Coordinated Dataset De-identification Across Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data de-identification methods, especially in cloud platforms, face challenges in protecting indirect identifiers and sensitive attributes due to high computational demands and resource requirements, often falling short in meeting legal privacy standards, particularly when handling large datasets.

Innovation Solution

A network device receives a dataset with masked direct identifiers from a client, applies data masking or pseudonymization techniques, and coordinates further de-identification methods to protect indirect identifiers and sensitive attributes, leveraging scalable cloud resources for processing and memory needs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data owners use existing in-house solutions for data de-identification, then data can be processed locally without leaving premises, but the solutions are limited to basic data masking algorithms and unable to adequately protect data to meet legal requirements

Engineering Contradiction:
Improveprivacy protection effectivenessVSAvoidde-identification technique capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The de-identification process is segmented into multiple stages: first, data owners apply local data masking techniques to direct identifiers; second, the masked data is transmitted to cloud platforms for advanced de-identification of indirect identifiers and sensitive attributes. This segmentation allows each stage to use appropriate techniques for its specific goals, combining local control with cloud-based advanced processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Encrypted data transmission serves as an intermediary mechanism between local data owners and cloud-based de-identification services. The encryption layer allows data to leave premises securely, enabling access to advanced cloud-based de-identification techniques while maintaining security during transit.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data owners allow highly sensitive personal data to leave their premises for cloud processing, then advanced de-identification can be performed, but security risks increase during data transfer

Engineering Contradiction:
Improvede-identification capabilityVSAvoidsecurity risk during data transfer
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Data masking techniques are applied preliminarily at the data owner's premises before data leaves the facility. This preliminary action reduces the sensitivity of the data during transmission, creating a first layer of protection that mitigates security risks while enabling cloud-based processing.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

Encryption serves as an intermediary protective layer during data transmission. The encrypted channel acts as a secure conduit that allows data to move from local systems to cloud platforms while protecting against interception or unauthorized access during transit.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cloud platforms perform advanced de-identification on large datasets, then comprehensive privacy protection can be achieved, but high computational demands and resource requirements arise

Engineering Contradiction:
Improveprivacy protection complianceVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The computational workload is segmented between local systems and cloud platforms. Local systems perform initial data masking on direct identifiers, reducing the complexity of data that needs to be processed in the cloud. This segmentation allows cloud resources to focus specifically on identifying and protecting indirect identifiers and sensitive attributes, optimizing overall computational efficiency.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If data owners use basic data masking algorithms locally, then data can be processed without leaving premises, but the protection is insufficient to meet legal privacy standards like HIPAA and GDPR

Engineering Contradiction:
Improvelocal processing capabilityVSAvoidlegal compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The de-identification process is divided into two complementary stages: local data masking of direct identifiers and cloud-based de-identification of indirect identifiers and sensitive attributes. This segmentation allows data owners to maintain local control for basic protection while leveraging cloud capabilities to achieve comprehensive legal compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The solution merges local data masking capabilities with cloud-based advanced de-identification services. By combining these two approaches, the system achieves both the ease of local operation and the comprehensive protection required for legal compliance, creating a hybrid architecture that leverages the strengths of both environments.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11093639B2Coordinated de-identification of a dataset across a network
Publication Date: 2021.08.17 WORKDAY INC
  • US11093639B2 patent drawing
  • US11093639B2 patent drawing
  • US11093639B2 patent drawing

AI summary

Methods, systems, and computer program products are provided. A network device receives, from a client device, a description of a dataset to be de-identified, and a list of one or more data de-identification techniques selected from groups consisting of a group of data masking techniques and a group of data pseudonymization techniques, and their configuration options supported by the client device. A first technique, from the at least one group of techniques and its configuration options supported by the client device and the network device are determined. The network device receives a dataset produced at the client device by applying the first technique and selected configuration options to corresponding attributes from the client device. The network device applies a de-identification technique to the dataset to produce a resulting set of de-identified data, wherein the de-identification technique is coordinated with the first technique and its configuration options to de-identify the dataset.