Data Privacy Apparatus for Content Distribution Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content delivery networks face challenges in ensuring the privacy of user data, as small datasets can be used to identify subscribers through derivative association, despite anonymization efforts, due to correlation with other data sources.

Innovation Solution

Implementing methods and apparatus to adjust and collapse anonymized data sets by broadening, replacing, or eliminating fields, ensuring that the cardinality of subsets meets predetermined thresholds to minimize the risk of identifying users, using algorithms to determine necessary adjustments and applying data privacy enhancement protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If anonymized data sets are transmitted to third parties for analysis, then data utility and commercial value are improved, but user privacy is compromised due to derivative association risks

Engineering Contradiction:
Improvedata utilityVSAvoidprivacy risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies parameter changes by modifying data set parameters (cardinality thresholds, field selections, aggregation levels) to balance privacy protection and data utility. The system dynamically adjusts these parameters based on risk assessment to enable safe data sharing.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary data processing system that sits between the data holder and third-party analysts. This intermediary evaluates data sets, applies privacy-enhancing transformations, and only releases data that meets privacy thresholds, thus mediating the conflict between utility and privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If data sets are transmitted without adjustment, then data accuracy and analytical value are improved, but the risk of identifying users through derivative association increases

Engineering Contradiction:
Improvedata accuracyVSAvoidprivacy protection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements preliminary action by evaluating and adjusting data sets before transmission to third parties. The system proactively identifies privacy risks and applies transformations in advance, ensuring privacy protection is built into the data sharing process rather than added reactively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential harm of data transmission (privacy exposure) into a benefit by using automated evaluation and adjustment processes. The system transforms risky raw data into safe, privacy-preserving data products that maintain analytical value while eliminating identification risks.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Object-affected harmful factors

If data fields are broadened or collapsed to protect privacy, then user identification risk is reduced, but data specificity and analytical precision deteriorate

Engineering Contradiction:
Improveidentification riskVSAvoiddata specificity
Core Design Contradiction:
Object-affected harmful factorsVSManufacturing precision

Solution Approach 1:

The patent applies partial action by selectively broadening or collapsing only specific data fields that pose identification risks, rather than transforming the entire data set. This allows the system to maintain high specificity in non-sensitive fields while applying privacy protection only where necessary.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements local quality by applying different transformation levels to different data fields based on their sensitivity and identification potential. The system evaluates each field's contribution to user identification and applies targeted adjustments, preserving data quality in low-risk areas while protecting high-risk areas.

Inventive Principle:
Principle #3Local quality

4Productivity

If automated algorithms are used to evaluate and adjust data sets, then processing efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by designing automated algorithms that autonomously evaluate data sets, assess privacy risks, and apply appropriate transformations without manual intervention. The system serves itself by making decisions about data processing based on predefined criteria and automated evaluation metrics.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent manages complexity through parameter changes by adjusting algorithmic parameters (thresholds, evaluation criteria, transformation rules) to optimize the balance between automation capability and system complexity. The system dynamically tunes these parameters based on data characteristics and privacy requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11271909B2Apparatus and methods ensuring data privacy in a content distribution network
Publication Date: 2022.03.08 TIME WARNER CABLE ENTERPRISES LLC
  • US11271909B2 patent drawing
  • US11271909B2 patent drawing
  • US11271909B2 patent drawing

AI summary

Methods and apparatus for ensuring the privacy of users and/or devices in a content delivery network from which data regarding the users' interaction with content is collected and distributed. In one embodiment, “tuning” records which describe the interaction of users with content or other activities of interest are collected. It is determined whether an opportunity for compromise of the user's privacy (e.g., by derivative association) is present. If it is determined that such an opportunity exists, at least portions of the data are modified (e.g., collapsed). The modification may comprise replacing a first explicit data value with a second descriptive data value, increasing a range for the value, generalizing the value, removing the value, or encoding the value. Further processing of the collected tuning records may include, validating the data, accounting for latency, and generating reports based thereon.