Anonymized Customer Data Analysis for Privacy Preservation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers are uncomfortable providing personally identifiable information for personalized experiences, leading to reduced interaction with websites, as they feel their privacy is compromised, resulting in websites becoming less effective and valuable.

Innovation Solution

A method that stores customer data in a protected database, restricting access to approved privacy-preserving queries, which generate aggregated data without personally identifiable information, and creates anonymous personas by injecting noise into customer data, ensuring individual privacy is preserved.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personalized customer data is collected and analyzed, then website relevance and effectiveness are improved, but customer privacy is compromised

Engineering Contradiction:
Improvewebsite effectivenessVSAvoidprivacy compromise
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personally identifiable information (PII) from customer data through a filtering mechanism. The system separates PII from behavioral and preference data, retaining only anonymized information for analysis. This extraction principle resolves the contradiction by removing the harmful element (PII) while preserving the useful elements (behavioral patterns) needed for website personalization.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary component - a privacy filter or anonymization layer - that sits between raw customer data and analysis systems. This intermediary processes data to remove PII while maintaining the utility of aggregated behavioral information. The mediator enables both privacy protection and effective data utilization simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If aggregated customer data is analyzed, then marketing effectiveness is improved, but individual customer privacy may be compromised

Engineering Contradiction:
Improvemarketing effectivenessVSAvoidindividual privacy
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments customer information into distinct categories: personally identifiable information (PII) and anonymized behavioral data. By segmenting the data types and applying different handling rules to each segment, the system enables aggregated analysis for marketing while protecting individual privacy. The segmentation principle allows simultaneous achievement of marketing effectiveness and privacy preservation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If customer data is stored for analysis, then data integrity is maintained, but security risks increase

Engineering Contradiction:
Improvedata integrityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and removes PII from stored customer data, retaining only anonymized information. By taking out the most sensitive elements (identifiable information) while preserving essential analytical data, the system maintains data integrity for analysis purposes while significantly reducing security risks associated with storing comprehensive personal information.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8140502B2Preserving individual information privacy by providing anonymized customer data
Publication Date: 2012.03.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8140502B2 patent drawing
  • US8140502B2 patent drawing
  • US8140502B2 patent drawing

AI summary

A method of preserving individual information privacy for each of a plurality of customers while providing aggregated information about the plurality of customers includes storing static customer data and dynamic customer data of the plurality of customers in a protected database. The method includes restricting shared access to the static customer data and the dynamic customer data to a set of approved privacy-preserving queries. The privacy preserving queries include a privacy-preserving aggregation query that uses one or more parameters to indicate a characteristic of interest for which aggregation of the static customer data and the dynamic customer data is requested. The privacy-preserving aggregation query may be configured to retrieve aggregated customer data related to the characteristic of interest. The aggregated customer data may be returned in response to the privacy-preserving aggregation query not including any personally identifiable information of any particular one of the plurality of customers.