Customer-Managed Anonymous Identifier Rotation for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems lack the ability for customers to manage their own anonymous identifiers, leading to a lack of anonymity as provider-managed pseudonyms are not truly anonymous.

Innovation Solution

Implementing a customer-managed anonymous identifier rotation system that uses zero-knowledge proofs to authenticate and periodically update anonymous identifiers, ensuring that non-anonymous identifiers remain confidential within a computing environment managed by the customer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If provider-managed pseudonyms are used for customer identifiers, then service provider can manage and track customer accounts, but customer anonymity is compromised as providers can access and potentially reveal non-anonymous identifiers

Engineering Contradiction:
Improveaccount management reliabilityVSAvoidanonymity loss
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an anonymous identifier as an intermediary between the customer's non-anonymous identifier and the service provider. This intermediary allows the service provider to manage accounts and provide services without directly accessing or knowing the customer's true identity, thus maintaining anonymity while enabling reliable account management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the identifier system into multiple layers: the non-anonymous identifier (customer's true identity), the anonymous identifier (intermediary), and service access tokens. This segmentation allows different parts of the system to use different identifier types, protecting the customer's true identity while enabling service management.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If service providers maintain all customer identifier information, then comprehensive account management is possible, but data protection and privacy compliance become difficult to ensure

Engineering Contradiction:
Improveaccount management easeVSAvoidprivacy information protection
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The anonymous identifier acts as a mediator that allows service providers to perform account management operations without accessing or storing sensitive personal information. The service provider can manage accounts using only the anonymous identifier, eliminating the need to handle or protect complex personal data while maintaining full operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If static pseudonyms are used for customer accounts, then simple identifier management is maintained, but customers cannot rotate or update their anonymous identifiers to enhance privacy

Engineering Contradiction:
Improveidentifier management complexityVSAvoididentifier rotation capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static pseudonym system into a dynamic one where anonymous identifiers can be rotated and updated. Customers can generate new anonymous identifiers and associate them with their accounts, allowing them to enhance privacy over time while the service provider continues to manage accounts using the current anonymous identifier without needing to understand or manage the rotation process.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250274441A1Customer-managed identifier rotation and anonymous processing
Publication Date: 2025.08.28 GOOGLE LLC
  • US20250274441A1 patent drawing
  • US20250274441A1 patent drawing
  • US20250274441A1 patent drawing

AI summary

Example embodiments of the present disclosure provide for an example method including establishing a computing environment accessible to a second computing system. The computing environment can include an anonymous identifier management tool. A first anonymous identifier associated with the second computing system can be established. Message data is exchanged from the computing environment to a first computing system. The message data can be associated with the first anonymous identifier without revealing a non-anonymous identifier associated with the first computing system. The anonymous identifier management tool can periodically update the first anonymous identifier to a second anonymous identifier. The first anonymous identifier and mapping data associating the first anonymous identifier and the second anonymous identifier is deleted.