Decentralized Genetic Data Storage via Proxy Re-Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The leakage of genetic data poses significant security risks, as it can be de-anonymized and used for unauthorized purposes, and existing centralized solutions are inadequate in protecting sensitive information.

Innovation Solution

A decentralized system using multiple layers of cryptographic protection and identity authentication, where genetic data is encrypted by the data owner and re-encrypted by a proxy server, ensuring only authorized servers can access and decrypt the data, with secure communication through asymmetric cryptography and digital signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If genetic data is stored in a centralized database, then access control and data management are simplified, but security risks increase due to single points of failure and centralized vulnerability

Engineering Contradiction:
Improvedata managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized database into multiple distributed nodes across a blockchain network. Each node stores encrypted genetic data locally, eliminating the single point of failure. The data is divided into blocks that are distributed and replicated across multiple servers, ensuring that no single node contains all genetic information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries including public-private key pairs, hash functions, and smart contracts as mediators between data storage and access. These cryptographic layers act as intermediaries that enable secure access control without requiring direct trust in any single entity, resolving the contradiction between simplified management and enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If genetic data is anonymized to protect privacy, then personal identification is prevented, but de-anonymization techniques can still identify individuals through facial recognition and social media data

Engineering Contradiction:
Improveprivacy protectionVSAvoidde-anonymization risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent employs asymmetric cryptography where the data owner holds the private key and the system holds the public key. This asymmetric relationship ensures that only the data owner can decrypt and access their genetic information, while the system can verify ownership without knowing the private key. This mathematical asymmetry provides strong privacy protection that cannot be breached by de-anonymization techniques.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent performs preliminary cryptographic hashing and encryption of genetic data before storage, transforming the data into an irreversible format. Hash functions create fixed-length digests that cannot be reversed to obtain original data, and encryption with the owner's private key ensures that only the owner can access the information, preventing any future de-anonymization attempts.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access control is restricted to only the data owner, then security is maximized, but authorized medical practitioners cannot access genetic data for medical purposes

Engineering Contradiction:
ImprovesecurityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control through smart contracts that can be updated and modified by the data owner at any time. Access permissions are not static but can be dynamically granted, revoked, or modified based on changing medical needs. The data owner can issue time-limited access tokens or grant access to specific practitioners for specific purposes, providing both security and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of access control by using cryptographic keys and smart contract conditions rather than simple username/password systems. Access is controlled through multiple parameters including data owner authorization, practitioner credentials, purpose of access, and time constraints. These parameter-based controls enable flexible authorization that maintains security while allowing necessary medical access.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If multiple servers are used for data storage and processing, then security and redundancy are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity and redundancyVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal blockchain infrastructure that serves multiple functions: data storage, access control, authentication, and transaction management. The same blockchain network and smart contract system handle all these functions, reducing overall system complexity despite the distributed architecture. Each node in the network performs multiple roles, eliminating the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses cryptographic copying where the same encrypted data and access control mechanisms are replicated across multiple nodes. Rather than creating complex unique systems at each node, the same validated blockchain protocol and smart contracts are copied and executed at every node, simplifying the architecture through standardization and replication of proven security mechanisms.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11451522B2System and method for enabling the secure storage, transmission and access of genetic data
Publication Date: 2022.09.20 CITY UNIVERSITY OF HONG KONG
  • US11451522B2 patent drawing
  • US11451522B2 patent drawing
  • US11451522B2 patent drawing

AI summary

A system and method for a computer system for the secure storage, transmittance and access of genetic data includes a coordinator server including a coordinator program arranged to update secure access information, the coordinator server being in communication with a genetic data sequencing server, a genetic data analysing server, and a genetic data storage server, whereby the coordinator server communicates the secure access information in a manner to allow the genetic data storage server to act as a proxy server between the genetic data sequencing server and the genetic data analysing server.