Private Healthcare Data Computing With Secure Enclave Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for processing private healthcare data face challenges in maintaining privacy and security, particularly when decrypting data for computation, which introduces runtime vulnerabilities and inefficiencies, and de-identification techniques fail to preserve data relationships and are limited to structured datasets.
Innovation Solution
The use of secure enclaves and cryptographic techniques to isolate and protect data processing, ensuring that data is encrypted within the enclave, decrypted only for computation, and re-encrypted before output, while maintaining data integrity and compliance with privacy regulations through policy-controlled data handling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If patient data is processed and stored for research purposes, then the usefulness and benefit of data analysis is improved, but patient privacy and data security are compromised
Solution Approach 1:
The system segments patient data into multiple components: encrypted data stored in secure databases, separate decryption keys held by different authorized parties, and isolated computing environments (sandboxes) for analysis. This segmentation ensures that no single entity has access to both the data and the keys needed to decrypt it, thereby maintaining privacy while enabling research analysis through coordinated computation across segmented components.
Solution Approach 2:
The patent introduces intermediary components including secure enclaves, trusted execution environments, and cryptographic protocols that act as mediators between the raw patient data and the analysis processes. These intermediaries enable computation on encrypted data without exposing the underlying information, thus facilitating research while preserving patient privacy through layered abstraction and controlled access mechanisms.
2Object-affected harmful factors
If data is encrypted to maintain privacy, then patient privacy is protected, but computational processing efficiency is reduced
Solution Approach 1:
The system performs preliminary encryption of patient data before it is stored or transferred, and pre-configures secure computing environments with necessary cryptographic infrastructure. Data is encrypted using efficient algorithms selected based on the intended computation type, and secure enclaves are pre-provisioned with trusted code and keys, reducing the computational overhead during actual analysis operations.
Solution Approach 2:
The patent employs different encryption parameters and algorithms depending on the specific computational task and security requirements. It dynamically adjusts encryption strength, key lengths, and computational parameters to balance privacy protection with processing efficiency, using lighter encryption for frequently accessed data and stronger encryption for sensitive operations, thereby optimizing the trade-off between security and performance.
Data Source
AI summary
Techniques are provided for computing with private healthcare data. The techniques include a de-identification method including receiving a text sequence; providing the text sequence to a plurality of entity tagging models, each of the plurality of entity tagging models being trained to tag one or more portions of the text sequence having a corresponding entity type; tagging one or more entities in the text sequence using the plurality of entity tagging models; and obfuscating each entity among the one or more tagged entities by replacing the entity with a surrogate, the surrogate being selected based on one or more attributes of the entity and maintaining characteristics similar to the entity being replaced.


