Tweak-Based Encryption for Pseudonym Range Preservation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing pseudonymization processes often alter or destroy statistical properties of sensitive data, making it difficult to analyze while maintaining privacy, and do not effectively enhance the entropy of pseudonym values to prevent association with plaintext values.

Innovation Solution

The use of index tweak-based format-preserving encryption (FPE) that applies a tweak to the encryption cipher based on ancillary data associated with plaintext values, ensuring a one-to-one correspondence and range preservation of pseudonym values while maximizing entropy, allowing for reversible conversion between plaintext and pseudonym values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional pseudonymization processes are used to convert plaintext sensitive data to pseudonyms, then privacy protection is improved, but statistical properties of the data are altered or destroyed

Engineering Contradiction:
Improveprivacy protectionVSAvoidstatistical properties
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies format-presving encryption (FPE) that changes the parameter of pseudonym generation to maintain the same statistical distribution and format as the original plaintext data. This allows statistical analysis to proceed on pseudonymized data while maintaining privacy protection.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of traditional pseudonymization that destroys statistical properties, the patent inverts the approach by using encryption that preserves the statistical characteristics of the original data, allowing both privacy protection and statistical analysis to coexist.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If pseudonymization processes are applied to protect sensitive data, then privacy is improved, but the entropy of pseudonym values is not enhanced, making association with plaintext values possible

Engineering Contradiction:
Improveprivacy protectionVSAvoidentropy of pseudonym values
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary tweaking to the encryption cipher before the actual encryption process. This preliminary action of tweaking the cipher with ancillary data ensures that the resulting pseudonyms have high entropy and cannot be easily associated with the original plaintext values.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary tweaking step that uses ancillary data to modify the encryption process. This intermediary mechanism enhances the entropy of pseudonym values by adding an additional layer of transformation beyond simple encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If format-preserving encryption is used to maintain data format, then usability is improved, but the ability to prevent association with plaintext values is reduced without tweaking

Engineering Contradiction:
Improvedata format preservationVSAvoidassociation prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges format-presving encryption with a tweaking mechanism that uses ancillary data. This combination maintains the format preservation benefit while adding the association prevention capability through the tweaking step, resolving the contradiction between usability and security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11106821B2Determining pseudonym values using tweak-based encryption
Publication Date: 2021.08.31 MICRO FOCUS LLC
  • US11106821B2 patent drawing
  • US11106821B2 patent drawing
  • US11106821B2 patent drawing

AI summary

A technique includes accessing data that represents a plurality of values that are associated with a plurality of ranges. The technique includes determining a pseudonym value for a given value, where the given value is associated with a given range and determining the pseudonym includes encrypting the given value to provide the pseudonym value; controlling the encryption to cause the pseudonym value to be within the given range; and tweaking the encryption based on an attribute that is associated with the given value.