IP Library Granted Patent US 11,461,499
Granted Patent B2
US 11,461,499 · App. 16/824,223 · Granted Oct 4, 2022

Dynamic data protection

Inventors: Brian Jun (Mountain View, CA); Jan T. Liphardt (Palo Alto, CA)
Assignee: Enya Inc.
G06F21/6263G06F21/6254G16H10/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,461,499
App. No.
16/824,223
Granted
Oct 4, 2022
Kind
B2
Abstract

Methods, systems and computer program products for health data protection. Embodiments commence upon receiving a data access request message from a participant in a health ecosystem. The data access request message comprises an indication of one or more health data sets that are held by or at least potentially of interest to the participant. System components are configured to receive the message and to identify the participant. Based on parameter values corresponding to a data protection policy of the participant, a data protection scheme is generated. The scheme includes parameter values derived from the data protection policy. The parameter values of the scheme are used to generate a variation of the health data set that is formed by applying one or more data anonymization, data obfuscation or other data protection techniques to the health data set. A balance among the parameters is calculated so as to achieve a desired outcome.

Claims (46)

1. A method for dynamic data protection, the method comprising:

receiving at least one data access request associated with a first data set, the at least one data access request being associated with at least one participant to access data that is exchanged over the Internet among two or more participants;

accessing at least one data protection policy corresponding to the at least one participant;

determining a data protection scheme based at least in part on parameter values corresponding to the at least one data protection policy;

generating a protected data set from the first data set, the protected data set being generated based at least in part on application of a selected hashing algorithm; and

provisioning access to the protected data set.

2. The method of claim 1 , wherein the selected hashing algorithm comprises a locality-sensitive hashing technique.

3. The method of claim 1 , further comprising:

selecting the first data set wherein the selecting of the first data set is based at least in part on at least a first data protection policy; and

selecting a second data set wherein the selecting of the second data set is based at least in part a second data protection policy.

4. The method of claim 1 , wherein the data protection scheme is determined based at least in part on a privacy budget parameter, the privacy budget parameter being derived from the at least one data protection policy.

5. The method of claim 1 , wherein at least one differential privacy algorithm is applied to the first data set in accordance with the data protection scheme.

6. The method of claim 1 , wherein access to at least a portion of the first data set is blocked in accordance with the data protection scheme.

7. The method of claim 1 , wherein at least a portion of the first data set is obfuscated in accordance with the data protection scheme.

8. The method of claim 7 , wherein the portion of the first data set is obfuscated by a locality-sensitive hashing technique.

9. The method of claim 1 , wherein the at least one data protection policy is characterized by one or more policy parameters, the one or more policy parameters being associated with at least one of, a policy identifier, a participant identifier, a user identifier, an inference performance indicator, or a data leakage tolerance indicator.

10. The method of claim 1 , further comprising:

issuing a set of instructions to cause an operational element of the at least one participant to apply a participant-specific policy to the first data set.

11. The method of claim 10 , further comprising:

storing participant-specific protected data after applying at least a portion of the participant-specific policy to the first data set.

12. The method of claim 11 , further comprising:

selecting a second data set wherein the second data set is selected based at least in part a second data access request that is received after the applying of the at least a portion of the participant-specific policy to the first data set.

13. A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by one or more processors causes the one or more processors to perform a set of acts for dynamic data protection, the set of acts comprising:

receiving at least one data access request associated with a first data set, the at least one data access request being associated with at least one participant to access data that is exchanged over the Internet among two or more participants;

accessing at least one data protection policy corresponding to the at least one participant;

determining a data protection scheme based at least in part on parameter values corresponding to the at least one data protection policy;

generating a protected data set from the first data set, the protected data set being generated based at least in part on application of a selected hashing algorithm; and

provisioning access to the protected data set.

14. The non-transitory computer readable medium of claim 13 , wherein the selected hashing algorithm comprises a locality-sensitive hashing technique.

15. The non-transitory computer readable medium of claim 13 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of:

selecting the first data set wherein the selecting of the first data set is based at least in part on at least a first data protection policy; and

selecting a second data set wherein the selecting of the second data set is based at least in part a second data protection policy.

16. The non-transitory computer readable medium of claim 13 , wherein the data protection scheme is determined based at least in part on a privacy budget parameter, the privacy budget parameter being derived from the at least one data protection policy.

17. The non-transitory computer readable medium of claim 13 , wherein at least one differential privacy algorithm is applied to the first data set in accordance with the data protection scheme.

18. A system for dynamic data protection, the system comprising:

a storage medium having stored thereon a sequence of instructions; and

one or more processors that execute the instructions to cause the one or more processors to perform a set of acts, the set of acts comprising:

receiving at least one data access request associated with a first data set, the at least one data access request being associated with at least one participant to access data that is exchanged over the Internet among two or more participants;

accessing at least one data protection policy corresponding to the at least one participant;

determining a data protection scheme based at least in part on parameter values corresponding to the at least one data protection policy;

generating a protected data set from the first data set, the protected data set being generated based at least in part on application of a selected hashing algorithm; and

provisioning access to the protected data set.

19. The system of claim 18 , wherein the selected hashing algorithm comprises a locality-sensitive hashing technique.

20. The system of claim 18 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of:

selecting the first data set wherein the selecting of the first data set is based at least in part on at least a first data protection policy; and

selecting a second data set wherein the selecting of the second data set is based at least in part a second data protection policy.

Continuity (2)
Continuation 16400030 · Apr 30, 2019
Related Publication 20200349288A1 · Nov 5, 2020
Cited By (1)
US 12,524,573