Ephemeral Cohort Privacy for Wearable Sensor Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for safeguarding sensor data from wearable devices, such as encryption and anonymous identifiers, are inadequate in preventing user de-anonymization due to the complexity and economic overhead of encryption, and the vulnerability of anonymization techniques to pattern recognition in large volumes of sensor data.

Innovation Solution

Assigning users with temporary membership to ephemeral cohorts based on the analysis of event sensor data, where the probability of assigning a user identity exceeds a threshold, to hide user identities and prevent de-anonymization by adjusting data scales, adding noise, or modifying cohort dimensions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to safeguard sensor data, then data security is improved, but computing complexity and technical overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidcomputing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the approach to data protection by dividing users into cohorts and applying differential privacy at the cohort level rather than requiring encryption of every individual data point. This reduces computational overhead while maintaining security through aggregated protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses ephemeral cohorts that are temporary and disposable, created and destroyed as needed for specific analysis purposes. These cohorts provide temporary protection without the long-term computational burden of encryption, allowing data to be protected only when and where needed.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If anonymous identifiers are used to protect user privacy, then personal information protection is improved, but users can still be de-anonymized through pattern recognition in sensor data

Engineering Contradiction:
Improveprivacy protectionVSAvoidanonymity effectiveness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces cohorts as an intermediary layer between users and the data analysis system. Instead of directly anonymizing individual users, the cohort acts as a mediator that aggregates users together, making individual identification difficult while still enabling useful analysis at the group level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds the dimension of cohort membership to user identification. Rather than relying solely on traditional anonymization techniques that operate in the user dimension, the system introduces a new cohort dimension that obscures individual identities through group aggregation and temporary assignment.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If large volumes of sensor data are collected for commercialization, then economic benefit is improved, but user de-anonymization risk increases

Engineering Contradiction:
Improvecommercialization potentialVSAvoidde-anonymization risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent makes cohorts dynamic and temporary rather than static and permanent. Cohorts are created, used for analysis, and then dissolved, changing the state of data protection over time. This dynamic approach allows commercialization of data insights while periodically resetting privacy protections to prevent pattern recognition.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10963319B2Enhancing privacy of sensor data from devices using ephemeral cohorts
Publication Date: 2021.03.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10963319B2 patent drawing
  • US10963319B2 patent drawing
  • US10963319B2 patent drawing

AI summary

A method, system and computer program product for enhancing privacy of event data. Event sensor data (e.g., body temperature, heart rate data) is received and analyzed by a subscriber to form a probability of assigning a user identity to the received event sensor data. The user of the event sensor data is then assigned with a temporary membership to a cohort (related group of users that share common characteristic(s) or experience(s)) to hide the identity of the user in response to the probability of assigning the user identity to the received event sensor data exceeding a threshold. Actions may then be performed based on the temporary membership to the cohort in order to ensure that the probability of assigning a user identity to the received event sensor data does not exceed the threshold. In this manner, privacy of the user's sensitive data is enhanced.