IP Library Granted Patent US 12,210,636
Granted Patent B2
US 12,210,636 · App. 18/444,540 · Granted Jan 28, 2025

System and method for multiparty secure computing platform

Inventors: Edison U. Ortiz (Orlando, FL); Arya Pourtabatabaie (Orlando, FL); Ambica Pawan Khandavilli (Orlando, FL); Margaret Inez Salter (Orlando, FL); Jordan Alexander Richards (Orlando, FL); Iustina-Miruna Vintila (Bucharest, RO); David Ian McKay (Toronto, CA); Christoph Knoess (Sag Harbor, NY); Justin Simonelis (Toronto, CA)
Assignee: ROYAL BANK OF CANADA
G06F21/602G06F12/1408G06N20/00H04L9/0844H04L9/321H04L9/3247G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,210,636
App. No.
18/444,540
Granted
Jan 28, 2025
Kind
B2
Abstract

Systems, methods, and corresponding non-transitory computer readable media describe a proposed system adapted as a platform governing the loading of data in a multiparty secure computing environment. In the multiparty secure computing environment described herein, multiple parties are able to load their secure information into a data warehouse having specific secure processing adaptations that limit both access and interactions with data stored thereon.

Claims (35)

1. A computer implemented system for operating a trusted execution environment maintaining a segregated data processing subsystem:

a computer readable memory having a protected memory region that is encrypted such that it is inaccessible to both an operating system and kernel system, the protected memory region including at least a data storage region and a data processing subsystem storage region maintaining the segregated data processing subsystem;

a computer readable cache memory; and

a secure enclave data processor operating a data custodian data process for automated policy enforcement of one or more data protection policies, the data custodian data process configured to:

receive a query data object representing a proposed query to be operated on one or more protected database elements having access controlled by the segregated data processing subsystem on the protected memory region;

apply the one or more data protection policies operable on the query data object to determine whether the query data object adheres to the one or more data protection policies;

upon a determination that the query data object adheres to the one or more data protection policies, release one or more data protection keys; and

access the one or more protected database elements using the data protection keys and cause execution of the proposed query to receive a query response data object.

2. The system of claim 1 , wherein data stored on the one or more protected database elements are coupled with one or more data protection attributes to be adhered to prior to any release of the data, wherein the data includes at least one of web query data and purchase transaction data, and the one or more data protection attributes are represented in metadata indicative of a user's tracked privacy preferences.

3. The system of claim 2 , wherein the one or more data protection attributes includes restrictions on a type of query computation to be performed on the one or more protected database elements.

4. The system of claim 1 , wherein the release of the data protection keys includes generating a control message that includes one or more characteristics of the secure enclave data processor operating the data custodian data process, the control message used to trigger the release of the data protection keys.

5. The system of claim 4 , wherein the one or more characteristics of the secure enclave data processor include an identification or a hash representation of a version of a software operating the secure enclave data processor.

6. The system of claim 1 , wherein the control message includes an attestation token data object that includes a data exchange public key.

7. The system of claim 6 , wherein the data exchange public key is utilized to encrypt the query response data object to generate an encrypted output data object.

8. The system of claim 1 , wherein the one or more data protection policies include one or more data owner specific policies.

9. The system of claim 1 , wherein a subset of the one or more data protection policies are applied to the query response data object to validate that the query response data object adheres to the subset of the one or more data protection policies.

10. The system of claim 1 , wherein the one or more protected database elements are encrypted during times when the data is at rest on a server, during movement between a client and a server, and while the data is in use.

11. A computer implemented method for operating a trusted execution environment maintaining a segregated data processing subsystem coupled to a computer readable memory having a protected memory region that is encrypted such that it is inaccessible to both an operating system and kernel system, the protected memory region including at least a data storage region and a data processing subsystem storage region maintaining the segregated data processing subsystem; a computer readable cache memory; and a secure enclave data processor operating a data custodian data process for automated policy enforcement of one or more data protection policies, the method comprising:

receiving a query data object representing a proposed query to be operated on one or more protected database elements having access controlled by the segregated data processing subsystem on the protected memory region;

applying the one or more data protection policies operable on the query data object to determine whether the query data object adheres to the one or more data protection policies;

upon a determination that the query data object adheres to the one or more data protection policies, release one or more data protection keys; and

accessing the one or more protected database elements using the data protection keys and cause execution of the proposed query to receive a query response data object.

12. The method of claim 11 , wherein data stored on the one or more protected database elements are coupled with one or more data protection attributes to be adhered to prior to any release of the data; wherein the data includes at least one of web query data and purchase transaction data, and the one or more data protection attributes are represented in metadata indicative of a user's tracked privacy preferences.

13. The method of claim 12 , wherein the one or more data protection attributes includes restrictions on a type of query computation to be performed on the one or more protected database elements.

14. The method of claim 11 , wherein the release of the data protection keys includes generating a control message that includes one or more characteristics of the secure enclave data processor operating the data custodian data process.

15. The method of claim 14 , wherein the one or more characteristics of the secure enclave data processor include an identification or a hash representation of a version of a software operating the secure enclave data processor.

16. The method of claim 11 , wherein the control message includes an attestation token data object that includes a data exchange public key.

17. The method of claim 16 , wherein the data exchange public key is utilized to encrypt the query response data object to generate an encrypted output data object.

18. The method of claim 11 , wherein the one or more data protection policies include one or more data owner specific policies.

19. The method of claim 11 , wherein a subset of the one or more data protection policies are applied to the query response data object to validate that the query response data object adheres to the subset of the one or more data protection policies.

20. A non-transitory computer readable medium storing machine interpretable instructions, which when executed by a processor, cause the processor to perform a computer implemented method for operating a trusted execution environment maintaining a segregated data processing subsystem coupled to a computer readable memory having a protected memory region that is encrypted such that it is inaccessible to both an operating system and kernel system, the protected memory region including at least a data storage region and a data processing subsystem storage region maintaining the segregated data processing subsystem; a computer readable cache memory; and a secure enclave data processor operating a data custodian data process for automated policy enforcement of one or more data protection policies, the method comprising:

receiving a query data object representing a proposed query to be operated on one or more protected database elements having access controlled by the segregated data processing subsystem on the protected memory region;

applying the one or more data protection policies operable on the query data object to determine whether the query data object adheres to the one or more data protection policies;

upon a determination that the query data object adheres to the one or more data protection policies, releasing one or more data protection keys; and

accessing the one or more protected database elements using the data protection keys and cause execution of the proposed query to receive a query response data object.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2024
From: MCKAY, DAVID IAN; KNOESS, CHRISTOPH
To: ROYAL BANK OF CANADA
Reel/Frame 069422/0658 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2024
From: SIMONELIS, JUSTIN
To: ROYAL BANK OF CANADA
Reel/Frame 069422/0705 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2024
From: ORTIZ, EDISON U.; POURTABATABAIE, ARYA; KHANDAVILLI, AMBICA PAWAN; SALTER, MARGARET INEZ; RICHARDS, JORDAN ALEXANDER; VINTILA, IUSTINA-MIRUNA
To: ROYAL BANK OF CANADA
Reel/Frame 069422/0780 →
Continuity (15)
Continuation 17474012 · Sep 13, 2021
Continuation In Part 17169221 · Feb 5, 2021
Continuation 16424242 · May 28, 2019
Provisional Application 63189611 · May 17, 2021
Provisional Application 63164444 · Mar 22, 2021
Provisional Application 63141788 · Jan 26, 2021
Provisional Application 63130540 · Dec 24, 2020
Provisional Application 63077368 · Sep 11, 2020
Provisional Application 63077373 · Sep 11, 2020
Provisional Application 62824697 · Mar 27, 2019
Provisional Application 62806394 · Feb 15, 2019
Provisional Application 62697140 · Jul 12, 2018
Provisional Application 62691406 · Jun 28, 2018
Provisional Application 62677133 · May 28, 2018
Related Publication 20240249001A1 · Jul 25, 2024
References Cited (15)
US 8161527B2 · Curren · 2012 [cited by examiner]
US 9027102B2 · Katzer · 2015 [cited by examiner]
US 20030115476A1 · McKee · 2003 [cited by examiner]
US 20050289119A1 · Weinberg et al. · 2005 [cited by applicant]
US 20070011736A1 · Kalibjian · 2007 [cited by examiner]
US 20100251360A1 · Sinclair · 2010 [cited by examiner]
US 20110277038A1 · Sahita · 2011 [cited by examiner]
US 20150156174A1 · Fahey et al. · 2015 [cited by applicant]
US 20180096137A1 · Trostle et al. · 2018 [cited by applicant]
US 20180212939A1 · Costa · 2018 [cited by applicant]
US 20190042937A1 · Sheller et al. · 2019 [cited by applicant]
US 20200267152A1 · Zellweger · 2020 [cited by examiner]
United States Patent & Trademark Office (USPTO), Non Final Rejection issued to U.S. Appl. No. 17/474,007, filed Feb. 9, 2024. [cited by applicant]
Chen Guoxing Chen 4329@Osu et al.: “OPERA Open Remote Attestation for Intel's Secure Enclaves”, Designing Interactive Systems Conference, ACM, 2 Penn Plaza, Suit 710NewyorkNY 10121-0701USA, Nov. 6, 2019 (Nov. 6, 2019), … [cited by applicant]
European Search Opinion for EP 21865444 dated Aug. 16, 2024. [cited by applicant]
Cited By (1)
US 12,706,918