Global Aggregated Security Search with Client Anonymity Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managed Security Service Providers (MSSPs) face challenges in allowing clients to securely access and query aggregated security data while maintaining client anonymity and adhering to privacy requirements, as existing systems do not effectively enable global searches or protect against unintended data leakage.

Innovation Solution

The system enables global searching of aggregated security data across a client base with configurable client anonymity settings, allowing clients to set an anonymity tolerance and filter out identifiable data points to prevent client identification, while authorizing authorized entities to access and process the data securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MSSPs aggregate security data from multiple clients to enable global threat detection, then threat detection capability is improved, but client anonymity and privacy protection deteriorate

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidclient anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments security data into multiple dimensions including threat-related features (for analysis) and anonymity-preserving transformations (for privacy). By dividing the data representation into searchable threat indicators and protected client identifiers, the system enables threat detection while maintaining client anonymity through selective data segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary anonymization layer that transforms client security data before aggregation. This intermediary process uses techniques such as k-anonymity and differential privacy to mediate between raw client data and aggregated threat intelligence, allowing threat detection without direct client identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If clients share security data to participate in threat intelligence communities, then collective security improvement is enhanced, but risk of data leakage and client identification increases

Engineering Contradiction:
Improvecollective security improvementVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anonymization actions to client data before it is shared in threat intelligence communities. By pre-processing data with anonymity-preserving transformations and applying privacy-by-design principles upfront, the system enables productive data sharing while preventing future data leakage risks through advance protective measures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes data parameters through anonymization transformations, converting identifiable client information into anonymized representations. By modifying data parameters such as removing direct identifiers, aggregating sensitive attributes, and applying noise transformations, the system enables collective security improvement while reducing data leakage risk through parameter transformation.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If strict privacy controls are implemented to protect client anonymity, then client privacy protection is improved, but ability to conduct global aggregated searches deteriorates

Engineering Contradiction:
Improveclient privacy protectionVSAvoidglobal search capability
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent implements dynamic privacy controls that adjust anonymity parameters based on search context and client preferences. By making privacy controls dynamic rather than static, the system can adapt the level of anonymity protection to specific search scenarios, enabling global aggregated searches while maintaining appropriate privacy protection through flexible, context-aware parameter adjustment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal search framework that handles both anonymized and non-anonymized data through a unified interface. By designing multi-functional search capabilities that work across different anonymity levels and data types, the system maintains ease of operation for global searches while preserving client privacy through consistent anonymization handling across diverse search scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11003718B2Systems and methods for enabling a global aggregated search, while allowing configurable client anonymity
Publication Date: 2021.05.11 SOPHOS INC
  • US11003718B2 patent drawing
  • US11003718B2 patent drawing
  • US11003718B2 patent drawing

AI summary

A system can enable a global search of security data of a client base. The system can include a processor operable to record anonymity values set by clients of the client base, and to receive search requests including one or more search parameters from the clients. Upon receipt of a search request, processor can generate a result set for the received search request and determine an aggregated anonymity value for the result set. The processor further may compare the aggregated anonymity value of the results set with a set anonymity value for each of the clients for filtering or removing the data points or information of the one or more clients with the set anonymity value that is greater than the aggregate anonymity value from the result set.