Logically Separated Working Environments for Secure Medical Image Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing medical imaging systems face difficulties in integrating unpermitted programs for image processing into clinical workflows while ensuring security, as current solutions either poorly integrate separate computers or provide insufficient security by granting wide-ranging access rights to unpermitted programs.

Innovation Solution

A computer system with two logically separated working environments, one for a permitted medical program and another for an unpermitted program, allows secure execution of the unpermitted program by using a uniform platform for command execution and image processing, with the unpermitted program's output marked for distinction, enabling testing and updating via a network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate computer system is provided for executing unpermitted programs, then security is improved, but integration into clinical workflow deteriorates due to poor access to image data and elaborate data transfer requirements

Engineering Contradiction:
ImprovesecurityVSAvoidintegration into clinical workflow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system is segmented into a first working environment for permitted programs and a second working environment for unpermitted programs, with logical separation ensuring security while maintaining workflow integration. The second working environment is isolated to prevent harm to the first environment, yet both can access the same image data through controlled interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computer system provides a unified platform that can execute both permitted medical programs and unpermitted testing programs through a single interface. The system accommodates multiple program types with different security requirements within one integrated environment, eliminating the need for separate computer systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If unpermitted programs are allowed to access image data with wide-ranging access rights, then integration into clinical workflow is improved, but security deteriorates as harmful programs can modify patient data or cause further harm

Engineering Contradiction:
Improveintegration into clinical workflowVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The working environments are logically segmented with different access rights. The second working environment for unpermitted programs operates in isolation, preventing it from harming the first working environment or its permitted programs, while still allowing necessary access to image data for testing purposes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A controlled interface acts as an intermediary between the two working environments. This intermediary enables the second environment to access image data when needed while preventing it from modifying critical data or harming the first environment, thus mediating between security requirements and workflow integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a separate computer system is used for unpermitted programs, then security is improved, but device complexity increases due to multiple systems and elaborate data transfer requirements

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the functionality of separate permitted and unpermitted program environments into a single computer system with logical separation. This combining approach maintains security through environmental isolation while simplifying the overall system architecture by eliminating the need for physically separate computer systems and complex data transfer infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9454547B2Computer system and method for image processing
Publication Date: 2016.09.27 SIEMENS HEALTHINEERS AG
  • US9454547B2 patent drawing
  • US9454547B2 patent drawing
  • US9454547B2 patent drawing

AI summary

A computer system for image processing has a first working environment with a first program for image processing, as well as a second working environment, logically separated from the first working environment, with a second program for image processing. The first working environment is implemented on a first server. Furthermore, the first working environment is designed to receive a first command to execute the first program and a second command to execute the second program, and to send the second command to the second working environment. The second working environment is designed to send an image processed by the second program to the first working environment. The communication of a user with the first and second program thus occurs via a uniform platform in the form of the first working environment, and the integration of the second program for image processing into the workflow is facilitated.