Consumer Information Manager for Privacy-Preserving Attribute Publication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face privacy concerns as they unknowingly disclose personal and contextual information over computer networks, leading to potential identification and undesirable consequences such as loss of reputation, financial harm, and safety risks, while existing systems for targeted content generation rely on precise user data that may not adequately protect user privacy.
Innovation Solution
A consumer device is configured to provide anonymous context information, using a consumer information manager to selectively disclose dimension attributes without revealing user identification, employing techniques like anonymization and post-publication monitoring to ensure privacy protection while enabling targeted content generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If user context information is disclosed to enable targeted content generation, then content relevance and user experience are improved, but user privacy and security are compromised
Solution Approach 1:
The patent creates a synthetic user profile that copies relevant contextual attributes (age, location, preferences) while excluding personally identifiable information. This synthetic profile serves as a surrogate for the real user data, enabling targeted content generation without exposing actual user identity or sensitive personal information.
Solution Approach 2:
The system extracts only the necessary contextual attributes from comprehensive user data while removing PII and sensitive information. By taking out only the relevant features needed for content targeting (such as demographic categories and preference indicators) and leaving behind identifying information, the patent achieves content relevance without privacy compromise.
2Productivity
If comprehensive user data is collected for targeted advertising, then advertising effectiveness is improved, but user privacy protection is worsened
Solution Approach 1:
The patent transforms detailed user attributes into aggregated statistical parameters and categorical representations. Instead of storing and using raw personal data, the system converts user characteristics into summarized profile parameters (e.g., age ranges, location zones, preference categories) that maintain advertising effectiveness while reducing data sensitivity and privacy risk.
Solution Approach 2:
The user profile is segmented into distinct attribute categories (demographic, geographic, preference-based) with each segment containing only the necessary information for specific advertising purposes. This segmentation allows targeted advertising to function while limiting the scope and sensitivity of stored data, improving privacy protection without sacrificing ad effectiveness.
3Ease of operation
If user attributes are made more specific for better targeting, then content personalization is improved, but identification risk increases
Solution Approach 1:
The patent applies different levels of specificity to different profile attributes based on their privacy risk characteristics. Highly specific attributes that pose identification risk (such as exact location, precise demographic data) are generalized to broader categories, while less sensitive attributes maintain higher specificity for effective personalization. This localized quality adjustment balances personalization effectiveness with identification protection.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present disclosure are directed toward publication and/or removal of attributes in a multi-user computing environment. In some embodiments, a consumer information manager (CIM) associated with a user of a multi-user computing system may receive a notification, from a dimension authority (DA), of a decrease in a population count of users of the computing system who have published an attribute within the computing system, and may determine whether the user has published the attribute. In response to receiving the notification of the decrease and determining that the user has published the attribute, the CIM may determine a likelihood that continued publication of the attribute will enable identification of the user, compare the likelihood to a threshold, and, when the likelihood exceeds the threshold, remove the attribute from publication. Other embodiments may be disclosed and/or claimed.