Systems and methods for use in neutral zone execution of logic
Systems and methods are provided for executing logic to provide data aggregates. One example method includes receiving, at a computing device of a service provider, from a relying party, a request for a data aggregate for a user based on a logic, where the data aggregate is based on first data for the user, and identifying a control for the first data. The method further includes, upon satisfying the identified control, retrieving, by the computing device, the first data from a first source party, generating a neutral zone, and executing, in the neutral zone, the logic on the retrieved first data. The method then includes providing an output from the executed logic as the data aggregate to the relying party, but not the first data, whereby the data aggregate is provided in lieu of the first data. And, the retrieved first data is deleted by eliminating the neutral zone.
1 . A computer-implemented method for use in executing logic to secure personal identifying information and to provide data aggregates, the method comprising:
receiving, at a computing device of a service provider, from a relying party, a request to provide a score based on an aggregation of personal identifying information (PII) of a user, without providing the PII of the user upon which the score is based, wherein the score is defined by a logic and wherein the logic is defined by the relying party;
identifying a control associated with first data, the first data including at least a first portion of the PII;
in response to the request, automatically generating, by the computing device, an isolated neutral zone as an on-demand virtual machine that is separate from the computing device of the service provider, the isolated neutral zone including the logic;
based on satisfying the identified control, retrieving, by the computing device, the first data from a first source party and passing the first data into the neutral zone, the first source party separate from the service provider and the relying party;
retrieving, by the computing device, second data from a second source party and passing the second data into the neutral zone, the second data including at least a second portion of the PII, the second source party separate from the service provider, the relying party, and the first source party;
temporarily storing, in the isolated neutral zone, the first data and the second data;
executing, exclusively within the isolated neutral zone, by the on-demand virtual machine, the logic on the temporarily stored PII in the neutral zone, by assigning points for multiple parameters of the PII and aggregating the assigned points to calculate the score;
transmitting, by the computing device, the score to the relying party, while restricting the PII from being provided to the relying party; and
after executing the logic and transmitting the score, deleting the neutral zone to delete the temporarily stored PII and the logic from the on-demand virtual machine, thereby preventing subsequent access to the PII from the on-demand virtual machine.
2 . The computer-implemented method of claim 1 , wherein identifying the control associated with the first data include identifying the control based on a data container, the data container including multiple tiers; and
wherein one of the multiple tiers is associated with the first data and wherein the control is linked to said one of the multiple tiers.
3 . The computer-implemented method of claim 1 , wherein the request includes the logic.
4 . The computer-implemented method of claim 1 , wherein the request includes an identifier of the logic, in lieu of the logic.
5 . A system for use in executing logic to secure personal identifying information and to provide data aggregates for users, the system comprising a service provider having at least one computing device configured to:
receive, from a relying party, a request to provide a score, which is based on an aggregation of personal identifying information (PII) of a user, without providing the PII of the user upon which the score is based, wherein the score is defined by a logic and wherein the logic is defined by the relying party;
identify a control associated with first data, wherein the first data includes at least a first portion of the PII;
in response to the request, automatically generate an isolated neutral zone as an on-demand virtual machine that is separate from the at least one computing device of the service provider, wherein the isolated neutral zone includes the logic;
upon satisfying the identified control, retrieve the first data from a first source party and pass the first data into the neutral zone, whereby the first data is stored in the neutral zone;
retrieve second data from a second source party and pass the second data into the neutral zone, wherein the second data includes at least a second portion of the PII, whereby the second data is stored in the neutral zone;
temporarily store the first data and the second data in the isolated neutral zone;
execute, exclusively within the isolated neutral zone, the logic on the temporarily stored PII, by assigning points for multiple parameters of the temporarily stored PII and aggregating the assigned points to calculate the score;
transmit the score, to the relying party in response to the request, while restricting the PII from being provided to the relying party; and
after executing the logic and transmitting the score, delete the neutral zone to delete the temporarily stored PII and the logic from the on-demand virtual machine, thereby preventing subsequent access to the PII from the on-demand virtual machine.
6 . The system of claim 5 , wherein the request includes the logic.
7 . The system of claim 5 , wherein that at least one computing device is configured, in order to identify the control associated with the first data, to identify the control based on a data container; and
wherein the data container includes multiple tiers of data, and wherein one of the multiple tiers is associated with the first data and wherein the control is linked to said one of the multiple tiers.
8 . The system of claim 5 , wherein the request includes an identifier of the logic, in lieu of the logic.
9 . The system of claim 5 , wherein the at least one computing device is further configured to:
transmit a request for a biometric authentication to a communication device associated with the user;
verify a response, from the user via the communication device, to the request for the biometric authentication; and
in response to verification of the response from the user, retrieve the first data from the first source party.