Healthcare Data Authenticator for Secure Application Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Healthcare data providers face challenges in securely sharing sensitive data with external processing applications due to varying security levels and terms of service, making it difficult to assess and manage risks across different platforms.
Innovation Solution
A system that uses an authenticator to identify and confirm terms of engagement, securely share encryption keys, and manage data sharing on an application-by-application basis, allowing healthcare providers to select specific applications, authorize, and revoke access, ensuring secure data processing and transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If healthcare data providers share data with multiple independent data processors offering different security levels and terms of service, then data processing functionality and versatility are improved, but security risk and difficulty of assessing confidentiality increase
Solution Approach 1:
The patent introduces an authenticator as an intermediary component that mediates between healthcare data providers and multiple independent data processors. This authenticator verifies encryption keys and confirms terms of engagement, allowing providers to access diverse processing functionality while maintaining centralized security control. The intermediary resolves the contradiction by enabling versatile data sharing across multiple processors without proportionally increasing security risk assessment burden.
2Reliability
If healthcare data is encrypted using provider-specific keys shared with specific applications, then data confidentiality is improved, but key management complexity and device complexity increase
Solution Approach 1:
The system implements self-service key management where each healthcare data provider generates and retains control of their own encryption keys. The provider's trusted component automatically manages key distribution to authorized applications without requiring complex centralized key management infrastructure. This approach maintains high data confidentiality while reducing key management complexity through automated, provider-controlled processes.
Solution Approach 2:
The patent segments encryption keys by both provider and specific application, creating unique key pairs for each provider-application combination. This segmentation allows fine-grained control over data confidentiality for each processing relationship while enabling automated key management through the authenticator. The segmented approach prevents the need for managing a single complex master key system across all providers and applications.
3Reliability
If the system verifies signed keys and terms of engagement for each application, then security control and reliability are improved, but processing time and ease of operation worsen
Solution Approach 1:
The authenticator performs verification of encryption keys and terms of engagement in advance, before actual healthcare data processing begins. By conducting security verification preliminarily, the system establishes trusted relationships upfront, allowing subsequent data processing to proceed without repeated verification delays. This preliminary action maintains high security control while minimizing time loss during operational phases.
4Reliability
If healthcare providers can revoke access and terminate data sharing, then security control and reliability are improved, but system complexity and ease of operation worsen
Solution Approach 1:
The system enables healthcare data providers to autonomously revoke access and terminate data sharing through their trusted components without requiring complex administrative procedures. Providers can independently manage their key relationships and terminate processing by specific applications whenever needed. This self-service capability maintains strong security control while minimizing system complexity by empowering providers with direct control over their data sharing arrangements.
Data Source
AI summary
A computer implemented method for a data sharing system to share healthcare data from a healthcare data provider with a healthcare data processing application. The method includes identifying one or more healthcare data processor applications, generating and displaying selectable options of the one or more data processor applications at a healthcare data provider, obtaining a selection of the one or more data processor applications from the healthcare data provider, obtaining a data provider/application-specific encryption keyset corresponding to each selected healthcare data processor application, the keyset comprising a private key and a public key, retaining the private key of the data provider/application-specific keyset with a trusted component of the healthcare data provider, and sharing the public key of the data provider/application-specific keyset with the corresponding selected healthcare data processor application.


