Homomorphic encryption in a healthcare network environment, system and methods

Inventors

Soon-Shiong, PatrickKupwade-Patil, HarshSeshadri, RaviWitchey, Nicholas J.

Assignees

Nant Holdings IP LLCNantworks LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11632358-B2

Patent

Publication Date

2023-04-18

Expiration Date


Abstract

A system and method for homomorphic encryption in a healthcare network environment is provided and includes receiving digital data over the healthcare network at a data custodian server in a plurality of formats from various data sources, encrypting the data according to a homomorphic encryption scheme, receiving a query at the data custodian server from a data consumer device concerning a portion of the encrypted data, initiating a secure homomorphic work session between the data custodian server and the data consumer device, generating a homomorphic work space associated with the homomorphic work session, compiling, by the data custodian server, a results set satisfying the query, loading the results set into the homomorphic work space, and building an application programming interface (API) compatible with the results set, the API facilitating encrypted analysis on the results set in the homomorphic work space.

Core Innovation

The disclosure describes establishing proof of a statement through the use of homomorphic encryption in a secure work session over a network between a first computing device and a second computing device. A homomorphic encryption memory area is allocated for use by the secure work session, and homomorphically encrypted data indicative of proof of the statement is loaded into the homomorphic encryption memory area. The homomorphically encrypted data is accessible to the second computing device via an application programming interface (API).

During the secure work session, the second computing device performs an operation on the homomorphically encrypted data in the homomorphic encryption memory area via the API to determine a result. The result is provided to the second computing device to establish proof of the statement based at least in part on the result. The proof is established without the second computing device being capable of decrypting the homomorphically encrypted data.

In system embodiments, a server initiates the secure work session and allocates the homomorphic encryption memory area, where the homomorphic encryption memory area is located at least in part on the server and/or on a computing device among a plurality of computing devices. Homomorphically encrypted data indicative of proof of the statement is loaded into the homomorphic encryption memory area, access to at least a portion of the encrypted data is provided via an API, and the at least one computing device performs an operation on the homomorphically encrypted data via the API. The server provides the result to establish proof without decrypting by the computing device performing the operation.

The document context further describes a healthcare-cloud system that uses homomorphic encryption to enable encrypted analysis without decrypting underlying healthcare data. It includes compiling query results into an encrypted results set or encrypted results vector, exposing the functionality through an API, and managing practical encrypted computation via noise management and renormalization in homomorphic work spaces. Optional zero-knowledge proof use, protected session/workspace handling, and homomorphic work session/workspace mechanisms are described as part of enabling secure encrypted proof and analysis in a healthcare network environment.

Claims Coverage

The document provides three independent claims directed to establishing proof of a statement using homomorphic encryption in a secure work session over a network, with encrypted proof-indicative data accessed via an API and processed to determine a result without decrypting by the computing device performing the operation.

Secure work session with API-accessible homomorphic encryption memory area

Initiating a secure work session over a network between a first computing device and a second computing device; allocating a homomorphic encryption memory area for use by the secure work session; loading homomorphically encrypted data indicative of proof of the statement into the homomorphic encryption memory area; and making at least a portion of the homomorphically encrypted data accessible to the second computing device via an application programming interface (API).

Result determination on encrypted data without decrypting

Determining a result from an operation performed by the second computing device on the homomorphically encrypted data in the homomorphic encryption memory area via the API; and providing the result to the second computing device to establish proof of the statement based at least in part on the result without the second computing device capable of decrypting the homomorphically encrypted data.

System instructions for establishing proof via homomorphic encryption over a secure work session

A system comprising non-transitory computer readable storage media storing instructions executable by one or more processors to perform operations including initiating a secure work session over a network between a first computing device and a second computing device; allocating a homomorphic encryption memory area; loading homomorphically encrypted data indicative of proof of the statement into the homomorphic encryption memory area with at least a portion accessible to the second computing device via an API; determining a result from an operation performed on the homomorphically encrypted data via the API; and providing the result to the second computing device to establish proof without the second computing device capable of decrypting the homomorphically encrypted data.

Distributed server-initiated homomorphic encryption proof system

A system comprising a plurality of computing devices and a server communicatively coupled to the plurality of computing devices, where the server is operable to initiate a secure work session over a network with one or more of the plurality of computing devices, allocate a homomorphic encryption memory area to be used by the secure work session, and load homomorphically encrypted data indicative of proof of the statement into the homomorphic encryption memory area, the homomorphic encryption memory area being located at least in part at either or both of the server and a computing device; provide API access to at least a portion of the encrypted data; enable the at least one computing device to perform an operation on the encrypted data via the API; and enable the server to provide a result determined from the operation to the at least one computing device to establish proof without the at least one computing device capable of decrypting the homomorphically encrypted data.

Across the independent claims, the core claim coverage is the same overall structure: secure work session initiation, allocation of a homomorphic encryption memory area holding homomorphically encrypted data indicative of proof, API-based access for a computing device to perform an operation and determine a result, and establishing proof while preventing the operation-performing computing device from decrypting the encrypted data. The system claim variants further specify executable instructions for performing these operations and a server-initiated distributed architecture with multiple computing devices and the homomorphic encryption memory area located at least in part on the server and/or computing devices.

Stated Advantages

Establishing proof of a statement based at least in part on a result determined from operations performed on homomorphically encrypted data.

Allowing the second computing device, or at least one computing device, to determine and use the result to establish proof without being capable of decrypting the homomorphically encrypted data.

Enabling access to encrypted data via an API for performing operations on the homomorphically encrypted data while maintaining encrypted operation confidentiality.

Enabling encrypted analysis without decrypting underlying healthcare data.

Documented Applications

A healthcare-cloud system environment for encrypted analysis of healthcare data, providing an API that supports encrypted analysis without decrypting the underlying healthcare data.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.