Endpoint Threat Data Encryption for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer security threats have become increasingly sophisticated, requiring constant updates in security products to detect and respond to emerging threats, and existing systems struggle to effectively collect and analyze threat data across isolated enterprise networks, making it difficult to detect and mitigate widespread propagation.

Innovation Solution

An endpoint computer in an enterprise network is configured to detect security threats, generate threat data, and encrypt user identifiable information before sending it to a smart protection network for aggregation, allowing for the analysis of emerging threats while maintaining user privacy through encryption and secure data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If threat data is collected and aggregated across enterprise networks for analysis, then the ability to detect and analyze emerging threats is improved, but user privacy is compromised due to exposure of user identifiable data

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiduser privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts user identifiable data from threat data and handles it separately through encryption. The system identifies and isolates sensitive user information, applying specific protective measures to it while allowing the rest of the threat data to be aggregated and analyzed for security threat detection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces encryption as an intermediary mechanism between user identifiable data and the aggregation system. By encrypting sensitive information before aggregation, the system creates a protective layer that allows data collection and analysis while preserving user privacy, as the encrypted data cannot be directly interpreted to identify users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If user identifiable data is encrypted before transmission, then user privacy is protected, but data analysis capability is reduced due to loss of information

Engineering Contradiction:
Improveuser privacy protectionVSAvoidthreat data analysis capability
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent extracts only the necessary user identifiable data elements for privacy protection while leaving the core threat analysis data unencrypted and fully available for analysis. This selective extraction approach ensures that encryption is applied only where privacy is at risk, not to the entire threat data set.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different data treatment approaches to different parts of the threat data. User identifiable data is encrypted to protect privacy, while other threat-related data remains unencrypted and accessible for full analysis capability, creating local quality variations in data protection intensity.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If threat data is aggregated from multiple isolated enterprise networks, then the ability to detect widespread propagation is improved, but system complexity increases due to data collection infrastructure

Engineering Contradiction:
Improvewidespread threat detectionVSAvoiddata collection system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal aggregation system that can collect and process threat data from multiple different enterprise networks through a common interface and protocol. This multi-functional system handles data collection, encryption, aggregation, and analysis in a unified platform, reducing the need for separate specialized systems for each network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the data collection system into modular components: endpoint agents that collect local threat data, encryption modules that protect sensitive information, aggregation servers that consolidate data from multiple networks, and analysis systems that process the aggregated information. This segmentation reduces overall system complexity by making each component independent and manageable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9043587B1Computer security threat data collection and aggregation with user privacy protection
Publication Date: 2015.05.26 TREND MICRO INC
  • US9043587B1 patent drawing
  • US9043587B1 patent drawing
  • US9043587B1 patent drawing

AI summary

An endpoint computer in an enterprise network is configured to detect computer security threat events, such as presence of a computer virus. Upon detection of a threat event, the endpoint computer generates computer security threat data for the threat event. The threat data may include user identifiable data that can be used to identify a user in the enterprise network. The endpoint computer encrypts the user identifiable data prior to sending the threat data to a smart protection network or to an enterprise server where threat data from various enterprise networks are collected for analysis. The endpoint computer may also encrypt an identifier for the threat data and provide the encrypted identifier to the smart protection network and to an enterprise server in the enterprise network. The enterprise server may use the encrypted identifier to retrieve the threat data from the smart protection network to generate user-specific reports.