Authenticated Hub Segments IoT Tracking from Medical Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for secure communication between electronic assets and a central server face challenges in authentication, tracking, and security, particularly in medical and wellness applications, where incorrect or missing devices can lead to fatal errors and security vulnerabilities like those exposed by the Ripple20 vulnerabilities.

Innovation Solution

Implementing an authenticated computer hub and central server system that securely connects and tracks electronic assets using biometric authentication, IoT protocols, and control directives to ensure only authorized devices connect and transmit data, minimizing the need for individual SIM cards and reducing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If wide-area communication technology (IoT protocols) is incorporated into all electronic assets for tracking, then tracking capability is improved, but security vulnerabilities increase and device complexity increases

Engineering Contradiction:
Improvetracking capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system divides tracking functionality into two segments: local electronic assets use short-range communication for data exchange, while the computer hub handles wide-area communication and tracking. This segmentation allows tracking capability without requiring IoT protocols in every electronic asset, thereby reducing security vulnerabilities and device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The computer hub acts as an intermediary between electronic assets and the central server. Electronic assets communicate locally with the hub via short-range communication, and the hub manages wide-area communication with the server. This intermediary approach enables tracking and data collection without exposing individual electronic assets to direct internet connectivity, reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If wide-area communication technology (IoT protocols) is incorporated into all electronic assets for tracking, then tracking capability is improved, but device complexity increases

Engineering Contradiction:
Improvetracking capabilityVSAvoiddevice requirements
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system divides tracking functionality into two segments: local electronic assets use short-range communication for data exchange, while the computer hub handles wide-area communication and tracking. This segmentation allows tracking capability without requiring IoT protocols in every electronic asset, thereby reducing security vulnerabilities and device complexity.

Inventive Principle:
Principle #1Segmentation

3Productivity

If electronic assets connect directly to central server using IoT protocols, then data transmission capability is improved, but security risks increase

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The computer hub acts as an intermediary between electronic assets and the central server. Electronic assets communicate locally with the hub via short-range communication, and the hub manages wide-area communication with the server. This intermediary approach enables tracking and data collection without exposing individual electronic assets to direct internet connectivity, reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If control over electronic asset connection is relaxed to allow more devices, then system adaptability is improved, but security control deteriorates

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication and authorization actions before allowing electronic assets to connect. The computer hub verifies the identity and permissions of each device before establishing communication, ensuring that only authorized devices can join the network. This preliminary control maintains security while allowing diverse device types to connect.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the computer hub continuously monitors connected devices and reports their status to the central server. The server can send commands back to the hub to manage device connections, allowing dynamic control over which devices are permitted to connect based on current security requirements and system state.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11436369B1Systems, devices and methods for securely communicating with electronic assets using an authenticated computer hub and a central server
  • US11436369B1 patent drawing
  • US11436369B1 patent drawing
  • US11436369B1 patent drawing

AI summary

Embodiments described herein provide methods and systems for securely communicating with electronic assets using an authenticated computer hub and a central server. The authenticated computer hub transmits a hub identity uniquely identifying the computer hub and communication results received from authenticated electronic assets, and receives an identity confirmation message and electronic asset identities to be authorized with control directives defining operational usage parameters. The authenticated computer hub has a user interface to display electronic assets granted access, and a short-range communication device to connect to authorized electronic assets to exchange information based on control directives. The methods and systems involve a central server with a non-transitory memory storing a list of authenticated hub identities, identifiers for electronic assets, control directives, and communication results from the authorized electronic assets, along with a hub manager interface, a communication interface, and a hardware processor.