IoT Device PII Removal via Abstraction and Redaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The collection and transmission of personally identifiable data by IoT devices pose security risks and compliance issues, and existing safeguards like encryption add complexity and cost, while also requiring extensive data storage.

Innovation Solution

A computerized method that processes and removes personally identifiable data locally on IoT devices before transmission, using techniques such as abstraction or redaction to convert the data into anonymized insights, which are then sent externally, ensuring that only non-identifiable information is shared and stored.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied when transmitting personally identifiable data, then security risk is reduced, but device complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidcomplexity and processing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and removes personally identifiable data from the data stream before transmission or storage. By taking out the harmful component (PII) rather than protecting the entire data stream, the system achieves security without requiring encryption infrastructure, thereby reducing device complexity and processing overhead while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If personally identifiable data is stored for longer periods with safeguards, then compliance requirements are met, but storage cost and data volume increase

Engineering Contradiction:
Improvecompliance requirement satisfactionVSAvoidamount of data storage needed
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent removes personally identifiable data from stored datasets, retaining only anonymized information. This extraction approach allows the system to maintain data for compliance purposes without storing the full volume of sensitive information, thereby reducing storage costs and data volume while still meeting legal retention requirements

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent discards personally identifiable data while recovering and retaining the useful analytical information in anonymized form. By discarding the harmful PII component and keeping the valuable non-identifiable data, the system achieves compliance without proportional storage cost increases

Inventive Principle:
Principle #34Discarding and recovering

3Productivity

If personally identifiable data is collected and transmitted, then analytics capabilities are enabled, but security risks and compliance issues arise

Engineering Contradiction:
Improveanalytics capabilityVSAvoidsecurity risk and compliance issue
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personally identifiable data from the collected information stream, separating the harmful PII component from the useful analytical data. This allows analytics to proceed on anonymized datasets, maintaining productivity while eliminating security risks and compliance issues associated with PII transmission

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent converts the potentially harmful personally identifiable data into beneficial anonymized information through removal of identifying characteristics. The same data collection infrastructure that could create security risks is instead used to generate valuable analytics from anonymized sources, turning a potential harm into a benefit

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP3692461B1Removing personally identifiable data before transmission from a device
Publication Date: 2023.06.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3692461B1 patent drawingFigure 1
  • EP3692461B1 patent drawingFigure 2
  • EP3692461B1 patent drawingFigure 3

AI summary

A device for removal of personally identifiable data receives monitoring data acquired by a sensor. The monitoring data including personally identifiable data relating to one or more individuals being monitored. The system processes the acquired monitoring data to remove the personally identifiable data by at least one of abstraction or redaction while the monitoring data is located on the device. The processed monitoring data having the personally identifiable data removed can thereby be transmitted external to the device with reduced security risk.