Distributed Personal Data Anonymization for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized personal data management systems in security systems compromise privacy and security by allowing unauthorized access to non-anonymized personal data, infringing on individual privacy and increasing the risk of data breaches.

Innovation Solution

A decentralized system with spatially separated security devices that anonymize personal data locally and manage permissions at each node, preventing unanonymized data transfer and ensuring secure, authorized access and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal data is collected and stored centrally for security management, then security monitoring capability is improved, but data privacy and security are compromised due to unauthorized access risks

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized data storage system into distributed nodes. Each security device maintains local storage of personal data and anonymization keys, eliminating the single central repository that is vulnerable to unauthorized access. This segmentation preserves security monitoring capabilities while distributing risk across multiple independent storage locations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces anonymization as an intermediary layer between personal data and storage. Personal data is transformed into anonymized form using cryptographic techniques, allowing security monitoring to function on anonymized data while the original personal data remains protected. This intermediary mechanism enables security functionality without direct exposure of sensitive personal information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If personal data is forwarded to a central location for processing, then centralized management is achieved, but privacy infringement occurs due to third-party access

Engineering Contradiction:
Improvecentralized managementVSAvoidprivacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies preliminary anonymization at the source (security devices) before data leaves the local environment. By transforming personal data into anonymized form upfront, the system enables centralized processing and management of anonymized data without compromising individual privacy. The anonymization action is performed in advance, preventing privacy loss during transmission and storage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements different data quality states at different locations. Personal data maintains its original quality locally at security devices where it is generated, while anonymized data is distributed to central and other nodes for processing. This local quality differentiation allows centralized management operations on anonymized data while preserving personal data privacy through localized anonymization.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If non-anonymized personal data is stored centrally, then data accessibility is improved, but security risk increases due to potential data breaches

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the state parameter of personal data from anonymized to non-anonymized form selectively. Non-anonymized personal data is stored locally at security devices with restricted access, while anonymized versions are made accessible centrally. This parameter transformation enables differentiated accessibility: high accessibility for anonymized data and high security for non-anonymized data, resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3471068B1Distributed system for managing personal information, method and computer program product
Publication Date: 2026.03.25 BUNDESDRUCKEREI GMBH
  • EP3471068B1 patent drawingFigure 1
  • EP3471068B1 patent drawingFigure 2
  • EP3471068B1 patent drawingFigure 3

AI summary

The invention relates to a system 200 for managing personal data D1, D2, D3, D4. The system 200 comprises a first security device 201 and a second security device 202. The security devices 201 and 202 are spatially separated and each is configured to capture personal data D1, D2, D3, D4 and to assign the captured personal data D1, D2, D3, D4 to identities ID1, ID2, ID3, ID4. The system 200 further comprises a management system 202, which is configured to manage authorizations for the identities ID1, ID2, ID3, ID4.The first security device 201 and the second security device 203 each anonymize the collected personal data and allow access to the personal data D1, D2, D3, D4 if authorization to access personal data D1, D2, D3, D4 exists, which is assigned to the identity ID1, ID2, ID3, ID4 that is assigned to the personal data D1, D2, D3, D4. The invention further relates to a method and a computer program product.