Asymmetric Key Sequence Decryption for Health Card Records

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The electronic health card system faces issues when a patient changes health insurance companies, as the new asymmetric key pair renders previous encrypted medical records inaccessible without manual activation of both old and new health cards.

Innovation Solution

A computer program product that allows decryption of data objects using any asymmetric key pair within a sequence, enabling secure access to encrypted medical records by generating a new ciphertext with both old and new health cards, without requiring the original encryption key pair, and includes a method for generating asymmetric cryptographic key pairs using user IDs and random values for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a new asymmetric key pair is generated when changing health insurance companies, then security is improved, but access to previously encrypted medical records is lost

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to encrypted medical records
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by encrypting the first authorization key with the second authorization key and storing this ciphertext in advance. When a key pair changes, the new key can automatically decrypt the ciphertext and retrieve the first authorization key, enabling access to previously encrypted medical records without manual intervention or loss of access.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the original asymmetric key pair is required for decryption, then security is maintained, but system complexity increases when key pairs change

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary mechanism by using the second authorization key to encrypt the first authorization key and store it as ciphertext. This intermediary encrypted key acts as a bridge, allowing the new key pair to access the first authorization key without requiring the original key pair, thereby reducing system complexity during key transitions while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual activation of both old and new health cards is required, then security control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically generating the ciphertext containing the encrypted first authorization key and making it accessible through the new key pair. When a patient changes health insurance companies, the system autonomously enables access to previous medical records using the new key pair without requiring manual activation or intervention, thereby improving ease of operation while maintaining security control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2340502B8Data processing system for providing authorization keys
Publication Date: 2016.06.01 COMPUGRP MEDICAL SE

AI summary

The invention relates to a computer-implemented method for providing authorization keys (154; 156; 162; 164), wherein the method comprises the following steps: - Receiving a further asymmetrical, cryptographic key pair (162; 164), wherein the further asymmetrical key pair is part of a key pair sequence, wherein the further asymmetrical key pair comprises a further first (162) and a further second (164) authorization key, - retrieving a ciphertext (150), wherein the ciphertext is associated with the key pair (154; 156) which immediately precedes the further key pair (162; 164) in the sequence of key pairs, wherein the ciphertext (150) comprises the initial first key encrypted with the second authorization key (156) of the key pair which immediately precedes the further key pair in the sequence of key pairs, - decrypting the initial first authorization key using the first authorization key (154) of the key pair which immediately precedes the further key pair in the sequence of key pairs, - generating a further ciphertext (150) through encryption of the decrypted initial first authorization key using the second authorization key (164) of the further key pair, - saving the further ciphertext (150).