IP Library › Granted Patent US 12,164,667
Granted Patent B2
US 12,164,667 · App. 17/743,749 · Granted Dec 10, 2024

Application privacy scanning systems and related methods

Inventors: Kevin Jones (Atlanta, GA); William DeWeese (Atlanta, GA); Justin Devenish (Atlanta, GA); Saravanan Pitchaimani (Atlanta, GA); Jonathan Blake Brannon (Smyrna, GA)
Assignee: OneTrust, LLC
G06F21/6245G06F16/901G06F16/904G06F16/9558
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,164,667
App. No.
17/743,749
Filed
May 13, 2022
Granted
Dec 10, 2024
Kind
B2
Examiner
KHATRI, ANIL
Art Unit
2197
USPC
726/26
Abstract

An application privacy analysis system is described, where the system obtains an application and analyzes it for privacy related data use. The system may determine privacy related activities of the application from established sources of such data and/or may decompile the application and analyze the resulting code to determine the privacy related activities of the application. The system may execute the application and monitor the communications traffic exchanged by the application to determine privacy related activities of the application. The system may store the results of such analyses for future reference.

Claims (56)

1. A method comprising:

analyzing privacy-related information for a software application on a remote device to generate privacy-related reports to improve privacy compliance of the software application by:

processing, by computing hardware, computer code for the software application on the remote device to determine that the software application collects, requests, or accesses personal data;

analyzing, by the computing hardware and based on processing the computer code, the computer code to determine permissions required for the software application by:

preparing the software application for analysis via an application intake;

reducing the computer code of the software application to machine code by utilizing an application decompiler; and

determining that the computer code uses the permissions to gain access to at least one of device hardware, device storage, or device data of the remote device on which the software application is executing via a static analysis of the computer code;

analyzing, by the computing hardware, a database using the permissions to determine that the software application utilizes the permissions that involves use of personal data of a user in association with using the software application to perform at least one of a privacy-related function, access a privacy-related attribute, or

access a privacy-related characteristic for the permissions that involves use of personal data of a user in association with using the software application;

generating, by the computing hardware, a privacy-related recommendation of the software application for addressing the use of at least one of performing the privacy-related function, accessing the privacy-related attribute, or accessing the privacy-related characteristic for the permissions; and

providing, by the computing hardware, a graphical user interface for displaying the privacy-related recommendation on a computing device, the privacy-related recommendation indicating the privacy compliance of the software application.

2. The method of claim 1 , wherein the device hardware comprises at least one of permissions to access a camera, a microphone, a receiver, or a transmitter of the remote device.

3. The method of claim 1 , wherein the device data comprises at least one of photographs, a calendar, contacts, or location determination residing on the remote device.

4. The method of claim 1 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the remote device.

5. The method of claim 1 , wherein analyzing the computer code to determine the permissions required for the software application comprises: identifying use of an application programming interface call within the software application configured to access the personal data of the user.

6. The method of claim 1 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to transmit the personal data of the user.

7. The method of claim 6 , further comprising:

determining, by the computing hardware, a geographical destination where the personal data is transmitted; and

determining, by the computing hardware, at least one of an applicable privacy law or a privacy regulation on transmitting the personal data based on the geographical destination, wherein the privacy-related recommendation is based on the applicable privacy law or the privacy regulation.

8. A system comprising:

a non-transitory computer-readable medium storing instructions; and

a processing device communicatively coupled to the non-transitory computer-readable medium,

wherein, the processing device is configured to execute the instructions and thereby perform operations comprising:

analyzing privacy-related information for a software application on a remote device to generate privacy-related reports to improve privacy compliance of the software application by:

processing computer code for the software application on the remote device to determine that the software application collects, requests, or accesses personal data;

analyzing, based on processing the computer code, the computer code to determine permissions required for the software application by:

preparing the software application for analysis via an application intake;

reducing the computer code of the software application to machine code by utilizing an application decompiler; and

determining that the computer code uses the permissions to gain access to at least one of device hardware, device storage, or device data of the remote device on which the software application is executing via a static analysis of the computer code;

analyzing a database using the permissions to correlate the permissions to determine that the software application utilizes the permissions that involves use of personal data of a user in association with using the software application to perform at least one of a privacy-related function, access a privacy-related attribute, or

access a privacy-related characteristic for the permissions that involves use of personal data of a user in association with using the software application;

generating a privacy-related recommendation of the software application for addressing the use of at least one of performing the privacy-related function, accessing the privacy-related attribute, or accessing the privacy-related characteristic for the permissions; and

providing a graphical user interface for displaying the privacy-related recommendation on a computing device, the privacy-related recommendation indicating the privacy compliance of the software application.

9. The system of claim 8 , wherein the device hardware comprises at least one of permissions to access a camera, a microphone, a receiver, or a transmitter of the remote device.

10. The system of claim 8 , wherein the device data comprises at least one of photographs, a calendar, contacts, or location determination residing on the remote device.

11. The system of claim 8 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the remote device.

12. The system of claim 8 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to access the personal data of the user.

13. The system of claim 8 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to transmit the personal data of the user.

14. The system of claim 13 , wherein the operations further comprise:

determining a geographical destination where the personal data is transmitted; and

determining at least one of an applicable privacy law or a privacy regulation on transmitting the personal data based on the geographical destination, wherein the privacy-related recommendation is based on the applicable privacy law or the privacy regulation.

15. A non-transitory computer-readable medium having program code that is stored thereon, the program code executable by one or more processing devices for performing operations comprising:

analyzing privacy-related information for a software application on a remote device to generate privacy-related reports to improve privacy compliance of the software application by:

processing computer code for the software application on the remote device to determine that the software application collects, requests, or accesses personal data;

analyzing, based on processing the computer code, the computer code to determine permissions required for the software application by:

preparing the software application for analysis via an application intake;

reducing the computer code of the software application to machine code by utilizing an application decompiler; and

determining that the computer code uses the permissions to gain access to at least one of device hardware, device storage, or device data of the remote device on which the software application is executing via a static analysis of the computer code;

querying a database using the permissions to determine that the software application utilizes the permissions that involves use of personal data of a user in association with using the software application to perform at least one of a privacy-related function, access a privacy-related attribute, or access a privacy-related characteristic for the permissions that involves use of personal data of a user in association with using the software application;

generating a privacy-related recommendation of the software application for addressing the use of at least one of performing the privacy-related function, accessing the privacy-related attribute, or accessing the privacy-related characteristic for the permissions; and

providing a graphical user interface for displaying the privacy-related recommendation on a computing device, the privacy-related recommendation indicating the privacy compliance of the software application.

16. The non-transitory computer-readable medium of claim 15 , wherein the device hardware comprises at least one of permissions to access a camera, a microphone, a receiver, or a transmitter of the remote device.

17. The non-transitory computer-readable medium of claim 15 , wherein the device data comprises at least one of photographs, a calendar, contacts, or location determination residing on the remote device.

18. The non-transitory computer-readable medium of claim 15 , wherein the device storage comprises at least one of shared storage, an application database, a key chain, private key information, public key information, blockchain information, advertising identifiers, or encrypted storage residing on the remote device.

19. The non-transitory computer-readable medium of claim 15 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to access the personal data of the user.

20. The non-transitory computer-readable medium of claim 15 , wherein analyzing the computer code to determine the permissions required for the software application comprises identifying use of an application programming interface call within the software application configured to transmit the personal data of the user.

Assignments (2)
SUPPLEMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 3, 2026
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 075801/0754 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2022
From: JONES, KEVIN; DEWEESE, WILLIAM; DEVENISH, JUSTIN; PITCHAIMANI, SARAVANAN; BRANNON, JONATHAN BLAKE
To: ONETRUST, LLC
Reel/Frame 059900/0355 →
Continuity (24)
Continuation 17463775 · Sep 1, 2021
Continuation 17163701 · Feb 1, 2021
Continuation 16915097 · Jun 29, 2020
Continuation In Part 16895278 · Jun 8, 2020
Continuation 16552765 · Aug 27, 2019
Continuation In Part 16277568 · Feb 15, 2019
Continuation In Part 16159634 · Oct 13, 2018
Continuation In Part 16055083 · Aug 4, 2018
Continuation In Part 15996208 · Jun 1, 2018
Continuation In Part 15853674 · Dec 22, 2017
Continuation In Part 15619455 · Jun 10, 2017
Continuation In Part 15254901 · Sep 1, 2016
Provisional Application 62868373 · Jun 28, 2019
Provisional Application 62728435 · Sep 7, 2018
Provisional Application 62631684 · Feb 17, 2018
Provisional Application 62631703 · Feb 17, 2018
Provisional Application 62572096 · Oct 13, 2017
Provisional Application 62547530 · Aug 18, 2017
Provisional Application 62541613 · Aug 4, 2017
Provisional Application 62537839 · Jul 27, 2017
Provisional Application 62360123 · Jul 8, 2016
Provisional Application 62353802 · Jun 23, 2016
Provisional Application 62348695 · Jun 10, 2016
Related Publication 20220269819A1 · Aug 25, 2022