IP Library Granted Patent US 7,430,671
Granted Patent B2
US 7,430,671 · App. 10/813,358 · Granted Sep 30, 2008

Systems and methods for preserving confidentiality of sensitive information in a point-of-care communications environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,430,671
App. No.
10/813,358
Granted
Sep 30, 2008
Kind
B2
Abstract

A data processing apparatus comprises a memory store; a data bus connected to the memory store, the data bus being adapted for transporting data to and from the memory store; a processing entity operative to release read and write commands towards the memory store, the write command being accompanied by first data intended to be written to the memory store; and an encryption module communicatively coupled to the processing entity and to the data bus. Upon the processing entity releasing a write command accompanied by said first data, the encryption module encrypts, in accordance with an encryption key, said first data and send an encrypted version of said first data onto the data bus for writing into the memory store. The reverse operation is performed upon the processing entity releasing a read command.

Claims (60)

1. An end user device for communication with a server, comprising:

a control entity operative to support a session with the server for an authenticated user;

a memory store operative to store sensitive information during the session;

a user interface for interfacing with the authenticated user; and

a network interface for interfacing with the server;

the control entity being further operative to (i) apply a policy based on stimuli received via the user interface and the network interface to determine whether confidentiality of the sensitive information stored in the memory store is to be preserved and (ii) responsive to determining that confidentiality of the sensitive information stored in the memory store is to be preserved, take an action to preserve confidentiality of the sensitive information stored in the memory store;

wherein said stimuli comprise user commands received via the user interface and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting a user command to terminate the session;

wherein said stimuli comprise user commands received via the user interface and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting a user command to suspend the session;

wherein said stimuli comprise user commands received via the user interface and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting a user command to authenticate a new user other than the authenticated user;

wherein said stimuli comprise network commands received via the network interface and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting a network command to terminate the session;

wherein said stimuli comprise network commands received via the network interface and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting a network command to suspend the session;

wherein said stimuli comprise pilot messages received via the network interface and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting a prolonged absence of pilot messages received from the network interface.

2. The end user device defined in claim 1 , further comprising an RF-ID detector operative to detecting an identification code of a potential user proximate to the end user device, the RF-ID detector further operative to provide a detected identification code to the control entity.

3. The end user device defined in claim 2 , the control entity being adapted to effect a comparison of the detected identification code to an identification code associated with the authenticated user.

4. The end user device defined in claim 3 , the control entity being adapted to estimate a distance between the authenticated user and the end user device based on the comparison.

5. The end user device defined in claim 4 , wherein said stimuli comprise the distance estimated by the control entity and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting that said distance exceeds a predetermined threshold.

6. The end user device defined in claim 4 , wherein said stimuli comprise the distance estimated by the control entity and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting that said distance continuously exceeds a predetermined threshold for a predetermined amount of time.

7. The end user device defined in claim 4 , wherein said stimuli comprise the distance estimated by the control entity and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting that an integral of said distance over time exceeds a predetermined threshold.

8. The end user device defined in claim 7 , the control entity being adapted to receive an indication of a distance between the authenticated user and the end user device.

9. The end user device defined in claim 8 , wherein said stimuli comprise said distance and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting that said distance exceeds a predetermined threshold.

10. The end user device defined in claim 8 , wherein said stimuli comprise the distance and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting that said distance continuously exceeds a predetermined threshold for a predetermined amount of time.

11. The end user device defined in claim 8 , wherein said stimuli comprise the distance and wherein determining that confidentiality of the sensitive information stored in the memory store is to be preserved comprises detecting that an integral of said distance over time exceeds a predetermined threshold.

12. The end user device defined in claim 1 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store comprises rendering the sensitive information stored in the memory store inaccessible to potential users of the end user device other than the authenticated user.

13. The end user device defined in claim 1 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store comprises erasing the sensitive information from the memory store.

14. The end user device defined in claim 1 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store comprises scrambling the sensitive information in the memory store.

15. The end user device defined in claim 1 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store comprises disabling the user interface.

16. The end user device defined in claim 1 , further comprising

a data bus connected to the memory store, the data bus being adapted for transporting data to and from the memory store;

an encryption module communicatively coupled to the control entity and to the data bus;

the control entity being further operative to release read and write commands towards the memory store, the write command being accompanied by first data intended to be written to the memory store;

upon the control entity releasing a write command accompanied by said first data, the encryption module being operative to encrypt, in accordance with an encryption key, said first data and send an encrypted version of said first data onto the data bus for writing into the memory store;

upon the control entity releasing a read command, the encryption module being operative to decrypt, in accordance with a decryption key, an encrypted version of second data received from the memory store via the data bus and provide said second data to the control entity.

17. The end user device defined in claim 16 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store comprises changing the decryption key.

18. The end user device defined in claim 16 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store comprises deleting the decryption key.

19. The end user device defined in claim 16 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store comprises causing the encryption module to use a new decryption key different from the previous decryption key.

20. The end user device defined in claim 19 , wherein the control entity being operative to take an action to preserve confidentiality of the sensitive information stored in the memory store further comprises storing the previous decryption key prior to causing the encryption module to use the new decryption key.

21. The end user device defined in claim 20 , the control entity further operative to (iii) determine whether confidentiality of the sensitive information stored in the memory store no longer needs to be preserved and (iv) responsive to determining that confidentiality of the sensitive information stored in the memory store no longer needs to be preserved, cause the encryption module to use said previous decryption key.

22. The end user device defined in claim 1 , the control entity being further operative to (iii) determine whether confidentiality of the sensitive information stored in the memory store no longer needs to be preserved and (iv) responsive to determining that confidentiality of the sensitive information stored in the memory store no longer needs to be preserved, take an action to reverse the action previously taken to preserve confidentiality of the sensitive information stored in the memory store.

23. The end user device defined in claim 22 , wherein the control entity being operative to determine whether confidentiality of the sensitive information stored in the memory store no longer needs to be preserved comprises the control entity being operative to apply a policy based on stimuli received via the user interface and the network interface.

24. The end user device defined in claim 23 , wherein said stimuli comprise user commands received via the user interface arid wherein determining that confidentiality of the sensitive information stored in the memory store no longer needs to be preserved comprises detecting a host command to unsuspend a suspended session.

25. The end user device defined in claim 1 being a mobile wireless device.

26. The end user defined in claim 1 , further comprising a label indicative of an inability to function outside a predetermined location.

27. A method, comprising:

establishing a healthcare session with an end user device servicing an authenticated user;

providing sensitive healthcare information to the end user device for storage thereon during the healthcare session;

detecting existence of a requirement to preserve confidentiality of the sensitive healthcare information; and

responsive to the detecting, sending a message to the end user device for causing the end user device to preserve the confidentiality of the sensitive healthcare information;

wherein detecting existence of a requirement to preserve confidentiality of the sensitive healthcare information comprises detecting a distance between the authenticated user and the end user device and determining that the distance exceeds a predetermined threshold.

28. A method, comprising:

establishing a healthcare session with an end user device servicing an authenticated user;

providing sensitive healthcare information to the end user device for storage thereon during the healthcare session;

detecting existence of a requirement to preserve confidentiality of the sensitive healthcare information; and

responsive to the detecting, sending a message to the end user device for causing the end user device to preserve the confidentiality of the sensitive healthcare information;

wherein detecting existence of a requirement to preserve confidentiality of the sensitive healthcare information comprises detecting a distance between the authenticated user and the end user device and determining that the distance continuously exceeds a predetermined threshold for a predetermined period of time.

29. A method, comprising:

establishing a healthcare session with an end user device servicing an authenticated user;

providing sensitive healthcare information to the end user device for storage thereon during the healthcare session;

detecting existence of a requirement to preserve confidentiality of the sensitive healthcare information; and

responsive to the detecting, sending a message to the end user device for causing the end user device to preserve the confidentiality of the sensitive healthcare information;

wherein detecting existence of a requirement to preserve confidentiality of the sensitive healthcare information comprises detecting a distance between the authenticated user and the end user device and determining that an integral of the distance over time exceeds a predetermined threshold.

Assignments (17)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.
Reel/Frame 045045/0564 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 023892/0500 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.
Reel/Frame 044891/0564 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →