Trusted Query Network for Anonymous Security Data Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Risk management in organizations is hindered by the lack of reliable empirical data for information security compromises, due to difficulties in data collection and the sensitivity of the information, which makes it challenging to accurately assess and mitigate risks, especially given the rarity of such events.
Innovation Solution
The implementation of a Trusted Query Network (TQN) that facilitates the sharing of sensitive information between organizations through anonymous, aggregated, and securely coordinated data exchange, ensuring participant trust and privacy, with distributed data handling and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If organizations share sensitive security data to improve risk analysis accuracy, then measurement precision improves, but data sensitivity and trust requirements worsen the complexity of collaboration
Solution Approach 1:
The patent introduces a trusted intermediary system that acts as a mediator between organizations sharing security data. This intermediary validates participants, manages access controls, and ensures data protection protocols are followed, thereby enabling accurate risk analysis while managing the complexity of inter-organizational trust and data sensitivity through a centralized coordination mechanism.
2Quantity of substance
If organizations collect and share empirical security loss data, then data availability improves, but data sensitivity and confidentiality concerns worsen
Solution Approach 1:
The patent transforms sensitive security loss data by changing its parameters through aggregation and anonymization. Individual organization data is aggregated into collective statistics that maintain analytical value while removing identifiable information. This parameter transformation allows data to be shared and analyzed without exposing sensitive organizational specifics, thus increasing data availability while mitigating sensitivity concerns.
3Quantity of substance
If collaborative data sharing is implemented to overcome data rarity, then empirical data availability improves, but trust requirements and security guarantees worsen system complexity
Solution Approach 1:
The patent employs a trusted intermediary system that acts as a mediator between organizations sharing security data. This intermediary validates participants, manages access controls, and ensures data protection protocols are followed, thereby enabling accurate risk analysis while managing the complexity of inter-organizational trust and data sensitivity through a centralized coordination mechanism.
Solution Approach 2:
The patent transforms sensitive security loss data by changing its parameters through aggregation and anonymization. Individual organization data is aggregated into collective statistics that maintain analytical value while removing identifiable information. This parameter transformation allows data to be shared and analyzed without exposing sensitive organizational specifics, thus increasing data availability while mitigating sensitivity concerns.
4Measurement precision
If comprehensive security loss data is collected for accurate risk profiles, then measurement precision improves, but the complexity of data collection and coordination worsens
Solution Approach 1:
The patent merges data collection efforts across multiple organizations into a unified collaborative system. By combining resources, standardized data schemas, and coordinated collection protocols, the system achieves comprehensive risk profiling accuracy that would be impossible for individual organizations to attain alone, while the shared infrastructure reduces the per-organization complexity burden.
Data Source
AI summary
Systems and methods are disclosed with which queries can be sent to various clients of a trusted query network in a trusted query network message. In one embodiment, each registered client receives the message and determines whether or not it will participate in the query. If so, the client adds to the message in a first data round a true response to the query and obfuscation data, and then forwards the message on to the next client (or back to the client that initiated the query if each client has added its data to the message). In a second round, the message is again sent to each participating client, which this time removes its obfuscation data. Once each client has removed its obfuscation data, a final result is obtained that can be sent to each of the clients.


