Trusted Data Provenance via Cryptographic Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As computing systems with numerous IoT devices become increasingly common, ensuring the trustworthiness and provenance of data from these devices is crucial to prevent tampering and maintain data integrity, especially in critical environments like industrial or medical settings.

Innovation Solution

A data acquisition system that involves receiving a trusted aggregate data object from an intermediate apparatus, which includes aggregate data from multiple data source devices, an intermediate apparatus quote describing its configuration, and a digital signature. This system verifies the integrity of the data and the intermediate apparatus, ensuring the data's trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transmitted from multiple IoT devices through intermediate edge servers to a cloud server, then the system can process and manage large amounts of data efficiently, but the risk of data tampering and loss of data provenance increases

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by creating cryptographic bindings between data and device identities before data leaves the source device. Each data packet is signed with the device's private key and includes a cryptographic binding to the device's identity, ensuring that data integrity is established upfront before transmission through potentially untrusted intermediate nodes. This prevents tampering during transit without requiring complex verification at each intermediate step.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic intermediaries in the form of trusted platform modules (TPM) or secure elements that mediate between the data source and the cloud server. These intermediaries provide cryptographic services including key generation, data signing, and identity verification, enabling the system to maintain data provenance and integrity without requiring direct trust between the edge server and data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic verification is performed at every intermediate node to ensure data integrity, then data trustworthiness is maintained, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedata trustworthinessVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex cryptographic verification operations from intermediate nodes and concentrates them in the cloud server. Intermediate edge servers only need to forward data with its cryptographic attachments without performing verification, while the cloud server performs comprehensive verification of cryptographic bindings and signatures. This extraction reduces the complexity burden on intermediate devices while maintaining overall system reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of information

If digital signatures and cryptographic bindings are attached to every data packet, then data provenance can be verified, but data transmission size and processing overhead increase

Engineering Contradiction:
Improvedata provenanceVSAvoiddata packet size
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent applies local quality by making cryptographic bindings device-specific and data-specific rather than applying uniform cryptographic overhead to all data. Each data packet receives a cryptographic binding tailored to its source device and content, using the device's unique identity and cryptographic keys. This approach provides strong provenance verification while minimizing redundant cryptographic data in each packet.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12242658B2Trusted data provenance
Publication Date: 2025.03.04 NOKIA TECHNOLOGIES OY
  • US12242658B2 patent drawing
  • US12242658B2 patent drawing
  • US12242658B2 patent drawing

AI summary

According to an example embodiment, a technique for data acquisition is provided, comprising: receiving, from an intermediate apparatus, a trusted aggregate data object comprising aggregate data object that comprises aggregate data comprising a respective trusted source data object for one or more data source apparatuses mapped to the intermediate apparatus and an intermediate apparatus quote that is descriptive of one or more aspects of a configuration of the intermediate apparatus upon production of the aggregate data, and an intermediate apparatus signature comprising a digital signature derived based on the aggregate data object using a first key assigned to the intermediate apparatus; and verifying, based at least in part on information received in the trusted aggregate data object, integrity of data included in the trusted aggregate data object and integrity of the intermediate apparatus.