Personal Information Risk Identification via Granular Permission Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing concern of personal data breaches due to excessive and irrelevant permission requests by mobile apps, leading to potential identity theft and economic losses, necessitates a more robust method for risk identification and management of personal information in the digital economy.
Innovation Solution
A method and system for risk identification of personal information that involves generating and managing specifications for data usage, collecting and storing user consent information, monitoring data storage and processing processes, and providing monitoring functions for data stored on service/platform provider sides, utilizing blockchain for data integrity and user control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile apps request excessive permissions to provide services, then service functionality is improved, but personal information security deteriorates
Solution Approach 1:
The patent segments permission management into granular levels, allowing users to grant specific permissions individually rather than all-or-nothing. The system divides data access rights into multiple permission types (e.g., read-only, write-access, share permissions) that can be independently controlled, enabling services to function with minimal necessary permissions while protecting personal information from excessive access.
Solution Approach 2:
The patent implements continuous feedback mechanisms where the system monitors and tracks permission usage in real-time. Users receive notifications and alerts when apps attempt to access permitted data, allowing them to revoke permissions dynamically. The system provides feedback reports showing which apps accessed which data, enabling informed decision-making about permission management.
2Productivity
If comprehensive data collection is performed to improve service quality, then user experience is improved, but risk of data breaches increases
Solution Approach 1:
The patent implements preliminary risk assessment and permission validation before data collection occurs. The system pre-evaluates whether data collection is necessary for the stated service purpose, pre-establishes encryption protocols, and pre-configures access controls. By performing these protective actions beforehand, the system enables comprehensive data collection for service quality while mitigating breach risks through预先 established security measures.
Solution Approach 2:
The patent introduces an intermediary permission management layer between the app and user data. This intermediary system acts as a broker that validates data access requests, enforces permission policies, and monitors data flows. The intermediary enables service providers to access comprehensive data when necessary while maintaining security controls that prevent unauthorized access and reduce breach risks.
3Object-affected harmful factors
If strict permission control is implemented to protect personal information, then information security is improved, but service functionality deteriorates
Solution Approach 1:
The patent implements dynamic permission management where access rights are not fixed but adapt based on context, user choices, and service requirements. Permissions can be granted temporarily for specific operations, adjusted based on user behavior patterns, and revoked when no longer needed. This dynamic approach maintains strong security controls while enabling service functionality by providing appropriate access when and where necessary.
Solution Approach 2:
The patent changes the parameters of permission control from binary (granted/not granted) to multi-dimensional, including time-based validity, operation-specific scope, and conditional access rules. By adjusting these parameters, the system can provide fine-grained control that protects personal information while maintaining service functionality through flexible, context-aware permission configurations.
4Reliability
If user consent management is enhanced to comply with regulations, then regulatory compliance is improved, but system complexity increases
Solution Approach 1:
The patent merges consent management functionality directly into the existing permission management system rather than creating a separate complex subsystem. By combining consent tracking, permission granting, and data access control into a unified framework, the system achieves regulatory compliance (such as GDPR requirements for explicit user consent) while avoiding the complexity of redundant separate systems. The integrated approach shares common infrastructure for user authentication, data tracking, and access control.
Data Source
AI summary
In some embodiments, a method for risk identification of personal information of a service/platform provider side is provided. A specification is received related to data usage for at least one among service and application of a third party side from a device of the third party side, and is stored in data storage of the service/platform provider side. User consent information is received from a user side using at least one among the service and application. The received information is stored in the data storage of the service/platform provider side. A process is inspected and monitored related to data storing and processing in user environment or platform environment of the user side using at least one among the service and application. A monitoring function is provided for data stored in the data storage of the service/platform provider side in connection with at least one among the service and application.


