IP Library Patent Application 14080126
Patent Application
App. No. 14/080,126

COMPUTER SYSTEM FOR STORING AND RETRIEVAL OF ENCRYPTED DATA ITEMS USING A TABLET COMPUTER AND COMPUTER-IMPLEMENTED METHOD

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/080,126
Abstract

A computer system comprising multiple sets of client computers coupled to a database system via a network. Each client computer having installed thereon an application program that comprises client computer specific log-in information. The database system having a log-in component for logging-in the client computers, and being partitioned into multiple relational databases. Each one of the relational databases being assigned to one set of the sets of client computers. Each one of the relational databases storing encrypted data items. Each data item being encrypted with one of the user or user-group specific cryptographic keys. A key identifier of the cryptographic key with which one of the data items is encrypted being stored in the relational database as an attribute of the one of the encrypted data items. The log-in component comprising assignment information indicative of the assignment of the databases to the set of client computers.

Claims (73)

1 . A computer system comprising:

at least one set of client computers, each client computer having installed thereon an application program, the application program comprising client computer specific log-in information (Lij),

a database system being coupled to the set of client computers via a network, the database system having a log-in component for logging-in the client computers, the database system comprising at least one database, being assigned to the set of client computers, the database storing encrypted data items, the data items belonging to tuples, each tuple comprising an attributive data item that is a tuple identifier, a set of the tuples comprising electronic forms, each of the electronic forms being identified by an attributive data item that is a form identifier for identification of one of the tuples that comprises data items specifying that electronic form, each data item being encrypted with a user or user-group specific cryptographic key, the key identifier of the cryptographic key with which one of the data items is encrypted being stored in the database as an attribute of the one of the encrypted data items, each one of the application programs being operational to perform the following steps for establishing a database connection:

(a) establishing a session with the database system over the network,

(b) transmitting the client computer specific log-in information to the database system via the session,

(c) storing the key and the key identifier by the client computer for use of the key by the client computer and without transmitting the key to the database system;

(d) each one of the application programs being operational to perform the following steps for writing a data item:

entry of the data item into the client computer,

encrypting the data item with the key that has been received by the client computer,

generating a database insert command, the insert command comprising the encrypted data item and the key identifier of the key with which the data item has been encrypted as an attribute of the encrypted data item for storing the encrypted data item in the database system with the key identifier as an attribute,

transmitting the insert command via the session to the database system,

each one of the application programs being operational to perform the following steps for retrieval of a data item:

entry of a search criterion into the client computer,

generating a database query using the search criterion and the key identifier, the key identifier limiting the query to encrypted data items that have an attribute matching the key identifier,

in response to the query, receiving at least one encrypted data item matching the search criterion from the database system,

decrypting the encrypted data item using the cryptographic key,

wherein at least one of the client computers is a tablet computer (Cij+1) having a wireless communication interface for coupling the client computer to the database system, the application program of the tablet computer being operational to perform the steps of

receiving one of the tuple identifiers and one of the form identifiers,

retrieval of the electronic form that is identified by the form identifier by generating the database query using the form identifier as the search criterion,

rendering of the electronic form on the tablet computer for entry of data items into the electronic form,

writing the data items that have been entered into the electronic form by generating the database insert command, the database insert command comprising the tuple identifier as an additional attribute for storing the encrypted data items as a portion of the tuple that is identified by the tuple identifier in the database.

2 . The computer system of claim 1 , wherein the application program of the tablet computer is operational for receiving the tuple identifier and the form identifier from another one of the client computers.

3 . The computer system of claim 2 , wherein the tablet computer has a short range communication interface, such as an NFC interface, for establishing a local connection with another one of the client computers, the short range communication interface being adapted for receiving the tuple identifier and the form identifier.

4 . The computer system of claim 3 , the short range communication interface being adapted for receiving the key and the key identifier from the other one of the client computers.

5 . The computer system of claim 1 , the application programs of the client computers and the application program of the tablet computer being adapted for communicating at least the tuple identifier and the form identifier as data items via the database system.

6 . The computer system of claim 1 , the tuples comprising patient tuples, each patient tuple comprising data items constituting an electronic medical record of a patient, one of the electronic forms being adapted for entry of anamnesis data items of a patient.

7 . The computer system of claim 1 comprising multiple of the sets of client computers, the database system being partitioned into multiple databases, each one of the databases being assigned to one of the sets of client computers, the log-in component comprising assignment information indicative of the assignment of the databases to the set of client computers, the database system is operational to perform the steps of:

(i) receiving the client computer specific log-in information via the session by the log-in component of the database system,

(ii) determining one of the databases of the database system that is assigned to the client computer on which the application program is installed using the assignment information by the log-in component of the database system,

(iii) entering the database insert command or the query received from the application program via the session into the database that has been determined using the log-in information for processing the query by that database.

8 . The computer system of claim 1 , wherein the query is generated by encrypting the search criterion with the entered key by the application program.

9 . The computer system of claim 1 , wherein the received key is erased from a memory of the client computer if any one of the following events occurs:

the application program which has received the key is closed;

the user is logged out from the client computer by a client log-in component after a timeout condition has been fulfilled;

the user session with the application program is timed out or closed by the user;

switching off a power supply of the client computer,

exhausting the storage capacity of a battery that powers the client computer;

entry of a user command in response to which the key is erased.

10 . The computer system of claim 9 , wherein the received key is erased from the memory of the tablet computer if the tablet computer is moved outside the coverage area of a wireless access point for the wireless communication interface such that a communication link formed between the wireless communication interface and the wireless access point is interrupted.

11 . The computer system of claim 1 , wherein the tablet computer has a position sensor for sensing a position of the tablet computer, wherein the received key is erased from a memory of the tablet computer if the position sensor senses that the tablet computer is moved outside an access restricted environment.

12 . The computer system of claim 1 , a first sub-set of the client computers of at least some of the sets of client computers being located in a separate access restricted environment a second sub-set of the client computers being located outside the access restricted environment.

13 . The computer system of claim 1 , the application program comprising a configuration file, such as an INI file, a registry or an XML config file, that contains the client computer specific log-in information.

14 . The computer system of claim 1 , wherein the application program is operational to receive a user credential, and to enter the user credential into a predefined deterministic algorithm for processing the user credential, wherein the processing of the user credential by the predefined algorithm provides the key and the key identifier for storing in step c).

15 . The computer system of claim 1 , further comprising a set of security tokens for each one of the sets of client computers, each security token being assigned to one authorized user of a group of users that are authorized for use of one of the sets of client computers, the user or user-group specific cryptographic key and the key identifier of that cryptographic key being stored on each one of the security tokens, wherein the key and the key identifier are received from one of the security tokens by the client computer in step c).

16 . The computer system of claim 15 , each security token having assigned an asymmetric cryptographic key pair comprising a private key and a public key, at least the private key being stored in the security token, each security token comprising a processor for generating an electronic signature using the private key, and each one of the application programs comprising being operational for

checking the validity of an electronic signature using the public key,

sending a command for generating an electronic signature for the data item that has been entered into the client computer to the one of the security tokens, and

receiving the electronic signature of that data item from the one of the security tokens,

wherein the insert command further comprises the electronic signature of the data item for storing the electronic signature together with the encrypted data item in the determined database, each one of the application programs being further operational to receive the electronic signature of the encrypted data item matching the search criterion from the database system, determining the public key that belongs to the asymmetric cryptographic key pair of the one of the security tokens and checking the validity of the data item using the public key.

17 . The computer system of claim 1 , the security token having a communication interface to the client computer for entry of the key and the key identifier.

18 . The computer system of claim 17 , the communication interface of the security token being adapted for receiving a command from the client computer for generating the electronic signature, for returning the electronic signature to the client computer and for entry of the cryptographic key and its identifier that are stored on the security token into the client computer.

19 . The computer system of claim 1 , a digital certificate for the asymmetric cryptographic key pair being stored on the security token.

20 . The computer system of claim 1 , the client computer being a personal computer, a portable computer, such as a laptop computer, a smartphone, a medical instrument or a portable digital appliance and/or the security token being a chip card, in particular an electronic health card or a telecommunications chip card, such as a SIM or USIM card, a USB-token, or a radio-frequency tag.

21 . A computer implemented method being implemented by a computer system of claim 1 , the method comprising

establishing a database connection by:

establishing a session with the database system over the network,

transmitting the client computer specific log-in information to the database system via the session,

storing the key and the key identifier by the client computer for use of the key by the client computer and without transmitting the key to the database system;

writing a data item by:

entry of the data item into the client computer,

encrypting the data item with the key that has been received by the client computer,

generating a database insert command, the insert command comprising the encrypted data item and the key identifier of the key with which the data item has been encrypted as an attribute of the encrypted data item for storing the encrypted data item in the database system with the key identifier as an attribute,

transmitting the insert command via the session to the database system,

retrieval of a data item by:

entry of a search criterion into the client computer,

generating a database query using the search criterion and the key identifier, the key identifier limiting the query to encrypted data items that have an attribute matching the key identifier,

in response to the query, receiving at least one encrypted data item matching the search criterion from the database system,

decrypting the encrypted data item using the cryptographic key,

wherein the application program of the tablet computer tablet computer performs the additional steps of

receiving one of the tuple identifiers and one of the form identifiers,

retrieval of the electronic form that is identified by the form identifier by generating the database query using the form identifier as the search criterion,

rendering of the electronic form on the tablet computer for entry of data items into the electronic form,

writing the data items that have been entered into the electronic form by generating the database insert command, the database insert command comprising the tuple identifier as an additional attribute for storing the encrypted data items as a portion of the tuple that is identified by the tuple identifier in the database.

Assignments (2)
CHANGE OF NAME Recorded Jul 1, 2016
From: COMPUGROUP MEDICAL AG
To: COMPUGROUP MEDICAL SE
Reel/Frame 039249/0854 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2013
From: SPALKA, ADRIAN, DR.; LEHNHARDT, JAN; RHO, TOBIAS, DR.
To: COMPUGROUP MEDICAL AG
Reel/Frame 031747/0360 →