Secure Identifier Matching in Encrypted Data Clean Rooms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital advertising methods face challenges in securely and efficiently sharing data between different entities due to privacy concerns, making it difficult to create target groups for advertising or marketing efforts without exposing sensitive customer information.

Innovation Solution

An encryption-based data clean room approach is implemented, allowing direct matching of user identifiers across different data sets using shared functions and encrypted data objects, ensuring that underlying data remains secure and private to each entity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If companies share customer data directly to perform overlap analysis and create target groups, then data analysis capability is improved, but data security and privacy protection deteriorate

Engineering Contradiction:
Improvedata analysis capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a trusted third-party platform that acts as an intermediary to perform overlap analysis between companies' customer data sets. This mediator enables data analysis capabilities while maintaining data security by never exposing the actual customer data to the companies, thus resolving the contradiction between productivity and reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses cryptographic hashing to create copies of customer identifiers that preserve the ability to perform matching and analysis while being irreversibly anonymized. These hash copies enable overlap analysis without exposing the original sensitive data, thereby maintaining both analytical capability and data security

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If companies use third-party cookies to track customer browsing history, then advertising targeting capability is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improveadvertising targeting capabilityVSAvoiduser privacy concerns
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces third-party cookies with cryptographic hash copies of customer identifiers that can be used for advertising targeting without exposing personal information. These hash-based copies enable the same advertising functionality while eliminating privacy harms associated with tracking actual user data

Inventive Principle:
Principle #26Copying

3Reliability

If companies encrypt their data before sharing to maintain security, then data security is improved, but data matching efficiency deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata matching efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies cryptographic hashing as a preliminary transformation to customer identifiers before sharing. This pre-processing step creates fixed-length hash values that are both secure and highly efficient for matching operations, thus maintaining data security while preserving matching efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms customer identifiers from their original format to cryptographic hash format, changing the parameter representation while preserving the ability to perform exact matching. This parameter transformation enables secure data sharing without sacrificing matching efficiency, as hash comparison remains computationally efficient

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12353583B2Secure multi-party encrypted identifier data sharing
Publication Date: 2025.07.08 SNOWFLAKE INC
  • US12353583B2 patent drawing
  • US12353583B2 patent drawing
  • US12353583B2 patent drawing

AI summary

Embodiments of the present disclosure may provide a data clean room allowing encryption based data analysis across multiple accounts, including different provider database user accounts that provide user data and a network service and a requesting user that generates one or more clean room requests. The data clean room may also restrict which data may be used in the analysis and may restrict the output.