Decentralized Medical Record Access via Reference Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for exchanging electronic medical records face security and privacy risks due to centralized architectures, which can lead to unauthorized access and breaches, especially in large-scale systems where the reliability of a central switching point is crucial for access control and data integrity.

Innovation Solution

A decentralized access system that generates references for medical records, including authorization information and pointers, allowing clients to retrieve records securely without relying on a central authority, using authentication and authorization mechanisms to ensure only authorized parties access the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized architecture is used for exchanging electronic medical records, then access control and data management become simpler and more efficient, but security and privacy risks increase due to the large attack surface and single point of failure

Engineering Contradiction:
Improveaccess control managementVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized access control system into distributed authorization components. Each healthcare organization maintains its own authorization decisions locally, eliminating the single point of failure in centralized systems while maintaining coordinated access control across the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary reference token that mediates between the client requesting access and the source system holding the record. This reference contains authorization information that enables decentralized verification without requiring a centralized authority, thus improving reliability while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a centralized switching point is used to manage access to medical records, then coordination and control are improved, but the system becomes vulnerable to breaches and failures at the central point

Engineering Contradiction:
Improveaccess coordinationVSAvoidsecurity breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the centralized switching point functionality into distributed components across multiple healthcare organizations. Each organization independently verifies authorization using the reference token, eliminating the security vulnerability of a centralized switching point while maintaining coordinated access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the authorization verification logic from the centralized switching point and places it locally at each source system. This extraction eliminates the single point of failure while preserving the coordination benefits through the shared reference token mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of information

If pull-based access is implemented to ensure up-to-date information retrieval, then data currency is improved, but unauthorized access and privacy risks increase without proper authorization mechanisms

Engineering Contradiction:
Improvedata currencyVSAvoidunauthorized access risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authorization by embedding authorization information in the reference token before the access request is made. This preliminary action ensures that only authorized clients can retrieve up-to-date information through pull-based access, eliminating the security risk while maintaining data currency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the reference token as a feedback mechanism that carries authorization information from the source system to the client. This feedback enables the client to verify authorization before pulling data, ensuring both data currency and security.

Inventive Principle:
Principle #23Feedback

4Reliability

If decentralized authorization is implemented to improve security, then system reliability is improved, but the complexity of managing distributed authorization increases

Engineering Contradiction:
Improvesystem securityVSAvoidauthorization management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authorization information, identification, and access control logic into a single reference token. This combination simplifies decentralized authorization management by providing a unified mechanism that handles multiple functions in one component, reducing complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The reference token serves multiple functions simultaneously: it identifies the client, carries authorization information, enables pull-based access, and provides verification credentials. This multi-functionality reduces the number of separate components needed, simplifying the decentralized authorization system while improving reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10599830B2System and method for controlled decentralized authorization and access for electronic records
Publication Date: 2020.03.24 NORTHEND SYST BV
  • US10599830B2 patent drawing
  • US10599830B2 patent drawing
  • US10599830B2 patent drawing

AI summary

A system and computer-implemented method for providing decentralized access to records. The method is performed on at least one computer system including at least one processor. The method includes the steps of: generating at least one reference for at least one record stored on a source system, the at least one reference comprising authorization information and a pointer to the at least one record; receiving, at the source system from a client system, a request to retrieve the at least one record from the source system, the request initiated using the at least one reference and including at least a portion of the at least one reference; authenticating or authorizing at least one of the client system and a user of the client system; and transmitting the at least one record from the source system to the client system.