发明名称 Two-stage anonymization of mobile network subscriber personal information
摘要 A two-stage anonymization process is applied to monitored network traffic in which unique user identifiers, such as the MSISDN (Mobile Station International Subscriber Directory Number), are extracted from the traffic and anonymized to generate an ASI (anonymized subscriber identifier). A strictly random RSI (random subscriber identifier) is generated and used to replace the ASI. The RSI is generated upon a first occurrence of an ASI and stored in a lookup table for utilization upon subsequent ASI occurrences. Use of the strictly random RSI enables various studies and analysis of user behavior to be performed at a heightened level of privacy protection as compared with conventional anonymization schemes that do not utilize strictly random identifiers.
申请公布号 US8862880(B2) 申请公布日期 2014.10.14
申请号 US201113241968 申请日期 2011.09.23
申请人 GfK Holding Inc. 发明人 Combet Jacques;LeMaitre Yves-Marie;Kivi Antero
分类号 H04L9/32;H04L29/06;H04W12/02;H04W8/26 主分类号 H04L9/32
代理机构 Dinicola & Young PC 代理人 Dinicola & Young PC ;Dinicola Brian K
主权项 1. A device for processing the anonymizing identifier associated with a user of a network comprising: a network probe; a memory; and a computer processor in communication with the memory, the processor executes a program stored on said memory to perform the steps of: tapping traffic traversing a portion of the network to collect session data; extracting the identifier wherein the identifier is one of mobile station international subscriber directory number (MSISDN), international mobile equipment identity (IMEI), or international mobile subscriber identity (IMSI) from the tapped traffic; applying by the network probe a cryptographic hash function Hash-based Message Authentication Code-Secure Hash Algorithm 1 (HMAC-SHA1) at least once to the extracted identifier to generate an anonymized subscriber identifier (ASI); applying twice in succession the HMAC-SHA1 to the MSISDN, IMEI, or IMSI respectively using two separate keys inserting the ASI into the session data; and sending the session data with inserted ASI to a network intelligence solution (NIS); generating random subscriber identifier (RSI) using random generator; enabling the NIS to associate the ASI to a strictly random subscriber identifier (RSI); and storing the associated ASI and RSI in a lookup table.
地址 New York NY US