Anonymity Protection System for Survey Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital survey systems fail to adequately protect the anonymity of respondents, as they often associate identifying information with responses, lack flexibility in data analysis, and allow data manipulation that can compromise anonymity, leading to breaches in respondent identity.

Innovation Solution

An anonymity protection system that determines and applies anonymity thresholds based on data sensitivity, respondent number, and predefined settings, modifies data output to maintain anonymity, and dynamically updates filtering options to prevent identity exposure, ensuring anonymity for both presented and filtered-out data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional survey systems display survey responses with identifying information, then data analysis capability is improved, but respondent anonymity is compromised

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidanonymity breach
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system extracts and removes identifying information from survey responses before display. PII redaction components scan and remove names, addresses, phone numbers, and other identifiers from response text, allowing analysts to access response content without exposure to identifying details.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different levels of anonymity protection to different data elements. Respondent identifiers are completely removed, while response content is preserved for analysis. This selective processing maintains data utility while protecting anonymity at the appropriate locations in the data structure.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If conventional systems filter survey responses to small groups, then data analysis precision is improved, but respondent anonymity is compromised

Engineering Contradiction:
Improvedata analysis precisionVSAvoidanonymity breach
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system preemptively prevents anonymity breaches by monitoring filter application in real-time. When a filter would reduce a group to a size that compromises anonymity (e.g., fewer than 5 respondents), the system automatically blocks the filter application or aggregates the data to maintain sufficient group size, preventing the harmful outcome before it occurs.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system provides feedback to analysts when attempted filters would compromise anonymity. The interface displays warnings about group sizes and prevents application of filters that would create identifiable groups, allowing analysts to adjust their analysis approach while maintaining anonymity protections.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If conventional systems provide verbatim text responses, then data accuracy is improved, but respondent anonymity is compromised

Engineering Contradiction:
Improvedata accuracyVSAvoidanonymity breach
Core Design Contradiction:
Manufacturing precisionVSObject-affected harmful factors

Solution Approach 1:

The system extracts and removes identifying language from verbatim text responses while preserving the substantive content. PII redaction components scan response text for names, locations, organizations, and other identifiers, removing only these elements to maintain data accuracy while eliminating anonymity risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies targeted redaction to specific identifying elements within text responses rather than removing entire responses. This selective processing preserves the accuracy and analytical value of response content while removing only the portions that compromise anonymity.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If survey systems collect detailed respondent information, then data utility is improved, but anonymity protection difficulty increases

Engineering Contradiction:
Improvedata utilityVSAvoidanonymity protection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments respondent data into distinct categories: identifiers (completely removed), quasi-identifiers (aggregated or suppressed), and response content (preserved). This segmentation allows the system to collect and utilize detailed information for analysis while applying appropriate anonymity protections to each data type independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary processing layer between data collection and data display. Anonymization components process the detailed respondent information through multiple stages (identification, redaction, aggregation) before presenting data to analysts, mediating between the need for detailed data and the need for anonymity protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11797588B2Maintaining anonymity of survey respondents while providing useful survey data
Publication Date: 2023.10.24 QUALTRICS LLC
  • US11797588B2 patent drawing
  • US11797588B2 patent drawing
  • US11797588B2 patent drawing

AI summary

The present disclosure relates to systems, non-transitory computer-readable media, and methods for maintaining the anonymity of survey respondents while providing useful data to an analyst. In particular, in one or more embodiments, the disclosed systems utilize various anonymity protections based on various anonymity thresholds. For example, the presently disclosed systems and methods may disallow or modify potentially identifying data filters, including generating alternate data groupings. Further, the systems and methods may modify text responses to reduce identification risk.