Dynamic De-identifier Data Matching for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for combining disparate data sets lack effective privacy protection, as they often rely on persistent identifiers, which may not provide sufficient anonymity, especially when combining data sets without any personally identifiable information.
Innovation Solution
The use of dynamic de-identifiers (DDIDs) to match and combine data sets without personally identifiable information, ensuring that no persistent identifiers are used during the process, thereby enhancing privacy protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If persistent identifiers are used to combine data sets, then data combination capability is improved, but privacy protection level deteriorates
Solution Approach 1:
The patent applies dynamics by transitioning from static persistent identifiers to dynamic de-identifiers that change over time. The system generates temporary identifiers that are valid only for specific time windows or sessions, allowing data combination capabilities while automatically expiring to maintain privacy protection. This resolves the contradiction by making the identifier system adaptable rather than fixed.
Solution Approach 2:
The patent introduces an intermediary component that acts as a bridge between data sets without exposing persistent identifiers. The system uses a matching service that receives de-identified data, performs matching operations using temporary identifiers, and returns results without revealing underlying personal information. This intermediary layer enables data combination while maintaining privacy boundaries.
2Object-affected harmful factors
If dynamic de-identifiers are used instead of persistent identifiers, then privacy protection level is improved, but data matching reliability deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-establishing matching criteria and validation rules before dynamic de-identifier matching occurs. The system defines matching thresholds, time window parameters, and confidence levels in advance, ensuring that even with changing identifiers, reliable matches can be achieved through pre-configured parameters that account for dynamic variations.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously monitors matching success rates and adjusts dynamic de-identifier parameters accordingly. When matching reliability drops, the system can extend time windows, adjust identifier rotation frequency, or refine matching algorithms based on observed performance, maintaining reliability while preserving privacy enhancement benefits.
3Object-affected harmful factors
If multiple computing devices are used to process data, then privacy protection through distributed processing is improved, but system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the data processing system into distinct functional components across multiple devices. Each device performs specific tasks such as data reception, de-identification, matching operations, or result generation, rather than requiring one device to handle all functions. This modular segmentation enables distributed processing for privacy while managing complexity through clear functional boundaries.
Solution Approach 2:
The patent implements universality by designing processing devices that can perform multiple functions within the data combination workflow. A single device can alternatively serve as a data receiver, de-identification processor, or matching engine depending on system configuration, reducing the need for specialized dedicated hardware and simplifying the overall multi-device architecture while maintaining distributed processing benefits.
Data Source
AI summary
A method for combining disparate data sets using dynamic de-identifiers includes: receiving a first data set from a first external entity, the data set including first data entries including attribute values, and wherein the first data set does not include any personally identifiable information; receiving a second data set from a second external entity, the data set including second data entries including attribute values, and wherein the second data set does not include any personally identifiable information; identifying a dynamic de-identifier (DDID) for each first data entry and second data entry; matching each second data entry to a first data entry based on a correspondence between the associated attribute values; identifying insights for at least one first data entry based on at least the attribute values included in the corresponding matched second data entry; and transmitting at least the identified insights to the first external entity.


