A distributed method for secure, real-time sharing of private information
Decentralized processing appliances with unique encryption and two-person rule ensure secure, real-time sharing of sensitive information across networks, addressing the inefficiencies of centralized systems by enabling immediate access control and privacy assurance.
Patent Information
- Application Number
- PCT/US2025/033704
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-20
- Filing Date
- 2025-06-16
- Publication Date
- 2025-12-26
AI Technical Summary
Current methods for sharing sensitive information across networks are costly, time-consuming, and often require centralized, trusted security services, making them inflexible and unable to adapt to dynamic conditions.
A decentralized, real-time method using physically sealed processing appliances that create unique encryption key pairs and validate access authorization, enabling secure communication between 'need-to-know' entities through a distributed network, with no user input or system administration, and enforced by a two-person rule.
Enables secure, real-time sharing of sensitive information across multiple organizations with minimal exposure risk, allowing immediate suspension of access when conditions change, and maintaining high privacy assurance.
Smart Images

Figure US2025033704_26122025_PF_FP_ABST
Abstract
Description
GU0020-PCT PATENT A DISTRIBUTED METHOD FOR SECURE, REAL-TIME SHARING OF PRIVATE INFORMATION Applicant: Georgetown University Inventor: J. Cory Smart CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] The present application claims the benefit of priority to U.S. Provisional PatentApplication No. 63 / 662,347, entitled “A DISTRIBUTED METHOD FOR SECURE, REAL- TIME SHARING OF PRIVATE INFORMATION” filed on June 20, 2024, which is incorporated herein by reference in its entirety.
[0002] Cross-reference is made to co-owned U.S. Patent No. 9,996,567 for PROCESS ANDFRAMEWORK FOR FACILITATING DATA SHARING USING A DISTRIBUTED HYPERGRAPH and similarly titled U.S. Patent No. 10,331,644, a continuation thereof, as well as co-owned U.S. Patent No.10,740,348 for APPLICATION PROGRAMMING INTERFACE AND HYPERGRAPH TRANSFER PROTOCOL SUPPORTING A GLOBAL HYPERGRAPH APPROACH TO REDUCING COMPLEXITY FOR ACCELERATED MULTI- DISCIPLINARY SCIENTIFIC DISCOVERY and similarly titled U.S. Patent No. 11,455,317. These patents and applications are incorporated herein by reference in their entireties. BACKGROUND Field of Embodiments
[0003] Generally, the field of the embodiments is secure communication over a network. Morespecifically, the embodiments describe a method for facilitating secure communications with a high level of privacy assurance across a distributed communications network. Description of Related Art
[0004] Organizations across many sectors have a significant need to share sensitive information.Current approaches are very costly and time consuming to establish, requiring both lengthy engineering design and legal approval processes. Current approaches are typically centralized or they require a centralized, trusted security service to administer. These approaches are also static, generally unable to adjust to changing dynamic conditions.GU0020-PCT PATENT
[0005] There is a need in the art for an improved, de-centralized (e.g., entity controlled) and real-time adaptation approach for sharing and protecting highly sensitive information between “need- to-know” to entities over a network. SUMMAR OF THE EMBODIMENTS
[0006] In a first exemplary embodiment, a physically sealed processing appliance for facilitatingsecure communications includes: a first data store including a pre-installed public encryption keyassociated with users of the appliance stored thereon; a processing store including a first set ofinstructions stored thereon for creating a unique private / public encryption key pair upon aninitial start-up of the processing appliance, the processing store further including a second set ofinstructions for running a validation sequence to validate access authorization for the applianceusers; and a second data store including at least one configuration template loaded onto theappliance by an access-validated user, wherein the configuration template includes a list of peersealed processing appliances with which the processing appliance can communicate.
[0007] In a second exemplary embodiment, a process for configuring a physically sealed,manually inaccessible processing appliance includes: powering up the processing appliance;wherein upon an initial power up of the processing appliance, a first set of instructions stored in apreviously provisioned processing store is automatically initiated to create a uniqueprivate / public encryption key pair for one or more previously provisioned appliance usersassociated with the processing appliance, wherein public encryption keys for the one or moreusers are stored in a first data store on the processing appliance; and initiating a second set ofinstructions for running a validation sequence to validate the one or more previously provisionedappliance users to the processing appliance and to facilitate authorization of further configurationof the processing appliance by validated users.
[0008] In a third exemplary embodiment, a non-transitory computer-readable medium storinginstructions that, when executed by a computer, perform the following process: upon an initialpower up of the processing appliance, a first set of instructions stored in a previously provisionedprocessing store is automatically initiated to create a unique private / public encryption key pairfor one or more previously provisioned appliance users associated with the processing appliance,wherein public encryption keys for the one or more users are stored in a first data store on theprocessing appliance; and initiating a second set of instructions for running a validation sequenceGU0020-PCT PATENT to validate the one or more previously provisioned appliance users to the processing appliance and to facilitate authorization of further configuration of the processing appliance by validated users. BRIEF DESCRIPTION OF THE FIGURES
[0009] Figure 1 illustrates a system of “black box” appliances connected to a computer networkin accordance with an embodiment herein;
[0010] Figure 2 illustrates the AvesTerra shared knowledge space notion that the system ofappliances of Figure 1 collectively manifest; and
[0011] Figure 3 illustrates an architecture of the centralized version of an appliance inaccordance with an embodiment herein. DETAILED DESCRIPTION
[0012] This embodiments described herein provide a method for numerous parties to shareprivate / confidential information at an exceptionally high level of privacy assurance. The embodiments operate in real-time and execute over a distributed communications network (e.g. the Internet). Information is only allowed to be shared after a “need-to-know” (“N2K”) has been established between parties. The risk of exposing private information while the N2K is being ascertained is extremely low. After N2K criteria is met, the only information accessible to those parties is that which conforms to the criteria and has been agreed to in advance by the contributing parties. Changes in N2K criteria can be detected in real-time, enabling information access to be immediately suspended.
[0013] The term “need to know” is a security practice that restricts access to information to onlythose that possess both the necessary security approvals (e.g. security clearance) and that require access to the information in order to conduct one’s official duties.
[0014] N2K is established in real-time between provisioned appliances. Upon start-up, theprovisioned appliances ask each other about their respective entities (e.g., people, places, etc.) and for those entities for which there is a legitimate match (i.e. the other appliance(s) confirmed that they had matching people), the other appliances grant authorization to the submitting appliance to access that entity’s information.GU0020-PCT PATENT
[0015] The embodied highly secure system 1 includes a series of embedded computing devices(i.e. appliances) 5a, 5b,… 5xthat operate as “black boxes”. That is, these appliances are computers that are sealed within a physical enclosure so that all inputs and outputs to the device are tightly controlled by the software within. The appliances have a physical owner, but there isno means for a person to, “log on”. Referring to Figure 3, when the appliance 5x is originallyprovisioned, the public keys of its Appliance Administrator 8 and Application Administrator 10are installed. The appliance 5x is then sealed and these cannot be changed without reprovisioning. Once sealed, any account on the appliance has been disabled. When theprovisioned appliance is powered-on, the appliance processing application 15 (also referencedherein by tradename “ATra”) initiates and runs, thereby managing all subsequent managementrequests, which it enforces via two-person rule. Thus, the provisioned appliances are self- contained, self-managed devices with no login access. Specifically, the devices have no user or system administration accounts. The programming and configuration of the appliance operating system and the application cannot be modified or overridden except via strict two-person rule with Appliance Administrator and Application Administrator which must have been established in advance. Furthermore, the appliances have no user input / output capabilities such as keyboards, pointing devices, displays, etc. All communications flow through the provisionedappliance that is solely controlled by the embedded appliance processing application 15 softwarecontained within. While in operation, a series of provisioned appliances are connected to a computer network (e.g., internet) 20, wherein a single appliance is physically allocated to each participating party (e.g. an individual, or an organization), as shown in Figures 1 and 2. Multiple cooperating parties can share a single appliance.
[0016] When a provisioned appliance is initially started, it contains no data, only the pre-installed public encryption keys for the Appliance Administrator 8 and ApplicationAdministrator 10. Upon startup, the appliance processing application 15 immediately creates aunique private / public encryption key pair. The Appliance Administrator 8 and the Application(ATra) Administrator 10 can create knowledge “compartments” e.g., system compartment 12and ATra compartment 16, on the appliance using two-person rule. That is, the Appliance Administrator can propose a compartment, and the Application Administrator must approve it in order for the compartment to take effect. Templates may be installed in the compartments.Templates are typically uploaded by the Appliance Administrator 8 and then are activated by theGU0020-PCT PATENT Application Administrator 10. Both of these individuals accomplish these tasks bycommunicating with the appliance processing application 15 which enforces all of the rules. Forexample, to load a configuration template 17 within the ATra compartment 16, bothadministrators must first execute a validation sequence using their private encryption key. As part of this validation sequence, an administrator receives an authorization code (i.e. typically 128-bit or greater) that is randomly generated by the appliance processing application 15 and encrypted using the respective administrator’s public key. Each administrator must then decrypt their encrypted authorization code using their private key to obtain their respective authorization codes. Each administrator then must present these back to the appliance processing application 15 as proof (i.e. validation) of their identity. If each of the administrator validation sequences are successful, the appliance processing application 15 will then allow the configuration template tobe loaded onto the appliance by the Appliance Administrator and then activated by theApplication Administrator. Included in the configuration template is a list of peer appliances with which the appliance can communicate. In order for this communication with a second peer appliance to be successful, however, the administrators of each separate appliance must share (1) their public encryption keys with the administrators of the peer appliances with whom they intend to communicate and (2) have the public encryption keys of the peer appliances with whom they plan to communicate installed in their respective appliances by those appliances’ administrators. Similar to configuration templates, public key installation on an appliance requires agreement between both appliance administrators (e.g. 2-person rule enforcement). For a 2-person rule configuration, one administrator (i.e. Appliance / System) would upload other appliance’s public keys onto their appliance, while the second administrator (i.e. Application) would then request their appliance to actually activate the public key. This process is again tightly controlled by the appliance itself.
[0017] Once appliances have validated their administrators, and configuration templates havebeen loaded, the appliances can then begin to communicate with each other. Appliances will typically first validate each other. This process is essentially identical to that of each appliance’s owner, with the appliances receiving authorization codes from their peer appliances if successful (appliance public keys will already have been shared and installed by appliance administrators). At this point, an appliance user can then import data onto their appliance. Appliances provide aprocess for users to do this which requires the administrators to first create a user dataGU0020-PCT PATENT compartment (again via 2-person rule), installing the user’s public key, and the user validating their unique authorization code, again randomly generated by the appliance processing application 15. The data import process is assisted by an import template 18I(and export templates 18E for exporting data by appliances) that users are allowed to upload to their respective appliances via the authorization code they have received and validated. The import template 18Idefines how data is imported. Data is imported in the form of files with records where each record describes what is typically referred to as an “entity.” Entities are typically representations of things such as people, organizations, or specific security compartments. Included in the records, and identified by the configuration templates 17, are the key fields the appliances are to use to ascertain N2K. For people, these fields could be name, date of birth, social security number, etc. For organizations, they could be analogous notions (e.g. name, date of incorporation, federal tax id, etc.). When an appliance detects a new entity (e.g. person), or an update to a previously detected entity, the appliance will contact each of the peer appliances, asking if there is a match to any of their entities. Each appliance uses its configuration template 17 to determine which other appliances it needs to check with. If another server detects a match, it “authorizes” access to the requesting appliance, as specified in its configuration template 17. The server, now peer appliance, sends back a match notice to the requesting appliance so that the requesting appliance is aware of the remote match, i.e., N2K. The requesting appliance uses the match notices from the peer appliance to update their own matching entities; automatically authorizing the peer appliance to the requesting appliance’s matching entities. As there is mutual interest in sharing information if there is a N2K, an appliance will typically respond if there is an appropriate match and the identifiers of the entities that have been matched. As each applianceknows to whom it is communicating, the appliance can then match the remote applianceauthorization code to its local entity’s authorization list. This then allows the remote appliance to view whatever information the local appliance has determined should be shared, based on its local N2K decision. Such N2K decisions are based on the information that the remote appliance has presented, and any additional criteria that local appliance owners include in their configuration templates 17.
[0018] One skilled in the art will appreciate the artifacts 14, such as certificates and patches,which may be stored in system compartment 12.GU0020-PCT PATENT
[0019] Once an appliance has an established N2K, access to the information is availableimmediately, although no information transfer is initiated. The appliances described herein arelayered directly upon the AvesTerra knowledge orchestra framework 30 described in co-ownedU.S. Patent No. 9,996,567 for PROCESS AND FRAMEWORK FOR FACILITATING DATASHARING USING A DISTRIBUTED HYPERGRAPH and similarly titled U.S. Patent No.10,331,644, a continuation thereof. Distributed communications between appliances may be implemented in accordance with the teachings of co-owned U.S. Patent No. 10,740,348 for APPLICATION PROGRAMMING INTERFACE AND HYPERGRAPH TRANSFER PROTOCOL SUPPORTING A GLOBAL HYPERGRAPH APPROACH TO REDUCING COMPLEXITY FOR ACCELERATED MULTI-DISCIPLINARY SCIENTIFIC DISCOVERY and similarly titled U.S. Patent No. 11,455,317.
[0020] Leveraging AvesTerra, the appliances collectively present a shared knowledge space ofentities to their respective users. An entity within a local appliance is accessed the same way as an entity in a remote appliance, simply via its entity unique identifier (EUID). The request, however, must have proper authorization for this access to occur, which the appliances collectively handle automatically through the matching process outlined above. Notification of matches can be performed in real-time as the AvesTerra framework provides a powerful, distributed entity-based event publication and subscription service. As a result, sharing across many organizations at any arbitrary scale is made possible. When a match condition no longer exists, the information access is then automatically relinquished simply by removing theappliance’s authorization on the appropriate entities. Figure 2 below illustrates the AvesTerrashared knowledge space notion that the appliances collectively manifest.
[0021] Each appliance runs core algorithms as described in U.S. Patent Nos. 9,996,567 and10,331,644. An exemplary architecture of the centralized version of an appliance is shown in Figure 3. This embodiment leverages the same basic software structure. However, this structure has been reformulated as described above for distributed operation. Many appliances leveraging this same internal basic software structure now work cooperatively across numerous organizations. Among the key advantages, data is no longer moved outside of an organization’s direct control unless a strict N2K has been established, and the data is required on demand for a specific analytic purpose. Thus, a data contributor can remove its data from view at any time with a simple internal authorization change within their local appliance.GU0020-PCT PATENT
[0022] It is to be understood that the novel concepts described and illustrated herein may assumevarious alternative configurations, except where expressly specified to the contrary. It is also to be understood that the specific systems, devices and processes illustrated in the attached drawings, and described herein, are simply exemplary embodiments of the embodied concepts defined in the appended claims.
Claims
GU0020-PCT PATENT CLAIMS:
1. A physically sealed processing appliance for facilitating secure communications, theprocessing appliance comprising: a first data store including a pre-installed public encryption key associated with users of the appliance stored thereon; a processing store including a first set of instructions stored thereon for creating a unique private / public encryption key pair upon an initial start-up of the processing appliance, the processing store further including a second set of instructions for running a validation sequence to validate access authorization for the appliance users; and a second data store including at least one configuration template loaded onto the appliance by an access-validated user, wherein the configuration template includes a list of peer sealed processing appliances with which the processing appliance can communicate.
2. The physically sealed processing appliance of claim 1, wherein the first data storeincludes different pre-installed public encryption keys associated with different users of theappliance stored thereon, and further wherein the first set of instructions creates different uniqueprivate / public encryption key pairs upon an initial start-up of the processing appliance for different users of the appliance which are stored in the first data store.
3. The physically sealed processing appliance of claim 1, wherein the processing storeincludes a random code generator for generating an encrypted validation code as part of the second set of instructions for running a validation sequence to validate access authorization for the appliance users, further wherein the randomly generated encrypted validation code isprovided to an access-requesting appliance user and the access-requesting appliance user de-crypts the encrypted validation code using its private key stored in the first data store to access the validation code.
4. The physically sealed processing appliance of claim 1, wherein the list of peer sealedprocessing appliances includes associated public keys for each of the listed peer sealed processing appliances.GU0020-PCT PATENT5. A process for configuring a physically sealed, manually inaccessible processingappliance, the process comprising: powering up the processing appliance; wherein upon an initial power up of the processing appliance, a first set of instructionsstored in a previously provisioned processing store is automatically initiated to create a uniqueprivate / public encryption key pair for one or more previously provisioned appliance users associated with the processing appliance, wherein public encryption keys for the one or more users are stored in a first data store on the processing appliance; and initiating a second set of instructions for running a validation sequence to validate the one or more previously provisioned appliance users to the processing appliance and to facilitate authorization of further configuration of the processing appliance by validated users.
6. The process according to claim 5, further comprising:generating, by a random code generator, a first encrypted validation code for a first of the one or more previously provisioned appliance users associated with the processing appliance; receiving, by the first of the one or more previously provisioned appliance users associated with the processing appliance, the first encrypted validation code from the processing store; decrypting, by the first of the one or more previously provisioned appliance users, the first randomly generated encrypted validation code from the processing store using their private key; and presenting the decrypted first validation code to the processing store to confirm they are a first validated user.
7. The process according to claim 6, further comprising:generating, by the random code generator, a second encrypted validation code for a second of the one or more previously provisioned appliance users associated with the processing appliance; receiving, by the second of the one or more previously provisioned appliance users associated with the processing appliance, the second encrypted validation code from the processing store;GU0020-PCT PATENT decrypting, by the second of the one or more previously provisioned appliance users, thesecond randomly generated encrypted validation code from the processing store using theirprivate key; and presenting the decrypted second validation code to the processing store to confirm theyare a second validated user.
8. The process according to claim 7, further comprising:receiving from one of the first or second validated users a configuration template forloading on a second data store of the processing appliance, wherein the configuration templateincludes a list of separate peer sealed processing appliances with which the processing appliancecan communicate.
9. The process according to claim 5, wherein the first data store includes different pre-installed public encryption keys associated with different users of the appliance stored thereon, and further wherein the first set of instructions creates different unique private / public encryptionkey pairs upon initial power up of the processing appliance for different users of the appliancewhich are stored in the first data store.
10. The process according to claim 8, wherein the list of peer sealed processing appliancesincludes associated public keys for each of the listed peer sealed processing appliances.
11. The process according to claim 10, further comprising:invoking a 2-person rule configuration process to activate communication with each ofthe listed peer sealed processing appliances.
12. The process according to claim 11, wherein the 2-person rule configuration processcomprises: uploading by the first validated user each of listed peer sealed processing appliances’public keys onto the first data store;requesting by the second validated user activation of the respective public keys of each oflisted peer sealed processing appliance by the processing store.GU0020-PCT PATENT13. A non-transitory computer-readable medium storing instructions that, when executed bya computer, perform a process for configuring a physically sealed, manually inaccessibleprocessing appliance, the process comprising: upon an initial power up of the processing appliance, a first set of instructions stored in a previously provisioned processing store is automatically initiated to create a unique private / public encryption key pair for one or more previously provisioned appliance users associated with the processing appliance, wherein public encryption keys for the one or more users are stored in a first data store on the processing appliance; and initiating a second set of instructions for running a validation sequence to validate the one or more previously provisioned appliance users to the processing appliance and to facilitateauthorization of further configuration of the processing appliance by validated users.
14. The non-transitory computer-readable medium storing instructions that, when executedby a computer, perform the process for configuring a physically sealed, manually inaccessibleprocessing appliance of claim 13, the process further comprising:generating, by a random code generator, a first encrypted validation code for a first of the one or more previously provisioned appliance users associated with the processing appliance; receiving, by the first of the one or more previously provisioned appliance users associated with the processing appliance, the first encrypted validation code from the processing store; decrypting, by the first of the one or more previously provisioned appliance users, the first randomly generated encrypted validation code from the processing store using their private key; and presenting the decrypted first validation code to the processing store to confirm they are a first validated user.
15. The non-transitory computer-readable medium storing instructions that, when executedby a computer, perform the process for configuring a physically sealed, manually inaccessible processing appliance of claim 14, the process further comprising:GU0020-PCT PATENT generating, by the random code generator, a second encrypted validation code for a second of the one or more previously provisioned appliance users associated with the processing appliance; receiving, by the second of the one or more previously provisioned appliance users associated with the processing appliance, the second encrypted validation code from the processing store; decrypting, by the second of the one or more previously provisioned appliance users, the second randomly generated encrypted validation code from the processing store using their private key; and presenting the decrypted second validation code to the processing store to confirm they are a second validated user.
16. The non-transitory computer-readable medium storing instructions that, when executedby a computer, perform the process for configuring a physically sealed, manually inaccessible processing appliance of claim 15, the process further comprising: receiving from one of the first or second validated users a configuration template for loading on a second data store of the processing appliance, wherein the configuration template includes a list of separate peer sealed processing appliances with which the processing appliancecan communicate, wherein the list of peer sealed processing appliances includes associatedpublic keys for each of the listed peer sealed processing appliances17. The non-transitory computer-readable medium storing instructions that, when executedby a computer, perform the process for configuring a physically sealed, manually inaccessible processing appliance of claim 16, the process further comprising: invoking a 2-person rule configuration process to activate communication with each of the listed peer sealed processing appliances.
18. The non-transitory computer-readable medium storing instructions that, when executedby a computer, perform the process for configuring a physically sealed, manually inaccessible processing appliance of claim 17, the process further comprising:GU0020-PCT PATENT uploading by the first validated user each of listed peer sealed processing appliances’ public keys onto the first data store; requesting by the second validated user activation of the respective public keys of each of listed peer sealed processing appliance by the processing store.
Citation Information
Patent Citations
Managing network connected devices
US20220247624A1
Blockchain schema for secure data transmission
US20230037520A1