Certified Intermediary Server for Secure Privacy Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for exchanging privacy-sensitive data, such as medical records, lack secure and controlled mechanisms, especially on public networks, and fail to protect authorizations which can reveal sensitive information about a patient's situation or mental/physical state.
Innovation Solution
A system utilizing a certified intermediary server to manage the exchange of privacy-sensitive data between certified party servers, ensuring that only authorized data is transmitted by verifying digital signatures and adhering to patient-provided authorizations, while keeping the authorizations confidential and secure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If privacy sensitive data is exchanged between institutions on a public network, then efficient data exchange is enabled, but security and control over authorized access is compromised
Solution Approach 1:
The patent introduces a trusted intermediary server that mediates between data requesting institutions and data holding institutions. This intermediary verifies authorizations, manages digital signatures, and controls data transmission, enabling secure exchange on public networks without requiring direct trusted connections between all parties.
Solution Approach 2:
The system segments authorization management from data exchange operations. Authorizations are issued and stored separately by the intermediary server, while data institutions can efficiently exchange data by simply verifying signatures and checking authorization status with the intermediary, separating security verification from data transmission.
2Ease of operation
If authorizations are made accessible to control data exchange, then precise control over data sharing is achieved, but the authorizations themselves become vulnerable to unauthorized access and intrusion
Solution Approach 1:
The intermediary server creates and manages digital copies of authorizations in the form of digital signatures and authorization records. The original authorization intent is captured and replicated in a secure, verifiable format that can be distributed and verified without exposing the underlying authorization data to unauthorized access.
Solution Approach 2:
The intermediary server acts as a secure vault for storing and managing authorization data. Institutions do not need direct access to each other's authorization systems; instead, they request verification from the intermediary, which securely manages authorization data and returns verification results without exposing the actual authorization contents.
3Device complexity
If direct exchange between institutions is implemented, then system complexity is reduced, but the ability to enforce granular authorizations and maintain security is weakened
Solution Approach 1:
The intermediary server provides multiple functions in a single system: authorization issuance, authorization storage, signature verification, and data exchange coordination. This universal approach allows institutions to use the same intermediary for all authorization-related operations, managing complexity centrally while maintaining granular control capabilities.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method is provided for controlling exchange of privacy sensitive data between a first certified party server (A) associated with a first party and at least a second certified party server (B) associated with a second party using a certified intermediate server (Y) subject to authorizations (XAB) imposed by an authorizing party (X), using a public network. Therein the first certified party server (A) transmits (S2) to the certified intermediate server (Y) a primary request (ARQ(IxA,ΓxA)) that includes a digitally signed primary request indication (ΙΧΑ,ΓΧΑ) comprising a primary request indication (IXA) specifying a set of privacy sensitive data units (XA) for which a copy (CXA) is requested and a digital signature (ΓΧΑ) of said first party, associated with said primary request indication (IXA). The certified intermediate server (Y) determines (S3) which authorizations are provided by the authorizing party (X) for transmission of information concerning privacy sensitive data from the second certified second party server (B) to the first certified party server (A). The certified intermediate server (Y) executes (S4) a query procedure (QP) in which at least includes transmitting the digitally signed primary request (ΙΧΑ,ΓΧΑ) by the certified intermediate server (Y) to the second certified party server (B). The second certified party server (B) inspects (S5) the digital signature (ΓΧΑ) to verify authenticity of said the primary request. Subject to confirmation of its authenticity it makes available a provider copy (CXAMB) including at least a censored copy, being a copy of a censored subset of privacy sensitive data units, the censored subset comprising the privacy sensitive data units as specified by the primary request indication (IXA) subject at least to said authorizations (XAB) and subject to availability thereof with the at least a second certified party server. It also provides a second party digital signature, i.e. a digital signature (ΓΒ) of the second certified party, associated with the censored subset. Upon completion of the query procedure, the censored copy and the second party digital signature are made available to the first certified party server as a digitally signed authorized copy.