US2023244806A1PendingUtilityA1

Securely processing shareable data utilizing a vault proxy

Assignee: SYMPATIC INCPriority: Jul 14, 2020Filed: Mar 28, 2023Published: Aug 3, 2023
Est. expiryJul 14, 2040(~14 yrs left)· nominal 20-yr term from priority
G06F 21/6218G06F 9/45558H04L 67/56G06F 2009/45579G06F 2009/45587G06F 2221/2141G06F 21/6245H04L 67/562H04L 67/563
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method includes a data processing system creating a proxy for a virtual vault to access a data owner system in accordance with a temporary credential protocol between the data processing system and the data owner system, where the proxy is an only path for transmitting data between the virtual vault and the data owner system. The method further includes the proxy facilitating processing, in accordance with data access credentials of the data owner system, of a data query from the virtual vault, where the data query is regarding shareable data of the data owner system. The method further includes the data processing system deleting the proxy when the data query has been completed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprises:
 creating, by a data processing system, a proxy for a virtual vault to access a data owner system in accordance with a temporary credential protocol between the data processing system and the data owner system, wherein the proxy is an only path for transmitting data between the virtual vault and the data owner system;   facilitating processing, by the proxy and in accordance with data access credentials of the data owner system, of a data query from the virtual vault, wherein the data query is regarding shareable data of the data owner system; and   deleting, by the data processing system, the proxy when the data query has been completed.   
     
     
         2 . The method of  claim 1 , wherein the facilitating processing the data query further comprises:
 receiving, by the proxy, one or more requests of the data query from a virtual machine within the virtual vault, wherein the one or more requests is requesting at least a portion of the shareable data;   when the one or more requests are valid, creating by the proxy, one or more data retrieval request based on the one or more requests and the data access credentials associated with the data owner system; and   forwarding, by the proxy, one or more data responses from the data owner system to the virtual machine.   
     
     
         3 . The method of  claim 2  further comprises:
 obtaining, by the proxy, an agreement from temporary storage of the virtual vault, wherein the agreement includes parameters for the data query that are valid within the virtual vault; 
 determining, by the proxy and based on the parameters, whether the one or more requests are in accordance with the parameters; and 
 when the one or more requests are in accordance with the parameters, determining, by the proxy, the one or more requests are valid. 
 
     
     
         4 . The method of  claim 1  further comprises:
 creating, by the data processing system, a proxy container, wherein the proxy container includes the proxy. 
 
     
     
         5 . The method of  claim 4  further comprises:
 creating, by the data processing system, temporary storage within the proxy container, wherein the temporary storage stores data access credentials of the proxy with respect to the data owner system. 
 
     
     
         6 . The method of  claim 1  further comprises:
 creating, by the data processing system, an analysis container, wherein the analysis container includes one or more virtual machines. 
 
     
     
         7 . The method of  claim 6 , wherein the analysis container is located within the virtual vault. 
     
     
         8 . The method of  claim 6 , wherein a virtual machine of the one or more virtual machines comprises one of:
 a virtual machine data mining module;   a virtual machine database module; and   a virtual machine data processing module.   
     
     
         9 . The method of  claim 1 , wherein the data access credentials include one or more of:
 a token;   a public/private keypair;   multi-factor authentication;   a username;   a password; and   an access key identifier and secret access key.   
     
     
         10 . The method of  claim 1  further comprises:
 modifying, by a virtual machine of the virtual vault, a data record of the data owner system such that an identity of an object of the data record to be substantially unknowable to produce a first portion of the shareable data, wherein the data includes a set of data records that includes the data record, wherein the data record includes a plurality of data fields, wherein a first set of data fields of the plurality of data fields is regarding identification of an object of the data record and a second set of data fields of the plurality of data fields is regarding data regarding the object, and wherein the modifying the data record includes altering content of the first set of data fields. 
 
     
     
         11 . A non-transitory computer readable storage medium comprises:
 at least one memory section that stores operational instructions, that when executed by one or more computing devices of a data processing system, causes the one or more computing devices to:   create a proxy for a virtual vault to access a data owner system in accordance with a temporary credential protocol between the data processing system and the data owner system, wherein the proxy is an only path for transmitting data between the virtual vault and the data owner system;   facilitate processing, in accordance with data access credentials of the data owner system, a data query from the virtual vault, wherein the data query is regarding shareable data of the data owner system; and   delete the proxy when the data query has been completed.   
     
     
         12 . The non-transitory computer readable storage medium of  claim 11 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 receive one or more requests of the data query from a virtual machine within the virtual vault, wherein the one or more requests is requesting at least a portion of the shareable data;   when the one or more requests are valid, create one or more data retrieval requests based on the one or more requests and the data access credentials associated with the data owner system; and   forward one or more data responses from the data owner system to the virtual machine.   
     
     
         13 . The non-transitory computer readable storage medium of  claim 12 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 obtain an agreement from temporary storage of the virtual vault, wherein the agreement includes parameters for the data query that are valid within the virtual vault;   determine based on the parameters, whether the one or more requests are in accordance with the parameters; and   when the one or more requests are in accordance with the parameters, determine the one or more requests are valid.   
     
     
         14 . The non-transitory computer readable storage medium of  claim 11 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 create a proxy container, wherein the proxy container includes the proxy.   
     
     
         15 . The non-transitory computer readable storage medium of  claim 14 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 create temporary storage within the proxy container, wherein the temporary storage stores data access credentials of the proxy with respect to the data owner system.   
     
     
         16 . The non-transitory computer readable storage medium of  claim 11 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 create an analysis container, wherein the analysis container includes one or more virtual machines.   
     
     
         17 . The non-transitory computer readable storage medium of  claim 16 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 create the analysis container within the virtual vault.   
     
     
         18 . The non-transitory computer readable storage medium of  claim 16 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 create the one or more virtual machines, wherein a virtual machine of the one or more virtual machines comprises one of a virtual machine data mining module, a virtual machine database module, and a virtual machine data processing module.   
     
     
         19 . The non-transitory computer readable storage medium of  claim 11 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to determine the data access credentials include one or more of:
 a token;   a public/private keypair;   multi-factor authentication;   a username;   a password; and   an access key identifier and secret access key.   
     
     
         20 . The non-transitory computer readable storage medium of  claim 11 , wherein the at least one memory section stores further operational instructions, that when executed by the one or more computing devices, causes the one or more computing devices to:
 modify a data record of the data owner system such that an identity of an object of the data record to be substantially unknowable to produce a first portion of the shareable data, wherein the data includes a set of data records that includes the data record, wherein the data record includes a plurality of data fields, wherein a first set of data fields of the plurality of data fields is regarding identification of an object of the data record and a second set of data fields of the plurality of data fields is regarding data regarding the object, and wherein the modifying the data record includes altering content of the first set of data fields.

Join the waitlist — get patent alerts

Track US2023244806A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.