IP Library Granted Patent US 10,910,089
Granted Patent B2
US 10,910,089 · App. 15/045,605 · Granted Feb 2, 2021

Methods and systems providing centralized encryption key management for sharing data across diverse entities

Inventors: Joseph R. Austin (Sterling, MA); Shahir Kassam-Adams (Lovingston, VA)
Assignee: UNIVERSAL PATIENT KEY, INC.
G16H10/60G06F21/6254G06Q20/382H04L9/3239H04L63/06G06Q2220/00H04L9/14H04L2209/42H04L2209/76H04L2209/88
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,910,089
App. No.
15/045,605
Filed
Feb 17, 2016
Granted
Feb 2, 2021
Kind
B2
Examiner
KUO, CHENYUH
Art Unit
3685
USPC
705/50
Abstract

A method and apparatus provide centralized encryption key management for sharing data across diverse entities. In particular, the present invention relates to a universal and regulatory compliant system and method for sharing personal data records across diverse entities while maintaining unique identifiers at each entity for protecting the identity of any particular person. The present invention enables multiple organizations to be able to share their respective disparate data in a manner in which the disparate personal data records can be aggregated and manipulated by a single entity without putting the personal data records at risk.

Claims (30)

1. A method for distributing universally shareable personal health data in compliance with legal and regulatory requirements, the method comprising:

storing, by a source client device, personal health data;

creating, by a key management system, a distributed software engine, wherein the distributed software engine comprises:

an encryption token;

a source client device encryption key unique to the source client device;

a destination client device encryption key unique to the destination client device; and

a processing template;

receiving from the key management system, by the source client device, the distributed software engine over a telecommunication network;

de-identifying, by the source client device, the personal health data, using the received distributed software engine, wherein the de-identifying the personal health data comprises:

executing the processing template, wherein the executing the processing template comprises:

formatting the personal health data;

creating a personal identifier hash value by combining the formatted personal health data with the encryption token; and

encrypting the personal identifier hash value with the source client device encryption key unique to the source client device;

decrypting the encrypted personal identifier hash value and re-encrypting the decrypted personal identifier hash value using the destination client device encryption key unique to the destination client device; and

transmitting, by the source client device, the re-encrypted personal identifier hash value to the destination client device.

2. The method of claim 1 , further comprising:

creating, by the key management system, one or more distributed software engines for one or more source client devices or destination client devices.

3. The method of claim 1 , wherein creating the distributed software engine comprises creating each distributed software engine by a trusted third party server of the key management system.

4. The method of claim 1 , further comprising:

requesting, by the distributed software engine, a password to access at least one of the encryption token, the source client device encryption key, the destination client device encryption key, and the processing template of the distributed software engine.

5. The method of claim 1 , further comprising:

registering and verifying, by the key management system, two or more entities; and,

requesting, by the distributed software engine, the encryption token, the source client device encryption key, the destination client device encryption key, and the processing template from a data vault of the key management system.

6. The method of claim 5 , further comprising:

registering, by the key management system, a source client device or at least one client destination device; and

wherein the method further comprises one of:

providing, by the key management system, a unique encryption key, or

creating, by the key management system, a client device encryption key and a client device identifier.

7. The method of claim 1 , further comprising:

receiving, by the distributed software engine at the source client device, a request from the destination client device to share the personal health data.

Assignments (5)
SECURITY INTEREST Recorded Sep 5, 2024
From: CIOX HEALTH, LLC; DATAVANT, INC.
To: BLUE OWL CAPITAL CORPORATION
Reel/Frame 068501/0573 →
RELEASE OF SECURITY INTEREST Recorded Aug 30, 2024
From: UBS AG CAYMAN ISLANDS BRANCH, AS ADMINISTRATIVE AGENT (AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH AS ADMINISTRATIVE AGENT)
To: DATAVANT, INC.
Reel/Frame 068453/0926 →
SECURITY INTEREST Recorded Mar 27, 2024
From: DATAVANT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 066922/0980 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2021
From: UNIVERSAL PATIENT KEY, INC.
To: DATAVANT, INC.
Reel/Frame 055148/0725 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2016
From: AUSTIN, JOSEPH R.; KASSAM-ADAMS, SHAHIR
To: UNIVERSAL PATIENT KEY, INC.
Reel/Frame 038412/0602 →
Continuity (2)
Provisional Application 62136196 · Mar 20, 2015
Related Publication 20160275309A1 · Sep 22, 2016
Cited By (4)
US 12,250,223 US 12,411,667 US 12,603,162 US 12,670,281