Privacy Thresholds for Venue Data Analytics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Balancing the need to ensure health and safety at large events while respecting individual privacy concerns, especially in the context of public health crises like the COVID-19 pandemic, is challenging due to the need for data collection and analysis to manage venue capacity, crowd density, and social distancing without compromising user privacy.
Innovation Solution
A communication system that allows portable devices to register with a venue, offering user-selectable data privacy thresholds for temporary access to demographic and health information, enabling anonymous analytics for venue management based on predetermined conditions, with options to grant public access under specific circumstances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private user information is accessed for analytics to manage venue capacity and crowd density, then venue safety management is improved, but user privacy is compromised
Solution Approach 1:
The patent introduces an intermediary processing layer that collects private user information, transforms it into anonymous aggregated data, and uses this anonymized data for venue analytics. This intermediary step allows the system to achieve reliable venue safety management through data analysis while preventing direct exposure of individual user privacy, as the data is processed through a mediating anonymization function before being used for safety decisions
Solution Approach 2:
The patent changes the parameter of data anonymity by transforming identifiable private information into anonymous aggregated statistics. By altering the state of the data from identifiable to anonymous through aggregation and anonymization processes, the system enables venue safety management analytics while maintaining user privacy protection, as the transformed data no longer contains personally identifiable information
2Reliability
If user data is collected and made public for venue notifications, then public health response is improved, but individual privacy protection deteriorates
Solution Approach 1:
The patent employs an intermediary anonymization process that acts as a buffer between private user data and public health notifications. The system collects individual data, processes it through anonymization intermediaries to create aggregated public health statistics, and then releases these anonymized results for public notification purposes. This intermediary transformation enables effective public health response while protecting individual privacy by ensuring no personally identifiable information is exposed in public notifications
Solution Approach 2:
The patent creates anonymized copies of user data that can be safely published for public health notifications without exposing original private information. By generating and using anonymized copies rather than original identifiable data, the system improves public health response capabilities through data-driven notifications while eliminating privacy exposure risks, as the copied anonymized data cannot be traced back to individual users
3Productivity
If anonymous analytics are performed on user information, then venue operations are optimized, but data security requirements increase
Solution Approach 1:
The patent applies preliminary anonymization action to user data before it is stored or processed for venue operations analytics. By performing the anonymization transformation in advance, before data enters the operational analytics system, the patent enables optimized venue operations through data-driven insights while reducing data security complexity, as the pre-anonymized data inherently requires fewer security safeguards since it cannot be traced back to individuals
Data Source
AI summary
A portable communication device, method, and system enable temporary access to private user information by a venue communication system. The temporary access to the private information is based on a registration that includes user selectable privacy thresholds and predetermined venue conditions. The temporary access by the venue communication system can be adjusted and limited by the portable communication device. The usage of the private data by the venue communication system may be limited to anonymous analytics and/or extended to non-anonymous analytics and notifications based on user input to the communication device.


