Application privacy scanning systems and related methods

US12164667B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12164667-B2
Application numberUS-202217743749-A
CountryUS
Kind codeB2
Filing dateMay 13, 2022
Priority dateJun 10, 2016
Publication dateDec 10, 2024
Grant dateDec 10, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An application privacy analysis system is described, where the system obtains an application and analyzes it for privacy related data use. The system may determine privacy related activities of the application from established sources of such data and/or may decompile the application and analyze the resulting code to determine the privacy related activities of the application. The system may execute the application and monitor the communications traffic exchanged by the application to determine privacy related activities of the application. The system may store the results of such analyses for future reference.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: analyzing privacy-related information for a software application on a remote device to generate privacy-related reports to improve privacy compliance of the software application by: processing, by computing hardware, computer code for the software application on the remote device to determine that the software application collects, requests, or accesses personal data; analyzing, by the computing hardware and based on processing the computer code, the computer code to determine permissions required for the software application by: preparing the software application for analysis via an application intake; reducing the computer code of the software application to machine code by utilizing an application decompiler; and determining that the computer code uses the permissions to gain access to at least one of device hardware, device storage, or device data of the remote device on which the software application is executing via a static analysis of the computer code; analyzing, by the computing hardware, a database using the permissions to determine that the software application utilizes the permissions that involves use of personal data of a user in association with using the software application to perform at least one of a privacy-related function, access a privacy-related attribute, or access a privacy-related characteristic for the permissions that involves use of personal data of a user in association with using the software application; generating, by the computing hardware, a privacy-related recommendation of the software application for addressing the use of at least one of performing the privacy-related function, accessing the privacy-related attribute, or accessing the privacy-related characteristic for the permissions; and providing, by the computing hardware, a graphical user interface for displaying the privacy-related recommendation on a computing device, the privacy-related recommendation indicating the privacy compliance of the software application. 2. The method of claim 1 , wherein the device hardware comprises at least one of permissions to access a camera, a microphone, a receiver, or a transmitter of the remote device. 3. The method of claim 1 , wherein the device data comprises at least one of photographs, a calendar, contacts, or location determination residing on the remote device. 4. The method of claim 1 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the remote device. 5. The method of claim 1 , wherein analyzing the computer code to determine the permissions required for the software application comprises: identifying use of an application programming interface call within the software application configured to access the personal data of the user. 6. The method of claim 1 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to transmit the personal data of the user. 7. The method of claim 6 , further comprising: determining, by the computing hardware, a geographical destination where the personal data is transmitted; and determining, by the computing hardware, at least one of an applicable privacy law or a privacy regulation on transmitting the personal data based on the geographical destination, wherein the privacy-related recommendation is based on the applicable privacy law or the privacy regulation. 8. A system comprising: a non-transitory computer-readable medium storing instructions; and a processing device communicatively coupled to the non-transitory computer-readable medium, wherein, the processing device is configured to execute the instructions and thereby perform operations comprising: analyzing privacy-related information for a software application on a remote device to generate privacy-related reports to improve privacy compliance of the software application by: processing computer code for the software application on the remote device to determine that the software application collects, requests, or accesses personal data; analyzing, based on processing the computer code, the computer code to determine permissions required for the software application by: preparing the software application for analysis via an application intake; reducing the computer code of the software application to machine code by utilizing an application decompiler; and determining that the computer code uses the permissions to gain access to at least one of device hardware, device storage, or device data of the remote device on which the software application is executing via a static analysis of the computer code; analyzing a database using the permissions to correlate the permissions to determine that the software application utilizes the permissions that involves use of personal data of a user in association with using the software application to perform at least one of a privacy-related function, access a privacy-related attribute, or access a privacy-related characteristic for the permissions that involves use of personal data of a user in association with using the software application; generating a privacy-related recommendation of the software application for addressing the use of at least one of performing the privacy-related function, accessing the privacy-related attribute, or accessing the privacy-related characteristic for the permissions; and providing a graphical user interface for displaying the privacy-related recommendation on a computing device, the privacy-related recommendation indicating the privacy compliance of the software application. 9. The system of claim 8 , wherein the device hardware comprises at least one of permissions to access a camera, a microphone, a receiver, or a transmitter of the remote device. 10. The system of claim 8 , wherein the device data comprises at least one of photographs, a calendar, contacts, or location determination residing on the remote device. 11. The system of claim 8 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the remote device. 12. The system of claim 8 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to access the personal data of the user. 13. The system of claim 8 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to transmit the personal data of the user. 14. The system of claim 13 , wherein the operations further comprise: determining a geographical destination where the personal data is transmitted; and determining at least one of an applicable privacy law or a privacy regulation on transmitting the personal data based on the geographical destination, wherein the privacy-related recommendation is based on the applicable privacy law or the privacy regulation. 15. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more process

Assignees

Inventors

Classifications

  • Indexing; Data structures therefor; Storage structures (for retrieval from the web G06F16/951) · CPC title

  • Browsing; Visualisation therefor (for navigating the web G06F16/954; browsing optimisation for the web G06F16/957) · CPC title

  • Details of hyperlinks; Management of linked annotations · CPC title

  • Test or assess software · CPC title

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12164667B2 cover?
An application privacy analysis system is described, where the system obtains an application and analyzes it for privacy related data use. The system may determine privacy related activities of the application from established sources of such data and/or may decompile the application and analyze the resulting code to determine the privacy related activities of the application. The system may ex…
Who is the assignee on this patent?
Onetrust Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Dec 10 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).