Secure Patient Data Sharing via Smart Card Credential Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Individual information stored in Internet-accessible storage devices is vulnerable to theft and unauthorized access, despite the use of sophisticated security techniques, posing risks of identity theft, fraud, and other disadvantages.
Innovation Solution
A facility for secure, geographically-diverse access to individual information using portable data storage devices like smart cards, which store encrypted user data and credentials, and data access devices that decrypt data only with valid credentials, ensuring secure access and periodic updates of security certificates to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If individual information is stored in Internet-accessible storage devices for easy access and sharing, then data accessibility and service efficiency are improved, but vulnerability to theft and unauthorized access increases
Solution Approach 1:
The system segments data access control by separating credentials (stored on portable devices) from data (stored in cloud repositories). This segmentation allows data to remain accessible in the cloud while control over access is distributed to multiple authorized parties through their respective portable devices, thereby maintaining accessibility while reducing vulnerability to unauthorized access.
Solution Approach 2:
The patent introduces portable data storage devices (smart cards) as intermediaries that hold credentials and enable secure access to cloud-stored data. These intermediary devices act as trusted mediators between users and the cloud storage system, providing an additional layer of security without compromising the ease of data access through Internet-connected devices.
2Reliability
If sophisticated security techniques are used to protect stored data, then data security is improved, but system complexity and difficulty of operation increase
Solution Approach 1:
The system implements self-service security mechanisms where portable data storage devices automatically perform credential verification and authentication operations. The smart cards contain embedded logic that enables them to independently validate credentials and establish secure connections without requiring complex user intervention or centralized verification, thereby maintaining high security while simplifying operation.
Solution Approach 2:
Security credentials are pre-loaded onto portable data storage devices before they are needed for data access. This preliminary action of pre-configuring authentication credentials eliminates the need for complex real-time credential management during data access operations, reducing system complexity while maintaining strong security through pre-validated authentication mechanisms.
3Reliability
If data is encrypted and access is restricted to authorized parties only, then data security is improved, but data sharing efficiency and service speed are reduced
Solution Approach 1:
The system implements dynamic access control where encryption keys and credentials can be updated, revoked, or modified without requiring changes to the underlying data storage or retrieval infrastructure. Portable data storage devices can dynamically present different credentials to different authorized parties, enabling flexible and efficient data sharing while maintaining security through adaptive authentication mechanisms.
Solution Approach 2:
The patent creates a universal access framework where a single portable data storage device architecture can serve multiple authorized parties with different access rights to the same data repository. The smart card system provides multi-functional credential storage and verification capabilities that enable efficient data sharing across multiple users and applications while maintaining centralized security control through standardized authentication protocols.
Data Source
AI summary
A sharing package data structure for the secure maintenance and sharing of information relating to a person with one or more parties is described. The data structure comprises: (1) a version of the data that has been encrypted in such a way that a data decryption key is needed to decrypt it; (2) a hash on the data decryption key; and (3) access control list entries each containing a version of the data decryption key that has been encrypted with a public key associated with a different party authorized to access the data. The contents of the data structure are usable to provide access to a decrypted version of the data to a party that is able to decrypt the encrypted data decryption key stored in one of the access control entries.


