One-Way Hashing for Database Record Anonymization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional database and networking technologies encrypt data but fail to anonymize personally identifiable information (PII), allowing unauthorized access to customer identities even when encryption is used.
Innovation Solution
Implement a one-way matching methodology using unique customer key identifiers generated by both the online service provider and data analytics service, which are concatenated to data records, ensuring that no identifying information is transmitted, thus maintaining customer anonymity during data transmission and storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional encryption is used to protect data in transit and storage, then data confidentiality is improved, but personally identifiable information can still be associated with customers if decrypted by unauthorized persons
Solution Approach 1:
The patent extracts personally identifiable information (PII) from data records and replaces it with hashed customer key identifiers. By removing the direct link between customer identities and their data, the system maintains confidentiality even when data is decrypted, as the hashed identifiers cannot be reverse-engineered to reveal original identities.
Solution Approach 2:
The patent introduces hashed customer key identifiers as an intermediary between customer identities and data records. This intermediary layer allows data to be associated with customers through matching hashed keys while preventing direct exposure of identity information, thus resolving the contradiction between maintainable confidentiality and preventable identity exposure.
2Adaptability or versatility
If customer data is shared between online service providers and analytics services, then analytics capability is improved, but customer privacy and data security are compromised
Solution Approach 1:
The patent creates hashed copies of customer key identifiers that can be shared between online service providers and analytics services without exposing original identity information. These copied hashed identifiers enable analytics processing while maintaining privacy, as they cannot be reverse-engineered to reveal customer identities.
Solution Approach 2:
The patent transforms customer identity parameters into hashed identifier parameters through one-way hashing functions. This parameter transformation allows data to be shared and processed for analytics purposes while the original identity parameters remain protected, resolving the contradiction between analytics capability and privacy protection.
3Productivity
If data records are transmitted over networks for analytics processing, then data utility is improved, but exposure to unauthorized access and interception increases
Solution Approach 1:
The patent applies preliminary hashing to customer key identifiers before data records are transmitted over networks. This preliminary action ensures that even if data is intercepted during transmission, the customer identity information remains protected because the hashed identifiers cannot be reverse-engineered to reveal original identities.
Data Source
AI summary
Disclosed herein are systems and methods allowing provider server and an analytics server to communicate confidential information but not compromise the anonymity of the customers if the data transmitted in either direction were to be intercepted or otherwise viewed by an unauthorized party, each server is configured to transmit the data records of the customers without any personally identifying information (PII) associated with the customers. The databases may “link” the data records by separately generating customer key identifiers for each unique customer having data in the one or both of the databases, according to predefined parameters and a predetermined one-way hashing algorithm. The unique customer key identifier may then be concatenated to, appended to, or otherwise associated with each data record for a particular customer that is being communicated between the servers.

