Private Inference Control via Homomorphic Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to effectively control inference channels and protect user privacy in online databases, as they either do not address indirect access to sensitive information or reveal query information to servers, leading to potential privacy breaches.

Innovation Solution

A system and method utilizing homomorphic encryption and pseudorandom functions to securely manage queries and key shares, ensuring that sensitive information is protected against both direct and indirect access attempts while maintaining user privacy by encrypting indices and attributes, and using secure function evaluation to prevent inference channel completion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If inference control is implemented by blocking queries, then unauthorized users cannot infer sensitive information, but the server cannot know what information is being retrieved

Engineering Contradiction:
Improveinference controlVSAvoidquery privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary cryptographic mechanism (homomorphic encryption and oblivious transfer) between the user and server. The server processes encrypted queries without decrypting them, acting as an intermediary that can filter inference channels while preserving user query privacy. This resolves the contradiction by enabling the server to block harmful inference patterns without learning the actual query content.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the query processing into multiple cryptographic layers: encrypted query submission, server-side inference control on encrypted data, and selective decryption only for authorized results. This segmentation allows inference control to operate independently on encrypted data, preventing both unauthorized inference and query exposure.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If queries are encrypted to protect user privacy, then the server cannot see query information, but inference control becomes more difficult to implement

Engineering Contradiction:
Improvequery privacyVSAvoidinference control mechanism
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent changes the parameter space by moving from plaintext query processing to encrypted query processing with homomorphic properties. This parameter change enables inference control to operate on ciphertexts directly, maintaining privacy while implementing control. The complexity is managed by selecting cryptographic parameters that balance security with computational efficiency.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all inference channels are blocked to prevent sensitive information compromise, then user privacy is protected, but legitimate information retrieval is hindered

Engineering Contradiction:
Improveprivacy protectionVSAvoidinformation retrieval
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies partial inference control by selectively blocking only those inference channels that lead to sensitive information compromise, rather than blocking all inference. The system identifies and permits legitimate inference paths while blocking harmful ones, achieving privacy protection without unnecessarily hindering information retrieval. This partial action resolves the contradiction by being sufficiently restrictive to protect privacy but not excessively so to maintain usability.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8229939B2Server-implemented system and method for providing private inference control
Publication Date: 2012.07.24 XEROX CORP
  • US8229939B2 patent drawing
  • US8229939B2 patent drawing
  • US8229939B2 patent drawing

AI summary

A server system maintains records and their associated attributes in a secure database. A plurality of queries generated by encrypting indices identifying a records and their associated attributes, by homomorphic encryption is received from a client system. A secret key is generated at a certain query count and is divided into randomly generated key shares. A key share sequence is homomorphically encrypted. A table is formed by encrypting the indices, secret key and attributes. Query responses, which each comprise the attributes for each of the records of the table of entries are provided. The key shares are decrypted sufficient to recover the secret key subject to a non-inference enabling query.