Customer-Managed Anonymous Identifier Rotation for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing systems lack the ability for customers to manage their own anonymous identifiers, leading to a lack of anonymity as provider-managed pseudonyms are not truly anonymous.
Innovation Solution
Implementing a customer-managed anonymous identifier rotation system that uses zero-knowledge proofs to authenticate and periodically update anonymous identifiers, ensuring that non-anonymous identifiers remain confidential within a computing environment managed by the customer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If provider-managed pseudonyms are used for customer identifiers, then service provider can manage and track customer accounts, but customer anonymity is compromised as providers can access and potentially reveal non-anonymous identifiers
Solution Approach 1:
The patent introduces an anonymous identifier as an intermediary between the customer's non-anonymous identifier and the service provider. This intermediary allows the service provider to manage accounts and provide services without directly accessing or knowing the customer's true identity, thus maintaining anonymity while enabling reliable account management.
Solution Approach 2:
The patent segments the identifier system into multiple layers: the non-anonymous identifier (customer's true identity), the anonymous identifier (intermediary), and service access tokens. This segmentation allows different parts of the system to use different identifier types, protecting the customer's true identity while enabling service management.
2Ease of operation
If service providers maintain all customer identifier information, then comprehensive account management is possible, but data protection and privacy compliance become difficult to ensure
Solution Approach 1:
The anonymous identifier acts as a mediator that allows service providers to perform account management operations without accessing or storing sensitive personal information. The service provider can manage accounts using only the anonymous identifier, eliminating the need to handle or protect complex personal data while maintaining full operational capability.
3Device complexity
If static pseudonyms are used for customer accounts, then simple identifier management is maintained, but customers cannot rotate or update their anonymous identifiers to enhance privacy
Solution Approach 1:
The patent transforms the static pseudonym system into a dynamic one where anonymous identifiers can be rotated and updated. Customers can generate new anonymous identifiers and associate them with their accounts, allowing them to enhance privacy over time while the service provider continues to manage accounts using the current anonymous identifier without needing to understand or manage the rotation process.
Data Source
AI summary
Example embodiments of the present disclosure provide for an example method including establishing a computing environment accessible to a second computing system. The computing environment can include an anonymous identifier management tool. A first anonymous identifier associated with the second computing system can be established. Message data is exchanged from the computing environment to a first computing system. The message data can be associated with the first anonymous identifier without revealing a non-anonymous identifier associated with the first computing system. The anonymous identifier management tool can periodically update the first anonymous identifier to a second anonymous identifier. The first anonymous identifier and mapping data associating the first anonymous identifier and the second anonymous identifier is deleted.


