Patient Data Security via Distributed External Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems fail to concurrently ensure the security and availability of sensitive medical information, particularly in healthcare settings, where unauthorized access can compromise patient safety and violate strict security requirements.
Innovation Solution
A method and system that securely stores patient information on an external device carried by patients, using a key pair generation and verification process involving a server system, user terminal, and identification medium, allowing authorized healthcare personnel to access and update information even without network connectivity through short-range communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive information is stored in server systems with network connectivity, then security control is improved, but availability is worsened due to network unavailability or connectivity issues
Solution Approach 1:
The system segments the centralized server storage into distributed local storage units (external devices carried by patients). Each device contains local storage capability with cryptographic verification mechanisms, allowing the system to maintain security through distributed architecture while eliminating single-point failure risks associated with centralized server dependency.
Solution Approach 2:
The patent introduces cryptographic intermediaries (digital signatures, public-private key pairs, and verification algorithms) as mediators between the stored information and access requests. These cryptographic mechanisms enable secure verification of information integrity and authorization without requiring continuous connection to central authorities, thus maintaining both security and availability.
2Productivity
If sensitive information is made accessible without network connection, then availability is improved, but security is worsened due to unauthorized access risks
Solution Approach 1:
The system performs preliminary cryptographic actions during information storage: generating public-private key pairs, creating digital signatures, and embedding verification mechanisms directly into the stored data structure. These preliminary security measures are baked into the information itself, enabling later verification and authorization checks to be performed locally without network connection, thus maintaining security alongside improved availability.
3Productivity
If physical documents are used to store medical information, then availability is improved, but security and durability are worsened due to damage and unauthorized access
Solution Approach 1:
The patent replaces the mechanical/physical storage system (paper documents) with an electronic-digital storage system that uses cryptographic fields and algorithms for security. Instead of relying on physical security measures (locked cabinets, controlled access rooms), the system uses digital signatures, public-key cryptography, and hash verification to protect information integrity and authorization, thereby maintaining availability while dramatically improving security and durability.
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
A method for securing sensitive information, includes storing patient information in a secured form in an external device (108) that is carried by a patient. A user terminal (102) obtains a first signature generated using a first secret key inside a first identification medium (106, 302A), where the first secret key is associated with a first healthcare person. Moreover, the user terminal communicates a write request that includes at least the first signature to the external device. The external device receives the write request from the user terminal when the user terminal is within a proximal communication range of the external device. Furthermore, the external device verifies at least the first signature received in the write request. The user terminal writes first information to the external device, based on verification of at least the first signature. A system (100A, 100B) for securing sensitive information is also provided.