Context Service System for Privacy-Compliant Customer Data Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customer information is often fragmented across different service platforms, leading to incomplete data and difficulty in associating customer attributes, which hinders personalized services and data sharing due to privacy and regulatory concerns.

Innovation Solution

A context service system employs Oblivious Pseudo-Random Functions (OPRF) and Verifiable OPRF to generate blinded attributes, allowing associations between customer information elements to be shared without revealing actual values, enabling secure and privacy-compliant data aggregation and querying across multiple platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customer information is segmented across different service platforms, then data privacy and security are improved, but the ability to associate customer attributes and provide personalized services deteriorates

Engineering Contradiction:
Improvedata privacy and securityVSAvoidassociation between customer attributes
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a context service system as an intermediary that operates on encrypted customer information. This mediator can associate customer attributes across different service platforms without having access to the actual plaintext data, thus maintaining privacy while enabling information association. The context service system uses cryptographic techniques to perform computations on encrypted data and return results that reveal associations without exposing sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If actual customer information values are shared across platforms, then the ability to provide personalized services is improved, but data privacy and regulatory compliance deteriorates

Engineering Contradiction:
Improvepersonalized servicesVSAvoiddata privacy exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary association information from the encrypted customer data without extracting or revealing the actual customer information values. The context service system performs computations that reveal relationships between attributes while leaving the sensitive data values hidden. This allows personalized services to be provided based on attribute associations without exposing harmful factors like personal identifiers.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If customer information is stored in encrypted form, then data security is improved, but the ability to query and associate attributes deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidattribute querying and association
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the operational parameters of cryptographic operations to enable querying on encrypted data. Instead of requiring decryption before computation, the system uses homomorphic encryption or searchable encryption techniques that allow specific types of computations and queries to be performed directly on encrypted data. This maintains security while improving ease of operation for attribute association tasks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11539517B2Private association of customer information across subscribers
Publication Date: 2022.12.27 CISCO TECHNOLOGY INC
  • US11539517B2 patent drawing
  • US11539517B2 patent drawing
  • US11539517B2 patent drawing

AI summary

Methods are provided for discovering related attributes with respect to an element in a customer data record, based on provided associations and for generating new associations between various elements of the customer data record. In these method, the context service system obtains, from a subscriber, a lookup request including a first blinded attribute. The first blinded attribute is obtained by applying an oblivious pseudo random function (OPRF) to a first element of a data record. The method further includes the context service system identifying at least one second blinded attribute associated with the first blinded attribute in a shared data partition of the context service system and providing, to the subscriber, at least one second element of the data record associated with the at least one second blinded attribute.