IP Library › Granted Patent US 12,244,726
Granted Patent B2
US 12,244,726 · App. 17/189,704 · Granted Mar 4, 2025

Data system with information provenance

Inventors: Taylor Hardin (Lebanon, NH); David Kotz (Lyme, NH)
Assignee: THE TRUSTEES OF DARTMOUTH COLLEGE
H04L9/3247H04L9/0637H04L9/0643H04L9/0825H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,726
App. No.
17/189,704
Granted
Mar 4, 2025
Kind
B2
Abstract

A secure, integrated data system and method users both blockchain and Trusted Execution Environment (TEE) technologies to achieve information provenance for data, particularly, mobile health device data. Using a blockchain to record and enforce data access policies removes the need to trust a single entity with gatekeeping the health data. Instead, participants form a consortium and collectively partake in verifying and enforcing access policies for data stored in private data silos. Data access and computation takes place inside of TEEs, which preserves data confidentiality and provides a verifiable attestation that can be stored on the blockchain for the purpose of information provenance.

Claims (28)

1. A system for maintaining information provenance of confidential data, comprising:

a device generating raw data;

a blockchain network storing smart contracts and provenance metadata; and

a trusted execution environment (TEE) network comprising hardware and software for providing secure execution of instructions stored in a computer-readable memory, said TEE network:

storing the raw data by:

receiving the raw data from the device;

encrypting the raw data to produce a new encrypted data;

storing the new encrypted data in a datastore; and

recording a first provenance metadata on the blockchain network, wherein the first provenance metadata comprises (1) a first hash of the raw data, (2) a first address of the new encrypted data in the datastore, (3) a first key encrypted form of a first encryption key that was used to encrypt the raw data, and (4) a first attestation report generated by a first TEE that stored the new encrypted data; and

performing computations on the new encrypted data in the datastore by:

verifying the first provenance metadata of the new encrypted data retrieved from the datastore in response to a computation request, executing confidential computations on the new encrypted data retrieved from the datastore and storing a result encrypted data in the datastore, wherein the result encrypted data comprises a confidential computation result, a second attestation report, and a list of input set data indexes; and

recording a second provenance metadata on the blockchain network, wherein the second provenance metadata comprises (1) a hash of the result encrypted data, (2) an address of the result encrypted data in the datastore, (3) a second key encrypted form of a second key that was used to encrypt the result encrypted data, and (4) a third attestation report generated by the TEE that stored the result encrypted data, for verifying a result of the confidential computations.

2. The system of claim 1 , further comprising a gateway device receiving the raw data from the device, adding a signature, and sending the raw data and the signature to the TEE network.

3. The system of claim 2 , wherein the gateway device further uploads the raw data into batches to send to the TEE network.

4. The system of claim 1 , wherein the blockchain network comprises a plurality of nodes maintained by a consortium.

5. The system of claim 1 , wherein verifying the first provenance metadata of the new encrypted data retrieved from the datastore further comprises:

receiving a request from an application to access the new encrypted data to perform a computation;

requesting the first provenance metadata from a blockchain interface;

checking whether the application has permission to access the new encrypted data and perform the computation;

when an application has the permission, the blockchain network provides the first provenance metadata, an encrypted computation program, and encrypted data keys;

verifying a signature of the application;

retrieving the new encrypted data from the datastore; and

decrypting the first encrypted key with a master data key, then decrypting the new encrypted data and the encrypted computation program using the decrypted first encrypting key and verifying hashes of the decrypted data.

6. The system of claim 1 , wherein the device for generating raw data is a mobile health device that monitors an aspect of a wearer's health during regular activities.

7. The system of claim 6 , wherein the mobile health device is a smart watch, heart rate monitor or glucose monitor.

8. The system of claim 2 , wherein the gateway device is a smart phone, smartwatch, tablet, laptop, or non-mobile device.

9. The system of claim 8 , wherein the signature added to the raw data by the gateway device identifies a wearer of the device.

10. The system of claim 1 , wherein TEE network is a secure computing environment resistant to privileged software attacks and hardware attacks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2024
From: HARDIN, TAYLOR; KOTZ, DAVID
To: THE TRUSTEES OF DARTMOUTH COLLEGE
Reel/Frame 069338/0713 →
Continuity (2)
Provisional Application 62984045 · Mar 2, 2020
Related Publication 20210273812A1 · Sep 2, 2021
References Cited (24)
US 20150335947A1 · Kaushansky · 2015 [cited by examiner]
US 20170319063A1 · Verdooner · 2017 [cited by examiner]
US 20190354693A1 · Yoon · 2019 [cited by examiner]
US 20200327250A1 · Wang · 2020 [cited by examiner]
CN 110661790 · 2019 [cited by examiner]
CN 110661790A · 2020 [cited by examiner]
Ayoade, Gbadebo “Decentralized IoT Data Management Using Blockchain and Trusted Execution Environment” [online] IEEE, Jul. 2018 [retrieved Jul. 15, 2023]. Retrieved from the Internet: URL: https://ieeexplore.ieee.org/do… [cited by examiner]
Zhang, Shifa “Genie: a Secure, Transparent Sharing and Services Platform for Genetic and Health Data” [online] Arxiv, Nov. 2018 [retrieved Jul. 15, 2023]. Retrieved from the Internet: URL: https://arxiv.org/pdf/1811.014… [cited by examiner]
Liang, Xueping “Towards Decentralized Accountability and Self-Sovereignty” [online] ResearchGate, Dec. 2017 [retrieved Jul. 15, 2023]. Retrieved from the Internet: URL: https://www.researchgate.net/publication/321137917… [cited by examiner]
Ayoade, Gbadebo “Decentralized IoT Data Management Using Blockchain and Trusted Execution Environment” [online] IEEE, Jul. 2018 [retrieved Jul. 15, 2023]. Retrieved from the Internet: URL: https://ieeexplore.ieee.org/do… [cited by examiner]
Janjua, Hassaan “Trusted Operations on Sensor Data” [online] MDPI, Apr. 2018 [retrieved Jul. 15, 2023]. Retrieved from the Internet: URL: https://www.mdpi.com/1424-8220/18/5/1364 (Year: 2018). [cited by examiner]
Greene et al., “Secure sharing of mHealth data streams through cryptographically-enforced access control,” [cited by applicant]
Chen et al., “Blockchain-Based Medical Records Secure Storage and Medical Service Framework,” [cited by applicant]
Dagher et al., “Ancile: Privacy-preserving framework for access control and interoperability of electronic health records using blockchain technology,” [cited by applicant]
Fan et al., “MedBlock: Efficient and Secure Medical Data Sharing Via Blockchain,” [cited by applicant]
Mense et al., “Concept for Sharing Distributed Personal Health Records with Blockchains,” [cited by applicant]
Wang et al., “Secure Cloud-Based EHR System Using Attribute-Based Cryptosystem and Blockchain,” [cited by applicant]
Liu et al., “BPDS: a Blockchain Based Privacy-Preserving Data Sharing for Electronic Medical Records,” IEEE Global Communications Conference, 2018—Proceedings. Institute of Electrical and Electronics Engineers Inc., Dec… [cited by applicant]
Mikula et al., “Identity and access management with blockchain in electronic healthcare records,” [cited by applicant]
Li et al., “Blockchain-Based Data Preservation System for Medical Data,” [cited by applicant]
Mohammadi et al., “CUREX: Secure and private health data exchange,” [cited by applicant]
Zhao et al., “Blockchain-based privacy-preserving remote data integrity checking scheme for IoT information systems,” [cited by applicant]
J. Li et al., “Blockchain-based public auditing for big data in cloud storage,” [cited by applicant]
Cheng et al., “Design of a Secure Medical Data Sharing Scheme Based on Blockchain,” [cited by applicant]