Dynamic De-identifiers for Privacy-Preserving Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively balance data privacy and security with the need for personalized offerings and research, as static identifiers can be easily tracked and lead to re-identification, compromising anonymity and security.
Innovation Solution
The implementation of dynamically changing de-identifiers (DDIDs) that are temporally unique and re-assignable, allowing data subjects to maintain anonymity and control over their data, preventing retention of metadata that could reveal personal information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static identifiers are used for tracking and personalization, then personalized offerings and research capabilities are improved, but data privacy and anonymity are compromised due to easy re-identification
Solution Approach 1:
The patent implements dynamic de-identifiers (DDIDs) that change over time rather than static identifiers. The DDID is regenerated periodically or based on specific triggers, making tracking difficult while allowing personalized services within each time window. This dynamic approach resolves the contradiction by enabling personalization during active sessions while preventing long-term re-identification.
Solution Approach 2:
The patent introduces an intermediary layer between the user's true identity and the data systems. The DDID acts as a mediator that allows personalized offerings to be delivered without exposing the actual identity. This intermediary mechanism enables research and personalization capabilities while maintaining anonymity, as the intermediary can be discarded or changed without affecting the underlying identity.
2Loss of information
If data is collected and stored for research and commerce, then research capabilities and commercial value are improved, but security and privacy protection are worsened
Solution Approach 1:
The patent applies different quality levels of identification to different data contexts. Within local contexts (specific time windows or sessions), the DDID provides sufficient identification for research and commercial purposes. However, across broader contexts, the identifier changes or is discarded, maintaining privacy security. This local quality approach allows data utility where needed while ensuring security where critical.
Solution Approach 2:
The patent changes key parameters of the identifier over time, including the DDID value itself, associated metadata, and expiration timestamps. These parameter changes enable the system to maintain useful data for research and commerce within valid time windows while automatically reducing security risks through expiration and regeneration. The dynamic parameter changes resolve the contradiction between data utility and security.
3Measurement precision
If identifiers are retained for extended periods, then data accuracy and personalized service quality are improved, but anonymity and security are compromised
Solution Approach 1:
The patent implements periodic regeneration of the DDID at defined intervals or upon specific triggers. This periodic action maintains data accuracy within each period by using consistent identifiers, while simultaneously preventing anonymity loss through regular changes. The periodic cycle ensures that no single identifier is retained indefinitely, resolving the contradiction between accuracy and anonymity.
Solution Approach 2:
The patent establishes predetermined expiration times and regeneration triggers for DDIDs before anonymity issues can arise. By implementing preliminary expiration mechanisms, the system ensures that identifiers are discarded or changed before they can be used for long-term tracking. This preliminary action maintains data accuracy during active periods while preventing future anonymity losses.
Data Source
AI summary
Various systems, computer-readable media, and computer-implemented methods of providing improved data privacy, anonymity and security by enabling subjects to which data pertains to remain “dynamically anonymous,” i.e., anonymous for as long as is desired—and to the extent that is desired—are disclosed herein. Embodiments include systems that create, access, use, store and/or erase data with increased privacy, anonymity and security, thereby facilitating the availability of more qualified and accurate information. When data is authorized by subjects to be shared with third parties, embodiments may facilitate sharing information in a dynamically controlled manner that enables delivery of temporally-, geographically-, and/or purpose-limited information to the receiving party. In one example, anonymity measurement scores may be calculated for the shared data elements so that a level of consent/involvement required by the Data Subject before sharing the relevant data elements to third parties may be specified.


