User Privacy Framework with Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for protecting user privacy in computer systems are cumbersome and lack user control, often leading to user frustration and abandonment of privacy policies, as system administrators set privacy settings uniformly for all users without individual user input.

Innovation Solution

A system and method that allows users to create and manage their own privacy policies through a user interface, using rules with conditions based on dimensions and elements, stored in a database, to control access to their information, enabling granular control over who can access their data and under what circumstances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If system administrators set privacy policies uniformly for all users, then privacy protection is simplified and easier to manage, but users lose control over their own information and cannot customize their privacy preferences

Engineering Contradiction:
Improveease of privacy policy managementVSAvoiduser control over privacy policy
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements self-service by enabling users to independently create, modify, and manage their own privacy policies through an intuitive interface. Users can define custom rules specifying which applications can access their information and under what conditions, eliminating the need for system administrator intervention and providing full control over their personal data.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If privacy frameworks allow users to control their own privacy policies, then user control and customization are improved, but the system becomes cumbersome and complex

Engineering Contradiction:
Improveuser control over privacy policyVSAvoidcomplexity of privacy policy management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by breaking down privacy policy management into discrete, manageable rules. Each rule addresses a specific application or type of information access, allowing users to control privacy on a granular level. This modular approach simplifies the interface and makes complex privacy decisions more manageable by handling one application or information type at a time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamics by allowing users to create flexible, condition-based privacy rules that can adapt to different situations. Users can specify multiple conditions for each rule (such as time of day, location, or specific actions) and modify their privacy preferences in real-time as their needs change, making the system adaptable rather than static.

Inventive Principle:
Principle #15Dynamics

3Reliability

If uniform privacy policies are implemented, then system-wide privacy protection is consistent and reliable, but individual user needs and preferences cannot be accommodated

Engineering Contradiction:
Improveconsistency of privacy protectionVSAvoidcustomization of privacy policy
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing different privacy rules to apply to different applications, information types, or user contexts. Instead of a single uniform policy, the system enables users to specify tailored privacy settings for each local context (individual application or data category), ensuring that each area of information access receives appropriate, customized protection based on user preferences.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10498766B1User privacy framework
Publication Date: 2019.12.03 GOOGLE LLC
  • US10498766B1 patent drawing
  • US10498766B1 patent drawing
  • US10498766B1 patent drawing

AI summary

A computer program product has a computer-readable storage medium having computer program instructions embodied therein for performing a method for implementing a privacy policy for a user. The method may include the user developing rules that determine whether another user (requester) can access information related to the user. The rules may be stored in a database coupled to a server and evaluated when a request is received from the requester to access the information. If a rule is satisfied by the requester, the server can return the information to the requester. The information can be returned at a level of granularity specified by the user in the satisfied rule. A privacy level can be set by the user to allow access to requesters based on the rules or to deny access to any requesters.