Zero Knowledge Analytics for Secure Cloud Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure cloud computing environments face challenges in providing data analytics to platform operators while maintaining the integrity and confidentiality of private data, as restrictive access policies inhibit the extraction and analysis of valuable non-private data.
Innovation Solution
The implementation of Zero Knowledge Analytics systems that extract, anonymize, and aggregate non-private data from secure cloud compute environments, allowing for data analytics outside the secure environment without compromising private data integrity, using trusted execution environments and secure hardware/software to isolate and manage private information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If restrictive access policies are implemented in secure cloud compute environments, then data confidentiality and integrity are improved, but the ability to perform data analytics is worsened
Solution Approach 1:
The patent segments data into private data (kept confidential within TEE) and non-private data (extracted for analytics). This segmentation allows the system to maintain data confidentiality for sensitive information while enabling analytics on non-sensitive attributes, thus resolving the contradiction between confidentiality and analytics capability.
Solution Approach 2:
The patent extracts non-private data from secure cloud compute environments for analytics purposes while leaving private data protected within the TEE. This extraction principle enables analytics capability without compromising the confidentiality of sensitive information, directly addressing the technical contradiction.
2Reliability
If private data is kept isolated within secure environments, then data security is improved, but the value to platform operators is worsened
Solution Approach 1:
The patent introduces an intermediary mechanism that extracts non-private data from the secure environment and makes it available to platform operators for analytics. This intermediary approach maintains data security within the TEE while providing value to platform operators through analytics on non-sensitive data, thus resolving the contradiction between security and platform value.
3Ease of operation
If data is encrypted and protected in secure world, then access control is improved, but data processing capability is worsened
Solution Approach 1:
The patent extracts non-private data from the encrypted secure environment for processing and analytics. This extraction allows data processing to occur on non-sensitive data without requiring decryption of the entire dataset, thus maintaining strong access control while enabling productive data processing on appropriate data.
Data Source
AI summary
Systems and methods described herein enable data analytics for secure cloud compute data that protects the integrity and confidentiality of the underlying data. A network device in a network creates an instance of a Trusted Execution Environment (TEE). The network device generates, in the TEE instance, transactional data that includes private information and removes the private information from the transactional data to generate extracted data. The network device encrypts, within the TEE instance, the extracted data and exports the encrypted extracted data to a memory outside of the TEE instance.


