Secure Clinical Trial Device Credential Transfer via Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Clinical trials face inefficiencies and security concerns when setting up client devices for subject users, particularly in resetting session data and providing credentials, as traditional methods like manual entry of usernames and passwords are cumbersome and prone to errors.
Innovation Solution
A computer-implemented method and system that allows for secure and efficient transfer of user credentials between a client device and a server, enabling automatic login by storing and retrieving coordinator and subject user credentials, utilizing biometric data, and integrating with a proprietary application to manage user access and session resets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual entry of usernames and passwords is used for client device setup, then ease of operation is maintained, but productivity decreases and errors increase
Solution Approach 1:
The system pre-configures client devices with placeholder credentials during manufacturing. When a subject user arrives at the investigation site, the site coordinator simply triggers a credential transfer process, and the device is automatically configured with the subject user's credentials, eliminating manual setup steps
Solution Approach 2:
A secure communication channel between the client device and the server acts as an intermediary to automatically transfer credentials. The server validates credentials and the device automatically updates its authentication information, eliminating the need for manual credential entry while maintaining security
2Productivity
If traditional manual credential provision is used, then security can be maintained through verification, but time consumption increases and operational efficiency decreases
Solution Approach 1:
The system performs preliminary actions by pre-configuring devices with placeholder credentials and establishing secure communication channels before the actual credential transfer is needed. This allows rapid credential updates when subjects arrive at the investigation site without time-consuming manual setup
Solution Approach 2:
The patent replaces manual mechanical credential transfer processes with automated electronic communication. The server automatically validates and transfers credentials through secure digital channels, eliminating manual verification steps and significantly reducing the time required for credential provision and session resets
3Reliability
If manual session reset is performed by site personnel, then control over data is maintained, but operational complexity increases and errors occur
Solution Approach 1:
The system enables self-service by allowing the client device to automatically manage its own credential updates and session resets. When a subject user arrives, the device automatically receives new credentials through the secure communication channel and updates its authentication information without requiring manual intervention from site personnel, reducing errors while maintaining security control
Data Source
AI summary
A method, device and system for transceiving clinical trial related information includes a client device and a server that communicate. An application of the client device has a client application of a clinical trial service whose server application is running on the server. A coordinator user profile with credentials and a user profile with credentials are maintained. The coordinator credentials are determined to be be authorized. The coordinator user obtains access to the application. Coordinator input data triggers user change for the client device. A request to the server application indicating the triggered user change is sent. Credentials are received from the server application and associated with the user profile. The coordinator user is logged out by disconnecting coordinator level access to the proprietary application and resetting the coordinator credentials and session data within the client device. The credentials are stored for automatic first logging in of the user.


