Encrypted Learning Model Processing for Confidential Health Data Training
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in performing machine learning on a learning model without disclosing confidential information and transferring health data, as described in WO2023/119421A, which does not address the use of encrypted models for machine learning.
Innovation Solution
A learning model processing device that receives an encrypted learning model, acquires a dataset, trains the model through confidential computation, and derives an encrypted trained model without disclosing the model or data, while also calculating pricing and rewards based on evaluation results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If health information is transferred from a data management base to a data use base for machine learning, then machine learning can be performed, but confidential information and personal information are exposed
Solution Approach 1:
The patent introduces a trusted execution environment (TEE) as an intermediary layer between the data management base and data use base. The TEE creates an isolated secure computing space where machine learning models are trained without exposing raw health information. The secure enclave acts as a mediator that allows computational access while maintaining data confidentiality through hardware-based isolation and encryption.
Solution Approach 2:
The patent creates a copy of the learning model within the trusted execution environment rather than transferring the actual data. The model is replicated in the secure environment where it can be trained on encrypted or anonymized data copies, ensuring that the original sensitive information remains protected in the data management base while still enabling machine learning operations.
2Ease of operation
If a learning model is moved to a data management base for training, then training can be performed locally, but the learning model which is confidential information is disclosed
Solution Approach 1:
The patent implements a nested structure where the learning model is embedded within a trusted execution environment that is itself nested within the data management base infrastructure. The model operates inside the secure enclave, which provides an additional layer of protection. This nested architecture allows the model to function locally while being protected by multiple layers of security boundaries.
Solution Approach 2:
The patent applies different security qualities to different parts of the system. The trusted execution environment provides enhanced security properties (confidentiality and integrity) specifically where the learning model resides, while other parts of the system operate with standard security measures. This localized security enhancement protects the model without requiring the entire system to be secured at the same level.
3Measurement precision
If a large amount of health information is input for machine learning, then model accuracy improves, but data privacy risks increase
Solution Approach 1:
The patent converts the potential harm of data exposure into a benefit by using the trusted execution environment to enable data processing that would otherwise be impossible. The strict security constraints of the TEE actually enhance the system by allowing the use of sensitive health data for model training while guaranteeing that the data cannot be accessed or leaked, thus turning the privacy risk into a protected resource for improving model accuracy.
Data Source
AI summary
The present invention includes a processor, in which the processor receives transmission of an encrypted learning model from a learning model generation device, acquires a dataset for a learning model, trains the learning model by using the dataset for a learning model through confidential computation, to derive an encrypted trained model, and transmits the trained model to the learning model generation device.


