Cross-Organization Data Sharing with Selective Quasi-Identifier Anonymization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in sharing transaction data across different entities while ensuring the privacy and protection of personally identifiable information (PII), as existing anonymization techniques may render quasi-identifiers useless or reduce their utility, thereby impacting data mining and analysis.

Innovation Solution

A cross-organization data sharing system that employs data anonymizer agents to selectively apply anonymization filters to quasi-identifiers based on type and jurisdictional requirements, correlating explicit user identifiers into internal identifiers without exposing sensitive information, allowing for aggregated analysis while maintaining data privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anonymization techniques are applied to quasi-identifiers, then privacy protection is improved, but data utility is worsened

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies different anonymization parameters (k-anonymity, l-diversity, t-closeness) to different types of quasi-identifiers based on their sensitivity and importance. This allows optimizing the balance between privacy protection and data utility for each attribute individually, rather than applying a uniform anonymization level to all data

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements selective anonymization where different levels of anonymization are applied to different quasi-identifier attributes based on their specific characteristics. Sensitive attributes receive stronger anonymization while less sensitive attributes maintain higher utility, achieving local optimization of the privacy-utility tradeoff

Inventive Principle:
Principle #3Local quality

2Productivity

If cross-organizational data sharing is enabled, then data mining capability is improved, but information security is worsened

Engineering Contradiction:
Improvedata mining capabilityVSAvoidinformation security risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted third-party data sharing platform that mediates between organizations. This intermediary handles the anonymization, matching, and sharing processes, ensuring that raw PII never leaves the controlling organization while still enabling cross-organizational data mining through the anonymized identifiers

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs anonymization and security processing in advance before data sharing occurs. Quasi-identifiers are pre-anonymized and pre-matched across organizations before any actual data sharing takes place, eliminating security risks during the sharing process while maintaining data mining capabilities

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If explicit identifiers are correlated across organizations, then data matching accuracy is improved, but privacy exposure is worsened

Engineering Contradiction:
Improvedata matching accuracyVSAvoidprivacy exposure
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent creates and uses copies of identifiers through hashing functions. Original explicit identifiers are transformed into hashed versions that can be correlated across organizations for accurate matching, while the original PII remains securely stored at each organization and is never exposed during the matching process

Inventive Principle:
Principle #26Copying

Solution Approach 2:

A trusted intermediary platform performs the correlation of hashed identifiers across organizations. The intermediary can match records accurately using the hashed copies without ever having access to or exposing the original explicit identifiers, thus achieving both accurate matching and privacy protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10614248B2Privacy preserving cross-organizational data sharing with anonymization filters
Publication Date: 2020.04.07 CA TECH INC
  • US10614248B2 patent drawing
  • US10614248B2 patent drawing
  • US10614248B2 patent drawing

AI summary

A system can be designed that shares transaction data across different organizations while preserving data privacy and anonymizing the source organization. Organizations can enter into an agreement to share transaction data with each other through a trusted data sharing system. The organizations can input user records that include primary and secondary explicit user identifiers into the data sharing system. The data sharing system can correlate explicit user identifiers of a user across organizations via an internal identifier without exposing explicit user identifiers. The data sharing system comprises a data anonymizer agent for each sharing organization. A data anonymizer agent selectively applies anonymization filters to quasi-identifiers in the transaction data based on quasi-identifier type to extend data privacy protection measures to quasi-identifiers without drastically reducing or eradicating the utility of the quasi-identifiers.