Privacy Manager Mediating Sensor Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively maintain user privacy in devices equipped with sensors, as they often reveal personal information when accessing location and contextual data, compromising user anonymity and privacy.

Innovation Solution

A privacy management system that determines requests for access to local data, processes privacy profile objects, and enforces privacy policies to control the granularity and access of sensitive information, using remote programmable objects and transformation rules to protect user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If sensor data is accessed to provide navigation and video conferencing services, then service functionality is improved, but user privacy and anonymity are compromised

Engineering Contradiction:
Improveservice functionalityVSAvoidprivacy compromise
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a privacy manager as an intermediary component that sits between sensor data collection and application access. This privacy manager evaluates privacy policies, determines whether data access is permitted, and mediates the flow of sensitive information to applications, thereby enabling service functionality while protecting user privacy through policy-based control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data access control mechanism into distinct components: privacy policies, privacy profile objects, and enforcement rules. This segmentation allows granular control over different types of sensor data (location, images, sound) and enables selective access based on specific privacy rules for each data type and application

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If detailed location information is provided to applications, then navigation accuracy is improved, but user anonymity is reduced

Engineering Contradiction:
Improvelocation accuracyVSAvoidanonymity
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies local quality by allowing different levels of data granularity for different applications and contexts. The privacy manager can permit high-precision location data for navigation applications while providing only coarse location information to other applications, thereby maintaining anonymity where full precision is not required while preserving accuracy where needed

Inventive Principle:
Principle #3Local quality

3Productivity

If comprehensive data access is granted to applications, then service quality is improved, but privacy policy enforcement complexity increases

Engineering Contradiction:
Improveservice qualityVSAvoidpolicy enforcement complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-defining privacy policies and privacy profile objects that encode access rules before data requests occur. These policies are established in advance and stored in the privacy manager, allowing automated enforcement decisions to be made quickly without complex real-time analysis, thereby reducing enforcement complexity while maintaining comprehensive control

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2681687B1Method and apparatus for enforcing data privacy
Publication Date: 2024.12.18 NOKIA TECHNOLOGIES OY
  • EP2681687B1 patent drawingFigure 1
  • EP2681687B1 patent drawingFigure 2
  • EP2681687B1 patent drawingFigure 3

AI summary

An approach for maintaining user privacy information is described. A privacy management platform determines a request, from one or more applications, for access to local data associated with a device. The platform then determines and processes one or more privacy profile objects associated with the local data to determine one or more privacy policies associated with the local data, the device, or a combination thereof. Enforcement of the one or more privacy policies is then caused for granting access to the local data.