Stalkerware Data Protection via Safety Plan Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for protecting data from stalkerware do not adequately address the unique safety needs of users in different situations, particularly those living with an abuser, as they may pose physical danger when attempting to remove stalkerware or require customized approaches to mitigate its effects without alerting the abuser.

Innovation Solution

A computer-implemented method that identifies stalkerware on a device, determines its transmission of private data to unauthorized devices, and allows users to select from customized safety plan options such as deleting, filtering, or spoofing data, based on their specific situation, to protect their data and safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated removal of stalkerware is implemented, then data protection effectiveness is improved, but user physical safety deteriorates when abuser is nearby

Engineering Contradiction:
Improvedata protection effectivenessVSAvoiduser physical safety
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts the stalkerware removal process based on real-time assessment of user safety conditions. When the abuser is determined to be nearby or posing physical threat, the system transitions from automated removal to controlled mitigation modes, allowing users to maintain stalkerware presence while protecting data through filtering and spoofing techniques.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameters of stalkerware interaction based on threat level. Instead of binary remove/keep decision, it implements gradient response levels: full removal when safe, partial removal with filtering when moderate risk, and spoofing mode when high risk. This transforms the protection mechanism from static to adaptive based on contextual parameters.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If stalkerware is completely removed from device, then data privacy is improved, but user safety deteriorates when living with abuser

Engineering Contradiction:
Improvedata privacyVSAvoiduser safety
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system introduces intermediary mechanisms between the user and stalkerware. Instead of direct removal or direct access, it implements data filtering layers and spoofing intermediaries that intercept and modify data flows. These intermediaries allow stalkerware to remain installed while preventing actual data exfiltration to the abuser.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system converts the harmful presence of stalkerware into a beneficial protective tool. By allowing stalkerware to remain installed under controlled conditions, it creates a decoy system that maintains the appearance of normal operation while actually protecting user data through filtering and spoofing. The harmful element becomes part of the protection strategy.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Object-affected harmful factors

If customized safety plans are implemented, then user safety is improved, but system complexity increases

Engineering Contradiction:
Improveuser safetyVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system segments the safety plan into distinct modular components: assessment module, filtering module, spoofing module, and emergency contact module. Each component operates independently and can be activated based on specific conditions. This modular architecture reduces complexity by allowing selective activation of only necessary functions rather than requiring all features to be simultaneously managed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary safety assessment and plan generation before actual threats materialize. During setup, users complete safety questionnaires and define preferences in advance. When threats are detected, the pre-configured safety plans are automatically activated, eliminating the need for complex real-time decision-making and reducing operational complexity during critical moments.

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If data filtering and spoofing are used instead of removal, then user safety is improved, but data protection effectiveness may deteriorate

Engineering Contradiction:
Improveuser safetyVSAvoiddata protection effectiveness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system applies partial data protection by filtering only the most critical data types (location, communications, financial information) while allowing less sensitive data to pass through. This selective filtering approach balances safety requirements with data protection effectiveness, protecting against immediate physical threats while maintaining normal device functionality and user awareness of data exposure.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11816209B1Systems and methods for protecting data on devices
Publication Date: 2023.11.14 GEN DIGITAL INC
  • US11816209B1 patent drawing
  • US11816209B1 patent drawing
  • US11816209B1 patent drawing

AI summary

A computer-implemented method for protecting data on devices may include (i) identifying a device that is operated by a user and that comprises private data pertaining to the user, (ii) determining that stalkerware on the device is sending the private data to an unauthorized device not operated by the user, (iii) requesting, in response to determining that the stalkerware is sending the private data to the unauthorized device, that the user select at least one safety plan step from a set of safety plan options, and (iv) modifying, at least in part based on the safety plan step selected by the user, outgoing data sent by the stalkerware to the unauthorized device. Various other methods, systems, and computer-readable media are also disclosed.