Anonymized Cloud Network Analytics Correlation via Watermarking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of on-premise network analytics data with cloud-based application analytics data to improve user experience in cloud-based communication sessions is challenging due to the risk of exposing personal identifying information, which is a concern for enterprise networks due to security and regulatory constraints.
Innovation Solution
A method is introduced where data packets from cloud-based communication sessions are watermarked, allowing on-premise network analytics and cloud-based application analytics to be correlated without exchanging personally identifiable information, using a network controller that receives and correlates the data using flow identifiers, enabling comprehensive analysis and troubleshooting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If on-premise network analytics data is integrated with cloud-based application analytics data, then comprehensive performance analysis and troubleshooting capability is improved, but user privacy security and enterprise data security are worsened due to exposure of personally identifiable information
Solution Approach 1:
The patent extracts and removes personally identifiable information (usernames, IP addresses, MAC addresses) from the analytics data before integration. Only anonymized data elements are exchanged between on-premise network analytics and cloud-based application analytics, allowing comprehensive performance analysis while eliminating privacy security risks.
Solution Approach 2:
The patent introduces an intermediary anonymization process that mediates between on-premise network analytics data and cloud-based application analytics data. This intermediary layer transforms identifiable information into anonymized form, enabling data integration for comprehensive analysis while protecting user privacy and enterprise security.
2Measurement precision
If personally identifiable information is shared between on-premise network and cloud application, then data correlation accuracy is improved, but enterprise security constraints and regulatory compliance are worsened
Solution Approach 1:
The patent extracts only the essential correlatable elements (anonymized identifiers) from personally identifiable information while removing sensitive data components. This extraction enables sufficient data correlation accuracy for troubleshooting while maintaining security compliance by eliminating PII from the exchange.
Solution Approach 2:
The patent transforms personally identifiable information parameters into anonymized parameters through systematic parameter changes. Usernames, IP addresses, and MAC addresses are converted into anonymized identifiers that maintain correlatability for accurate data matching while complying with enterprise security constraints and regulatory requirements.
3Productivity
If comprehensive analytics data integration is implemented, then troubleshooting effectiveness is improved, but data exchange complexity and system configuration difficulty are worsened
Solution Approach 1:
The patent implements self-service automation where the system automatically performs anonymization, data correlation, and integration without requiring complex manual configuration. The anonymization process and data matching occur automatically, simplifying the system while maintaining comprehensive troubleshooting effectiveness.
Solution Approach 2:
The patent performs preliminary anonymization of data before integration, preparing the data in advance for seamless correlation. By pre-processing the data to remove identifiable information and establish anonymized identifiers, the system reduces subsequent complexity in data exchange and integration while maintaining troubleshooting effectiveness.
Data Source
AI summary
The present disclosure provides a method of exchanging on-premise network analytics and cloud-based application analytics between an enterprise network and a cloud-based application without exchanging any personally identifiable information about the end users and devices involved in a communication session conducted over the enterprise network and using the cloud-based application. In one aspect, a method includes receiving, at a controller of a network, first analytics data, the first analytics data being embedded with a watermark, the first analytics data excluding personally identifiable information associated with end points of a communication session using a cloud-based application; receiving second analytics data from one or more components of the network, the second analytics data including the watermark; correlating the first analytics data and the second analytics data using the watermark to yield correlated data; and performing network analysis and troubleshooting using the correlated data.


