Trusted Query Network for Anonymous Security Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Risk management in organizations is hindered by the lack of reliable empirical data for information security compromises, due to difficulties in data collection and the sensitivity of the information, which makes it challenging to accurately assess and mitigate risks, especially given the rarity of such events.

Innovation Solution

The implementation of a Trusted Query Network (TQN) that facilitates the sharing of sensitive information between organizations through anonymous, aggregated, and securely coordinated data exchange, ensuring participant trust and privacy, with distributed data handling and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If organizations share sensitive security data to improve risk analysis accuracy, then measurement precision improves, but data sensitivity and trust requirements worsen the complexity of collaboration

Engineering Contradiction:
Improverisk analysis accuracyVSAvoidcollaboration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a trusted intermediary system that acts as a mediator between organizations sharing security data. This intermediary validates participants, manages access controls, and ensures data protection protocols are followed, thereby enabling accurate risk analysis while managing the complexity of inter-organizational trust and data sensitivity through a centralized coordination mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If organizations collect and share empirical security loss data, then data availability improves, but data sensitivity and confidentiality concerns worsen

Engineering Contradiction:
Improvedata availabilityVSAvoiddata sensitivity
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent transforms sensitive security loss data by changing its parameters through aggregation and anonymization. Individual organization data is aggregated into collective statistics that maintain analytical value while removing identifiable information. This parameter transformation allows data to be shared and analyzed without exposing sensitive organizational specifics, thus increasing data availability while mitigating sensitivity concerns.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If collaborative data sharing is implemented to overcome data rarity, then empirical data availability improves, but trust requirements and security guarantees worsen system complexity

Engineering Contradiction:
Improveempirical data availabilityVSAvoidtrust requirement
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent employs a trusted intermediary system that acts as a mediator between organizations sharing security data. This intermediary validates participants, manages access controls, and ensures data protection protocols are followed, thereby enabling accurate risk analysis while managing the complexity of inter-organizational trust and data sensitivity through a centralized coordination mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms sensitive security loss data by changing its parameters through aggregation and anonymization. Individual organization data is aggregated into collective statistics that maintain analytical value while removing identifiable information. This parameter transformation allows data to be shared and analyzed without exposing sensitive organizational specifics, thus increasing data availability while mitigating sensitivity concerns.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If comprehensive security loss data is collected for accurate risk profiles, then measurement precision improves, but the complexity of data collection and coordination worsens

Engineering Contradiction:
Improverisk profile accuracyVSAvoiddata collection complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges data collection efforts across multiple organizations into a unified collaborative system. By combining resources, standardized data schemas, and coordinated collection protocols, the system achieves comprehensive risk profiling accuracy that would be impossible for individual organizations to attain alone, while the shared infrastructure reduces the per-organization complexity burden.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8910237B2Trusted query network systems and methods
Publication Date: 2014.12.09 GEORGIA STATE UNIVERSITY RESEARCH FOUNDATION INC
  • US8910237B2 patent drawing
  • US8910237B2 patent drawing
  • US8910237B2 patent drawing

AI summary

Systems and methods are disclosed with which queries can be sent to various clients of a trusted query network in a trusted query network message. In one embodiment, each registered client receives the message and determines whether or not it will participate in the query. If so, the client adds to the message in a first data round a true response to the query and obfuscation data, and then forwards the message on to the next client (or back to the client that initiated the query if each client has added its data to the message). In a second round, the message is again sent to each participating client, which this time removes its obfuscation data. Once each client has removed its obfuscation data, a final result is obtained that can be sent to each of the clients.