IP Library Granted Patent US 11,334,681
Granted Patent B2
US 11,334,681 · App. 17/463,775 · Granted May 17, 2022

Application privacy scanning systems and related meihods

Inventors: Kevin Jones (Atlanta, GA); William DeWeese (Atlanta, GA); Justin Devenish (Atlanta, GA); Saravanan Pitchaimani (Atlanta, GA); Jonathan Blake Brannon (Smyrna, GA)
Assignee: OneTrust, LLC
G06F21/6245G06F16/901G06F16/904G06F16/9558
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,334,681
App. No.
17/463,775
Granted
May 17, 2022
Kind
B2
Abstract

An application privacy analysis system is described, where the system obtains an application and analyzes it for privacy related data use. The system may determine privacy related activities of the application from established sources of such data and/or may decompile the application and analyze the resulting code to determine the privacy related activities of the application. The system may execute the application and monitor the communications traffic exchanged by the application to determine privacy related activities of the application. The system may store the results of such analyses for future reference.

Claims (34)

1. A method comprising:

determining, by computing hardware, identifying information for a mobile device application;

querying, by the computing hardware, a software development kit database using the identifying information to identify a software development kit used to generate the mobile device application;

analyzing, by the computing hardware, computer code for the mobile device application and the software development kit to identify a use of at least one of a privacy-related function, a privacy-related attribute, or a privacy-related characteristic within the mobile device application, wherein identifying the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises identifying use of personal data of a user within the mobile device application;

generating, by the computing hardware, a recommendation for addressing the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic within the mobile device application; and

providing, by the computing hardware, a graphical user interface for displaying the recommendation on a computing device to the user.

2. The method of claim 1 , wherein identifying the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises identifying the mobile device application accessing of at least one of device component permissions or a device storage of a mobile device on which the mobile device application is executing.

3. The method of claim 2 , wherein the device component permissions comprise at least one of permissions to access a camera, a microphone, photographs, a calendar, contacts or location determination residing on the mobile device.

4. The method of claim 2 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the mobile device.

5. The method of claim 1 , wherein the identifying the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises identifying use of an application programming interface call within the mobile device application configured to transmit the personal data of the user of the mobile device application.

6. The method of claim 5 , further comprising:

determining, by the computing hardware, a geographical destination of the personal data transmitted; and

determining, by the computing hardware, at least one of an applicable privacy law or regulation on transmitting the personal data based on the geographical destination, wherein the recommendation is based on the applicable privacy law or regulation.

7. A system comprising:

a non-transitory computer-readable medium storing instructions; and

a processing device communicatively coupled to the non-transitory computer-readable medium, wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:

querying a software development kit database using identifying information for a mobile device application to identify a software development kit used to generate the mobile device application;

analyzing computer code for the mobile device application and the software development kit to identify a use of at least one of a privacy-related function, a privacy-related attribute, or a privacy-related characteristic within the mobile device application, wherein the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises use of personal data of a user of the mobile device application; and

generating a recommendation for addressing the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic within the mobile device application, wherein the recommendation is provided for display on a graphical user interface on a computing device to the user.

8. The system of claim 7 , wherein the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises access of at least one of device component permissions or a device storage of a mobile device on which the mobile device application is executing.

9. The system of claim 8 , wherein the device component permissions comprise at least one of permissions to access a camera, a microphone, photographs, a calendar, contacts or location determination residing on the mobile device.

10. The system of claim 8 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the mobile device.

11. The system of claim 7 , wherein the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises use of an application programming interface call to transmit the personal data of the user of the mobile device application.

12. The system of claim 11 , wherein the operations further comprise:

determining a geographical destination of the personal data transmitted; and

determining at least one of an applicable privacy law or regulation on transmitting the personal data based on the geographical destination.

13. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

querying a software development kit database using identifying information for a mobile device application to identify a software development kit used to generate the mobile device application;

analyzing computer code for the mobile device application and the software development kit to identify a use of at least one of a privacy-related function, a privacy-related attribute, or a privacy-related characteristic within the mobile device application, wherein identifying the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises use of personal data of a user of the mobile device application; and

generating a recommendation for addressing the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic within the mobile device application, wherein the recommendation is provided for display on a graphical user interface on a computing device to the user.

14. The non-transitory computer-readable medium of claim 13 , wherein the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises access of at least one of device component permissions or a device storage of a mobile device on which the mobile device application is executing.

15. The non-transitory computer-readable medium of claim 14 , wherein the device component permissions comprise at least one of permissions to access a camera, a microphone, photographs, a calendar, contacts or location determination residing on the mobile device.

16. The non-transitory computer-readable medium of claim 14 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the mobile device.

17. The non-transitory computer-readable medium of claim 13 , wherein the use of at least one of the privacy-related function, the privacy-related attribute, or the privacy-related characteristic comprises use of an application programming interface call to transmit the personal data of the user of the mobile device application.

Assignments (2)
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: JONES, KEVIN; DEWEESE, WILLIAM; DEVENISH, JUSTIN; PITCHAIMANI, SARAVANAN; BRANNON, JONATHAN BLAKE
To: ONETRUST, LLC
Reel/Frame 057354/0384 →