Triple-Blind Identity Mapping via Neutral Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current hashing methods for data privacy fail to prevent re-identification of pseudonymized identities, as anyone can reproduce the same hashed value to compare against outside or future sources.

Innovation Solution

A triple-blind identity mapping method and protocol that uses a central web service as a neutral facilitator, unable to produce surrogate keys, to inhibit re-identification by only sharing information between data owners upon a positive match, without disclosing identifying information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple hashing methods are used to pseudonymize identities, then data sharing becomes easier, but re-identification risk increases because anyone can reproduce hashed values to compare against outside sources

Engineering Contradiction:
Improvedata sharingVSAvoidre-identification risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a neutral third-party service as an intermediary that hosts the hash comparison functionality. This mediator prevents direct access to hashing algorithms and input data, allowing organizations to compare hashed values without exposing their data or reproduction capabilities to each other, thereby reducing re-identification risk while maintaining data sharing functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the hash comparison process into distinct components: data preparation, hashing, and comparison. By separating these functions and requiring third-party hosting for the comparison step, the system prevents any single party from having complete control over the entire process, reducing the ability to reproduce and compare hashed values maliciously

Inventive Principle:
Principle #1Segmentation

2Loss of information

If hashed information is exchanged between data owners, then identity mapping becomes possible, but privacy exposure risk increases because parties gain access to reproducible hashed values

Engineering Contradiction:
Improveidentity mapping capabilityVSAvoidprivacy exposure risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The third-party service acts as a mediator that receives hashed values from data owners, performs the comparison, and returns match results without exposing the actual hashed values or enabling reproduction. This intermediary approach allows identity mapping to occur while preventing privacy exposure that would result from direct exchange of reproducible hashed information

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If a central web service hosts the hashing algorithm and input data, then re-identification is inhibited, but the service requires access to sensitive deterministic inputs

Engineering Contradiction:
Improvere-identification preventionVSAvoidsecurity of deterministic inputs
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent extracts the sensitive deterministic inputs from the central web service environment and keeps them locally secured at the data owner's premises. Only the non-sensitive hashing algorithm and comparison logic are hosted centrally, while the critical input data remains in secure local storage, eliminating the security risk of exposing deterministic inputs to the third-party service

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12289398B2Method and protocol for triple-blind identity mapping
Publication Date: 2025.04.29 KARLSGATE
  • US12289398B2 patent drawing
  • US12289398B2 patent drawing
  • US12289398B2 patent drawing

AI summary

A method and protocol for triple-blind identity mapping that sufficiently address the need to reduce accidental or nefarious attempts to re-identify the underlying identities pseudonymized by current hashing methods are disclosed. The system abates the privacy exposure risk derived from the simple exchange of hashed information, because the referenced actors do not come into possession of the input values required to produce a repeatable function.