Temporary Pseudonymous Identity Architecture for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing ubiquity of internet access and data collection poses a challenge for users seeking to maintain privacy, as they are often required to provide personally-identifying information to access online services, leading to concerns about permanent tracking and data aggregation.

Innovation Solution

A platform identity client-server architecture generates a signed temporary pseudonymous identity (TPI) that includes a built-in expiry, allowing users to maintain anonymity while enabling venue operators to collect telemetry data without permanent correlation to personally-identifying information, using a trusted execution environment and direct anonymous attestation to verify the TPI's authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users provide personally-identifying information to access online services, then service access is enabled, but user privacy is compromised due to permanent tracking and data aggregation

Engineering Contradiction:
Improveservice accessVSAvoidprivacy loss
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements temporary pseudonymous identities (TPIs) that are short-lived and automatically expire after a defined period. These TPIs serve as disposable identifiers that allow service access without requiring permanent personally-identifying information. Once the TPI expires, it is discarded and cannot be used for tracking, thus resolving the contradiction between enabling service access and preventing permanent privacy loss.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent introduces TPIs as an intermediary layer between users and service providers. Instead of direct identification using personally-identifying information, the TPI acts as a mediator that enables service access while preventing direct correlation to the user's real identity. This intermediary mechanism allows service provision to continue while protecting user privacy from permanent tracking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If venue operators collect telemetry data for targeted advertising, then advertising effectiveness is improved, but user anonymity is compromised due to permanent data correlation

Engineering Contradiction:
Improveadvertising effectivenessVSAvoidanonymity loss
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic TPIs with built-in expiry mechanisms. The TPIs are not static permanent identifiers but dynamic, time-limited identifiers that automatically become invalid after a specified duration. This dynamic approach allows venue operators to collect and utilize telemetry data for targeted advertising during the active TPI period, improving advertising effectiveness, while ensuring that the data cannot be permanently correlated to user identity once the TPI expires.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses short-lived TPIs as disposable identifiers for telemetry collection. These TPIs enable targeted advertising during their active lifespan but are then discarded, preventing permanent data correlation. The temporary nature of these identifiers allows advertising effectiveness to be improved during the measurement period while ultimately protecting user anonymity through automatic expiration and disposal.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Quantity of substance

If permanent tracking data is stored for user correlation, then data aggregation value is improved, but privacy protection is reduced

Engineering Contradiction:
Improvedata aggregation valueVSAvoidprivacy exposure
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic TPI issuance with defined lifecycles. Instead of continuous permanent tracking, the system uses periodic, time-bounded identification where TPIs are issued for specific durations and then expire. This periodic approach allows data aggregation to occur within each TPI's active period, providing value for analytics and advertising, while the periodic expiration ensures that privacy protection is maintained by preventing indefinite data correlation.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent employs short-lived TPIs as temporary data carriers that enable data aggregation during their active lifespan but are then discarded. These disposable identifiers allow venue operators to collect and aggregate telemetry data for analysis and advertising purposes, improving data aggregation value, while their temporary nature ensures that once they expire, the data cannot be permanently correlated to user identity, thus protecting privacy.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9798895B2Platform identity architecture with a temporary pseudonymous identity
Publication Date: 2017.10.24 MCAFEE LLC
  • US9798895B2 patent drawing
  • US9798895B2 patent drawing
  • US9798895B2 patent drawing

AI summary

In an example, a client-server platform identity architecture is disclosed. The platform identity architecture may be used to enable a venue operator to provide online services and to collect telemetry data and metrics while giving end users greater control over privacy. When entering a compatible venue, the user's device generates a signed temporary pseudonymous identity (TPI) in secure hardware or software. Any telemetry uploaded to the venue server includes the signature so that the server can verify that the data are valid. The TPI may have a built-in expiry. The venue server may thus receive useful tracking data during the term of the TPI, while the user is assured that the data are not kept permanently or correlated to personally-identifying information.