Ventilation System Authorization Code Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current ventilation systems face challenges in ensuring secure and protected access to therapy data, as existing methods are vulnerable to unauthorized access due to serial number and device code exposure, which can be compromised or misused.

Innovation Solution

A method that involves storing an authorization code on a data processing device, accessible only after user authentication and action, ensuring that the code is not visible externally and can only be used by authorized users for specific ventilators or groups, enhancing data protection and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If serial number and device code are printed on the ventilator for access, then ease of operation is improved, but data security deteriorates

Engineering Contradiction:
Improveaccess to therapy dataVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authorization code is extracted from the physical device and stored in a separate, secure memory location that is not externally visible. The code is kept in the data processing unit's memory rather than being printed on the device, separating the authentication mechanism from the physical ventilator unit.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authorization code changes dynamically based on time and usage parameters. Instead of a static printed code, the system generates different authorization codes at different times or under different conditions, making it impossible to use a photographed or copied code for unauthorized access.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If authorization code is stored in memory for remote access, then productivity is improved, but reliability deteriorates

Engineering Contradiction:
Improveremote data access efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The authorization code is preliminarily prepared and stored in secure memory before any remote access attempt. The system pre-generates and stores multiple valid authorization codes with associated time parameters, so that when remote access is requested, the system can immediately verify against pre-stored credentials without requiring real-time generation or external verification.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If device code is made accessible for authentication, then ease of operation is improved, but loss of information deteriorates

Engineering Contradiction:
Improveauthentication processVSAvoidauthorization code exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The authorization code is extracted from external visibility and stored exclusively in the device's internal memory. The code cannot be read from outside the device, preventing photographing or copying. The authentication process remains easy because the code is automatically provided through the user interface when needed, but the information itself is protected from external exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3340095B1Ventilation system and method
Publication Date: 2020.07.08 LOWENSTEIN MEDICAL TECH SA
  • EP3340095B1 patent drawingFigure 1

AI summary

The present invention relates to a method for operating a data processing unit (2) of a ventilation system (10) comprising a ventilator (1) and a remote unit (3) spatially separate from the ventilator (1), wherein therapy data can be transmitted between the ventilator (1) and the remote unit (3) via the data processing unit (2). At least one authorization code is stored in the data processing unit (2) by a user of the ventilation system (10) in order to obtain authorized access to the therapy data via the remote unit (3). The authorization code is only made available to the user when the user requests it by performing a user action on the data processing unit (2).