Privacy Rules Engine for Wireless Customer Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing customer data privacy in wireless telephony services lack effective mechanisms to restrict access based on user-defined categories and roles, failing to adequately enforce privacy regulations and customer preferences.

Innovation Solution

A method and system for managing customer data privacy that assigns roles to entities accessing the data, determines access levels based on data categories, and uses a data retriever component to authenticate and authorize access, ensuring compliance with privacy rules and regulations by employing a data store and permissions data store to enforce access restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access to customer data is restricted based on roles and categories, then data security and privacy compliance are improved, but system complexity increases due to the need for authentication and authorization mechanisms

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments customer data into multiple categories (e.g., personal information, financial data, communication records) and assigns different access levels to different roles. This segmentation allows fine-grained control over data access, improving security without requiring a complete system redesign. Each data category can be independently managed with appropriate access restrictions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication and authorization system that sits between applications and customer data. This intermediary component (the privacy rules engine) mediates access requests by evaluating roles, categories, and access levels, thereby improving data security while isolating the complexity within a dedicated module rather than distributing it throughout the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple access levels are defined for different roles and data categories, then privacy rule enforcement is improved, but the difficulty of detecting and measuring authorization requirements increases

Engineering Contradiction:
Improveprivacy rule enforcementVSAvoidauthorization level detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary action by pre-defining roles, data categories, and access levels before actual data access occurs. Authorization rules are established in advance, mapping specific roles to specific access levels for each data category. This preliminary configuration simplifies runtime authorization detection, as the system only needs to evaluate pre-established rules rather than complex authorization logic during data access operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If role-based access control is implemented for customer data, then compliance with privacy regulations is improved, but device complexity increases due to additional authentication components

Engineering Contradiction:
Improveregulatory complianceVSAvoidauthentication components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal role-based access control framework that can be applied across multiple applications and data types. The authentication and authorization system serves multiple functions: it validates user identities, determines appropriate access levels, enforces privacy rules, and generates audit trails. This multi-functionality consolidates what could be separate complex components into a unified system, improving regulatory compliance while managing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7853786B1Rules engine architecture and implementation
Publication Date: 2010.12.14 T MOBILE INNOVATIONS LLC
  • US7853786B1 patent drawing
  • US7853786B1 patent drawing
  • US7853786B1 patent drawing

AI summary

A system for customer data privacy management is provided. The system includes a data store having customer data and privacy rules associated with the customer data, a rules engine that limits access to the customer data, an application to provide a service related to the customer data, and an interface in communication with the application and the rules engine. The rules engine promotes limiting access to customer data based on the service of the application and the privacy rules associated with the customer data. The customer data includes mobile location information and positioning information. The service of the application may be further defined as a mobile location service. The customer data includes a buddy list and one or more of the privacy rules can be associated with the buddy list to limit access by one or more applications to the buddy list.