Anonymous data exchange

By providing anonymized and encrypted data exchange mechanisms between data providers and data recipients, allowing data recipients to request lower anonymization levels in order to analyze specific patterns, solving the privacy and security concerns of data providers when sharing sensitive data and improving the identification of security threats.

CN120226309APending Publication Date: 2025-06-27ABB (SCHWEIZ) AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380080212.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-24
Filing Date
2023-11-15
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art has difficulty effectively addressing privacy and security concerns among data providers when sharing sensitive data, especially as the level of anonymization and encryption increases, identifying security threats becomes more difficult.

Method used

By providing anonymized and encrypted data exchange mechanisms between data providers and data recipients, data recipients allow data recipients to request a reduction in the level of anonymization in order to analyze specific patterns, thereby improving the ability to identify security threats.

Benefits of technology

It significantly increases the willingness of data providers to share sensitive data and improves the ability of data recipients to analyze and identify security threats, solving the difficulty of identifying threats by dynamically adjusting the anonymization level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120226309A_ABST
    Figure CN120226309A_ABST
Patent Text Reader

Abstract

A computer-implemented method for providing a data exchange of sensitive data between at least one data provider and at least one data recipient, comprising: providing sensitive data by the at least one data provider; anonymizing the provided sensitive data, and providing an anonymous connection link for the anonymous sensitive data; anonymous sensitive data having an anonymous connection link is provided to at least one data recipient, and anonymous communication is provided between the at least one data recipient and at least one data provider over the anonymous connection link in the event that the at least one data recipient considers that the anonymous sensitive data is of interest, the communication includes providing a request to change anonymization to at least one data provider via the anonymous communication, approving or rejecting the request to change anonymization by the at least one data provider, and when the request is approved, providing anonymous sensitive data with changed anonymization to at least one data recipient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a computer-implemented method, a data provider device, a data recipient device, and a system for providing data exchange of sensitive data between a data provider and at least one data recipient. Background Art

[0002] A general background of the present disclosure is to provide anonymized sensitive data from a data provider to a data recipient.

[0003] Current security operation technologies OT and industrial control system ICS infrastructures involve continuous monitoring of the infrastructure state. Security information and event management SIEM systems provide rules for detecting known threats by monitoring event data, and anomaly detection is a good way to discover unknown and suspicious situations. In the case of discovering such suspicious situations, further analysis is usually required, which includes knowledge of the latest attack scenarios and comparison with data from other sites. Therefore, the second-level analysis of such anomalies cannot be completed by each individual infrastructure owner, but should be bundled at the ICS and / or security solution provider. This approach requires the factory owner to send data representing the anomaly to the ICS and / or security solution provider. However, factory owners are usually reluctant to share this sensitive data. Data governance and data privacy rules, as well as cybersecurity awareness, generally do not allow the exchange of plaintext data. At the site of the ICS and / or security solution provider, experts can individually analyze the packages submitted by the factory owner or compare them with the packages of other factory owners. However, as the level of data anonymization and encryption increases, it becomes more difficult to identify certain patterns as security threats.

[0004] Therefore, there is a need to provide a method and system, in particular a suitable mechanism, which encourages and increases the willingness of data owners to send shared data (especially sensitive data) to data recipients in an encrypted and anonymized manner. In addition, there is a need to provide a method and system by which data recipients (especially experts) obtain multiple data to be analyzed and processed separately, and can request to see certain parts of the anonymized sensitive data with a lower level of anonymization, for example, to provide enhanced identification of certain patterns as security threats. Summary of the Invention

[0005] In one aspect of the present invention, there is provided a computer-implemented method for providing data exchange of sensitive data between at least one data provider and at least one data recipient, the method comprising:

[0006] providing sensitive data by at least one data provider;

[0007] Anonymize the provided sensitive data and provide an anonymized connection link to the anonymized sensitive data;

[0008] Provide anonymized sensitive data with an anonymized connection link to at least one data recipient,

[0009] In the case where the anonymized sensitive data is considered interesting by at least one data recipient,

[0010] Provide anonymized communication between at least one data recipient and at least one data provider through the anonymized connection link, where the communication includes:

[0011] Provide a request to change the anonymization to at least one data provider via the anonymized communication;

[0012] Receive the request by one of at least one data provider permitted to receive the request;

[0013] Approve or reject the request to change the anonymization by one of at least one data provider,

[0014] When the request is approved, provide anonymized sensitive data with the changed anonymization to at least one data recipient.

[0015] The term "sensitive data" used herein should be understood broadly and represents any data indicating private and / or secret data, which is not accessible or not accessible to the public. Sensitive data can include specific data types. Exemplary specific data types can be data representing abnormal situations, anomalies, company names, address data, personal data, factory data, device identifier data, device identifiers, alarm and event messages, and process values, but are not limited thereto. For sensitive data, data governance and data privacy rules as well as network security rules are usually applied. Sensitive data can be the entire data set of sensitive data or a fragment of a data set of a part of the entire data set of sensitive data, and the schema of the entire data set of sensitive data (such as a part of sensitive data indicating only one specific data type). Sensitive data can be provided through queries, identifications, or detections by data providers, but are not limited thereto.

[0016] The term "data provider" used herein should be understood broadly and represents any natural person and / or company capable of providing data. For example, a data provider can be a factory owner and a data owner, but is not limited thereto.

[0017] The term "data recipient" as used herein should be understood broadly and denotes any natural person and / or company capable of receiving data. For example, the data recipient can be an external data analyst, an industrial control system solution provider, a distributed control system provider, and / or a security solution provider, but is not limited thereto. The data recipient can receive anonymized sensitive data from at least two data providers, i.e., from multiple data providers.

[0018] The term "anonymization" as used herein should be understood in a broad sense and denotes any method or process for encrypting sensitive data. Anonymization is provided by applying an encryption algorithm to the sensitive data. For example, the encryption algorithm can be a standard encryption algorithm such as authenticated encryption, AES, ChaCha, Speck, but is not limited thereto. Optionally, such an algorithm can be used for authenticated encryption AEAD construction with associated data, such as AES-GCM. The anonymization of the encrypted fields can be revoked by sharing the key with the recipient, allowing the recipient to decrypt all fields encrypted with a certain key. Anonymization can provide multi-level anonymization, including at least three levels of anonymization, namely no anonymization, lower-level anonymization, and highest-level anonymization. Based on the level of anonymization, the data recipient does not know who sent the anonymized sensitive data and / or what each entry in the sensitive data means. Anonymization can be freely selected, picked, defined, and / or provided by the data provider via an anonymization configuration tool. The level of anonymization and anonymization / encryption can be changed by the data provider at any time. In addition, the anonymization of sensitive data can be revoked at any time. The anonymization level can be pre-provided, pre-selected, pre-configured by the data provider, or the anonymization level can be freely selected. In addition, in order to automate the anonymization of sensitive data, a default anonymization level can be set for each type of sensitive data.

[0019] As used herein, the phrase "anonymized sensitive data is considered of interest by at least one data recipient" should be understood broadly and means that the data recipient can examine / analyze the anonymized / encrypted sensitive data to determine the occurrence of known patterns. For example, the known pattern can be a previously occurred anomaly, etc., which is recognized or stored in the database of the data recipient device. For example, the pattern can be the minimum number of failed login attempts after a successful login attempt within a given time frame, but is not limited thereto. In the case of the occurrence of a known pattern, these patterns are identified as sensitive data of interest, such that the data recipient obtains a requirement / request to change the anonymization level of the anonymized sensitive data and obtains a request for downgrading the anonymization level of the data portion containing the pattern of interest.

[0020] The term "anonymous communication" as used herein shall be understood broadly and denotes any anonymous exchange of information and / or data, but is not limited thereto. It provides communication between a data provider and a data recipient. The communication between the data recipient and the data provider is provided by the following sub-steps. Each part of the anonymous sensitive data provided by the data provider and submitted / provided to the data recipient has an anonymous connection link respectively. When the data recipient wants to request the de-anonymization of the anonymous sensitive data, a request is provided with the anonymization connection link to at least one data provider. Since only one of the at least one data providers (i.e., the data provider of the original sensitive data) has the same, corresponding or complementary anonymous connection link, only one of the at least one data providers can and is allowed to receive and process the request sent by the data recipient. This one data provider among the at least one data providers can decrypt the request. The other data providers among the at least one data providers cannot decrypt the request and will not be able to obtain any information about the content of the request. When the data provider accepts the request and provides the anonymous sensitive data with a lower level of anonymization, the data provider provides this anonymous sensitive data back to the data recipient. Additionally or alternatively, the provision of the communication can be fully or at least partially automated. Thus, the change of the anonymization level and most of the sending requests are automatically executed, minimizing human interaction to a minimum. In addition to the requests provided during the communication, the data recipient can send requests and opinions to the data provider. Additionally or alternatively, the data provider is able to send response opinions back to the data recipient. The response opinions can include information on why the data recipient's request is rejected or accepted, i.e., the reasons for acceptance and rejection. The communication can be two-way communication. The communication can be carried out between the data recipient and the data provider at any time.

[0021] The term "request" as used herein shall be understood broadly and denotes any request or query for abolishing anonymization or downgrading the anonymization level. The request can be for the entire data set of the anonymous sensitive data or a part of the anonymous sensitive data, especially a specific data type of the anonymous sensitive data. Preferably, the request only requests a specific data type of the sensitive data. Additionally, the request can include opinions. For example, the opinion can be a question or an explanation, such as why the data recipient needs further de-anonymization. Furthermore, in the request, the data recipient can request to demarcate the anonymization level of the anonymous sensitive data to a specific level, i.e., the level selected by the data recipient.

[0022] The term "anonymous connection link" as used herein should be understood broadly and represents any link that provides a connection between a data provider and a data recipient. The anonymous connection link can be a unique identifier, a unique ID, and / or a public ID key, but is not limited thereto. For example, the public ID key is a long password. The connection link can be an integer or a string, but is not limited thereto. The anonymous connection link can be a unified link, i.e., the anonymous connection link of the data provider and the anonymous connection link of the submitted / provided anonymous sensitive data provided to the data recipient are the same, or a complementary link, i.e., the connection link of the data provider and the anonymous connection link of the submitted / provided anonymous sensitive data provided to the data recipient match each other, but is not limited thereto. The anonymous connection link prevents the data recipient from identifying the data provider.

[0023] The term "data" as used herein should be understood broadly in the current context and represents any kind of data. The data can be a single number / numerical value, multiple numbers / numerical values, multiple numbers / numerical values arranged in a list, a string, and an integer, but is not limited thereto.

[0024] By providing sensitive data anonymously, transferring these data from the data owner to the data recipient, and providing anonymous communication between at least one data recipient and the data provider, the willingness of the data provider to share sensitive data can be significantly increased. In addition, the data recipient (especially an expert) has the possibility to request and negotiate to see certain parts of the anonymous sensitive data, for example, with a lower anonymization level, enabling enhanced identification of certain patterns as security threats.

[0025] In an embodiment of a computer-implemented method for data exchange of sensitive data between a data provider and at least one data recipient, the anonymous communication is two-way communication.

[0026] The term "two-way communication" as used herein should be understood broadly and represents that communication between the data provider and the data recipient is possible in both directions, i.e., directly or indirectly from the data provider to the data recipient and directly or indirectly from the data recipient to the data provider.

[0027] By providing two-way communication between the data recipient and the data provider, negotiation of the anonymization level of the anonymous sensitive data can be provided, which increases the constructive exchange of sensitive data between the data provider and the data recipient. Specifically, the negotiation results in a state where both the data recipient and the data provider must find a compromise regarding the anonymization level such that both the data recipient and the data provider will benefit from the data exchange.

[0028] In an embodiment of a computer-implemented method for providing data exchange of sensitive data between a data provider and at least one data recipient, anonymization of the provided sensitive data includes multi-level anonymization, where the level of anonymization is selected and defined by at least one data provider.

[0029] By providing the possibility for the data provider to select and define the level of anonymization of this sensitive data, the willingness and trust of the data provider to share sensitive data can be significantly increased.

[0030] In an embodiment of a computer-implemented method for providing data exchange of sensitive data between a data provider and at least one data recipient, a change in anonymization includes revoking anonymization or reducing the level of anonymization.

[0031] In an embodiment of a computer-implemented method for providing data exchange of sensitive data between a data provider and at least one data recipient, the anonymized sensitive data is the entire data set of anonymized sensitive data or a part of the anonymized sensitive data set.

[0032] In an embodiment of a computer-implemented method for providing data exchange of sensitive data between a data provider and at least one data recipient, the method further includes the step of requiring the data provider to delete the provided anonymized sensitive data or replace the provided anonymized sensitive data with different data.

[0033] By giving the data provider the freedom of action to delete and replace the provided anonymized sensitive data with different data, the willingness and trust of the data provider to share sensitive data can be significantly increased.

[0034] In an embodiment of a computer-implemented method for providing data exchange of sensitive data between a data provider and at least one data recipient, the method further includes the steps of: processing, by at least one data recipient, the provided anonymized sensitive data with changed anonymization; and providing the result of the processing to at least one data provider.

[0035] The term "processing" used herein should be understood broadly and represents any method or process for separately analyzing the received anonymized sensitive data with changed anonymization or for comparing the anonymized sensitive data with changed anonymization with other data. The result of the processing can be the broadcast of new rules and / or newsletters, the result of the analysis, in particular an analysis report, but is not limited thereto. Additionally, the result of the processing can be provided to all other data providers.

[0036] By providing analysis to and providing the result to at least one data provider, the data provider can receive information about, for example, anomalies, etc.

[0037] In an embodiment of a computer-implemented method for providing data exchange of sensitive data between a data provider and at least one data receiver, the processing of the provided anonymized sensitive data with altered anonymization is an analysis of security threats.

[0038] On the other hand, a data provider device is proposed, comprising:

[0039] A first providing unit for providing sensitive data;

[0040] An anonymization unit for anonymizing the provided sensitive data and for providing an anonymization connection link to the anonymized sensitive data,

[0041] wherein the anonymization unit comprises an anonymization configuration tool for selecting and defining an anonymization level,

[0042] A second providing unit for providing the anonymized sensitive data with the anonymization connection link to at least one data receiver device; and

[0043] A communication unit for anonymous communication with at least one data receiver device,

[0044] wherein the communication unit comprises:

[0045] A receiver unit for receiving and allowing a request for altered anonymization;

[0046] A decision unit for the request for providing a decision on the received and allowed request;

[0047] An anonymization editing unit for providing anonymized sensitive data with altered anonymization; and

[0048] A third providing unit for providing the provided anonymized sensitive data with altered anonymization to at least one data receiver device.

[0049] The term "anonymization configuration tool" used herein should be understood broadly and denotes any tool by which a data provider selects, picks, and / or defines an anonymization level for one or more specific data types of anonymized sensitive data.

[0050] The term "decision unit regarding requests" used herein should be understood broadly and denotes any unit for providing acceptance or rejection of requests for anonymization levels of sensitive data subject to change. Additionally, the decision unit regarding requests is capable of storing specific anonymization justifications regarding specific portions, patterns, or specific data types of sensitive data. For example, in order to avoid excessive protocols for lower anonymization levels, a red flag can be set in the anonymization configuration tool for specific anonymization justifications that should not be changed. Further, when a request violates the red flag, a warning can be added to the request. Additionally, flags can be set for non-negotiable settings. In this case, requests for changes to non-negotiable anonymization levels are ignored. Additionally or alternatively, in order to ensure that data providers are not troubled by requests for changes to anonymization levels on data sets that the data providers have already rejected or accepted, duplicate requests from the same data provider are also ignored.

[0051] The term "anonymization editor unit" used herein should be understood broadly and denotes any unit for changing the anonymization level of sensitive data. In other words, the anonymization editor unit provides interactive changes to the anonymization levels of sensitive data or portions of sensitive data and / or individual data types, where the data recipient and the data provider interact with each other. Changes to the anonymization level can be provided at any time. The anonymization editor unit can be used to rewrite the anonymization level or the default anonymization level of anonymized sensitive data during the automatic anonymization process of sensitive data.

[0052] On the other hand, a data recipient device is proposed, comprising:

[0053] a receiving unit for receiving anonymized sensitive data with an anonymous connection link from at least one data provider device; and

[0054] a communication unit for anonymous communication with the data provider unit;

[0055] wherein the communication unit comprises:

[0056] a search unit for searching for anonymized sensitive data of interest;

[0057] an anonymization level change request unit for providing a request to change anonymization;

[0058] a providing unit for providing a request to change anonymization to at least one data provider device; and

[0059] a second receiving unit for receiving anonymized sensitive data with changed anonymization.

[0060] The term "receiving unit" as used herein should be understood broadly and represents any unit capable of receiving anonymized sensitive data from at least one data providing unit using an anonymized connection link. The receiving unit is capable of differentiating and / or providing notification regarding used or new data sets.

[0061] The term "anonymization level change request unit" as used herein should be understood broadly and represents any unit capable of providing a request to change anonymization to a desired anonymization level and capable of providing, with the request, the anonymized connection link received by the data recipient along with the received anonymized sensitive data. Additionally, the anonymization level change request unit is capable of providing an opinion with the request. For example, the opinion can be a question or an explanation, such as why the data recipient needs further de-anonymization.

[0062] In an embodiment of the data recipient device, the device further includes: a processing unit for processing the provided anonymized sensitive data with changed anonymization; and a third providing unit for providing the result of the processing to at least one data provider.

[0063] In an embodiment of the data recipient device, the data recipient device further includes a storage unit for storing the received anonymized sensitive data with the anonymized connection link and / or the result of the processing unit.

[0064] The term "storage unit" as used herein should be understood broadly and represents any unit for storing anonymized sensitive data. For example, the storage unit can be a database, a memory, a storage device, cloud storage, and / or a cache, but is not limited thereto. The storage unit stores data packets from data providers, knowledge about the selected anonymization level, connection links, and the storage of known patterns representing regions of interest such as security threats. Additionally, the storage unit also stores all services performed by the data recipient, such as analysis and determination. Furthermore, the storage unit stores information about which requests have been made for each record.

[0065] In another aspect, a system for providing data exchange of sensitive data between a data provider and at least one data recipient is provided, including a data provider unit as described in the present disclosure and a data recipient unit as described in the present disclosure.

[0066] In another aspect, a computer program element having instructions, when executed on a computing device in a computing environment, the instructions being configured to perform the steps of a computer-implemented method as described in the present disclosure in a system as described in the present disclosure.

[0067] In another aspect, a computer-readable storage medium including instructions, the instructions causing a computer to perform a computer-implemented method as described in the present disclosure when executed by the computer.

[0068] Any disclosure and embodiment described herein relates to the computer-implemented methods, data providing units, data receiving units, and systems listed above, and vice versa. Advantageously, the benefits provided by any embodiment and example equally apply to all other embodiments and examples, and vice versa.

[0069] As used herein, "determine" also includes "initiate or cause to determine", "generate" also includes "initiate or cause to generate", and "provide" also includes "initiate or cause to determine, generate, select, send, or receive". "Initiate or cause to perform an action" includes any processing signal that triggers a computing device to perform the corresponding action. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] In the following, the present disclosure is further described with reference to the accompanying drawings:

[0071] Figure 1 A flowchart of a computer-implemented method for providing data exchange of sensitive data between at least one data provider and at least one data recipient is shown;

[0072] Figure 2 An example embodiment of a data provider device is shown;

[0073] Figure 3 An example embodiment of a data recipient device is shown;

[0074] Figure 4 An example embodiment of a system for providing data exchange of sensitive data between at least one data provider and at least one data recipient is shown;

[0075] Figure 5 An example use of the system is shown;

[0076] Figure 6 An example of configuration settings / anonymization reasons in an anonymization configuration tool is shown;

[0077] Figure 7 A broadcast service is shown;

[0078] Figure 8 A flowchart showing how a data provider submits a data set is shown;

[0079] Figure 9 A flowchart showing how a data provider processes requests from a data recipient is shown;

[0080] Figure 10 A flowchart of data anonymization and submission in a data provider device is shown.

[0081] Figure 11A flowchart showing data processing in a data receiver device Detailed implementation manner

[0082] The following embodiments are merely examples of the computer-implemented methods and systems disclosed herein and should not be considered restrictive.

[0083] Figure 1 A flowchart showing a computer-implemented method for providing data exchange of sensitive data between at least one data provider and at least one data receiver. In the first step, sensitive data is provided by at least one data provider. In the second step, the provided sensitive data is anonymized by an encoding method, where different types of sensitive data have different anonymization levels. Additionally, in the second step, an anonymous connection link is provided for the anonymized sensitive data. The anonymous connection link is a unique ID that enables representing the anonymous connection between the provided anonymized sensitive data and the data provider respectively. In the third step, the anonymized sensitive data with the anonymous connection link is provided to at least one data receiver. The at least one data receiver receives data from multiple data providers and checks the received anonymized sensitive data if at least one data is considered of interest. In the case where the anonymized sensitive data is considered of interest by the at least one data receiver, anonymous communication between the at least one data receiver and the at least one data provider provided by the anonymous connection link is provided. Communication is provided through the anonymous connection link. The communication includes the following sub-steps: providing a request to change anonymization to at least one data provider via anonymous communication, where the request has the connection link of the anonymized sensitive data received by the data receiver. The communication also includes the sub-step of receiving the request by one of the at least one data providers allowed to receive the request. The request is allowed when the anonymous connection link of the data provider is the same as the requested anonymous connection link. Additionally, the communication includes the following steps: approving or rejecting the request to change anonymization by one of the at least one data providers, and when the request is approved, providing the anonymized sensitive data with the changed anonymization to at least one data receiver.

[0084] Optionally, the computer-implemented method for providing data exchange of sensitive data between at least one data provider and at least one data receiver further includes the step of requiring the deletion of the provided anonymized sensitive data or replacing the provided anonymized sensitive data with different data.

[0085] Optionally, the computer-implemented method for providing data exchange of sensitive data between at least one data provider and at least one data receiver further includes the steps of: processing the provided anonymized sensitive data with the changed anonymization by at least one data receiver; and providing the result of the processing to at least one data provider.

[0086] Figure 2 An example embodiment of a data provider device is shown. The data provider device 20 includes a first providing unit 21 for providing sensitive data, an anonymization unit 22 for anonymizing the provided sensitive data and for providing an anonymization connection link to the anonymized sensitive data. The anonymization unit 22 includes an anonymization configuration tool 23 for selecting and defining an anonymization level. The data provider device 20 further includes a second providing unit 24 for providing the anonymized sensitive data to at least one data recipient device and a communication unit 25 for anonymous communication with at least one data recipient device. The communication unit 25 includes: a recipient unit 26 for receiving and allowing a request regarding a change in anonymization; a decision unit 27 regarding the request for providing a decision on the received and allowed request; an anonymization editing unit 28 for providing anonymized sensitive data with a changed anonymization; and a third providing unit 29 for providing the provided anonymized sensitive data with the changed anonymization to at least one data recipient device.

[0087] Figure 3 An example embodiment of a data recipient device is shown. The data recipient device 30 includes: a receiving unit 31 for receiving anonymized sensitive data with an anonymization connection link from at least one data provider unit; and a communication unit 32 for anonymous communication with the data provider device. The communication unit 32 includes: a search unit 33 for searching for anonymized sensitive data of interest; an anonymization level change request unit 34 for providing a request to change anonymization; a providing unit 35 for providing the request to change anonymization to at least one data provider device; and a second receiving unit 36 for receiving anonymized sensitive data with a revoked or degraded anonymization.

[0088] Optionally, the data recipient device 30 further includes a processing unit 37 for processing the provided anonymized sensitive data with a changed anonymization and a third providing unit 38 for providing the result of the processing to at least one data provider.

[0089] Optionally, the data recipient device 30 further includes a storage unit 39 for storing the received anonymized sensitive data with an anonymization connection link.

[0090] Figure 4 An example embodiment of a system for data exchange of sensitive data between at least one data provider and at least one data recipient is shown. The system 40 includes a data provider unit 20 and a data recipient unit 30.

[0091] Figure 5An example use of the system is shown. The data provider has detected an anomaly in its data but cannot determine whether it is caused by a security issue. The data provider can submit the detected anomaly to the data receiver, specifically an external analyst, by using the data provider device. The data is anonymized according to predefined configuration settings. The data receiver receives the data and compares it with other cases. The data receiver can find similar cases, but to ensure whether these cases are comparable, the data receiver needs to know more data. The data receiver marks the data parts that need to be placed at a lower anonymization level, selects the desired anonymization level, adds an opinion on why this is necessary, and submits the request to the data provider. The request is sent to all data providers from whom the data receiver receives data, but only the data providers of the data of interest can receive and process the request. The data provider allows the anonymization change, and the modified data is resubmitted to the data receiver. Once the data receiver has completed the check, a report on the findings can be sent to the data provider.

[0092] Figure 6 An example of the configuration settings / anonymization reasons in the anonymization configuration tool is shown. Data types such as company name, address data, personal data, and process values are highly sensitive data, such that this data is not sent to the data receiver at all. Data types such as plant, device identifier, and KKS can be sent to the data receiver using medium anonymization / encryption. Data types such as alarm and event messages can be sent to the data receiver with high anonymization / encryption. In the case where the data receiver requests to change the anonymization level of the data type of the process value, the request is ignored. This is indicated by a red flag. In the case where the data receiver requests to change the anonymization level of the data types of company name, address data, personal data, plant, device identifier, and power plant classification system KKS, a warning is added when the request is received. In the case where the data receiver requests to change the anonymization level of the data type of alarm and event messages, the request is accepted without any approval from the data provider.

[0093] Figure 7 A broadcast service is shown. The infrastructure of system 40 can also be used to broadcast the results that can be further processed as newsletters and / or security information (i.e., the identification of security threats) and event management rules (SIEM rules) to all data providers who provide data to the data receiver. The data receiver provides these results and transmits these results wirelessly or wired to at least one data provider. The data provider can receive and check the results and can forward these results to users, such as newsletters, and to SIEM, such as SIEM rules.

[0094] Figure 8A flowchart showing how a data provider submits a data set is presented. The data provider checks the data and can detect anomalies. The data provider also provides anomaly-related data that can be stored in or queried from a database. When an anomaly is detected, a notification along with the anomaly data is provided to an internal analyst at the data provider device. In cases where an external analyst is required, the data provider submits a request for external analysis, a request for data submission, and receives data via a data exchange. Additionally, Figure 8 Possible steps before the data is anonymized and submitted to a data recipient are shown. It shows that some data providers can first have an internal data analyst to analyze the data. Then only cases that cannot be resolved are sent to an external data recipient. The step "Data processing by data exchange" summarizes Figure 10 all the steps.

[0095] Figure 9 A flowchart showing how a data provider processes requests from a data recipient is presented. When a request is received for the provided data, the request is checked. When the recipient is correct, the data provider checks whether the request has not been sent before or is negotiable. Otherwise, or when the request has been sent before or is non-negotiable, the request is deleted / ignored. After checking whether the request has not been sent before and is negotiable, the data provider checks for the presence of a red flag in the anonymization justification. When there is a red flag violation, a warning is added to the request. Otherwise, the request for data submission is accepted and a data exchange is provided. Additionally, Figure 9 Necessary steps around anonymization are shown. When these steps are required, there are two cases: (a) Figure 8 An internal request from the data provider is shown as the data needs to be sent out to a data recipient. (b) Figure 9 An external request from the data provider is shown. Here, other steps are necessary, such as checking for a red flag or checking whether the request has been sent before.

[0096] Figure 10 A flowchart showing data anonymization and submission in a data provider device is presented. The data provider device receives a request for data submission and displays the request to the responsible data. When the responsible data accepts the request, the anonymization level is provided again by considering the requested level and the anonymization justification. In cases where modification is required, a modification to the anonymization level is provided by showing the data to the responsible person and modifying the anonymization parameters. In cases where no modification is required, the data provider submits the sensitive data with proper anonymization to the data recipient. Further, Figure 10Shows the anonymization process. Anonymization depends on the settings made in the configuration tool and the requested level of anonymization (in the case of an external request). The anonymization of data is performed automatically and can be modified by the person in charge of data exchange. This can be done, for example, by using an anonymization editor, where areas of the data can be selected and anonymized to another level.

[0097] Figure 11 Shows a flowchart of data processing in the data recipient device. When the data recipient device receives sensitive data (especially new data), the received data is processed. During the processing of the received data, a notification is provided and it is checked whether there is an older version. In the case where an older version exists, that older version is deleted and the newer version is added to the storage, especially a storage medium. The new data and the notification stored on the storage medium are displayed and provided to the analyst. The analyst checks the new data by querying known threat patterns from another database. When the analyst comes to the conclusion that de-anonymization might be helpful, the analyst provides a request and submits the request to the data provider. Additionally, Figure 11 Shows the processing on the data recipient side. Once the data arrives, the data is stored, where the older version of the data is replaced, and the analyst is notified by a notification that new data has arrived. The analyst can view the data and perform an analysis using the new data, which also includes data from other data providers and known threat patterns. Based on the results of the analysis, the analyst can decide whether reduced anonymization of at least part of the data would be helpful. If the analyst decides that reduced anonymization of at least part of the data would be helpful, a request is sent to the data provider.

[0098] The present disclosure has been described in connection with preferred embodiments by way of example. However, other variations can be understood and implemented by those skilled in the art and practicing the claimed invention by studying the drawings, the present disclosure, and the claims. In particular, any of the presented steps can be performed in any order, that is, the present invention is not limited to a particular order of these steps. Additionally, it is not required that different steps be performed at a particular location or one node in a distributed system, that is, each step can be performed at different nodes using different devices / data processing units.

[0099] In the claims as well as in the specification, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. A single element or other unit can perform the functions of several entities or items recited in the claims. The fact that certain measures are recited in mutually different dependent claims does not mean that a combination of these measures cannot be used to advantage.

Claims

1. A computer-implemented method for providing data exchange of sensitive data between at least one data provider and at least one data recipient, comprising: providing sensitive data by the at least one data provider; anonymizing the provided sensitive data and providing an anonymous connection link to the anonymized sensitive data; providing the anonymized sensitive data with the anonymous connection link to the at least one data recipient, in a case where the anonymized sensitive data is considered of interest by the at least one data recipient, providing anonymous communication between the at least one data recipient and the at least one data provider through the anonymous connection link, wherein the communication comprises: providing a request to change the anonymization to the at least one data provider via the anonymous communication; receiving the request by one of the at least one data providers permitted to receive the request; approving or rejecting the request to change the anonymization by one of the at least one data providers, when the request is approved, providing the anonymized sensitive data with the changed anonymization to the at least one data recipient.

2. The computer-implemented method according to claim 1, wherein the anonymous communication is two-way communication.

3. The computer-implemented method according to any one of the preceding claims, wherein the anonymization of the provided sensitive data comprises multi-level anonymization, and the level of anonymization is selected and defined by the at least one data provider.

4. The computer-implemented method according to any one of the preceding claims, wherein changing the anonymization comprises abolishing the anonymization or reducing the level of anonymization.

5. The computer-implemented method according to any one of the preceding claims, wherein the anonymized sensitive data is the entire data set of anonymized sensitive data or a part of the anonymized sensitive data set.

6. The computer-implemented method according to any one of the preceding claims, further comprising: requiring the data provider to delete the provided anonymized sensitive data or replace the provided anonymized sensitive data with different data.

7. The computer-implemented method according to any one of the preceding claims, further comprising: processing, by the at least one data recipient, the provided anonymized sensitive data with the changed anonymization; and providing the result of the processing to the at least one data provider.

8. The computer-implemented method according to claim 7, wherein the processing of the provided anonymized sensitive data with the changed anonymization is an analysis of security threats.

9. A data provider device (20), comprising: a first providing unit (21) for providing sensitive data; an anonymization unit (22) for anonymizing the provided sensitive data and for providing an anonymous connection link to the anonymized sensitive data, wherein the anonymization unit (22) comprises an anonymization configuration tool (23) for selecting and defining the level of anonymization, A second providing unit (24) for providing anonymous sensitive data with an anonymous connection link to at least one data recipient device; and A communication unit (25) for anonymous communication with the at least one data recipient device, wherein the communication unit (25) includes: A recipient unit (26) for receiving and allowing requests for changing the anonymization; A decision unit (27) for requests for providing a decision on the received requests and the allowed requests; An anonymization editing unit (28) for providing anonymous sensitive data with changed anonymization; and A third providing unit (29) for providing the provided anonymous sensitive data with changed anonymization to the at least one data recipient device.

10. A data recipient device (30) comprising: A receiving unit (31) for receiving anonymous sensitive data with an anonymous connection link from at least one data provider unit; and A communication unit (32) for anonymous communication with the data provider device, wherein the communication unit (32) includes: A search unit (33) for searching for anonymous sensitive data of interest; An anonymization level change request unit (34) for providing a request for changing the anonymization; A providing unit (35) for providing the request for changing the anonymization to the at least one data provider device; and A second receiving unit (36) for receiving anonymous sensitive data with changed anonymization.

11. The data recipient device (30) according to claim 9, further comprising: A processing unit (37) for processing the provided anonymous sensitive data with changed anonymization; and A third providing unit (38) for providing the result of the processing to the at least one data provider.

12. The data recipient device (30) according to claim 9 or 10, further comprising: A storage unit (39) for storing the received anonymous sensitive data with the anonymous connection link and / or the result of the processing unit.

13. A system (40) for data exchange of sensitive data between a data provider and at least one data recipient, comprising: The data provider unit (20) according to claim 9, and The data recipient unit (30) according to claims 10 to 12.

14. A computer program element having instructions which, when executed on a computing device in a computing environment, are configured to perform the steps of the computer-implemented method according to any one of claims 1 to 8 in the system according to claim 13.

15. A computer-readable storage medium comprising instructions which, when executed by a computer, cause the computer to perform the computer-implemented method according to any one of claims 1 to 8.