Anonymous Identifier Security Information Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security information sharing systems among security management domains face challenges in protecting personal privacy, as real name identifiers can leak during information sharing, making it difficult to analyze meaningful security information.

Innovation Solution

A security information sharing system that employs an identifier conversion unit to convert real name identifiers into anonymous identifiers using a one-way hash function, ensuring personal information is not leaked, and includes a mapping information storage unit to facilitate secure analysis and transmission of anonymous identifier-based security information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If real name identifiers are shared in security information, then security analysis accuracy is improved, but personal privacy protection deteriorates

Engineering Contradiction:
Improvesecurity analysis accuracyVSAvoidpersonal privacy leakage
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an anonymous identifier as an intermediary element that replaces real name identifiers in security information sharing. This mediator allows security domains to analyze security events and correlate threats without directly exposing personal identifiable information, thus resolving the contradiction between analysis accuracy and privacy protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts and removes the personally identifiable portion (real name identifier) from the security information while retaining the essential security analysis capabilities through anonymous identifiers. This extraction allows security sharing to proceed without the harmful personal information component

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If anonymous identifiers are used to protect privacy, then personal information security is improved, but security information analysis capability deteriorates

Engineering Contradiction:
Improvepersonal information securityVSAvoidsecurity information analysis capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the parameter of the identifier from a personally identifiable format to an anonymous format that retains structural properties useful for security analysis. The anonymous identifier maintains consistency across different security domains, enabling correlation and pattern recognition while protecting personal information

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If real name identifiers are transmitted across security domains, then security information sharing completeness is improved, but information security risk increases

Engineering Contradiction:
Improvesecurity information sharing completenessVSAvoidinformation security risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The anonymous identifier serves as a mediator that enables complete security information sharing across domains without transmitting actual personal identifiers. This allows security events, attack patterns, and threat intelligence to be shared comprehensively while the intermediary anonymous identifier prevents direct exposure of personal information

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8789200B2Agent apparatus and method for sharing anonymous identifier-based security information among security management domains
Publication Date: 2014.07.22 ELECTRONICS & TELECOMM RES INST
  • US8789200B2 patent drawing
  • US8789200B2 patent drawing
  • US8789200B2 patent drawing

AI summary

The present invention relates to an agent apparatus and method for sharing anonymous identifier-based security information among security management domains. A plurality of security information sharing agent apparatuses respectively located in a plurality of security management domains and configured to collect security information and transmit collected security information to outside of the security management domains. Each security information sharing agent apparatus includes an identifier conversion unit for converting real name identifier-based security information into anonymous identifier-based security information by converting a real name identifier included in the security information into an anonymous identifier, and a security information communication unit for transmitting the anonymous identifier-based security information obtained by the identifier conversion unit to outside of a corresponding security management domain so that security information is shared among the plurality of security management domains.