Data Service for Genomic Privacy via Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access models for genomic and sensitive data do not adequately address the intransitivity of trust, leading to potential privacy breaches and ethical concerns, as they rely on users to enforce complex policies without sufficient technical capabilities.

Innovation Solution

The implementation of a data service that provides stronger security and privacy functionality, enabling policy-based governance and secure access to sensitive data through a framework of trusted cloud services, application programming interfaces (APIs), and sandboxed execution environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If researchers are given unfettered access to genomic data under trust-based models, then data availability for research is improved, but privacy protection and security control deteriorate

Engineering Contradiction:
Improvedata availability for researchVSAvoidprivacy protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a data service as an intermediary between researchers and genomic data. This service enforces access policies, controls data usage, and monitors compliance automatically. The intermediary layer allows researchers to access data for legitimate purposes while preventing privacy breaches through technical enforcement of policies, thus resolving the contradiction between data availability and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If complex privacy policies are enforced through user discretion, then flexibility in data use is improved, but reliability of policy enforcement deteriorates

Engineering Contradiction:
Improveflexibility in data useVSAvoidpolicy enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements automated policy enforcement mechanisms that operate without requiring user discretion. The data service automatically monitors data access, enforces usage policies, and detects violations. This self-service approach to policy enforcement maintains flexibility in legitimate data use while ensuring reliable enforcement through automated technical controls rather than relying on user judgment.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If users are responsible for enforcing privacy policies, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveuser responsibility for policy enforcementVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex policy enforcement functionality from the user's responsibility and places it within the data service infrastructure. Users simply request data access through standard interfaces, while the embedded policy enforcement mechanisms handle the complex verification and monitoring automatically. This extraction reduces the operational burden on users while managing the system complexity within the service layer.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250095788A1Secure computing systems and methods
Publication Date: 2025.03.20 INTERTRUST TECH CORP
  • US20250095788A1 patent drawing
  • US20250095788A1 patent drawing
  • US20250095788A1 patent drawing

AI summary

The present disclosure relates to systems and methods for facilitating trusted handling of genomic and/or other sensitive information. Certain embodiments may use a virtualized execution environment to execute code and/or programs that wish to access and/or otherwise use genomic and/or other sensitive information. In some embodiments, data requests from the code and/or programs may be routed through a transparent data access proxy configured to transform requests and/or associated responses to protect the integrity of the genomic and/or other sensitive information.