Data Controller for Privacy-Safe Analytics Outsourcing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The outsourcing of data analytics by utility companies to third-party service providers raises privacy concerns as they often provide excessive customer data, which can lead to unauthorized access and misuse, compromising customer privacy.

Innovation Solution

Implementing an access control policy that uses anonymous customer identifiers and evaluates each data query to determine if the requested data disclosure is allowed, ensuring only necessary data is shared and minimizing privacy risks by using a policy engine to manage and sanitize customer data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customer data is provided to third party service providers for data analytics, then data analytics capability is improved, but customer privacy is compromised

Engineering Contradiction:
Improvedata analytics capabilityVSAvoidcustomer privacy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data controller as an intermediary between the utility company (data provider) and third party service providers (data processors). This intermediary evaluates data queries, enforces access control policies, and sanitizes data before release, enabling analytics while protecting privacy through controlled mediation of data access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms customer data by removing personally identifiable information (sanitization) and converting it into anonymized datasets that retain analytical value but eliminate direct identification capability. This parameter change in data composition allows analytics to proceed while mitigating privacy risks

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If access control policies are implemented to protect customer privacy, then customer privacy is improved, but data sharing efficiency deteriorates

Engineering Contradiction:
Improvecustomer privacy protectionVSAvoiddata sharing efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-establishing access control policies and data sanitization rules before data sharing occurs. The data controller evaluates queries against predetermined policies and pre-sanitizes data, avoiding ad-hoc privacy assessments and improving overall data sharing efficiency through proactive governance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates sanitized copies of customer data that can be shared with third parties without exposing original sensitive information. These copied datasets maintain analytical utility while eliminating privacy risks, enabling efficient data sharing under access control policies

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9292706B2Customer data management for data analytics outsourcing
Publication Date: 2016.03.22 FUJITSU LTD
  • US9292706B2 patent drawing
  • US9292706B2 patent drawing
  • US9292706B2 patent drawing

AI summary

A method of customer data management in data analytics outsourcing includes communicating to a third party service provider an anonymous customer identifier (customer ID) that is uniquely associated with a customer. The method includes receiving from the third party service provider a customer data query that references the customer using the customer ID and requests customer data. The method includes determining whether an access control policy allows disclosure of customer data requested in the customer data query. In response to the access control policy allowing disclosure of the requested customer data, the method includes accessing the requested customer data and communicating the requested customer data to the third party service provider. In response to the access control policy prohibiting disclosure of the requested customer data, the method includes denying the customer data query.