Dynamic De-identifiers for Privacy-Preserving Data Personalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively balance data privacy and security with the need for personalized services and research, as static identifiers can be easily tracked and lead to re-identification, compromising anonymity and security.
Innovation Solution
The use of dynamically changing, temporally unique de-identifiers (DDIDs) that change over time, allowing data subjects to remain anonymous and control the sharing of information, preventing the retention of metadata that could reveal personal data attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static identifiers are used to track and personalize services, then service personalization and research capabilities are improved, but data privacy and security deteriorate due to easy tracking and re-identification
Solution Approach 1:
The patent applies the Dynamics principle by replacing static identifiers with dynamic de-identifiers (DDIDs) that change over time. The DDID is regenerated periodically or upon specific events, making tracking difficult while preserving the ability to provide personalized services through temporary associations between DDIDs and user profiles during active sessions.
Solution Approach 2:
The patent introduces an intermediary mechanism where the DDID acts as a temporary mediator between the user and the system. The DDID allows the system to access user data for personalization and research purposes without exposing the user's true identity, creating a protective layer that enables service delivery while maintaining privacy.
2Loss of information
If data is collected and stored for research and commerce, then research capabilities and commercial value are improved, but security and anonymity deteriorate due to aggregation risks
Solution Approach 1:
The patent applies segmentation by dividing user data access into temporal segments. Data is associated with DDIDs that are valid only for specific time periods or sessions, preventing long-term aggregation that could lead to re-identification. Research and commercial activities can access segmented data without obtaining a complete, persistent user profile.
Solution Approach 2:
The patent changes the temporal parameter of identifier validity. The DDID has a limited lifespan and changes over time, transforming the security model from permanent association to temporary association. This parameter change allows data to be useful for research and commerce during the DDID's valid period while preventing long-term tracking and aggregation.
3Measurement precision
If identifiers persist over time for tracking purposes, then tracking accuracy and service delivery are improved, but re-identification risk increases due to unlimited time for analysis
Solution Approach 1:
The patent implements periodic action by regenerating the DDID at regular intervals or upon specific events. This periodic renewal maintains tracking accuracy within each period while preventing long-term accumulation of identifying information. The system can track user behavior accurately during each DDID's valid period, then reset anonymity when the DDID changes.
Data Source
Figure 1
Figure 1A
Figure 1B
AI summary
Various systems, computer-readable media, and computer-implemented methods of providing improved data privacy, anonymity and security by enabling subjects to which data pertains to remain "dynamically anonymous," i.e., anonymous for as long as is desired— and to the extent that is desired— are disclosed herein. Embodiments include systems that create, access, use, store and / or erase data with increased privacy, anonymity and security, thereby facilitating the availability of more qualified and accurate information. When data is authorized by subjects to be shared with third parties, embodiments may facilitate sharing information in a dynamically controlled manner that enables delivery of temporally-, geographically-, and / or purpose-limited information to the receiving party. In one example, anonymity measurement scores may be calculated for the shared data elements so that a level of consent / involvement required by the Data Subject before sharing the relevant data elements to third parties may be specified.