Data processing system for securely processing shareable data
Abstract
A method includes a data processing system receiving, via an interface from a data consumer computing entity, a request for data processing in accordance with specific data criteria. The method further includes determining, based on the specific data criteria, a data owner system to utilize in processing the request. The method further includes securely accessing, in accordance with a temporary credential protocol between the data processing system and the data owner system, a database of the data owner system regarding a set of data records having the specific data criteria. The method further includes securely modifying the set of data records to produce a set of shareable data records. The method further includes executing a data analysis function on the set of shareable data records to produce an analytical result. The method further includes sending, via an interface, the analytical result to the data consumer computing entity.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A data processing system comprises:
an interface; memory; and a processing module operably coupled to the interface and the memory, wherein the processing module is operable to: receive, via the interface from a data consumer computing entity, a request for data processing in accordance with specific data criteria; determine, based on the specific data criteria, a data owner system to utilize in processing the request; securely access, in accordance with a temporary credential protocol between the data processing system and the data owner system, a database of the data owner system regarding a set of data records having the specific data criteria; securely modify the set of data records to produce a set of shareable data records; execute a data analysis function on the set of shareable data records to produce an analytical result; and send, via the interface, the analytical result to the data consumer computing entity.
2 . The data processing system of claim 1 , wherein the processing module is further operable to operate in accordance with the temporary credential protocol by:
establishing, by the data owner system, first temporary security credentials for the data processing system to create a virtual machine; and after the virtual machine is created and in accordance with the first temporary security credentials, establishing, by the data processing system, second temporary security credentials for the virtual machine to perform the securely accessing the database of the data owner system.
3 . The data processing system of claim 2 , wherein the processing module is further operable to:
create a second virtual machine for use with a second data owner system in accordance with a second temporary credential protocol between the data processing system and a second data owner system, wherein the second virtual machine operates to:
securely access a second database of the second data owner system regarding a second set of data records having the specific data criteria; and
modify the second set of data records to produce a second set of shareable data records.
4 . The data processing system of claim 3 , wherein the processing module is further operable to perform the executing the data analysis function by:
creating a data processing virtual machine to execute the data analysis function on the set of shareable data records and the second set of shareable data records to produce the analytical result; and after the analytical result is sent to the data consumer computing entity:
deleting the data processing virtual machine; and
deleting the first and second virtual machines.
5 . The data processing system of claim 1 , wherein the processing module is further operable
securely access, in accordance with the temporary credential protocol between the data processing system and a second data owner system, a second database of the second data owner system regarding a second set of data records having the specific data criteria; and securely modify the second set of data records to produce a second set of shareable data records.
6 . The data processing system of claim 5 , wherein the processing module is further operable to:
execute the data analysis function on the second set of shareable data records to produce a second analytical result.
7 . The data processing system of claim 6 , wherein the processing module is further operable to:
combine the second analytical result with the analytical result to produce an updated analytical result; and send, via the interface, the updated analytical result to the data consumer computing entity.
8 . The data processing system of claim 5 , wherein the processing module is further operable to:
combine shareable data records such that the second set of shareable data records are included in the set of shareable data records.
9 . The data processing system of claim 1 , wherein the processing module is further operable to:
determine a data record of the set of data records includes a plurality of data fields, wherein a first set of data fields of the plurality of data fields is regarding identification of an object of the data record and a second set of data fields of the plurality of data fields is regarding data regarding the object, and wherein the modifying the data record includes altering content of the first set of data fields to render identity of the object to be substantially unknowable.
10 . The data processing system of claim 9 , wherein the processing module is further operable to perform the altering by one or more of:
deleting the content of the first set of data fields; obfuscating the content of the first set of data fields; and replacing the content of the first set of data fields with generic content.
11 . The data processing system of claim 9 , wherein the processing module is further operable to perform the modifying by:
normalizing the set of data records to produce the set of shareable data records.
12 . The data processing system of claim 1 , wherein the processing module is further operable to:
determine the specific data criteria based on a query of the request; and generate the data analysis function based on the specific data criteria.
13 . The data processing system of claim 1 , wherein processing module is further operable to determine the specific data criteria comprises one or more of:
a first medication; a second medication; a blood type; doctor information; a plurality of patients; and a list of symptoms for each patient of the plurality of patients having the blood type, and taking the first and second medications.
14 . The data processing system of claim 1 , wherein the processing module is further operable to:
create a virtual database; and store the set of shareable data records in the virtual database.
15 . The data processing system of claim 14 , wherein the processing module is further operable to:
delete the virtual database after the analytical result is sent to the data consumer computing entity.
16 . The data processing system of claim 1 , wherein the processing module is further operable to perform the accessing the memory of the data owner system by:
identifying data fields of data records stored in the memory based on the specific data criteria to produce data fields of interest; accessing the data records stored in the memory; and when a data record of the data records includes the data fields of interest, adding the data record to the set of data records.
17 . The data processing system of claim 1 , wherein the processing module is further operable determine the data owner system to utilize in processing the request by:
identifying a number of data owner systems estimated to have data records associated with the specific data criteria; sending, via the interface, a participation request regarding a query of the request for data processing to the number of data owner systems; receiving, via the interface, one or more favorable participation responses from the number of data owner systems; and when a favorable participation response of the one or more favorable participation responses is from the data owner system, determining to utilize the data owner system in processing the request.
18 . The data processing system of claim 1 , wherein the processing module is further operable determine the data owner system to utilize in processing the request by:
identifying a number of data owner systems estimated to have data records associated with the specific data criteria, wherein the number of data owner systems have previously registered with the data processing system, agreed to fulfill certain requests, and provided information regarding data having the specific data criteria; determining whether the request is one of the certain requests; and when the request is one of the certain requests, selecting the data owner system from the number of data owner systems.
19 . The data processing system of claim 1 , wherein the processing module is further operable to:
execute a second data analysis function on the set of shareable data records to produce a second analytical result; and send, via the interface, the second analytical result to the data consumer computing entity.
20 . The data processing system of claim 1 , wherein the processing module is further operable to:
determine a required level of anonymity based on a data owner policy; and modifying data fields of the shareable set of data records such that the shareable set of data records have the required level of anonymity.Join the waitlist — get patent alerts
Track US2023089117A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.