iCAT Data Anonymization Views for Privacy Utility Trade-offs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data anonymization solutions are inflexible and fail to accommodate varying privacy and utility requirements of both data owners and processors, leading to incomplete data sharing and increased risk of privacy breaches, as they often prioritize either privacy or utility at the expense of the other, and lack integration of different anonymization methods.

Innovation Solution

The iCAT system allows for customizable anonymization by generating an access control matrix based on privacy constraints and utility requirements, enabling different anonymization levels for data attributes, and providing a bridge between data owners' privacy needs and processors' utility needs through a modular architecture that includes data preprocessing, anonymization, and access control mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional anonymization tools are used, then data can be anonymized, but the tools are inflexible and cannot accommodate varying privacy and utility requirements of different users

Engineering Contradiction:
Improveanonymization flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts anonymization parameters based on user roles, trust levels, and data sensitivity. Different users receive customized anonymization configurations rather than a static one-size-fits-all approach, allowing the system to adapt to varying privacy and utility requirements while managing complexity through automated role-based policies

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes anonymization parameters such as k-anonymity thresholds, suppression rates, and generalization levels based on user characteristics and data sensitivity. This allows flexible adaptation to different requirements without requiring completely different systems for each scenario

Inventive Principle:
Principle #35Parameter changes

2Reliability

If strong anonymization is applied to protect privacy, then privacy constraints are met, but data utility is reduced making it useless for analysis

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Different anonymization strengths are applied to different data attributes and different user groups. Sensitive attributes receive stronger anonymization while less sensitive attributes maintain higher utility. This local differentiation allows the system to protect privacy where needed while preserving data utility for analysis purposes

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial anonymization rather than complete anonymization, using techniques like k-anonymity where data is sufficiently protected for privacy but retains enough information for useful analysis. This avoids the extreme of complete anonymization that would render data useless

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If data owners enforce strict privacy requirements, then privacy is protected, but data processors cannot access useful information and data sharing is prevented

Engineering Contradiction:
Improveprivacy constraint enforcementVSAvoiddata sharing effectiveness
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system acts as an intermediary between data owners and processors, translating privacy requirements into appropriate anonymization configurations. It mediates the conflict by finding configurations that satisfy privacy constraints while maintaining sufficient utility for processors, enabling data sharing that would otherwise be blocked

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system incorporates feedback loops where anonymization configurations are evaluated based on both privacy metric satisfaction and data utility. This feedback mechanism allows iterative adjustment of anonymization parameters to achieve the optimal balance between privacy protection and data sharing effectiveness

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If existing anonymization tools are used, then anonymization can be performed, but they lack integration of different anonymization methods and cannot be systematically evaluated

Engineering Contradiction:
Improveanonymization method integrationVSAvoidevaluation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system merges multiple anonymization techniques including k-anonymity, l-diversity, t-closeness, and suppression into a unified framework. This integration allows the system to leverage the strengths of different methods while managing complexity through a systematic evaluation framework that automatically selects appropriate combinations

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12124610B2Data anonymization views
Publication Date: 2024.10.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12124610B2 patent drawing
  • US12124610B2 patent drawing
  • US12124610B2 patent drawing

AI summary

Systems and methods for anonymizing data are provided herein. A network node can receive privacy constraints from a data owner and utility requirements from at least one data processor. An anonymization mechanism can be selected for each data attribute in a data set, based on its specified privacy constraint and/or utility requirement, from the available anonymization mechanism(s) appropriate for its associated attribute type.