Encrypted EHR Storage via Metadata Tree and Key Hierarchy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The sharing of electronic health records (EHRs) among healthcare participants is complex and burdensome due to technical and legal issues, particularly in ensuring consistency, privacy, and security, especially for those lacking resources and expertise.

Innovation Solution

An electronic health record storage processing environment that uses an encrypted data store with a metadata tree for secure storage and access, where each EHR is uniquely encrypted with a patient key, provider key, and location, allowing seamless sharing among healthcare participants while maintaining privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If EHRs are shared among healthcare participants, then access to health information is improved, but privacy and security risks increase

Engineering Contradiction:
Improveaccess to health informationVSAvoidprivacy and security risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments EHR data into multiple encrypted partitions, each accessible only to authorized healthcare participants through unique decryption keys. This allows selective access to specific portions of health records while maintaining overall data security and privacy protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption system that mediates between data storage and access. Encryption keys act as intermediaries, controlling and regulating access to EHR data without requiring direct exposure of the underlying sensitive information, thus securing privacy while enabling authorized sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If EHRs are encrypted for security, then privacy is protected, but access complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidaccess complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements preliminary encryption of EHR data before storage, with decryption keys pre-configured for authorized participants. This preliminary action ensures privacy protection is built-in from the start, while the key management system is prepared in advance to simplify the access process for authorized users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates encrypted copies of EHR data that can be securely shared with multiple healthcare participants without exposing the original unencrypted data. These encrypted copies maintain data integrity and security while enabling widespread access to authorized personnel.

Inventive Principle:
Principle #26Copying

3Reliability

If multiple encryption keys are used for each EHR, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key management system where a single patient-controlled master key can derive multiple access keys for different healthcare participants. This multi-functional approach enhances security through multiple encryption layers while simplifying the system by allowing one master key to manage all access permissions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds a hierarchical dimension to key management, with a top-level patient master key that can generate and control multiple participant-specific keys. This dimensional approach to key organization enhances security through layered encryption while simplifying management through the hierarchical structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9940469B2Encrypted data store for records
Publication Date: 2018.04.10 MICRO FOCUS LLC
  • US9940469B2 patent drawing
  • US9940469B2 patent drawing
  • US9940469B2 patent drawing

AI summary

A method performed by a processing system includes determining a location in a metadata tree of a patient for an electronic health record, generating a record key for the electronic health record based on the location and a provider key corresponding to a provider, the provider key generated from a patient key corresponding to the patient, encrypting the electronic health record using the record key to generate a encrypted record, and providing the encrypted record to an encrypted data store.