Secure Unique Identifier Counting via Log Data Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for statistical analysis of server log files do not adequately protect user identities, as analysts may access unique identifier data, such as IP addresses and cookie IDs, despite field-level access controls being cumbersome and ineffective.

Innovation Solution

The approach involves stripping, replacing, or encrypting unique identifier data in log files to prevent analysts from accessing actual user identities, using analytics software packages and procedural domain-specific programming languages like Sawzall to process log records without exposing identifiers, and implementing encryption and minimum threshold mechanisms to further secure user privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If field level access controls are used to protect unique identifier data, then user privacy is protected, but system complexity and operational difficulty increase

Engineering Contradiction:
Improveuser privacy protectionVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts unique identifier fields from log records and processes them separately through secure counting mechanisms. The identifiers are removed from the analyst's view while still enabling statistical analysis, thus protecting privacy without requiring complex field-level access controls throughout the system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary secure counting system that sits between the log data and the analyst. This intermediary processes the unique identifiers through encryption and secure protocols, providing aggregate statistics to analysts while preventing direct access to individual identifiers, thereby simplifying the overall access control architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If field level access controls are implemented to restrict analyst access to unique identifier fields, then user identity protection improves, but ease of operation deteriorates

Engineering Contradiction:
Improveuser identity protectionVSAvoidanalyst operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure counting system automatically processes unique identifiers through encryption and aggregation without requiring analysts to manually control or manage access to individual fields. The system self-manages the security protocols and provides ready-to-use aggregate statistics, making operation simple for analysts while maintaining strong identity protection.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If unique identifier data is provided to analysts for statistical analysis, then analysis accuracy improves, but user privacy protection deteriorates

Engineering Contradiction:
Improvestatistical analysis accuracyVSAvoiduser privacy exposure
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent creates encrypted copies of unique identifier data that can be processed for statistical analysis without exposing the original identifiers. These encrypted copies maintain the necessary properties for accurate counting and categorization while preventing any possibility of identifying individual users, thus achieving both analysis accuracy and privacy protection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms unique identifier data through encryption and aggregation operations, changing the data parameters from identifiable individual records to aggregate statistical measures. This parameter transformation maintains the utility for statistical analysis while eliminating the privacy harm associated with exposing individual identifiers.

Inventive Principle:
Principle #35Parameter changes

4Ease of operation

If all unique identifier fields are made accessible to analysts, then ease of operation improves, but security against harmful factors deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoididentity disclosure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data access process into distinct components: raw log data, encrypted identifier copies, and final aggregate statistics. Analysts interact only with the aggregate statistics segment, which provides full analytical capability without exposing intermediate segments containing identifiable information, thus maintaining ease of operation while preventing identity disclosure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8756699B1Counting unique identifiers securely
Publication Date: 2014.06.17 GOOGLE LLC
  • US8756699B1 patent drawing
  • US8756699B1 patent drawing
  • US8756699B1 patent drawing

AI summary

A number of unique identifiers is determined by, at a device, receiving a request to determine the number of unique identifiers, outputting a response to the request, and receiving data representing the number of the unique identifiers based on the response to the request. The data representing the number of the unique identifiers is free of information indicative of an identity of a source of the unique identifiers.