IP Library Granted Patent US 11,838,295
Granted Patent B2
US 11,838,295 · App. 17/714,413 · Granted Dec 5, 2023

Delayed and provisional user authentication for medical devices

Inventor: Meinhard Dieter Ullrich (Lexington, MA)
Assignee: Imprivata, Inc.
H04L63/108G06F21/31G16H40/40G06F2221/2101G06F2221/2151
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,838,295
App. No.
17/714,413
Granted
Dec 5, 2023
Kind
B2
Abstract

Representative embodiments of operating a secured device requiring user authentication include receiving a request from a user for operating the device without prior authentication; granting the user temporary access to the device in accordance with a security policy that specifies a predetermined time interval and/or a predetermined number of device operations within which authentication must occur to continue at least some operations of the device; computationally storing an audit trail identifying the temporary access and actions performed during the temporary access; and upon determining that authentication has not been provided within the predetermined time interval or number of device operations, preventing at least some operations of the device and updating the audit trail to specify expiration of the temporary access.

Claims (35)

1. A method of operating a secured device requiring user authentication, the method comprising:

receiving a request from a user for operating the device without prior authentication;

without requiring validation from another user, granting the user temporary access to the device in accordance with a security policy, the security policy specifying at least one of (i) a predetermined time interval within which authentication must occur to continue at least some operations of the device or (ii) a predetermined number of device operations within which authentication must occur to continue at least some operations of the device;

computationally storing an audit trail identifying the temporary access and actions performed during the temporary access; and

upon determining that authentication has not been provided within the predetermined time interval or number of device operations, preventing at least some operations of the device and updating the audit trail to specify expiration of the temporary access.

2. The method of claim 1 , further comprising updating the audit trail to include a time of authentication upon authentication of the user within the predetermined time interval or number of device operations.

3. The method of claim 1 , wherein the temporary access allows the user to perform only some operations of the device.

4. The method of claim 1 , further comprising, upon determining that the user has failed to provide authentication within the predetermined time interval or number of device operations, causing at least one of (i) generation of an alert to the user or supervisory personnel or (ii) reversal of any adjustments to the device made by the user.

5. The method of claim 4 , further comprising accepting, as authentication, a permission remotely provided by previously authenticated personnel in accordance with an institutional security policy.

6. The method of claim 1 , further comprising receiving provisional authentication from the user prior to granting the temporary access.

7. The method of claim 6 , wherein the provisional authentication includes an identification of the user.

8. The method of claim 6 , wherein the provisional authentication is based on the user's proximity to the device without user action.

9. The method of claim 1 , wherein the audit trail includes an identification of the device and a time stamp associated with each of the user's operations of the device.

10. The method of claim 9 , wherein the audit trail includes an identification of the user.

11. The method of claim 1 , wherein the predetermined time interval and/or predetermined number of device operations is set dynamically.

12. The method of claim 1 , further comprising, upon determining that the user has failed to provide authentication within the predetermined time interval or number of device operations and receiving a request from a second user for operating the device, causing at least one of (i) generation of a message to the second user or supervisory personnel or (ii) reversal of any adjustments to the device made by the user.

13. A system for operating a secured device requiring user authentication, the system comprising:

a user interface for receiving a request from a user for operating the device;

memory storing a security policy specifying at least one of (i) a predetermined time interval within which authentication must occur to continue at least some operations of the device or (ii) a predetermined number of device operations within which authentication must occur to continue at least some operations of the device; and

a controller configured to:

without requiring validation from another user, grant, without prior authentication, the user temporary access to the device in accordance with the security policy;

computationally store, in the memory, an audit trail identifying the temporary access and actions performed during the temporary access; and

upon determining that authentication has not been provided within the predetermined time interval or number of device operations, prevent at least some operations of the device and update the audit trail to specify expiration of the temporary access.

14. The system of claim 13 , wherein the controller is further configured to update the audit trail to include a time of authentication upon authentication of the user within the predetermined time interval or number of device operations.

15. The system of claim 13 , wherein the temporary access allows the user to perform only some operations of the device.

16. The system of claim 13 , wherein the controller is further configured to:

upon determining that the user has failed to provide authentication within the predetermined time interval or number of device operations, cause at least one of (i) generation of an alert to the user or supervisory personnel or (ii) reversal of any adjustments to the device made by the user.

17. The system of claim 16 , wherein the memory further stores an institutional security policy, the controller being further configured to accept, as authentication, a permission remotely provided by previously authenticated personnel in accordance with the institutional security policy.

18. The system of claim 13 , further comprising at least one of a hands-free authentication system or a real-time location system (RTLS) for receiving provisional authentication from the user prior to granting the temporary access.

19. The system of claim 18 , wherein the provisional authentication includes an identification of the user.

20. The system of claim 18 , wherein the provisional authentication is based on the user's proximity to the device without user action.

21. The system of claim 13 , wherein the audit trail includes an identification of the device and a time stamp associated with each of the user's operations of the device.

22. The system of claim 21 , wherein the audit trail includes an identification of the user.

23. The system of claim 13 , wherein the controller is further configured to dynamically set the predetermined time interval and/or predetermined number of device operations.

24. The system of claim 13 , wherein the controller is further configured to cause, upon determining that the user has failed to provide authentication within the predetermined time interval or number of device operations and receiving a request from a second user for operating the device, at least one of (i) generation of a message to the second user or supervisory personnel or (ii) reversal of any adjustments to the device made by the user.

Assignments (4)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY COLLATERAL AT REEL/FRAME NO. 68553/0806 Recorded Sep 18, 2024
From: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
To: IMPRIVATA, INC.
Reel/Frame 068981/0790 →
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT (1L) Recorded Aug 12, 2024
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 068551/0623 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT (2L) Recorded Aug 12, 2024
From: IMPRIVATA, INC.
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 068553/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: ULLRICH, MEINHARD
To: IMPRIVATA, INC.
Reel/Frame 064414/0934 →
Cited By (1)
US 12,425,415