Pseudonymization Server for Secure Radiology Data Interchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for secure data interchange in medical radiology face challenges in ensuring confidentiality and compatibility across different network nodes, leading to increased infrastructure complexity and potential security breaches when transmitting radiological image data.

Innovation Solution

A network-based system utilizing a transmission node with a pseudonymization module to pseudonymize image data, a cloud-based processing node with virtual clients, and a collaboration server to manage secure data interchange, allowing secure data sharing across nodes without requiring identical equipment or software versions, while maintaining confidentiality by storing sensitive data within a defined security domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If complete screen interface content is transmitted to another computer interface, then collaboration between radiologists is enabled, but security-critical data records are transmitted beyond security boundaries

Engineering Contradiction:
Improvecollaboration capabilityVSAvoidsecurity compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the transmitted data into two distinct parts: pseudonymized image data that can be shared freely for collaboration, and confidential PHI data that remains protected within the security domain. This segmentation allows collaboration functionality while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A pseudonymization server acts as an intermediary between the transmitting and receiving systems. It receives the complete screen content, pseudonymizes the confidential data, and returns the processed content. This intermediary enables collaboration while preventing direct exposure of sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If only basic medical images are transmitted, then security boundaries are maintained, but receiver nodes require specific software and hardware installation increasing infrastructure complexity

Engineering Contradiction:
Improvesecurity complianceVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of transmitting raw image data that requires specific software to display, the system transmits a pseudonymized copy of the complete screen content. This copy contains all necessary visual information for collaboration while being self-contained and not requiring the receiving system to have identical software or hardware configurations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The pseudonymized screen content serves multiple functions: it maintains security compliance by excluding PHI data, provides complete visual information for collaboration, and works across different receiver node configurations without requiring specific software or hardware installations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If identical software versions are installed on both sending and receiving appliances, then error-free transmission is ensured, but installation and maintenance complexity increases

Engineering Contradiction:
Improvetransmission accuracyVSAvoidinstallation complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The pseudonymization server acts as a mediator that standardizes the data format before transmission. By processing the screen content through this intermediary, the system ensures compatibility and error-free transmission without requiring the receiving appliance to have the same software version as the sending appliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9882974B2Network-based collaboration for secure data interchange for image data records having confidential components
Publication Date: 2018.01.30 SIEMENS HEALTHINEERS AG
  • US9882974B2 patent drawing
  • US9882974B2 patent drawing
  • US9882974B2 patent drawing

AI summary

A network-based system (and method) is disclosed for the collaboration of transmission nodes and receiver nodes for secure data interchange for radiological image data records including confidential components. The processing node provides a set of virtual clients, wherein a virtual client is associated with a respective receiver node and is intended to provide the intended pseudonymized image data record. A connection message is sent to the respective receiver nodes. The connection message includes a reference to the address of the virtual client that the receiver node can use to retrieve the pseudonymized image data record if it is situated outside a security domain of the transmission node. Furthermore, the connection message includes a reference to a memory address in the local PHI share memory unit that the receiver node can use to provide the original image data record if the receiver node is situated inside the security domain.