Privacy-Preserving Data Linkage With Encrypted Statistical Counting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems fail to address the need for privacy protection when all user data is to be concealed, and there is a lack of techniques to generate statistical information without revealing a correspondence relationship with individuals, increasing the risk of privacy violations.

Innovation Solution

An information processing device employs encryption units to encrypt user IDs and attribute information using keyed one-way commutative operations and homomorphic encryption, followed by a counting process to generate encrypted count data, and a disclosure limitation process to produce statistical information without individual correlations, utilizing units like encryption, counting processing, and disclosure limitation units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user data is encrypted using traditional methods, then confidentiality is improved, but statistical analysis capability deteriorates

Engineering Contradiction:
ImproveconfidentialityVSAvoidstatistical analysis capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the encryption parameter from traditional symmetric/asymmetric encryption to homomorphic encryption, which allows mathematical operations on encrypted data. This enables statistical analysis (counting, aggregation) to be performed directly on encrypted user data without decryption, thus maintaining confidentiality while preserving statistical analysis capability

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces homomorphic encryption as an intermediary between data confidentiality and statistical analysis. The encryption scheme acts as a mediator that transforms data into a form that is both confidential and computable, allowing the system to achieve both goals simultaneously through the special mathematical properties of homomorphic encryption

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If user IDs are retained for data tracking, then data analysis accuracy is improved, but privacy protection deteriorates

Engineering Contradiction:
Improvedata analysis accuracyVSAvoidprivacy risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes user IDs from the data processing pipeline entirely. Instead of retaining identifiers for tracking, the system processes only anonymized attribute data, eliminating the source of privacy risk while maintaining the ability to perform statistical analysis on user behavior patterns

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses temporary, disposable session identifiers or anonymous tokens that are discarded after use, replacing persistent user IDs. These short-lived identifiers enable brief tracking for analysis purposes but cannot be used for long-term privacy invasion, thus balancing analysis accuracy with privacy protection

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If all user data is concealed for privacy protection, then privacy security is improved, but data utility deteriorates

Engineering Contradiction:
Improveprivacy securityVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the concealment parameter from complete data encryption to selective homomorphic encryption of only sensitive fields. This allows the system to maintain privacy security for sensitive data while preserving the utility of non-sensitive data for statistical analysis, thus resolving the contradiction between security and utility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments user data into sensitive information (encrypted with homomorphic encryption) and non-sensitive information (processed in plaintext or with lighter protection). This segmentation allows different levels of protection applied to different data types, maintaining both privacy security and data utility simultaneously

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260057102A1Information processing device and privacy protection data linkage system
Publication Date: 2026.02.26 NTT DOCOMO INC
  • US20260057102A1 patent drawing
  • US20260057102A1 patent drawing
  • US20260057102A1 patent drawing

AI summary

An information processing device (10) holds user data including: a user ID and attribute information related to a user and includes an encryption unit (11) that encrypts the user ID in user data to be counted on the basis of an encryption key held by the information processing device itself and a keyed one-way commutative operation and encrypts the attribute information in the user data using a homomorphic encryption method, in which a counting process is executable, to generate encrypted user data for the user data; a counting processing unit (12) that counts the number of encrypted user data items having common attribute information to generate encrypted count data; and a disclosure limitation processing unit (13) that executes a disclosure limitation process on the generated encrypted count data to generate encrypted statistical information.