In-Private Mode Virtual Machine Data Obscuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of personal computing devices face challenges in maintaining privacy and control over the data collected by applications and services, as existing methods are cumbersome, invasive, or require disabling essential device features.

Innovation Solution

The implementation of an 'in-private mode' (IPM) on user devices, which allows users to selectively control and obscure user-activity related data, enabling applications to function while preserving privacy by using a quarantine environment and modifying data to prevent user identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If users manually review and delete user activity data, then privacy control is improved, but operation complexity and time consumption increase significantly

Engineering Contradiction:
Improveprivacy data exposureVSAvoidmanual data review complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system automatically manages privacy protection by creating and deleting virtual machines without user intervention. The privacy management component autonomously provisions VMs based on detected privacy requests, configures them with appropriate data collection restrictions, and cleans up resources after the request expires, eliminating the need for manual data review and deletion by users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system proactively creates virtual machines and configures data collection restrictions before users need privacy protection. When a privacy request is detected, the system immediately provisions a VM with pre-configured data collection policies, ensuring privacy protection is in place before any data exposure can occur.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If users disable location detection and other features to protect privacy, then data collection is reduced, but device functionality and application performance deteriorate

Engineering Contradiction:
Improvepersonal data collectionVSAvoidapplication functionality
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system segments device functionality into different environments: a normal mode for full functionality and a virtual machine mode for restricted data collection. Applications can run in either mode, allowing users to maintain full functionality when needed while protecting privacy when required, without permanently disabling any device features.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual machine acts as an intermediary layer between applications and the device's data collection systems. Within the VM, applications can access modified or restricted data that protects user privacy while still enabling necessary functionality. The VM mediates between the need for data collection and the need for privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If users leave their computing device at home to maintain privacy, then data exposure is eliminated, but device accessibility and usability are lost

Engineering Contradiction:
Improveuser data exposureVSAvoiddevice accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system provides privacy protection as a self-service feature that activates automatically when needed. Users simply launch applications in privacy mode, and the system autonomously creates virtual machines, configures data collection restrictions, and manages the entire privacy protection process, eliminating the need to leave the device at home while maintaining data security.

Inventive Principle:
Principle #25Self-service

4Productivity

If applications require user data to function properly, then application performance is maintained, but user privacy and control over data are reduced

Engineering Contradiction:
Improveapplication operationVSAvoiduser data exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system applies different data collection policies to different contexts and applications. Within the virtual machine, applications receive modified data that protects user privacy, while the VM itself maintains the necessary functionality to run applications. This allows localized privacy protection without compromising overall system operation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes data parameters and collection policies dynamically based on the operational context. When running in privacy mode, the system modifies data parameters to protect user privacy while maintaining sufficient information for applications to function. The privacy management component adjusts data collection parameters in real-time based on the active virtual machine configuration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11790109B2Privacy control operation modes
Publication Date: 2023.10.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11790109B2 patent drawing
  • US11790109B2 patent drawing
  • US11790109B2 patent drawing

AI summary

Technology is disclosed for improving user privacy and providing user control over user-activity data collected from personal computing devices (i.e., user devices). User devices may be configured to operate in a private mode that enables a user to control, for example, which aspects of user-activity data are provided to applications and services running on their user device; to obscure or modify aspects of user-activity data so that certain applications and services, which may require this information to operate, may still function, but that the obscured information provided to these applications and services preserves user privacy or no longer may be used to identify the user; or to remove evidence of user-activity data created, monitored, reported, or otherwise collected by or on the user device while the user is operating their user device in the private mode setting.