Private Healthcare Data Computing With Secure Enclave Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for processing private healthcare data face challenges in maintaining privacy and security, particularly when decrypting data for computation, which introduces runtime vulnerabilities and inefficiencies, and de-identification techniques fail to preserve data relationships and are limited to structured datasets.

Innovation Solution

The use of secure enclaves and cryptographic techniques to isolate and protect data processing, ensuring that data is encrypted within the enclave, decrypted only for computation, and re-encrypted before output, while maintaining data integrity and compliance with privacy regulations through policy-controlled data handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If patient data is processed and stored for research purposes, then the usefulness and benefit of data analysis is improved, but patient privacy and data security are compromised

Engineering Contradiction:
Improvedata analysis capabilityVSAvoidprivacy risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system segments patient data into multiple components: encrypted data stored in secure databases, separate decryption keys held by different authorized parties, and isolated computing environments (sandboxes) for analysis. This segmentation ensures that no single entity has access to both the data and the keys needed to decrypt it, thereby maintaining privacy while enabling research analysis through coordinated computation across segmented components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including secure enclaves, trusted execution environments, and cryptographic protocols that act as mediators between the raw patient data and the analysis processes. These intermediaries enable computation on encrypted data without exposing the underlying information, thus facilitating research while preserving patient privacy through layered abstraction and controlled access mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If data is encrypted to maintain privacy, then patient privacy is protected, but computational processing efficiency is reduced

Engineering Contradiction:
Improveprivacy protectionVSAvoidprocessing efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system performs preliminary encryption of patient data before it is stored or transferred, and pre-configures secure computing environments with necessary cryptographic infrastructure. Data is encrypted using efficient algorithms selected based on the intended computation type, and secure enclaves are pre-provisioned with trusted code and keys, reducing the computational overhead during actual analysis operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs different encryption parameters and algorithms depending on the specific computational task and security requirements. It dynamically adjusts encryption strength, key lengths, and computational parameters to balance privacy protection with processing efficiency, using lighter encryption for frequently accessed data and stronger encryption for sensitive operations, thereby optimizing the trade-off between security and performance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12619782B2Systems and methods for computing with private healthcare data
Publication Date: 2026.05.05 NFERENCE INC
  • US12619782B2 patent drawing
  • US12619782B2 patent drawing
  • US12619782B2 patent drawing

AI summary

Techniques are provided for computing with private healthcare data. The techniques include a de-identification method including receiving a text sequence; providing the text sequence to a plurality of entity tagging models, each of the plurality of entity tagging models being trained to tag one or more portions of the text sequence having a corresponding entity type; tagging one or more entities in the text sequence using the plurality of entity tagging models; and obfuscating each entity among the one or more tagged entities by replacing the entity with a surrogate, the surrogate being selected based on one or more attributes of the entity and maintaining characteristics similar to the entity being replaced.