System and method for the anonymisation of sensitive personal data and method of obtaining such data
Abstract
The invention relates to a system for the management of sensitive personal data (DD_A), comprising two databases (45, 35) which are hosted by two independent sub-systems (40, 30). According to the invention, one of the aforementioned databases associates data (ID_A) identifying a person (A) with a common key (IDC_A) which is shared with the second database which in turn associates the common key (IDC_A) with the sensitive personal data (DD_A) of said person (A). The invention also relates to the use of said management system for the anonymisation of medical data.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
18 claims: 1 independent, 17 dependent
- 1REVENDICATIONS 1. Système de gestion de données personnelles sensibles (DD_A) comportant :-un premier sous-système informatique (40) comportant : - des moyens (41, 42, 43) de génération d'une clef commune (IDC_A) à partir de données d'identification (ID_A) d'une personne (A) ;- une base de données privée (45) qui associe ladite clef commune (IDC_A) auxdites données d'identification (ID_A) ;et - un deuxième sous-système informatique (30) comportant : - des moyens (38) d'obtention de ladite clef commune (IDC_A) ;- des moyens de génération d'un nombre aléatoire (NA) à partir de ladite clef commune (IDC_A) ;- des moyens (38) de réception d'un message d'enregistrement (M3) comportant au moins une donnée personnelle sensible (DD_A) de ladite personne (A) et ledit nombre aléatoire (NA) ;et - des moyens (31, 32, 33) pour mémoriser, dans une deuxième base de données (35), ladite donnée personnelle (DD_A) en association avec ledit nombre aléatoire (NA) et ladite clef commune (IDC_A).
- 2Système de gestion selon la revendication 1, caractérisé en ce que le deuxième sous-système informatique (30) comporte :- des moyens (31, 32, 33) pour obtenir au moins une donnée réduite (DR_A) à partir d'une donnée sensible (DD_A) ;et - des moyens pour envoyer, audit premier sous-système informatique (40), un message (M6) comportant ladite donnée réduite (DR_A) et la clef commune (IDC_A) associées à ladite donnée personnelle sensible (DD_A) dans la deuxième base de données (35),
- 3Système de gestion selon la revendication 1 ou 2, caractérisé en ce que le deuxième sous-système informatique (30) comporte des moyens (31, 32, 33) de traitement statistique desdites données sensibles (DD_A) mémorisées dans la deuxième base de données (35).
- 4Système de gestion selon l'une quelconque des revendications 1 à 3, caractérisé en ce que le deuxième sous-système informatique (30) comporte des moyens de création d'une paire de clef privée/publique de chiffrement (KPRIV_C, KPUB_C) ; système de gestion dans lequel ladite personne (A) utilise un support numérique personnel (10) pour calculer des données chiffrées (DC) à partir de ladite donnée personnelle sensible (DD_A), dudit nombre aléatoire (NA) et de ladite clef publique de chiffrement (KPUB_C), lesdites données chiffrées (DC) étant adaptées à être envoyées audit deuxième sous-système informatique (30) via un lecteur (20) de ce support (10) ; - ledit deuxième sous-système informatique (30) comportant :- des moyens (38) de réception desdites données chiffrées (DC) en provenance dudit lecteur (20) ;et - des moyens (31, 32, 33) pour déchiffrer, avec ladite clef privée de chiffrement (KPRIV_C), lesdites données chiffrées (DC), et obtenir ledit nombre aléatoire (NA) et ladite donnée personnelle (DD_A) en vue de leur mémorisation dans ladite deuxième base de données (35).
- 5Système de gestion selon la revendication 4, caractérisé en ce que ledit support (10) est adapté à obtenir lesdites données sensibles (DD_A) en provenance dudit lecteur (20).
- 6Système de gestion selon l'une quelconque des revendications 1 à 5, caractérisé en ce que :- ledit premier sous-système informatique (40) comporte : - des moyens (48) de réception d'une requête (RQl) pour obtenir une donnée personnelle sensible particulière (DD_A1) d'une personne (A) ;et - des moyens (48) pour envoyer, au deuxième sous-système informatique (30) une requête (RQ2) d'authentification de ladite personne (A), ladite requête d'authentification (RQ2) comportant un identifiant (NF) de ladite donnée personnelle sensible particulière (DD_A1) et la clef commune (IDC_A) générée à partir des données d'identification (ID_A) de ladite personne (A) ;et en ce que - ledit deuxième sous-système informatique (30) comporte : - des moyens (38) de réception de ladite requête d'authentification (RQ2) ;- des moyens (31, 32, 33) d'authentification de ladite personne (A) ;et - des moyens (38) pour envoyer ladite donnée personnelle sensible particulière (DD_A1) audit premier sous-système informatique (40) en cas de succès de ladite authentification.
- 7Système de gestion selon l'une quelconque des revendications 1 à 6, dans lequel lesdites données personnelles sensibles sont constituées par :- des données médicales détaillées (DD_A) relatives à une prestation médicale effectuée pour un patient (A), ces données médicales détaillées (DD_A) étant associées à des données médicales réduites (DR_A) ;et - des informations complémentaires comportant un montant (MP) de ladite prestation.
- 8Système de gestion selon la revendication 7, caractérisé en ce que :- la deuxième base de données (35) mémorise, en association avec ladite clef commune (IDC_A) générée pour un patient (A), des informations (DT_A) représentatives des droits (DT_A) de ce patient (A) ;en ce que : - le deuxième sous-système informatique (30) comporte : - des moyens (31, 32, 33) pour calculer un montant de remboursement (MR) à partir des droits (DT_A) de ce patient (A), et du montant de la prestation (MP) reçu sous forme de données chiffrées (DC) en provenance du lecteur (20) d'un professionnel de santé adapté à lire le support numérique personnel (10) dudit patient (A) ;et - des moyens (38) pour envoyer ledit montant de remboursement (MR) à destination dudit lecteur (20) ou du premier sous- système informatique (40).
- 9Procédé de gestion de données personnelles sensibles (DD_A) susceptible d'être mis en œuvre par un deuxième sous-système informatique (30) d'un système de gestion selon l'une quelconque des revendications 1 à 8, comportant :- une étape (ElO) d'obtention d'une clef commune (IDC_A) ;- une étape (E12) de génération d'un nombre aléatoire (NA) à partir de ladite clef commune (IDC_A) ;- une étape (E18) de réception d'un message d'enregistrement (M3) comportant au moins une donnée personnelle sensible (DD_A) de ladite personne (A) et ledit nombre aléatoire (NA) ;et - une étape (E22) de mémorisation, dans une deuxième base de données (35) dudit deuxième sous-système informatique (30), de ladite donnée personnelle sensible (DD_A) en association avec ledit nombre aléatoire (NA) et ladite clef commune (IDC_A).
- 10Procédé de gestion selon la revendication 9, caractérisé en ce qu'il comporte :- une étape (E24) d'obtention de données réduites (DR_A) à partir d'une donnée sensible (DD_A) ;et - une étape (E26) d'envoi, à destination d'un premier sous-système informatique (40) d'un système de gestion selon l'une quelconque des revendications 1 à 8, d'un message (M6) comportant ladite donnée réduite (DR_A) et la clef commune (IDC_A) associée à ladite donnée sensible (DD_A) dans la deuxième base de données (35).
- 11Procédé de gestion selon la revendication 9 ou 10, caractérisé en ce qu'il comporte en outre :- une étape (E18) de réception de données chiffrées (DC), calculées à partir d'une donnée personnelle sensible (DD_A), d'un nombre aléatoire (NA) et d'une clef publique de chiffrement (KPUB_C) ;- une étape (E20) de déchiffrement desdites données chiffrées (DC) avec une clef privée de chiffrement (KPRIV_C) associée à ladite clef publique (KPUELC), pour obtenir ledit nombre aléatoire (NA) et ladite donnée personnelle (DD_A) en vue de leur mémorisation dans ladite deuxième base de données (35).
- 12Procédé de gestion selon l'une quelconque des revendications 9 à 11, dans lequel lesdites données personnelles sensibles sont constituées par :- des données médicales détaillées (DD_A) relatives à une prestation médicale effectuée pour un patient (A), ces données médicales détaillées (DD_A) étant associées à des données médicales réduites (DR_A) ;et - des données complémentaires comportant un montant (MP) de ladite prestation ;et dans lequel la deuxième base de données (35) mémorise (E14), en association avec ladite clef commune (IDC_A) générée pour un patient (A), des informations (DT_A) représentatives des droits (DT_A) de ce patient (A), ce procédé étant caractérisé en ce qu'il comporte ;- une étape (E28) de calcul d'un montant de remboursement (MR) à partir des droits (DT_A) de ce patient (A), et du montant de la prestation (MP) reçu sous forme de données chiffrées (DC) en provenance d'un lecteur (20) d'un support numérique personnel (10) dudit patient (A) ;et -une étape (E30) d'envoi dudit montant de remboursement (MR) à destination dudit lecteur (20), ou du premier sous-système informatique (40).
- 13Procédé de gestion selon l'une quelconque des revendications 10 à 12, caractérisé en ce qu'il comporte :- une étape (E32) de réception d'une requête d'authentification (RQ2), en provenance dudit premier sous-système informatique (40), ladite requête d'authentification (RQ2) comportant un identifiant (NF) de ladite donnée personnelle sensible particulière (DD_A1) et une clef commune (IDC_A) générée pour une personne (A) ;- une étape (E34) d'authentification de ladite personne (A) ;et - une étape (E36) d'envoi de ladite donnée personnelle sensible particulière (DD_A1) audit premier sous-système informatique (40) en cas de succès de ladite authentification.
- 14Programme d'ordinateur sur un support d'informations, ledit programme étant susceptible d'être mis en œuvre par un deuxième sous- système informatique (30) d'un système de gestion selon l'une quelconque des revendications 1 à 8, ce programme comportant des instructions adaptées à la mise en œuvre d'un procédé de gestion de données personnelles sensibles selon l'une quelconque des revendications 9 à 13.
- 15Support d'informations lisible par un deuxième sous-système informatique (30) d'un système de gestion selon l'une quelconque des revendications 1 à 8, caractérisé en ce qu'il comporte des instructions d'un programme d'ordinateur selon la revendication 14.
- 16Procédé d'obtention de données personnelles sensibles (DD_A) susceptible d'être mis en œuvre dans un premier sous-système informatique (40) d'un système de gestion selon l'une quelconque des revendications 1 à 8, comportant :- une étape (FlO) de réception d'une requête (RQl) pour obtenir une donnée personnelle sensible particulière (DD_A1) d'une personne (A) ;et - une étape (F14) d'envoi, à un deuxième sous-système informatique (30) d'un système de gestion selon l'une quelconque des revendications 1 à 8, d'une requête (RQ2) d'authentification de ladite personne (A), ladite requête (RQ2) d'authentification comportant un identifiant (NF) de ladite donnée personnelle sensible particulière (DD_A1) et une clef commune (IDC_A) générée à partir des données d'identification (ID_A) de ladite personne (A) ;- une étape (F14) de réception de ladite donnée personnelle sensible particulière (DD_A1) en provenance dudit deuxième sous-système informatique (30) en cas de succès de ladite authentification.
- 17Programme d'ordinateur sur un support d'informations, ledit programme étant susceptible d'être mis en œuvre par un premier sous- système informatique (30) d'un système de gestion selon l'une quelconque des revendications 1 à 8, ce programme comportant des instructions adaptées à la mise en œuvre d'un procédé d'obtention de données personnelles sensibles selon la revendication 16.
- 18Support d'informations lisible par un premier sous-système informatique (40) d'un système de gestion selon l'une quelconque des revendications 1 à 8, caractérisé en ce qu'il comporte des instructions d'un programme d'ordinateur selon la revendication 17.
Independent claims18
127 paragraphs, as filed
0001System and method for anonymizing sensitive personal data and method for obtaining such data.
0002Invention background
0003The present invention relates to the general field of data anonymization.
0004The invention can be used, preferably, but not limited to, in the health field, for the anonymization of a patient's medical data.
0005In this area, complementary insurers have been wanting for several years to access health data contained in electronic care sheets that only compulsory insurers today receive.
0006It is easy to understand that this subject touches on sensitive points such as respect for individual freedoms and the preservation of medical confidentiality.
0007For several years, microcircuit cards (smart cards) have been used in the health field.
0008In France, for example, the healthcare professional (doctor, pharmacist,.,.) Uses a professional microcircuit card which has identification, signature and encryption functions allowing the transfer of electronic treatment sheets. The SESAME VITAL card for insured persons is currently only used for the identification of insured persons with healthcare professionals and the storage of their rights. It is well accepted by the insured because it speeds up the reimbursement procedure.
0009However, the SESAME VITALE card does not allow additional insurers to electronically process detailed medical data, for example to perform statistical analyzes on the entire insured population.
0010The document EP 1 099 996 describes a system for managing, anonymously, sensitive medical data of patients. This system comprises a first subsystem which associates, for each patient, the identification data of this patient with an identifier (scrambled ID) generated from its identification data.
0011The system according to EP 1 099 996 also includes a database which stores, for each patient, the sensitive medical data of this patient in association with his identifier, this data being received from data providers.
0012This system has a major drawback in that the same identifier is shared by the data providers, the first subsystem and the database.
0013Consequently, the system according to EP 1 099 996 is not strictly speaking an anonymous system, the first subsystem having the possibility, if it were able (lawfully or fraudulently) to access said database, to obtain all sensitive medical data of an identified patient.
0014Subject and summary of the invention
0015The invention aims to meet the demand of additional insurers to enable them to manage detailed data on medical services while respecting the strict rules in terms of protection of private life and medical confidentiality. The principle adopted is the anonymization of patient medical data, that is to say the transmission of detailed data from the healthcare professional to a third party in a non-nominative form. This principle is recommended in the Babusiaux report http://www.sante.gouv.fr/htm/actu/babusiaux/sommaire.htm.
0016Thus, and according to a first aspect, the invention relates to a system for managing sensitive personal data comprising:
0017- a first computer subsystem comprising: - means for generating a common key from identification data of a person;
0018- a private database which associates the common key with identification data; and
0019- a second computer subsystem comprising: - means for obtaining the common key; - means for generating a random number from the common key;
0020- Means for receiving a registration message comprising at least one sensitive datum of this person and the random number; and
0021- Means for storing, in a second database, the personal data in association with the random number and the common key.
0022This management system allows strict compliance with the anonymization constraint. Indeed, the first subsystem, which has the real identity of the person in the form of identification data but not the random number associated with this person, does not store the sensitive personal data of this person.
0023And the second subsystem, which memorizes the sensitive data of this person, cannot link this sensitive data to a person, because it does not memorize the real identity of this person, but only the common key shared with the first sub -system.
0024Consequently, even if the first subsystem obtained, by accident or dishonesty, the registration message intended for the second subsystem, it would be unable to identify the patient to whom the sensitive data contained in this message belong. , because the first subsystem only knows the common key and not the random number.
0025In a particular embodiment of the invention, the random number is used, as described later, to allow a person having a personal digital medium (for example a micro-circuit card) on which this random number is stored, to authenticate with the second subsystem.
0026In the health sector, the first subsystem can be implemented by complementary insurance or a mutual health insurance. It manages the contracts of the people, as well as the payment of the medical services but, according to the current law, it cannot know the detailed data of the services which they received.
0027The second subsystem, which acts as a provider of the first subsystem, can perform statistical processing on the detailed data. But it is not able to link this data to a person.
0028As we will see later, apart from the patient and the healthcare professional, no one should be able to know the detailed data of a particular patient, that is to say both his identity and the services provided. 'he received from the health professional.
0029In a preferred embodiment, the second subsystem of the management system according to the invention comprises:
0030- Means for obtaining at least one reduced datum from a sensitive datum; and
0031- Means for sending, to the first computer subsystem, a message comprising the reduced data and the common key associated with the sensitive personal data in the second database.
0032In this alternative embodiment, it will be considered that a sensitive detailed datum includes or is associated with a single reduced datum which is not sensitive.
0033It can therefore be stored in the private database of the first subsystem.
0034In the health field, the terms "detailed data" and "reduced data" are perfectly known.
0035The reduced data can in particular be used by the first subsystem which manages patient contracts. The detailed data can be associated with additional data including for example the amount of a medical service. To enhance the security of transactions, the personal data management system according to the invention comprises, in a particular embodiment, means for creating a pair of private / public signature keys, the public signature key, included in a certificate, being stored in the second subsystem, and the private signature key being stored in the patient's digital medium.
0036Preferably, the second subsystem includes means for creating a pair of private / public encryption keys.
0037Thus, when sensitive personal data of a patient must be transmitted to the second subsystem, this data is first of all encrypted by the digital medium of this person, using the public encryption key.
0038The encrypted data is then received by the second subsystem from a reader of this medium. On receipt of this data, the second subsystem decrypts this encrypted data with the previously stored private encryption key in order to obtain the random number and the sensitive personal data of this person. It then stores, in its second database, this personal data in association with the random number. In a preferred embodiment in which the personal digital support of the patient is a microcircuit card, the creation of the private / public signature key pair, and of a certificate linked to the aforementioned public key and common key is carried out by an insider.
0039As a variant, the creation of this pair of keys is carried out by the digital medium itself, which sends the public key to the second subsystem for creation of the certificate. This method further enhances security since the private key never leaves this medium.
0040In any case, the certificate, the private key and the random number are written in a protected area of this medium. In known manner, this digital medium comprises a signature algorithm as well as an encryption algorithm, preferably slightly asymmetrical. If necessary, it includes a pseudo-random number generator.
0041In a preferred embodiment, the sensitive data management system according to the invention can also be used to lift the anonymity of a particular sensitive personal data, at the request of the person concerned.
0042To this end, the first subsystem includes means for receiving a request for obtaining a particular sensitive personal data of a person.
0043Of course, the first subsystem should not be able to obtain other sensitive personal data from that person from the second subsystem.
0044Consequently, the invention provides that the first subsystem sends to the second subsystem a request for authentication of the person concerned, this request comprising an identifier of the particular sensitive personal data sought and the common key generated from the data. identification of this person.
0045In the context of a health system, the identifier can be an invoice number linked to a particular service. The second subsystem comprises means for receiving the authentication request, means for authenticating the person, and means for sending the particular sensitive personal data sought to the first subsystem in the event of authentication success. . This particular characteristic can be used, for example in the event of a complaint by a person.
0046The procedure for authenticating the person by the second subsystem is not part of the invention, and will not be detailed here. When the management system is used in the health field, the sensitive personal data of patients is received by the second subsystem from the reader of the digital support of the patient, physically installed at the health professional.
0047This sensitive data includes in particular the amount of the service concerned.
0048In this variant, preferably preferably, the second subsystem includes means for calculating a reimbursement amount from the amount of the service and the rights of the patient stored in the second database. This second subsystem includes means for sending this reimbursement amount to the reader (for the attention of the healthcare professional) or to the first computer subsystem.
0049Correlatively, the invention also relates to a method for managing sensitive personal data capable of being implemented by the second computer subsystem of a management system as defined above, comprising:
0050- a step of obtaining a common key;
0051- a step of generating a random number from the common key; a step of receiving a registration message comprising at least one sensitive personal data of the person and the random number; and
0052a step of memorizing, in a second database of said second computer subsystem, sensitive personal data, in association with the random number and the common key.
0053The invention also relates to a method for obtaining sensitive personal data capable of being implemented in a first subsystem of a management system as defined above, comprising:
0054- a step of receiving a request to obtain a particular sensitive personal data of a person; and
0055a step of sending, to a second computer subsystem of a management system as defined above, a request for authentication of the person, the authentication request comprising an identifier of the personal data particular sensitive and a common key generated from the person's identification data;
0056- a step of receiving the particular sensitive personal data coming from the second subsystem in the event of successful authentication.
0057The particular advantages of the management method and of the obtaining method according to the invention are identical to those of the personal data management system mentioned above and will not be repeated here. According to a preferred implementation, the different steps of the management method and / or of the obtaining method are determined by instructions from computer programs.
0058Consequently, the invention also relates to a computer program on an information medium, the program being capable of being implemented by a second subsystem of a management system as defined above, this program comprising instructions adapted to the implementation of a process for managing sensitive personal data as defined above.
0059And the invention also relates to a computer program on an information medium, the program being capable of being implemented by a first subsystem of a management system as defined above, this program comprising instructions adapted to the implementation of a process for obtaining sensitive personal data as defined above.
0060These programs can use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.
0061The invention also relates to an information medium readable by a second subsystem of a management system as defined above, characterized in that it comprises instructions of a computer program as defined above. -above.
0062The invention also relates to an information medium readable by a first subsystem of a management system as defined above, characterized in that it comprises instructions of a computer program as defined above. -above.
0063These information carriers can be any entity or device capable of storing the program. For example, the support may include a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or else a magnetic recording means, for example a floppy disk or a disc. hard.
0064On the other hand, these information carriers can be a transmissible medium such as an electrical or optical signal, which can be routed via an electrical or optical cable, by radio or by other means. The programs according to the invention can in particular be downloaded from a network, and in particular from a network of the Internet type.
0065Alternatively, the information carriers can be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the process in question.
0066Brief description of the drawings
0067Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an embodiment thereof devoid of any limiting character. In the figures:
0068- Figure 1 schematically shows a personal data management system according to the invention in a preferred embodiment;
0069FIG. 2 represents, in the form of a flowchart, the main steps of a method for managing sensitive personal data according to the invention in a preferred embodiment; and
0070- Figure 3 shows, in the form of a flowchart, the main steps of a method for obtaining sensitive personal data according to the invention in a preferred embodiment.
0071Detailed description of an embodiment
0072The following description will be made in the context of the anonymization of personal data in the health field.
0073In this exemplary embodiment, each insured patient has a personal digital medium constituted by a microcircuit card 10. As a variant, this digital medium can be constituted by a USB key, a mobile telephone, or any other electronic equipment comprising a storage space. secure, and cryptographic means of authentication, signature and encryption.
0074In the system of FIG. 1, there is shown a microcircuit card 10 belonging to an insured person A, a reader 20 belonging to a healthcare professional and adapted to read this microcircuit card, a second subsystem 30 adapted to receive, in an encrypted manner, the sensitive personal medical data of the insured A from the reader 20, and to memorize this data anonymously, and a first subsystem 40 which contains the personal data of the insured and which can be used to obtain a specific detailed data at the request of the insured.
0075In this embodiment, it will be considered that for any medical service, a healthcare professional generates, for patient A, sensitive personal data consisting of detailed medical data DD_A personal and additional data comprising an amount MP of the service. This detailed medical data DD_A is associated with reduced medical data DR_A.
0076The reduced medical data DR_A can for example constitute a subset of the detailed medical data DD_A. In a variant, the second subsystem includes a correspondence table allowing it to find the reduced data DR_A from detailed data DD_A.
0077The reduced data of a service are for example constituted by the name of a group of drugs, and the detailed data by the name of this group (reduced data), sensitive and personal information (name of the drug in the group).
0078Each patient A is identified by personal ID_A identification data, consisting for example of his name, address and social security number. These identification data ID_A are stored in a private database 45 of the first subsystem 40.
0079This first subsystem 40 comprises a processor 41, a read-only memory 42 which includes computer programs which can be executed by the processor 41, and a random access memory 43 necessary for the execution of these programs.
0080The read-only memory 42 comprises in particular a program for generating a key IDC_A from the identification data ID_A of a person A.
0081This key being shared by the second subsystem 30, we call it "common key IDC_A".
0082For each subscriber A to the management system according to the invention, the database 45 of the first subsystem 40 comprises a record 450 which associates with identification data ID_A of this person, the common key IDC_A generated. The second subsystem 30 also includes a processor 31, a read-only memory 32 comprising computer programs that can be executed by the processor 31 and a random access memory 33 necessary for the execution of these programs.
0083The read-only memory 32 comprises in particular a computer program adapted to implement the method for managing personal data, the flow diagram of which is shown in FIG. 2. This method comprises a first step ElO during which the second sub- system 30 obtains, for a person A whose identity he does not know, the common key IDC_A generated by the first subsystem 40. In the preferred embodiment described here, it is considered that each insured A has specific rights DT_A negotiated with his insurer, these rights DT_A being stored in the record 450 of the private database 45 of the first subsystem 1. On will also consider that these rights DT_A are obtained by the second subsystem 30 during the aforementioned obtaining step E10.
0084In the preferred embodiment described here, the step E10 of the data management method is followed by a step E12 during which the second subsystem 30 generates a random number NA from the common key IDC_A received at l 'previous step. In a preferred embodiment, the common key IDC_A and the random number NA are generated using a symmetric encryption scheme of the AES type. More specifically, the program for generating the common key IDC_A of the first subsystem 40 keeps a secret key AES K1 and the program for generating a random number of the second subsystem 30 keeps secret an AES key K2, the identifiers being calculated as follows:
0085- IDC_A = AESKI (ID_A); and<img file="WO2006079752A1_D0001.tif" />
0086This step E12 is followed by a step E14 during which the random number NA, the common key IDC_A and the rights DT_A of a person whose second subsystem 30 does not know the identity, are stored in a record 350 of a database 35 of the second subsystem 30.
0087As we will see later, this record 350 has a field, for the time being free, in which the second subsystem 30 will record the sensitive personal data DD_A of this person.
0088These sensitive data DD__A are therefore anonymous, in the sense that the second subsystem 30 does not know the identification data ID_A of this person. In the preferred embodiment described here, the first subsystem 40 and the second subsystem 30 respectively comprise communication means 38 and 48 making it possible to connect these subsystems via a network, for example the Internet network. These communication means consist of network cards and software layers known to those skilled in the art.
0089These means of communication can in particular be used to allow the second subsystem 30 to obtain the common key IDC_A from the first subsystem 40. We will now assume that the random number NA generated by the second subsystem 30, the common key IDC_A generated by the first subsystem 40 and the identification data ID_A of person A are sent to an inserter for the creation of a personal microcircuit card 10 of person A. In the embodiment described here, on receipt of this information, the pencarteur creates, during a step E16 of the data management method according to the invention, a pair of private / public signature keys KPRIV_S / KPUB_S and a certificate CERT including the public signature key KPUB_S and the identifier IDC_A. In a manner known to a person skilled in the art, using the common identification key IDC_A and the CERT certificate, the inserter is able to find all the data of a person A, and in particular his personal data ID_A, the random number NA and the private signature key KPRIV_S. In this preferred embodiment, the second subsystem creates a pair of private / public encryption keys KPRIV_C / KPUB__C. During this same step, the private encryption key KPRIV_C is stored in a memory area 34 of the second subsystem 30. The public encryption key KPUB_C is supplied to the inserter. The CERT certificate, the private signature key KPRIV_S associated with this certificate, the random number NA and the public encryption key KPUB_C are stored in a protected area 16 of the microcircuit card 10.
0090The microcircuit card 10 comprises a processor 11, a read-only memory 12 comprising programs that can be executed by the processor 11 and a random access memory 13 necessary for the execution of these programs.
0091We will now describe a medical service. Assume that person A goes to a health professional equipped with a reader 20 adapted to read the microcircuit card 10 of this person.
0092This reader 20 comprises a processor 21, a read-only memory 22 comprising programs that can be executed by the processor 21 and a random access memory 23 necessary for the execution of these programs. The reader 20 also comprises means 27 of communication adapted to communicate with means 17 of communication of the microcircuit card 10 in reading and writing.
0093The microcircuit card reader 20 also comprises means of communication 28 with the means of communication 38 of the second subsystem 30.
0094In the preferred embodiment described here, we will assume that the communication means 28 of the reader 20, the communication means 38 of the second subsystem 30 and the communication means 48 of the first subsystem 40 allow these three pieces of equipment to communicate via a network (for example Internet) not shown in Figure 1.
0095We will assume that the health service described here gives rise to the generation of detailed medical data DD_A to which correspond reduced data DR_A. The amount of the medical benefit is noted MP.
0096In the preferred embodiment described here, the reader 20 includes a keyboard 25 allowing the entry of detailed data DD_A and a screen 26 for controlling this entry.
0097When the detailed medical data DD_A are entered by the healthcare professional, these data and the amount MP of the service are sent in a message Ml to the microcircuit card 10 of patient A.
0098All of this data is received by the communication means 17 of the microcircuit card 10. The processor 11 of this card then implements a signature and encryption program stored in the ROM 12. More specifically, in the example described here, these encryption and signature programs use the RSA-PKCS algorithm as follows.
0099First, this program generates a signature S of the detailed personal data DD_A and additional data comprising the amount MP using the private signature key KPRIV_S and the certificate CERT.
0100This signature S includes the patient's detailed personal data DD_A and the amount MP of the service. Then the program encrypts, using the public encryption key KPUB_C, the signature S, the random number NA and the certificate CERT. It thus obtains DC encrypted data.
0101These encrypted data DC are read by the reader 20 (stream M2 in FIG. 1) then sent, in a recording message M3, to the second subsystem 30.
0102These encrypted data DC are received by the communication means 38 of the second subsystem 30 during a step E18 of the data management method according to the invention.
0103This step E18 is followed by a step E20 during which the processor 31 of the second subsystem 30 implements a program stored in the read-only memory 32 to decrypt this data DC.
0104To carry out this decryption, the aforementioned program uses the private decryption key KPRIV_C stored in memory 34 during step E16 described above.
0105This decryption step E20 allows the second subsystem 30 to recover the random number NA used for the encryption, the detailed data DD_A of the service included in the signature S, and additional data, for example the amount of the service MP.
0106During this step E20, the second subsystem 30 checks the signature S using the public signature key KPUELS.
0107This decryption step E20 is followed by a step E22 during which the second subsystem 30 stores, in the database 35, the personal medical data DD_A in the field left free of the record 350 comprising the random number NA included in the DC figures.
0108In the preferred embodiment described here, this storage step E22 is followed by a step E24 during which the second subsystem 30 implements a program stored in its memory 32 to obtain the reduced data DR_A, namely here the name of a drug group from detailed data DD_A. On the other hand it generates an NF invoice number.
0109This step E24 is followed by a step E26 during which the second subsystem 30 sends, to the first subsystem 40, a message M6 comprising the reduced data DR_A, the invoice number NF, possibly additional data such as the amount MP of the service, and the common key IDC_A stored in the aforementioned record 350. Thus, on receipt of this message M6, the first subsystem
011040 can store in the database 45 the reduced data DR_A in the record comprising the common key IDC_A.
0111The invoice number NF is stored in a field of the record 450 of the database 45 of the subsystem 1. The anonymization principle is respected since the detailed data DD_A are only known to the second subsystem 30, the latter not having access to the identification data ID_A stored in the private database 45 of the first subsystem 40.
0112In a preferred embodiment, the read-only memory 32 of the second subsystem 30 includes a program making it possible to perform statistical processing on the sensitive data DD_A stored in the second database 35.
0113In the preferred mode described here, the step E26 of sending the message M6 is followed by a step E28 during which the second subsystem 30 calculates, from the rights DT_A stored in the database 35 in the recording comprising the common key IDC_A, and of the amount of the service MP received in the encrypted data DC, an amount of reimbursement MR.
0114This reimbursement amount MR is sent, during a next step E30, to the reader 20 of the healthcare professional and to the first subsystem 40 by the network. The NF invoice number, the MR reimbursement amount and information relating to the service are supplied to the patient by the first subsystem 40, by mail for example.
0115Upon receipt of this reimbursement amount, the healthcare professional knows what amount remains to be paid by patient A.
0116We will now assume that patient A wishes to make a complaint on the invoice bearing the NF number.
0117For this, it wishes to obtain the detailed data DD_A relating to this invoice stored in the database 35 of the second subsystem 30.
0118In order to allow such obtaining, the first subsystem
011940 comprises, in its read-only memory 42, a computer program which implements a process for obtaining personal data in accordance with the invention. The main steps of this process will now be described with reference to FIG. 3.
0120This obtaining method comprises a first step FlO during which the first subsystem 40 receives a request RQl from patient A to obtain the sensitive personal data DD_A associated with the invoice NF.
0121This step F10 is followed by a step F12 during which the first subsystem 40 obtains, from the database 45, the common key IDC_A generated from the identification data ID_A of this person A. This step F12 is followed by a step F14 during which the first subsystem 40 sends the second subsystem 30 a request RQ2 to authenticate the person A.
0122This authentication request RQ2 includes the identifier NF of the invoice and the common key IDC_A obtained in the previous step. In the preferred embodiment described here, this request RQ2 is received during a step E32 of the data management method.
0123Those skilled in the art will understand that preferably, the reception and management of this request RQ2 are carried out in a process different from the process of recording the data itself. Anyway, this step E32 of receiving the request RQ2 is followed by a step E34 during which the second subsystem 30 seeks to authenticate the person A.
0124Different authentication methods can be implemented, the only constraint being that the authentication proper must actually be performed by the second subsystem 30 in order to prevent the first subsystem 40 from being able to use the request. obtaining RQl to obtain data other than that associated with the NF invoice. If the authentication succeeds, step E34 is followed by a step
0125E36 during which the second subsystem 30 sends the detailed data DD_A associated with the invoice number NF in the database 35 to the first subsystem 40.
0126These detailed data are received during a step F16 of the obtaining method according to the invention.
0127This detailed data can then be sent to insured A for verification.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO0118631A1 | Cites | World Intellectual Property Organization (WIPO) | X | International search | 9-18 |
| WO0169514A2 | Cites | World Intellectual Property Organization (WIPO) | X | International search | 9-18 |
| EP0884670A1 | Cites | European Patent Office (EPO) | A | International search | 1-18 |
| EP1099996A1 | Cites | European Patent Office (EPO) | A | International search | 1-18 |
| US2003208457A1 | Cites | United States of America | A | International search | 2,7,10,12 |
| FR2837301A1 | Cites | France | A | International search | 1-18 |
| US5606610A | Cites | United States of America | A | International search | 1-18 |
| US5778071A | Cites | United States of America | A | International search | 4,5,11 |
6 members in 4 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0500784 | France | A | |
| FR20050000784 | – | – | – |
| 0500784 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| FR2881248A1 | France | A1 | |
| WO2006079752A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| EP1849118A1 | European Patent Office (EPO) | A1 | |
| US2008304663A1 | United States of America | A1 | |
| US8607332B2 | United States of America | B2 | |
| EP1849118B1 | European Patent Office (EPO) | B1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Wipo information: published in national officeWWP | WWP | |
| Wipo information: entry into national phaseWWE | WWE | |
| Wipo information: entry into national phaseWWE | WWE | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 |
Numbers
- Publication
- 2006/079752
- Publication, DOCDB
- 2006079752
- Publication, EPODOC
- WO2006079752
- Application
- 50060
- Application, DOCDB
- 2006050060
- Application, EPODOC
- WO2006FR50060
Titles2
- English
- SYSTEM AND METHOD FOR THE ANONYMISATION OF SENSITIVE PERSONAL DATA AND METHOD OF OBTAINING SUCH DATA
- French
- SYSTEME ET PROCEDE D'ANONYMISATION DE DONNEES PERSONNELLES SENSIBLES ET PROCEDE D'OBTENTION DE TELLES DONNEES
Classification
- CPC, 2
- G06F21/6254
- G06F2221/2153
- IPC, 1
- G06F21 62
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo