Pseudonymizing Sensitive Objects in Online Conversations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Peer-to-peer online text conversations often leave sensitive content unedited on user devices, violating privacy regulations and retention preferences, as users cannot control retention actions on other users' devices, potentially exposing sensitive data.

Innovation Solution

A method that uses pseudonymization to protect sensitive objects in online conversations by identifying and replacing them with pseudonymized-object-holders based on user-specific protection policies, ensuring compliance with legal and geographical regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive data is retained on user devices for communication history, then conversation accessibility is improved, but privacy compliance deteriorates

Engineering Contradiction:
Improveconversation accessibilityVSAvoidprivacy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts sensitive information from the original message content and stores it separately in a sensitive information database. The original messages are then replaced with placeholder tokens that reference the extracted sensitive data. This separation allows the conversation history to be retained for accessibility while the actual sensitive data can be controlled and purged independently to comply with privacy regulations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a copy of sensitive information from the original messages and stores it in a dedicated sensitive information database. The original messages are replaced with placeholder tokens that reference this copied data. This copying mechanism enables the system to maintain conversation accessibility through placeholder references while allowing independent management and purging of the actual sensitive data copies to ensure privacy compliance.

Inventive Principle:
Principle #26Copying

2Reliability

If sensitive objects are replaced with pseudonymized holders, then privacy protection is improved, but data utility deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the sensitive portions of information from messages and replaces them with placeholder tokens, while preserving the non-sensitive context. This selective extraction maintains the utility of messages for understanding conversation flow and context, while protecting privacy by removing or pseudonymizing only the sensitive elements such as personal identifiers and confidential data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a separate copy of sensitive information in a secure database while replacing it with placeholder tokens in the conversation history. This copying approach preserves data utility by maintaining the structure and referenceability of the data, while the actual sensitive values are protected. The placeholder tokens preserve the positional and contextual information needed for conversation understanding without exposing actual sensitive data.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11727151B2Pseudonymizing sensitive objects in online content exchanges
Publication Date: 2023.08.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11727151B2 patent drawing
  • US11727151B2 patent drawing
  • US11727151B2 patent drawing

AI summary

A method for protecting content of online conversational content. The method provides for scanning content of an online conversational exchange between a first device and a second device. A sensitive object included in the content of the online conversation exchange is identified, based on object type information accessible from a protection policy included in respective user profiles. A pseudonymized-object-holder is assigned to the identified sensitive object according to the protection policy of the respective user profiles, and the identified sensitive object identified in the content of the online conversation exchange and stored on both the first device and the second device is replaced with a pseudonymized-object-holder, based on the sensitive-object protection policy of the respective user profiles.