Trusted Processing Enclaves for Privacy-Preserving IoT Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT and industrial IoT data management solutions lack an architecture that preserves user privacy when using individual-level user data in real time, failing to allow end users to request information without exposing identifying data, and existing solutions are not efficient or scalable for fast, responsive, and privacy-preserving data processing.

Innovation Solution

An architecture that enables data processing at the edge or in the cloud, allowing end users to define geospatial areas, request data from devices within those areas, process data anonymously, and delete the original data used for analysis, ensuring privacy by generating anonymous identifiers and returning only group-level analytical data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If individual-level data is collected and processed in real time, then productivity and decision-making quality are improved, but user privacy is compromised due to exposure of identifying data

Engineering Contradiction:
Improvereal-time data processing capabilityVSAvoidprivacy loss
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces trusted processing environments (TPEs) and secure enclaves as intermediary layers between data collection and analysis. These intermediaries process individual-level data in isolated, secure environments that prevent unauthorized access to identifying information while still enabling real-time analytical processing. The TPE acts as a mediator that allows productivity improvement without direct exposure of sensitive data to end users or general processing systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the data processing architecture into distinct isolated environments: untrusted environments for data collection, trusted processing environments for secure analysis, and controlled output interfaces for results delivery. This segmentation allows real-time processing of individual-level data to occur in isolated TPEs that are separated from the main system, preventing privacy compromise while maintaining processing capability.

Inventive Principle:
Principle #1Segmentation

2Loss of time

If data is processed quickly with minimal delay, then productivity is improved, but privacy protection mechanisms become more complex

Engineering Contradiction:
Improvedata processing delayVSAvoidprivacy protection architecture complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements preliminary setup of trusted processing environments with pre-configured security policies, cryptographic keys, and access controls before data processing begins. This preliminary action allows the complex privacy protection architecture to be established once, enabling subsequent real-time data processing without repeated setup delays. The TPEs are pre-authenticated and pre-configured to handle individual-level data securely from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trusted processing environments operate autonomously with built-in security mechanisms that automatically enforce privacy protections without requiring external intervention for each data processing operation. The TPEs self-manage cryptographic operations, access control enforcement, and secure data handling, reducing the operational complexity burden on external systems while maintaining rapid processing capabilities.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If end users can request and access individual-level data, then ease of operation is improved, but reliability of privacy protection deteriorates

Engineering Contradiction:
Improvedata request capabilityVSAvoidprivacy preservation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent inverts the traditional data access model by allowing end users to request analytical results without directly accessing individual-level data. Instead of users querying and receiving raw data, the system processes requests through TPEs that automatically perform secure analysis and return only aggregated or anonymized results. This inversion maintains ease of operation for data requests while fundamentally protecting privacy by design, making privacy preservation reliable rather than optional.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent implements feedback mechanisms where the trusted processing environments provide confirmation to users about the nature and scope of data processed, without revealing sensitive individual-level information. The system feeds back analytical results and processing metadata that verify privacy protections were applied, maintaining user trust and ease of operation while ensuring reliable privacy preservation through transparent but protected processing verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12141318B2Techniques for private and secure collection and processing of data for generalized analysis
Publication Date: 2024.11.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12141318B2 patent drawing
  • US12141318B2 patent drawing
  • US12141318B2 patent drawing

AI summary

The present disclosure relates to techniques for collection and processing of data over a network, and in particular to in providing generalized analysis for preserving privacy of data sources. In some embodiments, a system receives a request for analytical data made by a requester, wherein the request includes: information for identifying one or more data source devices to be queried for input data, a type of data processing to be performed on the input data for generating the analytical data, and a data type for the analytical data. In response to receiving the request, the system causes the one or more data source devices to be queried for the input data. The system causes a response that includes the analytical data to be sent to the requester. Other embodiments are described throughout the present disclosure.