Proxy Server Data Segmentation for Secure Practice Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current practice management systems for doctors and dentists lack security, flexibility, and cost-efficiency, particularly in transitioning from stand-alone solutions to web-based systems, due to data protection concerns regarding patient data transmission.

Innovation Solution

A computer system with a server and proxy server architecture where patient data is encrypted by the proxy server and stored on the server in encrypted form, while other data can be processed as plain text, using a combination of symmetric and asymmetric encryption methods, and special HTML attributes for data identification, ensuring secure communication and compliance with data protection regulations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all data is encrypted and stored in encrypted form on the server, then data protection and security are improved, but meaningful data processing and user-friendly operation become impossible

Engineering Contradiction:
Improvedata protectionVSAvoiddata processing capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments data into two categories: first data (patient-related information requiring encryption) and second data (processing information that can be transmitted in plain text). This segmentation allows the system to encrypt only what is necessary for security while maintaining the ability to process other data efficiently, thus resolving the contradiction between data protection and operational capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different data handling qualities to different data types: first data is encrypted and stored in encrypted form on the server, while second data is transmitted and processed in plain text. This local differentiation of data quality ensures that security is applied only where necessary, preserving operational efficiency for data that does not require encryption.

Inventive Principle:
Principle #3Local quality

2Reliability

If a proxy server is introduced to encrypt data before transmission to the server, then data protection compliance is improved, but system complexity increases

Engineering Contradiction:
Improvedata protection complianceVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a proxy server as an intermediary component between the client and the server. This proxy server handles the encryption and decryption of first data, allowing the server to remain relatively simple while still achieving data protection compliance. The intermediary absorbs the complexity of encryption operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If web-based practice management systems are implemented, then flexibility and cost-efficiency are improved, but data protection requirements make direct server access impossible

Engineering Contradiction:
ImproveflexibilityVSAvoiddata protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The proxy server acts as a mediator that enables web-based access while maintaining data protection. It encrypts first data before transmission to the server and decrypts it upon retrieval, allowing the system to achieve both flexibility of web-based access and reliability of data protection without requiring direct server access.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If first data is encrypted by the proxy server, then patient data confidentiality is improved, but the ability to process and search data becomes more difficult

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata processing efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent segments data processing into two streams: encrypted processing of first data (patient information) and plain text processing of second data (processing information). This segmentation allows the system to maintain confidentiality for sensitive data while preserving processing efficiency for data that does not require encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy server performs preliminary encryption of first data before it reaches the server, and preliminary decryption when retrieving data. This preliminary action ensures that data confidentiality is maintained throughout transmission and storage, while the server can still efficiently process second data in plain text format.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3373546A1Computer system and method with client, proxy-server and server
Publication Date: 2018.09.12 ARZ DENT GMBH
  • EP3373546A1 patent drawingFigure 1a~1c
  • EP3373546A1 patent drawingFigure 2
  • EP3373546A1 patent drawingFigure 3a~3b

AI summary

The present invention discloses a computer system comprising a server and a proxy server for communication with a client, in particular for providing a practice management system. The proxy server and the server are configured such that communication between the client and the server takes place via the proxy server, and data entered on the client can be stored on the server and retrieved by the client. It is provided that first data, which can be entered on the client, is encrypted by the proxy server in such a way that it cannot be decrypted by the server and is stored encrypted on the server. Second data, which can be entered on the client, is transmitted to the server in such a way that it can be processed there as plaintext.