Secure Data Portal Using Encrypted Synthetic Datasets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The lengthy process of obtaining permissions for data analysis in databases containing sensitive information significantly slows down the extraction of value from these databases and can prohibit projects from starting.
Innovation Solution
A mechanism combining privacy and encryption technologies through a cloud-based portal enables remote data exploration without the need for lengthy permission processes, using differential privacy and homomorphic encryption to allow secure access to sensitive data for analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional permission processes are used for data analysis, then data security and privacy protection are maintained, but the time required to extract value from the database increases significantly
Solution Approach 1:
The patent introduces a trusted third-party intermediary that holds cryptographic keys and enables secure data access without requiring direct permission negotiations between data owners and analysts. This intermediary facilitates encrypted data sharing and computation, allowing value extraction while maintaining security without the lengthy permission processes of traditional approaches.
Solution Approach 2:
The system performs preliminary cryptographic setup and key distribution before actual data analysis begins. Data is pre-encrypted and access controls are pre-configured, allowing analysts to immediately begin work on approved datasets without requiring additional permission approvals during the analysis process.
2Reliability
If encrypted data is used for analysis, then privacy is preserved, but the complexity of the data processing system increases
Solution Approach 1:
The patent replaces complex mechanical security systems (physical access controls, manual permission management) with cryptographic mechanisms. Homomorphic encryption and secure multi-party computation algorithms enable secure data processing without requiring complex physical security infrastructures or manual intervention, reducing operational complexity while maintaining strong privacy protection.
Solution Approach 2:
The cryptographic system is designed to perform multiple functions: encryption, decryption, secure computation, key management, and access control all through unified cryptographic protocols. This multi-functionality reduces the need for separate security systems and simplifies the overall architecture compared to implementing multiple independent security mechanisms.
3Productivity
If full data access is granted for analysis, then data exploration efficiency is improved, but sensitive information security is compromised
Solution Approach 1:
The patent implements fine-grained access control where different portions of the data have different security properties and access requirements. Specific fields or records can be encrypted with different keys or have different access policies, allowing analysts to access only the specific data portions they need for their analysis while other sensitive portions remain protected, maintaining both efficiency and security.
Solution Approach 2:
The system creates encrypted copies of the data that can be safely shared and analyzed without exposing the original sensitive information. These cryptographic replicas allow full data exploration on the copy while the original remains secure, enabling high productivity without compromising the security of the source data.
Data Source
AI summary
A system for private and secure data portal is described. A method includes receiving, from a first client device, a permission request and a data request for a first dataset that is stored at a second client device, providing the permission request and the data request to the second client device, the second client device configured to generate, in response to the permission request and the data request, a data usage approval document and an encrypted synthesized dataset corresponding to the data usage approval document, the encrypted synthesized dataset includes a synthetic second dataset representative of the first dataset, receiving, from the second client device, the data usage approval document and the encrypted synthesized dataset, performing, at a server, a computation on the encrypted synthesized dataset based on the data request, and providing the data usage approval document and results of the computation to the first client device.


