Medical Technology Data Transfer via Centralized Key Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a challenge in monitoring or controlling the transfer of machine data generated by medical technology systems, such as MRI and CT systems, to third parties, which can lead to unintended disclosure of internal technical processes.

Innovation Solution

A method for transmitting encrypted data from medical technology systems, where machine data is encrypted using a specific data key, and access is controlled through a central data transfer authorization entity, which issues user-specific data keys for decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If machine data is transferred to third parties for maintenance or analysis, then system functionality and performance are improved, but security and control over internal technical processes are compromised

Engineering Contradiction:
Improvedata access for maintenanceVSAvoidunauthorized disclosure of technical processes
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A central data transfer authorization entity is introduced as an intermediary between the medical technology system and third parties. This entity controls and monitors all data transfers by managing encryption keys, allowing maintenance personnel to access necessary machine data while preventing unauthorized disclosure of internal technical processes. The intermediary ensures that data is only transferred to authorized parties under controlled conditions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies encryption and decryption transformations to the machine data. Data is encrypted using a data key managed by the central authorization entity before transfer, and can only be decrypted by authorized third parties who possess the appropriate decryption keys. This parameter change (from plaintext to encrypted form) maintains security while enabling controlled access for maintenance purposes.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If data is encrypted to prevent unauthorized access, then security is improved, but ease of data transfer and access is reduced

Engineering Contradiction:
Improveunauthorized data accessVSAvoiddata transfer process
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The medical technology system automatically performs encryption of machine data using the data key without requiring manual intervention. The system self-manages the encryption process, generating and applying cryptographic transformations to protect data before transfer. This automation maintains security while minimizing the operational burden on users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The central data transfer authorization entity manages multiple functions including key generation, key distribution, authorization verification, and transfer monitoring. This multi-functional entity simplifies the overall process by consolidating security management tasks, making the encrypted data transfer system easier to operate despite the underlying cryptographic complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250124143A1Transferring Encrypted Data from a Medical Technology System
Publication Date: 2025.04.17 SIEMENS HEALTHINEERS AG
  • US20250124143A1 patent drawing
  • US20250124143A1 patent drawing
  • US20250124143A1 patent drawing

AI summary

Method for transmitting encrypted data from a medical technology system, including: generating the encrypted data by applying a DK to data generated by the MTS; transmitting a first user-specific DK for decrypting the encrypted data to a first data user authorized by a central data transfer authorization entity; transmitting the encrypted data from the MTS to the first data user; decrypting the encrypted data by the first data user by applying the first user-specific DK; transmitting a second user-specific DK, which is different from the first user-specific DK, by the central data transfer authorization entity to a second data user authorized by the central data transfer authorization entity for decrypting the encrypted data; transmitting the encrypted data by the MTS or by the first data user to the second data user; and decrypting the encrypted data by the second data user by applying the second user-specific DK.