Privacy Risk Assessment Engine for Application Code Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for identifying privacy risks in applications exchanging private information over networks are inadequate, as they rely on high-level visual inspections rather than code analysis, leading to inaccurate risk assessments and holistic evaluations.

Innovation Solution

A system comprising a privacy risk assessment device that automatically identifies and assesses privacy risks in application code by analyzing risk impact and likelihood, using a client device to capture risk information and a network to facilitate communication, and a storage device to store risk scores and remediation options.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional high-level visual inspection methods are used to identify privacy risks, then the assessment process is simple and quick, but the accuracy and detail of risk identification are insufficient

Engineering Contradiction:
Improverisk identification accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces manual visual inspection with automated code analysis using natural language processing and machine learning models. The system processes application code, data flow, and user interactions automatically to identify privacy risks, substituting human expert analysis with computational methods that provide consistent, scalable, and accurate risk detection without requiring manual intervention in each assessment case.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary assessment system that acts as a bridge between raw application code and final risk conclusions. This intermediary layer includes multiple analysis modules (code analysis, data flow analysis, user interaction analysis) that process information through structured pipelines, enabling accurate risk identification while maintaining system organization and manageability despite the complexity of automated analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If automated code analysis is implemented for privacy risk assessment, then risk identification accuracy improves, but the complexity of the assessment system increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem structural complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the privacy risk assessment system into distinct modular components: code analysis module, data flow analysis module, user interaction analysis module, risk calculation module, and reporting module. Each module performs a specific function and processes data independently before passing results to the next stage. This segmentation enables the system to handle complex analysis tasks while maintaining structural organization, facilitating easier maintenance, and allowing individual modules to be developed and optimized independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs multiple analysis parameters and metrics at different stages of the assessment process, including code structure parameters, data flow parameters, user interaction parameters, and risk scoring parameters. The system dynamically adjusts which parameters are analyzed based on the specific application being assessed, enabling accurate risk identification while managing computational complexity through selective parameter evaluation rather than analyzing all possible parameters uniformly.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If comprehensive privacy risk analysis is performed, then the detail and thoroughness of risk assessment improve, but the time and resources required increase

Engineering Contradiction:
Improverisk information completenessVSAvoidassessment time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis of application code, data structures, and user interactions before conducting the full privacy risk assessment. The system pre-identifies potential privacy-sensitive operations, data flows, and user permissions that require detailed examination. This preliminary action filters out low-risk areas and focuses comprehensive analysis only on identified risk zones, ensuring complete risk information is captured while reducing overall assessment time by avoiding exhaustive analysis of all code paths.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring and analysis of privacy risks throughout the application lifecycle, rather than performing discrete, time-consuming assessments. The system continuously tracks data flows, user interactions, and code changes, maintaining an updated understanding of privacy risks as the application evolves. This continuous action ensures comprehensive risk information is available in real-time without requiring periodic intensive assessment cycles that would consume significant time and resources.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10963571B2Privacy risk assessments
Publication Date: 2021.03.30 MICRO FOCUS LLC
  • US10963571B2 patent drawing
  • US10963571B2 patent drawing
  • US10963571B2 patent drawing

AI summary

Example implementations relate to privacy risk assessments. Some implementations may include a privacy risk identification engine to automatically identify privacy risks in an application based on an analysis of application code. Additionally, some implementations may include a privacy risk identification engine to obtain privacy risk information related to each of the privacy risks. Moreover, some implementations may include a privacy risk assessment engine to assess a severity of each of the privacy risks based on an analysis of the privacy risk information. In some examples, the analysis may include a determination of, for each of the privacy risks, a risk impact and a risk likelihood.