Multi-tenant Data Anonymization with Threshold Cryptography Forensics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security management systems in multi-tenant environments struggle to support authorized backtracking from anonymized data to specific devices or users for forensic analysis, especially in cases of malicious behavior, due to lack of proper privacy data processing and access control mechanisms.
Innovation Solution
Implementing a threshold cryptography-based key sharing mechanism that allows authorized entities to anonymize and store data, enabling authorized deanonymization and decryption of specific data instances for forensic investigation, while maintaining strict access control and compliance with GDPR regulations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If data is anonymized by the security solution to protect privacy, then privacy protection is improved, but the ability to backtrack to specific devices/users for forensics is lost
Solution Approach 1:
The key is divided into multiple key parts distributed among different trusted entities. The anonymization process uses these segmented key parts to encrypt data, allowing privacy protection while enabling authorized decryption through collaboration of multiple entities, thus resolving the contradiction between anonymization and forensics capability.
Solution Approach 2:
The security management entity acts as an intermediary that receives anonymized data from the connectivity platform and provides authorized decryption services to trusted entities. This intermediary role enables the system to maintain privacy through anonymization while providing controlled access to decrypted data for forensic investigations when authorized.
2Object-affected harmful factors
If existing anonymization approaches are used to minimize risk to individuals, then privacy protection is improved, but authorization control for accessing specific data is lost
Solution Approach 1:
The system dynamically manages access rights by allowing trusted entities to request and receive specific key parts based on authorization. The security management entity controls the distribution and usage of key parts, enabling dynamic authorization control that adapts to different access requests while maintaining privacy protection through the anonymization framework.
3Object-affected harmful factors
If data is stored in anonymized form to protect individuals, then privacy protection is improved, but the ability to investigate specific security events is hindered
Solution Approach 1:
The system performs preliminary anonymization of data during storage, protecting privacy in advance. When security events need investigation, the authorized decryption mechanism is activated to retrieve specific data, enabling both preliminary privacy protection and subsequent investigative capability through the key sharing and authorized decryption process.
Data Source
AI summary
According to some embodiments, a security management entity is provided. The security management entity includes processing circuitry configured to: generate a key having a plurality of key parts, anonymize at least a first data instance at least in part by using the key with threshold cryptography, transmit a respective key part to each one of the plurality of trusted entities, store at least one key part where the stored at least one key part is different from the transmitted respective key parts, receive a message from a first trusted entity of the plurality of trusted entities for investigating the anonymized first data instance where the message includes one of the transmitted respective key parts, and deanonymize the first data instance using the stored at least one key part and the one of the transmitted respective key parts associated with the first trusted entity.


