SSL Certificate-Based Medical Device Software Licensing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current software licensing methods either offer limited security with simple static license keys or high complexity and cost with dedicated license servers, and lack dynamic revocation capabilities, making them unsuitable for scalable and secure deployment.
Innovation Solution
Implementing a system that uses Secure Socket Layer (SSL) certificates for authentication and authorization, allowing for dynamic enabling or disabling of software features from a central location, with time and space variation capabilities, and integrating asset tracking and secure licensing processes using a Transport Layer Security (TLS) mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If static license keys are used for software licensing, then deployment complexity is minimized, but security protection is limited
Solution Approach 1:
The patent segments the licensing system into multiple components: static license keys for initial deployment, periodic license files for ongoing validation, and certificate authorities for security management. This segmentation allows the system to maintain simple deployment while incorporating enhanced security mechanisms that operate independently.
Solution Approach 2:
The patent introduces periodic license files as intermediaries between the static license keys and the software application. These license files act as mediators that contain cryptographic signatures and validation data, enabling enhanced security verification without requiring direct complex authentication mechanisms between the license key and application.
2Reliability
If dedicated license servers are implemented, then security protection is maximized, but deployment and maintenance complexity increases
Solution Approach 1:
The patent extracts the core security validation functionality from complex dedicated license servers and encapsulates it in periodic license files that can be independently generated and validated. This extraction allows security mechanisms to be distributed and managed without requiring centralized server infrastructure, reducing deployment and maintenance complexity while maintaining security.
Solution Approach 2:
The patent implements self-service licensing where the software application autonomously validates periodic license files using embedded cryptographic verification mechanisms. The system performs self-verification of license authenticity and feature entitlements without requiring continuous connection to or management of dedicated license servers, thereby reducing operational complexity.
3Duration of action of stationary object
If periodic license files are used, then license expiration can be enforced, but dynamic revocation capability is lost
Solution Approach 1:
The patent implements feedback mechanisms where the software application continuously monitors the validity of periodic license files and reports status to authorized management systems. This feedback loop enables authorized users to revoke licenses by generating new license files with updated cryptographic signatures, maintaining dynamic control while preserving expiration enforcement through the periodic validation cycle.
Data Source
AI summary
A system and method of enabling software features on medical devices uses a local server disposed at a medical facility and a license server remote from the local server. The method includes generating a software enabling indicator at the license server, the software enabling indicator comprising a numerical code representing a number of licenses to be allocated for a software feature. The method includes providing a digitally signed electronic document based on the software enabling indicator, transmitting the electronic document from the license server to the local server, and authenticating the license server at the local server using the electronic document. The method includes generating at the local server a plurality of second digital certificates based on the software enabling code, transmitting the second digital certificates to each of the medical devices, and enabling a software feature on the medical devices based on the second digital certificates.


