Encrypted Data Aggregation for Privacy-Preserving Measurement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing analytics systems face challenges in aggregating interaction data across multiple entities while maintaining user privacy, as they often require access to personal information to perform aggregation, which compromises user anonymity.

Innovation Solution

A method involving advanced cryptography and computer architectures that encrypt and conceal user identifiers and values, allowing for secure aggregation of data without revealing personal information, using techniques like elliptic curve encryption and homomorphic encryption to enable secure data correlation and credit distribution among content publishers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional analytics systems aggregate interaction data, then measurement precision is improved, but user privacy is compromised due to access to personal information

Engineering Contradiction:
Improveaggregation accuracyVSAvoidprivacy loss
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system segments the aggregation process into multiple independent computing systems, each holding different data portions. The first computing system holds encrypted identifiers, the second holds encrypted values, and a third decrypts results. This segmentation allows aggregation to proceed without any single system accessing both identifiers and values in plaintext, thus maintaining privacy while achieving measurement precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encrypted identifiers and encrypted values as intermediary representations that enable aggregation without direct access to personal information. These encrypted forms act as mediators that preserve the ability to perform aggregation operations while preventing privacy compromise, as the encryption schemes allow mathematical operations on encrypted data without decryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encrypted data is used to protect privacy, then user privacy is improved, but device complexity increases due to cryptographic operations

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic complexity from the core aggregation logic by separating encryption/decryption operations into dedicated computing systems. The first computing system performs encryption on identifiers, the second system performs aggregation on encrypted values, and the third system handles decryption. This extraction allows each component to be optimized independently, managing overall system complexity while maintaining strong privacy protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary encryption of identifiers and values before the aggregation process begins. By pre-encrypting the data using established cryptographic schemes, the patent eliminates the need for complex real-time encryption during aggregation, reducing operational complexity while maintaining privacy protection throughout the measurement process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11841973B2Methods for aggregating credit across interactions
Publication Date: 2023.12.12 GOOGLE LLC
  • US11841973B2 patent drawing
  • US11841973B2 patent drawing
  • US11841973B2 patent drawing

AI summary

A method disclosed herein may include receiving, at a first computing system, encrypted identifiers and encrypted values, performing, by the first computing system, a concealing operation on the encrypted identifiers to produce concealed encrypted identifiers, wherein the concealing operation conceals the encrypted identifiers from the first computing system and a second computing system but enables matching between the concealed encrypted identifiers, decrypting, by the second computing system, the concealed encrypted identifiers to produce concealed identifiers, and performing, by the second computing system, an aggregation operation using the concealed identifiers and the encrypted values to produce an encrypted aggregate value without accessing personally identifiable information associated with the encrypted values.