Adaptive Anonymization Protocols for Secure Data Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anonymization systems for personal data are often hindered by security measures, requiring complex and time-consuming adaptations, leading to inflexibility and poor extensibility, making it difficult to utilize them for various analytical purposes.
Innovation Solution
A computer system comprising a control computer, a provisioning computer, and user computers, where anonymization protocols are used to select and anonymize personal data adaptively for specific analysis functions, allowing secure and flexible data transfer without exposing sensitive data, enabling multiple analysis functions with different requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If anonymization software is installed in a security-critical system to enable data analysis, then data usability for analysis is improved, but system security and protection against malware deteriorate
Solution Approach 1:
The patent extracts the anonymization function from the security-critical system by using a separate, externally provided anonymization program. The core idea is to take out the data processing capability needed for analysis while leaving the secure storage system intact and unmodified, thus maintaining security while enabling analysis through external tools
Solution Approach 2:
The patent introduces an intermediary approach where data is transferred to a secure external environment for anonymization and analysis, then results are returned without exposing the original secure system to external software. This mediator pattern allows interaction between the secure system and external analysis tools without direct integration
2Adaptability or versatility
If multiple different anonymization programs are installed for different analysis purposes, then adaptability to various analysis functions is improved, but device complexity and installation effort deteriorate
Solution Approach 1:
The patent implements universality by designing a single anonymization program infrastructure that can handle multiple different analysis functions through configuration rather than through multiple separate installations. The system is built to be multi-functional, accommodating various analysis needs through a unified platform
Solution Approach 2:
The patent applies dynamics by making the anonymization program adaptable and reconfigurable for different analysis purposes without requiring reinstallation. The system can dynamically adjust to different analysis requirements through updates and configuration changes, maintaining flexibility while avoiding the complexity of multiple static installations
3Adaptability or versatility
If anonymization programs are frequently updated to keep up with data analysis dynamics, then adaptability to new analysis methods is improved, but ease of operation and maintenance deteriorate
Solution Approach 1:
The patent applies preliminary action by establishing a robust, pre-configured anonymization infrastructure that is designed from the outset to accommodate future analysis methods. The system is built with forward-thinking architecture that anticipates future needs, reducing the need for frequent updates and simplifying maintenance
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a computer system (100) for the anonymization of personal data. The computer system comprises a control computer system (128), a provisioning computer system (128, 262) and at least one user computer system (160). The control computer system comprises a control software (140) for providing anonymized personal data to an analysis software (139). The analysis software comprises a plurality of different analysis functions (132-138). The provisioning computer system comprises a plurality of anonymization protocols (121) each associated with one of said plurality of different analysis functions (132-138). Each of the anonymization protocols is configured to select and anonymize personal data in a manner adapted to the one analysis functions associated with said analysis protocol. The user computer system comprises a data store (102) in which personal data (104-110) is stored and an anonymization software (114). The anonymization software is configured for: - receiving at least one anonymization protocol (120); for each of said at least one anonymization protocol: - selecting and anonymizing a subset of the personal data in accordance with said anonymizing protocol; and - transferring the anonymized subset and an identifier of the anonymization protocol to the control software. The control software is configured for: - receiving the at least one anonymized subset and the at least one identifier from said anonymizing software; and - providing the subset and the identifier to the analysis software for performing those analysis functions to which the anonymization protocol identified by the identifier is associated, on the subset.