Dynamic De-Identifiers for Privacy-Preserving Data Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to maintain high levels of privacy and anonymity in decentralized networks, such as those using blockchain, while allowing for the extraction of informational value, as static identifiers are easily tracked and lead to re-identification, compromising data security and accuracy.
Innovation Solution
The implementation of dynamically changing de-identifiers (DDIDs) that are temporally unique and re-assignable, allowing Data Subjects to remain anonymous until they choose to share information, enabling controlled, geographically, and purpose-limited data sharing, even in decentralized networks, by using a Circle of Trust (CoT) to manage and obscure data elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If static identifiers are used in decentralized networks, then data extraction and analytics are enabled, but privacy and anonymity are compromised due to easy tracking and re-identification
Solution Approach 1:
The patent implements dynamically changing de-identifiers (DDIDs) that are temporally unique and re-assignable, transforming static identifiers into dynamic ones. This allows Data Subjects to remain anonymous until they choose to share information, enabling controlled data sharing while preventing continuous tracking and re-identification that occurs with static identifiers
Solution Approach 2:
The patent segments data elements into a Circle of Trust (CoT) framework where different data elements are separated and controlled independently. This segmentation allows selective sharing of specific data elements while maintaining anonymity for others, resolving the contradiction between extracting informational value and preserving privacy
2Productivity
If data is shared in decentralized networks, then analytics and AI benefits are achieved, but data aggregation enables re-identification and compromises security
Solution Approach 1:
The dynamically changing DDIDs prevent data aggregation across different time periods and contexts, as each DDID is temporally unique and cannot be linked to form a comprehensive profile. This maintains data security while still enabling analytics on the shared data elements
Solution Approach 2:
The Circle of Trust (CoT) acts as an intermediary framework that manages data sharing between Data Subjects and external systems. It controls which data elements are shared and under what conditions, enabling analytics capabilities while preventing unauthorized data aggregation that would compromise security
3Object-affected harmful factors
If anonymity is maintained in decentralized networks, then privacy is protected, but data accuracy and usefulness for AI/ML are reduced
Solution Approach 1:
The patent applies different levels of identification and anonymity to different data elements based on local requirements. The Circle of Trust framework allows specific data elements to be shared with appropriate precision for AI/ML applications while maintaining anonymity for other elements, resolving the contradiction between privacy protection and data usefulness
Data Source
AI summary
Systems, program storage devices, and methods for improving data privacy/trust/anonymity/pseudonymity and data value, wherein data related to a Data Subject can be used and stored, while minimizing re-identification risk by unauthorized parties and enabling data related to the Data Subject to be disclosed to an authorized party by granting access only to the data relevant to that authorized party's purpose, time, place, and/or other criterion via the obfuscation of specific data values. The techniques described herein maintain this level of privacy/trust/anonymity/pseudonymity, while empowering Data Subjects, e.g., consumers or customers of such authorized parties, by enabling protection of data at the desired level of engagement with various business entities. The techniques described herein also allow Data Controllers to perform General Data Protection Regulation (GDPR) and Schrems II-compliant (and surveillance-proof) data processing, via the functional separation of heterogeneous data (e.g., via the use of “Variant Twins”) from embedded trust and privacy controls.


