Diagnostic Reader Unit Encryption for Secure Multiplexed Assay Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current diagnostic systems for point-of-care applications are costly due to high prices per analyte and limited multiplexing capabilities, with existing solutions failing to efficiently manage and protect sensitive medical data, particularly in decentralized settings where sample transportation is necessary.

Innovation Solution

A diagnostic system that enables multiplexed diagnostic tests by encrypting analytical results, allowing users to selectively access desired data while controlling access and protecting privacy, using a combination of assay units, reader units, and evaluation units with encryption and authorization mechanisms to reduce costs and enhance data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiplexed diagnostic tests are used to detect multiple analytes simultaneously, then the productivity and analytical capabilities are improved, but the cost per test and device complexity increase

Engineering Contradiction:
Improvethroughput of analytical capabilitiesVSAvoidcomplexity of diagnostic system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the diagnostic system into separate functional modules: assay units for different analyte panels, reader units for signal detection, and a central server for data management. This allows the system to perform multiplexed testing while managing complexity through modular architecture, where each component has a specific function and can be independently optimized or replaced.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The reader unit is designed with universal capabilities to detect signals from multiple types of assay units simultaneously. The system can handle different analyte panels (cardiac, infectious disease, metabolic) using a single reader platform, reducing the need for multiple specialized devices and thereby managing complexity while maintaining high productivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If all analytical results from multiplexed tests are made accessible to users, then the information completeness is improved, but the data security and privacy protection are worsened

Engineering Contradiction:
Improvecompleteness of analytical resultsVSAvoidprivacy risk of medical data
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality control by encrypting specific portions of the data stream at different security levels. Sensitive personal identifiers and health information are encrypted with higher security protocols, while less sensitive operational data uses standard encryption. This allows complete data access for authorized users while maintaining differentiated privacy protection for different data elements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

A secure server acts as an intermediary between the diagnostic system and users. The server receives all analytical results, applies appropriate encryption and access control rules, then delivers data to authorized users. This intermediary layer ensures complete information availability while protecting privacy through centralized security management and selective data release.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If point-of-care testing is implemented to enable rapid results, then the response time is improved, but the sample transportation requirements and logistical complexity are worsened

Engineering Contradiction:
Improvetime to obtain diagnostic resultsVSAvoidlogistical complexity of sample management
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent extracts the complex sample transportation and processing requirements from the core diagnostic function by implementing automated sample collection and handling systems at the point of care. Sample collection devices are integrated with the assay units, and refrigeration/transport requirements are managed through portable equipment, separating these logistical complexities from the rapid testing capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The diagnostic system is designed to be self-sufficient at the point of care, with integrated sample collection, processing, and analysis capabilities. The system automatically manages sample handling, reagent dispensing, and result reporting without requiring external laboratory infrastructure, thereby enabling rapid results while managing logistical complexity through automation.

Inventive Principle:
Principle #25Self-service

4Reliability

If access control mechanisms are implemented to protect medical data, then the data security is improved, but the system complexity and user authorization requirements are worsened

Engineering Contradiction:
Improvesecurity of medical dataVSAvoidcomplexity of authorization system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

User authorization and access rights are predetermined and configured in advance through role-based access control profiles. The system pre-assigns permission levels to different user roles (physicians, laboratory personnel, patients) based on their functions, so that during operation, users simply need authentication rather than complex real-time authorization decisions. This preliminary configuration reduces operational complexity while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10380376B2System and method for protecting and controlling access to analytical results of a diagnostic test assay
Publication Date: 2019.08.13 ONE DROP DIAGNOSTICS
  • US10380376B2 patent drawing
  • US10380376B2 patent drawing
  • US10380376B2 patent drawing

AI summary

A reader unit (31) is configured to be operationally coupled with an assay unit (11) that is capable of performing one or more diagnostic tests (13) on one or more physiological samples (15), and is configured (32, 36) to obtain test raw data (73) of diagnostic tests performed on an assay unit operationally coupled with the reader unit. The reader unit comprises an encryption module (33) that is configured to encrypt input data with locking key data (75), the input data comprising the test raw data, or data derived from said test raw data. The reader unit is configured to provide access to the encrypted data (77), but not to the input data.