TEE-Based Data Anonymization for Multi-Tenant Privacy-Utility Balance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data anonymization tools are inflexible and one-size-fits-all, failing to accommodate varying privacy and utility requirements of different data owners and processors, leading to inefficient data sharing and potential privacy breaches.
Innovation Solution
A system and method for multi-entity data anonymization using Trusted Execution Environments (TEEs) that negotiate privacy and utility levels, allowing customized anonymization based on individual customer requirements and enabling secure data analysis across multiple entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If data is shared across multiple entities for analysis, then data utility and analysis accuracy are improved, but privacy breach risks increase
Solution Approach 1:
The patent segments data processing into two distinct environments: a trusted execution environment (TEE) for privacy-sensitive operations and a non-TEE environment for analysis. Data is divided into anonymized versions for analysis and protected versions for sensitive operations, allowing simultaneous achievement of analysis utility and privacy protection
Solution Approach 2:
The patent introduces a trusted execution environment (TEE) as an intermediary layer between data owners and data processors. The TEE acts as a mediator that verifies data processing requests, performs zero-knowledge proofs, and enables secure data sharing without exposing raw personal data, thus facilitating analysis while protecting privacy
2Object-affected harmful factors
If strict anonymization is applied to protect privacy, then privacy protection is improved, but data utility for analysis deteriorates
Solution Approach 1:
The patent implements dynamic anonymization where the level of anonymization adjusts based on the trustworthiness of the requesting entity. Entities that pass TEE verification and demonstrate legitimate analysis needs receive access to less anonymized data, while untrusted entities receive highly anonymized data. This dynamic approach maintains privacy protection while preserving data utility for authorized analysis
Solution Approach 2:
The patent changes the parameter of anonymization intensity based on the execution environment. In TEE environments, data can be processed with lower anonymization intensity to maintain utility, while in non-TEE environments, higher anonymization intensity is applied to ensure privacy. This parameter adjustment resolves the contradiction between privacy protection and data utility
3Measurement precision
If data is collected from multiple customers for centralized analysis, then detection accuracy for subtle attacks is improved, but across-customer privacy breaches may occur
Solution Approach 1:
The patent segments customer data processing by creating isolated TEE instances for each customer while allowing controlled interaction through standardized interfaces. Each customer's data remains segregated in their own TEE environment, preventing cross-customer privacy breaches, while the standardized interaction mechanisms enable aggregated analysis for detecting subtle attacks across the multi-tenant system
Data Source
AI summary
A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a secured environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE. The first anonymization parameters are based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.


