IP Library Granted Patent US 10,915,642
Granted Patent B2
US 10,915,642 · App. 16/202,355 · Granted Feb 9, 2021

Private analytics using multi-party computation

Inventors: Jeb R. Linton (Manassas, VA); Dennis Kramer (Siler City, NC); Irma Sheriff (Whitby, CA)
Assignee: International Business Machines Corporation
G06F21/602G06F8/41G06F21/604H04L9/0861H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,915,642
App. No.
16/202,355
Granted
Feb 9, 2021
Kind
B2
Abstract

A method, system, and computer program product for performing strong desensitization of sensitive data within a garbled circuit includes: compiling a predetermined program into a first program, where the compiled first program is encoded in a form of a garbled circuit, and where the predetermined program runs on sensitive data; and executing the first program, where executing the first program includes: executing an analytics function using tokenized data with a first set of sensitive information and analytics data with a second set of sensitive information, where the tokenized data originated from a data provider and the analytics data originated from an analytics provider; and generating an output of the first program using a result of the analytics function, where the output contains desensitized data.

Claims (35)

1. A system comprising:

one or more computer processors; and

a memory,

wherein the system is configured to:

compile a predetermined program into a first program, wherein the compiled first program is encoded in a form of a garbled circuit, and wherein the predetermined program runs on sensitive data; and

execute the first program, wherein executing the first program comprises:

executing an analytics function using tokenized data with a first set of sensitive information and analytics data with a second set of sensitive information, wherein:

the tokenized data originated from a data provider and the analytics data originated from an analytics provider,

the tokenized data includes sensitive data elements that have been obscured, and

executing the analytics function comprises executing a first matched analytics function on the analytics provider and a second matched analytics function on the data provider, and

generating an output of the first program using a result of the analytics function, wherein the output contains desensitized data.

2. The system of claim 1 , wherein executing the first program further comprises:

in response to executing the analytics function, desensitizing the result of the analytics function using a statistical desensitization technique, wherein the desensitizing comprises obscuring the first set of sensitive information and the second set of sensitive information.

3. The system of claim 1 , wherein executing the first program further comprises encrypting the output.

4. The system of claim 3 , wherein:

one of the data provider and the analytics provider is an owning party and one is a non-owning party, and

encrypting the output comprises:

receiving an encryption key from the owning party, and

encrypting the output using the encryption key.

5. A computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a server to cause the server to perform a method, the method comprising:

compiling a predetermined program into a first program, wherein the compiled first program is encoded in a form of a garbled circuit, and wherein the predetermined program runs on sensitive data; and

executing the first program, wherein executing the first program comprises:

executing an analytics function using tokenized data with a first set of sensitive information and analytics data with a second set of sensitive information, wherein:

the tokenized data originated from a data provider and the analytics data originated from an analytics provider,

the tokenized data includes sensitive data elements that have been obscured, and

executing the analytics function comprises executing a first matched analytics function on the analytics provider and a second matched analytics function on the data provider, and

generating an output of the first program using a result of the analytics function, wherein the output contains desensitized data.

6. The computer program product of claim 5 , wherein executing the first program further comprises:

in response to executing the analytics function, desensitizing the result of the analytics function using a statistical desensitization technique, wherein the desensitizing comprises obscuring the first set of sensitive information and the second set of sensitive information.

7. The computer program product of claim 5 , wherein executing the first program further comprises encrypting the output.

8. The computer program product of claim 7 , wherein:

one of the data provider and the analytics provider is an owning party and one is a non-owning party, and

encrypting the output comprises:

receiving an encryption key from the owning party, and

encrypting the output using the encryption key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2018
From: LINTON, JEB R.; KRAMER, DENNIS; SHERIFF, IRMA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047604/0826 →
Continuity (1)
Related Publication 20200167483A1 · May 28, 2020