Privacy Budget Tracking for Differential Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for analyzing sensitive information, such as health data and financial records, are invasive, resource-intensive, and compromise analytical utility, failing to ensure privacy, especially when data is stored across disparate sources.

Innovation Solution

A system that receives queries from clients and executes differentially private versions of these queries on a private database, using a privacy budget to balance information release and privacy protection, incorporating a privacy device that determines the privacy spend and applies noise to query responses to maintain confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional methods such as data masking, hashing, or anonymization are used to protect privacy, then privacy protection is improved, but analytical utility is compromised and the methods become invasive and resource-intensive

Engineering Contradiction:
Improveprivacy protectionVSAvoidanalytical utility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a privacy budget as an intermediary mechanism that mediates between privacy protection and analytical utility. The privacy budget system allows queries to be executed on sensitive data while tracking and controlling the cumulative privacy impact, enabling analysts to gain insights without directly accessing or exposing individual records. This intermediary framework resolves the contradiction by providing a structured approach that balances both concerns.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of privacy protection from a binary state (protected/not protected) to a quantifiable metric (privacy budget spend). By introducing epsilon (ε) as a measurable parameter that can be tracked and controlled across multiple queries, the system enables dynamic adjustment of privacy protection levels while maintaining analytical utility. This parameter transformation allows organizations to optimize the balance between privacy and insight generation.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If data is accessed and analyzed across disparate data sources, then analytical value is improved, but privacy risks increase and security concerns arise

Engineering Contradiction:
Improveanalytical valueVSAvoidprivacy risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a privacy budget before any data access occurs. The privacy budget is pre-configured with maximum allowable spend limits, and the system proactively tracks cumulative spend across queries before privacy thresholds are exceeded. This preliminary framework prevents privacy breaches by design, allowing analytical value to be extracted from disparate sources while maintaining security controls in place rather than reacting to threats after they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that continuously monitor and report cumulative privacy spend across multiple queries on disparate data sources. The system provides real-time feedback to analysts about remaining privacy budget, enabling them to adjust their analytical approaches accordingly. This feedback loop allows organizations to safely leverage multiple data sources while maintaining awareness and control over privacy risks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12130942B2Budget tracking in a differentially private database system
Publication Date: 2024.10.29 SNOWFLAKE INC
  • US12130942B2 patent drawing
  • US12130942B2 patent drawing
  • US12130942B2 patent drawing

AI summary

Techniques are described for budget tracking in a differentially private security system. A request to perform a query of a private database system is received by a privacy device from a client device. The request is associated with a level of differential privacy. A privacy budget corresponding to the received request is accessed by the privacy device. The privacy budget includes a cumulative privacy spend and a maximum privacy spend, the cumulative privacy spend representative of previous queries of the private database system. A privacy spend associated with the received request is determined by the privacy device based at least in part on the level of differential privacy associated with the received request. If a sum of the determined privacy spend and the cumulative privacy spend is less than the maximum privacy spend, the query is performed. Otherwise a security action is performed based on a security policy.