Two-Certificate Network Attachment for Medical Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Wi-Fi architectures, such as those using the C4MI platform, do not allow wireless medical devices to access networks outside their specific clinical network configuration, limiting their ability to communicate across multiple network tiers.

Innovation Solution

A system and method for secure, automated network discovery and attachment using a two-certificate authentication scheme, where a Wi-Fi module and a functionality module of a purpose-built device interact with an authentication, authorization, and accounting server, and an application server to securely attach to a provider network, employing Passpoint and C4MI protocols for multi-tiered network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single-certificate authentication scheme is used for network attachment, then the authentication process is simpler and faster, but the device cannot access multiple network tiers and lacks fine-grained security control

Engineering Contradiction:
Improvenetwork tier accessibilityVSAvoidauthentication scheme complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication scheme is segmented into two distinct certificates: a first certificate for initial network attachment and a second certificate for accessing additional network tiers. This segmentation allows the device to authenticate at different security levels corresponding to different network layers, enabling multi-tier access while maintaining clear separation of authentication functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication system is designed to be universal across multiple network tiers. The same device and authentication infrastructure can handle both single-tier and multi-tier access scenarios, making the system adaptable to different deployment configurations without requiring separate authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If manual network connection procedures are used, then authentication security is maintained, but user convenience and network attachment speed are reduced

Engineering Contradiction:
Improvenetwork attachment automationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Security credentials (both certificates) are pre-configured in the device before deployment. The authentication process is automated through pre-established protocols and server configurations, eliminating the need for manual user intervention while maintaining security through pre-validated credential verification processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device autonomously performs network discovery, certificate selection, and authentication without requiring manual user input. The system self-manages the complex multi-certificate authentication process, including automatically presenting the appropriate certificates to the authentication server and handling the verification workflow.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security verification is implemented across all network access points, then unauthorized access is prevented, but network attachment time and processing overhead increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidnetwork attachment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security verification is segmented into two distinct phases corresponding to the two certificates. The first certificate provides rapid initial authentication for basic network access, while the second certificate provides additional verification only when accessing higher-security network tiers. This segmented approach prevents unauthorized access at each layer while minimizing overall attachment time through progressive verification.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11924192B2Systems and methods for secure automated network attachment
Publication Date: 2024.03.05 CABLE TELEVISION LAB INC
  • US11924192B2 patent drawing
  • US11924192B2 patent drawing
  • US11924192B2 patent drawing

AI summary

A method for automatically attaching a purpose-built electronic device to a provider network includes steps of discovering, by a Wi-Fi module of the purpose-built electronic device, a wireless data network in operable communication with the provider network selecting, by the Wi-Fi module, the wireless data network, transmitting a primary authentication certificate from the Wi-Fi module to an authentication, authorization, and accounting server of the provider network, receiving, by an application server of the provider network, a secondary authentication certificate from a functionality module of the purpose-built electronic device authenticating, by the provider network, the primary and secondary authentication certificates, and attaching the purpose-built device to the provider network.