User Data Access Control With Blocking and Anonymization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for granting access to user data lack transparency, irreversibility, and provide weak protection against tracking by third-party applications, compromising user privacy.

Innovation Solution

A system and method that includes a blocker to block unauthorized data processing, a data collector to transfer data to a storage device, a data access rights manager to determine and manage access rights, and an anonymizer to protect user identities, ensuring secure and transparent data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is collected and distributed around the network without controlled access mechanisms, then data availability and processing efficiency are improved, but user privacy protection and security deteriorate

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiduser privacy exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary access control system that mediates between data collection needs and privacy protection requirements. This system acts as a gateway that allows data to be collected and processed while enforcing access rights and authentication protocols, thus maintaining productivity while protecting user privacy from harmful exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments data access rights into different levels and categories, allowing fine-grained control over who can access what data. By dividing access permissions into granular segments rather than treating all data access uniformly, the system enables efficient data processing for authorized purposes while preventing unauthorized privacy violations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control mechanisms are implemented to protect user privacy, then security and privacy protection are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improveprivacy protection reliabilityVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by establishing access control policies and authentication mechanisms before data access occurs. By pre-configuring access rights, authentication credentials, and permission structures in advance, the system ensures reliable privacy protection without adding complexity during actual data operations, as the control framework is already in place.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If third-party applications are granted broad access to user data for functionality purposes, then application functionality and user service quality are improved, but vulnerability to tracking and data misuse increases

Engineering Contradiction:
Improveapplication functionalityVSAvoidtracking vulnerability
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by granting different access rights to different third-party applications based on their specific functionality needs. Instead of providing blanket access to all data, each application receives only the specific data portions and access levels required for its intended function, thereby maintaining ease of operation while reducing tracking vulnerability through localized, purpose-specific access permissions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3975025B1System and method of granting access to data of a user
Publication Date: 2025.07.30 AO KASPERSKY LAB
  • EP3975025B1 patent drawingFigure 1
  • EP3975025B1 patent drawingFigure 2
  • EP3975025B1 patent drawingFigure 2a

AI summary

Disclosed herein are systems and methods for granting access to data of a user. An exemplary method comprises: blocking the processing of data of a user, transferring the data of the user to a storage device, receiving a request for data processing from a collected data processor of a device, redirecting the received request to the storage device, determining, by the storage device, data access rights for the collected data processor of the device from which the request for data processing is received in accordance with data access rights established by a data access rights manager, and providing access to the data in accordance with the determined data access rights.