Dynamic De-Identifiers for Privacy-Preserving Data Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively balance data privacy and security with the need for personalized services and research, as static identifiers can be easily tracked and lead to re-identification, compromising anonymity and security.
Innovation Solution
The use of dynamically changing, temporally unique de-identifiers (DDIDs) that change over time or with purpose, preventing the retention of metadata that could reveal personal information, allowing data subjects to maintain control over their anonymity and privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static identifiers are used for data tracking and personalized services, then service personalization and research accuracy are improved, but data privacy and security deteriorate due to easy tracking and re-identification
Solution Approach 1:
The patent applies dynamics by replacing static identifiers with dynamic de-identifiers (DDIDs) that change over time. The DDID rotates between different values (e.g., DDID1, DDID2, DDID3) at different time points, allowing the same data subject to be represented by different identifiers in different contexts. This dynamic approach maintains the ability to provide personalized services through controlled re-association while preventing continuous tracking and re-identification, thus resolving the contradiction between service personalization and data privacy protection.
2Measurement precision
If static identifiers are used for data collection, then research accuracy and data utility are improved, but anonymity and security are compromised
Solution Approach 1:
The patent applies preliminary action by pre-planning and pre-executing identifier rotation before re-identification can occur. The system proactively changes the DDID at predetermined intervals or triggers, ensuring that by the time any tracking or analysis attempt is made, the identifier has already changed. This preliminary rotation action prevents the accumulation of trackable data points that could lead to re-identification, while still allowing research accuracy through controlled re-association within authorized contexts.
3Object-affected harmful factors
If dynamically changing de-identifiers are used, then data privacy and security are improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary component (the DDID rotation mechanism and association system) that mediates between data collection needs and privacy protection requirements. This intermediary layer manages the complexity of dynamic identifier rotation by providing automated rotation logic, secure storage of DDID mappings, and controlled re-association capabilities. The intermediary absorbs the system complexity while presenting a simplified interface to both data subjects and researchers, thus resolving the contradiction between enhanced privacy protection and system complexity.
4Reliability
If dynamic de-identifiers rotate over time, then re-identification is prevented, but data continuity and tracking capability are reduced
Solution Approach 1:
The patent applies segmentation by dividing the continuous data collection process into discrete time segments, each associated with a different DDID value. Instead of using a single continuous identifier, the system segments the identification process into multiple discrete identifier instances (DDID1 for time period 1, DDID2 for time period 2, etc.). This segmentation prevents continuous tracking across time while maintaining data continuity within each segmented period, and enables controlled re-association across segments when authorized, thus resolving the contradiction between anonymity maintenance and data continuity.
Data Source
AI summary
Various systems, computer-readable media, and computer-implemented methods of providing improved data privacy, anonymity, and security by enabling subjects to which data pertains to remain “dynamically anonymous,” i.e., anonymous for as long as is desired—and to the extent desired—are disclosed herein. This concept is also referred to herein as “anonosizing.” In some embodiments, the anonosizing of data may be implemented by encoding and decoding data under controlled conditions to support specific uses within designated authorized contexts. By anonosizing data controls via “identifying” and/or “associating” data elements within a population, data uses may be restricted to only those uses permissioned by a data subject or authorized third party. If new authorized data uses arise, all original data value and utility may be retained to support them—to the extent authorized by a data subject or authorized third party—but inappropriate, i.e., non-permissioned, uses of identifying information may be prevented.


