Metadata Anonymization Policy Enforcement for User Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current unified endpoint management (UEM) systems lack a method to protect user anonymity and prevent unwanted metadata disclosure, as they do not provide policies to control or modify metadata associated with user-generated content.
Innovation Solution
A computing device enrolls with a server having a metadata anonymization policy, generating and combining metadata with user content data, and modifies or blocks metadata access according to predefined permission policies, ensuring only compliant metadata is accessible, and in some cases, modifying or removing geolocation, timestamp, or user identification metadata to protect user anonymity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If metadata is combined with user content data for comprehensive information storage, then information completeness is improved, but user anonymity protection deteriorates
Solution Approach 1:
The patent extracts sensitive metadata (geolocation, timestamp, user identification) from user content data and processes it separately through anonymization policies. This allows the main content to retain comprehensive information while sensitive elements are removed or modified to protect user anonymity.
Solution Approach 2:
The patent applies different quality treatments to different parts of metadata based on sensitivity levels. Critical anonymization fields (geolocation, timestamp, user ID) are modified or removed, while non-sensitive metadata is preserved, creating local quality differentiation within the metadata structure.
2Object-affected harmful factors
If metadata anonymization policies are enforced to protect user anonymity, then user privacy protection is improved, but metadata accessibility and utility deteriorate
Solution Approach 1:
The patent changes parameters of sensitive metadata fields by applying anonymization transformations. Geolocation coordinates are obscured, timestamps are generalized or removed, and user identification fields are anonymized, thereby reducing metadata utility for tracking while maintaining user privacy protection.
Solution Approach 2:
The patent applies partial anonymization by selectively processing only sensitive metadata fields rather than all metadata. This partial action approach maintains necessary metadata utility for content management while removing only the excessive sensitive information that compromises user privacy.
3Adaptability or versatility
If multiple metadata permission policies are implemented for different devices, then policy adaptability is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements a universal metadata anonymization policy framework that can be applied across multiple device types and platforms. The same core anonymization principles and processes are used universally, allowing the system to handle diverse devices without requiring completely separate policy implementations for each device type.
Solution Approach 2:
The patent segments metadata permission policies into distinct categories based on device types and sensitivity levels. By organizing policies into manageable segments rather than creating unique policies for every device configuration, the system achieves adaptability while controlling complexity through structured segmentation.
Data Source
AI summary
A computing device may include a memory and a processor cooperating with the memory to enroll with a server having a metadata anonymization policy associated therewith, generate metadata and combine the metadata with respective user content data, where the computing device has a given metadata permission policy associated therewith from among a plurality of different metadata permission policies. The processor may further determine user content data having metadata combined therewith in violation of the metadata anonymization policy, and when the given metadata permission policy permits modification of metadata, modify the metadata in violation of the metadata anonymization policy so that only the modified metadata is accessible when the user content data is accessed.


