Cross-Organization Data Sharing with Selective Quasi-Identifier Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in sharing transaction data across different entities while ensuring the privacy and protection of personally identifiable information (PII), as existing anonymization techniques may render quasi-identifiers useless or reduce their utility, thereby impacting data mining and analysis.
Innovation Solution
A cross-organization data sharing system that employs data anonymizer agents to selectively apply anonymization filters to quasi-identifiers based on type and jurisdictional requirements, correlating explicit user identifiers into internal identifiers without exposing sensitive information, allowing for aggregated analysis while maintaining data privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anonymization techniques are applied to quasi-identifiers, then privacy protection is improved, but data utility is worsened
Solution Approach 1:
The patent applies different anonymization parameters (k-anonymity, l-diversity, t-closeness) to different types of quasi-identifiers based on their sensitivity and importance. This allows optimizing the balance between privacy protection and data utility for each attribute individually, rather than applying a uniform anonymization level to all data
Solution Approach 2:
The system implements selective anonymization where different levels of anonymization are applied to different quasi-identifier attributes based on their specific characteristics. Sensitive attributes receive stronger anonymization while less sensitive attributes maintain higher utility, achieving local optimization of the privacy-utility tradeoff
2Productivity
If cross-organizational data sharing is enabled, then data mining capability is improved, but information security is worsened
Solution Approach 1:
The patent introduces a trusted third-party data sharing platform that mediates between organizations. This intermediary handles the anonymization, matching, and sharing processes, ensuring that raw PII never leaves the controlling organization while still enabling cross-organizational data mining through the anonymized identifiers
Solution Approach 2:
The system performs anonymization and security processing in advance before data sharing occurs. Quasi-identifiers are pre-anonymized and pre-matched across organizations before any actual data sharing takes place, eliminating security risks during the sharing process while maintaining data mining capabilities
3Measurement precision
If explicit identifiers are correlated across organizations, then data matching accuracy is improved, but privacy exposure is worsened
Solution Approach 1:
The patent creates and uses copies of identifiers through hashing functions. Original explicit identifiers are transformed into hashed versions that can be correlated across organizations for accurate matching, while the original PII remains securely stored at each organization and is never exposed during the matching process
Solution Approach 2:
A trusted intermediary platform performs the correlation of hashed identifiers across organizations. The intermediary can match records accurately using the hashed copies without ever having access to or exposing the original explicit identifiers, thus achieving both accurate matching and privacy protection
Data Source
AI summary
A system can be designed that shares transaction data across different organizations while preserving data privacy and anonymizing the source organization. Organizations can enter into an agreement to share transaction data with each other through a trusted data sharing system. The organizations can input user records that include primary and secondary explicit user identifiers into the data sharing system. The data sharing system can correlate explicit user identifiers of a user across organizations via an internal identifier without exposing explicit user identifiers. The data sharing system comprises a data anonymizer agent for each sharing organization. A data anonymizer agent selectively applies anonymization filters to quasi-identifiers in the transaction data based on quasi-identifier type to extend data privacy protection measures to quasi-identifiers without drastically reducing or eradicating the utility of the quasi-identifiers.


