Personal data anonymization system (PDAS) with customized token
The invention relates to a device and method for protecting sensitive personal data held in a public storage, comprising a trusted tokenization system having at least one trusted interface to an instance that may provide, process, possess, and/or retrieve sensitive personal data, and at least one interface to a public storage not containing sensitive personal data, wherein the tokenization system is configured to replace a sensitive personal reference of the data in the public storage with a non-sensitive data element and to store an association between the sensitive personal reference and the non-sensitive data element in a secure environment, wherein the non-sensitive data element is generated in a user-specific manner such that the non-sensitive data element can be processed in an existing infrastructure of a user without adaptation of said infrastructure.
1 . A device for protecting sensitive personal data held in a public storage, comprising:
a transmitter and a receiver;
at least one trusted interface to a secured trusted access computing device that provides, processes, possesses, and/or retrieves sensitive personal data; and
at least one interface to a public storage not containing sensitive personal data, wherein the device is configured to replace a sensitive personal reference of the sensitive personal data in the public storage with a non-sensitive data element and to store an association between the sensitive personal reference and the non-sensitive data element in a secure environment, wherein the non-sensitive data element is generated in a user-specific manner such that the non-sensitive data element is processed in an existing infrastructure of a user without adaptation of said infrastructure, wherein the device further comprises or is connected to a database in the secure environment, wherein when data is queried from the database, requested non-sensitive data elements are provided with a cryptographic checksum for which a certificate is issued externally together with the query result, wherein the device is configured to send, for a specific transaction, the sensitive personal data, the non-sensitive data element, an associated data element ID, and a security code, wherein the security code is valid for a predetermined period of time and is encrypted with a token key that is unique for the transaction and only valid for the predetermined period, wherein the token key includes: a Token data element IDs of data to be sent, time stamp to the minute, IP address of a person that the sensitive personal data belongs to, and transaction-specific details.
2 . The device of claim 1 , wherein the sensitive personal data is health data and/or patient data.
3 . The device of claim 1 , further comprising a configurable, rights system for data access.
4 . The device of claim 1 , wherein the device is configured to manage distributed data elements of the user and/or assign distributed data elements to the user.
5 . The device of claim 1 , wherein the device is configured to generate plural non-sensitive data elements as tokens for different use cases.
6 . The device of claim 1 , wherein the device is configured to encrypt and/or sign the sensitive personal data.
7 . The device of claim 1 , wherein the device is configured to prevent falsification of the sensitive personal data.
8 . The device of claim 1 , wherein the device is configured to prevent incorrect assignment of the sensitive personal data.
9 . The device of claim 1 , wherein the device is configured to include the user as a central data release instance.
10 . The device of claim 1 , wherein the device is configured to allow the user, anonymized by the non-sensitive data element, to authorize a release of the sensitive personal data to a cloud service provider.
11 . The device of claim 10 , wherein the device is configured to perform a two-factor authentication to confirm the sensitive personal data release, said two-factor authentication comprising at least one of a fingerprint, a face ID, an implanted ID readable via smartphone nearfield communication and an authorization server interface.
12 . The device of claim 1 , wherein the device is configured to allow the user to authorize predetermined uses of the sensitive personal data by feeding the sensitive personal data to a machine learning system and/or not storing it in clinical trial databases.
13 . The device of claim 1 , wherein the device further comprises or is connected to a database in the secure environment, wherein when data is queried from the database, requested non-sensitive data elements are provided with a cryptographic checksum for which a certificate is issued externally together with the query result.
14 . A computer implemented method for protecting sensitive personal data held in a public storage, comprising the steps of:
Providing, processing, possessing, and/or retrieving sensitive personal data by means of a device having a transmitter, a receiver, and at least one trusted interface to a secured trusted access device;
Providing at least one interface to a public storage not containing sensitive personal data;
Replacing a sensitive personal reference of the sensitive personal data in the public storage with a non-sensitive data element by means of the device;
Storing an association between the sensitive personal reference and the non-sensitive data element in a secure environment, wherein the non-sensitive data element is generated in a user-specific manner such that the non-sensitive data element is processed in an existing infrastructure of a user without adaptation of said infrastructure;
Querying data and providing requested non-sensitive data elements with a cryptographic checksum for which a certificate is issued externally together with the query result;
Sending, for a specific transaction, the sensitive personal data, the non-sensitive data element, an associated data element ID, and a security code, wherein the security code is valid for a predetermined period of time and is encrypted with a token key that is unique for the transaction and only valid for the predetermined period, wherein the token key includes: a Token, data element IDs of data to be sent, time stamp to the minute, IP address of a person that the sensitive personal data belongs to, and transaction-specific details.