Adaptive Data De-Identification Rules for Evolving Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Static data de-identification rules become outdated due to changing data and knowledge, making them susceptible to re-identification and privacy attacks, as they are not dynamically adapted to evolving conditions.

Innovation Solution

A system that periodically monitors datasets and dynamically changes data de-identification rulesets using machine learning to maintain privacy protection, adapting rules in real-time to ensure compliance with privacy requirements and legal frameworks like HIPAA Safe Harbor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static data de-identification rules are used, then initial privacy protection is achieved, but the protection becomes outdated and vulnerable to re-identification attacks over time

Engineering Contradiction:
Improveprivacy protection effectivenessVSAvoidadaptability to changing data conditions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic data de-identification by continuously monitoring data streams and automatically adjusting de-identification rules in real-time. The system transitions from static, pre-defined rules to dynamic rules that adapt to changing data characteristics, population density, and re-identification risks, ensuring ongoing privacy protection effectiveness.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms by continuously monitoring data streams, evaluating the effectiveness of current de-identification rules, and using this information to adjust rules dynamically. The monitoring component detects changes in data characteristics and feeds this information back to the rule adjustment mechanism, creating a closed-loop system that maintains privacy protection adaptability.

Inventive Principle:
Principle #23Feedback

2Reliability

If de-identification rules are frequently updated to maintain privacy protection, then privacy security is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improveprivacy protection securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically monitoring data characteristics, evaluating rule effectiveness, and adjusting de-identification rules without requiring manual intervention. The automated rule adjustment mechanism uses pre-defined criteria and algorithms to dynamically modify rules, reducing operational complexity while maintaining high privacy security through continuous adaptation.

Inventive Principle:
Principle #25Self-service

3Reliability

If continuous monitoring and dynamic rule adjustment are implemented, then privacy protection is maintained, but processing time and computational resources increase

Engineering Contradiction:
Improveprivacy protection maintenanceVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements periodic monitoring and evaluation of de-identification rules at specified intervals rather than continuously for every data point. This periodic action maintains privacy protection effectiveness while reducing computational overhead and preserving data processing efficiency by adjusting the frequency of rule evaluations based on data stream characteristics.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11762835B2Adaptive statistical data de-identification based on evolving data streams
Publication Date: 2023.09.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11762835B2 patent drawing
  • US11762835B2 patent drawing
  • US11762835B2 patent drawing

AI summary

A system dynamically changes a data de-identification ruleset applied to a dataset for de-identifying data and comprises at least one processor. The system periodically monitors a dataset derived from data that is de-identified according to a data de-identification ruleset under a set of conditions. The set of conditions for the data de-identification ruleset is evaluated with respect to the monitored data to determine applicability of the data de-identification. One or more rules of the data de-identification ruleset are dynamically changed in response to the evaluation indicating one or more conditions of the set of conditions for the data de-identification ruleset are no longer satisfied. Embodiments of the present invention may further include a method and computer program product for dynamically changing a data de-identification ruleset applied to a dataset for de-identifying data in substantially the same manner described above.