History Information Anonymization via Selective ID Grouping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional anonymization methods, such as k-anonymity, often result in information loss when anonymizing history information from household electrical appliances or AV equipment, particularly when temporary IDs need to be changed frequently, which hinders data analysis across different time periods.
Innovation Solution
A history information anonymization method that associates and groups user device data, selectively changes IDs only when anonymity is not satisfied, and extends the ID replacement period to prevent information loss while maintaining anonymity, by grouping user devices based on identical history information and adjusting IDs within these groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional anonymization methods (k-anonymity) are used to process history information, then individual anonymity is protected, but information loss occurs and ID replacement frequency increases
Solution Approach 1:
The patent segments the anonymization process into distinct steps: association (linking history information with user device IDs), grouping (clustering devices with identical history information), anonymity judgment (evaluating whether groups meet anonymity thresholds), and selective ID changing (modifying IDs only when necessary). This segmentation allows precise control over when anonymization is applied, preventing unnecessary information loss while maintaining anonymity where sufficient.
Solution Approach 2:
Instead of applying anonymization universally to all history information, the patent applies partial action by selectively changing IDs only for user devices that fail the anonymity judgment criterion. Devices that already satisfy anonymity requirements retain their original IDs and associated history information intact, thus avoiding unnecessary information loss while still protecting anonymity where needed.
2Reliability
If frequent ID replacement is performed to maintain anonymity, then individual identification is prevented, but data analysis across time periods becomes difficult
Solution Approach 1:
The patent implements periodic anonymization evaluation by judging anonymity at regular intervals (each collection cycle) and only performing ID changes when the judgment indicates anonymity is insufficient. This periodic approach with conditional execution reduces the frequency of ID replacements compared to conventional methods, maintaining anonymity while preserving temporal continuity for data analysis.
Solution Approach 2:
The anonymity judgment step provides feedback on whether current ID assignments satisfy anonymity requirements. This feedback mechanism allows the system to adaptively determine whether ID changes are necessary, rather than following a fixed replacement schedule. When feedback indicates anonymity is sufficient, ID changes are deferred, preserving temporal continuity for analysis while maintaining privacy protection.
3Reliability
If all user device IDs are changed to ensure anonymity, then privacy protection is maximized, but information loss increases and processing complexity rises
Solution Approach 1:
The patent applies local quality by treating different user devices differently based on their specific anonymity requirements. Instead of uniformly changing all IDs, the system evaluates each device's history information group and applies ID changes only where locally necessary to meet anonymity thresholds. This localized approach reduces overall processing complexity and information loss while maintaining adequate privacy protection.
Solution Approach 2:
The patent changes the parameter of ID modification from a fixed rule (change all IDs) to a dynamic condition-based parameter (change IDs only when anonymity judgment fails). This parameter change allows the system to adapt the degree of anonymization to actual needs, reducing unnecessary processing complexity and information loss while maintaining privacy protection where required.
Data Source
AI summary
A history information anonymization method is provided that includes associating each of a plurality of pieces of history information collected from a plurality of TVs in a current cycle with a temporary ID associated with a TV at a collection destination. The method also includes getting together a plurality of IDs into a plurality of groups such that for the IDs in each group, contents of history information associated in the current cycle and in a past cycle are identical. The method further includes judging whether each of the plurality of groups satisfies anonymity, and changing only some of the plurality of temporary IDs associated with the plurality of TVs, when it is judged that any of the plurality of groups does not satisfy anonymity.


