IoT Data Provenance via Secure Multiparty Computation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for authenticating collective data from multiple Internet of Things (IoT) devices are computationally expensive and not scalable, especially when individual devices are mutually distrusting and privacy of raw data needs to be maintained, leading to challenges in verifying data provenance without sharing sensitive information.

Innovation Solution

The described techniques provide a method for efficient secure multiparty computation by provisioning evaluation parameters to IoT devices, allowing them to verify the provenance of collectively generated data without sharing individual data, using group profiles and evaluation parameters to generate collective data provenance information and verification parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current authentication methods are used for collective data from multiple IoT devices, then data provenance verification is achieved, but computational complexity increases and scalability deteriorates

Engineering Contradiction:
Improvedata provenance verificationVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process by introducing intermediary components (hash functions, evaluation parameters, commitment values) that break down the complex verification task into manageable parts. Each device generates local commitments and proofs without needing to process all other devices' data directly, reducing individual computational burden while maintaining collective verification capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries (hash functions, commitment schemes, evaluation parameters) that mediate between raw device data and final verification. These intermediaries enable proof generation and verification without requiring direct access to or processing of sensitive raw data, reducing computational complexity while preserving provenance verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If current authentication methods are used for collective data from multiple IoT devices, then data provenance verification is achieved, but scalability deteriorates

Engineering Contradiction:
Improvedata provenance verificationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication process is segmented so that each device independently generates commitments and proofs based on its own data and shared evaluation parameters. This segmentation allows the system to scale linearly with the number of devices, as each device's computational workload remains constant regardless of total system size, unlike quadratic scaling in traditional mutual verification approaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each device performs self-service authentication by generating its own commitment values and proof elements locally using shared evaluation parameters. Devices verify their own contributions without burdening other devices or a central authority with excessive computational tasks, enabling scalable deployment across large IoT networks.

Inventive Principle:
Principle #25Self-service

3Reliability

If individual devices share raw data for collective authentication, then data provenance can be verified, but individual data privacy is compromised

Engineering Contradiction:
Improvedata provenance verificationVSAvoiddata privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the essential verification elements (commitment values, proof elements, hash outputs) from the raw device data, separating these from the sensitive original information. Devices share only these extracted verification artifacts rather than raw data, enabling provenance verification while preserving privacy through selective information disclosure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Cryptographic intermediaries (hash functions, commitment schemes, zero-knowledge proof structures) act as mediators between raw private data and public verification. These intermediaries transform sensitive data into verification-ready forms that reveal provenance information while mathematically guaranteeing that original data remains confidential and不可逆.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If devices are mutually distrusting, then security requirements increase, but authentication efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary actions by pre-distributing evaluation parameters and cryptographic credentials to devices before authentication occurs. This preliminary setup enables devices to independently generate valid proofs without real-time negotiation or mutual verification handshakes, maintaining high security for distrusting devices while significantly improving authentication efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each device performs self-service authentication using pre-configured evaluation parameters and its own data. Devices independently generate commitments, proofs, and verification elements without requiring interactive protocols with other devices or centralized coordination during the authentication moment, achieving both high security for distrusting parties and efficient non-interactive verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11516667B2Aggregate data provenance
Publication Date: 2022.11.29 QUALCOMM INC
  • US11516667B2 patent drawing
  • US11516667B2 patent drawing
  • US11516667B2 patent drawing

AI summary

Methods, systems, and devices for communications are described. A device or a group of devices may generate data. The group of devices may receive a group profile from a node that identifies the devices to be included, and the group profile may include a function to be evaluated at each of the devices. The node may also provision evaluation parameters which may allow the device to provide authenticated aggregate data to a requesting third party, without sharing the data between the devices and without sharing the data with the node, thus concurrently maintaining individual data privacy and data provenance.