Tokenized Identity Bridge for Secure Data Engineering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data engineering processes face challenges in securing identity identifiers during data processing, particularly in large-scale networks where data breaches can expose customer identities, and existing solutions do not adequately protect customer anonymity in advertising and marketing contexts.

Innovation Solution

A system and method that involve generating and using tokenized identifiers by creating a cross-reference table with encrypted service identifiers, customer location codes, and address location codes, replacing unique usage identifiers in data usage logs with tokenized identifiers, and managing these records through an identity translation service to ensure customer identity protection and data anonymity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique usage identifiers are used in data usage logs, then data processing and advertising purposes can be fulfilled, but customer identities are exposed and security is compromised

Engineering Contradiction:
Improvecustomer identity protectionVSAvoiddata anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces tokenized identifiers as intermediary elements that replace direct customer identifiers in data usage logs. These tokens act as mediators between the need for data processing and the requirement for identity protection, allowing analytics and advertising functions to proceed while customer identities remain concealed through the cross-reference table mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the identification system using tokenized identifiers that mirror the functionality of unique usage identifiers without exposing actual customer identities. The cross-reference table maintains the correspondence between tokens and real identifiers, enabling data processing to work with anonymized copies rather than sensitive original data

Inventive Principle:
Principle #26Copying

2Reliability

If tokenized identifiers are generated and cross-reference tables are maintained, then customer identity security is enhanced, but system complexity increases

Engineering Contradiction:
Improveidentity securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identification system into distinct components: tokenized identifiers for data processing, encrypted storage in cross-reference tables, and separate processing systems. This segmentation isolates the complexity into manageable modules while distributing the security functionality across multiple system layers, making the complex system more maintainable and understandable

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If encrypted service identifiers are stored in cross-reference tables, then data breach impact is reduced, but storage and processing requirements increase

Engineering Contradiction:
Improvedata breach impactVSAvoiddata storage volume
Core Design Contradiction:
Object-affected harmful factorsVSQuantity of substance

Solution Approach 1:

The patent transforms identifiers from plaintext to encrypted format, changing the parameter of data representation. This encryption transformation increases the compactness of stored data while simultaneously reducing the harmful impact of potential data breaches, as encrypted identifiers cannot be easily reverse-engineered even if accessed by unauthorized parties

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11409912B2System and method for securing identity identifiers for data engineering processing
Publication Date: 2022.08.09 AT&T INTELLECTUAL PROPERTY I L P
  • US11409912B2 patent drawing
  • US11409912B2 patent drawing
  • US11409912B2 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, a processing system including a processor with a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations including: receiving an identity bridge file comprising records from a service provider, wherein each record includes one or more encrypted service identifiers for a customer, a customer location code of the customer, and an address location code of the customer; determining whether a tokenized identifier exists in a cross-reference table; responsive to a determination that the tokenized identifier does not exist in the cross-reference table: a) generating a new tokenized identifier; and b) adding a record to the cross-reference table comprising the new tokenized identifier, the customer location code, the address location code, and the one or more encrypted service identifiers; securing a usage record of a data usage log, wherein the usage record includes a unique usage identifier, wherein the securing comprises replacing the unique usage identifier with a matching tokenized identifier from the cross-reference table, resulting in secured usage records; and providing the secured usage records to data engineering. Other embodiments are disclosed.