Telemetry Data Association via Hashed Domain Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems are unable to associate telemetry data from different entities, such as guest and host machines residing on a physical computer or from different physical computers, which limits the ability to analyze and refine server applications and configurations effectively.
Innovation Solution
Incorporating information that identifies but preserves anonymity, such as fully qualified domain names (FQDNs) or Active Directory GUIDs, into telemetry data, and using one-way hashing algorithms like SHA-256 to enable the association of telemetry data from different entities without compromising privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional telemetry data collection methods are used with obfuscated identifiers, then entity anonymity is preserved, but the ability to associate telemetry data from different entities is lost
Solution Approach 1:
The patent introduces a domain name as an intermediary element that entities can voluntarily include in their telemetry data. This domain name serves as a mediator that allows the information collection facility to associate telemetry data from different entities belonging to the same organization or domain, while still preserving the anonymity of individual entities through the use of obfuscated machine identifiers. The domain name acts as a bridge between complete anonymity and full identifiability.
2Loss of information
If entity identifiers are included in telemetry data to enable association, then data analysis capability is improved, but entity anonymity is compromised
Solution Approach 1:
The patent segments the entity identification information into two distinct parts: a volatile component (machine identifier) that changes frequently and a stable component (domain name) that remains consistent. This segmentation allows the telemetry data to be associated across different sessions through the stable domain name portion, while the volatile machine identifier portion continues to provide anonymity by changing over time. The segmented approach resolves the contradiction between association capability and anonymity preservation.
3Object-affected harmful factors
If machine identifiers are made volatile to enhance anonymity, then entity privacy is protected, but the ability to track system evolution over time is reduced
Solution Approach 1:
The patent implements a dynamic identification scheme where the machine identifier portion of the entity identifier is designed to change or become volatile over time, while the domain name portion remains static. This dynamic approach allows the system to protect privacy through identifier rotation while still maintaining the ability to track system evolution by associating different identifier states with the same domain. The dynamic nature of the identifier resolves the contradiction between privacy protection and evolution tracking.
Data Source
AI summary
Embodiments of the invention provide an ability to associate telemetry data received from different entities, such as guest and/or host machines residing on one or more particular physical computers (e.g., server computers) executing virtualization software. In some embodiments, telemetry data supplied by each entity includes information that identifies, and preserves the anonymity of, the entity (e.g., the computer(s) on which the guest and/or host machine(s) reside(s)). For example, if the entities comprise guest and/or host machines residing on a single computer, the information may comprise a one-way hash of the fully qualified domain name (FQDN) of the computer. If the entities are guest and/or host machines residing on a group of computers, the information may comprise a one-way hash of a portion of an FQDN for each computer which is common to all computers in the group. If the group of computers belong to a network domain having a globally unique identifier (GUID) (e.g., as employed by Microsoft Active Directory), the information may comprise a one-way hash of a portion of the GUID.


