Centralized Support User Management for Healthcare Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed healthcare information management systems, traditional approaches to managing central support user access are insecure and inefficient, as generic administrator logins are shared among multiple users, leading to difficulties in tracking specific user actions and maintaining security, especially when user roles change.

Innovation Solution

A centralized support user management system where permission data for support users is established and managed at a central server, allowing unique credentials and granular access control, enabling efficient distribution of permission changes across all local nodes and enhancing security by tracking specific user actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If generic administrator login is provided to all central support users for access to local node, then ease of operation is improved, but security and user tracking capability deteriorates

Engineering Contradiction:
Improveaccess to local nodeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the generic administrator login into individual user credentials. Each central support user is assigned a unique username and password combination, replacing the shared generic login. This segmentation enables individual user tracking while maintaining access capability, resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a centralized user management system that provides feedback mechanisms for user authentication and authorization. The central server maintains user credential databases and provides real-time verification, enabling secure tracking of individual user actions while maintaining ease of access through automated authentication processes.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If generic administrator login is shared among multiple users, then ease of operation is improved, but ability to track specific user actions deteriorates

Engineering Contradiction:
Improveaccess to local nodeVSAvoiduser action tracking
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the shared administrator account into individual user accounts with unique identifiers. Each central support user receives distinct credentials (username/password), enabling the system to track and attribute specific actions to individual users while maintaining the simplicity of centralized authentication through the user management system.

Inventive Principle:
Principle #1Segmentation

3Reliability

If role-based security model is implemented with individual user credentials, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiduser management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the user management functionality into a centralized system that coordinates between the central server and local nodes. Rather than implementing complex security systems at each local node, the authentication and authorization logic is consolidated at the central server, reducing local device complexity while maintaining strong security through centralized credential verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a centralized user management system as an intermediary between users and local nodes. This intermediary handles authentication, credential verification, and authorization decisions, simplifying the security implementation at local nodes while maintaining robust security through centralized control and coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If permission data is managed centrally at server, then adaptability and efficiency of permission changes is improved, but network communication requirements increase

Engineering Contradiction:
Improvepermission data managementVSAvoidnetwork communication
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements periodic synchronization of permission data from the central server to local nodes. Rather than continuous communication, the system updates permission data at scheduled intervals or when changes occur, reducing network traffic while maintaining adaptability. Local nodes receive updated permission sets periodically and cache them for efficient local enforcement.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20230239300A1Central user management in a distributed healthcare information management system
Publication Date: 2023.07.27 BAXA CORPORATION
  • US20230239300A1 patent drawing
  • US20230239300A1 patent drawing
  • US20230239300A1 patent drawing

AI summary

Centralized support user management in a distributed healthcare information management system is disclosed. Support user management may include generation of permission data that may be distributed from a central server to one or more remote access terminals, which may execute a healthcare information management application such as, for example, a pharmacy workflow management application. The permission data is used to authenticate remote verification users, thereby enabling remote verification of the preparation of medication doses at individual dose preparation work stations.