Privacy-Preserving Data Linkage With Encrypted Statistical Counting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing systems fail to address the need for privacy protection when all user data is to be concealed, and there is a lack of techniques to generate statistical information without revealing a correspondence relationship with individuals, increasing the risk of privacy violations.
Innovation Solution
An information processing device employs encryption units to encrypt user IDs and attribute information using keyed one-way commutative operations and homomorphic encryption, followed by a counting process to generate encrypted count data, and a disclosure limitation process to produce statistical information without individual correlations, utilizing units like encryption, counting processing, and disclosure limitation units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user data is encrypted using traditional methods, then confidentiality is improved, but statistical analysis capability deteriorates
Solution Approach 1:
The patent changes the encryption parameter from traditional symmetric/asymmetric encryption to homomorphic encryption, which allows mathematical operations on encrypted data. This enables statistical analysis (counting, aggregation) to be performed directly on encrypted user data without decryption, thus maintaining confidentiality while preserving statistical analysis capability
Solution Approach 2:
The patent introduces homomorphic encryption as an intermediary between data confidentiality and statistical analysis. The encryption scheme acts as a mediator that transforms data into a form that is both confidential and computable, allowing the system to achieve both goals simultaneously through the special mathematical properties of homomorphic encryption
2Measurement precision
If user IDs are retained for data tracking, then data analysis accuracy is improved, but privacy protection deteriorates
Solution Approach 1:
The patent extracts and removes user IDs from the data processing pipeline entirely. Instead of retaining identifiers for tracking, the system processes only anonymized attribute data, eliminating the source of privacy risk while maintaining the ability to perform statistical analysis on user behavior patterns
Solution Approach 2:
The patent uses temporary, disposable session identifiers or anonymous tokens that are discarded after use, replacing persistent user IDs. These short-lived identifiers enable brief tracking for analysis purposes but cannot be used for long-term privacy invasion, thus balancing analysis accuracy with privacy protection
3Reliability
If all user data is concealed for privacy protection, then privacy security is improved, but data utility deteriorates
Solution Approach 1:
The patent changes the concealment parameter from complete data encryption to selective homomorphic encryption of only sensitive fields. This allows the system to maintain privacy security for sensitive data while preserving the utility of non-sensitive data for statistical analysis, thus resolving the contradiction between security and utility
Solution Approach 2:
The patent segments user data into sensitive information (encrypted with homomorphic encryption) and non-sensitive information (processed in plaintext or with lighter protection). This segmentation allows different levels of protection applied to different data types, maintaining both privacy security and data utility simultaneously
Data Source
AI summary
An information processing device (10) holds user data including: a user ID and attribute information related to a user and includes an encryption unit (11) that encrypts the user ID in user data to be counted on the basis of an encryption key held by the information processing device itself and a keyed one-way commutative operation and encrypts the attribute information in the user data using a homomorphic encryption method, in which a counting process is executable, to generate encrypted user data for the user data; a counting processing unit (12) that counts the number of encrypted user data items having common attribute information to generate encrypted count data; and a disclosure limitation processing unit (13) that executes a disclosure limitation process on the generated encrypted count data to generate encrypted statistical information.


