Anonym ID Switching for Leaked User Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to effectively prevent identification of anonymous information even when it leaks, as they do not adequately manage the association between anonymous and real name information, leaving users vulnerable to privacy breaches.
Innovation Solution
A server device and method that acquires a risk value when anonymous information leaks, and associates or switches anonym IDs with the anonymous information, ensuring that even if the information leaks, it is difficult to identify the corresponding user by implementing anonym ID management processes such as switching or differentiating anonym IDs based on risk thresholds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anonymous information is stored separately from real name information, then user privacy protection is improved, but the ability to identify users when information leaks remains insufficient
Solution Approach 1:
The patent segments anonymous information into multiple division information pieces (first division information, second division information, etc.) and stores them separately with different anonym IDs. This segmentation ensures that even if one piece leaks, the complete user identity cannot be reconstructed without all pieces and their corresponding anonym IDs.
Solution Approach 2:
The patent dynamically changes the anonym ID parameter based on risk values. When a leak risk is detected, the system switches to using different anonym IDs for different pieces of division information, making it impossible for attackers to link the leaked information to a specific user identity.
2Reliability
If anonym ID switching is implemented when risk value exceeds threshold, then identification difficulty of leaked information is improved, but system complexity increases
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors risk values and automatically adjusts anonym ID assignment strategies. When the risk value exceeds a predetermined threshold, the system feedbacks to switch to differentiated anonym IDs; when the risk is low, it can use unified anonym IDs, thus managing complexity dynamically rather than statically.
Solution Approach 2:
The anonym ID management system is made dynamic rather than static. The system adapts its behavior based on real-time risk assessments, switching between different operational modes (unified anonym ID vs. differentiated anonym IDs) to balance security requirements with system complexity.
3Reliability
If division information is created with different anonym IDs, then user identification from leaked data is prevented, but data processing complexity increases
Solution Approach 1:
The patent divides anonymous information into multiple independent division information pieces (e.g., first division information, second division information), each associated with a different anonym ID. This segmentation ensures that compromising one piece does not reveal the complete user identity, as all pieces are required for reconstruction.
Solution Approach 2:
Different parts of the divided information are assigned different security qualities through unique anonym IDs. Each division information piece has its own local security characteristic (its specific anonym ID), making the overall system more secure while allowing efficient processing of individual pieces.
Data Source
AI summary
Provided is a server device including a risk value acquisition unit that acquires a risk value in a case in which a user's anonymous information leaks and a processing execution unit that associates an anonym ID for identifying the anonymous information with the anonymous information. In a case in which the risk value exceeds a predetermined threshold value, the processing execution unit executes at least any of processing of switching the anonym ID associated with the anonymous information or processing of differentiating anonym IDs associated with a plurality of pieces of division information obtained through division of the anonymous information.


