Privacy-Utility Tradeoff Computation for Data Marketplaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively quantify the tradeoff between data privacy and utility, making it challenging for data sellers and buyers to make informed decisions, particularly in data publishing and trading scenarios where sensitive information is at risk of being linked and misused.

Innovation Solution

A method and system that analyze data to identify sensitive attributes, generate adversary models by partitioning the data into buckets, compute anonymity indices, and sanitize data using masking techniques to balance privacy and utility, ensuring data is protected while maintaining its value for consumers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quasi-identifier attributes are suppressed or removed to protect privacy, then privacy risk is reduced, but data utility and value are degraded

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system changes the parameter of attribute representation by transforming quasi-identifiers into hashed values through cryptographic functions. This transformation maintains the ability to perform joins and analytics while preventing direct identification of individuals, thus resolving the contradiction between privacy protection and data utility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary mechanism (hashing function with salt) that mediates between the need for privacy protection and data utility. The hashed quasi-identifiers serve as an intermediate representation that enables data processing while protecting original identifiers, allowing both privacy and utility requirements to be satisfied

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If detailed quasi-identifier attributes are retained for data utility, then data value is maintained, but privacy risk increases due to potential linking attacks

Engineering Contradiction:
Improvedata utilityVSAvoidprivacy risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system segments the quasi-identifier attributes into multiple components (e.g., first part and second part of hashed values) that can be independently processed. This segmentation allows the data to maintain utility for analytics while distributing the identification risk across multiple segments, making linking attacks more difficult

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies parameter changes by transforming the quasi-identifier attributes through cryptographic hashing with salt, changing their representation from directly usable identifiers to protected hashed values that maintain analytical utility while reducing identification risk

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11182502B2Systems and methods for computing data privacy-utility tradeoff
Publication Date: 2021.11.23 TATA CONSULTANCY SERVICES LTD
  • US11182502B2 patent drawing
  • US11182502B2 patent drawing
  • US11182502B2 patent drawing

AI summary

Systems and methods for computing data privacy-utility tradeoff is disclosed. Large data hubs like data marketplace are a source of data that may be of utility to data buyers. However, output data provided to data sellers is required to meet the privacy requirements of data sellers and at the same time maintain a level of utility to data buyers. Conventionally known methods of achieving data privacy tend to suppress components of data that may result in reduced utility of the data. Systems and methods of the present disclosure compute this tradeoff to establish need for data transformation, if any, before data is shared with data sellers.