Telecom Access Management System for Third Party Application Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a concern about unauthorized access and privacy protection in telecommunication networks, particularly regarding Third Party Applications (TPAs) that offer services on behalf of users, as existing systems lack effective control over which TPAs can access user data and execute services, leading to potential misuse of sensitive information.

Innovation Solution

A method and system are implemented to control which TPAs access a user's device and define access levels, utilizing an Access Management System (AMS) that manages Third Party Applications, Mobile Device Numbers, and user permissions, allowing for secure execution of services and billing, with features like whitelisting and blacklisting to regulate access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Third Party Applications are allowed to access user devices and execute services, then service functionality and user experience are improved, but privacy protection and security control deteriorate

Engineering Contradiction:
Improveservice functionalityVSAvoidprivacy protection
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments access permissions by creating distinct permission sets for different TPAs, allowing each application to receive only the minimum necessary access rights. The system divides user data and service execution rights into granular permission units that can be selectively granted, thus enabling service functionality while protecting privacy through controlled segmentation of access rights.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary permission management system that sits between TPAs and user devices. This intermediary layer validates and controls all access requests, mediating between the need for TPA functionality and the requirement for privacy protection. The intermediary enforces permission policies, audits access, and prevents unauthorized operations, resolving the contradiction by adding a controlling layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access control mechanisms are implemented for Third Party Applications, then privacy protection and security are improved, but system complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal permission management framework that handles multiple TPAs, users, and service types through a single integrated system. The permission management module serves multiple functions: authentication, authorization, auditing, and policy enforcement across diverse applications and devices. This multi-functional approach consolidates complexity into a manageable central system rather than requiring separate control mechanisms for each TPA.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent manages complexity by dynamically changing permission parameters based on service requirements, user preferences, and security policies. The system adjusts access rights, validation strictness, and monitoring levels as parameters rather than maintaining fixed complex structures. This allows the system to adapt its complexity level to actual needs, simplifying operations when possible while maintaining protection where required.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If multiple access levels are defined for Third Party Applications, then privacy control precision is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improveprivacy control precisionVSAvoidmanagement overhead
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements dynamic access levels that can be adjusted in real-time based on service context, user actions, and security requirements. Rather than static permission levels, the system dynamically modifies access rights during operation, allowing precise control when needed while automatically reducing restrictions when safe. This dynamic approach achieves high precision control without permanent complex management structures for each access level.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies partial permission granting where TPAs receive only the specific subset of permissions needed for their function rather than comprehensive access levels. The system implements minimum necessary access for each service type, avoiding excessive permission assignments. This partial action approach achieves sufficient privacy control precision without the overhead of managing comprehensive multi-level permission systems for all possible access scenarios.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7499995B2Managing permission for accessing third party applications on a telecommunications network
Publication Date: 2009.03.03 KYNDRYL INC
  • US7499995B2 patent drawing
  • US7499995B2 patent drawing
  • US7499995B2 patent drawing

AI summary

A method and system are presented that controls which TPAs are authorized to access user data and execute services provided by a service delivery platform in a telecommunications network. The method defines a level of access authorized for each user to protect the privacy of data that populates the TPA.