Secure Enclave Analytics for Confidential Laboratory Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Clinical laboratories are reluctant to collaborate due to privacy and security concerns, relying on untrusted third-party infrastructure for data analytics, which poses risks of data theft, unauthorized access, and integrity breaches, limiting data sharing and analysis capabilities.

Innovation Solution

A client-server based collaborative laboratory data analytics system using Intel SGX trusted execution environment ensures confidentiality and integrity by creating a secure enclave for data exchange, attesting execution environment integrity, and employing secure communication and encryption to protect patient data from unauthorized access and modification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If laboratories use third-party infrastructure for data analytics, then computation and storage efficiency is improved, but trust and security are worsened

Engineering Contradiction:
Improvecomputation and storage efficiencyVSAvoidtrust and security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a Trusted Execution Environment (TEE) as an intermediary layer between the untrusted third-party cloud infrastructure and the sensitive patient data. The TEE creates a secure enclave that mediates all data operations, allowing laboratories to leverage cloud computing resources while maintaining cryptographic guarantees of data confidentiality and integrity. This resolves the contradiction by enabling efficient cloud-based analytics (improving productivity) while the TEE intermediary ensures security and trust (maintaining reliability).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the security model by changing the trust parameter from relying on the honesty of third-party infrastructure providers to relying on cryptographic proofs and hardware-enforced security boundaries. By using attestation mechanisms and secure enclaves, the system changes how trust is established - not through organizational trust but through mathematical and hardware guarantees, thereby improving reliability while maintaining cloud-based productivity.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If laboratories share patient data for collaborative analysis, then data analytics capability is improved, but privacy and security risks are worsened

Engineering Contradiction:
Improvedata analytics capabilityVSAvoidprivacy and security risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security-critical operations (data decryption, analysis execution, result generation) from the untrusted cloud environment and places them inside a Trusted Execution Environment. This extraction allows collaborative analytics across multiple laboratories because each lab's data remains encrypted outside the TEE and only decrypts within the secure enclave, eliminating privacy risks while enabling enhanced analytics capabilities through data aggregation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The TEE creates an inert or isolated environment for processing sensitive patient data during collaborative analytics. Within this secure enclave, data from multiple laboratories can be combined and analyzed without risk of interception or unauthorized access. The inert nature of the TEE environment ensures that even though data is shared for collaborative purposes, the privacy and security risks are eliminated because the data cannot escape the secure boundary.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Measurement precision

If data is stored and processed in plain text for analysis, then analysis accuracy is improved, but data theft and modification risks are worsened

Engineering Contradiction:
Improveanalysis accuracyVSAvoiddata theft and modification risks
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary encryption to patient data before it leaves the laboratory systems, and maintains this encrypted state throughout storage and transmission. The data is only decrypted within the Trusted Execution Environment immediately before analysis operations. This preliminary protective action ensures that even if data is intercepted or accessed unauthorized, it remains encrypted and unusable, thereby eliminating theft and modification risks while still enabling accurate analysis within the secure enclave.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12518039B2Secure collaborative laboratory data analytics system
Publication Date: 2026.01.06 ROCHE DIAGNOSTICS OPERATIONS INC
  • US12518039B2 patent drawing
  • US12518039B2 patent drawing
  • US12518039B2 patent drawing

AI summary

A method of creating a secure collaborative analysis system for securely using a dataset from a plurality of laboratories (150) while ensuring confidentiality, integrity, and authenticity of input and result data among the plurality of collaborating laboratories (150) is presented. The plurality of laboratories (150) are communicatively connected to an execution environment. The method comprise creating a secure enclave (110) within the execution environment for data exchange and analysis, attestation of the execution environment and the secure enclave (110) to verify integrity and authenticity of the system, generating a random 12-byte character inside the secure enclave (110) to provide integrity protection for storing records in a database (130), and building a communication component to provide a means of secure communication between the plurality of laboratories (150) and the execution environment. The communication component comprises a trusted section within the secure enclave (110) and an unprotected section. The plurality of laboratories (150) communicate with the trusted part via a secure channel. The method further comprises detecting any unauthorized modification to the record stored in the database (130) outside of the secure enclave (110) by a records integrity component, storing the encrypted dataset in the persistent storage disk (120) received from the plurality of laboratories (150), retrieving the encrypted dataset inside the secure enclave (110), decrypting the encrypted dataset inside the secure enclave (110), providing the decrypted dataset to an analysis engine component within the secure enclave (110) for analysis, and providing results of that analysis to plurality of laboratories (150) in the secure manner.