IP Library Granted Patent US 11,587,669
Granted Patent B2
US 11,587,669 · App. 17/447,557 · Granted Feb 21, 2023

Passing authentication token to authorize access to rest calls via web sockets

Inventors: Ben Xavier (San Diego, CA); Dennis Krabbe (San Diego, CA); Lito Patiag (San Diego, CA)
Assignee: ICU Medical, Inc.
G16H40/20A61M5/142A61M5/172G06F12/0802G16H20/17G16H40/40G16H40/60G16H40/63G16H40/67G16H80/00H04L63/08H04L67/125H04L67/34H04L67/565H04L69/08H04L69/18A61M2005/14208A61M2205/18A61M2205/3553A61M2205/3561A61M2205/3584A61M2205/3592A61M2205/52H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,587,669
App. No.
17/447,557
Granted
Feb 21, 2023
Kind
B2
Abstract

Various techniques for facilitating communication with and across a clinical environment and a cloud environment are described. For example, a method for authenticating a network device residing in the clinical environment using a token is described. An authentication proxy in the cloud environment can receive a request from a connectivity adapter in the clinical environment and retrieve a security token from an authentication system in the cloud. The connectivity adapter can use the security token to send signed requests to the authentication system.

Claims (34)

1. A method for authenticating a network device residing in a clinical environment, the method comprising:

processing, by an authentication proxy in communication with (i) the network device residing in the clinical environment, and (ii) an authentication system, an authentication request from the network device residing in the clinical environment via a first network connection, wherein the authentication request includes identifying information associated with the clinical environment, and wherein the clinical environment includes one or more medical devices in communication with the network device;

transmitting login credentials usable to authenticate the network device to the authentication system via a second network connection different from the first network connection via which the authentication request was received;

receiving a token from the authentication system, the token being usable by the network device to transmit requests to the authentication system; and

transmitting the token to the network device residing in the clinical environment via the first network connection that is different from the second network connection via which the token was received.

2. The method of claim 1 , wherein the first network connection is a Web Socket connection.

3. The method of claim 1 , wherein the first network connection is secured and authenticated.

4. The method of claim 1 , further comprising causing the network device residing in the clinical environment to transmit a signed request to the authentication system.

5. The method of claim 1 , wherein the first network connection and the second network connection are both established over a wide area network.

6. The method of claim 1 , further comprising receiving a message from the network device residing in the clinical environment via the first network connection, wherein the message includes information associated with the one or more medical devices in communication with the network device.

7. The method of claim 6 , wherein the network device is configured to communicate with the one or more medical devices over a local area network.

8. A system configured to authenticate a network device residing in a clinical environment, the system comprising:

one or more processors in communication with (i) a network device residing in the clinical environment, and (ii) an authentication system configured to authenticate requests from the network device; and

one or more memories in communication with the one or more processors and storing computer-executable instructions that, when executed by the one or more processors, configure the one or more processors to:

process an authentication request from the network device residing in the clinical environment via a first network connection, wherein the authentication request includes identifying information associated with the clinical environment, and wherein the clinical environment includes one or more medical devices in communication with the network device;

cause login credentials usable to authenticate the network device to be transmitted to the authentication system via a second network connection different from the first network connection via which the authentication request was received;

receive a token from the authentication system, the token being usable by the network device to transmit requests to the authentication system; and

cause the token to be transmitted to the network device residing in the clinical environment via the first network connection that is different from the second network connection via which the token was received.

9. The system of claim 8 , wherein the first network connection is a Web Socket connection.

10. The system of claim 8 , wherein the first network connection is secured and authenticated.

11. The system of claim 8 , wherein the computer-executable instructions, when executed by the one or more processors, further configure the one or more processors to cause the network device residing in the clinical environment to transmit a signed request to the authentication system.

12. The system of claim 8 , wherein the first network connection and the second network connection are both established over a wide area network.

13. The system of claim 8 , wherein the computer-executable instructions, when executed by the one or more processors, further configure the one or more processors to receive a message from the network device residing in the clinical environment via the first network connection, wherein the message includes information associated with the one or more medical devices in communication with the network device.

14. The system of claim 13 , wherein the network device is configured to communicate with the one or more medical devices over a local area network.

15. Non-transitory physical computer storage storing computer-executable instructions that, when executed by one or more computing devices in communication with (i) a network device residing in a clinical environment, and (ii) an authentication system, configure the one or more computing devices to:

process an authentication request from the network device residing in the clinical environment via a first network connection, wherein the authentication request includes identifying information associated with the clinical environment, and wherein the clinical environment includes one or more medical devices in communication with the network device;

cause login credentials usable to authenticate the network device to be transmitted to the authentication system via a second network connection different from the first network connection via which the authentication request was received;

receive a token from the authentication system, the token being usable by the network device to transmit requests to the authentication system; and

cause the token to be transmitted to the network device residing in the clinical environment via the first network connection that is different from the second network connection via which the token was received.

16. The non-transitory physical computer storage of claim 15 , wherein the first network connection is a secured and authenticated Web Socket connection.

17. The non-transitory physical computer storage of claim 15 , wherein the computer-executable instructions, when executed by the one or more computing devices, further configure the one or more computing devices to cause the network device residing in the clinical environment to transmit a signed request to the authentication system.

18. The non-transitory physical computer storage of claim 15 , wherein the first network connection and the second network connection are both established over a wide area network.

19. The non-transitory physical computer storage of claim 15 , wherein the computer-executable instructions, when executed by the one or more computing devices, further configure the one or more computing devices to receive a message from the network device residing in the clinical environment via the first network connection, wherein the message includes information associated with the one or more medical devices in communication with the network device.

20. The non-transitory physical computer storage of claim 15 , wherein the network device is configured to communicate with the one or more medical devices over a local area network.

Assignments (1)
SECURITY AGREEMENT Recorded Mar 31, 2022
From: ICU MEDICAL, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 059618/0412 →
Cited By (9)
US 12,380,982 US 12,380,997 US 12,395,429 US 12,420,009 US 12,431,238 US 12,458,749 US 12,562,268 US 12,592,305 US 12,640,275