US2019347441A1PendingUtilityA1

Patient privacy de-identification in firewall switches forming VLAN segregation

Assignee: CHAN TAT WAIPriority: Apr 5, 2017Filed: Jul 22, 2019Published: Nov 14, 2019
Est. expiryApr 5, 2037(~10.7 yrs left)· nominal 20-yr term from priority
Inventors:Tat Chan
H04L 63/101G06Q 20/1235G06F 21/105G06F 21/6245G06F 2221/0713G06F 21/1015
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present disclosure relates to firewall switches allowing user remote access providing virtual networks and logging support to access information associated with their license via a virtual network. In one example of the present disclosure, user data associated with a user having an account on a virtual network is obtained. Access control list associated with an identified application pid from an application database is then obtained, the identified application pid having been previously purchased by the user and the identified application being selected by the user from a user device. An application programming interface of the virtual network is then invoked to publish the transaction associated with the identified application pid to a central log storage.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . An computer-implemented network dataflow monitoring system allowing user remote access providing virtual networks and logging support to applications, comprising data inspection software, whitelist and blacklist filters, and a set of user-specified patient identifiers, having software components for performing the steps of:
 obtaining, by the computer, user data associated with a user having an account on a first virtual network (VLAN);   obtaining, by the computer, access control list (ACL) associated with an identified application pid from a application database, the identified application pid having been previously authorized for access by the user and the identified application pid being accessed by the user from a user device;   detecting, by the computer, no occurrence of the user-specified patient identifiers in the user data;   in response to detecting no occurrence of the user-specified patient identifiers in the user data:
 a. routing the user data to a first VLAN; 
 b. routing the user data by masking the user-specified patient identifiers to a second de-identified VLAN; 
 c. routing the user-specified patient identifiers to a third encrypted VLAN; 
   and invoking, by the computer, an application programming interface (API) of the virtual network to publish the transaction associated with the identified application pid to a central log storage hosted on a second virtual network (VLAN).   
     
     
         2 . The computer-implemented method of  claim 1 , wherein obtaining the access control list further comprises transmitting, by the computer, a request for the access control list to a application directory service. 
     
     
         3 . The computer-implemented method of claim further comprising obtaining, by the computer, license information associated with a user purchase, and wherein obtaining the user data, obtaining the access control list, and obtaining the license information comprises electronically receiving, by the computer, the user data and access control list from a retailer from which the user purchased the identified application pid. 
     
     
         4 . The computer-implemented method of  claim 1 , further comprising: obtaining, by the computer, license information associated with a user license, and further comprising storing, by the computer, the user data, license information, and access control list in a database; and storing, by the computer, user data for a plurality of users, license information for a plurality of licenses, and access control list for a plurality of application pid in the database. 
     
     
         5 . The computer-implemented method of  claim 1 , wherein obtaining access control list further comprises: receiving, by the computer, a request from the user device regarding the identified application pid; and retrieving, by the computer, the access control list from a web server associated with a application directory service. 
     
     
         6 . The computer-implemented method of  claim 1 , further comprising transmitting, by the computer, the access control list via a communication network using an API to a web server associated with a third party web service, the third party web service being configured to receive access control list from a plurality of sources, tabulate access control list for a plurality of applications, and enable a plurality of users to access the access control list for the plurality of applications. 
     
     
         7 . A firewall switch allowing user remote access providing virtual networks and logging support to applications containing non-transitory computer-readable medium storing instructions that, when executed by a processing resource, cause the processing resource to perform the steps comprising: obtaining user data associated with a user having an account on a virtual network; enabling a user to select an identified application pid from a user device, the identified application pid having been previously purchased by the user; obtaining access control list associated with the identified application pid; and invoking, in response to the selection of the identified application pid by the user, an API of the social network to publish the transaction associated with the identified application pid to a central log storage. 
     
     
         8 . The firewall switch of  claim 7 , wherein the computer-executable instructions cause the processing resource to further perform the steps comprising: storing user information, wherein the storing user information is further comprised of storing information related to a plurality of users, a plurality of application pids, and a plurality of license information. 
     
     
         9 . The firewall switch of claim wherein the computer-executable instructions cause the processing resource to further perform the steps comprising: communicating with a web server associated with a retailer, wherein the user data is obtained through a financial institution card used to purchase the application via a mobile device associated with the retailer, the mobile device being in communication with the web server. 
     
     
         10 . The firewall switch of  claim 8 , wherein the computer-executable instructions cause the processing resource to further perform the steps comprising: receiving a request from a user device regarding the identification of the application; and obtaining the application information from a web server associated with a application information service.

Join the waitlist — get patent alerts

Track US2019347441A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.