Privacy-Preserving Health Record Service via Distributed Ledger

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in managing and deleting their personal health record data from service providers, leading to concerns about privacy and control, while service providers struggle with fair administration of trial periods due to lack of monitoring and transparency.

Innovation Solution

A user device with a mobile app utilizes a distributed ledger to store and control user data, generating a unique token for interactions with service providers, ensuring anonymous data management and enforcing trial period rules, allowing users to switch between services while maintaining data privacy and fairness for providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users store their personal health record data with service providers for convenient access and service delivery, then service quality and accessibility are improved, but users lose control over their data and face privacy risks when unsubscribing

Engineering Contradiction:
Improvedata accessibilityVSAvoidprivacy risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a distributed ledger as an intermediary between users and service providers. The ledger stores encrypted user data hashes and access permissions, allowing service providers to verify data integrity and deliver services without directly accessing or controlling the actual health record data. This mediator architecture enables convenient service delivery while preserving user privacy and data control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the critical verification function from centralized data storage. Instead of service providers storing and managing user health data, the system extracts the essential element (data verification capability) and stores it in a distributed ledger. This allows providers to confirm data existence and integrity without holding the actual data, eliminating the privacy risk while maintaining service functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If service providers collect and retain user data for continuous service improvement, then service quality is improved, but users cannot completely delete their data when unsubscribing

Engineering Contradiction:
Improveservice qualityVSAvoiddata management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent separates data verification from data storage. Service providers store only cryptographic hashes and metadata in the distributed ledger, while actual health data remains under user control. When users unsubscribe, they can completely delete their data from provider systems because providers never held the actual data, only verification capabilities. This maintains service quality through verification while enabling complete data deletion.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses cryptographic copying where service providers work with hash copies of user data rather than the actual data. These hash copies enable service delivery and quality assurance without compromising the original data. Users can delete the source data while the hash copies in the ledger continue to enable verification and service continuity.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If users provide sensitive personal information during sign-up for personal health record services, then service functionality is improved, but users face risks when services become undesirable or need to be unsubscribed

Engineering Contradiction:
Improveservice functionalityVSAvoiddata control trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The distributed ledger acts as a trust intermediary that verifies user identities and data ownership without requiring users to share sensitive personal information with service providers. The ledger stores verified identity hashes and authorization tokens, enabling service providers to authenticate users and deliver personalized services while users retain full control over their identity data and can freely unsubscribe.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If service providers manually monitor trial period durations to ensure fair administration, then operational simplicity is maintained, but fairness and transparency of trial periods deteriorate

Engineering Contradiction:
Improvemonitoring system complexityVSAvoidtrial period fairness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements self-service monitoring through smart contracts on the distributed ledger. Trial period rules, duration limits, and fairness constraints are encoded in the ledger itself. The system automatically enforces these rules without requiring manual monitoring by service providers. This increases system complexity slightly but dramatically improves trial period fairness, transparency, and reliability through automated, tamper-proof enforcement.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11610022B2Privacy preserving personal health record service ecosystem trials
Publication Date: 2023.03.21 KONINKLIJKE PHILIPS NV
  • US11610022B2 patent drawing
  • US11610022B2 patent drawing
  • US11610022B2 patent drawing

AI summary

A user device comprises an app that stores and maintains exclusive control of user data, and causes one or more processors to send a request for services according to a trial period to a distributed ledger associated with service providers and anonymously interact with the service providers according to a set of rules maintained in the distributed ledger by passing along a token uniquely associated with the user during for the respective interaction with each service provider without the user data being shared with the service providers.