Zero Knowledge Analytics for Secure Cloud Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure cloud computing environments face challenges in providing data analytics to platform operators while maintaining the integrity and confidentiality of private data, as restrictive access policies inhibit the extraction and analysis of valuable non-private data.

Innovation Solution

The implementation of Zero Knowledge Analytics systems that extract, anonymize, and aggregate non-private data from secure cloud compute environments, allowing for data analytics outside the secure environment without compromising private data integrity, using trusted execution environments and secure hardware/software to isolate and manage private information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If restrictive access policies are implemented in secure cloud compute environments, then data confidentiality and integrity are improved, but the ability to perform data analytics is worsened

Engineering Contradiction:
Improvedata confidentialityVSAvoidanalytics capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments data into private data (kept confidential within TEE) and non-private data (extracted for analytics). This segmentation allows the system to maintain data confidentiality for sensitive information while enabling analytics on non-sensitive attributes, thus resolving the contradiction between confidentiality and analytics capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts non-private data from secure cloud compute environments for analytics purposes while leaving private data protected within the TEE. This extraction principle enables analytics capability without compromising the confidentiality of sensitive information, directly addressing the technical contradiction.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If private data is kept isolated within secure environments, then data security is improved, but the value to platform operators is worsened

Engineering Contradiction:
Improvedata securityVSAvoidplatform value
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism that extracts non-private data from the secure environment and makes it available to platform operators for analytics. This intermediary approach maintains data security within the TEE while providing value to platform operators through analytics on non-sensitive data, thus resolving the contradiction between security and platform value.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If data is encrypted and protected in secure world, then access control is improved, but data processing capability is worsened

Engineering Contradiction:
Improveaccess controlVSAvoiddata processing
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent extracts non-private data from the encrypted secure environment for processing and analytics. This extraction allows data processing to occur on non-sensitive data without requiring decryption of the entire dataset, thus maintaining strong access control while enabling productive data processing on appropriate data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11354437B2System and methods for providing data analytics for secure cloud compute data
Publication Date: 2022.06.07 VERIZON PATENT & LICENSING INC
  • US11354437B2 patent drawing
  • US11354437B2 patent drawing
  • US11354437B2 patent drawing

AI summary

Systems and methods described herein enable data analytics for secure cloud compute data that protects the integrity and confidentiality of the underlying data. A network device in a network creates an instance of a Trusted Execution Environment (TEE). The network device generates, in the TEE instance, transactional data that includes private information and removes the private information from the transactional data to generate extracted data. The network device encrypts, within the TEE instance, the extracted data and exports the encrypted extracted data to a memory outside of the TEE instance.