Medical Data Desensitization via Secure Environment Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data encryption methods for medical data compromise portability and increase the risk of sensitive data leakage due to key management challenges, and physical isolation limits data flow and flexibility.

Innovation Solution

A method and system that perform desensitization processing on medical data in a secure working environment, allowing secure data transmission between devices without human intervention, using desensitization and restoration processes preset in each environment, and optional encryption for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is used to protect sensitive data in medical data, then the security of sensitive data is improved, but the portability of medical data deteriorates

Engineering Contradiction:
Improvesecurity of sensitive dataVSAvoidportability of medical data
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments medical data into sensitive data and non-sensitive data components. Desensitization processing selectively masks or removes sensitive portions while preserving non-sensitive information, allowing the data to maintain utility and portability without exposing sensitive elements. This segmentation approach resolves the contradiction by protecting only what needs protection while keeping the rest accessible and portable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces desensitization processing as an intermediary mechanism between the original medical data and its transmission/storage. This intermediary process transforms the data into a form that maintains portability and usability while inherently protecting sensitive information through masking or removal, eliminating the need for complex encryption-key management systems that hinder portability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data encryption is used to protect sensitive data, then the security of sensitive data is improved, but the complexity of key management increases

Engineering Contradiction:
Improvesecurity of sensitive dataVSAvoidcomplexity of key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts sensitive data from the complete medical data set and applies desensitization processing specifically to these extracted sensitive portions. By separating the protection mechanism from the entire data set and applying it only where needed, the system eliminates complex encryption-key management while maintaining security for sensitive information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The desensitization processing is automatically applied through preset rules and algorithms that identify and mask sensitive data without requiring manual key management or complex security protocols. The system serves itself by automatically protecting sensitive information through structured processing, eliminating the need for external key management complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If physical isolation is used to protect sensitive data, then the security of sensitive data is improved, but the flexibility of data flow deteriorates

Engineering Contradiction:
Improvesecurity of sensitive dataVSAvoidflexibility of data flow
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the state of sensitive data from its original form to a desensitized form through masking or removal of sensitive elements. This parameter change allows the data to flow freely across systems and platforms without requiring physical isolation, as the sensitive information is already protected in its transmitted state. The data maintains flexibility and portability while security is ensured through the transformed parameter state.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11735319B2Method and system for processing medical data
Publication Date: 2023.08.22 BEIJING TSINGHUA CHANGGUNG HOSPITAL
  • US11735319B2 patent drawing
  • US11735319B2 patent drawing
  • US11735319B2 patent drawing

AI summary

A method and a system for processing medical data are provided. The method executed by a first device and a second device includes: the first device performs desensitization processing on first medical data in a first secure working environment to obtain desensitized data, provides the desensitized data to the second device; the desensitization processing is preset in the first secure working environment, and the first medical data is stored in the first secure working environment; the second device performs restoration processing on the desensitized data in a second secure working environment to obtain the first medical data, the restoration processing is preset in a second secure working environment, and the restoration processing corresponds to the desensitization processing.