Edge TEE Personal Data Encryption for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Video surveillance systems struggle to handle detected anomalies effectively, as they lack the capability to identify individuals and decide on alert generation based on their identity, posing privacy and security concerns due to central management of personal data.
Innovation Solution
A data privacy system comprising a local computer system with a trusted execution environment (TEE) for anomaly detection and encryption of personal data, which securely transmits encrypted data to a backend system for comparison with stored data, enabling secure and privacy-compliant alert generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If personal data is centrally managed for anomaly analysis, then system control and processing capability are improved, but privacy security and compliance with regulations deteriorate
Solution Approach 1:
The patent divides the centralized system into distributed edge devices that perform local anomaly detection and data processing. Each edge device independently processes images and extracts personal data locally, eliminating the need to centralize sensitive personal data while maintaining effective anomaly monitoring across the network.
Solution Approach 2:
The patent introduces encrypted data as an intermediary form between raw personal data and processed anomaly information. Personal data is extracted and encrypted at the edge device, then transmitted to the central server only in encrypted form, serving as a mediator that enables centralized analysis while protecting privacy through cryptographic transformation.
2Measurement precision
If personal data is extracted and transmitted for analysis, then anomaly detection accuracy is improved, but data transmission security and storage safety deteriorate
Solution Approach 1:
The patent applies encryption to personal data immediately upon extraction at the edge device, before any transmission or storage operations. This preliminary cryptographic protection ensures that data remains secure throughout its lifecycle, eliminating the need for separate security measures during transmission and storage phases.
3Reliability
If encrypted data is transmitted to backend system, then privacy protection is improved, but processing time and computational overhead increase
Solution Approach 1:
The patent segments the processing workflow into two distinct phases: local encryption at the edge device and decryption-only operations at the central server. This segmentation allows computationally intensive encryption to occur locally where data is generated, while the central server performs only lightweight decryption and comparison operations, minimizing overall processing time.
Solution Approach 2:
The patent performs encryption as a preliminary action at the edge device before data transmission. By completing the computationally intensive encryption operation locally and beforehand, the system avoids time-consuming encryption operations at the central server, reducing overall processing latency while maintaining security.
Data Source
AI summary
Methods and systems for securely managing personal data associated with image processing include an image sensor configured to capture an image, a local computer system local to the image sensor, and a backend computer system remote from the image sensor. The local computer system has a processor with a trusted execution environment (TEE) that detects anomalies in images from the image sensor, extracts personal data from the image, and encrypts the personal data. The local computer system then sends the extracted, encrypted personal data to the backend computer system, where a backend TEE decrypts the extracted, encrypted personal data, and performs data processing by comparing the decrypted personal data to other personal data that is stored in a backend database in the backend computer system.


