Credential Enabled Reference for Secure External Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Proprietary record managing systems, such as EMR/EHR systems, often fail to receive file formats from third-party service providers due to infrastructure limitations or intentional restrictions, leading to delays and security concerns, particularly in industries like healthcare where seamless data exchange is crucial.

Innovation Solution

A method and system for creating a credential-enabled reference that allows secure access to downloadable content, such as diagnostic test results, by generating a protected URL link that can be accessed only by authorized and authenticated users, ensuring privacy and security through authentication and authorization processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If proprietary record managing systems receive files from third-party service providers, then data exchange efficiency is improved, but system security and privacy protection deteriorate

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoidsystem security and privacy protection
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a credential-enabled reference (CER) as an intermediary mechanism that mediates between third-party service providers and proprietary record managing systems. The CER acts as a secure gateway that allows data exchange while maintaining system security through authentication and authorization protocols, thus resolving the contradiction between improving data exchange efficiency and maintaining security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the file transfer process into multiple controlled stages: credential verification, authentication, authorization, and controlled access. Instead of allowing direct file access, the system breaks down the access process into discrete security checkpoints, enabling secure data exchange while maintaining granular control over what data can be accessed and by whom.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If proprietary record managing systems accept all file formats from third parties, then adaptability is improved, but system complexity and infrastructure burden worsen

Engineering Contradiction:
Improvefile format compatibilityVSAvoidsystem infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the file format conversion and processing complexity from the proprietary record managing system and places it in the third-party service provider's domain. The system generates downloadable content in the required format at the source, eliminating the need for the record managing system to handle multiple file formats directly, thus maintaining adaptability while reducing infrastructure complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of requiring the record managing system to natively support all file formats, the patent creates downloadable content copies in the appropriate formats at the third-party service provider end. These copied files are then delivered through the secure reference mechanism, allowing format versatility without adding complexity to the core system.

Inventive Principle:
Principle #26Copying

3Loss of information

If large files are transferred to record managing systems, then data completeness is improved, but storage and processing burden worsens

Engineering Contradiction:
Improvedata completenessVSAvoidstorage and processing burden
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent transitions from a traditional file transfer model (where entire files are moved) to a reference-based access model. Instead of transferring large files directly to the record managing system, the system creates lightweight reference pointers that point to the actual data location. This dimensional change from file-transfer space to reference-space allows complete data access without the storage burden of duplicating large files.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The credential-enabled reference acts as an intermediary that connects the record managing system to external data sources without requiring direct file transfer. The reference mechanism enables complete data access while the actual data remains stored at the third-party provider, eliminating the storage burden on the record managing system while maintaining data completeness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240202271A1Credential enabled reference for external resource access
Publication Date: 2024.06.20 LABORATORY CORPORATION OF AMERICA HOLDINGS INC
  • US20240202271A1 patent drawing
  • US20240202271A1 patent drawing
  • US20240202271A1 patent drawing

AI summary

A computing environment can provide secure downloadable content regarding diagnostic test results to authorized and authenticated users. For example, a method disclosed herein can include receiving a diagnostic testing order for performing one or more tests. The method can also include generating downloadable content displaying test results. The method can further include generating a reference to a web resource including the downloadable content. Additionally, the method can include associating the reference with authorized users. The method can include delivering the reference for access by authorized users. The method can also include receiving a request for access to the web resource. Additionally, the method can include confirming the request is from an authenticated user. The method can further include confirming the request is from one of the authorized users. The method can include providing access to the web resource including the downloadable content to the authenticated and authorized user.