Secure Networked System for Sensitive Data Hashing and Research Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in securing sensitive personal information within networks while allowing access for research and data mining without compromising privacy, as modern technology often enables unauthorized access to reverse-engineer 'secure' data.

Innovation Solution

A secure networked system where personal information is cleansed and hashed using specific rules and algorithms across data contributor environments, further secured with a private salt within a secure facility, and linked with unique IDs for controlled access through a virtual private network with two-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal information is hashed and salted to secure it, then security and privacy are improved, but access for research and data mining becomes more restricted

Engineering Contradiction:
ImprovesecurityVSAvoidaccess for research
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a secure facility computing environment as an intermediary between data contributor computing environments and researchers. This intermediary performs the hashing and salting operations on personal information, creating a layered architecture where the secure facility acts as a mediator that enables research access while maintaining security through its cryptographic processing layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a transformed copy of personal information through hashing and salting operations. The original personal information remains protected, while a cryptographic transform (hashed and salted version) is generated that can be used for research purposes. This copying approach allows research access without exposing the original unsecured data.

Inventive Principle:
Principle #26Copying

2Stability of the object's composition

If data is hashed with public salt to ensure consistent structure across environments, then data portability and consistency are improved, but security against re-identification is weakened

Engineering Contradiction:
Improvedata structure consistencyVSAvoidsecurity against re-identification
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The patent segments the salting process into two distinct phases: a public salting phase performed by data contributor computing environments that ensures consistency, and a private salting phase performed by the secure facility computing environment that enhances security. This segmentation allows each phase to serve its specific function without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested hashing structure where the secure facility computes a hash of the personal information, then salts and hashes the result again with a private salt. This nested approach (hash then salt-and-hash again) creates multiple layers of protection while maintaining structural consistency through the standardized public salt first step.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If multiple hashing and salting steps are implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the secure facility computing environment to perform multiple functions: receiving data from multiple data contributor environments, applying consistent public salt, performing private salting, hashing operations, and providing research access. This multi-functionality consolidates complexity into a single centralized system rather than distributing it across multiple independent components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11907399B2Highly secure networked system and methods for storage, processing, and transmission of sensitive personal information
Publication Date: 2024.02.20 OPTUM INC
  • US11907399B2 patent drawing
  • US11907399B2 patent drawing
  • US11907399B2 patent drawing

AI summary

A highly secure networked system and methods for storage, processing, and transmission of sensitive information are described. Sensitive, e.g. personal/private, information is cleansed, salted, and hashed by data contributor computing environments. Cleansing, salting, and hashing by multiple data contributor computing environments occurs using the same processes to ensure output hashed values are consistent across multiple sources. The hashed sensitive information is hashed a second time by a secure facility computing environment. The second hashing of the data involves a private salt inaccessible to third parties. The second hashed data is linked to previously hashed data (when possible) and assigned a unique ID. Data dictionaries are created for particular individuals provided access to the highly secure information, e.g. researchers. Prior to a data dictionary being accessible by a researcher computing device, the data dictionary undergoes compliance and statistical analyses regarding potential re-identification of the source unhashed data. The data dictionaries are viewable by researchers as certified views via a secure VPN.