Mobile Network Data Anonymization via Dynamic Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for anonymizing event and customer relation data in mobile communication networks fail to adequately protect individual privacy, as they can be vulnerable to deanonymization through location-based and behavior pattern analysis, leading to potential identification of subscribers.

Innovation Solution

A method that anonymizes event data by counting and merging location event data sets, discarding those with low activity, and applying k-anonymity to static data to ensure that personal information is sufficiently obscured, thereby increasing the effort required for deanonymization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If location event data sets are provided in detailed form to enable useful applications, then the utility and value of the data increases, but the risk of deanonymization and privacy violation increases

Engineering Contradiction:
Improveutility of data for applicationsVSAvoidprivacy violation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges location event data sets by combining multiple individual data sets into aggregated groups. This is achieved by counting co-occurrences of location attributes across different data sets and merging those that appear together frequently, thereby preserving utility while reducing deanonymization risk through aggregation

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameter of data aggregation level by adjusting the threshold for merging location event data sets. By dynamically setting the threshold based on diversity metrics, the system transforms the data from individual detailed records to aggregated statistical patterns, maintaining versatility while enhancing privacy protection

Inventive Principle:
Principle #35Parameter changes

2Reliability

If data aggregation is increased to protect privacy through anonymization, then privacy protection improves, but the precision and detail of location information deteriorates

Engineering Contradiction:
Improveprivacy protection levelVSAvoidlocation information detail
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces dynamic adjustment of aggregation thresholds based on the diversity of location attributes. The threshold is not fixed but adapts according to the measured diversity metric, allowing the system to dynamically balance privacy protection with location information precision based on the specific data characteristics

Inventive Principle:
Principle #15Dynamics

3Device complexity

If location event data sets are merged to increase anonymization level, then the effort for deanonymization increases, but the quantity of usable detailed data decreases

Engineering Contradiction:
Improvedeanonymization effortVSAvoidquantity of detailed data
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The patent changes the aggregation parameter adaptively by adjusting the merging threshold based on diversity metrics. This allows optimal control over the balance between increasing deanonymization effort through merging and preserving the quantity of usable detailed data, rather than using a fixed aggressive merging approach

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3061280B1A method for anonymization of data collected within a mobile communication network
Publication Date: 2022.01.19 TELEFONICA GERMANY GMBH & CO
  • EP3061280B1 patent drawingFigure 1
  • EP3061280B1 patent drawingFigure 2
  • EP3061280B1 patent drawingFigure 3

AI summary

The invention relates to a method for anonymization of event data collected within a system or network providing a service for subscribers/customers wherein each event data set is related to an individual subscriber/customer of the system/network and includes at least one attribute wherein the method counts the number of event data sets related to varying individual subscribers having identical or nearly identical values for at least one attribute. The invention further relates to a method for anonymization of static data related to individual subscribers of a mobile communication network wherein each static data set consist of different attributes and the method identifies specific profiles derivable form the static data and drops one or more respective attribute of the static data sets and/or classifies two or more static data sets to a certain group having at least one matching attribute.