may be used. Additionally, a user may be able to see how many of his “friends” (or other contacts) have extended trust to a particular entity, which may aid the user in making a decision about whether to extend trust to that entity. User interfaces may be provided to allow users to specify how their data are to be used.