IP Library › Granted Patent US 11,853,455
Granted Patent B2
US 11,853,455 · App. 17/124,568 · Granted Dec 26, 2023

Access control in privacy firewalls

Inventors: Omer Dror (Tel Aviv, IL); Ofir Farchy (Modiin, IL)
Assignee: LYNX MD LTD
G06F21/6245G06F16/2358G06F16/24568G06F21/606G06F21/629G06N20/00G16H10/60G06F2221/2145H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,853,455
App. No.
17/124,568
Filed
Dec 17, 2020
Granted
Dec 26, 2023
Kind
B2
Art Unit
2491
USPC
726/28
Abstract

Systems, methods and non-transitory computer readable media for controlling access in privacy firewalls are provided. A request to access a content of an element may be received, the content of the element may include a first portion and a second portion, the first portion may include identifiable information and the second portion may include no identifiable information. A permission record corresponding to the element may be accessed. In response to a first value in the permission record, access may be provided to the content of the element, including access to the first and second portions, and in response to a second value in the permission record, partial access may be provided to the content of the element, the partial access may include access to the second portion and may exclude access to the first portion.

Claims (75)

1. A non-transitory computer readable medium storing a software program comprising data and computer implementable instructions for carrying out a method for controlling access to private medical information in privacy firewalls, the method comprising:

receiving an input defining a function selected from a group consisting of a mathematical function, computer function, linear function, non-linear function, polynomial function, continuous function, discontinuous function, differentiable function, and non-differentiable function;

receiving a request to access a content of an element, the content of the element includes at least a first portion and a second portion, the first portion includes identifiable information and the second portion does not include identifiable information;

accessing a permission record corresponding to the element;

in response to a first value in the permission record, providing access to the content of the element, including access to the first portion and the second portion of the content of the element; and

in response to a second value in the permission record:

providing partial access to the content of the element, the partial access including access to the second portion of the content of the element and excluding access to the first portion of the content of the element;

causing a usage of an identified copy of element to calculate a value of the function; and

presenting a de-identified copy of the element with the calculated value of the function,

wherein receiving the request to access the content of the element comprises:

accessing a stream of digital communication data sent by a first computing device to a second computing device; and

analyzing the stream to detect the request in the stream,

wherein excluding access to the first portion of the content of the element comprises:

accessing a second stream of digital communication data, the second stream of digital communication is a stream sent by the second computing device to the first computing device;

analyzing the second stream to detect information based on at least part of the first portion of the content of the element in the second stream; and

in response to a detection of the information based on the at least part of the first portion of the content of the element, blocking at least part of the second stream from reaching the first computing device.

2. The non-transitory computer readable medium of claim 1 , wherein the method further comprises:

in response to a third value in the permission record, providing access to synthetic information, the synthetic information is based on the content of the element.

3. The non-transitory computer readable medium of claim 1 , wherein the method further comprises:

in response to a third value in the permission record, providing statistical information based on the content of the element.

4. The non-transitory computer readable medium of claim 1 , wherein the method further comprises:

in response to a third value in the permission record, providing statistical information based on a selected portion of the content of the element.

5. The non-transitory computer readable medium of claim 1 , wherein the method further comprises:

in response to a third value in the permission record, denying access to the content of the element.

6. The non-transitory computer readable medium of claim 1 , wherein the method further comprises:

determining whether a third portion of the content of the element includes identifiable information;

in response to the first value in the permission record, providing access to the third portion of the content of the element;

in response to the second value in the permission record and a determination that the third portion of the content of the element includes identifiable information, denying access to the third portion of the content of the element; and

in response to the second value in the permission record and a determination that the third portion of the content of the element do not include identifiable information, providing access to the third portion of the content of the element.

7. The non-transitory computer readable medium of claim 1 , wherein the analysis of the stream is performed by a third computing device.

8. The non-transitory computer readable medium of claim 1 , wherein the analysis of the stream is performed by the second computing device.

9. The non-transitory computer readable medium of claim 1 , wherein excluding access to the first portion of the content of the element comprises:

modifying at least part of the stream of digital communication data to obtain a modified stream; and

providing the modified stream to the second computing device.

10. The non-transitory computer readable medium of claim 1 , wherein the method further comprises:

in response to the first value in the permission record, allowing at least part of the stream of digital communication data to reach the second computing device; and

in response to a third value in the permission record, blocking the at least part of the stream of digital communication data from reaching the second computing device.

11. The non-transitory computer readable medium of claim 1 , wherein the request to access the content of the element includes an indication of a requesting entity, and the method further comprises selecting the permission record corresponding to the element of a plurality of alternative permission records corresponding to the element based on the requesting entity.

12. The non-transitory computer readable medium of claim 1 , wherein the request to access the content of the element includes an indication of an intendent usage, and the method further comprises selecting the permission record corresponding to the element of a plurality of alternative permission records corresponding to the element based on the intendent usage.

13. The non-transitory computer readable medium of claim 1 , wherein the request to access the content of the element is a request to access the content of the element for a mathematical optimization of a function, and the method further comprises, in response to the second value in the permission record calculating an update information for the mathematical optimization of the second function calculated using the first portion of the content of the element, and providing the calculated update information.

14. The non-transitory computer readable medium of claim 1 , wherein the request to access the content of the element is a request to access the content of the element for a mathematical optimization of a function, and the method further comprises, in response to the second value in the permission record, calculating a value of a mathematical expression of a gradient of the second function calculated using the first portion of the content of the element, and providing the calculated value of the mathematical expression of the gradient.

15. The non-transitory computer readable medium of claim 1 , wherein the request to access the content of the element is a request to access the content of the element to determine a value of a function using the first portion of the content of the element, and the method further comprises, in response to the second value in the permission record, calculating a value of the second function calculated using the first portion of the content of the element, and providing the calculated value of the second function.

16. A system for controlling access to private medical information in privacy firewalls, the system comprising:

at least one processing unit configured to:

receive an input defining a function selected from a group consisting of a mathematical function, computer function, linear function, non-linear function, polynomial function, continuous function, discontinuous function, differentiable function, and non-differentiable function;

receive a request to access a content of an element, the content of the element includes at least a first portion and a second portion, the first portion includes identifiable information and the second portion does not include identifiable information;

access a permission record corresponding to the element;

in response to a first value in the permission record, provide access to the content of the element, including access to the first portion and the second portion of the content of the element; and

in response to a second value in the permission record:

provide partial access to the content of the element, the partial access includes access to the second portion of the content of the element and excludes access to the first portion of the content of the element;

cause a usage of an identified copy of the element to calculate a value of the function; and

cause presenting a de-identified copy of the element with the calculate value the function,

wherein receiving the request to access the content of the element comprises:

accessing a stream of digital communication data sent by a first computing device to a second computing device; and

analyzing the stream to detect the request in the stream,

wherein excluding access to the first portion of the content of the element comprises:

accessing a second stream of digital communication data, the second stream of digital communication is a stream sent by the second computing device to the first computing device;

analyzing the second stream to detect information based on at least part of the first portion of the content of the element in the second stream; and

in response to a detection of the information based on the at least part of the first portion of the content of the element, blocking at least part of the second stream from reaching the first computing device.

17. A method for controlling access to private medical information in privacy firewalls, the method comprising:

Receiving an input defining a function selected from a group consisting of a mathematical function, computer function, linear function, non-linear function, polynomial function, continuous function, discontinuous function, differentiable function, and non-differentiable function;

receiving a request to access a content of an element, the content of the element includes at least a first portion and a second portion, the first portion includes identifiable information and the second portion does not include identifiable information;

accessing a permission record corresponding to the element;

in response to a first value in the permission record, providing access to the content of the element, including access to the first portion and the second portion of the content of the element; and

in response to a second value in the permission record:

providing partial access to the content of the element, the partial access includes access to the second portion of the content of the element and excludes access to the first portion of the content of the element;

causing a usage of an identified copy of the element to calculate a value of the function; and

causing presenting a de-identified copy of the element with the calculated value of the function,

wherein receiving the request to access the content of the element comprises:

accessing a stream of digital communication data sent by a first computing device to a second computing device; and

analyzing the stream to detect the request in the stream,

wherein excluding access to the first portion of the content of the element comprises:

accessing a second stream of digital communication data, the second stream of digital communication is a stream sent by the second computing device to the first computing device;

analyzing the second stream to detect information based on at least part of the first portion of the content of the element in the second stream; and

in response to a detection of the information based on the at least part of the first portion of the content of the element, blocking at least part of the second stream from reaching the first computing device.

Assignments (2)
SECURITY INTEREST Recorded Nov 11, 2022
From: LYNX MD LTD.
To: SILICON VALLEY BANK
Reel/Frame 061730/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2021
From: DROR, OMER; FARCHY, OFIR
To: LYNX MD LTD
Reel/Frame 056475/0487 →
Continuity (3)
Provisional Application 63026154 · May 18, 2020
Provisional Application 62950188 · Dec 19, 2019
Related Publication 20210103678A1 · Apr 8, 2021
Cited By (1)
US 12,407,658