Secure Private Data Sharing via Trusted Execution Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for sharing private data, such as genetic information, face challenges in ensuring security, authenticity, and incentivizing data providers while preventing fraudulent data distribution, as conventional approaches lack robust security measures and transparent remuneration mechanisms.

Innovation Solution

A secure system utilizing a distributed ledger and trusted execution environments (TEEs) to register, share, and remunerate private data, where data providers receive cryptographic keys for secure data sharing, and smart contracts manage access and payment, while authenticating data through genetic correlation analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional data sharing methods are used, then ease of operation is improved, but security and data privacy are worsened

Engineering Contradiction:
Improvedata sharing convenienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary between data providers and data users. The TEE securely stores encryption keys and performs cryptographic operations, acting as a mediator that enables data sharing without exposing sensitive information. This resolves the contradiction by providing a secure intermediary layer that maintains both ease of operation and data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces conventional mechanical/data access methods with cryptographic mechanisms. Instead of direct data access, the system uses public-key cryptography, digital signatures, and encrypted data transmission. This substitution of cryptographic mechanisms for conventional access methods enables secure data sharing while maintaining operational convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If data providers are incentivized to share data, then productivity is improved, but fraudulent data distribution is worsened

Engineering Contradiction:
Improvedata sharing volumeVSAvoidfraudulent data
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where data users provide evaluations and ratings of the quality and authenticity of shared data. This feedback is recorded on the blockchain and influences future data sharing decisions and remuneration. The feedback loop enables the system to identify and reduce fraudulent data while maintaining incentives for legitimate data providers, thus resolving the contradiction between productivity and fraud prevention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary authentication and verification of data providers and data users before enabling data sharing. The system pre-establishes identities, cryptographic keys, and trust relationships on the blockchain before actual data exchange occurs. This preliminary action prevents fraudulent participants from entering the system, thereby enabling productive data sharing without fraud.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If transparent remuneration mechanisms are implemented, then loss of information is reduced, but device complexity is worsened

Engineering Contradiction:
Improveremuneration transparencyVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent uses blockchain technology to create immutable copies of all remuneration transactions and data sharing agreements. These cryptographic copies are stored on the distributed ledger, providing transparent and verifiable records without requiring complex centralized tracking systems. The copying mechanism on the blockchain achieves transparency while the distributed nature of the ledger manages complexity through decentralization.

Inventive Principle:
Principle #26Copying

4Reliability

If cryptographic security measures are applied, then reliability is improved, but ease of operation is worsened

Engineering Contradiction:
Improvedata protectionVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the trusted execution environment automatically performs cryptographic operations such as key generation, data encryption, and digital signing without requiring manual user intervention. The system autonomously manages security protocols, which maintains high reliability through consistent cryptographic application while preserving ease of operation by eliminating complex security management tasks for users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3622660B1Systems and methods for crowdsourcing, analyzing, and/or matching personal data
Publication Date: 2023.08.30 MASSACHUSETTS INST OF TECH
  • EP3622660B1 patent drawingFigure 1
  • EP3622660B1 patent drawingFigure 2
  • EP3622660B1 patent drawingFigure 3A

AI summary

Described herein are a secure system for sharing private data and related systems and methods for incentivizing and validating private data sharing. In some embodiments, private data providers may register to selectively share private data under controlled sharing conditions. The private data may be cryptographic ally secured using encryption information corresponding to one or more secure execution environments. To demonstrate to the private data providers that the secure execution environment is secure and trustworthy, attestations demonstrating the security of the secure execution environment may be stored in a distributed ledger (e.g., a public blockchain). Private data users that want access to shared private data may publish applications for operating on the private data to a secure execution environment and publish, in a distributed ledger, an indication that the application is available to receive private data. The distributed ledger may also store sharing conditions under which the private data will be shared.