Healthcare Data Authenticator for Secure Application Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Healthcare data providers face challenges in securely sharing sensitive data with external processing applications due to varying security levels and terms of service, making it difficult to assess and manage risks across different platforms.

Innovation Solution

A system that uses an authenticator to identify and confirm terms of engagement, securely share encryption keys, and manage data sharing on an application-by-application basis, allowing healthcare providers to select specific applications, authorize, and revoke access, ensuring secure data processing and transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If healthcare data providers share data with multiple independent data processors offering different security levels and terms of service, then data processing functionality and versatility are improved, but security risk and difficulty of assessing confidentiality increase

Engineering Contradiction:
Improvedata processing functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authenticator as an intermediary component that mediates between healthcare data providers and multiple independent data processors. This authenticator verifies encryption keys and confirms terms of engagement, allowing providers to access diverse processing functionality while maintaining centralized security control. The intermediary resolves the contradiction by enabling versatile data sharing across multiple processors without proportionally increasing security risk assessment burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If healthcare data is encrypted using provider-specific keys shared with specific applications, then data confidentiality is improved, but key management complexity and device complexity increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service key management where each healthcare data provider generates and retains control of their own encryption keys. The provider's trusted component automatically manages key distribution to authorized applications without requiring complex centralized key management infrastructure. This approach maintains high data confidentiality while reducing key management complexity through automated, provider-controlled processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments encryption keys by both provider and specific application, creating unique key pairs for each provider-application combination. This segmentation allows fine-grained control over data confidentiality for each processing relationship while enabling automated key management through the authenticator. The segmented approach prevents the need for managing a single complex master key system across all providers and applications.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the system verifies signed keys and terms of engagement for each application, then security control and reliability are improved, but processing time and ease of operation worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authenticator performs verification of encryption keys and terms of engagement in advance, before actual healthcare data processing begins. By conducting security verification preliminarily, the system establishes trusted relationships upfront, allowing subsequent data processing to proceed without repeated verification delays. This preliminary action maintains high security control while minimizing time loss during operational phases.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If healthcare providers can revoke access and terminate data sharing, then security control and reliability are improved, but system complexity and ease of operation worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables healthcare data providers to autonomously revoke access and terminate data sharing through their trusted components without requiring complex administrative procedures. Providers can independently manage their key relationships and terminate processing by specific applications whenever needed. This self-service capability maintains strong security control while minimizing system complexity by empowering providers with direct control over their data sharing arrangements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240127942A1Systems and methods for sharing healthcare data with healthcare data processors
Publication Date: 2024.04.18 ROCHE DIAGNOSTICS OPERATIONS INC
  • US20240127942A1 patent drawing
  • US20240127942A1 patent drawing
  • US20240127942A1 patent drawing

AI summary

A computer implemented method for a data sharing system to share healthcare data from a healthcare data provider with a healthcare data processing application. The method includes identifying one or more healthcare data processor applications, generating and displaying selectable options of the one or more data processor applications at a healthcare data provider, obtaining a selection of the one or more data processor applications from the healthcare data provider, obtaining a data provider/application-specific encryption keyset corresponding to each selected healthcare data processor application, the keyset comprising a private key and a public key, retaining the private key of the data provider/application-specific keyset with a trusted component of the healthcare data provider, and sharing the public key of the data provider/application-specific keyset with the corresponding selected healthcare data processor application.