Online Service Data Policies for Purpose-Based Access and Trust Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online services lack sufficient control over how user data is used, allowing entities to use data for unintended purposes, and users have limited visibility into the trust relationships of other users with these entities.
Innovation Solution
A system that allows users to categorize their data and specify who can use it and for what purpose, with the option to share trust information with other users, and provides interfaces to manage these permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are allowed to share data with entities, then service functionality and user convenience are improved, but user privacy and data control are worsened due to lack of fine-grained permission control
Solution Approach 1:
The permission model is segmented into multiple independent dimensions: data categories (contact info, health info, etc.), entity types (companies, organizations), and purposes (service provision, marketing, etc.). Users can independently control each dimension, allowing fine-grained data sharing control without overwhelming complexity.
Solution Approach 2:
The patent adds new dimensions to the traditional permission model by introducing purpose-based control and trust relationship visibility. Instead of simple allow/deny permissions, the system operates in a multi-dimensional space encompassing data type, entity, purpose, and trust level.
2Reliability
If users can see trust information of other users, then decision-making capability is improved, but privacy control is worsened due to additional data sharing requirements
Solution Approach 1:
The trust information itself becomes a controlled data category that can be shared or protected based on user preferences. The same permission infrastructure that controls data sharing also controls trust information sharing, allowing users to decide whether to reveal their trust relationships to others.
Solution Approach 2:
Users receive feedback about which entities other users trust, enabling informed decision-making. This feedback mechanism is itself subject to permission control, allowing users to choose whether to receive or display trust information from other users.
3Object-affected harmful factors
If permission control is made more granular, then data protection is improved, but user interface complexity is worsened
Solution Approach 1:
The complex permission control is segmented into manageable categories and purposes. Users interact with simplified interfaces for each category (contact info, health info, etc.) and each purpose (service provision, marketing, etc.), making the overall system more manageable despite the fine-grained control available.
Data Source
AI summary
An online service may maintain or create data for a user, and a user may be allowed to exert control over how the data are used. In one example, there may be several categories of data, and the user may be able to specify who may use the data, and the purpose for which the data may be used. Additionally, a user may be able to see how many of his “friends” (or other contacts) have extended trust to a particular entity, which may aid the user in making a decision about whether to extend trust to that entity. User interfaces may be provided to allow users to specify how their data are to be used.


