Network Identity Management via Tree Structure Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network identity management techniques fail to adequately protect the privacy of entities in networks, as they do not sufficiently conceal identity information, allowing users to infer relationships between entities despite anonymization efforts.

Innovation Solution

A system generates a tree structure representing a network with unique identifiers for each node, where protected nodes are opaque and only identity information for unprotected nodes is revealed, making it difficult for users to infer relationships between entities, even when an entity is represented by multiple nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anonymization techniques are used to conceal entity identity information, then entity privacy is protected, but users cannot view the identity of entities in the network

Engineering Contradiction:
Improveprivacy protectionVSAvoididentity information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments entity information into two distinct parts: identity information (names, email addresses, phone numbers) and generic information (presence in network, links between entities). This segmentation allows the system to selectively disclose generic information while protecting identity information, resolving the contradiction between privacy protection and information availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and removes identity information from the network data presented to users. By taking out the sensitive identity components while retaining the structural and relational information, the system enables users to analyze network properties without accessing protected identity details, thus balancing privacy protection with information utility.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If identity information is concealed from users, then entity privacy is protected, but users may still infer entity identities through relationship analysis

Engineering Contradiction:
Improveprivacy protectionVSAvoididentity inference
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary system (the network analysis system) that acts as a mediator between the network data and users. This intermediary processes and filters the information, presenting only generic network structure data while blocking identity information. The intermediary prevents users from directly accessing identity information that could enable inference, thus strengthening privacy protection while maintaining network analysis capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If generic network information is disclosed to users, then network properties are preserved for analysis, but entity identity protection may be compromised

Engineering Contradiction:
Improvenetwork informationVSAvoidprivacy protection
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent applies local quality by treating different types of information with different levels of disclosure. Generic network information (structure, relationships, presence) is made accessible with high quality for analysis, while identity information is protected with restricted access. This differentiated approach allows the system to optimize both information disclosure and privacy protection for different data categories simultaneously.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9626524B2Managing network identities
Publication Date: 2017.04.18 SAP SE
  • US9626524B2 patent drawing
  • US9626524B2 patent drawing
  • US9626524B2 patent drawing

AI summary

Techniques for managing network identities include generating, with a local computing system, a tree structure representing a network comprising a plurality of entities, the tree structure comprising a plurality of nodes, each node of the plurality of nodes representing an entity of the plurality of entities, at least one entity of the plurality of entities is represented by more than one node of the plurality of nodes; assigning a unique identifier to each node; identifying each node of the plurality of nodes as being a protected node or an unprotected node; and transmitting, to a remote computing system, the tree structure, the unique identifiers for the protected nodes, and identity information of the entities for the unprotected nodes.