Trusted Query Network Anonymity Security Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security risk management systems face challenges due to imprecise data and disclosure inhibitions, leading to inadequate risk assessment and investment decisions, as organizations hesitate to share security breach data due to reputation and legal concerns, resulting in a lack of objective metrics for prioritizing security threats and vulnerabilities.

Innovation Solution

The Trusted Query Network (TQN) systems and methods enable anonymous and secure data sharing by using obfuscating data and randomized paths to aggregate security assessment results, ensuring that only aggregated data is shared, thus protecting the identity of participating organizations and reducing the risk of data disclosure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If organizations share security breach data publicly, then empirical risk statistics can be developed, but reputation damage and legal risks increase

Engineering Contradiction:
Improveavailability of security breach dataVSAvoidreputation damage and legal risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted intermediary system that collects, aggregates, and anonymizes security breach data from multiple organizations. This intermediary acts as a mediator that enables data sharing while protecting individual organizations from reputation damage and legal risks by ensuring data is processed in a controlled, anonymous manner that complies with legal requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates anonymized copies of security breach data that retain statistical value for risk analysis while removing identifying information. These copies can be shared and analyzed without exposing the original organizations, enabling empirical statistics development while protecting reputations.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If organizations withhold security breach data, then reputation is protected, but objective risk assessment metrics cannot be developed

Engineering Contradiction:
Improvereputation protectionVSAvoidaccuracy of risk assessment metrics
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The trusted intermediary system enables organizations to contribute data without directly exposing their identities, thus protecting reputation while still allowing accurate risk metrics to be developed from the aggregated anonymized data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system merges data from multiple organizations into aggregated statistical results that preserve measurement precision for risk assessment while individualizing the contribution so no single organization's reputation is compromised by the disclosure.

Inventive Principle:
Principle #5Merging (Combining)

3Loss of information

If security data is shared privately among industry groups, then data availability improves, but anti-trust law violations and public exposure risks increase

Engineering Contradiction:
Improveavailability of security dataVSAvoidanti-trust law violations and public exposure
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a neutral intermediary that processes data collection and aggregation, replacing private industry group collaborations. This intermediary structure ensures compliance with anti-trust laws by preventing collusive arrangements while still enabling data sharing for legitimate security risk assessment purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts the data aggregation function from private industry groups and places it in a neutral, legally-compliant intermediary structure. This removes the anti-trust risk associated with private collaborations while maintaining the benefit of aggregated security data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8775402B2Trusted query network systems and methods
Publication Date: 2014.07.08 GEORGIA STATE UNIVERSITY RESEARCH FOUNDATION INC
  • US8775402B2 patent drawing
  • US8775402B2 patent drawing
  • US8775402B2 patent drawing

AI summary

Systems and methods for enabling organizations to anonymously share aggregated security assessment results while keeping the raw or private data locally within the organization.