Role-Based Biometric Access Control for Healthcare Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web-enabled information retrieval systems lack efficient role-based access control, making it difficult for healthcare professionals to access patient data from various locations while ensuring privacy and restricting inappropriate access.

Innovation Solution

A web-based system that provides role-based access to biometric and healthcare information, allowing different user roles (e.g., patient, clinician, administrator) to access specific web pages and perform actions based on their defined roles, using log-on information, biometric data, or computer-readable cards, enabling access via internet-enabled devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If web-based access to patient information is provided from various locations, then accessibility and ease of operation are improved, but security and privacy protection become more difficult to maintain

Engineering Contradiction:
Improveaccessibility to patient informationVSAvoidprivacy breaches and inappropriate access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments access rights by defining multiple roles (clinician, administrator, patient) with different permission levels. Each role can access only the information and functions appropriate to their professional needs, thereby maintaining security while enabling widespread access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authentication mechanism that verifies user identities and assigns roles before granting access. This mediator layer controls and logs all access attempts, ensuring that even remote access through various devices maintains security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If role-based access control is implemented, then privacy protection and security are improved, but system complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidaccess control system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system uses universal role definitions that can be applied across multiple users and access points. A single role configuration can govern access for numerous clinicians, administrators, or patients, reducing the overall complexity despite the detailed access control requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple access levels are provided for different users, then adaptability and versatility are improved, but difficulty of detecting and measuring appropriate access becomes greater

Engineering Contradiction:
Improveaccess levels for different usersVSAvoidappropriate access control
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system visually distinguishes different access levels and roles through color-coded interfaces and indicators. This makes it immediately apparent to users what level of access they have and what information they are permitted to view or modify, simplifying the detection of appropriate access boundaries.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS7730078B2Role based internet access and individualized role based systems to view biometric information
Publication Date: 2010.06.01 MOBILEHELP LLC
  • US7730078B2 patent drawing
  • US7730078B2 patent drawing
  • US7730078B2 patent drawing

AI summary

A web based application makes data conveniently and readily available to individuals dispersed from a common collection site or database. Individuals can access various levels of retrospective or previously stored data in the database only in accordance with pre-defined roles, or levels which can be established at log on.