Privacy-Preserving Ad Targeting via Generalized Persona Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing advertisement networks face challenges in maintaining user privacy, particularly in the IoT context, where data sharing for personalized advertising risks exposing identifiable information, and users have limited control over data flow, leading to privacy concerns and regulatory issues.

Innovation Solution

A system and method that involves a user device generalizing persona data, encrypting it with a session key, and communicating it through a mediator system to an advertisement network, using additive homomorphic encryption and pseudo-identity data to ensure privacy while allowing for targeted advertising without revealing personal identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If user data is tracked and shared for personalized advertising, then advertising effectiveness is improved, but user privacy is compromised

Engineering Contradiction:
Improveadvertising effectivenessVSAvoidprivacy exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces multiple intermediary layers including a mediator system, trusted execution environment (TEE), and additive homomorphic encryption to act as buffers between user data and advertising networks. These intermediaries enable processing of advertising-relevant information without exposing raw personal data, thus maintaining advertising effectiveness while protecting user privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms user data parameters by converting identifiable personal information into generalized persona attributes through cryptographic operations. Data is encrypted, generalized, and processed in transformed states that retain advertising utility while removing personally identifiable information, effectively changing the parameter representation to balance privacy and effectiveness.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If identifiable information is collected for advertising personalization, then targeting accuracy is improved, but regulatory compliance deteriorates

Engineering Contradiction:
Improvetargeting accuracyVSAvoidregulatory compliance
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments user information into multiple layers: identifiable information kept locally on user devices, generalized persona data processed by mediators, and encrypted tokens transmitted to advertising networks. This segmentation allows precise targeting through persona attributes while compliance is maintained by never exposing raw identifiable information to external systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-generalizing and encrypting user data before it leaves the user's device. Persona data is aggregated and anonymized in advance through TEE-protected processes, ensuring that only compliant, de-identified information enters the advertising ecosystem, thus preventing regulatory violations before they can occur.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If data is anonymized and encrypted to protect privacy, then user privacy is maintained, but data utility for advertising decreases

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent applies different levels of privacy protection and data processing to different components of user information. Sensitive personally identifiable information receives maximum encryption and local retention, while generalized persona attributes available for advertising processing retain more detail. This local quality differentiation maintains privacy for critical data while preserving utility for advertising-relevant characteristics.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system creates composite data structures combining multiple encrypted tokens, generalized attributes, and cryptographic proofs that together form a privacy-protecting yet advertising-useful information package. These composite representations integrate multiple privacy-preserving techniques to achieve both protection and utility simultaneously.

Inventive Principle:
Principle #40Composite materials

4Area of stationary object

If traditional tracking mechanisms are extended to IoT devices, then advertising reach is expanded, but consumer resistance increases

Engineering Contradiction:
Improveadvertising reachVSAvoidconsumer acceptance
Core Design Contradiction:
Area of stationary objectVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where IoT devices and user devices autonomously generate, encrypt, and manage their own persona data and advertising tokens without requiring continuous user interaction or consent. This automation reduces consumer burden and resistance while expanding reach to IoT ecosystems through privacy-preserving autonomous operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Mediator systems are introduced as trusted intermediaries that handle the complexity of cross-device and IoT data aggregation, allowing advertising networks to expand reach into IoT domains without directly exposing consumers to tracking mechanisms. The mediators absorb consumer-facing privacy concerns while enabling broad advertising deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11921888B2System, method, and computer program product for maintaining user privacy in advertisement networks
Publication Date: 2024.03.05 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11921888B2 patent drawing
  • US11921888B2 patent drawing
  • US11921888B2 patent drawing

AI summary

A method for maintaining user privacy in advertisement networks may include receiving first persona data associated with a first user from at least one publisher system. The first persona data may be generalized to form first generalized persona data. A session key may be generated. The first generalized persona data and the session key may be encrypted with a first public key of an advertisement network system to form a first ciphertext. The first ciphertext and first user identity data may be communicated to a mediator system. The first user identity data may be associated with first user's identity. A first encrypted targeted advertisement may be received based on the first generalized persona data from the advertisement network system via the mediator system. The first encrypted targeted advertisement may be decrypted with the session key to form a first targeted advertisement. A system and computer program product are also disclosed.