PEKS Encryption for Privacy-Preserving User Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user profiling methods fail to maintain user privacy as they often require decryption of user data, exposing sensitive information during profiling processes.

Innovation Solution

The use of Public Key Encryption with Keyword Search (PEKS) system encrypts user data with a public key and rules with a private key, allowing for matching without decryption, ensuring privacy by using trapdoors and maintaining encryption throughout the profiling process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If user data is decrypted for profiling analysis, then profiling accuracy is improved, but user privacy is compromised

Engineering Contradiction:
Improveprofiling accuracyVSAvoiduser privacy exposure
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces encrypted data as an intermediary form that allows profiling operations to be performed without exposing the original plaintext user data. The encrypted data serves as a mediator between the need for accurate profiling and the requirement for privacy protection, enabling match operations on encrypted representations while maintaining data confidentiality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms user data from plaintext to encrypted form, changing its parameter state. This parameter change allows the data to retain its informational content for profiling purposes while simultaneously protecting its semantic meaning from unauthorized interpretation, thus resolving the contradiction between accuracy and privacy.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If encryption is applied to user data during profiling, then user privacy is protected, but the complexity of the profiling system increases

Engineering Contradiction:
Improveuser privacy protectionVSAvoidprofiling system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies encryption to user data before the profiling process begins, performing the protective action in advance. This preliminary encryption step simplifies the overall system architecture by establishing security boundaries upfront, allowing subsequent profiling operations to work with pre-encrypted data without requiring complex real-time encryption/decryption mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If traditional decryption-based profiling is used, then profiling functionality is simple, but security vulnerabilities increase

Engineering Contradiction:
Improveprofiling operation simplicityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses encrypted data representations as intermediaries that enable profiling operations without requiring decryption. This intermediary approach maintains operational simplicity by allowing match operations on encrypted data while simultaneously eliminating security vulnerabilities associated with plaintext handling and decryption processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8520842B2Maintaining privacy during user profiling
Publication Date: 2013.08.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8520842B2 patent drawing
  • US8520842B2 patent drawing
  • US8520842B2 patent drawing

AI summary

Systems, methods, and computer storage media having computer-executable instructions embodied thereon that maintain privacy during user profiling are provided. A profiling service receives, from a first device, rules for profiling a user. The rules were encrypted using a private key. The profiling service also receives, from a second device, user data. The user data was encrypted using a public key communicated to the second device by the first device. The profiling service then matches the encrypted rules with the encrypted user data, and based on the matching, generates a profile for the user. In embodiments, such a user profile can be utilized to deliver personalized digital content to a user.