Personal Data Manager Mediator for User Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current personal data management systems are fragmented, redundant, and lack user control, leading to inconsistent and unreliable data due to an application-centric paradigm, where personal data is collected and stored independently by various applications without transparency or user oversight.

Innovation Solution

A user-centric personal data management system that creates certifications for applications, allowing users to define policies for data access and storage, ensuring compliance with user-defined rules, and providing a secure digital space for data management, including real-time data monitoring and logging of data access and usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications independently collect and store personal data without centralized management, then applications can access data quickly and operations are simple, but data becomes fragmented, redundant, and unreliable across different applications

Engineering Contradiction:
ImproveApplication data access simplicityVSAvoidData consistency and reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Personal Data Manager (PDM) as an intermediary component that sits between applications and personal data. The PDM mediates all data access requests, enforcing user policies and maintaining data consistency. This intermediary structure allows applications to access data through a standardized interface while preventing data fragmentation and ensuring reliability across the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If applications independently manage personal data without user oversight, then data access is fast and straightforward, but users lose control over their personal data and transparency is reduced

Engineering Contradiction:
ImproveData access efficiencyVSAvoidUser control and transparency
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements a user-centric architecture where users directly control their personal data through the Personal Data Manager. Users can define policies, grant permissions, and monitor data access independently. The system provides self-service capabilities allowing users to manage their own data without requiring application developer intervention, thus maintaining both efficiency and user control.

Inventive Principle:
Principle #25Self-service

3Reliability

If a centralized system manages all personal data access with user policies and certifications, then data integrity and user control are improved, but system complexity increases

Engineering Contradiction:
ImproveData integrity and user controlVSAvoidSystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data management system into distinct modular components: a Personal Data Manager for policy enforcement, an APP registry for certification management, and policy modules for access control. This segmentation allows each component to perform its specific function independently, reducing overall system complexity while maintaining data integrity and user control through specialized functionality.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10776510B2System for managing personal data
Publication Date: 2020.09.15 TELECOM ITALIA SPA
  • US10776510B2 patent drawing
  • US10776510B2 patent drawing
  • US10776510B2 patent drawing

AI summary

A method for managing personal data of a user of a user device is provided. The user device is adapted to have installed thereon an application (APP). The APP is configured to require access to the personal data when running on the user device. The method comprises creating a certification for the APP, the certification being based on a corresponding statement providing information regarding the relationship between the APP and personal data; associating the certification to the APP for certifying the APP; allowing the user to provide user-defined policies about exploiting the user personal data; checking whether the user-defined policies provided by the user are compatible with requirements of the APP defined in the corresponding statement. If the user-defined policies are compatible with the requirements of the APP defined in the statement, the method executes operations when the APP running on the user device requires to access personal data.