IP Library › Granted Patent US 11,977,652
Granted Patent B2
US 11,977,652 · App. 17/543,908 · Granted May 7, 2024

Secure compartmented access infrastructure for sensitive databases

Inventor: Jonathan E. Magen (Jenkintown, PA)
Assignee: Evernorth Strategic Development, Inc.
G06F21/6218G06F21/53G06F2221/031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,977,652
App. No.
17/543,908
Granted
May 7, 2024
Kind
B2
Abstract

A system for providing compartmented access to secure data assets includes a mobile device, a secure access platform, and a secure data storage platform. The mobile device may be configured to generate a user interface configured to allow a user to input credentials and a request for a secure data asset on the secure data storage platform. The mobile device may transmit the credentials and the request to a secure access platform. The secure access platform may transmit the credentials to the secure data storage platform. The secure data storage platform may transfer a copy of the secure data assets to a data access module on the secure data access platform. The secure access platform may be configured to create an appling instance, receive the copy of the secure data assets, and transmit a response package based on the copy of the secure data access to the mobile device.

Claims (80)

1. A system for providing compartmented access to secure data assets, comprising:

a mobile device, comprising:

a first processor,

an input device,

a data analysis application, and

a first transceiver;

a secure access platform, comprising:

an authentication module,

a sandbox orchestrator,

a second processor,

an appling model catalog, and

a second transceiver; and

a secure data storage platform, comprising:

a third processor,

a secure data access module,

a secure database comprising a secure data asset, and

a third transceiver,

wherein the first processor, the input device, and the data analysis application are configured to generate a user interface configured to allow a user to input credentials and a request for the secure data asset,

wherein the first processor, the data analysis application, and the first transceiver are configured to:

transmit the credentials to the authentication module via the second transceiver, and

transmit the request for access to the sandbox orchestrator via the second transceiver,

wherein the second processor, the authentication module, and the second transceiver are configured to transmit the credentials to the secure data access module via the third transceiver,

wherein the third processor and the secure data access module are configured to transfer a copy of the secure data asset to the secure data access module,

wherein the second processor, the sandbox orchestrator, and the second transceiver are configured to:

generate a virtualization instance,

select an appling from the appling model catalog, and

create an appling instance of the selected appling in the virtualization instance, and

wherein the second processor, the sandbox orchestrator, the appling instance, and the second transceiver are configured to:

receive the copy of the secure data asset from the secure data access module,

format a response package based on the copy of the secure data asset, and

transmit the response package to the data analysis application via the first transceiver.

2. The system of claim 1 , wherein:

the secure database comprises a plurality of unauthorized data assets; and

the secure data access module is configured to:

determine that the credentials do not provide access to each of the plurality of unauthorized data asset, and

determine that the credentials provide access to the secure data asset.

3. The system of claim 2 , wherein the third processor and the secure data access module are configured to transfer a copy of the secure data asset to a secure storage partition.

4. The system of claim 1 , wherein the second processor, the sandbox orchestrator, the appling instance, and the second transceiver are configured to:

determine that the copy of the secure data asset contains a correct data type; and

in response to determining that the copy of the secure data asset contains the correct data type, format the response package to contain data extracted from the secure data asset.

5. The system of claim 4 , wherein the response package is formatted in a Fast Healthcare Interoperability Resources (FHIR) format.

6. The system of claim 1 , wherein the second processor, the sandbox orchestrator, the appling instance, and the second transceiver are configured to:

determine that the copy of the secure data asset does not contain a correct data type; and

in response to determining that the copy of the secure data asset does not contain the correct data type, format the response package to contain an error code.

7. The system of claim 1 , wherein the second processor, the authentication module, and the sandbox orchestrator are configured to close the appling instance in response to a condition.

8. The system of claim 7 , wherein the second processor, the authentication module, and the sandbox orchestrator are configured to close the virtualization instance in response to the condition.

9. The system of claim 8 , wherein the second processor, the authentication module, and the sandbox orchestrator are configured to send an erase signal to the secure data access module.

10. The system of claim 9 , wherein the third processor and the secure data access module are configured to purge the copy of the secure data asset from the secure data access module in response to the erase signal.

11. The system of claim 7 , wherein the condition comprises transmission, by the second processor, the sandbox orchestrator, the appling instance, and the second transceiver, of the response package.

12. The system of claim 7 , wherein the condition comprises a determination by the authentication module that a session of the data analysis application timed out.

13. The system of claim 7 , wherein the condition comprises a determination by the authentication module that a session of the data analysis application ended.

14. The system of claim 1 , wherein the second processor and the sandbox orchestrator are configured to:

generate a second virtualization instance;

select a second appling from the appling model catalog; and

create a second appling instance of the selected second appling in the second virtualization instance.

15. The system of claim 14 , wherein:

the virtualization instance is isolated from the second virtualization instance; and

the appling instance is isolated from the second appling instance.

16. The system of claim 15 , wherein the mobile device is isolated from the second virtualization instance and the second appling instance.

17. A method for providing compartmenting access to secure data assets, the method comprising:

transmitting credentials from a mobile device to an authentication module on a secure access platform;

transmitting a request for access from the mobile device to a sandbox orchestrator on the secure access platform;

transmitting the credentials from the authentication module to a secure data access module on a secure data storage platform;

determining, at the secure data access module, which of a plurality of secure data assets stored on a secure database the credentials provide access to;

transferring, to the secure data access module, selected data assets, wherein the selected data assets are the secure data assets that the credentials provide access to;

generating, at the secure access platform, a virtualization instance;

running, at the secure access platform, an appling instance in the virtualization instance;

receiving the selected data assets transmitted from the secure data access module using the appling instance;

formatting the selected data assets using the appling instance; and

transmitting the formatted selected data assets from the appling instance to the mobile device.

18. The method of claim 17 , wherein the formatted selected data assets are in a Fast Healthcare Interoperability Resources (FHIR) format.

19. The method of claim 17 , further comprising:

closing the appling instance in response to transmitting the formatted selected data assets from the appling instance to the mobile device; and

closing the virtualization instance in response to transmitting the formatted selected data assets from the appling instance to the mobile device.

20. The method of claim 17 , further comprising:

generating, at the secure access platform, a second virtualization instance; and

running, at the secure access platform, a second appling instance in the second virtualization instance,

wherein:

the virtualization instance is isolated from the second virtualization instance, and

the appling instance is isolated from the second appling instance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2021
From: MAGEN, JONATHAN E.
To: EVERNORTH STRATEGIC DEVELOPMENT, INC.
Reel/Frame 058316/0899 →
Continuity (1)
Related Publication 20230177192A1 · Jun 8, 2023