US 12,225,112 B2
Medical equipment, an authentication server and methods for authorizing a user access to an equipment via an equipment user interface
Jens Cameron, Lund (SE)
Assigned to Gambro Lundia AB, Lund (SE)
Appl. No. 17/757,818
Filed by GAMBRO LUNDIA AB, Lund (SE)
PCT Filed Dec. 14, 2020, PCT No. PCT/EP2020/085946
§ 371(c)(1), (2) Date Jun. 21, 2022,
PCT Pub. No. WO2021/122440, PCT Pub. Date Jun. 24, 2021.
Claims priority of application No. 1951502-2 (SE), filed on Dec. 19, 2019.
Prior Publication US 2024/0031133 A1, Jan. 25, 2024
Int. Cl. H04L 29/06 (2006.01); H04L 9/08 (2006.01); H04L 9/32 (2006.01)
CPC H04L 9/0825 (2013.01) [H04L 9/0844 (2013.01); H04L 9/3271 (2013.01); H04L 2209/88 (2013.01)] 8 Claims
OG exemplary drawing
 
1. A method for authorizing user access to medical equipment that is offline from an authentication server via an equipment interface, the method comprising:
storing an authority public key (QB) of an authority asymmetric key pair associated with the authentication server;
providing, to the user via the equipment interface, an authorization challenge indicative of an equipment public key (QA) of a temporary equipment asymmetric key pair generated in the medical equipment each time a user wants to access the medical equipment;
receiving, from the user via the equipment interface, a response code comprising validity information encrypted using a shared key derivable from an authority private key (dB) of the authority asymmetric key pair and the provided equipment public key (QA); and
authorizing, after determining that the validity information is valid, user access to the medical equipment, wherein the validity information is decrypted using the same shared key but derived in the medical equipment using the stored authority public key (QB) and an equipment private key (dA) of the temporary equipment asymmetric key pair,
wherein the authorizing additionally comprises authorizing the user access during a certain time period and authorizing different levels of the user access depending on information comprised in the response code.