Security Domain Bridge for Cross-Domain Information Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems, particularly in healthcare and financial sectors, face challenges in securely sharing and managing private information across different security domains without direct administrator contact, leading to issues like unauthorized access, delays, and compliance with regulations like HIPAA, especially for individuals with developmental disabilities.

Innovation Solution

A system that enables secure sharing and management of information across multiple security domains by using algorithms for authorized access, emergency access, and tracking changes, allowing users to record and update information securely, with roles and privileges assigned by administrators, and enabling secure access to archived data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rule-based security access systems with passwords are used, then security and privacy protection is improved, but the ability to share information across different security domains is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidinformation sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a security domain bridge as an intermediary component that enables information sharing between different security domains without requiring direct administrator contact or compromising security protocols. The bridge acts as a mediator that translates and facilitates authorized information exchange while maintaining the integrity of each domain's security rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system provides a universal access control mechanism that can handle multiple types of information sharing scenarios across different security domains through a single integrated framework. The security domain bridge can manage various access patterns, emergency situations, and information types while maintaining consistent security enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If paper format information sharing is used due to lack of compatible electronic formats, then security and privacy can be maintained, but delays, missing information, and lack of clarity are introduced

Engineering Contradiction:
ImprovesecurityVSAvoidinformation sharing speed
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical paper-based information sharing system with an electronic system that uses standardized data formats and secure transmission protocols. The security domain bridge enables electronic information exchange that is both secure and efficient, eliminating the delays and ambiguities inherent in paper-based processes while maintaining security standards.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If all doctors and health professionals are provided with access to all patients' information, then ease of operation in emergencies is improved, but potential liability for not properly protecting sensitive information increases

Engineering Contradiction:
Improveaccessibility in emergenciesVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic access control that can adapt user privileges based on contextual factors such as emergency situations, user roles, and information sensitivity. During emergencies, the system can temporarily expand access rights while maintaining audit trails, allowing healthcare professionals to access necessary information without permanently compromising security or creating liability risks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security domain bridge incorporates feedback mechanisms that continuously monitor access patterns, detect anomalies, and provide real-time alerts to administrators. This feedback system enables the system to respond to security threats and adjust access controls dynamically, balancing ease of operation with protection against unauthorized access.

Inventive Principle:
Principle #23Feedback

4Reliability

If separate accounts and passwords are maintained for each user across organizations, then security is improved, but complexity of managing access and privileges increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the access management functions of multiple security domains into a single unified security domain bridge. This consolidation allows administrators to manage user access, privileges, and authentication across different organizations through a single interface and set of rules, significantly reducing the complexity of managing separate accounts and passwords while maintaining security standards.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9794257B2Managing secure sharing of private information across security domains by individuals having a service authorization
Publication Date: 2017.10.17 THERAP SERVICES LLC
  • US9794257B2 patent drawing
  • US9794257B2 patent drawing
  • US9794257B2 patent drawing

AI summary

A system and method of granting a service authorization to a service provider in a regulating or funding agency of a first organization to access one or more individual's information in a second organization, where a service authorization comprises an authorization to access information and to provide specific services from said regulating or funding agency, the request for service authorization coming from an organization from an individual, patent or guardian of the individual, or regulating or funding organization, for service to be provided to an individual whose private information is stored within the second organization. A system for approving or rejecting the service authorization requests is provided based on authorization of the service provider, as well as a system and method for recording and sharing the outcomes of all decisions with the organization. If a service authorization is approved, it may be integrated into the organization's own workflow.