Blockchain-Based Cyber Threat Information Sharing Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in sharing cyber-threat information due to trust issues, interoperability, automation, safeguarding sensitive information, and protecting classified data, which hinders effective threat detection and mitigation strategies.

Innovation Solution

A distributed, trusted, and anonymized Cyber Threat Information sharing platform based on blockchain technology, utilizing smart contracts to manage and control information sharing coalitions, ensuring that only organizations meeting predefined policies can access and consume shared data, with access permissions logged on a blockchain ledger.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations share cyber-threat information through traditional centralized platforms, then information exchange can occur, but trust issues and security risks arise due to centralized control and potential data breaches

Engineering Contradiction:
Improvetrust in information sharingVSAvoidcentralized control structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized information sharing platform into a distributed blockchain network where multiple independent nodes organize information sharing autonomously. Each organization operates as an independent node with equal rights, eliminating the need for a single centralized controller and thereby reducing trust issues while maintaining system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces smart contracts as intermediary components that automatically enforce sharing policies, access controls, and data protection rules. These self-executing contracts act as mediators between organizations, ensuring trustworthy information exchange without requiring direct trust relationships between participating parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If organizations implement strict access controls and anonymization to protect sensitive information, then data security is improved, but information interoperability and automation are hindered

Engineering Contradiction:
Improvedata securityVSAvoidinformation interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms sensitive identifying parameters into anonymized pseudonyms while maintaining the functional integrity of threat intelligence data. By changing the parameter representation (from real identities to blockchain addresses) rather than the data content itself, the system achieves both security through anonymization and interoperability through standardized data formats.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal blockchain-based access control framework that can handle multiple types of sensitive information (threat intelligence, vulnerability data, security policies) through a single standardized interface. This multi-functional approach enables different organizations with varying security requirements to interoperate seamlessly while maintaining their own access control policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Extent of automation

If traditional centralized systems are used for threat information sharing, then automation can be implemented, but trust and security issues arise from centralized control

Engineering Contradiction:
Improveautomated information sharingVSAvoidtrust in centralized system
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent implements self-service automation through smart contracts that automatically execute information sharing, access control, and policy enforcement without human intervention or centralized coordination. The blockchain network and smart contracts autonomously manage the entire information exchange process, eliminating trust issues associated with centralized automation while maintaining high levels of automation.

Inventive Principle:
Principle #25Self-service

4Loss of information

If organizations share classified and sensitive information, then collective threat understanding is improved, but protection of classified information becomes more difficult

Engineering Contradiction:
Improvecollective threat knowledgeVSAvoidrisk to classified information
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent adds the dimension of blockchain-based cryptographic verification and anonymization to traditional information sharing. By moving from a two-dimensional model (sender-receiver) to a multi-dimensional model that includes blockchain addresses, smart contract policies, and cryptographic proofs, the system enables sharing of sensitive information while maintaining protection through multiple layers of security in different dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11546366B2Threat information sharing based on blockchain
Publication Date: 2023.01.03 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11546366B2 patent drawing
  • US11546366B2 patent drawing
  • US11546366B2 patent drawing

AI summary

Systems and methods provide a platform for threat information sharing. A method comprises transmitting an access permission request to a blockchain network. The request asks for access to cyber threat information stored in at least one cyber threat information storage system. The information may come from a plurality of organizations. The blockchain network may include a blockchain ledger storing access control information from the plurality of organizations. Upon receipt of a reference to an access permission token generated by the blockchain network using at least one smart contract, a transaction request to the cyber threat information server may be sent. In response to the transaction request including the reference to the access permission token, the requested cyber threat information may be retrieved from the cyber threat information server.