Bidirectional Data Obfuscation for Network Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network providers face challenges in sharing raw data outputs from network devices due to data sovereignty concerns, which can lead to skewed or invalid analysis results. Additionally, large support datasets generated by network devices are costly to transmit, store, and process.

Innovation Solution

A method involving bidirectional data obfuscation and atomization within a network runtime environment, where data objects are obfuscated to produce obfuscated data objects that are related but not identifiable. Individual requests are sent to a target device for second values of the obfuscated data objects, and the responses are used to evaluate logic without de-obfuscating the values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If raw data outputs are shared from network devices to analysis teams, then data analysis can be performed, but data sovereignty concerns are violated and sensitive information is exposed

Engineering Contradiction:
Improvedata analysis validityVSAvoiddata sovereignty violation
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an obfuscation layer as an intermediary between the network device data and the analysis team. This intermediary transforms raw data into obfuscated data that preserves analytical value while removing sensitive information, thus mediating between data sharing needs and data sovereignty requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates obfuscated copies of the original data that can be shared with analysis teams. These copies contain transformed data that maintains analytical utility while eliminating sensitive identifiers and proprietary information, allowing analysis without direct exposure of raw data

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If data is obfuscated to protect sovereignty, then sensitive information is protected, but analysis results may become skewed or invalid

Engineering Contradiction:
Improvedata sovereignty protectionVSAvoidanalysis validity
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The obfuscation process applies different transformation techniques to different parts of the data based on their sensitivity and analytical importance. Critical analytical features are preserved while sensitive identifiers are removed or transformed, creating locally optimized data quality for both protection and analysis purposes

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent transforms data parameters through obfuscation techniques such as generalization, aggregation, and perturbation. These parameter changes maintain the statistical and relational properties needed for valid analysis while removing identifiable sensitive information

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If large support datasets are transmitted for diagnostic analysis, then comprehensive analysis can be performed, but transmission and storage costs increase significantly

Engineering Contradiction:
Improvediagnostic analysis completenessVSAvoidtransmission and storage cost
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The patent extracts only the essential diagnostic information needed for analysis while leaving out redundant or less critical data. This extraction process reduces the overall data volume that needs to be transmitted and stored, lowering costs while maintaining analysis completeness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent divides large datasets into smaller, manageable segments or atomic units that can be processed independently. This segmentation allows for selective transmission of only necessary data portions, reducing overall transmission and storage requirements while preserving diagnostic capability

Inventive Principle:
Principle #1Segmentation

4Productivity

If intellectual capital logic is distributed to network devices, then analysis capability is improved, but exposure to third parties increases competitive risk

Engineering Contradiction:
Improveanalysis capabilityVSAvoidcompetitive advantage exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary obfuscation and data transformation before distributing analysis logic to network devices. This preliminary action ensures that even if third parties access the distributed logic, they encounter only obfuscated data that cannot be reverse-engineered to reveal proprietary intellectual capital

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The obfuscation layer serves as a protective intermediary between the intellectual capital logic and potential third-party exposure. It allows the logic to be distributed for improved analysis capability while the intermediary prevents direct exposure of sensitive proprietary elements

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250039154A1Bidirectional data obfuscation and atomization within unsecured fragmented runtime environments
Publication Date: 2025.01.30 CISCO TECHNOLOGY INC
  • US20250039154A1 patent drawing
  • US20250039154A1 patent drawing
  • US20250039154A1 patent drawing

AI summary

A method performed at an analysis server, comprising: identifying data objects used by logic configured to produce alternative outcomes depending on first values of the data objects; obfuscating the data objects to produce obfuscated data objects that are related to, but do not identify, the data objects; sending, to a target device, individual requests for second values of the obfuscated data objects; receiving, from the target device, individual responses to the individual requests, wherein the individual responses include obfuscated second values that are related to but do not identify the second values; and evaluating the logic using the obfuscated second values in place of the first values, and without de-obfuscating the obfuscated second values, to produce one of the alternative outcomes.