Pseudonymization Node for Privacy-Preserving Network Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communications networks utilizing software containers and microservices, monitoring network performance is challenging due to the large number of containers, and existing application performance monitoring tools often require sharing sensitive information over public networks, violating data protection regulations.

Innovation Solution

A method where a first node in a communications network receives trace data, replaces sensitive attributes with pseudonymized attributes, and sends the pseudonymized data to a monitoring node for analysis, then replaces pseudonymized attributes back to original or less identifying attributes for network monitoring information, minimizing sensitive information sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application performance monitoring tools are used to monitor network performance, then network monitoring capability is improved, but sensitive information sharing over public networks occurs violating data protection regulations

Engineering Contradiction:
Improvenetwork monitoring capabilityVSAvoidsensitive information sharing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data processing node as an intermediary between the network function and the APM tool. This intermediary performs pseudonymization of sensitive attributes in trace data before transmission to the APM tool, and performs attribute mapping when receiving monitoring information back. The intermediary thus enables monitoring capability while preventing direct sharing of sensitive information over public networks, resolving the contradiction between monitoring reliability and data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If trace data with sensitive attributes is shared with APM provider, then network monitoring is enabled, but data protection regulations are violated

Engineering Contradiction:
Improvenetwork monitoring efficiencyVSAvoidsensitive information exposure
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies parameter changes by transforming the attributes in the trace data through pseudonymization. Sensitive attributes (such as user identity, location, subscriber number) are replaced with pseudonyms that maintain the structural and relational properties needed for monitoring while eliminating direct identification of sensitive information. This attribute transformation enables efficient network monitoring productivity while preventing sensitive information exposure to external APM providers.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If attributes are replaced with pseudonyms, then sensitive information sharing is reduced, but network monitoring accuracy may be compromised

Engineering Contradiction:
Improvesensitive information sharingVSAvoidnetwork monitoring accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent implements a feedback mechanism where the APM tool returns network monitoring information containing the pseudonymized attributes, and the data processing node performs attribute mapping to translate these back to the original attribute values or less identifying attributes. This feedback loop preserves the accuracy needed for monitoring by maintaining the ability to identify and correlate network performance issues, while still reducing sensitive information sharing during the initial data transmission phase.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11888721B2Network monitoring
Publication Date: 2024.01.30 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11888721B2 patent drawing
  • US11888721B2 patent drawing
  • US11888721B2 patent drawing

AI summary

In one aspect, a method performed by a first node in a first communications network is provided. The method includes receiving first trace data for the first communications network, in which the first trace data comprises one or more first attributes. The method further includes replacing the one or more first attributes in the first trace data with corresponding second attributes to provide second trace data, sending the second trace data to a second node for performing network monitoring and receiving, from the second node, first network monitoring information for the first communications network based on the second trace data, in which the first network monitoring information comprises the one or more second attributes. The method further includes replacing at least one of the second attributes in the first network monitoring information with corresponding third attributes, based on the first attributes, to provide second network monitoring information.