Anonymization Server for Location Data Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to securely store and anonymize location data to prevent individual identification, as demonstrated by studies showing that location information can uniquely identify individuals, posing challenges under GDPR and HIPAA regulations, and existing anonymization methods compromise the utility of the data.
Innovation Solution
A system that utilizes an anonymization server to receive location data from tracking devices, partitions trajectories based on changes in movement behavior, and swaps similar partitions to generate anonymized data that cannot be traced back to a specific user, while maintaining the utility of the original information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If location data is stored with high precision to maintain data utility, then analytics value is improved, but individual identification risk increases
Solution Approach 1:
The patent segments location data into multiple components: precise location coordinates are separated from personal identifiers. The system processes location data through partitioning trajectories into segments and swapping similar segments between different users, thereby preserving spatial-temporal patterns for analytics while removing unique identifying characteristics.
Solution Approach 2:
The patent introduces an anonymization server as an intermediary between data collection and data storage/analysis. This intermediary processes raw location data by removing personally identifiable information while preserving analytical value, acting as a buffer that decouples the conflict between precision and privacy.
2Reliability
If location data is anonymized to prevent identification, then privacy security is improved, but data utility for analytics deteriorates
Solution Approach 1:
The patent changes key parameters of location data through the anonymization process. It transforms precise continuous coordinates into discretized grid cells, modifies temporal resolution by aggregating to broader time windows, and alters spatial resolution by generalizing coordinates. These parameter changes reduce identification risk while preserving patterns necessary for analytics.
Solution Approach 2:
The patent applies different levels of anonymization to different components of location data. High-precision coordinates are transformed into grid cells, while temporal patterns are preserved through trajectory segmentation. This selective application of anonymization techniques maintains local qualities necessary for analytics while removing globally identifying features.
3Quantity of substance
If comprehensive location tracking is implemented to gather data, then data completeness is improved, but identification accuracy increases
Solution Approach 1:
The patent applies preliminary anonymization processing to location data immediately upon collection, before the data is stored or analyzed. The anonymization server processes trajectories by removing identifiers and generalizing coordinates in advance, ensuring that even comprehensive datasets cannot be used for identification.
Solution Approach 2:
The patent transforms location data from continuous high-dimensional coordinates into discretized grid cells with lower dimensionality. By mapping precise coordinates to grid identifiers and aggregating temporal data into broader time windows, the system reduces the precision dimension while maintaining pattern information in aggregated form.
Data Source
AI summary
A system and for improving security of personally identifiable information stored in a computer database. The system and method enable a user's location information to be maintained in a data storage and retrieval system in such a way that it prohibits a user from being uniquely identified by the location information stored in the data storage and the retrieval system.


