Escrow Certificate Mechanism for Anonymous Telemetry Collection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities are reluctant to provide telemetry data due to concerns about disclosing sensitive information, leading to opt-out or non-participation, and existing methods fail to ensure anonymous yet traceable data collection.

Innovation Solution

An escrow mechanism that issues certificates or data identifying telemetry sources without revealing their identity, allowing verification of authenticity without disclosing source information, enabling anonymous and traceable telemetry data collection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If telemetry sources provide identifying information to ensure data authenticity, then data reliability is improved, but privacy protection deteriorates

Engineering Contradiction:
Improvedata authenticityVSAvoidprivacy disclosure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to telemetry sources. These certificates serve as trusted intermediaries that verify source authenticity without revealing actual identities. The CA acts as a mediator between the telemetry source and collector, enabling authentication while maintaining anonymity through the certificate-based trust chain.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses digital certificates as copies or representations of source identity. Instead of transmitting actual identifying information, the system transmits certificate objects that contain verified authentication information. These certificate copies allow verification of source legitimacy without exposing the actual source identity, separating the authentication function from the identification function.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If telemetry sources remain anonymous to protect sensitive information, then privacy protection is improved, but data reliability deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata authenticity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent segments the authentication information into separate components: the actual source identity remains hidden, while the certificate containing verification credentials is transmitted separately. This segmentation allows the system to verify authenticity through the certificate while the source identity remains anonymous. The authentication function is separated from the identification function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The digital certificate serves as an intermediary that enables authentication without direct identification. The certificate contains verified information about the source (such as a hash of the source identifier) that can be validated by the collector without revealing the actual source identity. This intermediary mechanism resolves the contradiction by providing trust without exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If identifying information is collected to verify source quality, then measurement precision is improved, but loss of information increases

Engineering Contradiction:
Improvesource quality verificationVSAvoidsource identity disclosure
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent creates a copy of the source identification information in the form of a digital certificate. This certificate contains a hash or representation of the source identifier that can be used for verification purposes. By working with this certificate copy rather than the actual source identity, the system achieves measurement precision for source quality verification while avoiding the loss or disclosure of sensitive identifying information.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2321779B1Collecting anonymous and traceable telemetry
Publication Date: 2019.11.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2321779B1 patent drawingFigure 1
  • EP2321779B1 patent drawingFigure 2
  • EP2321779B1 patent drawingFigure 3

AI summary

Aspects of the subject matter described herein relate to collecting anonymous and traceable telemetry. In aspects, a telemetry source may obtain a certificate or other data from an escrow certificate issuer. The certificate includes information usable by a certificate collector to verify that the certificate is valid, but does not include information usable to identify the telemetry source to the telemetry collector.