Temporary Identifier Rotation for Privacy-Preserving Data Collection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in accumulating sensitive information from user devices while preserving user privacy, as they often rely on permanent identifiers that can be exploited for tracking or identifying users, making data vulnerable to adversarial attacks and privacy violations.
Innovation Solution
Utilizing temporary, ephemeral identifiers for user devices that are periodically changed to prevent linking sensitive information to specific users, ensuring privacy by decoupling user behavior analysis from permanent identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If permanent identifiers are used to track user devices, then data analysis capability is improved, but user privacy protection deteriorates
Solution Approach 1:
The patent applies dynamics by making identifiers temporary and changing over time rather than permanent and static. Each user device receives a new temporary identifier after a defined period, causing the identifier system to evolve dynamically. This resolves the contradiction by enabling data analysis within each temporary period while preventing long-term privacy violations through identifier rotation.
Solution Approach 2:
The patent uses temporary identifiers that are short-lived and disposable, replacing them periodically rather than using permanent identifiers. These cheap, short-living identifiers enable sufficient data analysis for their active period while automatically expiring to protect user privacy, directly resolving the technical contradiction between analysis capability and privacy protection.
2Object-affected harmful factors
If temporary identifiers are used periodically, then user privacy protection is improved, but data continuity for analysis deteriorates
Solution Approach 1:
The patent implements periodic action by systematically replacing temporary identifiers at defined intervals. This periodic replacement maintains privacy protection while creating structured data segments that can be analyzed within each period. The regularity of the periodic action ensures data continuity in terms of analysis coverage, even if individual identifier links are broken.
Solution Approach 2:
The patent segments the continuous data collection process into discrete periods, each with its own temporary identifier. This segmentation breaks the continuous tracking chain into manageable segments that can be analyzed independently, maintaining privacy between segments while preserving analytical value within each segment through systematic data collection.
3Reliability
If identifier replacement is implemented frequently, then adversarial attack resistance is improved, but system complexity deteriorates
Solution Approach 1:
The patent applies self-service by enabling user devices to automatically receive and use new temporary identifiers without manual intervention. The system autonomously manages identifier replacement, reducing the complexity burden on users while maintaining high security through frequent, automatic identifier rotation that resists adversarial attacks.
Solution Approach 2:
The patent uses feedback mechanisms where the system monitors identifier usage and automatically triggers replacement based on defined criteria such as time periods or data collection milestones. This feedback-driven approach optimizes the balance between security (frequent replacement) and complexity (automated management), resolving the contradiction by making the system adaptively manage identifier lifecycle.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method, system and product including communicating a first report associated with a first temporary identifier of a user device; upon receiving the first report from the user device, storing the first report with the first temporary identifier; communicating a message comprising a second temporary identifier of the user device; communicating a second report that is associated with the second temporary identifier of the user device, wherein the second report is not associated with the first temporary identifier; upon receiving from the user device a second report, storing the second report with the second temporary identifier, whereby the first report cannot be directly matched with the second report based on respective identifiers thereof.