IP Library Granted Patent US 11,593,512
Granted Patent B2
US 11,593,512 · App. 16/612,993 · Granted Feb 28, 2023

Systems and methods for crowdsourcing, analyzing, and/or matching personal data

Inventors: Zhizhuo Zhang (Branford, CT); Manolis Kellis (Boston, MA); Dianbo Liu (Cambridge, MA); Anne Kim (Cambridge, MA); Lauren Huang (New York, NY); Sandeep Nuckchady (Quatre Bornes, MU)
Assignee: Massachusetts Institute of Technology
G06F21/6245G06F9/45558G06F16/2365G06F21/602G06Q50/265G16B20/20G16B20/40G16B30/10G16B50/40G16H10/40G16H50/30G16H50/70H04L9/30G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,593,512
App. No.
16/612,993
Granted
Feb 28, 2023
Kind
B2
Abstract

Described herein are a secure system for sharing private data and related systems and methods for incentivizing and validating private data sharing. In some embodiments, private data providers may register to selectively share private data under controlled sharing conditions. The private data may be cryptographically secured using encryption information corresponding to one or more secure execution environments. To demonstrate to the private data providers that the secure execution environment is secure and trustworthy, attestations demonstrating the security of the secure execution environment may be stored in a distributed ledger (e.g., a public blockchain). Private data users that want access to shared private data may publish applications for operating on the private data to a secure execution environment and publish, in a distributed ledger, an indication that the application is available to receive private data. The distributed ledger may also store sharing conditions under which the private data will be shared.

Claims (62)

1. A computer-implemented method for sharing private data, the method comprising:

registering private data for sharing within a secure platform for exchange of private information, wherein registering the private data comprises:

obtaining, from a secure execution environment, security information to secure private data;

storing, in a first distributed ledger, an attestation report identifying that the secure execution environment has been secured; and

storing, in a second distributed ledger, an identification that the private data has been registered for sharing within the secure platform; and

in response to receiving an instruction from a user granting access to the secured private data, triggering transmission of the secured private data to the secure execution environment to be processed, wherein the triggering comprises recording, in the second distributed ledger, an indication that the access has been granted to the secured private data.

2. The method of claim 1 , wherein the method further comprises securing the private data within an enclave associated with at least one Trusted Execution Environment (TEE).

3. The method of claim 2 , wherein obtaining, from a secure execution environment, security information to secure private data comprises obtaining a public encryption key that corresponds to a private encryption key in the secure execution environment.

4. The method of claim 1 , wherein the method further comprises securing the private data via a virtual machine executing within the secure execution environment.

5. The method of claim 1 , wherein the method further comprises, in response to receiving the instruction from the user granting access to the secured private data:

receiving a confirmation that the secured private data was used in generation of a private information model and that an ownership interest by the user in the private information model has been recorded in the second distributed ledger.

6. The method of claim 1 , wherein the method further comprises:

receiving a search query identifying desired private data;

determining whether the desired private data corresponds to the private data; and

in response to determining that the private data corresponds to the desired private data, transmitting a message to a source of the search query, the message indicating that the private data corresponds to the desired private data.

7. The method of claim 1 , the method further comprising:

transmitting the secured private data to a second secure execution environment; and

receiving one or more search indices indicating one or more respective characteristics of the private data.

8. The method of claim 1 , the method further comprising:

receiving a request to validate a characteristic of the private data; and

in response to the request, transmitting the secured private data to a second secure execution environment configured to validate the characteristic.

9. The method of claim 1 , the method further comprising:

generating a message; and

transmitting the message, wherein transmitting the message comprises evaluating a garbled circuit, generated by a remote computing device, configured to obscure respective identities of a sender and a recipient of the message.

10. The method of claim 1 , the method further comprising, in response to transmitting the secured private data to the secure execution environment, receiving an indication of a remuneration via the distributed ledger.

11. The method of claim 10 , the method further comprising:

in response to transmitting the secured private data to the secure execution environment, receiving an indication that a task making use of the private data has completed; and

subsequent to receiving the indication that the task making use of the private data has completed, receiving an indication of an expected value of a future remuneration via the distributed ledger.

12. The method of claim 1 , the method further comprising storing the secured private data in a repository.

13. The method of claim 1 , wherein the private data comprises genomic data, social information data, picture data, phenotypic data, medical data, financial data, and/or insurance data.

14. At least one non-transitory computer-readable storage medium having encoded thereon executable instructions that, when executed by at least one processor, cause the at least one processor to carry out a method for sharing private data, the method comprising:

registering private data for sharing within a secure platform for exchange of private information, wherein registering the private data comprises:

obtaining, from a secure execution environment, security information to secure private data;

storing, in a first distributed ledger, an attestation report identifying that the secure execution environment has been secured; and

storing, in a second distributed ledger, an identification that the private data has been registered for sharing within the secure platform; and

in response to receiving an instruction from a user granting access to the secured private data, triggering transmission of the secured private data to the secure execution environment to be processed, wherein the triggering comprises recording, in the second distributed ledger, an indication that the access has been granted to the secured private data.

15. The at least one non-transitory computer-readable storage medium of claim 14 , wherein the method further comprises, in response to receiving the instruction from the user granting access to the secured private data:

receiving a confirmation that the secured private data was used in generation of a private information model and that an ownership interest by the user in the private information model has been recorded in the second distributed ledger.

16. The at least one non-transitory computer-readable storage medium of claim 14 , wherein the method further comprises:

receiving a search query identifying desired private data;

determining whether the desired private data corresponds to the private data; and

in response to determining that the private data corresponds to the desired private data, transmitting a message to a source of the search query, the message indicating that the private data corresponds to the desired private data.

17. The at least one non-transitory computer-readable storage medium of claim 14 , wherein the method further comprises:

receiving a request to validate a characteristic of the private data; and

in response to the request, transmitting the secured private data to a second secure execution environment configured to validate the characteristic.

18. An apparatus comprising:

at least one processor; and

at least one storage medium having encoded thereon executable instructions that, when executed by the at least one processor, cause the at least one processor to carry out a method for sharing private data, the method comprising:

registering private data for sharing within a secure platform for exchange of private information, wherein registering the private data comprises:

obtaining, from a secure execution environment, security information to secure private data;

storing, in a first distributed ledger, an attestation report identifying that the secure execution environment has been secured; and

storing, in a second distributed ledger, an identification that the private data has been registered for sharing within the secure platform; and

in response to receiving an instruction from a user granting access to the secured private data, triggering transmission of the secured private data to the secure execution environment to be processed, wherein the triggering comprises recording in the second distributed ledger an indication that the access has been granted to the secured private data.

19. The apparatus of claim 18 , wherein the method further comprises, in response to receiving the instruction from the user granting access to the secured private data:

receiving a confirmation that the secured private data was used in generation of a private information model and that an ownership interest by the user in the private information model has been recorded in the second distributed ledger.

20. The apparatus of claim 18 , wherein the method further comprises:

receiving a search query identifying desired private data;

determining whether the desired private data corresponds to the private data; and

in response to determining that the private data corresponds to the desired private data, transmitting a message to a source of the search query, the message indicating that the private data corresponds to the desired private data.

21. The apparatus of claim 18 , wherein the method further comprises:

receiving a request to validate a characteristic of the private data; and

in response to the request, transmitting the secured private data to a second secure execution environment configured to validate the characteristic.

Assignments (2)
CONFIRMATORY LICENSE Recorded Aug 2, 2022
From: MASSACHUSETTS INSTITUTE OF TECHNOLOGY
To: NATIONAL INSTITUTES OF HEALTH (NIH), U.S. DEPT. OF HEALTH AND HUMAN SERVICES (DHHS), U.S. GOVERNMENT
Reel/Frame 061048/0467 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2019
From: ZHANG, ZHIZHUO; KELLIS, MANOLIS; KIM, ANNE; LIU, DIANBO; HUANG, LAUREN; NUCKCHADY, SANDEEP
To: MASSACHUSETTS INSTITUTE OF TECHNOLOGY
Reel/Frame 051383/0579 →
Continuity (3)
Provisional Application 62632330 · Feb 19, 2018
Provisional Application 62505822 · May 12, 2017
Related Publication 20200202038A1 · Jun 25, 2020