Data Management System for Third-Party Sensor Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The aggregation of data from multiple third-party devices creates privacy and security risks for users, as this data can potentially reveal personally identifying information (PII) and expose users to other privacy and security concerns.
Innovation Solution
A data management system that includes monitoring devices with sensors generating sensor data, which is transmitted to a third-party system. The system uses a processor to receive user information, request sensor data, analyze the data for risk values, and output instructions to purge the data based on these risk values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensor data from multiple third-party devices is aggregated and stored in a remote server, then the system can monitor and analyze user environment effectively, but privacy and security risks increase due to potential exposure of personally identifying information
Solution Approach 1:
The patent extracts and removes personally identifying information (PII) from sensor data during the data processing pipeline. The system separates PII from non-PII data, storing only the anonymized portions in the remote server, thereby maintaining monitoring effectiveness while eliminating privacy risks associated with stored PII.
Solution Approach 2:
The patent introduces an intermediary data processing layer between the third-party devices and the remote server. This intermediary component anonymizes data by removing PII before transmission and storage, acting as a mediator that preserves data utility for monitoring while protecting user privacy and security.
2Ease of operation
If sensor data is stored in a remote server accessible by the third-party device manufacturer, then data accessibility and analysis capability are improved, but the number of storage locations increases creating additional security exposure points
Solution Approach 1:
The patent extracts PII from sensor data before storage, removing the sensitive elements that would require multiple secure storage locations. This allows the system to maintain data accessibility in a centralized remote server while eliminating the need for additional secure storage points, thereby reducing security exposure.
Solution Approach 2:
The patent changes the state of the data by transforming it from identifiable to anonymized form. This parameter change (from PII-containing to PII-free) allows the data to be stored in a single remote server location with reduced security requirements, maintaining accessibility while simplifying the storage architecture.
3Reliability
If the system continuously monitors and analyzes sensor data for privacy risks, then security risk detection capability is improved, but computational resources and processing time are consumed
Solution Approach 1:
The patent performs preliminary anonymization of sensor data by removing PII before the data is transmitted to and stored in the remote server. This preliminary action eliminates the need for continuous computational analysis of PII for privacy risk detection, as the PII is already removed, thereby reducing ongoing computational resource consumption while maintaining security risk detection for other threats.
Data Source
AI summary
A data management system may include a monitoring device comprising a sensor, a memory storing executable instructions, and a processor. The sensor may generate sensor data and transmits the sensor data to a third-party system. The processor may receive the sensor data from the third-party system and associate the sensor data with a user account. The user account may include additional sensor data from other monitoring devices and such that the sensor data together with the additional sensor data comprises aggregated sensor data. The processor may determine a risk value of the aggregated sensor data is greater than a risk threshold and flag the user account in response to determining the risk value of the sensor data is greater than the risk threshold. The processor may also transmit a signal indicative of the flagged user account to an application of a user device.


