IP Library › Granted Patent US 12,333,026
Granted Patent B2
US 12,333,026 · App. 18/403,885 · Granted Jun 17, 2025

System and method for secure electronic transaction platform

Inventors: Edison U. Ortiz (Orlando, FL); Arya Pourtabatabaie (Orlando, FL); Ambica Pawan Khandavilli (Orlando, FL); Margaret Inez Salter (Orlando, FL); Jordan Alexander Richards (Orlando, FL); Iustina-Miruna Vintila (Bucharest, RO)
Assignee: ROYAL BANK OF CANADA
G06F21/602G06F12/1408G06N20/00H04L9/0844H04L9/321H04L9/3247G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,333,026
App. No.
18/403,885
Granted
Jun 17, 2025
Kind
B2
Abstract

A system for processing data within a Trusted Execution Environment (TEE) of a processor is provided. The system may include: a trust manager unit for verifying identity of a partner and issuing a communication key to the partner upon said verification of identity; at least one interface for receiving encrypted data from the partner encrypted using the communication key; a secure database within the TEE for storing the encrypted data with a storage key and for preventing unauthorized access of the encrypted data within the TEE; and a recommendation engine for decrypting and analyzing the encrypted data to generate recommendations based on the decrypted data.

Claims (40)

1. A computer implemented system for maintaining a segregated data processing subsystem, the system comprising:

a computer readable memory having a protected memory region that is encrypted by a storage key such that the protected memory region is segregated relative to at least one of an operating system or a kernel system, the protected memory region including at least a data storage region and a data processing subsystem storage region;

a secure processor configured to provide:

a data receiver configured to separately receive, from each partner system of a plurality of partner systems, a data set corresponding to the partner system encrypted by a key corresponding to the partner system;

the data receiver configured to securely store, using the storage key, the encrypted data sets received from the plurality of partner systems within the data storage region of the protected memory region;

responsive to receiving a query data message relating to the encrypted data sets in the protected memory region, decrypt and store, the encrypted data sets within the data processing subsystem storage region of the protected memory region;

execute the query against the decrypted data sets, and

generate an output data structure generated based on the execution of the query against the decrypted data sets stored in the protected memory region.

2. The system of claim 1 , wherein the segregated data processing subsystem maintains a segregated machine learning data model architecture comprising interconnected computing nodes that operate in concert to generate the output data structure using at least a portion of the one or more data sets in the data storage region in the protected memory region as training sets or validation sets representing data from at least two computing devices of the plurality of computing devices.

3. The system of claim 2 , wherein the secure processor is configured to:

transmit to one or more sub processors a partition of the protected memory region;

and wherein the one or more sub processors are configured to process the corresponding partition of the protected memory region using a local copy of the machine learning data model architecture to generate one or more parameter update data structures, the one or more parameter update data structures are aggregated such that they can be used to refine at least one parameter of the machine learning data model architecture.

4. The system of claim 3 , wherein there are at least two sub processors, including a first sub processor and a second sub processor that are configured to transmit one or more parameter update data structures directly between one another to update the corresponding local copy of the machine learning data model architecture.

5. The system of claim 1 , wherein the data receiver is further configured to generate public/private key pairs each corresponding to a computing device of the one or more corresponding computing devices, and wherein the corresponding key is a private key corresponding to the corresponding computing device.

6. The system of claim 1 , wherein the protected memory region is encrypted using the storage key that is only accessible by a trusted execution environment operating on the secure processor during execution of a query as instructed in the query data message, the storage key not accessible by computing processes corresponding to the operating system or the kernel system.

7. The system of claim 1 , wherein the protected memory region is encrypted with the storage key that is only accessible to the secure processor and is inaccessible to administrator accounts of a system upon which the secure processor resides.

8. The system of claim 7 , wherein the storage key uses a unique endorsement key generated during manufacturing that is not accessible outside the secure processor.

9. The system of claim 1 , wherein a remote attestation process is periodically conducted by a secure processor, the remote attestation process including transmitting a remote attestation payload to the secure processor.

10. The system of claim 1 , wherein a remote attestation process is periodically conducted by the secure processor, and the remote attestation process including the secure processor generating a remote attestation transcript data structure.

11. A computer implemented method for a trusted execution environment maintaining a segregated data processing subsystem, the method operating on a computer readable memory having a protected memory region that is encrypted by a storage key such that it is segregated relative to at least one of an operating system or kernel system of a computing device implementing the trusted execution environment, the protected memory region including at least a data storage region and a data processing subsystem storage region, the method comprising:

receiving, from each partner system of a plurality of partner systems, a data set corresponding to the partner system encrypted by a key corresponding to the partner system;

securely storing, using the storage key, the encrypted data sets received from the plurality of partner systems within the data region of the protected memory region;

responsive to receiving a query data message relating to the encrypted data sets in the protected memory region, decrypting and storing, the encrypted data sets within the data processing subsystem storage region of the protected memory region;

executing the query against the decrypted data sets; and

generating, using processes running within the protected memory region, an output data structure based on the execution of the query against the decrypted data sets stored in the protected memory region.

12. The method of claim 11 , wherein the segregated data processing subsystem maintains a segregated machine learning data model architecture comprising a series of interconnected computing nodes that operate in concert to generate the output data structure responsive to the query data message using at least a portion of the one or more data sets into data storage region in the protected memory region as training sets or validation sets.

13. The method of claim 12 , comprising transmitting to one or more sub processors a partition of the protected memory region;

processing the corresponding partition of the protected memory region using a local copy of the machine learning data model architecture to generate one or more parameter update data structures used to refine at least one parameter of the machine learning data model architecture that are distributed to the one or more sub processors to update the corresponding local copy of the machine learning data model architecture.

14. The method of claim 11 , wherein the data receiver is further configured to generate public/private key pairs each corresponding to a computing device of the one or more corresponding computing devices; and wherein the corresponding key is the private key corresponding to the corresponding computing device.

15. The method of claim 11 , wherein the protected memory region is encrypted using the storage key that is only accessible by a trusted execution environment operating on the secure processor during execution of a query as instructed in the query data message, the storage key not accessible by computing processes corresponding to the operating system or the kernel system.

16. The method of claim 11 , wherein the protected memory region is encrypted with the storage key that is only accessible to the secure processor and is inaccessible to the administrator accounts of a system upon which the secure processor resides.

17. The method of claim 16 , wherein the storage key uses a unique endorsement key generated during manufacturing that is not accessible outside the secure processor.

18. The method of claim 11 , comprising periodically conducting a remote attestation, the remote attestation process including transmitting a remote attestation payload to the secure processor.

19. The method of claim 11 , comprising periodically conducting a remote attestation process, the remote attestation process including generating, by the secure processor, a remote attestation transcript data structure.

20. A non-transitory computer readable medium, storing machine interpretable instructions which when executed by a processor, cause the processor to perform a computer implemented method for a trusted execution environment maintaining a segregated data processing subsystem, the method operating on a computer readable memory having a protected memory region that is encrypted by a storage key such that it is segregated relative to at least one of an operating system or a kernel system of a computing device implementing the trusted execution environment, the protected memory region including at least a data storage region and a data processing subsystem storage region, the method comprising:

receiving, from each partner system of a plurality of partner systems, a data set corresponding to the partner system encrypted using a key corresponding to the partner system;

securely storing, using the storage key, the encrypted data sets received from the plurality of partner systems within the data region of the protected memory region;

responsive to receiving a query data message relating to the encrypted data sets in the protected memory region, decrypting and storing, the encrypted data sets within the data processing subsystem storage region of the protected memory region;

executing the query against the decrypted data sets; and

generating, using processes running within the protected memory region, an output data structure based on the execution of the query against the decrypted data sets stored in the protected memory region.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2025
From: ORTIZ, EDISON U.; POURTABATABAIE, ARYA; KHANDAVILLI, AMBICA PAWAN; SALTER, MARGARET INEZ; RICHARDS, JORDAN ALEXANDER; VINTILA, IUSTINA-MIRUNA
To: ROYAL BANK OF CANADA
Reel/Frame 070514/0235 →
Continuity (2)
Continuation In Part 17169221 · Feb 5, 2021
Related Publication 20240184898A1 · Jun 6, 2024
References Cited (76)
US 7401361B2 · Freeman · 2008 [cited by applicant]
US 7434068B2 · Nguyen · 2008 [cited by applicant]
US 7463739B2 · Couillard · 2008 [cited by applicant]
US 8190917B2 · Nutter · 2012 [cited by examiner]
US 8213618B2 · Dewan · 2012 [cited by examiner]
US 8219811B2 · Roundtree · 2012 [cited by applicant]
US 8316237B1 · Felsher · 2012 [cited by applicant]
US 8386798B2 · Dodgson · 2013 [cited by examiner]
US 8572410B1 · Tkacik · 2013 [cited by examiner]
US 8738932B2 · Lee · 2014 [cited by examiner]
US 8959615B2 · Nagai · 2015 [cited by applicant]
US 9258331B2 · Dyer · 2016 [cited by applicant]
US 10956585B2 · Ortiz · 2021 [cited by applicant]
US 11520913B2 · Boivie · 2022 [cited by applicant]
US 20030005322A1 · Kiiveri · 2003 [cited by applicant]
US 20070101434A1 · Jevans · 2007 [cited by applicant]
US 20080046760A1 · Nakazato · 2008 [cited by applicant]
US 20080263371A1 · Weissman · 2008 [cited by applicant]
US 20090151006A1 · Saeki · 2009 [cited by applicant]
US 20090187772A1 · Lange · 2009 [cited by examiner]
US 20100031370A1 · Ellison · 2010 [cited by applicant]
US 20100250935A1 · Ginter et al. · 2010 [cited by applicant]
US 20110082979A1 · Ramesh · 2011 [cited by examiner]
US 20120159195A1 · von Behren · 2012 [cited by applicant]
US 20120221866A1 · Flynn · 2012 [cited by applicant]
US 20130151848A1 · Baumann et al. · 2013 [cited by applicant]
US 20130173916A1 · Sato · 2013 [cited by examiner]
US 20130219507A1 · Chang · 2013 [cited by examiner]
US 20130276149A1 · Gremaud · 2013 [cited by applicant]
US 20130311789A1 · Johnson · 2013 [cited by applicant]
US 20140032934A1 · Nagai · 2014 [cited by applicant]
US 20140108805A1 · Smith · 2014 [cited by applicant]
US 20140157423A1 · Edelsten · 2014 [cited by applicant]
US 20150163206A1 · McCarthy · 2015 [cited by applicant]
US 20150220456A1 · Fel · 2015 [cited by applicant]
US 20150220737A1 · Rothman · 2015 [cited by applicant]
US 20160182465A1 · Lam · 2016 [cited by applicant]
US 20160204945A1 · Lange · 2016 [cited by examiner]
US 20170033930A1 · Costa et al. · 2017 [cited by applicant]
US 20170093806A1 · Phegade et al. · 2017 [cited by applicant]
US 20170243028A1 · Lafever et al. · 2017 [cited by applicant]
US 20170257365A1 · Gonzalez · 2017 [cited by applicant]
US 20170270509A1 · Colegate et al. · 2017 [cited by applicant]
US 20170372226A1 · Costa et al. · 2017 [cited by applicant]
US 20180359228A1 · Lerner · 2018 [cited by applicant]
US 20190036208A1 · Ortiz et al. · 2019 [cited by applicant]
US 20210203491A1 · Wei · 2021 [cited by applicant]
CN 1234892A · 1999 [cited by applicant]
CN 1700138A · 2005 [cited by applicant]
CN 102687133A · 2012 [cited by applicant]
CN 105745678A · 2016 [cited by applicant]
CN 106255984A · 2016 [cited by applicant]
CN 106416121A · 2017 [cited by applicant]
CN 107332671A · 2017 [cited by applicant]
WO 2015089171A1 · 2015 [cited by applicant]
United States Patent & Trademark Office (USPTO), Non Final Rejection issued to U.S. Appl. No. 17/169,221, filed Jan. 27, 2022. [cited by applicant]
China National Intellectual Property Administration (CNIPA), First Office Action issued to CN 2019800341609, Dec. 22, 2023. [cited by applicant]
Israeli Patent Office, Office Action issued to IL 277974, Mar. 20, 2023. [cited by applicant]
IP Australia, Examination report No. 1 issued to Application No. 2019277292, Aug. 10, 2023. [cited by applicant]
Japanese Patent Office (JPO), Notification of Reasons for Refusal to JP 2020-566967, May 23, 2023. [cited by applicant]
Intellectual Property India, First Examination Report to Application No. 202027052946, Jul. 7, 2022. [cited by applicant]
European Patent Office (EPO), Extended European Search Report to EP Application No. 19812339.0, Jan. 26, 2022. [cited by applicant]
International Search Report and Written Opinion issued in International Application No. PCT/CA2019/050725, dated Sep. 5, 2019. [cited by applicant]
Form PTO/SB/08a filed in U.S. Appl. No. 17/169,221, filed Nov. 10, 2023 approved by Examiner (4 pages). [cited by applicant]
Form PTO/SB/08a filed in U.S. Appl. No. 17/169,221, filed Aug. 23, 2023 approved by Examiner (4 pages). [cited by applicant]
Form PTO-892 related to U.S. Appl. No. 17/169,221, which was part of paper dated Aug. 11, 2023 (1 page). [cited by applicant]
Form PTO-892 related to U.S. Appl. No. 17/169,221, which was part of paper dated Jan. 11, 2023 (1 page). [cited by applicant]
Form PTO/SB/08a filed in U.S. Appl. No. 17/169,221, filed Jul. 8, 2022 approved by Examiner (4 pages). [cited by applicant]
Form PTO-892 related to U.S. Appl. No. 17/169,221, which was part of paper dated Jun. 22, 2022 (1 page). [cited by applicant]
Form PTO/SB/08a filed in U.S. Appl. No. 17/169,221, filed Apr. 25, 2022 approved by Examiner (4 pages). [cited by applicant]
Form PTO-892 related to U.S. Appl. No. 17/169,221, which was part of paper dated Jan. 23, 2022 (1 page). [cited by applicant]
Form PTO-892 related to U.S. Appl. No. 16/424,242, which was part of paper dated Oct. 30, 2020 (1 page). [cited by applicant]
Form PTO/SB/08a filed in U.S. Appl. No. 17/169,221, filed Nov. 26, 2019, and submitted as well in U.S. Appl. No. 17/169,221, filed Apr. 23, 2021 (3 pages). [cited by applicant]
Korean Intellectual Property Office (KIPO), Notice of Preliminary Rejection issued to KR 10-2020-7036669, Apr. 16, 2024. [cited by applicant]
European Patent Office (EPO), Communication from Examining Division issued to EP 19.812.339.0, Mar. 16, 2023. [cited by applicant]
John M. et al: “Intel Software Guard Extensions Tutorial Series: Part 1, Intel SGX Foundation”, Internet Citation, Jul. 7, 2016 (Jul. 7, 2016), XP002779031, Retrieved from the Internet: URL:https://software.intel.com/en… [cited by applicant]