Anonymous Context Attestation via Zero Knowledge Proofs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures lack collaboration and resource sharing among businesses, governments, and institutions to effectively counter advanced persistent security threats and cyber-attacks, due to concerns over data sharing and lack of a common language for threat intelligence.

Innovation Solution

A system for anonymous context attestation and threat analytics that uses an OS-independent model with zero knowledge proofs (ZKPs) to enable minimal information sharing between devices, allowing parent nodes to verify child nodes' threat intelligence data, preserving anonymity through techniques like Enhanced Privacy Identification (EPID) and Identity Mixer technology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If threat intelligence data is shared among organizations to improve cybersecurity collaboration, then the effectiveness of threat detection and response is improved, but concerns regarding data sharing security and loss of information control arise

Engineering Contradiction:
Improvecybersecurity effectivenessVSAvoiddata sharing control
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary between organizations sharing threat intelligence. The TEE acts as a secure mediator that enables collaborative threat detection while preserving data confidentiality and controlling information access. Organizations can share threat indicators through the TEE without exposing their raw data, thus improving cybersecurity effectiveness while maintaining data sharing control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical data sharing mechanisms (direct exchange of threat intelligence data between organizations) with cryptographic proof systems. Instead of sharing actual threat data, organizations generate and exchange zero-knowledge proofs or cryptographic attestations that verify threat conditions without revealing the underlying information. This substitution enables collaboration while preventing loss of information control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If detailed threat intelligence data is shared to improve analysis accuracy, then the precision of threat detection is improved, but the complexity of the sharing infrastructure and difficulty of verification increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidsharing infrastructure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential verification information needed for threat detection from the complete threat intelligence data. Instead of sharing detailed raw data, the system extracts and shares cryptographic proofs or attestation tokens that contain just enough information to verify threat conditions. This extraction maintains detection accuracy while reducing infrastructure complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms threat intelligence data from its original detailed form into simplified cryptographic parameters (hashes, digital signatures, zero-knowledge proofs). This parameter transformation changes the data representation to a form that is both sufficient for accurate threat detection and simple to verify, thereby reducing infrastructure complexity while maintaining measurement precision.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If organizations collaborate on threat intelligence sharing, then the quantity of shared security information increases, but the lack of a common language and standardized formats creates barriers to effective collaboration

Engineering Contradiction:
Improveshared security informationVSAvoidcollaboration compatibility
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal cryptographic framework that can handle multiple types of threat intelligence data from different organizations with diverse formats and languages. The trusted execution environment and standardized proof-generation mechanisms provide a multi-functional platform that adapts to various data sources while maintaining consistent verification processes, thereby increasing shared information quantity while improving collaboration compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If more information is shared about device attributes for better threat analytics, then the quality of threat intelligence analysis is improved, but the loss of device anonymity and privacy increases

Engineering Contradiction:
Improvethreat intelligence analysis qualityVSAvoiddevice anonymity
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The trusted execution environment serves as an intermediary that enables threat analytics while protecting device anonymity. The TEE allows devices to contribute threat information and receive analytics insights without revealing their identity or detailed attributes. The intermediary verifies and processes information while maintaining a barrier that preserves device privacy, thus improving analysis quality without sacrificing anonymity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces direct information exchange mechanisms with cryptographic attribution systems. Instead of sharing identifiable device attributes, the system uses anonymous cryptographic identifiers and zero-knowledge proofs that allow verification of threat conditions without exposing device identity. This substitution enables high-quality threat intelligence analysis while maintaining device anonymity through cryptographic rather than mechanical information sharing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10440046B2Technologies for anonymous context attestation and threat analytics
Publication Date: 2019.10.08 INTEL CORP
  • US10440046B2 patent drawing
  • US10440046B2 patent drawing
  • US10440046B2 patent drawing

AI summary

Technologies for anonymous context attestation and threat analytics include a computing device to receive sensor data generated by one or more sensors of the computing device and generate an attestation quote based on the sensor data. The attestation quote includes obfuscated attributes of the computing device based on the sensor data. The computing device transmits zero knowledge commitment of the attestation quote to a server and receives a challenge from the server in response to transmitting the zero knowledge commitment. The challenge requests an indication regarding whether the obfuscated attributes of the computing device have commonality with attributes identified in a challenge profile received with the challenge. The computing device generates a zero knowledge proof that the obfuscated attributes of the computing device have commonality with the attributes identified in the challenge profile.