IP Library › Granted Patent US 11,777,940
Granted Patent B2
US 11,777,940 · App. 16/960,664 · Granted Oct 3, 2023

Storing and accessing medical datasets on the blockchain

Inventors: Florian Hager (Erlangen, DE); Christoph Pedain (Munich, DE); Benedikt Krueger (Ebensfeld, DE)
Assignee: Siemens Healthcare GmbH
H04L63/102G06F16/9035G16H10/60H04L63/0823H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,940
App. No.
16/960,664
Granted
Oct 3, 2023
Kind
B2
Abstract

Methods are disclosed for setting up a microservice, enhancing a ledger of microservices with a further microservice and accessing medical datasets stored in a microservice. The microservice contains the medical dataset in an encrypted form. The microservice includes an access logic based on accessing entity information. The access logic defines access conditions to the medical dataset and is configured to grant access to the medical dataset upon the access conditions being fulfilled.

Claims (49)

1. A method for setting up a microservice, the method comprising:

receiving a medical dataset;

receiving accessing entity information describing an accessing entity, the accessing entity information including access credentials related to the microservice, and the access credentials including an access certificate relating to ownership of a public key; and

setting up the microservice, based on the accessing entity information, by

encrypting the medical dataset using the public key,

storing the encrypted medical dataset in the microservice, and

defining access conditions to the medical dataset based on the access credentials such that the medical dataset can be accessed when the access conditions are fulfilled.

2. The method of claim 1 , wherein the medical dataset relates to a patient, and wherein the accessing entity is different from the patient.

3. The method of claim 1 , wherein the accessing entity information includes access credentials stored related to the microservice, wherein the the access conditions are based on the access credentials, and wherein the access conditions are fulfilled upon the access credentials being related to a requesting entity requesting access to the medical dataset.

4. The method of claim 3 , wherein the access certificate belongs to the accessing entity and wherein the access certificate is related to the requesting entity upon an identity of the requesting entity being verified by the access certificate.

5. The method of claim 3 , wherein the access certificate belongs to the microservice and is derived from a certificate belonging to the accessing entity, and wherein the access certificate is related to the requesting entity upon an identity of the requesting entity being verified by the certificate belonging to the accessing entity.

6. The method of claim 1 , further comprising:

determining that a certificate belongs to an entity in response to the entity having access to a private key corresponding with the public key.

7. A method for accessing a medical dataset included in a microservice in an encrypted form, the method comprising:

receiving an access request to the medical dataset by a requesting entity, the access request including accessing entity information describing the accessing entity, the accessing entity information including access credentials, and the access credentials including an access certificate relating to ownership of a public key;

determining whether access conditions are met according to an access logic and the accessing entity information, the access logic defining access conditions to the medical dataset;

performing a check upon the access conditions being met; and

granting access to the medical dataset, to the requesting entity, depending on a result of the check performed.

8. The method of claim 7 , wherein the access logic defines the access conditions based on the access credentials, and wherein the result of the check performed is positive, granting the requesting entity access to the medical dataset, upon the access credentials being related to request credentials related to the requesting entity.

9. The method of claim 8 , wherein the request credentials are a request certificate, and wherein the result of the check performed is positive, granting the requesting entity access to the medical dataset, upon the access certificate being related to the request certificate.

10. The method of claim 9 , wherein the access certificate belongs to the accessing entity and the access certificate is related to the request certificate upon the request certificate being derived from the access certificate.

11. The method of claim 9 , wherein the access certificate belongs to the microservice and is directly authorized by a certificate belonging to the accessing entity, and wherein the access certificate is related to the request certificate upon the request certificate being derived from the certificate belonging to the accessing entity.

12. The method of claim 9 , wherein the access certificate and the request certificate are documented in an access ledger, and wherein the access ledger regulates relationships between certificates.

13. The method of claim 8 , wherein the result of the check performed is positive upon the request credentials matching the access credentials.

14. A method for accessing information stored in a digital twin, the method comprising:

receiving an access request requesting access to a subset of information stored in the digital twin by a requesting entity, the digital twin including multiple microservices storing information about a real-world source and a profile assigned to the digital twin, the profile defining access to the subset of the information stored in the digital twin via accessing entity information including an access certificate relating to ownership of a public key;

performing a check upon the requesting entity being subject to the profile; and

granting access to the subset of information in the digital twin depending on a result of the check performed, wherein

the information about the real-world source is a medical dataset, and

the profile is configurable by the real-world source.

15. The method of claim 14 , wherein the information is contained by the multiple microservices in encrypted form and the subset of the information is contained by a subset of the multiple microservices.

16. The method of claim 15 , wherein the multiple microservices include access logic for the information contained by the multiple microservices, and wherein the profile defines that access logic of the subset of the multiple microservices grant the requesting entity access to the subset of information upon the requesting entity being subject to the profile.

17. The method of claim 16 , wherein the access logic of the subset of the multiple microservices are based on the accessing entity information describing a same accessing entity.

18. The method of claim 14 , wherein the granting access to the subset of information comprises:

receiving an access request to the medical dataset by the requesting entity;

performing a check upon access conditions being met by the requesting entity; and

granting access to the medical dataset, to the requesting entity, depending on a result of the check performed.

19. A non-transitory computer readable medium storing a computer program, the computer program being loadable into a memory of a computer system and including program code sections that, when executed, cause the computer system to:

receive a medical dataset;

receive accessing entity information describing an accessing entity, the accessing entity information including access credentials related to a microservice, and the access credentials including an access certificate relating to ownership of a public key; and

set up the microservice, based on the accessing entity information, by

encrypting the medical dataset using the public key,

storing the encrypted medical dataset in the microservice, and

defining access conditions to the medical dataset based on the access credentials such that the medical dataset can be accessed when the access conditions are fulfilled.

20. A non-transitory computer readable medium storing a computer program, the computer program being loadable into a memory of a computer system and including program code sections that, when executed, cause the computer system to:

receive an access request to a medical dataset by a requesting entity, the access request including accessing entity information describing the accessing entity, the accessing entity information including access credentials, and the access credentials including an access certificate relating to ownership of a public key;

determine whether the access conditions are met according to an access logic and the accessing entity information, the access logic defining access conditions to the medical dataset;

perform a check upon the access conditions being met; and

grant access to the medical dataset, to the requesting entity, depending on a result of the check performed.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2023
From: SIEMENS HEALTHCARE GMBH
To: SIEMENS HEALTHINEERS AG
Reel/Frame 066267/0346 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2020
From: PEDAIN, CHRISTOPH; HAGER, FLORIAN; KRUEGER, BENEDIKT
To: SIEMENS HEALTHCARE GMBH
Reel/Frame 054103/0503 →
Priority Claims (1)
EP 18151466 · Jan 12, 2018 · regional
Continuity (1)
Related Publication 20200358782A1 · Nov 12, 2020