User-Centric Data Maintenance via OS Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely aggregating and sharing user-centric data across various apps, posing security and privacy risks due to unauthorized access and exposure of personal information.
Innovation Solution
A system where an operating system acts as a trusted broker, defining user-centric profiles based on user-defined data from various apps, restricting unauthorized access by exposing only necessary information to requestor apps after satisfying specific access criteria, and facilitating actions while keeping sensitive data secure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user centric data is aggregated and shared between apps, then data accessibility and functionality are improved, but security and privacy risks increase due to unauthorized access
Solution Approach 1:
The operating system acts as an intermediary between data provider apps and requestor apps. It defines user centric profiles that contain user centric data, controls access to these profiles through access criteria evaluation, and facilitates actions without exposing sensitive data to unauthorized apps. This mediator approach enables data sharing while maintaining security by filtering and controlling what information is exposed to which apps.
2Ease of operation
If all user centric data is exposed to requestor apps, then app functionality is enhanced, but unauthorized access to sensitive information occurs
Solution Approach 1:
The system implements local quality by providing different levels of data access to different apps based on their specific needs and authorization. Each user centric profile can have different access criteria for different requestor apps, allowing each app to receive only the specific portions of data it requires for its function, rather than exposing all data universally. This enables tailored data sharing that enhances functionality while protecting sensitive information.
3Reliability
If access criteria are implemented for user centric profiles, then security is improved, but system complexity increases
Solution Approach 1:
The system implements self-service by enabling data provider apps to define their own access criteria for their user centric profiles. Apps can specify which portions of their data should be accessible to which requestor apps under what conditions. This self-defined access control mechanism reduces the burden on the operating system to manage complex access rules centrally, while still providing comprehensive security through distributed access policy management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
One or more techniques and/or systems are provided for dynamically maintaining user centric data. For example, a data provider app may have knowledge about user centric data associated with a user (e.g., a social network app may have contact information for a social network friend of the user). A user centric profile may be defined for the user centric data based upon information provided by the data provider app (e.g., a contact card may be generated for the social network friend). Responsive to receiving a request for the user centric profile from a requestor app (e.g., an event planning app), the user centric profile may be exposed to the user but not to the requestor app for security and/or privacy purposes. For example, an operating system may present at least some of the user centric profile within an operating system user interface.