Data clean room
Embodiments of the present disclosure may provide a data clean room allowing secure data analysis across multiple accounts, without the use of third parties. Each account may be associated with a different company or party. The data clean room may provide security functions to safeguard sensitive information. For example, the data clean room may restrict access to data in other accounts. The data clean room may also restrict which data may be used in the analysis and may restrict the output. The overlap data may be anonymized to prevent sensitive information from being revealed.
1 . A method comprising:
providing a data clean room for a first party data in a first account in a network-based data system and a second party data in a second account in the network-based data system, the data clean room comprising a cross reference table including results a secure function execution using the first party data and the second party data, the providing the first party data comprises:
uploading a load file to a secure cloud storage location;
storing data from the load file into an enclave account; and
setting access restrictions for the data from the load file based on control information;
receiving a query request directed to the data clean room;
executing a first portion of the query request based on the first party data and the cross reference table;
generating an interim table based on executing the first portion of the query request;
generating a secure query request comprising instructions related to executing a second portion of the query request;
executing, at the second account, the secure query request and joining results of the secure query requests with information from an interim table to generate final results of the query request; and
sharing the secure query request and the interim table with the second account to execute the second portion of the query request.
2 . The method of claim 1 , wherein providing the data clean room comprises:
executing a secure function using the first party data to generate a first result, including creating links to the first party data and anonymizing identification information in the first party data; and
sharing the secure function with the second account.
3 . The method of claim 2 , wherein providing the data clean room further comprises:
executing the secure function using the second party data to generate a second result and restricting the second account from accessing the first party data; and
generating the cross reference table with the first result and second result, the cross reference table providing anonymized matches of the first and second results.
4 . The method of claim 3 , wherein providing the data clean room further comprises:
generating dummy matching information in the second result for an instance of no match.
5 . The method of claim 3 , further comprising:
generating a summary report of the anonymized matches.
6 . A machine-storage medium embodying instructions that, when executed by a machine, cause the machine to perform operations comprising:
providing a data clean room for a first party data in a first account in a network-based data system and a second party data in a second account in the network-based data system, the data clean room comprising a cross reference table including results a secure function execution using the first party data and the second party data, the providing the first party data comprises:
uploading a load file to a secure cloud storage location;
storing data from the load file into an enclave account; and
setting access restrictions for the data from the load file based on control information;
receiving a query request directed to the data clean room;
executing a first portion of the query request based on the first party data and the cross reference table;
generating an interim table based on executing the first portion of the query request;
generating a secure query request comprising instructions related to executing a second portion of the query request;
executing, at the second account, the secure query request and joining results of the secure query requests with information from an interim table to generate final results of the query request; and
sharing the secure query request and the interim table with the second account to execute the second portion of the query request.
7 . The machine-storage medium of claim 6 , wherein providing the data clean room comprises:
executing a secure function using the first party data to generate a first result, including creating links to the first party data and anonymizing identification information in the first party data; and
sharing the secure function with the second account.
8 . The machine-storage medium of claim 7 , wherein providing the data clean room further comprises:
executing the secure function using the second party data to generate a second result and restricting the second account from accessing the first party data; and
generating the cross reference table with the first result and second result, the cross reference table providing anonymized matches of the first and second results.
9 . The machine-storage medium of claim 8 , wherein providing the data clean room further comprises:
generating dummy matching information in the second result for an instance of no match.
10 . The machine-storage medium of claim 8 , further comprising:
generating a summary report of the anonymized matches.
11 . A system comprising:
a memory having programming instructions stored thereon, which, when executed by the one or more processors, performs one or more operations comprising:
providing a data clean room for a first party data in a first account in a network-based data system and a second party data in a second account in the network-based data system, the data clean room comprising a cross reference table including results a secure function execution using the first party data and the second party data, the providing the first party data comprises:
uploading a load file to a secure cloud storage location;
storing data from the load file into an enclave account; and
setting access restrictions for the data from the load file based on control information;
receiving a query request directed to the data clean room;
executing a first portion of the query request based on the first party data and the cross reference table;
generating an interim table based on executing the first portion of the query request;
generating a secure query request comprising instructions related to executing a second portion of the query request; and
executing, at the second account, the secure query request and joining results of the secure query requests with information from an interim table to generate final results of the query request; and
sharing the secure query request and the interim table with the second account to execute the second portion of the query request.
12 . The system of claim 11 , wherein providing the data clean room comprises:
executing a secure function using the first party data to generate a first result, including creating links to the first party data and anonymizing identification information in the first party data; and
sharing the secure function with the second account.
13 . The system of claim 12 , wherein providing the data clean room further comprises:
executing the secure function using the second party data to generate a second result and restricting the second account from accessing the first party data; and
generating the cross reference table with the first result and second result, the cross reference table providing anonymized matches of the first and second results.
14 . The system of claim 13 , wherein providing the data clean room further comprises:
generating dummy matching information in the second result for an instance of no match.
15 . The system of claim 13 , further comprising:
generating a summary report of the anonymized matches.