Secure Clinical Trial Device Credential Transfer via Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Clinical trials face inefficiencies and security concerns when setting up client devices for subject users, particularly in resetting session data and providing credentials, as traditional methods like manual entry of usernames and passwords are cumbersome and prone to errors.

Innovation Solution

A computer-implemented method and system that allows for secure and efficient transfer of user credentials between a client device and a server, enabling automatic login by storing and retrieving coordinator and subject user credentials, utilizing biometric data, and integrating with a proprietary application to manage user access and session resets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual entry of usernames and passwords is used for client device setup, then ease of operation is maintained, but productivity decreases and errors increase

Engineering Contradiction:
Improveclient device setup efficiencyVSAvoidcredential management process
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system pre-configures client devices with placeholder credentials during manufacturing. When a subject user arrives at the investigation site, the site coordinator simply triggers a credential transfer process, and the device is automatically configured with the subject user's credentials, eliminating manual setup steps

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A secure communication channel between the client device and the server acts as an intermediary to automatically transfer credentials. The server validates credentials and the device automatically updates its authentication information, eliminating the need for manual credential entry while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If traditional manual credential provision is used, then security can be maintained through verification, but time consumption increases and operational efficiency decreases

Engineering Contradiction:
Improvecredential transfer speedVSAvoidsession reset time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring devices with placeholder credentials and establishing secure communication channels before the actual credential transfer is needed. This allows rapid credential updates when subjects arrive at the investigation site without time-consuming manual setup

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical credential transfer processes with automated electronic communication. The server automatically validates and transfers credentials through secure digital channels, eliminating manual verification steps and significantly reducing the time required for credential provision and session resets

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual session reset is performed by site personnel, then control over data is maintained, but operational complexity increases and errors occur

Engineering Contradiction:
Improvecredential securityVSAvoidsession management process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service by allowing the client device to automatically manage its own credential updates and session resets. When a subject user arrives, the device automatically receives new credentials through the secure communication channel and updates its authentication information without requiring manual intervention from site personnel, reducing errors while maintaining security control

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10515717B2Method and apparatus for secure setup of clinical trial client device
Publication Date: 2019.12.24 CRF BOX OY
  • US10515717B2 patent drawing
  • US10515717B2 patent drawing
  • US10515717B2 patent drawing

AI summary

A method, device and system for transceiving clinical trial related information includes a client device and a server that communicate. An application of the client device has a client application of a clinical trial service whose server application is running on the server. A coordinator user profile with credentials and a user profile with credentials are maintained. The coordinator credentials are determined to be be authorized. The coordinator user obtains access to the application. Coordinator input data triggers user change for the client device. A request to the server application indicating the triggered user change is sent. Credentials are received from the server application and associated with the user profile. The coordinator user is logged out by disconnecting coordinator level access to the proprietary application and resetting the coordinator credentials and session data within the client device. The credentials are stored for automatic first logging in of the user.