Anonymous User Data Storage with Controlled Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges with existing remote data storage systems as they lack full control over their data, anonymity, and complete removal of information, especially when data is linked to other users, leading to issues in data breaches and access disputes.
Innovation Solution
A method and system for remotely storing user data anonymously, using unique identifiers and encryption keys to control access, allowing users to upload content to a server where it is stored anonymously and can be accessed by designated third parties while ensuring complete expungability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user data is stored remotely on a server for easy access, then data accessibility is improved, but user control and anonymity over the data deteriorate
Solution Approach 1:
The system segments user identity from user data by introducing unique identifiers (UUIDs) that act as intermediaries. The server stores data associated with UUIDs rather than direct user identities, separating the storage function from the identity function. This allows the server to provide accessible storage while the user maintains control through their private key that can verify and manage access to their data.
Solution Approach 2:
The patent introduces multiple intermediary layers: unique identifiers serve as mediators between users and stored data, encryption keys act as intermediaries for access control, and the system architecture itself serves as an intermediary that enables users to control third-party access without directly managing the storage infrastructure. These intermediaries preserve user anonymity and control while enabling remote storage accessibility.
2Adaptability or versatility
If user information is posted and linked to other user data for social interaction, then social connectivity is improved, but complete data removal and anonymity deteriorate
Solution Approach 1:
The system extracts user identity information from the stored data by using unique identifiers instead of storing actual personal information. When users want to remove their data, they can generate a new UUID or use their private key to revoke access, effectively taking their identity out of the system while leaving the data structure intact. This enables complete removal of user-associated information while maintaining the data's utility for authorized access.
Solution Approach 2:
The system changes the parameter of data identification from using persistent user identities to using changeable unique identifiers. Users can generate new UUIDs or revoke old ones, changing the identification parameter to achieve anonymity or data removal. This parameter change allows social connectivity through identifier linking while preserving the ability to completely remove or anonymize data by changing the identifier.
3Adaptability or versatility
If third parties are granted access to user data for collaboration, then data sharing utility is improved, but security control and anonymity deteriorate
Solution Approach 1:
The system implements dynamic access control where third-party permissions are not static but can be changed at any time by the data owner through their private key. Access rights can be granted, modified, or revoked dynamically without affecting the stored data or requiring system administrator intervention. This dynamic control maintains security and anonymity while enabling flexible data sharing utility.
Solution Approach 2:
The patent implements self-service access control where users independently manage their own data sharing permissions using their private keys. Users can grant access to third parties, manage permission levels, and revoke access without requiring the server or other intermediaries to intervene. This self-service mechanism maintains user anonymity and security control while providing robust data sharing capability.
Data Source
AI summary
Methods and systems are configured to store user data and control access to the user data, wherein the data is stored remotely from the user (such as external to a user's computing device) and the user's data is maintained anonymously. Content is stored in association with a user identifier and access by third parties is controlled by linked third party identifiers.


