Privacy-Preserving Threat Mitigation via Encrypted Data Similarity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in sharing security data to enhance threat prediction and mitigation due to inefficiencies in determining the expected benefits of collaboration, which limits their ability to effectively partner and share information.

Innovation Solution

A system that receives encrypted data sets from organizations, performs privacy-preserving operations such as private set intersection, and computes similarity values to determine the expected benefits of collaboration, facilitating the selection of preferred partners while maintaining data confidentiality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If companies share security data to enhance threat prediction, then the accuracy of security intelligence and analytics mitigation techniques is improved, but the efficiency of determining expected benefits of collaboration deteriorates due to computational requirements

Engineering Contradiction:
Improveaccuracy of security intelligenceVSAvoidefficiency of determining collaboration benefits
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

A centralized server acts as an intermediary to compute similarity values between companies' security data sets. The server receives encrypted data sets from multiple companies, performs private set intersection computations to determine collaboration benefits, and returns similarity values without requiring companies to perform computationally intensive comparisons themselves. This resolves the contradiction by centralizing the computation to improve overall efficiency while maintaining accurate security intelligence analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical data sharing and comparison processes with cryptographic techniques. Companies encrypt their security data sets before sharing them with the centralized server. The server performs computations on encrypted data using cryptographic protocols that enable similarity calculation without decrypting the underlying data, thus maintaining security while improving computational efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If companies perform separate computations to determine expected benefits of collaboration, then the accuracy of partner selection is improved, but the computational resources required increase significantly

Engineering Contradiction:
Improveaccuracy of partner selectionVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent merges the computation of similarity values into a single centralized process performed by the server. Instead of each company independently performing computationally intensive comparisons against all other companies (which would require O(n²) computations), the server performs a single private set intersection computation that efficiently determines collaboration benefits for all company pairs simultaneously. This merging approach maintains accurate partner selection while dramatically reducing total computational resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9477839B2Methods for centralized privacy-preserving collaborative threat mitigation
Publication Date: 2016.10.25 XEROX CORP
  • US9477839B2 patent drawing
  • US9477839B2 patent drawing
  • US9477839B2 patent drawing

AI summary

One embodiment of the present invention provides a system to facilitate collaboration for mitigating network threats. During operation, the system receives encrypted data sets from a plurality of entities. The data sets including data describing threats to network security. The system performs privacy-preserving operations on the encrypted data sets, such as private set intersection. The system then computes one or more metrics based on results of the private set intersection computations. The system may generate a similarity matrix based on the one or more metrics, and returns one or more similarity values from the similarity matrix to one or more entities of the plurality of entities.