Method, system, and medium for performing private set intersection with multiple parties

By using encryption keys in the data repository to protect data, the problem that malicious entities in PSI technology may inadvertently obtain sensitive data, and the security and privacy protection of data are achieved.

CN116941219BActive Publication Date: 2025-05-13VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202280008294.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-01-12
Filing Date
2022-01-11
Publication Date
2025-05-13
Estimated Expiration
2042-01-11

AI Technical Summary

Technical Problem

Existing Privacy Set Interview (PSI) technology is difficult to prevent malicious entities from accidentally obtaining sensitive data during a session with the data owner.

Method used

By generating a data repository and protecting data using data classification encryption keys and data authorization encryption keys, ensuring that only authorized entities can access and calculate data intersections.

Benefits of technology

Effectively prevent malicious entities from accessing sensitive data without authorization, ensuring the privacy and security of data owners when using PSI technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116941219B_ABST
    Figure CN116941219B_ABST
Patent Text Reader

Abstract

The present invention provides a system for performing a privacy set intersection (PSI) technique with multiple parties using a data repository, the system comprising at least one processor, the at least one processor generating a data repository; receiving a privacy set intersection (PSI) data query from a submitting entity system associated with a submitting entity, the PSI data query comprising a matching parameter for executing the PSI data query; transmitting a data classification encryption key to the submitting entity system, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameter; determining whether to authorize the PSI data query to the data repository; transmitting a data authorization encryption key to the submitting entity system based on determining that the PSI data query to the data repository is authorized; and executing the PSI data query to the data repository. Methods and computer program products are also provided.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to U.S. Application No. 17 / 146,562, filed on January 12, 2021, the entire contents of which are hereby incorporated by reference.

[0003] background Technical Field

[0004] The present disclosure relates generally to Private Set Intersection (PSI) techniques and, in some non-limiting embodiments or aspects, to systems, methods, and computer program products for conducting PSI techniques with multiple parties using a data repository. Background Art

[0005] Private Set Intersection (PSI) may refer to a secure multi-party computation cryptographic technique that allows two parties (e.g., two data owners), each holding a set of information elements, to compare encrypted versions of those sets in order to compute the intersection between the sets (e.g., the elements that are common between the two sets). For PSI, neither party discloses anything to the other except the elements contained in the intersection between the two sets.

[0006] In some cases, organizations (e.g., business entities such as companies or financial institutions) may want to share data to perform operations on the data, such as machine learning tasks, structured query language (SQL) tasks, etc. For example, a group within the Financial Services Information Sharing and Analysis Center (FS-ISAC) may need to share data across organizations to determine how to prevent fraud. However, regulations from government entities, such as the California Consumer Privacy Act (CCPA) in California or the General Data Protection Regulation (GDPR) in the European Union, may make it difficult for organizations to share their data. To address this issue, PSI technology can be used, which can allow organizations to anonymize the data being shared and only de-anonymize the data that is common between two or more organizations.

[0007] However, the PSI technique may not account for a malicious entity that may provide data that does not belong to the malicious entity and is not authorized to be used by the malicious entity, such as account numbers (e.g., primary account number (PAN), bank account number, credit card account number, etc.). In some cases, the malicious entity may obtain the account number through scraping techniques used on Internet websites. In some cases, the malicious entity may attempt to perform PSI techniques (e.g., PSI data queries) with random account numbers. In this way, during a session with the malicious entity, the data owner and the malicious entity calculate the intersection using the PSI technique, and the malicious entity may cause the data owner to inadvertently provide sensitive data, such as information associated with an account number. Summary of the invention

[0008] Thus, systems, methods, and computer program products are disclosed for conducting a private set intersection (PSI) technique with multiple parties using a data repository.

[0009] According to some non-limiting embodiments or aspects, a method is provided, comprising: generating a data repository with at least one processor; receiving a privacy set intersection (PSI) data query with the at least one processor, wherein the PSI data query includes matching parameters for performing the PSI data query on the data repository; transmitting a data classification encryption key with the at least one processor, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameters; determining with the at least one processor whether to authorize the PSI data query on the data repository; transmitting a data authorization encryption key with the at least one processor based on determining authorization to perform the PSI data query on the data repository; and performing the PSI data query on the data repository with the at least one processor.

[0010] According to some non-limiting embodiments or aspects, a system is provided, comprising: a data repository hosting system, the data repository hosting system comprising at least one processor, the at least one processor being programmed or configured to: generate a data repository; receive a privacy set intersection (PSI) data query from a submitting entity system associated with a submitting entity, wherein the PSI data query comprises matching parameters for executing the PSI data query on the data repository; transmit a data classification encryption key to the submitting entity system, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameters; determine whether to authorize a PSI data query on the data repository; based on determining that the PSI data query on the data repository is authorized, transmit a data authorization encryption key to the submitting entity system; and execute the PSI data query on the data repository.

[0011] According to some non-limiting embodiments or aspects, a computer program product is provided, the computer program product comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium comprising one or more instructions, the one or more instructions, when executed by at least one processor, causing the at least one processor to: generate a data repository; receive a privacy set intersection (PSI) data query, wherein the PSI data query comprises matching parameters for performing the PSI data query on the data repository; transmit a data classification encryption key, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameters; determine whether to authorize a PSI data query on the data repository; transmit a data authorization encryption key based on determining that the PSI data query on the data repository is authorized; and perform the PSI data query on the data repository.

[0012] Other non-limiting embodiments or aspects are set forth in the following numbered clauses:

[0013] Clause 1: A method comprising: generating a data repository with at least one processor; receiving a privacy set intersection (PSI) data query with the at least one processor, wherein the PSI data query includes matching parameters for performing the PSI data query on the data repository; transmitting a data classification encryption key with the at least one processor, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameters; determining with the at least one processor whether to authorize the PSI data query on the data repository; transmitting a data authorization encryption key with the at least one processor based on determining authorization to perform the PSI data query on the data repository; and performing the PSI data query on the data repository with the at least one processor.

[0014] Clause 2: The method according to clause 1 also includes: generating PSI results based on executing the PSI data query on the data repository; providing the PSI results as input to the machine learning algorithm; and generating output of the machine learning algorithm based on the input.

[0015] Clause 3: A method according to clause 1 or 2, wherein generating the data repository comprises: encrypting a first data field of a first transaction data record associated with a first entity using a first data classification encryption key to provide an encrypted first data field of the first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on the classification of the first data field of the first transaction data record and the first entity; encrypting a second data field of the first transaction data record associated with the first entity using a second data classification encryption key to provide an encrypted second data field of the first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on the classification of the second data field of the first transaction data record and the first entity Assigning the second data classification encryption key; encrypting the first data field of the second transaction data record associated with the second entity using the third data classification encryption key to provide an encrypted first data field of the second transaction data record associated with the second entity, wherein the third data classification encryption key is assigned based on the classification of the first data field of the second transaction data record and the second entity; and encrypting the second data field of the second transaction data record associated with the second entity using the fourth data classification encryption key to provide an encrypted second data field of the second transaction data record associated with the second entity, wherein the fourth data classification encryption key is assigned based on the classification of the second data field of the second transaction data record and the second entity.

[0016] Clause 4: A method according to any one of clauses 1-3, wherein generating the data repository comprises: encrypting an encrypted first data field of a first transaction data record associated with the first entity using a first data authorization encryption key to provide a two-layer encrypted first data field of the first transaction data record associated with the first entity, wherein the first data authorization encryption key is assigned based on the first entity; encrypting an encrypted first data field of a second transaction data record associated with the second entity using a second data authorization encryption key to provide a two-layer encrypted first data field of a second transaction data record associated with the second entity, wherein the second data authorization encryption key is assigned based on the second entity; storing the two-layer encrypted first data field of the first transaction data record associated with the first entity in the data repository; and storing the two-layer encrypted first data field of the second transaction data record associated with the second entity in the data repository.

[0017] Clause 5: A method according to any one of clauses 1-4, wherein generating the data repository includes: storing an encrypted second data field of a first transaction data record associated with the first entity in the data repository; and storing an encrypted second data field of a second transaction data record associated with the second entity in the data repository.

[0018] Clause 6: A method according to any one of clauses 1-5, wherein the PSI data query also includes an authorization parameter associated with the matching parameter, wherein determining whether to authorize the PSI data query to the data repository includes: transmitting an authorization request based on the PSI data query; receiving an authorization response, wherein the authorization response includes transaction data associated with the matching parameter; determining that the transaction data associated with the matching parameter included in the authorization response corresponds to the authorization parameter associated with the matching parameter; and determining that the PSI data query is authorized based on determining that the transaction data associated with the matching parameter corresponds to the authorization parameter associated with the matching parameter.

[0019] Clause 7: A method according to any one of clauses 1-6, wherein receiving the PSI data query comprises: receiving the PSI data query from a submitting entity; and wherein transmitting the data authorization encryption key comprises: transmitting the data authorization encryption key to the submitting entity based on determining authorization to perform the PSI data query on the data repository.

[0020] Clause 8: A system comprising: a data repository hosting system, the data repository hosting system comprising at least one processor, the at least one processor being programmed or configured to: generate a data repository; receive a privacy set intersection (PSI) data query from a submitting entity system associated with a submitting entity, wherein the PSI data query comprises a matching parameter for performing the PSI data query on the data repository; transmit a data classification encryption key to the submitting entity system, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameter; determine whether to authorize a PSI data query on the data repository; based on determining that the PSI data query on the data repository is authorized, transmit a data authorization encryption key to the submitting entity system; and perform the PSI data query on the data repository.

[0021] Clause 9: A system according to clause 8, wherein the at least one processor is further programmed or configured to: generate PSI results based on executing the PSI data query on the data repository; and transmit the PSI results to the submission entity system, wherein the submission entity system is programmed or configured to: provide the PSI results as input to the machine learning algorithm; and generate output of the machine learning algorithm based on the input.

[0022] Clause 10: A system according to clause 8 or 9, wherein when generating the data repository, the at least one processor is programmed or configured to: encrypt a first data field of a first transaction data record associated with a first entity using a first data classification encryption key to provide an encrypted first data field of the first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on the classification of the first data field of the first transaction data record and the first entity; encrypt a second data field of the first transaction data record associated with the first entity using a second data classification encryption key to provide an encrypted second data field of the first transaction data record associated with the first entity, wherein the second data field of the first transaction data record is assigned based on the classification of the first data field of the first transaction data record and the first entity. classification and assigning the second data classification encryption key to the first entity; encrypting the first data field of the second transaction data record associated with the second entity using a third data classification encryption key to provide an encrypted first data field of the second transaction data record associated with the second entity, wherein the third data classification encryption key is assigned based on the classification of the first data field of the second transaction data record and the second entity; and encrypting the second data field of the second transaction data record associated with the second entity using a fourth data classification encryption key to provide an encrypted second data field of the second transaction data record associated with the second entity, wherein the fourth data classification encryption key is assigned based on the classification of the second data field of the second transaction data record and the second entity.

[0023] Clause 11: A system according to any one of clauses 8-10, wherein when the data repository is generated, the at least one processor is programmed or configured to: encrypt an encrypted first data field of a first transaction data record associated with the first entity using a first data authorization encryption key to provide a two-layer encrypted first data field of the first transaction data record associated with the first entity, wherein the first data authorization encryption key is assigned based on the first entity; encrypt an encrypted first data field of a second transaction data record associated with the second entity using a second data authorization encryption key to provide a two-layer encrypted first data field of a second transaction data record associated with the second entity, wherein the second data authorization encryption key is assigned based on the second entity; store the two-layer encrypted first data field of the first transaction data record associated with the first entity in the data repository; and store the two-layer encrypted first data field of the second transaction data record associated with the second entity in the data repository.

[0024] Clause 12: A system according to any of clauses 8-11, wherein when the data repository is generated, the at least one processor is programmed or configured to: store an encrypted second data field of a first transaction data record associated with the first entity in the data repository; and store an encrypted second data field of a second transaction data record associated with the second entity in the data repository.

[0025] Clause 13: A system according to any one of clauses 8-12, wherein the PSI data query also includes an authorization parameter associated with the matching parameter, wherein when determining whether to authorize the PSI data query to the data repository, the at least one processor is programmed or configured to: transmit an authorization request based on the PSI data query; receive an authorization response, wherein the authorization response includes transaction data associated with the matching parameter; determine that the transaction data associated with the matching parameter included in the authorization response corresponds to the authorization parameter associated with the matching parameter; and determine to authorize the PSI data query based on determining that the transaction data associated with the matching parameter corresponds to the authorization parameter associated with the matching parameter.

[0026] Clause 14: A system according to any one of clauses 8-13, wherein when transmitting the data authorization encryption key, the at least one processor is programmed or configured to: based on determining authorization to perform the PSI data query on the data repository, transmit the data authorization encryption key to the submitting entity system.

[0027] Clause 15: A computer program product, comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium comprising one or more instructions that, when executed by at least one processor, cause the at least one processor to: generate a data repository; receive a privacy set intersection (PSI) data query, wherein the PSI data query comprises matching parameters for performing the PSI data query on the data repository; transmit a data classification encryption key, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameters; determine whether a PSI data query is authorized to be performed on the data repository; transmit a data authorization encryption key based on determining that a PSI data query is authorized to be performed on the data repository; and perform the PSI data query on the data repository.

[0028] Clause 16: A computer program product according to clause 15, wherein the one or more instructions, when executed by at least one processor, further cause the at least one processor to: generate PSI results based on executing the PSI data query on the data repository; provide the PSI results as input to a machine learning algorithm; and generate an output of the machine learning algorithm based on the input.

[0029] Clause 17: A computer program product according to clause 15 or 16, wherein the one or more instructions that cause the at least one processor to generate the data repository cause the at least one processor to: encrypt a first data field of a first transaction data record associated with a first entity using a first data classification encryption key to provide an encrypted first data field of the first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on the classification of the first data field of the first transaction data record and the first entity; encrypt a second data field of the first transaction data record associated with the first entity using a second data classification encryption key to provide an encrypted second data field of the first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on the classification of the first data field of the first transaction data record and the first entity. the first data field of a second transaction data record associated with the second entity is encrypted using a third data classification encryption key to provide an encrypted first data field of a second transaction data record associated with the second entity, wherein the third data classification encryption key is assigned based on the classification of the first data field of the second transaction data record and the second entity; and the second data field of the second transaction data record associated with the second entity is encrypted using a fourth data classification encryption key to provide an encrypted second data field of the second transaction data record associated with the second entity, wherein the fourth data classification encryption key is assigned based on the classification of the second data field of the second transaction data record and the second entity.

[0030] Clause 18: A computer program product according to any one of clauses 15-17, wherein one or more instructions that cause the at least one processor to generate the data repository cause the at least one processor to: encrypt an encrypted first data field of a first transaction data record associated with the first entity using a first data authorization encryption key to provide two layers of encrypted first data fields of the first transaction data record associated with the first entity, wherein the first data authorization encryption key is assigned based on the first entity; encrypt an encrypted first data field of a second transaction data record associated with the second entity using a second data authorization encryption key to provide two layers of encrypted first data fields of the second transaction data record associated with the second entity, wherein the second data authorization encryption key is assigned based on the second entity; store the two layers of encrypted first data fields of the first transaction data record associated with the first entity in the data repository; and store the two layers of encrypted first data fields of the second transaction data record associated with the second entity in the data repository.

[0031] Clause 19: A computer program product according to any one of clauses 15-18, wherein the one or more instructions that cause the at least one processor to generate the data repository cause the at least one processor to: store an encrypted second data field of a first transaction data record associated with the first entity in the data repository; and store an encrypted second data field of a second transaction data record associated with the second entity in the data repository.

[0032] Clause 20: A computer program product according to any one of clauses 15-19, wherein the PSI data query also includes an authorization parameter associated with the matching parameter, wherein one or more instructions that cause the at least one processor to determine whether to authorize the PSI data query to the data repository cause the at least one processor to: transmit an authorization request based on the PSI data query; receive an authorization response, wherein the authorization response includes transaction data associated with the matching parameter; determine that the transaction data associated with the matching parameter included in the authorization response corresponds to the authorization parameter associated with the matching parameter; and determine that the PSI data query is authorized based on determining that the transaction data associated with the matching parameter corresponds to the authorization parameter associated with the matching parameter.

[0033] These and other features and characteristics of the present disclosure, as well as methods of operation and functions of combinations of related structural elements and parts, and economies of manufacturing will become more apparent when considering the following description and the appended claims with reference to the accompanying drawings, all of which form a part of this specification, wherein like reference numerals indicate corresponding parts in the various figures. However, it is to be expressly understood that the drawings are for illustration and description purposes only and are not intended to be used as definitions of limitations of the present disclosure. Unless the context clearly dictates otherwise, when used in this specification and claims, the singular forms "a", "an", and "the" include plural referents. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 is a diagram of a non-limiting embodiment or aspect of an environment in which the systems, apparatus, products, devices and / or methods described herein may be implemented according to the principles of the present disclosure;

[0035] Figure 2 yes Figure 1 Figures of non-limiting embodiments or aspects of one or more devices and / or components of one or more systems;

[0036] Figure 3 is a flow chart of a non-limiting embodiment or aspect of a process of performing a Private Set Intersection (PSI) technique with multiple parties using a data repository; and

[0037] Figure 4A-Figure 4Iis an illustration of a non-limiting example or aspect of an implementation of a process for conducting PSI technology with multiple parties using a data repository. DETAILED DESCRIPTION

[0038] For the purpose of description below, the terms "end", "upper", "lower", "right", "left", "vertical", "horizontal", "top", "bottom", "lateral", "longitudinal" and their derivatives shall refer to the present disclosure as it is oriented in the accompanying drawings. However, it should be understood that the present disclosure may adopt various alternative variations and step sequences, unless expressly specified to the contrary. It should also be understood that the specific devices and processes illustrated in the drawings and described in the following description are merely exemplary embodiments or aspects of the present disclosure. Therefore, unless otherwise indicated, specific dimensions and other physical characteristics associated with the embodiments or aspects of the embodiments disclosed herein should not be considered as limiting.

[0039] The aspects, parts, elements, structures, actions, steps, functions, instructions, etc. used herein should not be understood as being critical or necessary unless explicitly described as such. In addition, as used herein, the article "one" is intended to include one or more items, and can be used interchangeably with "one or more" and "at least one". In addition, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, a combination of related items and unrelated items, etc.), and can be used interchangeably with "one or more" or "at least one". In the case of wishing only one item, the term "one" or similar language is used. And, as used herein, the term "having" etc. is intended to be an open term. In addition, unless otherwise explicitly stated, the phrase "based on" is intended to mean "based at least in part". Where appropriate, the phrase "based on" can also mean "in response to".

[0040] As used herein, the terms "communication" and "communication" may refer to the reception, admission, transmission, transfer, provisioning, etc. of information (e.g., data, signals, messages, instructions, commands, etc.). A unit (e.g., a device, a system, a component of a device or system, a combination thereof, etc.) communicating with another unit means that the unit is able to directly or indirectly receive information from the other unit and / or pass (e.g., send) information to the other unit. This may refer to a direct or indirect connection that is wired and / or wireless in nature. In addition, although the information sent may be modified, processed, relayed, and / or routed between the first unit and the second unit, the two units may also communicate with each other. For example, the first unit may communicate with the second unit even if the first unit passively receives information and does not actively send information to the second unit. As another example, the first unit may communicate with the second unit if at least one intermediate unit (e.g., a third unit located between the first unit and the second unit) processes the information received from the first unit and sends the processed information to the second unit. In some non-limiting embodiments or aspects, a message may refer to a network packet (e.g., a data packet, etc.) including data.

[0041] As used herein, the terms "issuer," "issuer institution," "issuer bank," or "payment device issuer" may refer to one or more entities that provide an individual (e.g., a user, customer, etc.) with an account for conducting payment transactions, such as credit payment transactions and / or debit payment transactions. For example, an issuer institution may provide a customer with an account identifier, such as a primary account number (PAN), that uniquely identifies one or more accounts associated with the customer. In some non-limiting embodiments or aspects, an issuer may be associated with a bank identification number (BIN) that uniquely identifies the issuer institution. As used herein, an "issuer system" may refer to one or more computer systems operated by or on behalf of an issuer, such as a server that executes one or more software applications. For example, an issuer system may include one or more authorization servers for authorizing transactions.

[0042] As used herein, the term "transaction service provider" may refer to an entity that receives transaction authorization requests from merchants or other entities and, in some cases, provides payment assurance through an agreement between a transaction service provider and an issuer institution. For example, a transaction service provider may include a payment network, such as Visa®, MasterCard®, American Express®, or any other entity that processes transactions. As used herein, the term "transaction service provider system" may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction service provider system that executes one or more software applications. A transaction service provider system may include one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of a transaction service provider.

[0043] As used herein, the term "merchant" may refer to one or more entities (e.g., operators of retail businesses) that provide goods and / or services and / or access to goods and / or services to users (e.g., customers, consumers, etc.) based on transactions such as payment transactions. As used herein, a "merchant system" may refer to one or more computer systems operated by or on behalf of a merchant, such as a server executing one or more software applications. As used herein, the term "product" may refer to one or more goods and / or services provided by a merchant.

[0044] As used herein, the term "acquirer" may refer to an entity that is licensed by a transaction service provider and approved by the transaction service provider to initiate a transaction (e.g., a payment transaction) involving a payment device associated with a transaction service provider. As used herein, the term "acquirer system" may also refer to one or more computer systems, computer devices, etc. operated by or on behalf of an acquirer. Transactions that an acquirer may initiate may include payment transactions (e.g., purchases, original credit transactions (OCTs), account funds transactions (AFTs), etc.). In some non-limiting embodiments or aspects, an acquirer may be authorized by a transaction service provider to sign a contract with a merchant or service provider to initiate a transaction involving a payment device associated with a transaction service provider. An acquirer may sign a contract with a payment service provider to enable the payment service provider to provide sponsorship to a merchant. An acquirer may monitor the compliance of a payment service provider in accordance with transaction service provider regulations. An acquirer may perform due diligence on a payment service provider and ensure that appropriate due diligence occurs before signing a contract with a sponsored merchant. An acquirer may be responsible for all transaction service provider programs operated or sponsored by an acquirer. An acquirer may be responsible for the actions of an acquirer payment facilitator, merchants sponsored by the acquirer payment facilitator, etc. In some non-limiting embodiments or aspects, the acquirer may be a financial institution, such as a bank.

[0045] As used herein, the term "payment gateway" may refer to an entity and / or a payment processing system operated by or on behalf of such an entity that provides payment services (e.g., transaction service provider payment services, payment processing services, etc.) to one or more merchants (e.g., transaction service provider payment services, payment processing services, etc.). The payment service may be associated with the use of a portable financial device managed by a transaction service provider. As used herein, the term "payment gateway system" may refer to one or more computer systems, computer devices, servers, server groups, etc. operated by or on behalf of a payment gateway.

[0046] As used herein, the terms "client" and "client device" may refer to one or more computing devices, such as processors, storage devices, and / or similar computer components that access services that may be provided by a server. In some non-limiting embodiments or aspects, a client device may include an electronic device configured to communicate with one or more networks and / or facilitate payment transactions, such as, but not limited to, one or more desktop computers, one or more portable computers (e.g., tablet computers), one or more mobile devices (e.g., cellular phones, smartphones, personal digital assistants, wearable devices such as watches, glasses, lenses, and / or clothing, etc.), and / or other similar devices. In addition, the term "client" may also refer to an entity that owns, uses, and / or operates a client device to facilitate a transaction with another entity.

[0047] As used herein, the term "server" may refer to one or more computing devices, such as processors, storage devices, and / or similar computer components, that communicate with client devices and / or other computing devices over a network, such as the Internet or a private network, and, in some examples, facilitate communications between other servers and / or client devices.

[0048] As used herein, the term "system" may refer to one or more computing devices or combinations of computing devices, such as, but not limited to, processors, servers, client devices, software applications, and / or other similar components. In addition, as used herein, references to "servers" or "processors" may refer to previously described servers and / or processors stated as performing a previous step or function, different servers and / or processors, and / or combinations of servers and / or processors. For example, as used in the specification and claims, a first server and / or first processor stated as performing a first step or function may refer to the same or different servers and / or processors stated as performing a second step or function.

[0049] Improved systems, methods, and computer program products for performing a privacy set intersection (PSI) technique with multiple parties using a data repository are provided. Embodiments of the present disclosure may include a data repository hosting system, the data repository hosting system including at least one processor, the at least one processor being programmed or configured to: generate a data repository; receive a PSI data query from a submitting entity system associated with a submitting entity, wherein the PSI data query includes a matching parameter for performing the PSI data query on the data repository; transmit a data classification encryption key to the submitting entity system, wherein the data classification encryption key is associated with a data field corresponding to a matching parameter data field of the matching parameter; determine whether to authorize a PSI data query on the data repository; based on determining that the PSI data query on the data repository is authorized, transmit a data authorization encryption key to the submitting entity system; and perform the PSI data query on the data repository.

[0050] In this way, embodiments of the present disclosure allow a system to prevent unauthorized access to sensitive data by entities such as malicious entities when using PSI techniques on a data repository. Based on the use of data classification encryption keys and data authorization encryption keys, the system can prevent data owners from inadvertently providing sensitive data to entities during sessions involving the computation of intersections using PSI techniques.

[0051] Reference now Figure 1 , Figure 1 1 is an illustration of an exemplary environment 100 in which the apparatus, systems, methods, and / or products described herein may be implemented. Figure 1 As shown, environment 100 includes a data repository hosting system 102, a submission entity system 104, at least one data owner entity system (e.g., data owner entity systems 106-1 through 106-n, collectively "data owner entity system 106" and individually "data owner entity system 106"), and / or a communication network 108. Data repository hosting system 102, submission entity system 104, and / or data owner entity system 106 may be interconnected (e.g., establish communication connections, etc.) via a wired connection, a wireless connection, or a combination of wired and wireless connections.

[0052] The data repository hosting system 102 may include one or more computing devices configured to communicate with the submitting entity system 104 and / or the data owner entity system 106 via the communication network 108. For example, the data repository hosting system 102 may include a server, a server group, and / or other similar devices. In some non-limiting embodiments or aspects, the data repository hosting system 102 may be associated with a transaction service provider system as described herein. Additionally or alternatively, as described herein, the data repository hosting system 102 may be associated with a merchant system, a payment gateway, an acquirer system, an issuer system, and / or a third-party system. In some non-limiting embodiments or aspects, the data repository hosting system 102 may communicate with at least one data storage device, which may be local or remote to the data repository hosting system 102. In some non-limiting embodiments or aspects, the data repository hosting system 102 may be able to receive information from the data storage device, store information in the data storage device, transmit information to the data storage device, or search for information stored in the data storage device.

[0053] The submitting entity system 104 may include one or more computing devices configured to communicate with the data repository hosting system 102 and / or the data owner entity system 106 via the communication network 108. For example, the submitting entity system 104 may include computing devices, such as servers, server groups, client devices, client device groups, desktop computers, portable computers (e.g., tablet computers, laptop computers, etc.), mobile devices (e.g., cellular phones, smart phones, personal digital assistants, wearable devices, etc.), and / or other similar devices. In some non-limiting embodiments or aspects, the submitting entity system 104 may be associated with a user (e.g., an individual operating a device). Additionally or alternatively, the submitting entity system 104 may be associated with a merchant system as described herein. Additionally or alternatively, the submitting entity system 104 may be associated with a payment gateway, an acquirer system, an issuer system, a transaction service provider system, and / or a third-party system as described herein. In some non-limiting embodiments or aspects, the submitting entity system 104 may be the same as one of the data owner entity systems 106 (eg, a given data owner entity 106 may transmit a PSI data query, as described herein, and thus may be considered to be the submitting entity system 104 ).

[0054] The data owner entity system 106 may include one or more computing devices configured to communicate with the data repository hosting system 102, the submitting entity system 104, and / or other data owner entity systems 106 via the communication network 108. For example, each data owner entity system 106 may include a computing device, such as a server, a server group, and / or other similar devices. In some non-limiting embodiments or aspects, at least one of the data owner entity systems 106 may be associated with an issuer system as described herein. Additionally or alternatively, at least one of the data owner entity systems 106 may be associated with a transaction service provider system as described herein. Additionally or alternatively, at least one of the data owner entity systems 106 may be associated with a merchant system, a payment gateway, an acquirer system, a user, and / or a third-party system as described herein.

[0055] The communication network 108 may include one or more wired and / or wireless networks. For example, the communication network 108 may include a cellular network (e.g., a long term evolution (LTE) network, a third generation (3G) network, a fourth generation (4G) network, a fifth generation (5G) network, a code division multiple access (CDMA) network, etc.), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., a public switched telephone network (PSTN)), etc.), a private network, an ad hoc network, an intranet, the Internet, a fiber-based network, a cloud computing network, etc., and / or a combination of these or other types of networks.

[0056] Figure 1 The number and arrangement of systems and / or devices shown in are provided as examples. Additional systems and / or devices, fewer systems and / or devices, different systems and / or devices, or devices that are similar to the present invention may be present. Figure 1 The systems and / or devices shown in the drawings may be arranged in different ways. In addition, the invention may be implemented in a single system and / or a single device. Figure 1 Two or more systems and / or devices shown, or Figure 1 The single system or single device shown may be implemented as multiple distributed systems or devices. Additionally or alternatively, a set of systems or a set of devices (e.g., one or more systems, one or more devices) of environment 100 may perform one or more functions described as being performed by another set of systems or another set of devices of environment 100.

[0057] Reference now Figure 2 , Figure 22 is an illustration of exemplary components of an apparatus 200. The apparatus 200 may correspond to one or more apparatuses of the data repository hosting system 102, one or more apparatuses of the submitting entity system 104, and one or more apparatuses of the data owner entity system 106. In some non-limiting embodiments or aspects, one or more apparatuses of the data repository hosting system 102, one or more apparatuses of the submitting entity system 104, and / or one or more apparatuses of the data owner entity system 106 may include at least one apparatus 200 and / or at least one component of the apparatus 200. Figure 2 As shown, apparatus 200 may include a bus 202 , a processor 204 , a memory 206 , a storage component 208 , an input component 210 , an output component 212 , and a communication interface 214 .

[0058] The bus 202 may include components that permit communication between components of the device 200. In some non-limiting embodiments or aspects, the processor 204 may be implemented in hardware, software, or a combination of hardware and software. For example, the processor 204 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), etc.), a microprocessor, a digital signal processor (DSP), and / or any processing component that can be programmed to perform a function (e.g., a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc.). The memory 206 may include a random access memory (RAM), a read-only memory (ROM), and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory, optical memory, etc.) that stores information and / or instructions for use by the processor 204.

[0059] Storage component 208 may store information and / or software associated with the operation and use of device 200. For example, storage component 208 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optical disk, a solid-state disk, etc.), a compact disk (CD), a digital versatile disk (DVD), a floppy disk, a cassette, a magnetic tape, and / or another type of computer-readable medium, and a corresponding drive.

[0060] Input components 210 may include components that permit device 200 to receive information, for example, via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, a microphone, a camera, etc.). Additionally or alternatively, input components 210 may include sensors for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, etc.). Output components 212 may include components that provide output information from device 200 (e.g., a display, a speaker, one or more light emitting diodes (LEDs), etc.).

[0061] The communication interface 214 may include transceiver-like components (e.g., transceivers, separate receivers and transmitters, etc.) that enable the device 200 to communicate with other devices, such as via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection. The communication interface 214 may permit the device 200 to receive information from another device and / or provide information to another device. For example, the communication interface 214 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi® interface, a Bluetooth® interface, a Zigbee® interface, a cellular network interface, etc.

[0062] The device 200 can perform one or more processes described herein. The device 200 can perform these processes based on the processor 204 executing software instructions stored by a computer-readable medium such as the memory 206 and / or the storage component 208. Computer-readable media (e.g., non-transitory computer-readable media) are defined herein as non-transitory memory devices. Non-transitory memory devices include memory space located within a single physical storage device or memory space spread across multiple physical storage devices.

[0063] The software instructions may be read into the memory 206 and / or storage component 208 from another computer-readable medium or from another device via the communication interface 214. When executed, the software instructions stored in the memory 206 and / or storage component 208 may cause the processor 204 to perform one or more processes described herein. Additionally or alternatively, hard-wired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Therefore, the embodiments or aspects described herein are not limited to any specific combination of hardware circuitry and software.

[0064] The memory 206 and / or the storage component 208 may include a data storage device or one or more data structures (e.g., a database, etc.). The device 200 can receive information from, store information in, transmit information to, or search for information stored in the data storage device or one or more data structures in the memory 206 and / or the storage component 208. For example, the information may include input data, output data, transaction data, account data, or any combination thereof.

[0065] Figure 2 The number and arrangement of components shown in FIG. 2 are provided as examples. In some non-limiting embodiments or aspects, the device 200 may include additional components, fewer components, different components, or components in a manner similar to that of the embodiment of the present invention. Figure 2Additionally or alternatively, one set of components (eg, one or more components) of the apparatus 200 may perform one or more functions described as being performed by another set of components of the apparatus 200.

[0066] Reference now Figure 3 , Figure 3 1 is a flow chart of a non-limiting embodiment or aspect of a process 300 for performing a privacy set intersection (PSI) technique with multiple parties using a data repository. In some non-limiting embodiments or aspects, one or more functions described with respect to process 300 may be performed by a data repository hosting system 102 (e.g., in full, in part, etc.). In some non-limiting embodiments or aspects, one or more steps of process 300 may be performed by another device or group of devices (e.g., submitting entity system 104, data owner entity system 106, etc.) that is separate from or includes the data repository hosting system 102 (e.g., in full, in part, etc.).

[0067] like Figure 3 As shown, at step 302, process 300 may include generating a data repository. For example, the data repository hosting system 102 may generate a data repository (e.g., a data lake, a database, etc.). In some non-limiting embodiments or aspects, the data repository hosting system 102 may receive data (e.g., transaction data, transaction data records, etc.) from at least one data owner entity system 106, and the data repository hosting system 102 may generate the data repository based on the data received from the data owner entity system 106.

[0068] In some non-limiting embodiments or aspects, the data repository may include data associated with (e.g., received from and / or similarly operated on) at least one data owner entity system 106 (e.g., multiple data owner entity systems 106). For example, the data repository hosting system 102 may receive data from each data owner entity system 106 (e.g., each data owner entity system 106 that has chosen to share data in the data repository). In some non-limiting embodiments or aspects, each data owner entity system 106 may have (e.g., store, access and / or similarly operate on) data (e.g., transaction data) including at least one data record (e.g., transaction data record). Additionally or alternatively, each data record (e.g., transaction data record) may include at least one data field (e.g., multiple data fields). In some non-limiting embodiments or aspects, each data owner entity system 106 may choose (e.g., select and / or similarly operate on) to share at least some data fields (e.g., a subset of data fields) of at least some data records (e.g., a subset of data records) of the corresponding data owner entity system 106. Additionally or alternatively, each data owner entity system 106 may transmit to the data repository hosting system 102 the data (e.g., a subset of data fields of a subset of data records and / or the like) and / or encrypted versions thereof (e.g., encrypted data fields as described herein, etc.) that the corresponding data owner entity system 106 selects to share.

[0069] In some non-limiting embodiments or aspects, data from each respective data owner entity system 106 may be encrypted using at least one encryption key (e.g., a data classification encryption key, a data authorization key, etc., as described herein) associated with the respective data owner entity system 106. For example, each data owner entity system 106 may generate a data classification encryption key for each data field to be shared. Additionally or alternatively, each data owner entity system 106 may encrypt its data (e.g., each data field of a subset of data fields of a subset of data records and / or the like) with a respective data classification encryption key, for example, prior to transmitting the encrypted data (e.g., the encrypted data field) to the data repository hosting system 102 to provide the encrypted data (e.g., the encrypted data field). In some non-limiting embodiments or aspects, the data repository hosting system 102 may generate at least one data classification encryption key. Additionally or alternatively, the data repository hosting system 102 may encrypt at least one data field (e.g., a data field of a data record received from the data owner entity system 106, a data field of a data record stored by the data repository hosting system 102, and / or the like) with a corresponding data classification encryption key (e.g., as generated by the data repository hosting system 102).

[0070] For purposes of illustration and not limitation, the first data owner entity system 106-1 may encrypt a first data field of a first transaction data record using a first data classification encryption key to provide an encrypted first data field of the first transaction data record, and the first data classification encryption key may be generated (e.g., created, assigned, and / or the like) by the first data owner entity system 106-1 based on the classification of the first data field of the first transaction data record and the first data owner entity. The first data owner entity system 106-1 may encrypt a second data field of the first transaction data record using a second data classification encryption key to provide an encrypted second data field of the first transaction data record, and the second data classification encryption key may be generated (e.g., created, assigned, and / or the like) by the first data owner entity system 106-1 based on the classification of the second data field of the first transaction data record and the first data owner entity. Additionally or alternatively, the second data owner entity system 106-2 may encrypt the first data field of the second transaction data record using a third data classification encryption key to provide an encrypted first data field of the second transaction data record, and the third data classification encryption key may be generated (e.g., created, assigned, and / or the like) by the second data owner entity system 106-2 based on the classification of the first data field of the second transaction data record and the second data owner entity. The second data owner entity system 106-2 may encrypt the second data field of the second transaction data record using a fourth data classification encryption key to provide an encrypted second data field of the second transaction data record, and the fourth data classification encryption key may be generated (e.g., created, assigned, and / or the like) by the second data owner entity system 106-2 based on the classification of the second data field of the second transaction data record and the second data owner entity. Additionally or alternatively, the data repository hosting system 102 may encrypt the first data field of the third transaction data record using a fifth data classification encryption key to provide an encrypted first data field of the third transaction data record, and the fifth data classification encryption key may be generated (e.g., created, assigned, and / or the like) by the data repository hosting system 102 based on the classification of the first data field of the third transaction data record and the data repository hosting. The first data field of the third transaction data record may correspond to the first data field of the first transaction record. The data repository hosting system 102 may encrypt the second data field of the third transaction data record using a sixth data classification encryption key to provide an encrypted second data field of the third transaction data record, and the sixth data classification encryption key may be generated (e.g., created, assigned, and / or the like) by the data repository hosting system 102 based on the classification of the second data field of the third transaction data record and the data repository hosting.Additionally or alternatively, the data repository hosting system 102 may encrypt the first data field of the fourth transaction data record with the fifth data classification encryption key to provide an encrypted first data field of the fourth transaction data record. The first data field of the fourth transaction data record may correspond to the first data field of the second transaction record. The data repository hosting system 102 may encrypt the second data field of the fourth transaction data record with the sixth data classification encryption key to provide an encrypted second data field of the fourth transaction data record.

[0071] In some non-limiting embodiments or aspects, the data repository hosting system 102 may generate a data authorization encryption key for each data owner entity system 106. Additionally or alternatively, the data repository hosting system 102 may encrypt at least one data field associated with each respective data owner entity system 106 with its respective data authorization encryption key. Additionally or alternatively, the data repository hosting system 102 may transmit the respective data authorization encryption key to each respective data owner entity system 106.

[0072] For purposes of illustration and not limitation, the data repository hosting system 102 may encrypt an encrypted first data field of a third transaction data record (e.g., corresponding to a first data field of a first transaction data record associated with the first data owner entity system 106-1) with a first data authorization encryption key (e.g., generated by the data repository hosting system 102 for the first data owner entity system 106-1) to provide a two-layer encrypted first data field of the third transaction data record. Additionally or alternatively, the data repository hosting system 102 may encrypt an encrypted first data field of a fourth transaction data record (e.g., corresponding to a first data field of a second transaction data record associated with the second data owner entity system 106-2) with a second data authorization encryption key (e.g., generated by the data repository hosting system 102 for the second data owner entity system 106-2) to provide a two-layer encrypted first data field of the fourth transaction data record.

[0073] In some non-limiting embodiments or aspects, the data repository hosting system 102 can store encrypted data (e.g., at least some of the encrypted data fields, two-layer encrypted data fields, etc., as described herein) to provide a data repository. Additionally or alternatively, the data repository hosting system 102 can transmit the corresponding data classification encryption key of each two-layer encrypted data field to the corresponding data owner entity system 106 associated therewith.

[0074] For purposes of illustration and not limitation, the data repository hosting system 102 may store two layers of encrypted first data fields of a third transaction data record, two layers of encrypted first data fields of a fourth transaction data record, an encrypted first data field of the first transaction data record, an encrypted second data field of the first transaction data record, an encrypted first data field of the second transaction data record, an encrypted second data field of the second transaction data record, an encrypted second data field of the third transaction data record, an encrypted second data field of the fourth transaction data record, and so on. For example, the data repository hosting system 102 may store the two layers of encrypted first data fields of the third transaction data record in association with the encrypted second data fields of the first transaction data record and / or the encrypted second data fields of the third transaction data record (e.g., in a single data record, in a single row of a database, etc.). Additionally or alternatively, the data repository hosting system 102 may store the two layers of encrypted first data fields of the fourth transaction data record in association with the encrypted second data fields of the second transaction data record and / or the encrypted second data fields of the fourth transaction data record. Additionally or alternatively, the data repository hosting system 102 may transmit the fifth data classification encryption key to the first data owner entity system 106 - 1 and / or the second data owner entity system 106 - 2 .

[0075] In some non-limiting embodiments or aspects, each data owner entity system 106 may generate a data authorization encryption key (e.g., in addition to, instead of, or the like, a data authorization key generated by the data repository hosting system 102). Additionally or alternatively, each data owner entity system 106 may encrypt at least one data field using its corresponding data authorization encryption key.

[0076] For purposes of illustration and not limitation, the first data owner entity system 106-1 may encrypt the encrypted first data field of the first transaction data record (e.g., corresponding to the first data field of the third transaction data record) with a third data authorization encryption key (e.g., generated by the first data owner entity system 106-1) to provide two layers of encrypted first data fields of the first transaction data record. Additionally or alternatively, the second data owner entity system 106-2 may encrypt the encrypted first data field of the second transaction data record (e.g., corresponding to the first data field of the fourth transaction data record) with a fourth data authorization encryption key (e.g., generated by the second data owner entity system 106-2) to provide two layers of encrypted first data fields of the second transaction data record.

[0077] In some non-limiting embodiments or aspects, the data repository hosting system 102 may store two layers of encrypted data (e.g., two layers of encrypted data fields, etc., as described herein) from each data owner entity system 106 in the data repository. For example, each data owner entity system 106 may transmit its respective two layers of encrypted data to the data repository hosting system 102. Additionally or alternatively, the data repository hosting system 102 may store such two layers of encrypted data in the data repository (e.g., in addition to the encrypted data stored therein, in place of at least a portion of the encrypted data stored therein, etc.).

[0078] For purposes of illustration and not limitation, the first data owner entity system 106-1 may transmit the two-layer encrypted first data field of the first transaction data record to the data repository hosting system 102, and / or the data repository hosting system 102 may replace the two-layer encrypted first data field of the third transaction data record with the two-layer encrypted first data field of the first transaction data record. Additionally or alternatively, the second data owner entity system 106-2 may transmit the two-layer encrypted first data field of the second transaction data record to the data repository hosting system 102, and / or the data repository hosting system 102 may replace the two-layer encrypted first data field of the fourth transaction data record with the two-layer encrypted first data field of the second transaction data record.

[0079] like Figure 3 As shown, at step 304, process 300 may include receiving a PSI data query. For example, data repository hosting system 102 may receive the PSI data query from submitting entity system 104. In some non-limiting embodiments, the PSI data query may include matching parameters for performing the PSI data query on the data repository. Additionally or alternatively, the PSI data query may include authorization parameters associated with the matching parameters. Additionally or alternatively, the PSI data query may include an expected output based on at least one of the matching parameters, the authorization parameters, any combination thereof, and the like.

[0080] In some non-limiting embodiments or aspects, the expected output may be associated with an output of the machine learning algorithm. For example, the machine learning algorithm may be configured (e.g., trained, programmed, etc.) to generate an output (e.g., an expected output) based on at least one input. In some non-limiting embodiments or aspects, the submitting entity system 104 may transmit the machine learning algorithm and / or a list of at least one input to the machine learning algorithm to the data repository hosting system 102. Additionally or alternatively, the data repository hosting system 102 may determine at least one field (e.g., an encrypted field) of the data repository associated with at least one input to the machine learning algorithm.

[0081] For purposes of illustration and not limitation, the submitting entity system 104 may be associated with a merchant system. Additionally or alternatively, the submitting entity system 104 may store an account identifier associated with the user (and / or other data associated therewith, such as an expiration date, a security code (e.g., a card security code (CSC), card verification data (CVD), a card verification number, a card verification value (CVV), a card verification value code, a card verification code (CVC), a verification code (V-code or V-code), a signature panel code (SPC), etc.), transaction data, any combination thereof, etc.). The submitting entity system 104 may transmit a PSI data query with an account identifier (and / or a tokenized version thereof) as a matching parameter (and / or other data such as an expiration date, a security code, transaction data, etc. as an authorization parameter) to the data repository hosting system 102. Additionally or alternatively, the submitting entity system 104 may transmit a machine learning algorithm associated with a desired output (e.g., a probability that a user will purchase a given product) to the data repository hosting system 102. Additionally or alternatively, the data repository hosting system 102 may determine at least one input to the machine learning algorithm (e.g., based on the machine learning algorithm). The data repository hosting system 102 may determine at least one field of the data repository based on the input to the machine learning algorithm. For example, the data repository may determine a field associated with an account identifier, a purchase history, a location (e.g., a zip code), any combination thereof, etc. based on the input to the machine learning algorithm.

[0082] like Figure 3 As shown, process 300 may include transmitting the data classification encryption key at step 306. For example, data repository hosting system 102 may transmit the data classification encryption key to submitting entity system 104. In some non-limiting embodiments or aspects, the data classification encryption key may be associated with a data field corresponding to a data field of a matching parameter.

[0083] For purposes of illustration and not limitation, the data repository hosting system 102 may transmit a data classification encryption key (e.g., a first data classification encryption key, a third data classification encryption key, a fifth data classification encryption key, etc.) to the submitting entity system 104. For example, the (double-encrypted) first field of the first transaction data record, the (double-encrypted) first field of the second transaction data record, the (double-encrypted) first field of the third transaction data record, or the (double-encrypted) first field of the fourth transaction data record may correspond to a matching parameter (e.g., an account identifier). For example, the data repository hosting system 102 may determine that the (double-encrypted) first field of the first transaction data record corresponds to a matching parameter (e.g., an account identifier). Additionally or alternatively, the data repository hosting system 102 may transmit the first data classification encryption key to the submitting entity system 104.

[0084] like Figure 3 As shown, at step 308, process 300 may include determining whether to authorize a PSI data query on the data repository. For example, the data repository hosting system 102 and / or one of the data owner entity systems 106 may determine whether to authorize a PSI data query on the data repository. In some non-limiting embodiments or aspects, the data repository hosting system 102 and / or the data owner entity system 106 may determine whether to authorize a PSI data query on the data repository based on a rule of the data owner entity system 106. For example, the data repository hosting system 102 and / or the data owner entity system 106 may compare the PSI data query with the rule of the data owner entity system 106. If the PSI data query satisfies the rule, the data repository hosting system 102 and / or the data owner entity system 106 may determine that the PSI data query is authorized. If the PSI data query does not satisfy the rule, the data repository hosting system 102 and / or the data owner entity system 106 may determine that the PSI data query is not authorized.

[0085] In some non-limiting embodiments or aspects, as described herein, the PSI data query may include a matching parameter and / or an authorization parameter. Additionally or alternatively, the data repository hosting system 102 and / or the submitting entity system 104 may transmit an authorization request based on the PSI data query to the data owner entity system 106. Additionally or alternatively, the data repository hosting system 102 and / or the submitting entity system 104 may receive an authorization response.

[0086] In some non-limiting embodiments, the authorization response may include transaction data associated with the matching parameters. For example, such an authorization response may be received by the data repository hosting system 102. Additionally or alternatively, the data repository hosting system 102 may determine that the transaction data associated with the matching parameters included in the authorization response corresponds to the authorization parameters associated with the matching parameters. The data repository hosting system 102 may determine that the PSI data query is authorized based on (e.g., in response to) determining that the transaction data associated with the matching parameters corresponds to the authorization parameters associated with the matching parameters.

[0087] In some non-limiting embodiments or aspects, the submitting entity system 104 may transmit the authorization request to the data owner entity system 106. Additionally or alternatively, each data owner entity system 106 that receives the authorization request may determine whether the transaction data associated with the matching parameters (e.g., stored by the corresponding data owner entity system 106) corresponds to the authorization parameters associated with the matching parameters. Additionally or alternatively, at least one data owner entity system 106 may determine that the PSI data query is authorized based on (e.g., in response to) determining that the transaction data associated with the matching parameters corresponds to the authorization parameters associated with the matching parameters. Such data owner entity system 106 may transmit an authorization response to the submitting entity system 104. In some non-limiting embodiments or aspects, the authorization response may include a data authorization key, as described below.

[0088] like Figure 3 As shown, at step 310, process 300 may include transmitting a data authorization key. For example, one of the data repository hosting system 102 and / or the data owner entity system 106 may transmit the data authorization encryption key to the submitting entity system 104 based on determining authorization to perform a PSI data query on the data repository.

[0089] In some non-limiting embodiments or aspects, the data repository hosting system 102 and / or the data owner entity system 106 may transmit a data authorization encryption key to the submitting entity system 104 based on determining authorization to make a PSI data query to the data repository. For example, the data repository hosting system 102 may transmit a data authorization encryption key generated by the data repository hosting system 102 to the submitting entity system 104. Additionally or alternatively, the data repository hosting system 102 may receive (e.g., from one of the data owner entity systems 106) a data authorization encryption key (e.g., as generated by the respective data owner entity system 106), and / or the data repository hosting system 102 may transmit such a data authorization encryption key to the submitting entity system 104.

[0090] In some non-limiting embodiments or aspects, the data repository hosting system 102 and / or one of the data owner entity systems 106 may transmit a data authorization encryption key (e.g., as generated by the respective data owner entity system 106) to the submitting entity system 104. For example, the respective data owner entity system 106 may transmit the data authorization encryption key based on (e.g., in response to) determining that a PSI data query is authorized. In some non-limiting embodiments or aspects, the data repository hosting system 102 and / or one of the data owner entity systems 106 may transmit a data classification encryption key to the submitting entity system 104. For example, the data repository hosting system 102 and / or one of the data owner entity systems 106 may transmit the data classification encryption key to the submitting entity system 104 based on determining that a PSI data query is authorized.

[0091] For purposes of illustration and not limitation, the first data owner entity system 106-1 may transmit a third data authorization encryption key (e.g., generated by the first data owner entity system 106-1 to provide a two-layer encrypted first data field of the first transaction data record) to the submitting entity system 104 based on determining that the PSI data query from the submitting entity system 104 is authorized. Additionally or alternatively, the data repository hosting system 102 may transmit the first data authorization encryption key (e.g., generated by the data repository hosting system 102 to provide a two-layer encrypted first data field of the third transaction data record) to the submitting entity system 104 based on determining that the PSI data query from the submitting entity system 104 is authorized.

[0092] like Figure 3 As shown, at step 312, process 300 may include performing a PSI data query on a data repository. For example, data repository hosting system 102 may perform a PSI data query on a data repository (e.g., perform a PSI protocol on the data repository). In some non-limiting embodiments or aspects, data repository hosting system 102 may perform a PSI data query by using a PSI technique to calculate an intersection between PSI data queries submitted (e.g., transmitted) by submitting entity system 104 and the data repository and received from the submitting entity system and the data repository. In some non-limiting embodiments or aspects, the PSI technique may include using an oblivious pseudo-random function (OPRF), such as a one-time OPRF.

[0093] In some non-limiting embodiments or aspects, the data repository hosting system 102 can generate PSI results based on performing PSI data queries on the data repository. For example, the data repository hosting system 102 can generate PSI results based on calculating intersections between PSI data queries submitted by and received from the submitting entity system 104 and the data repository using PSI techniques. In some non-limiting embodiments or aspects, the PSI results can include transaction data records including one or more two-layer encrypted data fields.

[0094] In some non-limiting embodiments or aspects, the data repository hosting system 102 may transmit the PSI results to the submitting entity system 104. For example, the data repository hosting system 102 may transmit encrypted data (e.g., encrypted data fields) corresponding to the PSI results to the submitting entity system 104. Additionally or alternatively, the data repository hosting system 102 may transmit a data classification encryption key associated with the encrypted data (e.g., encrypted data fields) corresponding to the PSI results to the submitting entity system 104.

[0095] In some non-limiting embodiments or aspects, the data repository hosting system 102 may perform machine learning calculations based on the PSI results. In some non-limiting embodiments, the data repository hosting system 102 may provide the PSI results as an input to a machine learning algorithm. Additionally or alternatively, the data repository hosting system 102 may generate an output of the machine learning algorithm based on the input. In some non-limiting embodiments or aspects, the data repository hosting system 102 may transmit the output of the machine learning algorithm to the submitting entity system 104. In some non-limiting embodiments or aspects, the submitting entity system 104 may generate an output of the machine learning algorithm based on the input (e.g., the PSI results).

[0096] In some non-limiting embodiments or aspects, the submitting entity system 104 may receive the PSI results, and the submitting entity system 104 may perform machine learning calculations based on the PSI results. In some non-limiting embodiments or aspects, the submitting entity system 104 may use a data authorization encryption key and / or a data classification encryption key to decrypt the PSI results. In one example, the submitting entity system 104 may receive the PSI results, and the submitting entity system 104 may use a data authorization encryption key associated with the data owner entity system 106 (e.g., a data authorization encryption key provided by the data owner entity system 106 to the submitting entity system 104, a data authorization encryption key provided by the data owner entity system 106 to the data repository hosting system 102, etc.), which was used to encrypt the data included in the PSI results. In this example, the submitting entity system 104 may use the data authorization encryption key to decrypt one or more two-layer encrypted data fields of the transaction data record included in the PSI results. Additionally, the submitting entity system 104 may use a data classification encryption key associated with a classification of one or more encrypted data fields of a transaction data record included in the PSI result (e.g., a data classification encryption key that was used to encrypt one or more data fields of the transaction record based on a classification of the one or more data fields).

[0097] In some non-limiting embodiments or aspects, if the submitting entity system 104 does not have the appropriate encryption key (e.g., a data authorization encryption key and / or a data classification encryption key) to decrypt the encrypted data fields of the PSI results, the submitting entity system 104 may not be able to perform machine learning calculations based on the PSI results. For example, if the submitting entity system 104 does not receive the appropriate encryption key from the data repository hosting system 102 and / or the data owner system 106, the submitting entity system 104 may not be able to decrypt one or more encrypted data fields of the PSI results, and the submitting entity system 104 may not be able to perform machine learning calculations based on one or more encrypted data fields of the PSI results that may not be decrypted. In some non-limiting embodiments or aspects, the submitting entity system 104 may not be able to perform machine learning calculations based on any encrypted data fields in the PSI results that cannot be decrypted. Additionally or alternatively, the submitting entity system 104 is able to perform machine learning calculations based on any encrypted data fields in the PSI results that are able to be decrypted.

[0098] In some non-limiting embodiments or aspects, the data repository hosting system 102 may create an audit record based on performing a PSI data query on the data repository. For example, the data repository hosting system 102 may create an audit record that includes data associated with a PSI data query that was performed on the data repository from the submitting entity system 104. In some non-limiting embodiments or aspects, the audit record may include data indicating the identity of the submitting entity system 104 and / or data indicating one or more data authorization encryption keys and / or one or more data classification encryption keys for decrypting the PSI results of the PSI data query. In some non-limiting embodiments or aspects, the audit record may include data indicating a situation in which the PSI data query includes a request for data of an unauthorized transaction record. For example, the audit record may include a data field indicating that the PSI data query from the submitting entity system 104 includes a request for data of a transaction record that the submitting entity system 104 is not authorized to access. In some non-limiting embodiments or aspects, the audit record may include a data field indicating that the submitting entity system 104 is a malicious entity based on the PSI data query from the submitting entity system 104 including a request for data of transaction records that the submitting entity system 104 is not authorized to access. In some non-limiting embodiments or aspects, the data repository hosting system 102 may store the audit record in a data repository.

[0099] Reference now Figure 4A – Fig. 4I , Figure 4A-Figure 4I 4 is an illustration of an embodiment 400 of a process (eg, process 300) for conducting PSI techniques with multiple parties using a data repository. Figure 4A – Fig. 4IAs shown in , the embodiment 400 may include the data repository hosting system 102, the data owner entity system 106-1, the data owner entity system 106-2, the data owner entity system 106-3, and the submitting entity system 104. However, some non-limiting embodiments or aspects may include the data repository hosting system 102, the data owner entity system 106-2, the data owner entity system 106-3, and the submitting entity system 104, and in the embodiment 400, the operations specified by the data owner entity system 106-1 and the data owner entity system 106-1 are independent. For example, in some non-limiting embodiments or aspects, the embodiment 400 may include the data repository hosting system 102 using the second transaction data record from the data owner entity system 106-2 and the third transaction data record from the data owner entity system 106-3, but not using the first transaction data record from the data owner entity system 106-1, to generate a data repository. In this example, the data owner entity system 106-2 may be referred to as the "first entity" and the data owner entity system 106-3 may be referred to as the "second entity". Additionally, although the account is referred to as a primary account number (PAN) in embodiment 400, any PAN may be a token of a PAN (eg, a tokenized PAN).

[0100] like FIG. 4A to FIG. 4F , the data repository hosting system 102 can generate a data repository. Figure 4A As shown in the figure mark 405, the data repository hosting system 102 can receive a first transaction data record associated with the data owner entity system 106-1, a second transaction data record associated with the data owner entity system 106-2, and a third transaction data record associated with the data owner entity system 106-3 from the data owner entity system 106-1, the data owner entity system 106-2, and the data owner entity system 106-3 respectively.

[0101] like Figure 4B As shown in the figure mark 410, the data repository hosting system 102 can encrypt the first data field of the first transaction data record with the first data classification encryption key. For example, the data repository hosting system 102 can encrypt the first data field of the first transaction data record, and the first data field has a first classification (e.g., classification, category, etc.) displayed as "account number", wherein the first data classification encryption key corresponds to the first classification (e.g., account encryption key) to provide an encrypted first data field of the first transaction data record. In some non-limiting embodiments or aspects, the data owner entity system 106-1 can encrypt the first data field of the first transaction data record with the first data classification encryption key before transmitting the first transaction data record to the data repository hosting system 102. Also as shown Figure 4B As shown in the figure mark 415, the data repository hosting system 102 can encrypt the second data field of the first transaction data record with the second data classification encryption key. For example, the data repository hosting system 102 can encrypt the second data field of the first transaction data record, the second data field having a second classification displayed as "zip code", where the second data classification encryption key corresponds to the second classification (e.g., the zip code encryption key) to provide an encrypted second data field of the first transaction data record. In some non-limiting embodiments or aspects, the data owner entity system 106-1 can encrypt the first data field and / or the second data field of the first transaction data record with the first data classification encryption key and / or the second data classification encryption key, respectively, before transmitting the first transaction data record to the data repository hosting system 102.

[0102] like Figure 4C As shown in the figure mark 420, the data repository hosting system 102 can encrypt the first data field of the second transaction data record with a third data classification encryption key. For example, the data repository hosting system 102 can encrypt the first data field of the second transaction data record, where the first data field has a third classification displayed as "Purchase History", where the third data classification encryption key corresponds to the third classification (e.g., the purchase history encryption key) to provide an encrypted first data field of the second transaction data record. In some non-limiting embodiments or aspects, the first data classification encryption key, the second data classification encryption key, and / or the third data classification encryption key can be assigned to the data owner entity system 106-1. Figure 4C As also shown in the figure by reference numeral 425, the data repository hosting system 102 can encrypt the second data field of the second transaction data record with the first data classification encryption key. For example, the data repository hosting system 102 can encrypt the second data field of the second transaction data record, the second data field having a first classification displayed as "account number", where the first data classification encryption key corresponds to the first classification to provide an encrypted second data field of the second transaction data record. In some non-limiting embodiments or aspects, the data owner entity system 106-2 can encrypt the first data field and / or the second data field of the second transaction data record with the third data classification encryption key and / or the first data classification encryption key, respectively, before transmitting the second transaction data record to the data repository hosting system 102.

[0103] like Figure 4DAs shown by reference numeral 430 in the figure, the data repository hosting system 102 can encrypt the first data field of the third transaction data record with the third data classification encryption key. For example, the data repository hosting system 102 can encrypt the first data field of the third transaction data record, the third data record having a third classification shown as "Purchase History", where the third data classification encryption key corresponds to the third classification (e.g., the purchase history encryption key) to provide an encrypted first data field of the third transaction data record. Figure 4D As shown by reference numeral 435 in the figure, the data repository hosting system 102 may encrypt the second data field of the third transaction data record with the first data classification encryption key. For example, the data repository hosting system 102 may encrypt the first data field of the third transaction data record, the first data field having a first classification displayed as "account number", where the first data classification encryption key corresponds to the first classification to provide an encrypted second data field of the third transaction data record. In some non-limiting embodiments or aspects, the data owner entity system 106-3 may encrypt the first data field and / or the second data field of the third transaction data record with the third data classification encryption key and / or the first data classification encryption key, respectively, before transmitting the third transaction data record to the data repository hosting system 102.

[0104] like Figure 4E As shown by reference numeral 440, the data repository hosting system 102 may generate a data repository based on the first transaction data record, the second transaction data record, and the third transaction data record. For example, the data repository hosting system 102 may combine the encrypted first data field of the first transaction data record, the encrypted second data field of the first transaction data record, the encrypted first data field of the second transaction data record, the encrypted second data field of the second transaction data record, the encrypted first data field of the third transaction data record, and the encrypted second data field of the third transaction data record to generate the data repository. In some non-limiting embodiments or aspects, the data repository hosting system 102 may remove columns having data fields having the first classification for the data owner entity system 106-1 based on determining that the data fields having the first classification for the data owner entity system 106-2 and the data owner entity system 106-3 correspond to the data fields having the first classification for the data owner entity system 106-1.

[0105] like Figure 4FAs shown by reference numeral 445, the data repository hosting system 102 may encrypt the encrypted first data field and the encrypted second data field of the second transaction data record associated with the data owner entity system 106-2 with the first data authorization encryption key to provide two layers of encrypted first data fields and two layers of encrypted second data fields for the second transaction data record associated with the data owner entity system 106-2. In some non-limiting embodiments or aspects, the first data authorization encryption key is assigned to the data owner entity system 106-2. In some non-limiting embodiments or aspects, the data owner entity system 106-2 may encrypt the encrypted first data field and the encrypted second data field of the second transaction data record with the first data authorization encryption key to provide two layers of encrypted first data fields and two layers of encrypted second data fields for the second transaction data record associated with the data owner entity system 106-2.

[0106] Also like Figure 4F As shown by reference numeral 450, the data repository hosting system 102 may encrypt the encrypted first data field and the encrypted second data field of the third transaction data record associated with the data owner entity system 106-3 with the second data authorization encryption key to provide two layers of encrypted first data fields and two layers of encrypted second data fields of the third transaction data record associated with the data owner entity system 106-3. In some non-limiting embodiments or aspects, the second data authorization encryption key is assigned to the data owner entity system 106-3. In some non-limiting embodiments or aspects, the data owner entity system 106-3 may encrypt the encrypted first data field and the encrypted second data field of the third transaction data record with the second data authorization encryption key to provide two layers of encrypted first data fields and two layers of encrypted second data fields of the third transaction data record associated with the data owner entity system 106-3.

[0107] In some non-limiting embodiments or aspects, the data repository hosting system 102 may store the two-layer encrypted first data field and the two-layer encrypted second data field of the second transaction data record associated with the data owner entity system 106-2 in the data repository. Additionally or alternatively, the data repository hosting system 102 may store the two-layer encrypted first data field and the two-layer encrypted second data field of the third transaction data record associated with the data owner entity system 106-3 in the data repository.

[0108] like Figure 4GAs shown by reference numeral 455 in the figure, the data repository hosting system 102 can receive a PSI data query from the submitting entity system 104. In some non-limiting embodiments or aspects, the PSI data query can include matching parameters and authorization parameters for performing the PSI data query on the data repository. In some non-limiting embodiments or aspects, the matching parameters can be associated with a data field (e.g., a data field of a transaction data record). For example, the matching parameters can have a classification associated with the data field. In this example, the matching parameter can be an account number for which an intersection with the data repository is to be calculated. Figure 4G As shown by reference numeral 460, the data repository hosting system 102 may transmit a data classification encryption key for a classification of a data field corresponding to a data field associated with a match parameter of a PSI data query (e.g., a match parameter data field of the match parameter). For example, considering that the match parameter of the PSI data query is an account number, the data repository hosting system 102 may transmit a second data classification encryption key for a second classification of the data field as an account number because the second classification corresponds to the account number data field of the match parameter of the PSI data query.

[0109] like Figure 4H As shown by reference numeral 465 in the figure, the data repository hosting system 102 can determine that a PSI data query is authorized for the data repository. For example, the data repository hosting system 102 can transmit an authorization request to the data owner entity system 106-1, the data owner entity system 106-2, and / or the data owner entity system 106-3 based on the PSI data query. The authorization request can include matching parameters for the PSI data query. In some non-limiting embodiments or aspects, the data repository hosting system 102 can receive an authorization response from the data owner entity system 106-1, the data owner entity system 106-2, and / or the data owner entity system 106-3 based on the authorization request. The authorization response can include an indication that the PSI data query is authorized. In some non-limiting embodiments or aspects, the authorization response can include transaction data associated with the matching parameters. In some non-limiting embodiments or aspects, the authorization response can be received by the data repository hosting system 102, and the data repository hosting system 102 can determine that the transaction data associated with the matching parameters included in the authorization response corresponds to the authorization parameters for the PSI data query. The data repository hosting system 102 may determine that the PSI data query is authorized based on (eg, in response to) determining that the transaction data associated with the matching parameters corresponds to the authorization parameters.

[0110] like Figure 4HAs shown by reference numeral 470, the data repository hosting system 102 may transmit the data authorization encryption key to the submitting entity system 104. For example, the data repository hosting system 102 may transmit the first data authorization encryption key and / or the second data authorization encryption key to the submitting entity system 104 based on determining authorization to perform a PSI data query on the data repository.

[0111] like Fig. 4I As shown by reference numeral 475 in the figure, the data repository hosting system 102 can perform a PSI data query on the data repository. For example, the data repository hosting system 102 can perform the PSI data query by using PSI technology to calculate the intersection between the matching parameters of the PSI data query from the submitting entity system 104 and the data repository. In some non-limiting embodiments or aspects, the PSI technology can include using an oblivious pseudo-random function (OPRF), such as a one-time OPRF. In some non-limiting embodiments or aspects, the data repository hosting system 102 can generate a PSI result for the PSI data query based on performing the PSI data query on the data repository. For example, the data repository hosting system 102 can generate a PSI result based on calculating the intersection between the matching parameters of the PSI data query from the submitting entity system 104 and the data repository using PSI technology. In some non-limiting embodiments or aspects, the data repository hosting system 102 can transmit the PSI result to the submitting entity system 104.

[0112] Although the above methods, systems, and computer program products have been described in detail based on what are currently considered to be the most practical and preferred embodiments or aspects for the purpose of illustration, it should be understood that such details are only for the purpose of illustration, and the present disclosure is not limited to the described embodiments or aspects, but rather, the present disclosure is intended to cover modifications and equivalent arrangements within the spirit and scope of the appended claims. For example, it should be understood that the present disclosure contemplates that, to the extent possible, one or more features of any embodiment or aspect may be combined with one or more features of any other embodiment or aspect.

Claims

1. A method comprising: generating a data repository with at least one processor; receiving, with the at least one processor, a privacy set intersection (PSI) data query, wherein the PSI data query includes matching parameters for executing the PSI data query against the data repository; transmitting, with the at least one processor, a data classification encryption key for encrypting a data field of a transaction data record associated with an entity, wherein the data classification encryption key is associated with a data field of a match parameter data field corresponding to the match parameter; determining, with the at least one processor, whether to authorize the query of the data repository for the PSI data; transmitting, with the at least one processor, a data authorization encryption key based on determining authorization to conduct the PSI data query to the data repository, wherein the data authorization encryption key is used to encrypt an encrypted data field of a transaction data record associated with an entity to provide two layers of encrypted data fields; as well as The PSI data query is executed against the data repository with the at least one processor.

2. The method according to claim 1, further comprising: generating a PSI result based on executing the PSI data query on the data repository; Providing the PSI results as input to a machine learning algorithm; as well as An output of the machine learning algorithm is generated based on the input.

3. The method of claim 1 , wherein generating the data repository comprises: encrypting a first data field of a first transaction data record associated with a first entity using a first data classification encryption key to provide an encrypted first data field of a first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on a classification of the first data field of the first transaction data record and the first entity; encrypting a second data field of a first transaction data record associated with the first entity using a second data classification encryption key to provide an encrypted second data field of the first transaction data record associated with the first entity, wherein the second data classification encryption key is assigned based on the classification of the second data field of the first transaction data record and the first entity; encrypting a first data field of a second transaction data record associated with a second entity using a third data classification encryption key to provide an encrypted first data field of a second transaction data record associated with the second entity, wherein the third data classification encryption key is assigned based on the classification of the first data field of the second transaction data record and the second entity; as well as A second data field of a second transaction data record associated with the second entity is encrypted using a fourth data classification encryption key to provide an encrypted second data field of a second transaction data record associated with the second entity, wherein the fourth data classification encryption key is assigned based on the classification of the second data field of the second transaction data record and the second entity.

4. The method of claim 3, wherein generating the data repository comprises: encrypting an encrypted first data field of a first transaction data record associated with the first entity using a first data authorization encryption key to provide two layers of encrypted first data fields of a first transaction data record associated with the first entity, wherein the first data authorization encryption key is assigned based on the first entity; encrypting the encrypted first data field of a second transaction data record associated with the second entity using a second data authorization encryption key to provide two layers of encrypted first data fields of a second transaction data record associated with the second entity, wherein the second data authorization encryption key is assigned based on the second entity; storing a two-layer encrypted first data field of a first transaction data record associated with the first entity in the data repository; as well as The two-layer encrypted first data field of a second transaction data record associated with the second entity is stored in the data repository.

5. The method of claim 3, wherein generating the data repository comprises: storing an encrypted second data field of a first transaction data record associated with the first entity in the data repository; as well as An encrypted second data field of a second transaction data record associated with the second entity is stored in the data repository.

6. The method of claim 1 , wherein the PSI data query further includes an authorization parameter associated with the matching parameter, wherein determining whether to authorize the PSI data query to the data repository comprises: querying a transmission authorization request based on the PSI data; receiving an authorization response, wherein the authorization response includes transaction data associated with the matching parameters; determining that the transaction data associated with the match parameters included in the authorization response corresponds to the authorization parameters associated with the match parameters; and Authorization of the PSI data query is determined based on determining that the transaction data associated with the matching parameters corresponds to the authorization parameters associated with the matching parameters.

7. The method of claim 1, wherein receiving the PSI data query comprises: receiving the PSI data query from a submitting entity; and The transmitting of the data authorization encryption key comprises: Based on determining authorization to conduct the PSI data query to the data repository, the data authorization encryption key is transmitted to the submitting entity.

8. A system comprising: A data repository hosting system, the data repository hosting system comprising at least one processor, the at least one processor being programmed or configured to: Generate data repository; receiving a privacy set intersection PSI data query from a submitting entity system associated with a submitting entity, wherein the PSI data query includes matching parameters for performing the PSI data query on the data repository; transmitting to the submitting entity system a data classification encryption key for encrypting a data field of a transaction data record associated with an entity, wherein the data classification encryption key is associated with a data field of a match parameter data field corresponding to the match parameter; determining whether to authorize the PSI data query to the data repository; transmitting a data authorization encryption key to the submitting entity system based on determining authorization to conduct the PSI data query on the data repository, wherein the data authorization encryption key is used to encrypt an encrypted data field of a transaction data record associated with the entity to provide two layers of encrypted data fields; as well as The PSI data query is performed on the data repository.

9. The system of claim 8, wherein the at least one processor is further programmed or configured to: generating a PSI result based on executing the PSI data query against the data repository; and transmitting the PSI result to the submitting entity system, wherein the submitting entity system is programmed or configured to: providing the PSI results as input to a machine learning algorithm; and An output of the machine learning algorithm is generated based on the input.

10. The system of claim 8, wherein when generating the data repository, the at least one processor is programmed or configured to: encrypting a first data field of a first transaction data record associated with a first entity using a first data classification encryption key to provide an encrypted first data field of a first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on a classification of the first data field of the first transaction data record and the first entity; encrypting a second data field of a first transaction data record associated with the first entity using a second data classification encryption key to provide an encrypted second data field of the first transaction data record associated with the first entity, wherein the second data classification encryption key is assigned based on the classification of the second data field of the first transaction data record and the first entity; encrypting a first data field of a second transaction data record associated with a second entity using a third data classification encryption key to provide an encrypted first data field of a second transaction data record associated with the second entity, wherein the third data classification encryption key is assigned based on the classification of the first data field of the second transaction data record and the second entity; as well as A second data field of a second transaction data record associated with the second entity is encrypted using a fourth data classification encryption key to provide an encrypted second data field of a second transaction data record associated with the second entity, wherein the fourth data classification encryption key is assigned based on the classification of the second data field of the second transaction data record and the second entity.

11. The system of claim 10, wherein when generating the data repository, the at least one processor is programmed or configured to: encrypting an encrypted first data field of a first transaction data record associated with the first entity using a first data authorization encryption key to provide two layers of encrypted first data fields of a first transaction data record associated with the first entity, wherein the first data authorization encryption key is assigned based on the first entity; encrypting the encrypted first data field of a second transaction data record associated with the second entity using a second data authorization encryption key to provide two layers of encrypted first data fields of a second transaction data record associated with the second entity, wherein the second data authorization encryption key is assigned based on the second entity; storing a two-layer encrypted first data field of a first transaction data record associated with the first entity in the data repository; as well as The two-layer encrypted first data field of a second transaction data record associated with the second entity is stored in the data repository.

12. The system of claim 10, wherein when generating the data repository, the at least one processor is programmed or configured to: storing an encrypted second data field of a first transaction data record associated with the first entity in the data repository; and An encrypted second data field of a second transaction data record associated with the second entity is stored in the data repository.

13. The system of claim 8, wherein the PSI data query further comprises an authorization parameter associated with the matching parameter, wherein when determining whether to authorize the PSI data query to the data repository, the at least one processor is programmed or configured to: querying a transmission authorization request based on the PSI data; receiving an authorization response, wherein the authorization response includes transaction data associated with the matching parameters; determining that the transaction data associated with the match parameters included in the authorization response corresponds to the authorization parameters associated with the match parameters; and Based on determining that the transaction data associated with the matching parameters corresponds to the authorization parameters associated with the matching parameters, it is determined that the PSI data query is authorized.

14. The system of claim 8, wherein when transmitting the data authorization encryption key, the at least one processor is programmed or configured to: Based on determining authorization to conduct the PSI data query to the data repository, the data authorization encryption key is transmitted to the submitting entity system.

15. A non-transitory computer readable medium comprising one or more instructions that, when executed by at least one processor, cause the at least one processor to: Generate data repository; receiving a private set intersection PSI data query, wherein the PSI data query includes matching parameters for executing the PSI data query on the data repository; transmitting a data classification encryption key for encrypting a data field of a transaction data record associated with an entity, wherein the data classification encryption key is associated with a data field of a match parameter data field corresponding to the match parameter; determining whether to authorize the PSI data query to the data repository; transmitting a data authorization encryption key based on determining authorization to conduct the PSI data query to the data repository, wherein the data authorization encryption key is used to encrypt an encrypted data field of a transaction data record associated with an entity to provide two layers of encrypted data fields; as well as The PSI data query is performed on the data repository.

16. The non-transitory computer readable medium of claim 15, wherein the one or more instructions, when executed by at least one processor, further cause the at least one processor to: generating a PSI result based on executing the PSI data query on the data repository; providing the PSI results as input to a machine learning algorithm; and An output of the machine learning algorithm is generated based on the input.

17. The non-transitory computer readable medium of claim 15, wherein: The one or more instructions causing the at least one processor to generate the data repository cause the at least one processor to: encrypting a first data field of a first transaction data record associated with a first entity using a first data classification encryption key to provide an encrypted first data field of a first transaction data record associated with the first entity, wherein the first data classification encryption key is assigned based on a classification of the first data field of the first transaction data record and the first entity; encrypting a second data field of a first transaction data record associated with the first entity using a second data classification encryption key to provide an encrypted second data field of the first transaction data record associated with the first entity, wherein the second data classification encryption key is assigned based on the classification of the second data field of the first transaction data record and the first entity; encrypting a first data field of a second transaction data record associated with a second entity using a third data classification encryption key to provide an encrypted first data field of a second transaction data record associated with the second entity, wherein the third data classification encryption key is assigned based on the classification of the first data field of the second transaction data record and the second entity; as well as A second data field of a second transaction data record associated with the second entity is encrypted using a fourth data classification encryption key to provide an encrypted second data field of a second transaction data record associated with the second entity, wherein the fourth data classification encryption key is assigned based on the classification of the second data field of the second transaction data record and the second entity.

18. The non-transitory computer readable medium of claim 17, wherein: The one or more instructions causing the at least one processor to generate the data repository cause the at least one processor to: encrypting an encrypted first data field of a first transaction data record associated with the first entity using a first data authorization encryption key to provide two layers of encrypted first data fields of a first transaction data record associated with the first entity, wherein the first data authorization encryption key is assigned based on the first entity; encrypting the encrypted first data field of a second transaction data record associated with the second entity using a second data authorization encryption key to provide two layers of encrypted first data fields of a second transaction data record associated with the second entity, wherein the second data authorization encryption key is assigned based on the second entity; storing a two-layer encrypted first data field of a first transaction data record associated with the first entity in the data repository; as well as The two-layer encrypted first data field of a second transaction data record associated with the second entity is stored in the data repository.

19. The non-transitory computer readable medium of claim 17, wherein: The one or more instructions causing the at least one processor to generate the data repository cause the at least one processor to: storing an encrypted second data field of a first transaction data record associated with the first entity in the data repository; as well as An encrypted second data field of a second transaction data record associated with the second entity is stored in the data repository.

20. The non-transitory computer-readable medium of claim 15, wherein the PSI data query further comprises an authorization parameter associated with the matching parameter, wherein the one or more instructions that cause the at least one processor to determine whether to authorize the PSI data query to the data repository cause the at least one processor to: querying a transmission authorization request based on the PSI data; receiving an authorization response, wherein the authorization response includes transaction data associated with the matching parameters; determining that the transaction data associated with the match parameters included in the authorization response corresponds to the authorization parameters associated with the match parameters; and Based on determining that the transaction data associated with the matching parameters corresponds to the authorization parameters associated with the matching parameters, it is determined that the PSI data query is authorized.

Citation Information

Patent Citations

  • Data objects associated with private set intersection (PSI)

    US20190075088A1