Server equipment, computer programs, and data management methods
The described system ensures secure transmission of sensitive personal information by authenticating client devices, enhancing security without compromising user convenience by only transmitting data after successful authentication.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2026-04-08
AI Technical Summary
Existing dosing management systems lack sufficient security measures to protect sensitive personal information transmitted from client devices without compromising user convenience.
A server device and client device system that authenticates client devices using identification information and contract information to ensure secure transmission of sensitive personal information only when authentication is successful, preventing unauthorized access.
Enhances the security of sensitive personal information transmission by ensuring it is only sent to the server device after successful authentication, thereby reducing the burden on users and preventing unauthorized access.
Smart Images

Figure 2026060347000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a server device capable of communicating with a client device on which a service related to drug prescription is executed. The present disclosure also relates to a computer program executable by a processor mounted on the server device. The present disclosure also relates to a data management method executed by the server device and the client device.
Background Art
[0002] A dosing management system including a client device and a server device capable of data communication via a communication network is disclosed. Information related to a drug prescription for a patient is transmitted from the client terminal device to the server device. The server device stores the acquired information in a database.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] It is required to enhance the security of the personal information to be considered transmitted from the client device without impairing the convenience of the user of the client device.
Means for Solving the Problems
[0005] One exemplary aspect that can be provided by the present disclosure is a server device capable of communicating with a client device on which a service related to drug prescription is executed, an interface that receives identification information capable of identifying the client device from the client device, A processor that authenticates the identification information by referring to contract information defining the service, and when the authentication is successful, sends destination information indicating the destination of the dataset containing sensitive personal information relating to the patient receiving the drug prescription to the client device. It is equipped with.
[0006] One possible embodiment provided by this disclosure is a computer program executable by a processor installed in a server device capable of communicating with a client device on which a drug prescription service is performed, By being executed, the server device will The client device receives identification information that can identify the client device from the client device. Authentication of the identification information is performed by referring to the contract information that defines the aforementioned service. Once the authentication is successful, destination information indicating the recipient of the dataset containing sensitive personal information relating to the patient receiving the drug prescription is sent to the client device.
[0007] One example of an embodiment that may be provided by this disclosure is a data management method performed by a client device on which a drug prescription service is provided and a server device located at a location separate from the client device, Identification information that can identify the client device is transmitted from the client device to the server device. The server device authenticates the identification information by referring to the contract information that defines the service. Once the authentication is successful, the server device transmits destination information indicating the recipient of the dataset containing sensitive personal information relating to the patient receiving the drug prescription to the client device. The client device transmits the dataset to the destination indicated by the destination information.
[0008] According to the configurations described in each of the above examples, a dataset containing sensitive personal information will not be transmitted to the server device unless authentication of the client device is successful. Therefore, it is possible to avoid situations in which sensitive personal information is transmitted to the server device, for example, when contract renewal has been forgotten. If the client device transmits identification information that identifies itself, the server device will check the contract status, thus reducing the burden on the client device user. Therefore, the security of sensitive personal information transmitted from the client device can be enhanced without compromising the convenience of the client device user. [Brief explanation of the drawing]
[0009] [Figure 1] This illustrates the configuration of a data management system according to one embodiment. [Figure 2] Figure 1 illustrates the functional configuration of the client and server devices. [Figure 3] Figure 2 illustrates the contract information stored in the server device's storage. [Figure 4] Figure 1 illustrates the flow of data management methods performed by the data management system. [Modes for carrying out the invention]
[0010] Examples of embodiments will be described in detail below with reference to the attached drawings. In each drawing referenced in the following description, the elements shown have been made recognizable as necessary. The scale is being changed.
[0011] As used in this disclosure, the term "medical institution" refers to an institution where medical professionals provide information about pharmaceuticals to patients. Examples of "medical institutions" include hospitals, clinics, medical offices, pharmacies, drugstores, and other similar institutions. Examples of "medical professionals" include doctors, nurses, pharmacists, care managers, and registered dietitians.
[0012] Figure 1 illustrates the configuration of a data management system 10 according to an exemplary embodiment. The data management system 10 includes a client device 11 and a server device 12.
[0013] The client device 11 is used to provide services related to drug prescriptions to users. "Users" can include both medical staff and patients. Examples of "services related to drug prescriptions" include creation and management of electronic medical records, support for medication guidance, support for dispensing, follow-up of medication, remote medication guidance, provision of electronic drug diaries, support for the management of medical institutions, inventory management of pharmaceuticals, and the like.
[0014] There can be a plurality of client devices 11. The client device 11 may be a stationary device installed at a specific location, or may be a portable device that can be carried by a user.
[0015] The server device 12 is installed at a location remote from the client device 11. The client device 11 and the server device 12 are configured to perform two-way communication of data via a communication network 20.
[0016] As illustrated in Figure 2, the client device 11 includes a communication interface 111. On the other hand, the server device 12 includes a communication interface 121. Each of the communication interface 111 and the communication interface 121 is a hardware interface configured to enable the above-described two-way data communication.
[0017] The client device 11 includes a user interface 112 and a processor 113. The user interface 112 is a hardware interface that mediates the exchange of information between the user and the processor 113 and receives instructions from the user to cause the client device 11 to execute predetermined operations. The user interface 112 and the processor 113 may be mounted in a common housing, or may be provided in a distributed manner in independent housings.
[0018] A predetermined operation executed by the client device 11 includes transmitting an identification information ID to the server device 12. The identification information ID is information that can identify at least one of the client device 11 and the user who uses the client device 11. Examples of the identification information ID include a client certificate issued to the client device 11 or the user, a terminal identifier issued to the client device 11, and the like.
[0019] The server device 12 includes a storage 122. The storage 122 is a storage device realized by a semiconductor memory, a hard disk device, a magnetic tape device, or the like. In order to allow two-way communication between the client device 11 and the server device 12, the identification information ID of the client device 11 is stored in the storage 122 in advance.
[0020] In addition, contract information CT illustrated in FIG. 3 is stored in the storage 122. The contract information CT indicates a contract concluded between the user of the client device 11 and the service provider regarding the service provided in the client device 11. The contract information CT specifies the type of service provided, the valid period of the service provided, the type of patient-sensitive personal information that can be used within the service provided, and the like. Examples of patient-sensitive personal information include the physical characteristics, medical history, and medication history of the patient.
[0021] In the example shown in FIG. 3, the contract information CT indicates that services A, B, and C can be provided in the client device 11. In service A, the use of sensitive personal information a, sensitive personal information b, and sensitive personal information c is permitted. In service B, the use of sensitive personal information a, sensitive personal information c, and sensitive personal information d is permitted. In service C, the use of sensitive personal information c and sensitive personal information e is permitted.
[0022] As illustrated in Figure 2, a predetermined operation performed by the client device 11 includes sending the source dataset OR used in the provided service to the server device 12. The source dataset OR includes, for example, information relating to medications prescribed to a patient. This information includes sensitive personal information of the patient.
[0023] The original dataset OR received by the communication interface 121 of the server device 12 is stored in the storage 122.
[0024] Note that there may be multiple storage devices 122. The identification information ID, contract information CT, and original dataset OR may be stored in different storage areas of the same storage device, or they may be stored in multiple different storage devices.
[0025] The server device 12 includes a processor 123. The processor 123 is configured to refer to the identification information ID, contract information CT, and original dataset OR stored in the storage 122 as needed.
[0026] Referring to Figure 4, the flow of the data management method performed in the data management system 10 will be explained in detail.
[0027] A user of client device 11 who wishes to send the source dataset OR used in the provided service inputs a predetermined operation into the user interface 112. In response to this operation, the processor 113 reads the identification information ID stored in storage (not shown) and transmits it to the server device 12 via the communication interface 111 (STEP 11).
[0028] When the server device 12 receives the identification information ID via the communication interface 121, the processor 123 performs authentication processing for the client device 11. As used herein, the term "authentication processing" means the process of confirming that (1) the identification information ID of the client device 11 is valid, and (2) the contract relating to the services provided to the client device 11 is valid. Authentication is determined to be successful when both are confirmed to be valid.
[0029] Regarding item (1), the processor 123 compares the identification information ID received via the communication interface 121 with the identification information ID of the client device 11 that is pre-stored in the storage 122. If the two match, the received identification information ID is determined to be valid.
[0030] Regarding item (2), the processor 123 refers to the contract information CT for the client device 11 stored in the storage 122. If the contract for at least one service specified by the contract information CT has not been terminated and its expiration date has not passed, the contract for the services provided to the client device 11 is determined to be valid.
[0031] The processing related to item (1) and the processing related to item (2) may be executed in either order or in parallel. Based on the results of both processes, the processor 123 determines whether authentication of the client device 11 has been successful (STEP 21).
[0032] If it is determined that at least one of the identification information ID and the service contract is invalid (NO in STEP 21), the processor 123 sends notification information NT indicating that authentication failed to the client device 11 via the communication interface 121.
[0033] When notification information NT is received by the communication interface 111 of the client device 11, the processor 113 causes the user interface 112 to provide information notifying that authentication has failed (STEP 12).
[0034] When authentication of the client device 11 is successful (YES in STEP 21), the processor 123 of the server device 12 generates destination information DS indicating the destination of the original dataset OR and sends it to the client device 11 via the communication interface 121 (STEP 22). For example, the destination can be identified by a URL corresponding to the storage area of the storage 122 where the original dataset OR is stored.
[0035] When destination information DS is received by the communication interface 111 of the client device 11, the processor 113 prompts the user interface 112 to provide information notifying that authentication has been successful, along with the destination of the original dataset OR indicated by the destination information DS (STEP 13). Providing the destination may be used in lieu of notifying that authentication has been successful.
[0036] The user of client device 11 performs an operation via the user interface 112 to send the original dataset OR to the destination indicated by the destination information DS. In response to this operation, the processor 113 sends the original dataset OR from the communication interface 111 to the server device 12 (STEP 14).
[0037] The processor 123 of the server device 12 stores the original dataset OR received via the communication interface 121 into the storage 122 (STEP 23).
[0038] With the configuration described above, the original dataset OR containing sensitive personal information will not be sent to the server device 12 unless authentication of the client device 11 is successful. Therefore, it is possible to avoid situations in which sensitive personal information is sent to the server device 12, for example, when contract renewal has been forgotten. If the client device 11 sends an identification information ID to identify itself, the server device 12 will refer to the contract status, thus reducing the burden on the user of the client device 11. Therefore, the security of sensitive personal information sent from the client device 11 can be enhanced without compromising the convenience of the user of the client device 11.
[0039] Continuing, or in response to an instruction from the client device 11 requesting the use of a specific service, the processor 123 determines the scope of sensitive personal information contained in the original dataset OR stored in storage 122 that will be used for the service dataset SV that causes the client device 11 to provide the service (STEP 24 in Figure 4).
[0040] As described above with reference to the contract information CT illustrated in Figure 3, sensitive personal information that can be used for at least one service provided by the client device 11 is defined. The processor 123 refers to the contract information CT for the service specified by the instruction from the client device 11 and identifies the range of sensitive personal information contained in the original dataset OR that can be used in the service dataset SV.
[0041] For example, if the client device 11 instructs the use of service C, the processor 123 refers to the contents related to service C in the contract information CT. In this example, the contract information CT specifies that only sensitive personal information c and sensitive personal information e should be used, so the processor 123 generates the service dataset SV using only sensitive personal information c and sensitive personal information e from the sensitive personal information contained in the original dataset OR. Subsequently, the processor 123 transmits the generated service dataset SV to the client device 11 via the communication interface 121 (STEP 25).
[0042] When the service dataset SV is received by the communication interface 111 of the client device 11, the processor 113 causes the user interface 112 to provide the service corresponding to the service dataset SV (STEP 15).
[0043] With this configuration, when the client device 11 sends the original dataset OR to the specified destination, the server device 12 references the contract information CT and distinguishes between sensitive personal information that can be used and sensitive personal information that cannot be used, depending on the service provided. This prevents the leakage of unnecessary sensitive personal information through the provided service without forcing the user of the client device 11 to specify the scope of sensitive personal information that can be used.
[0044] The above advantages become even more pronounced when the client device 11 can provide multiple services, particularly as illustrated in Figure 3, and when the scope of sensitive personal information that can be used differs for each service. Once the client device 11 sends the original dataset OR to the specified destination, the server device 12 references the contract information CT, and the scope of sensitive personal information included in the service dataset SV changes for each service provided. This prevents the leakage of unnecessary sensitive personal information through the services provided, without requiring the user of the client device 11 to be aware of the potentially different scope of sensitive personal information that can be used for each service.
[0045] Each of the processors 113 of the client device 11 and the processor 123 of the server device 12, which have the various functions described above, can be realized by at least one general-purpose microprocessor that works in cooperation with at least one general-purpose memory. Examples of general-purpose microprocessors include CPUs, MPUs, and GPUs. Examples of general-purpose memory include ROMs and RAMs. In this case, the ROM may store a computer program that performs the above-described processing. ROM is an example of a non-temporary computer-readable medium in which a computer program is stored. The general-purpose microprocessor selects at least a portion of the program stored in the ROM and loads it onto the RAM, and then works in cooperation with the RAM to execute the above-described processing. The computer program may be pre-installed in the general-purpose memory, or it may be downloaded from an external server device via a communication network and then installed in the general-purpose memory. In this case, the external server device is an example of a non-temporary computer-readable medium in which a computer program is stored.
[0046] Each of processors 113 and 123 may be implemented by at least one dedicated integrated circuit capable of executing the above-described computer program. Examples of dedicated integrated circuits include microcontrollers, ASICs, FPGAs, etc. In this case, the above-described computer program is pre-installed in a memory element included in the dedicated integrated circuit. This memory element is an example of a computer-readable medium in which the computer program is stored. Each of processors 113 and 123 can also be implemented by a combination of a general-purpose microprocessor and a dedicated integrated circuit.
[0047] The configurations described herein are merely examples to facilitate understanding of this disclosure. Each configuration example may be modified or combined with other configuration examples as appropriate, as long as it does not deviate from the intent of this disclosure.
[0048] In the above embodiment example, the scope of sensitive personal information included in the service dataset SV is changed depending on the service provided by the client device 11. However, the scope of sensitive personal information included in the service dataset SV may also be changed depending on the format of the source dataset OR transmitted from the client device 11. In other words, the scope of sensitive personal information included in the service dataset SV may be changed depending on the format of the source dataset OR. The term "format differences" includes not only differences in file formats but also differences in versions within the same file format.
[0049] In this case, information indicating the relationship between the file format and the scope of sensitive personal information included in the service dataset SV is pre-stored in the storage 122, as in the contract information CT in the above embodiment example.
[0050] With this configuration, once the client device 11 sends the original dataset OR to the specified destination, the server device 12 references the information, and the scope of sensitive personal information included in the service dataset SV changes depending on the format of the original dataset OR. This prevents the leakage of unnecessary sensitive personal information through the provided service without making the user of the client device 11 aware of the range of usable sensitive personal information that may differ depending on the format of the original dataset OR. [Explanation of symbols]
[0051] 11: Client device, 12: Server device, 121: Communication interface, 123: Processor, CT: Contract information, DS: Destination information, ID: Identification information, OR: Original dataset
Claims
1. A server device capable of communicating with a client device on which services related to drug prescriptions are provided, An interface that receives identification information from the client device that can identify the client device, A processor that authenticates the identification information by referring to contract information defining the service, and when the authentication is successful, transmits destination information indicating the destination of a dataset containing sensitive personal information relating to patients receiving the drug prescription to the client device. It is equipped with Server device.
2. The aforementioned processor, By referring to the aforementioned contract information, the extent to which the data set transmitted from the client device is used for the service is determined. The server device according to claim 1.
3. The aforementioned service includes multiple services, The processor is capable of changing the range for each of the plurality of services. The server device according to claim 2.
4. The aforementioned dataset includes multiple datasets of different formats. The processor is capable of changing the range based on the format. The server device according to claim 2.
5. A computer program executable by a processor installed in a server device capable of communicating with a client device on which a drug prescription service is provided, By being executed, the server device will The client device receives identification information that can identify the client device from the client device. Authentication of the identification information is performed by referring to the contract information that defines the aforementioned service. Once the authentication is successful, destination information indicating the recipient of the dataset containing sensitive personal information relating to the patient receiving the drug prescription is sent to the client device. Computer program.
6. A data management method performed by a client device on which drug prescription services are provided and a server device installed at a location separate from the client device, Identification information that can identify the client device is transmitted from the client device to the server device. The server device authenticates the identification information by referring to the contract information that defines the service. Once the authentication is successful, the server device transmits destination information indicating the destination of the dataset containing sensitive personal information relating to the patient receiving the drug prescription to the client device. The client device transmits the dataset to the destination indicated by the destination information. Data management methods.
Citation Information
Patent Citations
Medication management system, management server, and management server control program
JP2024055808A