Electronic File Encryption for Privacy and Traceability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively protect patient private information in electronic prescriptions, making it difficult to trace past medical records due to loss of key information.
Innovation Solution
A method and apparatus for acquiring an electronic file that involves sending a request message to a platform server, determining verification information, and encrypting private information in the electronic file using a first encryption key of the information providing server, ensuring that only the information providing server can decrypt the information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If patient private information is hidden or deleted in electronic prescriptions, then privacy protection is improved, but the ability to trace past medical records is lost due to loss of key information
Solution Approach 1:
The patent segments patient information into two categories: identity information (name, ID number) that is deleted for privacy protection, and traceability information (encrypted using multiple encryption keys) that remains accessible to authorized parties. This segmentation allows simultaneous achievement of privacy protection and medical record traceability.
Solution Approach 2:
The patent implements nested encryption where multiple encryption keys are layered to protect different levels of information. The first encryption key protects identity information, while a second encryption key protects traceability information. This nested structure enables selective access where regular users see only deleted identity info while authorized personnel can decrypt and access complete medical history.
2Reliability
If multiple encryption keys are used to protect private information, then security is improved, but system complexity increases
Solution Approach 1:
The patent introduces a platform server as an intermediary that manages the complexity of multiple encryption keys. The platform server automatically handles key generation, distribution, and decryption coordination between the information providing server and terminal devices. This intermediary absorbs the cryptographic complexity while presenting a simplified interface to users.
Solution Approach 2:
The patent changes the parameter of encryption from a single key to multiple keys with different security levels and access permissions. The first encryption key (higher security) protects identity information, while the second encryption key (lower security) protects traceability information. This parameter change enables differentiated access control without requiring complex custom encryption logic.
3Object-affected harmful factors
If identity information is completely deleted for privacy protection, then privacy security is improved, but the ability to verify patient identity for supervision and case examination is lost
Solution Approach 1:
The patent performs preliminary encryption of traceability information using multiple encryption keys before identity information is deleted. This preliminary action ensures that even though identity info is removed, the encrypted traceability data remains intact and can be decrypted by supervision departments using the second encryption key, enabling post-deletion identity verification.
Solution Approach 2:
The patent adds a new dimension of access control by implementing hierarchical encryption keys with different permission levels. The first encryption key provides basic privacy protection, while the second encryption key enables supervision access. This dimensional approach to security allows identity verification for supervision purposes without compromising the privacy security achieved through information deletion.
Data Source
AI summary
The disclosure provides a method and an apparatus for acquiring an electronic file. The method for acquiring an electronic file comprises: sending a first request message for acquiring an electronic file to a platform server, wherein the first request message carries a first identifier of an information providing server providing the electronic file; receiving first prompt information returned from the platform server according to the first request message; determining first verification information for identity authentication according to the first prompt information, and sending the first verification information to the platform server; and receiving the electronic file forwarded by the platform server, wherein the electronic file is from the information providing server, and private information in the electronic file is encrypted through a first encryption key of the information providing server. The technical solutions in the disclosed embodiments can effectively protect private information of a user from being leaked by a platform server, thereby ensuring privacy security of the user.


