Temporary Pseudonymous Identity Architecture for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing ubiquity of internet access and data collection poses a challenge for users seeking to maintain privacy, as they are often required to provide personally-identifying information to access online services, leading to concerns about permanent tracking and data aggregation.
Innovation Solution
A platform identity client-server architecture generates a signed temporary pseudonymous identity (TPI) that includes a built-in expiry, allowing users to maintain anonymity while enabling venue operators to collect telemetry data without permanent correlation to personally-identifying information, using a trusted execution environment and direct anonymous attestation to verify the TPI's authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide personally-identifying information to access online services, then service access is enabled, but user privacy is compromised due to permanent tracking and data aggregation
Solution Approach 1:
The patent implements temporary pseudonymous identities (TPIs) that are short-lived and automatically expire after a defined period. These TPIs serve as disposable identifiers that allow service access without requiring permanent personally-identifying information. Once the TPI expires, it is discarded and cannot be used for tracking, thus resolving the contradiction between enabling service access and preventing permanent privacy loss.
Solution Approach 2:
The patent introduces TPIs as an intermediary layer between users and service providers. Instead of direct identification using personally-identifying information, the TPI acts as a mediator that enables service access while preventing direct correlation to the user's real identity. This intermediary mechanism allows service provision to continue while protecting user privacy from permanent tracking.
2Productivity
If venue operators collect telemetry data for targeted advertising, then advertising effectiveness is improved, but user anonymity is compromised due to permanent data correlation
Solution Approach 1:
The patent implements dynamic TPIs with built-in expiry mechanisms. The TPIs are not static permanent identifiers but dynamic, time-limited identifiers that automatically become invalid after a specified duration. This dynamic approach allows venue operators to collect and utilize telemetry data for targeted advertising during the active TPI period, improving advertising effectiveness, while ensuring that the data cannot be permanently correlated to user identity once the TPI expires.
Solution Approach 2:
The patent uses short-lived TPIs as disposable identifiers for telemetry collection. These TPIs enable targeted advertising during their active lifespan but are then discarded, preventing permanent data correlation. The temporary nature of these identifiers allows advertising effectiveness to be improved during the measurement period while ultimately protecting user anonymity through automatic expiration and disposal.
3Quantity of substance
If permanent tracking data is stored for user correlation, then data aggregation value is improved, but privacy protection is reduced
Solution Approach 1:
The patent implements periodic TPI issuance with defined lifecycles. Instead of continuous permanent tracking, the system uses periodic, time-bounded identification where TPIs are issued for specific durations and then expire. This periodic approach allows data aggregation to occur within each TPI's active period, providing value for analytics and advertising, while the periodic expiration ensures that privacy protection is maintained by preventing indefinite data correlation.
Solution Approach 2:
The patent employs short-lived TPIs as temporary data carriers that enable data aggregation during their active lifespan but are then discarded. These disposable identifiers allow venue operators to collect and aggregate telemetry data for analysis and advertising purposes, improving data aggregation value, while their temporary nature ensures that once they expire, the data cannot be permanently correlated to user identity, thus protecting privacy.
Data Source
AI summary
In an example, a client-server platform identity architecture is disclosed. The platform identity architecture may be used to enable a venue operator to provide online services and to collect telemetry data and metrics while giving end users greater control over privacy. When entering a compatible venue, the user's device generates a signed temporary pseudonymous identity (TPI) in secure hardware or software. Any telemetry uploaded to the venue server includes the signature so that the server can verify that the data are valid. The TPI may have a built-in expiry. The venue server may thus receive useful tracking data during the term of the TPI, while the user is assured that the data are not kept permanently or correlated to personally-identifying information.


