Privacy Agent Encoding for Social Media Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of public online services face privacy risks due to the access of their content by social networking sites, third-party applications, and advertisers, as open APIs can circumvent access control settings, making user data vulnerable to data mining and privacy issues.

Innovation Solution

A system and method that allows end-users to encode content before posting, using a privacy agent to intercept and encrypt data, with a policy server governing access, ensuring only authorized viewers can decrypt and access the content, and enabling users to control who sees their posts by managing access policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If open APIs are provided to enable third-party integration, then site functionality and user experience are enhanced, but user data becomes vulnerable to data mining and privacy violations

Engineering Contradiction:
Improvethird-party integration capabilityVSAvoiddata privacy vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an API gateway as an intermediary component between third-party applications and user data. This gateway enforces access control policies, authentication mechanisms, and data protection rules, allowing third-party integration while preventing direct access to sensitive user information. The gateway acts as a mediator that enables functionality while blocking harmful data mining activities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and authorization checks before any third-party application can access user data. Access control policies are established and enforced in advance, requiring third-party applications to prove their identity and purpose before being granted any level of access. This preliminary action prevents unauthorized data access while maintaining open integration capabilities.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If access control settings are provided to restrict user data viewing, then user privacy is protected, but open APIs can circumvent these settings

Engineering Contradiction:
Improveprivacy protection levelVSAvoidAPI accessibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements a feedback mechanism where the API gateway continuously monitors and enforces access control policies. When a third-party application requests access, the system checks against established privacy settings and user preferences, providing real-time feedback by granting or denying access based on policy compliance. This ensures access control settings cannot be circumvented while maintaining API accessibility for authorized applications.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent makes access control settings dynamic and adaptable rather than static. The system can adjust access permissions in real-time based on user actions, context, and policy requirements. This dynamic approach allows open APIs to remain accessible while adaptively enforcing privacy protections, as the system can respond to changing conditions and prevent circumvention attempts.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If user data is made accessible to third parties for service enhancement, then platform functionality improves, but users lose control over their own content

Engineering Contradiction:
Improveplatform functionalityVSAvoiduser content control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent empowers users with self-service capabilities to manage their own data access permissions. Users can directly control which third-party applications access their data, modify these permissions at any time, and revoke access when desired. This self-service approach maintains user control over content while allowing platform functionality to be enhanced through authorized third-party integrations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent requires preliminary user consent and authorization before any third-party application can access user data. Users are presented with clear permission requests that explain what data will be accessed and by whom, allowing them to make informed decisions. This preliminary action ensures users retain control over their content while enabling platform functionality enhancements through authorized access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10552636B2Security systems and methods for encoding and decoding digital content
Publication Date: 2020.02.04 ESW HOLDINGS INC
  • US10552636B2 patent drawing
  • US10552636B2 patent drawing
  • US10552636B2 patent drawing

AI summary

Systems and methods may be provided for masking data on public networks. At a publishing node, the system may monitor data input fields in a webpage, and intercept and encode content, such as text, images, and video input at the data input fields, prior to the content being posted online on a public service provider's website. A policy may be defined to control which users are permitted access to a key to decode the encoded content. The policy may defer to a third party policy node in determining key access. An account for a controlling entity, such as a guardian or employer, may be configured to control the encoding status of posts made by another. The controlling entity may control who has key access to decode posts made by the other account. The guardian account may be configured to have preemptive rights over posting decisions made by the minor.