First-Party Framework for Secure Health Data Interchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in managing and securely sharing personal health information across different devices and applications, particularly in ensuring user privacy and authorization control.

Innovation Solution

A system and method for managing user information that enables secure storage and interchange of health data types, allowing third-party applications to request and access specific data types while maintaining user authorization control through a first-party application framework, which includes background processes for data interpretation and aggregation, and supports the addition of new data types via asset downloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party applications can access user health information, then application functionality is enhanced, but user privacy and data security are compromised

Engineering Contradiction:
Improveapplication functionalityVSAvoiduser privacy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a first-party application framework as an intermediary between third-party applications and user health information. This framework acts as a mediator that receives requests from third-party applications, validates user authorization, and controls data access accordingly. The framework ensures that only authorized data is shared while maintaining user privacy and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If new data types are added to support emerging health devices, then system adaptability is improved, but system complexity increases

Engineering Contradiction:
Improvesupport for new data typesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the data type management into distinct components: a first-party application framework that maintains a list of supported data types, and third-party applications that request specific data types. This segmentation allows new data types to be added to the framework without affecting the entire system, as each component can independently handle and validate data types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically manages data types by allowing the first-party framework to update its list of supported data types in response to new health devices. The framework can add, remove, or modify data type definitions without requiring system-wide changes, enabling flexible adaptation to emerging technologies while maintaining manageable complexity.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If authorization control is implemented for data access, then user privacy is protected, but access efficiency is reduced

Engineering Contradiction:
Improvedata securityVSAvoiddata access efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements preliminary authorization checks before data access is granted. The first-party framework validates user authorization requests in advance, establishing clear access rules before any data transfer occurs. This preliminary action ensures security while streamlining the actual data access process, as authorized requests can proceed efficiently without repeated verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11404146B2Managing user information—data type extension
Publication Date: 2022.08.02 APPLE INC
  • US11404146B2 patent drawing
  • US11404146B2 patent drawing
  • US11404146B2 patent drawing

AI summary

Systems, methods, and computer-readable medium are provided for managing user information. For example, instructions for implementing a background process configured to manage a first set of data types may be received from a service provider. A data download that includes information about the new data type may also be received from the service provider. A request to access data corresponding to the new data type may be received from an application. Additionally, in some examples, the data corresponding to the new data type may be provided to the application based at least in part on interpreting the data download.