US2024045989A1PendingUtilityA1

Systems and methods for secure data aggregation and computation

Assignee: EXPERIAN INF SOLUTIONS INCPriority: Jan 11, 2019Filed: Feb 21, 2023Published: Feb 8, 2024
Est. expiryJan 11, 2039(~12.5 yrs left)· nominal 20-yr term from priority
G06F 21/6245G06Q 50/265G06F 16/9535G06F 21/602G06Q 40/03G06F 21/6254
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for data aggregation and processing are provided in manner that is decentralized and preserves privacy. A data aggregation and computation system may include an interface, a controller, and one or more clusters of computation nodes. The interface may receive an inquiry from a requesting entity for computing information regarding an individual based on pieces of information held by a plurality of entities. The controller may communicate an identifier for the individual to a processor system associated with each of the entities based on the inquiry. The clusters of computation nodes may each receive encrypted data fragments from each of the processor systems, the data fragments comprising unrecognizable fragments that no individual processor system can re-assemble to recover the information, perform secure, multi-party computations based on the data fragments, and generate a result based on the secure, multi-party computations for the individual.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A system comprising:
 memory; and   at least one computing device configured with computer-executable instructions that, when executed, cause the at least one computing device to perform operations comprising at least:
 receiving an inquiry from a requesting entity system requesting generation or calculation of information regarding an individual based on pieces of protected information held by a plurality of data provider systems; 
 based on the inquiry, communicating requests to each of a plurality of computation nodes to generate encrypted data fragments associated with the inquiry, wherein the requests each include an identifier corresponding to the individual, wherein each of the plurality of computation nodes is associated with a respective one of the data provider systems and is designated to process one or more of the pieces of protected information held by the respective data provider; 
 receiving, in response to the requests, the encrypted data fragments from the plurality of computation nodes without receiving any of the protected information, wherein a first subset of the encrypted data fragments received from a first computation node are different than a second subset of the encrypted data fragments received from a second computation node, wherein the first subset of the encrypted data fragments have been generated based on one or more different pieces of protected information than the second subset of the encrypted data fragments have been generated based on, wherein encrypted data fragments generated by each computation node cannot be re-assembled by any other computation node to recover corresponding protected information; 
 performing secure multi-party computations based on the encrypted data fragments received from each of the plurality of computation nodes; 
 generating a result related to the individual based on the secure multi-party computations; and 
 generating and transmitting, to the requesting entity system, a response to the inquiry based on the result related to the individual. 
   
     
     
         22 . The system of  claim 21 , wherein the plurality of data provider systems comprises one or more of: a financial institution, a healthcare institution, or a consumer data institution. 
     
     
         23 . The system of  claim 21 , further comprising an identifier database, wherein the at least one computing device is further configured to:
 identify respective identifiers of the individual for each of the plurality of data provider systems based on the inquiry, and   communicate the respective identifiers to the respective computation node for each data provider system.   
     
     
         24 . The system of  claim 21 , wherein each computation node is configured to perform initial computations with respect to one or more of the pieces of protected information before generating corresponding encrypted data fragments. 
     
     
         25 . The system of  claim 21 , wherein the plurality of computation nodes are clustered or grouped into two or more clusters or computation groups that are each assigned to a different one of the plurality of data provider systems. 
     
     
         26 . The system of  claim 25 , wherein a quantity of computation nodes within an individual cluster or computation group is based on a desired security level. 
     
     
         27 . The system of  claim 21 , wherein the inquiry comprises an information verification request comprising verification information to be verified, and wherein the response to the enquiry is an affirmative or negative response. 
     
     
         28 . The system of  claim 27 , wherein the at least one computing device is further configured to provide the affirmative response to the requesting entity system in response to the inquiry when the result verifies the verification information. 
     
     
         29 . The system of  claim 21 , wherein the inquiry comprises a request to compute a credit score for the individual, and wherein the response comprises the credit score for the individual. 
     
     
         30 . A computer-implemented method comprising:
 receiving an inquiry from a requesting entity system requesting generation or calculation of information regarding an individual based on pieces of protected information held by a plurality of data provider systems;   based on the inquiry, communicating requests to each of a plurality of computation nodes to generate encrypted data fragments associated with the inquiry, wherein the requests each include an identifier corresponding to the individual, wherein each of the plurality of computation nodes is associated with a respective one of the data provider systems and is designated to process one or more of the pieces of protected information held by the respective data provider;   receiving, in response to the requests, the encrypted data fragments from the plurality of computation nodes without receiving any of the protected information, wherein a first subset of the encrypted data fragments received from a first computation node are different than a second subset of the encrypted data fragments received from a second computation node, wherein the first subset of the encrypted data fragments have been generated based on one or more different pieces of protected information than the second subset of the encrypted data fragments have been generated based on, wherein encrypted data fragments generated by each computation node cannot be re-assembled by any other computation node to recover corresponding protected information;   performing secure multi-party computations based on the encrypted data fragments received from each of the plurality of computation nodes;   generating a result related to the individual based on the secure multi-party computations; and   generating and transmitting, to the requesting entity system, a response to the inquiry based on the result related to the individual.   
     
     
         31 . The computer-implemented method of  claim 30 , wherein the plurality of data provider systems comprises one or more of: a financial institution, a healthcare institution, or a consumer data institution. 
     
     
         32 . The computer-implemented method of  claim 30 , wherein each computation node is configured to perform initial computations with respect to one or more of the pieces of protected information before generating corresponding encrypted data fragments. 
     
     
         33 . The computer-implemented method of  claim 30 , wherein the plurality of computation nodes are clustered or grouped into two or more clusters or computation groups that are each assigned to a different one of the plurality of data provider systems. 
     
     
         34 . The computer-implemented method of  claim 33 , wherein a quantity of computation nodes within an individual cluster or computation group is based on a desired security level. 
     
     
         35 . The computer-implemented method of  claim 30 , wherein the inquiry comprises an information verification request comprising verification information to be verified, and wherein the response to the enquiry is an affirmative or negative response. 
     
     
         36 . The computer-implemented method of  claim 35 , wherein the at least one computing device is further configured to provide the affirmative response to the requesting entity system in response to the inquiry when the result verifies the verification information. 
     
     
         37 . The computer-implemented method of  claim 30 , wherein the inquiry comprises a request to compute a credit score for the individual, and wherein the response comprises the credit score for the individual. 
     
     
         38 . A non-transitory computer storage medium storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising at least:
 receiving an inquiry from a requesting entity system requesting generation or calculation of information regarding an individual based on pieces of protected information held by a plurality of data provider systems;   based on the inquiry, communicating requests to each of a plurality of computation nodes to generate encrypted data fragments associated with the inquiry, wherein the requests each include an identifier corresponding to the individual, wherein each of the plurality of computation nodes is associated with a respective one of the data provider systems and is designated to process one or more of the pieces of protected information held by the respective data provider;   receiving, in response to the requests, the encrypted data fragments from the plurality of computation nodes without receiving any of the protected information, wherein a first subset of the encrypted data fragments received from a first computation node are different than a second subset of the encrypted data fragments received from a second computation node, wherein the first subset of the encrypted data fragments have been generated based on one or more different pieces of protected information than the second subset of the encrypted data fragments have been generated based on, wherein encrypted data fragments generated by each computation node cannot be re-assembled by any other computation node to recover corresponding protected information;   performing secure multi-party computations based on the encrypted data fragments received from each of the plurality of computation nodes;   generating a result related to the individual based on the secure multi-party computations; and   generating and transmitting, to the requesting entity system, a response to the inquiry based on the result related to the individual.

Join the waitlist — get patent alerts

Track US2024045989A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.