IP Library › Granted Patent US 12,107,960
Granted Patent B2
US 12,107,960 · App. 18/325,842 · Granted Oct 1, 2024

Secure and zero knowledge data sharing for cloud applications

Inventors: Amer Haider (Saratoga, CA); Ali Ahmed (Saratoga, CA)
Assignee: Masimo Corporation
H04L9/3221G06F16/951G06F21/14G06F21/6218G06F21/6227H04L9/0825H04L9/14H04L63/0428H04L63/06H04L67/10H04L2463/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,960
App. No.
18/325,842
Granted
Oct 1, 2024
Kind
B2
Abstract

Disclosed is a zero-knowledge distributed application configured to securely share information among groups of users having various roles, such as doctors and patients. Confidential information may be encrypted client-side, with private keys that reside solely client side. Encrypted collections of data may be uploaded to, and hosted by, a server that does not have access to keys suitable to decrypt the data. Other users may retrieve encrypted data from the server and decrypt some or all of the data with keys suitable to gain access to at least part of the encrypted data. The system includes a key hierarchy with multiple entry points to a top layer by which access is selectively granted to various users and keys may be recovered.

Claims (20)

1. A system for communicating patient data between a first computing device associated with a patient and second computing device associated with a care provider, the system comprising one or more hardware processors configured to:

request patient data over a network from a third computing system, wherein said patient data is encrypted with a first key and received from the first computing device without the first key, and wherein said third computing system does not have a decryption key to decrypt the patient data that is encrypted, wherein the second computing device is further configured to decrypt the encrypted data with a second key that is different than the first key and wherein the second key is a private key obtained by decrypting an encrypted private key (EPK) that was stored as part of a key hierarchy structure (KHS),

wherein the private key is obtained by decrypting an encrypted private key (EPK) that was stored as part of a key hierarchy structure (KHS).

2. The system of claim 1 , wherein the first key is a public key.

3. The system of claim 1 , wherein the first and the second keys are generated at a time of registration of the patient as a new user.

4. The system of claim 1 , wherein another KHS is created based on a request to generate shared data.

5. The system of claim 1 , wherein names of entries of the KHS are obfuscated.

6. A system for communicating patient data, the system comprising a computing system configured to:

store encrypted patient data associated with a patient without access to any decryption keys to decrypt the encrypted patient data, wherein the encrypted patient data is encrypted with a first key; and

transmit the encrypted patient data based on a request for stored patient data, wherein the encrypted patient data is decrypted with a second key that is different than the first key and wherein the second key is a private key,

wherein the private key is obtained by decrypting an encrypted private key (EPK) that was stored as part of a key hierarchy structure (KHS).

7. The system of claim 6 , wherein the first key is a public key.

8. The system of claim 6 , wherein the first and the second keys are generated at a time of registration of the patient as a new user.

9. The system of claim 6 , wherein names of entries of the KHS are obfuscated.

10. A method for communicating patient data, the method comprising:

storing encrypted patient data associated with a patient without access to any decryption keys to decrypt the encrypted patient data, wherein the encrypted patient data is encrypted with a first key; and

transmitting the encrypted patient data based on a request for stored patient data, wherein the encrypted patient data is decrypted with a second key that is different than the first key and wherein the second key is obtained by decrypting an encrypted private key (EPK) that was stored as part of a key hierarchy structure (KHS).

11. The method of claim 10 , wherein the first key is a public key.

12. The method of claim 10 , wherein the first and the second keys are generated at a time of registration of the patient as a new user.

13. The method of claim 10 , wherein names of entries of the KHS are obfuscated.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2026
From: HAIDER, AMER
To: MASIMO CORPORATION
Reel/Frame 075577/0946 →
Continuity (5)
Continuation 17500805 · Oct 13, 2021
Continuation 16834641 · Mar 30, 2020
Continuation 15642632 · Jul 6, 2017
Provisional Application 62358783 · Jul 6, 2016
Related Publication 20230388126A1 · Nov 30, 2023
Cited By (1)
US 12,750,228