Instrument Interlock TOTP Access for Offline Usage Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems for laboratory instruments face challenges due to outdated operating systems, network connectivity issues, and user experience problems, making authentication difficult and costly, especially with TOTP methods requiring keyboards or browsers, which are not user-friendly or scalable.
Innovation Solution
A system utilizing time-based one-time passwords (TOTPs) generated on user devices and verified by interlock devices to grant access to laboratory instruments, with usage tracking integrated through an interlock device and central server, eliminating the need for traditional authentication methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional username and password authentication is used on keyboards, then access control can be implemented, but user experience deteriorates and deployment becomes difficult especially on touchscreen devices and instruments without network access
Solution Approach 1:
The patent replaces traditional mechanical keyboard input with optical scanning technology. Users present their ID through a camera or scanner, and the system automatically retrieves authentication credentials, eliminating the need for manual typing on keyboards or touchscreens.
Solution Approach 2:
The patent introduces an intermediary database system that stores user credentials and instrument access rights. Instead of direct authentication at the instrument, the system mediates access by verifying user identity through optical scanning and checking against stored credentials, simplifying the interaction at the instrument level.
2Adaptability or versatility
If proxy servers are used to provide network access for authentication, then network connectivity can be restored, but infrastructure complexity increases and security issues arise
Solution Approach 1:
The patent extracts the authentication functionality from network-dependent systems and implements it locally at each instrument. By storing credentials and access rights in local databases, the system eliminates the need for proxy servers and network infrastructure for authentication, making each instrument self-sufficient.
3Reliability
If dedicated kiosk computers with browsers are deployed for interlock-based access control, then authentication can be implemented, but device cost and deployment difficulty increase significantly
Solution Approach 1:
The patent makes the instrument's existing display and input capabilities multi-functional. The same display screen used for showing instrument status is also used for optical scanning and authentication, eliminating the need for dedicated kiosk computers and reducing overall system cost.
Solution Approach 2:
The instrument performs its own authentication functions using its built-in camera or scanner, display, and processor. Instead of requiring external dedicated computers, the instrument serves itself by implementing the full authentication workflow locally, reducing deployment complexity and cost.
4Reliability
If TOTP is sent via email or telephone for two-factor authentication, then security is enhanced, but authentication time increases and user convenience decreases
Solution Approach 1:
The system performs preliminary actions by pre-storing user credentials, instrument access rights, and TOTP secrets in databases before authentication is needed. When a user attempts to access an instrument, the authentication process quickly verifies pre-computed values without requiring real-time email or phone communication.
Data Source
Figure 1~2
Figure 3A~3B
AI summary
In a method for controlling access to an instrument (110) that is coupled to an interlock (112) device that controls access to the instrument (110), in which a user time- based one-time password that is unique to each user or project is periodically generated (312). A set of instrument time-based one-time passwords that correspond to each user time-based one-time password for the instrument is periodically generated (320). The set of instrument time-based one-time passwords is stored in the interlock device. The user time-based one-time password is received from a user (316). Only when the user time- based one-time password received from the user corresponds to one of the set of instrument time-based one-time passwords that is stored by the interlock device (326) then the interlock device is instructed to allow access to the instrument by the user (328). Parameters relating to use of the instrument by the user are recorded.