Dynamic Privacy Management for Ring Signature Subgroups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved privacy management in ring signatures and similar cryptographic constructs to balance the privacy goals of clients and servers in communication systems, as existing technologies struggle to implement diverse privacy policies efficiently while preserving anonymity.

Innovation Solution

The system dynamically manages privacy by mapping clients into subgroups of bounded size, allowing clients and servers to control the selection of the subgroup for ring signature generation, using a variable privacy parameter to adjust the subgroup size and manage privacy leakage, enabling flexible privacy policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the subgroup size is increased to provide higher privacy protection, then the difficulty of determining which client produced the signature increases, but the ability to perform analytics and correlation decreases

Engineering Contradiction:
Improveprivacy protection levelVSAvoidanalytics capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamic privacy management where the subgroup size parameter u can be adjusted over time based on policy requirements. The system can switch between different privacy levels by changing the subgroup size, allowing optimization between privacy protection and analytics capability depending on current needs. This is achieved through the dynamic selection of subgroup sizes for ring signature generation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses parameter changes by varying the subgroup size parameter u to control the balance between privacy and analytics. By changing this parameter, the system can enforce different privacy policies - larger u values provide higher privacy while smaller u values enable better analytics. This parameter adjustment mechanism allows flexible adaptation to different operational requirements.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If the subgroup size is decreased to improve analytics capability, then the ability to perform correlation improves, but the privacy protection level decreases

Engineering Contradiction:
Improveanalytics capabilityVSAvoidprivacy protection level
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system dynamically adjusts subgroup sizes based on policy requirements, allowing it to switch between analytics-optimized modes (smaller subgroups) and privacy-optimized modes (larger subgroups). This dynamic capability enables the system to respond to changing operational needs without compromising either privacy or analytics capability permanently.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

By changing the subgroup size parameter u, the system can optimize for analytics capability when needed. Smaller subgroup sizes make it easier to perform correlation and analytics while still providing some privacy protection through the ring signature mechanism. This parameter adjustment allows flexible trade-off management.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If fixed subgroup sizes are used, then the implementation is simpler, but the ability to enforce diverse privacy policies is limited

Engineering Contradiction:
Improveimplementation complexityVSAvoidprivacy policy flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic privacy management where the subgroup size parameter can be adjusted based on policy requirements. This allows the system to enforce diverse privacy policies by changing subgroup sizes dynamically, providing both simplicity of implementation and flexibility in policy enforcement through a unified dynamic framework.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses parameter changes to achieve policy flexibility. By varying the subgroup size parameter u, the system can enforce different privacy policies without requiring complex separate implementations for each policy type. This parameter-based approach provides versatility while maintaining implementation simplicity.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If variable subgroup sizes are used to enforce diverse privacy policies, then policy flexibility increases, but the computational overhead and complexity increases

Engineering Contradiction:
Improveprivacy policy flexibilityVSAvoidcomputational overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the client population into subgroups of varying sizes based on privacy policy requirements. This segmentation approach allows diverse privacy policies to be enforced by organizing clients into appropriate subgroup structures, providing policy flexibility while managing computational complexity through structured organization rather than exhaustive processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system manages computational overhead through parameter changes by efficiently adjusting the subgroup size parameter u. This allows the system to enforce diverse privacy policies with controlled computational cost, as the parameter adjustment provides a straightforward mechanism for policy enforcement without requiring complex computational procedures for each policy change.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9660813B1Dynamic privacy management for communications of clients in privacy-preserving groups
Publication Date: 2017.05.23 EMC IP HLDG CO LLC
  • US9660813B1 patent drawing
  • US9660813B1 patent drawing
  • US9660813B1 patent drawing

AI summary

A server is configured to communicate with a group of clients over a network in one embodiment. The server maps the group of clients into a plurality of subgroups of bounded size, communicates to a given one of the clients information identifying the particular subgroup to which that client belongs as well as the other clients in that subgroup. The given client utilizes the communicated information to generate a ring signature over the corresponding subgroup of clients based on the communicated information. The subgroup size may be bounded to a minimum size and a maximum size in accordance with a variable privacy parameter. The server can increase or decrease the value of the parameter in order to provide respective increased or decreased privacy to the clients, by making it respectively more or less difficult to determine which client in a corresponding one of the subgroups produced the received ring signature.