Tokenized Trial Data Linking via Bridge File

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for de-identifying personal health information in healthcare data sets are inadequate, leading to privacy breaches and limitations in data sharing and analysis, as they rely on single hashing seeds or encryption keys, making it difficult to link anonymized trial data with de-identified patient data across different healthcare entities.

Innovation Solution

A method and system that generates multiple tokens from personal identification information for a subject participating in a trial, creating a bridge file that links the subject identifier with these tokens, allowing for secure linking of trial data to other de-identified data without revealing personal information, using unique encryption keys managed by a central platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If conventional hashing methods with single encryption keys are used to de-identify personal health information, then data privacy protection is improved, but the ability to link anonymized trial data with de-identified patient data across different healthcare entities deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata linking capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent divides the encryption key into multiple separate keys, with each key managed by a different healthcare entity. This segmentation allows each entity to independently encrypt and de-identify their own data using their unique key, while still enabling linkage across entities through a central coordination mechanism that maps subject identifiers across the fragmented key system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a central management system as an intermediary that coordinates between multiple healthcare entities. This intermediary maintains the mapping relationships between subject identifiers from different entities and manages the complex inter-key relationships, enabling data linkage without requiring direct key sharing between entities and thus preserving privacy while enabling connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proprietary de-identification methods are used by each healthcare entity, then entity-specific data security is improved, but the ability to aggregate and share data for meaningful analysis deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata aggregation capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Each healthcare entity maintains its own proprietary encryption key, preserving entity-specific security autonomy. The segmentation of the key management system allows each entity to independently secure their data while the central coordination layer provides the infrastructure for aggregation, thus maintaining both security independence and data sharing capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal interface and standardized mapping mechanism that works across different proprietary encryption systems. The central management system provides universal functionality to aggregate data from multiple entities with different proprietary methods, enabling meaningful analysis without requiring entities to abandon their secure proprietary approaches.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If subject identifiers are used in trial data to maintain anonymity, then subject privacy is improved, but the ability to link trial data with other de-identified data deteriorates

Engineering Contradiction:
Improvesubject anonymityVSAvoiddata linkage information
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent introduces a central management system as an intermediary that holds the mapping relationships between trial subject identifiers and external de-identified data identifiers. This intermediary enables linkage without exposing the direct connection between subject identifiers and personal information, maintaining anonymity while providing the necessary linkage capability through controlled access to mapping data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary mapping and tokenization actions before data linkage is needed. Subject identifiers are pre-mapped to unique tokens and the relationships are pre-established in the central management system. This preliminary action enables efficient linkage operations later without requiring real-time decryption or exposure of identifying information, thus preserving anonymity while enabling data connection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11755779B1Linking of tokenized trial data to other tokenized data
Publication Date: 2023.09.12 DATAVANT INC
  • US11755779B1 patent drawing
  • US11755779B1 patent drawing
  • US11755779B1 patent drawing

AI summary

Systems and methodologies for generating a bridge file linking a subject identifier (Subject ID) (or a tokenized subject identifier), used to anonymize a subject in a trial, to tokenized personal identification information (PII), used to de-identify other data for the subject, without revealing the link between the subject identifier (subject ID) and the personal identifying information (PII) for the subject. The bridge file can then be used to link trial data for the subject anonymized with a subject ID to other data for the subject de-identified with tokenized PII.