Trusted Query Network Anonymity Security Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information security risk management systems face challenges due to imprecise data and disclosure inhibitions, leading to inadequate risk assessment and investment decisions, as organizations hesitate to share security breach data due to reputation and legal concerns, resulting in a lack of objective metrics for prioritizing security threats and vulnerabilities.
Innovation Solution
The Trusted Query Network (TQN) systems and methods enable anonymous and secure data sharing by using obfuscating data and randomized paths to aggregate security assessment results, ensuring that only aggregated data is shared, thus protecting the identity of participating organizations and reducing the risk of data disclosure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If organizations share security breach data publicly, then empirical risk statistics can be developed, but reputation damage and legal risks increase
Solution Approach 1:
The patent introduces a trusted intermediary system that collects, aggregates, and anonymizes security breach data from multiple organizations. This intermediary acts as a mediator that enables data sharing while protecting individual organizations from reputation damage and legal risks by ensuring data is processed in a controlled, anonymous manner that complies with legal requirements.
Solution Approach 2:
The system creates anonymized copies of security breach data that retain statistical value for risk analysis while removing identifying information. These copies can be shared and analyzed without exposing the original organizations, enabling empirical statistics development while protecting reputations.
2Object-affected harmful factors
If organizations withhold security breach data, then reputation is protected, but objective risk assessment metrics cannot be developed
Solution Approach 1:
The trusted intermediary system enables organizations to contribute data without directly exposing their identities, thus protecting reputation while still allowing accurate risk metrics to be developed from the aggregated anonymized data.
Solution Approach 2:
The system merges data from multiple organizations into aggregated statistical results that preserve measurement precision for risk assessment while individualizing the contribution so no single organization's reputation is compromised by the disclosure.
3Loss of information
If security data is shared privately among industry groups, then data availability improves, but anti-trust law violations and public exposure risks increase
Solution Approach 1:
The patent introduces a neutral intermediary that processes data collection and aggregation, replacing private industry group collaborations. This intermediary structure ensures compliance with anti-trust laws by preventing collusive arrangements while still enabling data sharing for legitimate security risk assessment purposes.
Solution Approach 2:
The system extracts the data aggregation function from private industry groups and places it in a neutral, legally-compliant intermediary structure. This removes the anti-trust risk associated with private collaborations while maintaining the benefit of aggregated security data.
Data Source
AI summary
Systems and methods for enabling organizations to anonymously share aggregated security assessment results while keeping the raw or private data locally within the organization.


