Private Data Aggregation Framework for Untrusted Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to data privacy in crowdsourcing applications are inadequate, as they fail to effectively protect sensitive user data when shared with untrusted servers, leading to privacy concerns that hinder the wider acceptance of such services.

Innovation Solution

A private data aggregation framework that includes a private data aggregation engine with modules for user-defined privacy specifications, perturbation guidance, and encryption, allowing users to specify safe zones and precision parameters to randomize data before transmission, ensuring that only aggregated statistics are shared without revealing individual user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user data is shared with untrusted servers for data aggregation, then service functionality is improved, but user privacy is compromised

Engineering Contradiction:
Improveservice functionalityVSAvoiduser privacy
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by adding randomized noise to user data before transmission to the server. This preprocessing step ensures that privacy protection is built into the data before it leaves the user's device, allowing the server to process aggregated statistics without accessing raw personal information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Randomized noise acts as an intermediary between the user's personal data and the aggregation server. This mediator transforms the data into a form that preserves statistical utility for service functionality while preventing the server from recovering individual user information, thus protecting privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If data is sanitized before leaving user device, then privacy protection is improved, but data utility for aggregation is reduced

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata utility
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system changes the parameters of data sanitization by using randomized noise addition with carefully controlled distribution and magnitude. This parameter adjustment allows the data to retain sufficient statistical properties for useful aggregation while providing strong privacy protection through the randomized transformation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10956603B2Private dataaggregation framework for untrusted servers
Publication Date: 2021.03.23 SAMSUNG ELECTRONICS CO LTD
  • US10956603B2 patent drawing
  • US10956603B2 patent drawing
  • US10956603B2 patent drawing

AI summary

A first device specifies a privacy specification. The privacy specification includes at least a safe zone and a precision parameter may also be specified. A second device, such as an untrusted server, uses the privacy specification to provide guidance to the first device on how to perturb sensitive data. The first device then uses the guidance to transform sensitive data and provides it to the second device. The data transformation permits the first device to share sensitive data in a manner that preserves the privacy of the first user but permits statistics on aggregated data to be generated by an untrusted server.