Method and system for providing a secure multi-user portable database
    1.
    发明申请
    Method and system for providing a secure multi-user portable database 有权
    用于提供安全的多用户便携式数据库的方法和系统

    公开(公告)号:US20070006322A1

    公开(公告)日:2007-01-04

    申请号:US11173133

    申请日:2005-07-01

    摘要: A system and method for providing, managing, and accessing a multi-user secure portable database using secure memory cards is provided. The database has a secure portion for storing security keys and a non-secure portion for encrypted data files. Access to the encrypted data files is controlled by assigning access rights through an access control matrix to each encrypted data file according to a hierarchical structure of users. A user requesting access is identified in the hierarchy, associated with a key for allowing the requested access, and the requested access allowed to a file in accordance with the rights allocated through the access control matrix. A patient can selectively grant access to encrypted medical records on his card to a physician. Authentication of the owner/patient is preferably required. Other records required by emergency medical personnel are readable from the same card without requiring permission from the patient.

    摘要翻译: 提供了一种使用安全存储卡提供,管理和访问多用户安全便携式数据库的系统和方法。 数据库具有用于存储安全密钥的安全部分和用于加密的数据文件的非安全部分。 根据用户的层次结构,通过访问控制矩阵向每个加密数据文件分配访问权限来控制对加密数据文件的访问。 在层次结构中识别与用于允许所请求的访问的密钥相关联的请求访问的用户,以及根据通过访问控制矩阵分配的权限允许的所请求的访问文件。 患者可以选择性地向医师授予他卡上的加密医疗记录的访问权限。 所有者/患者的认证最好是需要的。 紧急医务人员所需的其他记录可从同一张卡片中读取,无需患者许可。

    METHOD AND SYSTEM FOR PROVIDING A SECURE COMMUNICATION CHANNEL TO PORTABLE PRIVATIZED DATA
    2.
    发明申请
    METHOD AND SYSTEM FOR PROVIDING A SECURE COMMUNICATION CHANNEL TO PORTABLE PRIVATIZED DATA 审中-公开
    提供安全通信信道到便携式私有数据的方法和系统

    公开(公告)号:US20160080364A1

    公开(公告)日:2016-03-17

    申请号:US14837144

    申请日:2015-08-27

    摘要: A system and method for communicating secure, privatized data stored on a first user device with a second user device requesting access thereto includes initiating a timed access gate for receiving verification of authenticating credentials from the second user device, after the first user credentials associated with the first user device are verified. If the second user device is verified within the predetermined period of time, an authentication handshake between the first user device and the second user device is completed. On completion of the handshake, a communication channel is opened for transmitting the first user's privatized data between the first user device and the second user device.

    摘要翻译: 用于将存储在第一用户设备上的安全私有化数据与请求访问的第二用户设备通信的系统和方法包括在与所述第二用户认证相关联的所述第一用户凭证之后启动用于接收来自所述第二用户设备的认证凭证的验证的定时访问门 第一个用户设备被验证。 如果在预定时间段内验证第二用户设备,则完成第一用户设备和第二用户设备之间的认证握手。 在握手完成时,打开通信通道,用于在第一用户设备和第二用户设备之间发送第一用户的私有化数据。

    Method and system for providing a secure multi-user portable database
    4.
    发明授权
    Method and system for providing a secure multi-user portable database 有权
    用于提供安全的多用户便携式数据库的方法和系统

    公开(公告)号:US07661146B2

    公开(公告)日:2010-02-09

    申请号:US11173133

    申请日:2005-07-01

    IPC分类号: G06F7/04 G06F17/30 H04N7/16

    摘要: A system and method for providing, managing, and accessing a multi-user secure portable database using secure memory cards is provided. The database has a secure portion for storing security keys and a non-secure portion for encrypted data files. Access to the encrypted data files is controlled by assigning access rights through an access control matrix to each encrypted data file according to a hierarchical structure of users. A user requesting access is identified in the hierarchy, associated with a key for allowing the requested access, and the requested access allowed to a file in accordance with the rights allocated through the access control matrix. A patient can selectively grant access to encrypted medical records on his card to a physician. Authentication of the owner/patient is preferably required. Other records required by emergency medical personnel are readable from the same card without requiring permission from the patient.

    摘要翻译: 提供了一种使用安全存储卡提供,管理和访问多用户安全便携式数据库的系统和方法。 数据库具有用于存储安全密钥的安全部分和用于加密的数据文件的非安全部分。 根据用户的层次结构,通过访问控制矩阵向每个加密数据文件分配访问权限来控制对加密数据文件的访问。 在层次结构中识别与用于允许所请求的访问的密钥相关联的请求访问的用户,以及根据通过访问控制矩阵分配的权限允许的所请求的访问文件。 患者可以选择性地向医师授予他卡上的加密医疗记录的访问权限。 所有者/患者的认证最好是需要的。 紧急医务人员所需的其他记录可从同一张卡片中读取,无需患者许可。