Health Data Storage Segmentation for Security and Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current health data management systems fail to securely share health data, leading to private information exposure and improper use, as they do not adequately differentiate between general and sensitive health data, resulting in insecure storage and sharing practices.
Innovation Solution
A method and apparatus that classify health data by security types using a security type table, where general data is stored in an open memory and sensitive data in a secure memory, ensuring appropriate access and sharing only with authorized groups, such as medical teams.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If health data is stored in open memory for easy access, then ease of operation is improved, but security and privacy protection deteriorate
Solution Approach 1:
The patent segments health data storage into two distinct memory spaces: open memory for general health data and secure memory for sensitive health data. This segmentation allows different access levels for different data types, resolving the contradiction between ease of access and security protection.
Solution Approach 2:
The patent applies local quality by providing different access characteristics to different parts of the storage system. Open memory allows broad access for general health data, while secure memory provides restricted access for sensitive data. This localized differentiation of access quality resolves the contradiction between overall ease of operation and specific security requirements.
2Ease of operation
If health data is shared with anyone for accessibility, then ease of operation is improved, but harmful factors increase due to private information exposure
Solution Approach 1:
The patent segments health data into general and sensitive categories, enabling selective sharing. General health data can be shared broadly while sensitive data remains restricted, thus maintaining accessibility where needed while preventing harmful information exposure.
Solution Approach 2:
The patent introduces a security type table as an intermediary mechanism that mediates between data owners and data access requests. This intermediary structure enables controlled sharing by determining whether data should be accessible to anyone or restricted to specific groups, thereby preventing private information exposure while maintaining necessary accessibility.
3Device complexity
If all health data is stored in a single location for simplicity, then device complexity is reduced, but security management becomes insufficient
Solution Approach 1:
The patent divides the storage system into multiple secure storage locations with different security levels. This segmentation, while increasing structural complexity, enables differentiated security management for different data types, resolving the contradiction between simplicity and security management capability.
Solution Approach 2:
The patent changes the parameter of storage location based on data sensitivity. By varying the storage parameter (open memory vs. secure memory) according to the security type of health data, the system achieves adequate security management while maintaining a relatively simple overall structure through systematic parameter assignment.
Data Source
AI summary
An apparatus and method for managing health data through a user terminal are provided. The method includes inputting a user terminal number for identifying the user terminal, and information of a medical instrument for measuring the health data to a management server interworked with the user terminal, receiving, by a receiver, a security type table mapped onto the user terminal number and comprising a security type code for instructing the health data which the medical instrument has measured to be stored in a first memory without security or in a second memory with security, from the management server, and storing the health data in the first memory or the second memory, which the security type code instructs, through determining the security type code of the security type table when the health data is received from the medical instrument.


