Server Risk Profile for Third-Party Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in configuring data sharing options with third-party applications, often accepting excessive data sharing due to complexity and time constraints, which can lead to security concerns and risks such as data leakage and unauthorized transactions.

Innovation Solution

A server system generates a risk profile based on on-device application data, including installed applications and permission levels, to configure a data sharing configuration option that specifies the types of data to be shared, ensuring secure and controlled access by third-party applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If users manually configure data sharing options for each third-party application, then data sharing control precision is improved, but user time consumption and operational complexity increase

Engineering Contradiction:
Improvedata sharing control precisionVSAvoiduser time consumption
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of application behavior and data access patterns before the user needs to make decisions. By pre-evaluating which data types are actually accessed by each third-party application and pre-configuring appropriate sharing rules based on this analysis, the system reduces the time users need to spend on manual configuration while maintaining precise control over data sharing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables automated self-service configuration of data sharing options by analyzing application behavior patterns and automatically generating appropriate sharing rules. The system serves itself by monitoring data access requests, identifying patterns, and configuring sharing permissions without requiring manual user intervention for each application, thus reducing time consumption while maintaining control precision.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If users accept default data sharing configuration options to save time, then operational complexity is reduced, but data security and privacy protection deteriorate

Engineering Contradiction:
Improveease of configurationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors and analyzes actual data access patterns by third-party applications, comparing them against the configured sharing rules. When discrepancies are detected (e.g., an application accessing data types it shouldn't have), the system provides feedback to the user and can automatically adjust permissions. This feedback mechanism ensures that even when users accept default options, the system maintains security by detecting and responding to unauthorized access attempts.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system introduces an intermediary layer between the user's data and third-party applications. This intermediary automatically evaluates data access requests, enforces sharing rules, and mediates between the user's convenience preferences and security requirements. It translates high-level user preferences into specific access controls, ensuring security is maintained without requiring users to manually configure each permission.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If third-party applications request extensive data access permissions, then application functionality is improved, but data exposure risk increases

Engineering Contradiction:
Improveapplication functionalityVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments data access permissions into fine-grained categories and types, allowing precise control over what each third-party application can access. Instead of treating data access as a single broad permission, the system divides it into specific data types (e.g., contacts, location, camera) and further segments by application, time, and usage context. This segmentation enables applications to receive only the specific permissions they need for their functionality while minimizing overall data exposure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different permission levels and access rules to different data types and different applications based on their specific needs and trust levels. Each application receives a customized permission profile tailored to its functionality requirements, rather than a uniform permission set. This local quality approach ensures that each application gets the minimum necessary access while maintaining security across the entire system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12021876B2Systems and methods for controlling third-party access of protected data
Publication Date: 2024.06.25 THE TORONTO DOMINION BANK
  • US12021876B2 patent drawing
  • US12021876B2 patent drawing
  • US12021876B2 patent drawing

AI summary

A server comprises a communications module, a processor coupled to the communications module, and a memory coupled to the processor, the memory storing processor-executable instructions which, when executed, configure the processor to receive, via the communications module and from a monitoring application installed on a remote computing device, on-device application data, generate a risk profile for a user based at least on the on-device application data, configure a data sharing configuration option for sharing data associated with the user based on the risk profile for the user, and share the data based on the data sharing configuration option.