IP Library › Granted Patent US 11,153,089
Granted Patent B2
US 11,153,089 · App. 16/834,641 · Granted Oct 19, 2021

Secure and zero knowledge data sharing for cloud applications

Inventors: Amer Haider (Saratoga, CA); Ali Ahmed (Saratoga, CA)
Assignee: Masimo Corporation
H04L9/3221G06F16/951G06F21/14G06F21/6218G06F21/6227H04L9/0825H04L9/14H04L63/0428H04L63/06H04L67/10H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,089
App. No.
16/834,641
Granted
Oct 19, 2021
Kind
B2
Abstract

Disclosed is a zero-knowledge distributed application configured to securely share information among groups of users having various roles, such as doctors and patients. Confidential information may be encrypted client-side, with private keys that reside solely client side. Encrypted collections of data may be uploaded to, and hosted by, a server that does not have access to keys suitable to decrypt the data. Other users may retrieve encrypted data from the server and decrypt some or all of the data with keys suitable to gain access to at least part of the encrypted data. The system includes a key hierarchy with multiple entry points to a top layer by which access is selectively granted to various users and keys may be recovered.

Claims (11)

1. A method of communicating data between a first computing device associated with a patient and a second computing device associated with a care provider, comprising:

obtaining patient data with the first computing device associated with a patient;

encrypting the patient data with a first key at the first computing device;

transmitting the encrypted patient data without providing the first key to decrypt the data to a server;

storing the encrypted data at the server, wherein the server does not have access to any key to decrypt the encrypted data;

receiving a request for the stored encrypted data from the second computing device associated with the care provider; and

decrypting the encrypted data with a second key that is different than the first key, wherein the second key is a private key obtained by decrypting an encrypted private key (EPK) that was stored as part of a key hierarchy structure (KHS).

2. The method of claim 1 , wherein the first key is a public key.

3. The method of claim 1 , wherein the first and the second keys are generated at a time of registration of the patient as a new user.

4. The method of claim 1 , wherein another KHS is created based on a request to generate shared data.

5. The method of claim 1 , wherein names of entries of the KHS are obfuscated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2026
From: HAIDER, AMER
To: MASIMO CORPORATION
Reel/Frame 075577/0946 →
Continuity (3)
Continuation 15642632 · Jul 6, 2017
Provisional Application 62358783 · Jul 6, 2016
Related Publication 20200295937A1 · Sep 17, 2020
Cited By (2)
US 12,329,548 US 12,750,228