Electronic File Encryption for Privacy and Traceability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively protect patient private information in electronic prescriptions, making it difficult to trace past medical records due to loss of key information.

Innovation Solution

A method and apparatus for acquiring an electronic file that involves sending a request message to a platform server, determining verification information, and encrypting private information in the electronic file using a first encryption key of the information providing server, ensuring that only the information providing server can decrypt the information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If patient private information is hidden or deleted in electronic prescriptions, then privacy protection is improved, but the ability to trace past medical records is lost due to loss of key information

Engineering Contradiction:
Improveprivacy protectionVSAvoidtraceability of medical records
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent segments patient information into two categories: identity information (name, ID number) that is deleted for privacy protection, and traceability information (encrypted using multiple encryption keys) that remains accessible to authorized parties. This segmentation allows simultaneous achievement of privacy protection and medical record traceability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested encryption where multiple encryption keys are layered to protect different levels of information. The first encryption key protects identity information, while a second encryption key protects traceability information. This nested structure enables selective access where regular users see only deleted identity info while authorized personnel can decrypt and access complete medical history.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If multiple encryption keys are used to protect private information, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity of private informationVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a platform server as an intermediary that manages the complexity of multiple encryption keys. The platform server automatically handles key generation, distribution, and decryption coordination between the information providing server and terminal devices. This intermediary absorbs the cryptographic complexity while presenting a simplified interface to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of encryption from a single key to multiple keys with different security levels and access permissions. The first encryption key (higher security) protects identity information, while the second encryption key (lower security) protects traceability information. This parameter change enables differentiated access control without requiring complex custom encryption logic.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If identity information is completely deleted for privacy protection, then privacy security is improved, but the ability to verify patient identity for supervision and case examination is lost

Engineering Contradiction:
Improveprivacy securityVSAvoididentity verification for supervision
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent performs preliminary encryption of traceability information using multiple encryption keys before identity information is deleted. This preliminary action ensures that even though identity info is removed, the encrypted traceability data remains intact and can be decrypted by supervision departments using the second encryption key, enabling post-deletion identity verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent adds a new dimension of access control by implementing hierarchical encryption keys with different permission levels. The first encryption key provides basic privacy protection, while the second encryption key enables supervision access. This dimensional approach to security allows identity verification for supervision purposes without compromising the privacy security achieved through information deletion.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12297768B2Method and apparatus for securing communications using multiple encryption keys
Publication Date: 2025.05.13 ALIBABA GROUP HOLDING LTD
  • US12297768B2 patent drawing
  • US12297768B2 patent drawing
  • US12297768B2 patent drawing

AI summary

The disclosure provides a method and an apparatus for acquiring an electronic file. The method for acquiring an electronic file comprises: sending a first request message for acquiring an electronic file to a platform server, wherein the first request message carries a first identifier of an information providing server providing the electronic file; receiving first prompt information returned from the platform server according to the first request message; determining first verification information for identity authentication according to the first prompt information, and sending the first verification information to the platform server; and receiving the electronic file forwarded by the platform server, wherein the electronic file is from the information providing server, and private information in the electronic file is encrypted through a first encryption key of the information providing server. The technical solutions in the disclosed embodiments can effectively protect private information of a user from being leaked by a platform server, thereby ensuring privacy security of the user.