Session Anonymizer Using Quarantined Synthetic PII

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for securing personally identifiable information (PII) in web analytics tools are insufficient, allowing unauthorized access and violating data security, especially in real-time tracking scenarios.

Innovation Solution

A method involving quarantining PII data before transmission, synthesizing it into synthetic data, and controlling access through predetermined time limits to ensure secure anonymization, compliant with GDPR.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If PII data is transmitted in real-time to external servers for web analytics, then the analytics functionality and user experience optimization are improved, but the data security and risk of unauthorized access to PII worsen

Engineering Contradiction:
Improveanalytics processing speedVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by synthesizing pseudonymous data from PII before the data is transmitted to external servers. The system performs data synthesis in advance, creating pseudonymous identifiers that replace direct PII elements such as IP addresses and device identifiers. This preliminary transformation ensures that when analytics data is transmitted, the PII has already been anonymized, thus maintaining both analytics functionality and data security without requiring real-time processing delays.

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If PII data is stored and processed without anonymization, then the data utility for user tracking and analysis is improved, but the probability of unauthorized access and PII exposure worsens

Engineering Contradiction:
Improvedata utilityVSAvoidunauthorized access risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies parameter changes by transforming PII data into pseudonymous data through systematic parameter modification. The data synthesis process changes key parameters such as IP addresses, device identifiers, and user identifiers into pseudonymous equivalents that maintain statistical properties for analytics purposes but eliminate direct identifiability. This transformation maintains data utility for analysis while fundamentally changing the parameters that could enable unauthorized access or PII exposure.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If conventional obfuscation methods are used on tracked data, then some level of anonymity is achieved, but the anonymity is insufficient and conclusions about users and devices can still be drawn

Engineering Contradiction:
Improveanonymity levelVSAvoidanonymity effectiveness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies the copying principle by creating pseudonymous copies of PII data that replicate statistical characteristics while eliminating identifying information. Instead of merely obfuscating original PII, the system generates synthetic pseudonymous data that copies the structural and statistical properties needed for analytics (such as traffic patterns, device types, and behavioral metrics) while completely replacing direct PII elements. This copying approach creates data that is functionally equivalent for analysis purposes but fundamentally different in terms of identifiability, thus achieving effective anonymity that conventional obfuscation cannot provide.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12363078B2Session anonymizer
Publication Date: 2025.07.15 RED BULL GMBH
  • US12363078B2 patent drawing
  • US12363078B2 patent drawing
  • US12363078B2 patent drawing

AI summary

A computer-implemented method, computer-readable storage medium, and computing system for providing anonymized personally identifiable information includes obtaining a first request including first data indicating actions that happened at a client device and second data that is associated with the first data and is based on personally identifiable information associated with the client device; quarantining at least the second data which at least includes storing at least the second data in a data storage; retrieving data from the data storage, wherein the retrieved data is based on the stored second data; and generating a third request to be transmitted to a server external to the one or more first computers. The third request includes the first data and synthetic data associated with the first data. The synthetic data is based on the retrieved data and was synthesized based on the personally identifiable information.