Viewing Session Takeover Locking Mechanism for Medical Imaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In medical imaging applications, there is a need to allow multiple users to take over a viewing session for patient data while maintaining security controls and audit logging, as standard practices often result in HIPAA violations and unnecessary privilege escalation due to differing user privileges and access levels.

Innovation Solution

A system and method for viewing session takeover that includes a locking mechanism to prevent access to patient medical data until subsequent user authentication, with configuration parameters associated with the primary user account applied to the secondary user's session, ensuring secure and controlled access without terminating the viewing session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a viewing session is left open for multiple users to access patient data, then ease of operation is improved, but security control deteriorates leading to HIPAA violations and unauthorized access

Engineering Contradiction:
Improveease of access to patient dataVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary locking mechanism that sits between the patient data and multiple users. When a user logs out, the system automatically locks the viewing session with a lock indicator, preventing subsequent users from accessing the data without proper authentication. This intermediary control resolves the contradiction by maintaining ease of operation for authorized users while enforcing security controls to prevent unauthorized access and HIPAA violations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If user privileges are escalated to allow any user to take over a viewing session, then adaptability is improved, but harmful factors increase due to unnecessary privilege escalation

Engineering Contradiction:
Improveuser session transfer capabilityVSAvoidprivilege escalation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by maintaining different privilege levels for different users within the same viewing session framework. The system preserves the primary user's configuration parameters and applies them to the secondary user's session, allowing adaptability in session transfer while maintaining local security boundaries. Each user operates with their own authenticated privileges, preventing unnecessary privilege escalation while enabling seamless session takeover for authorized users.

Inventive Principle:
Principle #3Local quality

3Reliability

If a locking mechanism is implemented to prevent unauthorized access, then security control is improved, but ease of operation deteriorates due to additional authentication requirements

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by automatically applying the primary user's configuration parameters to the secondary user's session before the secondary user begins work. This preliminary setup eliminates the need for secondary users to reconfigure their environment, maintaining ease of operation despite the added authentication step. The lock indicator is also established in advance, clearly communicating the security state to users and reducing confusion.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If configuration parameters are applied from primary user to secondary user session, then productivity is improved by avoiding reconfiguration, but device complexity increases

Engineering Contradiction:
Improvesession transfer efficiencyVSAvoidsession management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent uses copying by replicating the primary user's configuration parameters and applying them to the secondary user's session. Instead of requiring secondary users to manually reconfigure their environment, the system copies relevant settings from the primary user, significantly improving productivity during session transfers. This copying mechanism manages device complexity by automating the parameter transfer process through the session controller.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10157292B2Viewing session takeover in medical imaging applications
Publication Date: 2018.12.18 MERATIVE US LP
  • US10157292B2 patent drawing
  • US10157292B2 patent drawing
  • US10157292B2 patent drawing

AI summary

A system for viewing session takeover is provided. A plurality of user accounts have access to patient medical data images. A locking mechanism is operable by each user to prevent access to patient medical data until subsequent user authentication, without terminating a viewing session. A storage medium maintains configuration parameters associated with the primary user account. A session controller establishes a viewing session by retrieving the patient medical data for viewing on the display. The session controller applies the configuration parameters associated with the primary user account to the viewing session of the secondary user. A log records each user access associated with each viewing session.