Systems and methods for computing with private healthcare data

Inventors

Aravamudan, MuraliMURUGADOSS, KarthikArdhanari, SankarRajasekharan, AjitAnand, AkashBarve, RakeshSoundararajan, VenkataramananAWASTHI, SamirWagner, TylerNAQVI, Shamim

Assignees

Nference Inc

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12205691-B2

Patent

Publication Date

2025-01-21

Expiration Date


Abstract

Techniques are provided for computing with private healthcare data. The techniques include a method comprising constructing an isolated memory partition that forms a secure enclave and pre-provisioning software within the secure enclave. The pre-provisioned software is configured to receive at least one of input data or the instructions for the one or more application computing processes in an encrypted form; decrypt the at least one of input data or instructions using one or more cryptographic keys; execute the one or more application computing processes based on the decrypted at least one of input data or instructions to generate output data; generate a proof of execution that indicates that the one or more application computing processes operated on the received input data; encrypt the output data using the one or more cryptographic keys; and provide external access to the encrypted output data and the proof of execution.

Core Innovation

The disclosure relates to computing with private healthcare data using a secure enclave. A secure enclave is formed for running one or more application computing processes in isolation from one or more unauthorized computing processes running on one or more processors, and pre-provisioned software is configured inside the secure enclave to receive input data in encrypted form, load the input data into the secure enclave, and load one or more programs for analyzing the input data into the secure enclave.

Within the secure enclave, the pre-provisioned software decrypts the input data using one or more cryptographic keys and executes the one or more application computing processes based on the decrypted input data to generate output data. The system then generates a proof of execution proving that the one or more instructions of the one or more application computing processes operated on the received input data, and provides external access to the proof of execution.

A secure enclave architecture is described that separates secure and unsecure portions of the computing environment and extends trust using attestation and proof-of-execution across federated and pipeline chains. The disclosure also addresses privacy and regulatory context for healthcare data, including de-identification assurances and related properties such as inscrutability, and mentions privacy policy enforcement, de-identification provenance or probability assurances, information masking, and query-responsive fragment search with augmented curation and temporal discrimination.

Claims Coverage

The partial content provides two independent claims, one method claim and one system claim. Both claims share isolated secure enclave execution with encrypted input handling, in-enclave decryption using cryptographic keys, analysis program execution, output generation, and generation with external access to a proof of execution that verifies operated instructions on received input data.

Isolated secure enclave execution for application computing processes

Form at least one secure enclave available to one or more processors for running one or more application computing processes in isolation from one or more unauthorized computing processes running on the one or more processors.

Pre-provisioned enclave software for encrypted input reception and analysis program loading

Pre-provision software within the at least one secure enclave configured to receive input data in an encrypted form, load the input data into the at least one secure enclave, and load one or more programs for analyzing the input data into the at least one secure enclave.

In-enclave decryption using cryptographic keys and execution to generate output

Decrypt the one or more input data using one or more cryptographic keys, then execute the one or more application computing processes based on the decrypted at least one of input data to generate output data.

Proof of execution generation and external access

Generate a proof of execution proving that the one or more instructions of the one or more application computing processes operated on the received input data, and provide external access to the proof of execution.

Isolated memory partition to construct the secure enclave

Forming the secure enclave includes constructing an isolated memory partition to create the secure enclave.

Cryptographic keys contained within the secure enclave

Decrypting input data uses one or more cryptographic keys stored within at least one secure enclave.

Encrypt output data and provide external access to the encrypted output data

Encrypt output data using one or more cryptographic keys and provide external access to the encrypted output data.

De-identify input data by removing identifying information

De-identify input data by removing information identifying one or more individuals or entities before loading the input data into the at least one secure enclave.

Input data includes an electronic health record

The input data includes at least an electronic health record.

Receiving encrypted input data from a data provider

Receive the input data in an encrypted form from a data provider.

Across the independent method and system claims, the core inventive coverage is isolated execution of application computing processes within at least one secure enclave using pre-provisioned software to load encrypted input, run analysis programs inside the enclave, decrypt input using cryptographic keys, generate output data, and generate a proof of execution proving operated instructions on received input data with external access. Dependent features further tighten enclave construction via an isolated memory partition, constrain key handling to secure enclave containment, optionally de-identify input data and specify electronic health record input, and extend handling by encrypting output and providing encrypted-output external access or receiving encrypted inputs from a data provider.

Stated Advantages

Enables proof of execution that proves the one or more instructions operated on received input data, with external access to the proof of execution.

Runs application computing processes in isolation from unauthorized computing processes.

Decrypts encrypted input data within the secure enclave and uses cryptographic keys associated with the enclave-based process.

Supports de-identification by removing information identifying individuals or entities before enclave loading.

Provides external access to encrypted output data by encrypting output data using cryptographic keys.

Documented Applications

Computing with private healthcare data, including electronic health record input data, using a secure enclave for analysis and output generation with verifiable proof of execution.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.