IP Library › Granted Patent US 12,730,930
Granted Patent B2
US 12,730,930 · App. 18/901,614 · Granted Sep 8, 2026

Using a secure enclave to satisfy retention and expungement requirements with respect to private data

Inventors: Sergey Yekhanin (Redmond, WA); Joshua Stanley Allen (Bellevue, WA); Ankit Srivastava (Bellevue, WA); Ralph Kennedy Johnston, Jr. (Renton, WA); Janardhan Dattatreya Kulkarni (Seattle, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/6245G06F21/602G06F21/78G06F21/86H04L9/0894H04L9/3247G06F2221/2101G06F2221/2149H04L2209/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,930
App. No.
18/901,614
Granted
Sep 8, 2026
Kind
B2
Abstract

Data may contain personal information and be subject to privacy requirements. The data may be encrypted and only a secure enclave may be able to decrypt the encrypted data. The secure enclave may be used to generate a report based on the encrypted data and a first set of added noise. The report may be subject to audit requirements and satisfy a differential privacy guarantee. The encrypted data may be stored for a first period. After the first period, the secure enclave may be used to generate a private synopsis based on the encrypted data and a second set of added noise. The private synopsis may satisfy the differential privacy guarantee. The private synopsis may be encrypted and only the secure enclave may be able to decrypt the encrypted private synopsis. The encrypted data may be expunged, and the encrypted private synopsis may be retained for a second period.

Claims (50)

1 . A method comprising:

storing data, wherein the data contains personal information of one or more individuals and is subject to privacy requirements;

encrypting the data such that the data becomes encrypted data, wherein only a secure enclave can decrypt the encrypted data using a first decryption key;

generating, by the secure enclave, a report based on the encrypted data and a first set of added noise, wherein the report is subject to audit requirements and satisfies a differential privacy guarantee;

storing the encrypted data for a first period of time;

aggregating, after the first period of time and by the secure enclave, the encrypted data and a second set of added noise to generate a private synopsis that satisfies the differential privacy guarantee;

encrypting the private synopsis to generate an encrypted private synopsis, wherein only the secure enclave can decrypt the encrypted private synopsis using a second decryption key;

expunging the encrypted data; and

retaining the encrypted private synopsis for a second period of time.

2 . The method of claim 1 , further comprising:

generating a revised report based on the report and the encrypted private synopsis.

3 . The method of claim 2 , wherein the revised report corrects an error in the report.

4 . The method of claim 2 , wherein the secure enclave generates the revised report.

5 . The method of claim 1 , wherein the first period of time is pre-defined based on the audit requirements or the privacy requirements and the second period of time is pre-defined based on the audit requirements.

6 . The method of claim 1 , wherein the differential privacy guarantee is pre-defined based on the privacy requirements.

7 . The method of claim 1 , wherein the private synopsis satisfies the audit requirements.

8 . The method of claim 1 , wherein the secure enclave generates the first decryption key and the second decryption key.

9 . A system comprising:

one or more processors;

memory in electronic communication with the one or more processors; and

instructions stored in the memory, the instructions being executable by the one or more processors to:

store data, wherein the data contains personal information of one or more individuals and is subject to privacy requirements;

encrypt the data such that the data becomes encrypted data, wherein only a secure enclave can decrypt the encrypted data using a first decryption key;

generate, by the secure enclave, a report based on the encrypted data and a first set of added noise, wherein the report is subject to audit requirements and satisfies a differential privacy guarantee;

store the encrypted data for a first period of time;

aggregate, after the first period of time and by the secure enclave, the encrypted data and a second set of added noise to generate a private synopsis that satisfies the differential privacy guarantee;

encrypt the private synopsis to generate an encrypted private synopsis, wherein only the secure enclave can decrypt the encrypted private synopsis using a second decryption key;

expunge the encrypted data; and

retain the encrypted private synopsis for a second period of time.

10 . The system of claim 9 , the instructions further being executable by the one or more processors to:

generate a revised report based on the report and the encrypted private synopsis.

11 . The system of claim 10 , wherein the revised report corrects an error in the report.

12 . The system of claim 10 , wherein the secure enclave generates the revised report.

13 . The system of claim 9 , wherein the first period of time is pre-defined based on the audit requirements or the privacy requirements and the second period of time is pre-defined based on the audit requirements.

14 . The system of claim 9 , wherein the differential privacy guarantee is pre-defined based on the privacy requirements.

15 . The system of claim 9 , wherein the private synopsis satisfies the audit requirements.

16 . The system of claim 9 , wherein the secure enclave generates the first decryption key and the second decryption key.

17 . A non-transitory computer-readable medium comprising instructions that are executable by one or more processors to cause a computing system to:

store data, wherein the data contains personal information of one or more individuals and is subject to privacy requirements;

encrypt the data such that the data becomes encrypted data, wherein only a secure enclave can decrypt the encrypted data using a first decryption key;

generate, by the secure enclave, a report based on the encrypted data and a first set of added noise, wherein the report is subject to audit requirements and satisfies a differential privacy guarantee;

store the encrypted data for a first period of time;

aggregate, after the first period of time and by the secure enclave, the encrypted data and a second set of added noise to generate a private synopsis that satisfies the differential privacy guarantee;

encrypt the private synopsis to generate an encrypted private synopsis, wherein only the secure enclave can decrypt the encrypted private synopsis using a second decryption key;

expunge the encrypted data; and

retain the encrypted private synopsis for a second period of time.

18 . The non-transitory computer-readable medium of claim 17 , further comprising additional instructions that are executable by the one or more processors to cause the computing system to:

generate a revised report based on the report and the encrypted private synopsis.

19 . The non-transitory computer-readable medium of claim 18 , wherein the revised report corrects an error in the report.

20 . The non-transitory computer-readable medium of claim 18 , wherein the secure enclave generates the revised report.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2024
From: YEKHANIN, SERGEY; ALLEN, JOSHUA STANLEY; SRIVASTAVA, ANKIT; JOHNSTON, RALPH KENNEDY, JR.; KULKARNI, JANARDHAN DATTATREYA
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 068740/0070 →
Continuity (3)
Division 17970148 · Oct 20, 2022
Division 15931020 · May 13, 2020
Related Publication 20250021689A1 · Jan 16, 2025
References Cited (15)
US 9584517B1 · Roth · 2017 [cited by examiner]
US 11288377B1 · Kopylov · 2022 [cited by examiner]
US 11341281B2 · Skourtis · 2022 [cited by examiner]
US 20020029280A1 · Holden · 2002 [cited by examiner]
US 20050065824A1 · Kohan · 2005 [cited by examiner]
US 20080120240A1 · Ginter · 2008 [cited by examiner]
US 20170323265A1 · Burrows · 2017 [cited by examiner]
US 20180096166A1 · Rogers · 2018 [cited by examiner]
US 20180287802A1 · Brickell · 2018 [cited by examiner]
US 20180301222A1 · Dew, Sr. · 2018 [cited by examiner]
US 20210240853A1 · Carlson · 2021 [cited by examiner]
US 20210357526A1 · Yekhanin · 2021 [cited by examiner]
US 20240289471A1 · Gomez · 2024 [cited by examiner]
Decision to Grant pursuant to Article 97(1) received in European Application No. 21724926.7, mailed on May 15, 2025, 2 pages. [cited by applicant]
Communication under Rule 71(3) Received in European Patent Application No. 21724926.7, mailed on Jan. 9, 2025, 07 pages. [cited by applicant]