IP Library › Granted Patent US 12,462,059
Granted Patent B2
US 12,462,059 · App. 18/413,650 · Granted Nov 4, 2025

Method for managing data according to one or more privacy protection rules

Inventor: Philippe Miliau Georges Le Berre (Versoix, CH)
Assignee: CINDY L. WARNER
G06F21/6245G06F21/602H04L9/3073
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,059
App. No.
18/413,650
Granted
Nov 4, 2025
Kind
B2
Abstract

The present document discloses a system and a method for structuring and organising data, including personally identifiable information, into a set of databases. The system and method allow for an individual to whom the data relates to be able to share parts of the data with different third parties in a privacy-respecting manner, respecting any applicable legislation related to data privacy. Third parties thus only can access parts of the data which are relevant to them and they need to seek the consent of the individual in order to have access to any private information.

Claims (34)

1 . A computer-implemented method for managing data by a data storage provider at a data storage center according to one or more territory-specific privacy protection rules, said data related to a data subject and comprising private data and external data, said private data including personally identifiable information comprising one or more private attributes, the data subject is an identifiable natural person, the privacy protection rule depending on a nationality or residence of the data subject and/or a geographical location of a data source device in which at least part of said external data is generated or stored and/or a nationality or residence of the data storage provider or geographical location of the data storage center and/or a nationality or residence of an identifiable data processing entity with which said external data may be shared, said data subject having a unique, fixed, private identifier, said method comprising:

encrypting said private attributes under a secret key, the secret key is a private key of a private and public key pair according to a public-key cryptography algorithm, to form a private data record, identifiable by said private identifier, related to said data subject;

generating one or more protected data sets from the private data record, each protected data set corresponding to a scoped data domain, the scoped data domain is defined by a typology of the managed data and a geographical scope related to where the external data was generated or will be generated, each protected data set having a unique protected identifier derived from the private identifier and identifiable by a corresponding protected key derived from the secret key pair, the protected key is a private key of a private and public key pair according to a public-key cryptography algorithm, said generating of one or more protected data sets comprising, for each scoped data domain:

grouping a set of protected attributes into a protected data structure associated with the corresponding protected data set, said protected attributes comprising tokenized versions of the private attributes used to form the corresponding private data record; and

encrypting the protected attributes under the protected key;

the method further comprising, depending on one or more predetermined combinations of protected attributes present in the external data to be managed:

generating one restricted identifier per combination, each restricted identifier is based on:

the protected identifier of the scoped data domain to which the managed external data from the data source device belongs; and/or

one or more protected attribute identifiers of one or more protected attributes in the protected data structure in the scoped data domain to which the managed external data from the data source device belongs;

each restricted identifier is uniquely identifiable by a corresponding restricted key derived from the protected key pair of the protected identifier of the scoped data domain to which the managed external data from the data source device belongs, the restricted key is a private key of a private and public key pair according to a public-key cryptography algorithm; and

ingesting the external data from the data source device and replacing the protected attributes by their corresponding restricted identifiers, said ingested data thus shareable with the data processing entity according to the privacy protection rules.

2 . The method according to claim 1 , wherein at least one of said protected attributes is at least temporarily related to the data subject and is specific to the corresponding protected data structure in that it has no corresponding private attribute.

3 . The method according to claim 2 , wherein said privacy protection rule depends on a consent from the data subject for the identifiable data processing entity to access all or part of the data.

4 . The method according to claim 1 , wherein the protected key is derived for a particular scoped data domain from the secret key using a key derivation function.

5 . The method according to claim 1 , wherein the ingested external data is encrypted under the restricted key, said restricted key derived from the protected key and/or one or more relevant protected attribute identifiers using a key derivation function.

6 . The method according to claim 1 , wherein the private identifier is derived, by one or more processors of the data storage center, from a combination of at least a random or pseudo-random string uniquely attributed to the data subject on one hand and a nonce on the other hand.

7 . The method according to claim 1 , wherein the protected identifier is a unique identifier derived, by one or more processors of the data storage center, from a combination of at least the corresponding private identifier on one hand and a nonce on the other hand.

8 . The method according to claim 1 , wherein the protected attribute identifier is a unique identifier derived, by one or more processors of the data storage center, from a combination of at least the private identifier and a nonce.

9 . The method according to claim 7 , wherein the combination involves forming a digest.

10 . The method according to claim 9 , wherein the digest is produced using a one-way cryptographic function.

11 . The method according to claim 10 , wherein the one-way cryptographic function is a cryptographic hash function.

12 . The method according to claim 1 , wherein said data subject has been formally verified as who they claim to be.

13 . A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations to allow a data storage provider at a data storage center to manage data according to one or more territory-specific privacy protection rules, said data related to a data subject and comprising private data and external data, said private data including personally identifiable information comprising one or more private attributes, the data subject is an identifiable natural person, the privacy protection rule depending on a nationality or residence of the data subject and/or a geographical location of a data source device in which at least part of said external data is generated or stored and/or a nationality or residence of the data storage provider or geographical location of the data storage center and/or a nationality or residence of an identifiable data processing entity with which said external data may be shared, said data subject having a unique, fixed, private identifier, said managing comprising:

encrypting said private attributes under a secret key, the secret key is a private key of a private and public key pair according to a public-key cryptography algorithm, to form a private data record, identifiable by said private identifier, related to said data subject;

generating one or more protected data sets from the private data record, each protected data set corresponding to a scoped data domain, the scoped data domain defined by a typology of the managed data and a geographical scope related to where the external data was generated or will be generated, each protected data set having a unique protected identifier derived from the private identifier and is identifiable by a corresponding protected key derived from the secret key pair, the protected key is a private key of a private and public key pair according to a public-key cryptography algorithm, said generating of one or more protected data sets comprising, for each scoped data domain:

grouping a set of protected attributes into a protected data structure associated with the corresponding protected data set, said protected attributes comprising tokenized versions of the private attributes used to form the corresponding private data record; and

encrypting the protected attributes under the protected key;

the method further comprising, depending on one or more predetermined combinations of protected attributes present in the external data to be managed:

generating one restricted identifier per combination, each restricted identifier based on:

the protected identifier of the scoped data domain to which the managed external data from the data source device belongs; and/or

one or more protected attribute identifiers of one or more protected attributes in the protected data structure in the scoped data domain to which the managed external data from the data source device belongs;

each restricted identifier uniquely identifiable by a corresponding restricted key derived from the protected key pair of the protected identifier of the scoped data domain to which the managed external data from the data source device belongs, the restricted key is a private key of a private and public key pair according to a public-key cryptography algorithm; and

ingesting the external data from the data source device and replacing the protected attributes by their corresponding restricted identifiers, said ingested data thus shareable with the data processing entity according to the privacy protection rules.

14 . A computer system for managing external data from at least one data source device for conditional access by at least one identifiable data processing entity, comprising one or more computer processors, and the non-transitory machine-readable medium according to claim 13 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2024
From: LE BERRE, PHILIPPE MILIAU GEORGES
To: 360 OF ME, INC.
Reel/Frame 066138/0143 →
Continuity (1)
Related Publication 20250232057A1 · Jul 17, 2025
References Cited (41)
US 9202078B2 · Abuelsaad et al. · 2015 [cited by applicant]
US 9830476B2 · Fontecchio · 2017 [cited by applicant]
US 9973455B1 · Fowler · 2018 [cited by examiner]
US 9998435B1 · Kothari · 2018 [cited by applicant]
US 10769305B2 · Lowenberg et al. · 2020 [cited by applicant]
US 11023842B2 · Beaumont · 2021 [cited by examiner]
US 11036884B2 · Gkoulalas-Divanis · 2021 [cited by applicant]
US 11138337B2 · Yousfi et al. · 2021 [cited by applicant]
US 20180167201A1 · Naqvi · 2018 [cited by examiner]
US 20180307859A1 · LaFever · 2018 [cited by examiner]
US 20190238525A1 · Padmanabhan · 2019 [cited by examiner]
US 20200186506A1 · Shockley · 2020 [cited by examiner]
US 20200311304A1 · Parthasarathy · 2020 [cited by examiner]
US 20200327250A1 · Wang · 2020 [cited by examiner]
US 20200402625A1 · Aravamudan · 2020 [cited by examiner]
US 20200403795A1 · Murdoch · 2020 [cited by examiner]
US 20210026982A1 · Amarendran · 2021 [cited by examiner]
US 20210209251A1 · Parthasarathy · 2021 [cited by examiner]
US 20220147645A1 · Linde · 2022 [cited by examiner]
US 20220222373A1 · Villax · 2022 [cited by examiner]
US 20220321335A1 · Lum · 2022 [cited by examiner]
US 20230161900A1 · Boutros · 2023 [cited by examiner]
US 20230195933A1 · Satish Padmanabhan · 2023 [cited by examiner]
US 20230299938A9 · Dai · 2023 [cited by examiner]
US 20240070324A1 · Cuellar Jaramillo · 2024 [cited by examiner]
US 20240202725A1 · Anapliotis · 2024 [cited by examiner]
CN 106716914A · 2017 [cited by examiner]
CN 109559117A · 2019 [cited by examiner]
CN 113973508B · 2023 [cited by examiner]
JP 7439125B2 · 2024 [cited by examiner]
WO WO2018201009A1 · 2018 [cited by examiner]
WO WO2019246568A1 · 2019 [cited by examiner]
WO WO2021204313A1 · 2021 [cited by examiner]
WO WO2024069562A1 · 2024 [cited by examiner]
WO WO2024100425A1 · 2024 [cited by examiner]
Samson Esayas,“The Role of Anonymisation and Pseudonymisation Under the EU Data Privacy Rules”, European Journal of Law and Technology, vol. 6, No. 2, 2015 , 23 Pages Posted: Mar. 13, 2016 (Year: 2015). [cited by examiner]
Sophie Stalla-Bourdillon and Alison Knight, “Anonymous Data V. Personal Data—A False Debate: An EE Perspective on Anonymization, Pseudonymization and Personal Data,” 38 pages (Year: 2016). [cited by examiner]
Joana Ferreira Marques, “Analysis of Data Anonymization Techniques”, 1Polytechnic Institute of Coimbra, Coimbra Institute of Engineering, Rua Pedro Nunes, 3030-199 Coimbra, Portugal, (Year: 2020). [cited by examiner]
Sérgio Luís Ribeiro, “Privacy Protection with Pseudonymization and Anonymization In a Health IoT System”, Published in: 2019 IEEE 19th International Conference on Bioinformatics and Bioengineering (BIBE), Date of Confer… [cited by examiner]
Shukor Abd Razak, “Data Anonymization Using Pseudonym System to Preserve Data Privacy”, Published in: IEEE Access (vol. 8), pp. 43256-43264, Date of Publication: Feb. 28, 2020 , 9 pages (Year: 2020). [cited by examiner]
Hao Jin, “A Review of Secure and Privacy-Preserving Medical Data Sharing”, Published in: IEEE Access (vol. 7) pp. 61656-61669, Date of Publication: May 14, 2019 (Year: 2019). [cited by examiner]