IP Library Granted Patent US 12,142,370
Granted Patent B2
US 12,142,370 · App. 18/154,750 · Granted Nov 12, 2024

Passing authentication token to authorize access to rest calls via web sockets

Inventors: Ben Xavier (San Diego, CA); Dennis Krabbe (San Diego, CA); Lito Patiag (San Diego, CA)
Assignee: ICU Medical, Inc.
G16H40/20A61M5/142A61M5/172G06F12/0802G06F16/24552G16H20/17G16H40/40G16H40/60G16H40/63G16H40/67G16H80/00H04L43/0811H04L43/16H04L63/08H04L67/125H04L67/34H04L67/565H04L67/5682H04L69/08H04L69/18A61M2005/14208A61M2205/18A61M2205/3553A61M2205/3561A61M2205/3584A61M2205/3592A61M2205/52H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,142,370
App. No.
18/154,750
Granted
Nov 12, 2024
Kind
B2
Abstract

Various techniques for facilitating communication with and across a clinical environment and a cloud environment are described. For example, a method for authenticating a network device residing in the clinical environment using a token is described. An authentication proxy in the cloud environment can receive a request from a connectivity adapter in the clinical environment and retrieve a security token from an authentication system in the cloud. The connectivity adapter can use the security token to send signed requests to the authentication system.

Claims (34)

1. A method for authenticating a network device residing in a network environment, the method comprising:

processing, by a proxy, an authentication request from the network device residing in the network environment, wherein the proxy is in communication with (i) the network device residing in the network environment, and (ii) an authentication system configured to perform authentication based on login requests from a plurality of user devices not residing in the network environment as well as the network device residing in the network environment, wherein the authentication request from the network device includes identifying information associated with the network environment, and wherein the network environment includes one or more devices in communication with the network device;

transmitting login information to the authentication system;

receiving a token from the authentication system; and

transmitting the token to the network device residing in the network environment such that the token is usable by the network device to transmit requests to the authentication system.

2. The method of claim 1 , wherein the login information is transmitted via a WebSocket connection.

3. The method of claim 1 , wherein the login information is transmitted via a network connection that is secured and authenticated.

4. The method of claim 1 , further comprising causing the network device residing in the network environment to transmit a signed request to the authentication system.

5. The method of claim 1 , wherein the login information is transmitted, and the token is received, via one or more network connections that are established over a wide area network.

6. The method of claim 1 , further comprising receiving a message from the network device residing in the network environment via a network connection via which the login information was transmitted, wherein the message includes information associated with the one or more devices in communication with the network device.

7. The method of claim 1 , wherein the network device is configured to communicate with the one or more devices over a local area network.

8. A system configured to authenticate a network device residing in a network environment, the system comprising:

one or more processors in communication with (i) a network device residing in the network environment, and (ii) an authentication system configured to perform authentication based on login requests from a plurality of user devices not residing in the network environment as well as the network device residing in the network environment; and

one or more memories in communication with the one or more processors and storing computer-executable instructions that, when executed by the one or more processors, configure the one or more processors to:

process an authentication request from the network device residing in the network environment, wherein the authentication request includes identifying information associated with the network environment, and wherein the network environment includes one or more devices in communication with the network device;

cause login information to be transmitted to the authentication system;

receive a token from the authentication system; and

cause the token to be transmitted to the network device residing in the network environment such that the token is usable by the network device to transmit requests to the authentication system.

9. The system of claim 8 , wherein the login information is transmitted via a WebSocket connection.

10. The system of claim 8 , wherein the login information is transmitted via a network connection that is secured and authenticated.

11. The system of claim 8 , wherein the computer-executable instructions, when executed by the one or more processors, further configure the one or more processors to cause the network device residing in the network environment to transmit a signed request to the authentication system.

12. The system of claim 8 , wherein the login information is transmitted, and the token is received, via one or more network connections that are established over a wide area network.

13. The system of claim 8 , wherein the computer-executable instructions, when executed by the one or more processors, further configure the one or more processors to receive a message from the network device residing in the network environment via a network connection via which the login information was transmitted, wherein the message includes information associated with the one or more devices in communication with the network device.

14. The system of claim 8 , wherein the network device is configured to communicate with the one or more devices over a local area network.

15. Non-transitory physical computer storage storing computer-executable instructions that, when executed by one or more computing devices in communication with (i) a network device residing in a network environment, and (ii) an authentication system configured to perform authentication based on login requests from a plurality of user devices not residing in the network environment as well as the network device residing in the network environment, configure the one or more computing devices to:

process an authentication request from the network device residing in the network environment, wherein the authentication request includes identifying information associated with the network environment, and wherein the network environment includes one or more devices in communication with the network device;

cause login information to be transmitted to the authentication system;

receive a token from the authentication system, the token being usable by the network device to transmit requests to the authentication system; and

cause the token to be transmitted to the network device residing in the network environment such that the token is usable by the network device to transmit requests to the authentication system.

16. The non-transitory physical computer storage of claim 15 , wherein the login information is transmitted via a secured and authenticated WebSocket connection.

17. The non-transitory physical computer storage of claim 15 , wherein the computer-executable instructions, when executed by the one or more computing devices, further configure the one or more computing devices to cause the network device residing in the network environment to transmit a signed request to the authentication system.

18. The non-transitory physical computer storage of claim 15 , wherein the login information is transmitted, and the token is received, via one or more network connections that are established over a wide area network.

19. The non-transitory physical computer storage of claim 15 , wherein the computer-executable instructions, when executed by the one or more computing devices, further configure the one or more computing devices to receive a message from the network device residing in the network environment via a network connection via which the login information was transmitted, wherein the message includes information associated with the one or more devices in communication with the network device.

20. The non-transitory physical computer storage of claim 15 , wherein the network device is configured to communicate with the one or more devices over a local area network.

Assignments (1)
SECURITY INTEREST Recorded Oct 31, 2025
From: ICU MEDICAL, INC.; EXCELSIOR MEDICAL CORPORATION; TANGENT MEDICAL TECHNOLOGIES, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073428/0588 →