Hierarchical IoT Data Aggregation for Anonymity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The aggregation of IoT data from anonymous networked devices poses challenges in protecting device anonymity, as aggregating data from small groups of devices risks exposing their identities, while ensuring data privacy and security thresholds are maintained.

Innovation Solution

A hierarchical network system is implemented, where anonymous authentication credentials are provided to IoT devices, using Zero Knowledge Proof cryptography and a data aggregation framework that allows devices to register and report data only when the number of reporting devices meets or exceeds a security threshold, ensuring anonymity and secure data aggregation across multiple levels of the network hierarchy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is aggregated from a small number of devices, then data aggregation efficiency is improved, but device anonymity is compromised

Engineering Contradiction:
Improvedata aggregation efficiencyVSAvoiddevice anonymity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the data aggregation process into multiple hierarchical levels (edge aggregators, regional aggregators, central aggregators). Data is aggregated incrementally at each level, ensuring that at no point does a small group of devices aggregate to a single analyzer, thus maintaining anonymity while enabling efficient aggregation through distributed processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension to data aggregation by implementing staged aggregation over time. Data from multiple devices is collected and held in buffers at intermediate aggregators before being forwarded upstream, ensuring that aggregation thresholds are met before analysis occurs, thereby protecting device identities while maintaining aggregation efficiency.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If anonymous credentials are used for device authentication, then device privacy is protected, but system security management becomes more complex

Engineering Contradiction:
Improvedevice privacyVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces credential authorities as intermediary entities that issue and manage anonymous credentials for devices. These authorities operate at different hierarchical levels and use public key infrastructure with zero-knowledge proofs to verify device credentials without exposing device identities, thus maintaining privacy while simplifying security management through centralized credential issuance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces traditional mechanical authentication systems (which rely on identifiable device credentials) with cryptographic authentication based on public key infrastructure and zero-knowledge proofs. This substitution allows devices to prove their legitimacy without revealing their identities, protecting privacy while enabling robust security verification through mathematical proofs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If data aggregation thresholds are enforced to protect anonymity, then device identity protection is improved, but data aggregation speed decreases

Engineering Contradiction:
Improvedevice identity protectionVSAvoiddata aggregation speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements dynamic data aggregation where aggregation thresholds and forwarding decisions are adjusted based on real-time conditions. Intermediate aggregators buffer data temporarily and forward it upstream when thresholds are not met, but can forward aggregated data downstream when thresholds are exceeded, dynamically optimizing both anonymity protection and aggregation speed based on current data volumes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where aggregators monitor the number of devices contributing data and adjust their aggregation behavior accordingly. When feedback indicates that sufficient devices are contributing, aggregators can proceed with upstream forwarding; when feedback shows insufficient contributions, aggregators retain data in buffers, thus dynamically balancing anonymity protection with aggregation efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11265305B2Managing anonymous network connections
Publication Date: 2022.03.01 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11265305B2 patent drawing
  • US11265305B2 patent drawing
  • US11265305B2 patent drawing

AI summary

Managing anonymous network connections. In one aspect managing anonymous network connections by providing anonymous authentication credentials to a plurality of devices in a hierarchical network, registering a first set of devices at a first data aggregator, determining that the first set of devices at the first aggregator numbers less than a first threshold value, registering the first set of devices with a second aggregator upstream in the hierarchy from the first aggregator, causing data from the first set of devices to be received at the second aggregator.