Privacy-Preserving Configuration Aggregation for Peer Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of software applications with numerous configuration parameters makes it time-consuming for users to troubleshoot undesired behavior, often requiring technical support and raising privacy and integrity issues when retrieving configuration information from other systems.

Innovation Solution

A method and system for aggregating configuration information from friend devices in a way that protects privacy by dividing contributions into shares, making it difficult for attackers to determine individual device contributions, and determining the cardinality of configuration parameters using hash values to support the number of possible values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If configuration information is collected from multiple computer systems to identify faulty parameters, then troubleshooting efficiency is improved, but privacy and integrity issues worsen due to exposure of sensitive configuration data

Engineering Contradiction:
Improvetroubleshooting efficiencyVSAvoidprivacy and integrity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments configuration values into discrete bins based on hash values, allowing aggregation of frequency information without exposing actual configuration values. This segmentation enables troubleshooting through pattern recognition while protecting privacy by never transmitting or storing the actual sensitive configuration data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hash values as an intermediary representation of configuration data. Instead of directly sharing sensitive configuration values, systems share hashed representations that preserve statistical information for troubleshooting while eliminating the ability to reconstruct original values, thus mediating between troubleshooting needs and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If all configuration parameter values are reviewed to identify faults, then troubleshooting accuracy is improved, but time consumption worsens due to the large number of parameters

Engineering Contradiction:
Improvetroubleshooting accuracyVSAvoidtroubleshooting time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary aggregation of configuration data from multiple systems before analysis. By pre-collecting and binning configuration values into frequency distributions across the peer group, the system prepares troubleshooting information in advance, allowing rapid identification of outliers without reviewing individual parameters during the actual troubleshooting event.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates simplified copies of configuration data in the form of binned frequency distributions. Instead of analyzing actual configuration values, the system works with copied statistical representations that retain the essential information needed for comparison and fault identification while being much more efficient to process.

Inventive Principle:
Principle #26Copying

3Measurement precision

If configuration data from friend devices is aggregated, then identification of at-fault parameters is improved, but security risks worsen due to potential attacks on individual device contributions

Engineering Contradiction:
Improveparameter identification accuracyVSAvoidsecurity attack surface
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent segments individual device contributions into hash-based bins, making it impossible to trace aggregated statistics back to individual devices. This segmentation approach ensures that even if an attacker compromises one device, they cannot isolate or manipulate their own contribution in the aggregate, as it is indistinguishable from other devices with similar configuration hash values.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses hash values as an intermediary layer between individual device configurations and the aggregated analysis. This intermediary transformation ensures that no device can directly influence or be identified in the aggregation process, protecting against attacks where an adversary might try to manipulate their contribution or trace the source of aggregated data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7743123B2Aggregating information from a cluster of peers
Publication Date: 2010.06.22 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7743123B2 patent drawing
  • US7743123B2 patent drawing
  • US7743123B2 patent drawing

AI summary

A method and system for aggregating configuration information from friend devices is provided. The aggregation system attempts to foil attacks on the privacy of data contributed to a request by aggregating data from a cluster of friend devices in such a way that it is difficult for a device in the cluster and an attacking device outside the cluster to determine the contribution of an individual device to the data. The aggregation system of an initiator device may also determine the cardinality of a parameter so that the corresponding parameter vector can have a size large enough to support the number of possible values. The aggregation system determines the cardinality by counting nonzero hash values of the actual values that are provided by the devices.