IP Library › Granted Patent US 12,277,238
Granted Patent B2
US 12,277,238 · App. 17/844,292 · Granted Apr 15, 2025

System and method for controlling data using containers

Inventor: Alan Rodriguez (Dallas, TX)
Assignee: Alan Rodriguez
G06F21/62G06F21/78H04L9/30G06F2221/2101H04L2209/16H04L2209/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,277,238
App. No.
17/844,292
Granted
Apr 15, 2025
Kind
B2
Abstract

An electronic device for managing secured data containers, the electronic device comprising at least one network interface, at least one memory storing executable instructions, and at least one processor coupled to the at least one network interface and the at least one memory. Execution of the executable instructions by the at least one processor causes the electronic device to receive a request for data container creation, retrieve data related to the request for data container creation, retrieve one or more parameters constraining use of the data, encrypt the data using a public encryption key, encode the encrypted data into a data storage area of a data container, encode the one or more parameters constraining use of the data into a machine readable parameter storage area of the data container, and assign a UUID to the data container.

Claims (129)

1. An electronic device for managing secured data containers,

the electronic device comprising:

at least one network interface;

at least one memory storing executable instructions; and

at least one processor coupled to the at least one network interface and the at least one memory, wherein execution of the executable instructions by the at least one processor causes the electronic device to:

receive, via the network interface from another electronic device, an access request related to data in a data container;

determine to grant the access request based on one or more parameters constraining use of the data;

perform privacy enhancement using the data in the data container, wherein the privacy enhancement is performed using zero-knowledge proofs to:

retrieve the data container and extract one or more data values from the data container;

determine information needed from the data container for the access request;

using the extracted one or more data values, transmit an answer to the other electronic device;

receive a request for a proof; and

in response to the request for the proof:

manipulate the extracted one or more data values and transfer a result of the manipulation of the extracted one or more data values to the other electronic device;

select a random value, manipulate the random value, and transmit a result of the manipulation of the random value to the other electronic device;

receive a request for one of a plurality of calculation results and transmit a result of the one of the plurality of calculation results to the other electronic device; and

receive confirmation of proof from the other electronic device.

2. The electronic device of claim 1 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

perform the privacy enhancement further using one or more of:

homomorphic encryption;

secure enclaves;

differential privacy;

federated analysis; or

secure multiparty computation.

3. The electronic device of claim 2 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

perform the privacy enhancement further using the differential privacy, wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

retrieve the data container and extract the data from the data container;

introduce noise into the data to create noisy data;

output a result using the noisy data; and

transmit the result to the other electronic device.

4. The electronic device of claim 3 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

perform the privacy enhancement further using the federated analysis, wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

retrieve the data container and extract the data from the data container;

analyze the extracted data and determine an output using the extracted data;

discard the extracted data;

obtain one or more other outputs from one or more other data sources without commingling the data from the container and data from the one or more other data sources;

generate, using the determined output and the one or more other outputs, a final result; and

transmit the final result to the other electronic device.

5. The electronic device of claim 2 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

perform the privacy enhancement further using the homomorphic encryption, wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

retrieve the data container, wherein the data container is encrypted using an encryption key;

perform an operation on the encrypted data container to generate a second encrypted data container; and

transmit the second encrypted data container to the other electronic device, wherein the other electronic device either requests decryption of the second encrypted data container using a decryption key or decrypts the second encrypted data container using a decryption key available to the other electronic device.

6. The electronic device of claim 2 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

determine to grant the access request based on the one or more parameters constraining use of the data and based on at least one of a requester identity, temporal parameters, location parameters, functional parameters, proxy parameters, tracking parameters, aggregation parameters, and duration parameters; and

log a result of the access request in an audit log.

7. The electronic device of claim 6 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

perform the privacy enhancement further using the secure multiparty computation, wherein execution of the executable instructions by the at least one processor further causes the electronic device to:

retrieve the data container and extract the data from the data container;

randomly manipulate the extracted data one or more times;

containerize the randomly manipulated data and share the containerized randomly manipulated data with one or more third party devices;

receive one or more other containers of other randomly manipulated data from the one or more third party devices;

perform a calculation on the extracted data, the randomly manipulated data, and the other randomly manipulated data to generate an intermediate result;

transmit the intermediate result to the one or more third party devices;

receive one or more other intermediate results from the one or more third party devices;

determine an answer to the access request based on the intermediate result and the other intermediate results; and

transmit the answer to the other electronic device.

8. The electronic device of claim 6 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to provide, in response to the grant of the access request, one or more obfuscated results without providing any of the data from the data container.

9. The electronic device of claim 1 , wherein execution of the executable instructions by the at least one processor further causes the electronic device to create a record associated with the data container in a graph database accessible by the electronic device, wherein the graph database defines relationships between the data container and one or more other data containers and defines access permissions to the data container in accordance with the one or more parameters constraining use of the data.

10. A method of an electronic device for managing secured data containers, the method comprising:

receiving an access request, from another electronic device, related to data in a data container;

determining to grant the access request based on one or more parameters constraining use of the data;

performing privacy enhancement using the data in the data container, wherein the privacy enhancement is performed using zero-knowledge proofs, including:

retrieving the data container and extract one or more data values from the data container;

determining information needed from the data container for the access request;

using the extracted one or more data values, transmitting an answer to the other electronic device;

receiving a request for a proof; and

in response to the request for the proof:

manipulating the extracted one or more data values and transferring a result of the manipulation of the extracted one or more data values to the other electronic device;

selecting a random value, manipulate the random value, and transmit a result of the manipulation of the random value to the other electronic device;

receiving a request for one of a plurality of calculation results and transmit a result of the one of the plurality of calculation results to the other electronic device; and

receiving confirmation of proof from the other electronic device.

11. The method of claim 10 , further comprising:

performing the privacy enhancement further using one or more of:

homomorphic encryption;

secure enclaves;

differential privacy;

federated analysis; or

secure multiparty computation.

12. The method of claim 11 , further comprising:

performing the privacy enhancement further using the differential privacy, including:

retrieving the data container and extract the data from the data container;

introducing noise into the data to create noisy data;

outputting a result using the noisy data; and

transmitting the result to the other electronic device.

13. The method of claim 12 , further comprising:

performing the privacy enhancement further using the federated analysis, including:

retrieving the data container and extracting the data from the data container;

analyzing the extracted data and determining an output using the extracted data;

discarding the extracted data;

obtaining one or more other outputs from one or more other data sources without commingling the data from the container and data from the one or more other data sources;

generating, using the determined output and the one or more other outputs, a final result; and

transmitting the final result to the other electronic device.

14. The method of claim 11 , further comprising:

performing the privacy enhancement further using the homomorphic encryption, including:

retrieving the data container, wherein the data container is encrypted using an encryption key;

performing an operation on the encrypted data container to generate a second encrypted data container; and

transmitting the second encrypted data container to the other electronic device, wherein the other electronic device either requests decryption of the second encrypted data container using a decryption key or decrypts the second encrypted data container using a decryption key available to the other electronic device.

15. The method of claim 11 , further comprising:

determining to grant the access request based on the one or more parameters constraining use of the data and based on at least one of a requester identity, temporal parameters, location parameters, functional parameters, proxy parameters, tracking parameters, aggregation parameters, and duration parameters; and

logging a result of the access request in an audit log.

16. The method of claim 15 , further comprising:

performing the privacy enhancement further using the secure multiparty computation, including:

retrieving the data container and extract the data from the data container;

randomly manipulating the extracted data one or more times;

containerizing the randomly manipulated data and sharing the containerized randomly manipulated data with one or more third party devices;

receiving one or more other containers of other randomly manipulated data from the one or more third party devices;

performing a calculation on the extracted data, the randomly manipulated data, and the other randomly manipulated data to generate an intermediate result;

transmitting the intermediate result to the one or more third party devices;

receiving one or more other intermediate results from the one or more third party devices;

determining an answer to the access request based on the intermediate result and the other intermediate results; and

transmitting the answer to the other electronic device.

17. The method of claim 15 , further comprising providing, in response to granting the access request, one or more obfuscated results without providing any of the data from the data container.

18. The method of claim 10 , further comprising creating a record associated with the data container in a graph database accessible by the electronic device, wherein the graph database defines relationships between the data container and one or more other data containers and defines access permissions to the data container in accordance with the one or more parameters constraining use of the data.

19. A method of an electronic device for managing secured data containers, the method comprising:

receiving an access request, from another electronic device, related to data in a data container;

determining to grant the access request based on one or more parameters constraining use of the data and based on at least one of a requester identity, temporal parameters, location parameters, functional parameters, proxy parameters, tracking parameters, aggregation parameters, and duration parameters;

logging a result of the access request in an audit log; and

performing privacy enhancement using the data in the data container and using secure multiparty computation, including:

retrieving the data container and extract the data from the data container;

randomly manipulating the extracted data one or more times;

containerizing the randomly manipulated data and sharing the containerized randomly manipulated data with one or more third party devices;

receiving one or more other containers of other randomly manipulated data from the one or more third party devices;

performing a calculation on the extracted data, the randomly manipulated data, and the other randomly manipulated data to generate an intermediate result;

transmitting the intermediate result to the one or more third party devices;

receiving one or more other intermediate results from the one or more third party devices;

determining an answer to the access request based on the intermediate result and the other intermediate results; and

transmitting the answer to the other electronic device.

20. The method of claim 19 , further comprising providing, in response to granting the access request, one or more obfuscated results without providing any of the data from the data container.

Continuity (3)
Continuation 17326592 · May 21, 2021
Provisional Application 63126580 · Dec 17, 2020
Related Publication 20230147698A1 · May 11, 2023
References Cited (63)
US 6778826B2 · Rankin · 2004 [cited by applicant]
US 6826574B1 · Colbath · 2004 [cited by applicant]
US 7630986B1 · Herz et al. · 2009 [cited by applicant]
US 7899706B1 · Stone et al. · 2011 [cited by applicant]
US 7966369B1 · Briere et al. · 2011 [cited by applicant]
US 8005722B2 · Hutchison et al. · 2011 [cited by applicant]
US 8200527B1 · Thompson et al. · 2012 [cited by applicant]
US 8880100B2 · Dobyns · 2014 [cited by applicant]
US 9032544B2 · Shelton · 2015 [cited by applicant]
US 9191509B2 · Jones et al. · 2015 [cited by applicant]
US 9400985B2 · Dobyns · 2016 [cited by applicant]
US 9411967B2 · Parecki et al. · 2016 [cited by applicant]
US 9600834B2 · Kilroy et al. · 2017 [cited by applicant]
US 9811806B1 · Kuang · 2017 [cited by examiner]
US 10187443B2 · Gong et al. · 2019 [cited by applicant]
US 10521605B1 · Scuderi · 2019 [cited by examiner]
US 20020013850A1 · Mitchell et al. · 2002 [cited by applicant]
US 20020026394A1 · Savage et al. · 2002 [cited by applicant]
US 20030130893A1 · Farmer · 2003 [cited by applicant]
US 20040098285A1 · Breslin et al. · 2004 [cited by applicant]
US 20040153908A1 · Schiavone et al. · 2004 [cited by applicant]
US 20050164704A1 · Winsor · 2005 [cited by applicant]
US 20060074727A1 · Briere · 2006 [cited by applicant]
US 20060195441A1 · Julia et al. · 2006 [cited by applicant]
US 20060195595A1 · Mendez et al. · 2006 [cited by applicant]
US 20070192121A1 · Routson · 2007 [cited by applicant]
US 20070204329A1 · Peckover · 2007 [cited by applicant]
US 20070276759A1 · Ginter et al. · 2007 [cited by applicant]
US 20090049469A1 · Small et al. · 2009 [cited by applicant]
US 20090083032A1 · Jablokov et al. · 2009 [cited by applicant]
US 20090113319A1 · Dawson et al. · 2009 [cited by applicant]
US 20090132395A1 · Lam et al. · 2009 [cited by applicant]
US 20090248680A1 · Kalavade · 2009 [cited by applicant]
US 20090254511A1 · Yeap et al. · 2009 [cited by applicant]
US 20100010916A1 · Hutchison et al. · 2010 [cited by applicant]
US 20100199042A1 · Bates et al. · 2010 [cited by applicant]
US 20110276494A1 · Hutchison et al. · 2011 [cited by applicant]
US 20110289566A1 · Resch et al. · 2011 [cited by applicant]
US 20130332362A1 · Ciurea · 2013 [cited by applicant]
US 20140047556A1 · Davis · 2014 [cited by examiner]
US 20140090021A1 · Berkovitz et al. · 2014 [cited by applicant]
US 20140208154A1 · Gladwin et al. · 2014 [cited by applicant]
US 20140310788A1 · Ricci · 2014 [cited by applicant]
US 20140344015A1 · Puértolas-Montañés et al. · 2014 [cited by applicant]
US 20150143129A1 · Duffy · 2015 [cited by applicant]
US 20170041296A1 · Ford et al. · 2017 [cited by applicant]
US 20170255912A1 · Casebolt · 2017 [cited by applicant]
US 20180137292A1 · Sanso · 2018 [cited by examiner]
US 20190158558A1 · Gong et al. · 2019 [cited by applicant]
US 20190347701A1 · Viljoen et al. · 2019 [cited by applicant]
US 20200125744A1 · Smith et al. · 2020 [cited by applicant]
US 20200134207A1 · Doshi · 2020 [cited by examiner]
US 20200351323A1 · Gong et al. · 2020 [cited by applicant]
US 20220004649A1 · Smith et al. · 2022 [cited by applicant]
JP 2001101274A · 2001 [cited by applicant]
WO 9802835A1 · 1998 [cited by applicant]
WO 2010027517A3 · 2010 [cited by applicant]
Blake et al., The Next Generation of Data-Sharing in Financial Services: Using Privacy Enhancing Techniques to Unlock New Value, World Economic Forum, Sep. 2019, retrieved from http://www3.weforum.org/docs/WEF_Next_Gen_… [cited by applicant]
Department of Homeland Security Management Directive System, MD No. 11042.1, Safeguarding Sensitive but Unclassified (For Official Use Only) Information, Jan. 6, 2005. https://www.dhs.gov/xlibrary/assets/foia/mgmt_direc… [cited by applicant]
Patent Cooperation Treaty: International Search Report and Written Opinion of Related Application PCT/US21/63938; Kari Rodriguez; Mar. 16, 2022; 9 pages. [cited by applicant]
Shinseki et al., Department of the Army Information Security Program, Army Regulation 380-5, Washington, DC, Sep. 29, 2000, 311 pages, retrieved online Nov. 9, 2019 from https://fas.org/irp/doddir/army/ar380-5.pdf (2000… [cited by applicant]
SQLite, SQLite As An Application File Format, Retrieved Mar. 1, 2021 from https://www.sqlite.org/appfileformat.html. [cited by applicant]
Patent Cooperation Treat: International Preliminary Report on Patentability for PCT/US2021/063938; Miki Kobayashi; Jun. 29, 2023; 8 pages. [cited by applicant]