Interface proxy device for network security
By mirroring the software services of medical devices onto a separate interface proxy box, the problem of rapidly responding to cybersecurity vulnerabilities in medical devices is solved, enabling fast and economical network security updates and device protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- F HOFFMANN LA ROCHE & CO AG
- Filing Date
- 2020-05-28
- Publication Date
- 2026-05-12
AI Technical Summary
Existing technologies are ill-equipped to respond quickly to cybersecurity vulnerabilities in medical devices, especially failing to meet the FDA's 30-day remediation requirement. Furthermore, existing solutions require customization for each device or include unnecessary services, which reduces device security.
By using an interface proxy box, the software services of medical devices are mirrored onto a separate interface proxy box, and unified management and updates are performed through a backend server, enabling rapid patching and updates, isolating security vulnerabilities, and providing a unified network security solution.
It enables rapid and economical response to cybersecurity issues of medical devices, reduces the cybersecurity workload of each device, improves device security and flexibility, and supports the reuse and expansion of multiple medical devices.
Smart Images

Figure CN116232705B_ABST
Abstract
Description
[0001] This application is a divisional application of application number 202010466773.4 filed on May 28, 2020, entitled "Interface Proxy Device for Network Security". Technical Field
[0002] This disclosure generally relates to cybersecurity for medical devices, and more particularly to the deployment of rapid cybersecurity updates for medical devices. Background Technology
[0003] Medical devices typically face stringent and ongoing cybersecurity requirements. As medical devices increasingly utilize more network interfaces and a growing number of off-the-shelf (OTSS) software components, timely response can be a significant challenge, as all of these can introduce vulnerabilities.
[0004] Currently, if a vulnerability such as WannaCry is discovered, each business unit within a company, along with the company's cybersecurity department, needs to determine if any business unit is affected and, if so, immediately define a method for resolving the issue. This is extremely expensive; for example, patching such a network vulnerability requires significant funding (e.g., one million CHF), and the slow, typical network vulnerability patching cycle can take approximately 6-12 months, thus failing to meet the 30-day timeline set by the FDA. One of the most serious issues might relate to vulnerabilities in libraries of exposed remote services. Fixing these service issues might require patching the infected libraries, which are often part of the medical device software, triggering a full software release. By separating / mirroring these services into a separate interface proxy box shared by all the company's medical devices, the vulnerable libraries can be patched for all medical devices at once within the separate interface proxy box without triggering individual software updates. Leaving the vulnerable libraries on the medical devices is acceptable because the libraries reside behind a patched and securely presented separate interface proxy box.
[0005] Prior art document U.S. Patent 9,485,218 discloses a protective device for preventing, detecting, and responding to security threats. However, the prior art does not address the problem of rapid patching to address issues such as FDA remediation time requirements. Nor does the prior art consider the differences in the underlying product it seeks to protect to accommodate the services it provides. Instead, the prior art proposes a scheme in which patching is either done for multiple instances or deployed as a generic product without product-specific enhancements. According to the concepts proposed in the prior art, the "security box" will either need to be customized for each specific product or contain too many services that a particular product may not need, thereby reducing the security of the underlying device in question. Summary of the Invention
[0006] A technical solution is provided to explicitly monitor all interfaces of a medical device to create a unified network security scheme on general interfaces that are easy to update and / or patch, thereby improving the network security of the medical device.
[0007] This invention relates to a system for providing network protection for medical devices in a medical environment. The system includes: a medical device including multiple software services; a backend server configured to maintain software updates and provide software updates to the medical device; and an interface proxy box connected to the medical device and communicating with the backend server. The interface proxy box is configured to identify the multiple software services residing on the medical device. The interface proxy box is configured to install the identified multiple software services residing on the medical device and configure the installed software services to match the multiple software services residing on the medical device. The interface proxy box is configured to periodically communicate with the backend server and receive security updates and apply the security updates to the multiple software services installed and configured on the interface proxy box. The medical device is configured to utilize the updated software services on the interface proxy box.
[0008] This invention provides a creative technical solution to address the FDA's requirement for rapid response to medical device security issues and vulnerabilities. The interface proxy box represents a security measure that can provide a certain level of network security for the underlying medical device. This invention provides an automated medical device-specific setup, allowing the mirroring and installation of specific software services of the medical device onto the interface proxy box, and enabling rapid updates to the libraries and software packages on the interface proxy box to ensure a minimal (and therefore reinforced) installation on the interface proxy box.
[0009] The interface proxy box includes a medical device interface configured to communicate with a medical device. The interface proxy box can communicate with the medical device wirelessly or via a wired connection. The interface proxy box is configured to have software services installed and configured on the interface proxy box that match or mirror software services residing on the connected medical device. The interface proxy box also includes a backend server interface configured to periodically communicate with a backend server. The backend server communicates with the interface proxy box via the backend server interface software service to update the libraries and software packages of the software services installed on the interface proxy box. The interface proxy box is configured to apply these software service library and software package updates to the software services installed and configured on the interface proxy box. The connected medical device then utilizes the updated software services installed on the interface proxy box.
[0010] Security vulnerabilities often enter medical device systems via connected interfaces (such as networking interfaces, USB, serial ports, Bluetooth, WiFi, etc.). Using this invention, these interfaces can be fed into an interface proxy box instead of being directly fed into the medical device. In one embodiment, the interface proxy box is configured to be internally located within the medical device itself.
[0011] In another embodiment, the interface proxy box is located externally to the medical device and communicates with the medical device via a communication network (such as, for example, an Ethernet connection). Alternatively, the interface proxy box can communicate with the medical device via a wired connection. Therefore, the interface proxy box then has a separately defined interface leading to the medical device. These multiple interfaces fed into the interface proxy box can then be monitored, and the interface drivers can be easily patched on the interface proxy box without any interaction with the medical device, thus avoiding the need for any re-verification of the medical device due to software updates and patches.
[0012] This allows for patching and updating of the SSL library on the interface proxy box, eliminating the need to patch and update the software services on the actual medical device itself. Furthermore, the USB mass storage device can offer its contents as a Server Message Block (SMB) share, and all security issues and vulnerabilities can be addressed through this interface proxy box without involving the medical device.
[0013] In one embodiment, the input device can be directly connected to an interface proxy box. The interface proxy box is configured to analyze any input signals from the input device before sending them to the medical device. The input device can be, for example, a barcode scanner, RFID receiver, keyboard, touchscreen, or a combination thereof. By analyzing the input at the interface proxy box, it is possible to check whether these inputs contain known SQL injection (or any other malicious injection) commands, thus providing an additional layer of network security for the medical device.
[0014] Furthermore, additional monitoring modules can be developed for the interface proxy box, thereby removing these monitoring tasks from the medical device itself. Therefore, the interface proxy box can be shared among several medical devices that may depend on this single input accessory.
[0015] In another embodiment, a virus scanner can also be added to the interface proxy box, and it can also be used in conjunction with packet inspection to implement a general firewall to resolve any targeted network attacks against the interface proxy box before the network attack can reach the medical device.
[0016] In another embodiment, support for all add-on modules can also be built into the interface proxy box along with support for integrated cloud-based remote services (such as for remote service activities, for example) to allow security features to be easily extended over time.
[0017] Because different medical devices rely on different software services, the interface proxy box needs to be adapted accordingly. This can be achieved by initially using an interface proxy box as a generic basic element version, which only detects the underlying software services of the medical device to be protected after the interface proxy box initially connects to the medical device. After the initial connection with the medical device and the identification of the medical device's software services, the interface proxy box can request only those specific libraries and packages associated with the specific software service settings of that particular medical device from the controlled backend server. This results in a repository of trusted software services being set up on the connected interface proxy box, providing a set of supported mirrorable software services that can be automatically configured based on the configuration of the underlying medical device host.
[0018] The interface proxy box can be a piece of physical hardware that is directly (preferably internally) connected to the medical device to be protected. This is necessary because there may be a need to update all the software (including the kernel and the like) on this interface proxy box. Since the software services on the medical device may still be slightly vulnerable (but not exposed because the medical device's only interface is directly connected to the interface proxy box), it is essential that people cannot directly access the software services from the medical device, but will always need to go through the interface proxy box.
[0019] By placing a hardware interface proxy box next to a medical system or device and connecting it to a communication network (such as LAN, Wi-Fi, or WAN), security and control mechanisms can be deployed more quickly, utilizing the independent lifecycle of the medical device or system. Network security and control mechanisms can begin with correctly identifying the medical device or system, concealing configured data, encrypting that data and transmission channels, complying with new security constraints (from customer regulations or internal requirements), leveraging the ability to simultaneously communicate with multiple channels using different protocols to redirect messages to different locations, and applying different control criteria to each channel using highly granular yet centralized configuration.
[0020] This approach is particularly advantageous for older, legacy medical devices that cannot be updated or patched due to the operating system installed on the medical device and / or due to outdated hardware issues preventing connection to the backend server.
[0021] This approach will reduce the cybersecurity workload for each medical device because the interface proxy box is reusable; it can be moved from one medical device to another and reconfigured to mirror a new device. The interface proxy box will also allow for a quick, easy, and affordable response to most cybersecurity issues. Essentially, the interface proxy box creates a defensive perimeter around the interface, protecting the medical device itself and allowing software updates to be postponed until the next "normal" software update while still maintaining a high level of security against everyday cybersecurity threats.
[0022] Isolated interface proxy boxes can also be used to implement certain security features in medical devices.
[0023] For example:
[0024] *Transmitting Results to Printer—The interface proxy box can transmit results and any other information to the printer protocol so that medical devices can be connected to the printer via the interface proxy box. If any new printer is added to the medical system environment, or if a customer needs to print more than one label of the same message, the interface proxy box can create multiple channels to different printers and transmit the message accordingly.
[0025] *Direct connectivity and message transformation for integration with EMR and enterprise solutions—Connecting medical devices and systems to other systems can involve complex message transformation and integration overhead. Implementing these features in each medical device can be expensive and requires inclusion throughout the device's lifecycle, which can be long or difficult to change. Interface proxy boxes allow for the development of custom drivers that can interact with both the medical device and the target system with the support of additional systems (if needed), enabling the integration functionality to be implemented and handled independently of the medical device itself.
[0026] * Integration with RFID readers for easy login processes in legacy devices—As regulations and the complexity of hospital / laboratory infrastructure change over time, new security requirements may emerge that still need to include all the functionality of each medical device, which may be difficult or impossible for manufacturers who do not want to include that medical device throughout its lifecycle. If the medical device implements workflows or events for verifying users, the interface agent box can be used as an interface to support new features such as verifying users via RFID, thereby simplifying the process and improving efficiency.
[0027] *Monitoring and Analysis—The interface agent box extends a company’s systems by implementing monitoring and analysis features without modifying the system’s internal behavior, enabling medical device companies to track the status of medical devices (including commercial events when available) and field systems, and to facilitate customer needs.
[0028] Isolating security vulnerabilities from connected interfaces into isolated interface proxy boxes has several advantages, as these boxes have defined interfaces leading to the main medical device. One such advantage is that the interface proxy boxes can be patched and updated without interfering with or affecting the main medical device.
[0029] Another important advantage is that the interface proxy box can self-configure for many different medical devices and only install the software required by the medical device it is physically connected to.
[0030] In addition, the interface proxy box has the following advantages: it can be reused or easily moved from one medical device to another.
[0031] Furthermore, the interface proxy box can support all additional modules, which can be built into the interface proxy box, thereby allowing for easy expansion of security features over time. The interface proxy box can also support integrated remote services, such as for remote service activities.
[0032] In another alternative embodiment, the interface proxy box can be manually updated, for example, by swapping out the interface proxy box or installing new features on it. This offers the advantage that the interface proxy box can operate without connecting to a backend server. However, using this embodiment, the timeline for addressing the security vulnerability may still be too long for regulatory agencies, and medical devices may remain vulnerable.
[0033] A computer-implemented method for providing network protection to medical devices in a medical environment is also provided. The method includes: connecting an interface proxy box to a medical device; connecting the interface proxy box to a backend server via a communication connection; obtaining detailed information about underlying software services residing on the medical device from the interface proxy box; requesting the underlying software services of the medical device from the backend server from the interface proxy box; receiving the software services of the medical device from the backend server and installing them onto the interface proxy box; configuring and mapping the software services of the medical device on the interface proxy box such that the software services installed on the interface proxy box mirror the software services associated with the underlying software services residing on the medical device; periodically synchronizing the interface proxy box with the backend server; receiving and applying updates and patches for the software services of the medical device installed and configured on the interface proxy box from the backend server when updates and patches are detected; and having the medical device utilize the updated medical device software services on the interface proxy box.
[0034] The computer-implemented method also includes: analyzing the input by an interface proxy box before the medical device receives input from the input device.
[0035] The computer-implemented method also includes connecting the interface proxy box to the medical device via a wireless connection (such as, for example, an Ethernet connection). The interface proxy box can also be connected to the medical device via a direct connection (such as, for example, a USB connection).
[0036] In one embodiment, the following steps are performed manually: receiving security updates from the backend server and applying the security updates to the libraries installed and configured on the interface proxy box.
[0037] In one embodiment, updates and patches are security updates. When such security vulnerabilities are detected, these security updates can be installed and configured on the interface proxy box.
[0038] In one embodiment, the following steps are performed manually: receiving updates and patches from the backend server and applying the updates and patches to the libraries installed and configured on the interface proxy box.
[0039] In summary, the interface proxy box allows for a quick, easy, and affordable response to most cybersecurity issues, creating a defensive perimeter around the interface before such cybersecurity problems can reach the connected medical device. Furthermore, any updates or patches to the software services residing on the interface proxy box will not depend on software updates or patches for the connected medical device. Attached Figure Description
[0040] The following detailed description of specific embodiments of this disclosure will be best understood when read in conjunction with the accompanying drawings, in which similar structures are indicated by similar reference numerals, and wherein:
[0041] Figure 1 The illustration shows a schematic arrangement of a box according to an embodiment of the present disclosure.
[0042] Figure 2 The illustration shows the workflow of the configuration process for an interface proxy box according to an embodiment of the present disclosure.
[0043] Figure 3 The illustration shows a workflow for updating an interface proxy box according to an embodiment of the present disclosure. Detailed Implementation
[0044] In the following detailed description of the embodiments, reference is made to the accompanying drawings, which form a part of the detailed description, and specific embodiments in which the present disclosure may be practiced are shown in an illustrative rather than limiting manner. It should be understood that other embodiments may be utilized, and logical, mechanical, and electrical changes may be made without departing from the spirit and scope of the present disclosure.
[0045] Certain terms will be used in this patent application. The composition of the terms should not be construed as being limited by the particular terms chosen, but rather as relating to the general concept that follows the particular term.
[0046] As used below, the terms “have,” “contain,” or “include,” or any grammatical variations thereof, are used in a non-exclusive manner. Therefore, in addition to the features introduced by these terms, they can also refer to either the absence of other features in the entity described in the context, or the presence of one or more other features. For example, the statements “A has B,” “A contains B,” and “A includes B” can refer to two cases: that no other elements exist in A besides B (i.e., A consists solely and exclusively of B), and that entity A contains one or more other elements besides B (such as element C, elements C and D, or even other elements).
[0047] Furthermore, it should be noted that the terms "at least one," "one or more," or similar expressions indicating that a feature or element may exist once or more will generally be used only once when the corresponding feature or element is introduced. In the following text, in most cases, the expressions "at least one" or "one or more" will not be repeated when referring to the corresponding feature or element, even though it is true that the corresponding feature or element may exist once or more.
[0048] As used herein, the term "medical device" encompasses any device or device component operable to perform one or more processing steps / workflow steps on one or more medical devices or systems. The term "processing step" refers here to physically performed processing steps, such as centrifugation, pipetting, aliquoting, reagent preparation, quality control (QC) preparation, sequencing library preparation, incubation, sample analysis, and sample transport.
[0049] As used herein, the term "communication network" encompasses any type of wireless network (such as Wi-Fi, GSM, UMTS, or other wireless digital networks) or cable-based network (such as Ethernet or the like). For example, a communication network includes a combination of wired and wireless networks. In embodiments where the units of a system are included within a medical device, the communication network includes communication channels within the medical device.
[0050] First refer to Figure 1 , Figure 1 The illustration shows a schematic setup for configuring the interface proxy box 7. Typically, the interface proxy box 7 is a generic interface proxy box, meaning it does not have any software services installed on it. Initially, the interface proxy box 7 is directly connected to medical devices 5b and 6b via a communication network 9, such as, for example, an Ethernet connection within medical systems 5a and 5b. In another embodiment, the interface proxy box 7 is integrated into and directly connected to the medical devices 5b and 6b themselves.
[0051] After establishing the first connection 9 between the interface proxy box 7 and the medical devices 5b and 6b, the interface proxy box 7 communicates with the medical devices 5b and 6b via the communication connection 9, and identifies the software service 10 residing on and used by the medical devices 5b and 6b. For example, and as... Figure 1 As shown, in the first medical system 5a, the interface proxy box 7 determines that the medical device 5b has A, D and F software services 10 installed on the medical device 5b, and in the second medical system 6a, the interface proxy box 7 determines that the medical device 6b has B and F software services 10 installed on the medical device 6b.
[0052] Then, the interface proxy box 7 requests from the backend server 1 (via another communication network, such as, for example, the Internet / cloud 3) the latest versions of the software service 10 library 2a-f associated with those specific software services 10 residing on specific medical devices 5b, 6b. For example, and as... Figure 1 As shown, the interface proxy box 7 connected to medical device 5b will request libraries 2a, 2d, and 2f from the backend server 1, while the interface proxy box 7 connected to medical device 6b will request libraries 2b and 2f. Depending on the specific software service 10 residing on medical devices 5b and 6b, the interface proxy box 7 installs those specific software services 10 and configures itself to match or mirror the software services 10 residing on the specific medical devices 5b and 6b connected to it. Therefore, the interface proxy box 7 is customized for the specific medical devices 5b and 6b to which it is connected. Thus, due to the customization process during the setup of the interface proxy box 7, only one type of interface proxy box 7 is needed for all types of medical devices 5b and 6b. Furthermore, the interface proxy box 7 is reusable and interchangeable across all types of medical devices.
[0053] Interface proxy box 7 synchronizes itself (again via a network connection such as, for example, the Internet / Cloud 3) with backend server 1 periodically / on a schedule as needed. If, during synchronization, it is determined that any software service 10 installed on medical devices 5b and 6b requires an update or patch, backend server 1 will provide the update and / or patch to specific libraries 2a-f for those specific software services 10 installed on medical devices 5b and 6b on interface proxy box 7. Medical devices 5b and 6b will then use those updated and / or patched libraries 2a-f installed on interface proxy box 7.
[0054] Go to Figure 2 , Figure 2 The swimlane diagrams of backend server 1, interface proxy box 7, and medical devices 5b and 6b illustrate a typical workflow for the initial configuration process of interface proxy box 7.
[0055] Beginning in step 15, the new universal interface proxy box 7 connects to medical devices 5b and 6b via a communication connection (such as, for example, Ethernet connection 9 or a USB device). In step 20, the interface proxy box 7 requests and obtains information about a specific basic software service 10 residing on medical devices 5b and 6b via the communication connection between the interface proxy box 7 and medical devices 5b and 6b (such as, for example, Ethernet connection 9 or a USB device). In step 30, medical devices 5b and 6b, in conjunction with the request from the interface proxy box 7 via a communication connection such as, for example, Ethernet connection 9 or a USB device, transmit information about the specific basic software service 10 of medical devices 5b and 6b.
[0056] Based on the software service 10 information received by medical devices 5b and 6b in step 30, in step 40, the interface proxy box 7 requests, via another communication connection such as the Internet / cloud 3, the necessary libraries 2a-f for the specific software service 10 set up for the connected medical devices 5b and 6b. In step 50, the backend server 1, via another communication connection such as the Internet / cloud 3, combines the request from the interface proxy box 7 with the request to send the requested software service 10 libraries 2a-f to the interface proxy box 7.
[0057] In step 60, the requested software services 10 of the connected medical devices 5b and 6b, as well as the libraries 2a-f associated with those software services 10 of the connected medical devices 5b and 6b received from the backend server 1, are installed on the interface proxy box 7.
[0058] In step 70, the installed software service 10 received from the backend server 1 is securely configured on the interface proxy box 7 according to the specific software service settings of medical devices 5b and 6b.
[0059] Finally, in step 80, the interface proxy box 7 mirrors or maps data from libraries 2a-f from the mirror software service now configured and installed on the interface proxy box 7 to a specific software service 10 residing on the medical devices 5b, 6b of the underlying connection.
[0060] Now, turn to Figure 3 , Figure 3 The swimlane diagrams using backend server 1, interface proxy box 7, and medical devices 5b and 6b illustrate the workflow for updating interface proxy box 7 after initial connection, installation, and configuration of medical devices 5b and 6b via communication connection 9 such as an Ethernet connection or USB device.
[0061] In step 200, the interface proxy box 7 periodically synchronizes / communicates with the backend server 1 via other communication connections such as, for example, the Internet / cloud 3. Synchronization / communication may be based on a schedule, or it may occur when new patches or updates for the software service 10 for the connected medical devices 5b, 6b are available, or both.
[0062] In step 100, the backend server 1 has a library of software services 10 and / or new patches and / or updates for configurations 2a-f for the connected medical devices 5b and 6b. In one embodiment, a new patch or update could be a newly discovered security vulnerability. Because the backend server 1 and the interface proxy box 7 periodically synchronize / communicate via other communication connections such as the Internet / Cloud 3, in step 400, new updates / patches of the library / configurations 2a-f for the software services 10 for the connected medical devices 5b and 6b are sent to the interface proxy box 7 via other communication connections such as the Internet / Cloud 3. Therefore, once the library or configuration 2a-f update / patches for the connected medical devices 5b and 6b are created at the backend server 1, the interface proxy box 7 can theoretically receive the updated version from the backend server 1.
[0063] In step 300, the interface proxy box 7 requests only the updated library / configuration 2a-f patches for the software service 10 of the connected medical devices 5b and 6b, which are necessary for the specific software service settings residing on the connected medical devices 5b and 6b.
[0064] Therefore, in step 500, the interface proxy box 7 can ensure the existence of a trusted software service repository that is separate from the software service 10 residing on the connected medical devices 5b and 6b, and protect the software service 10 residing on the connected medical devices 5b and 6b from potential network threats and attacks by providing an additional layer of protection.
[0065] Finally, in step 600, medical devices 5b and 6b can then use the updated software service 10 library 2a-f, which is installed and configured on the interface proxy box 7. This workflow enables medical devices 5b and 6b to run the updated software service 10 on the interface proxy box 7, and thus reduces the risk of network vulnerabilities in near real-time.
[0066] A computer program product is further disclosed and proposed, comprising computer-executable instructions for performing the methods disclosed in one or more embodiments included herein when the program is executed on a computer or computer network. Specifically, the computer program may be stored on a computer-readable data carrier or a server computer. Thus, specifically, one, more, or even all of the method steps described above can be performed by using a computer or computer network, preferably by using a computer program.
[0067] As used herein, computer program products refer to programs as tradable products. Products can typically exist in any format (such as paper) or on a computer-readable data carrier, either locally or in a remote location. Specifically, computer program products can be distributed across data networks (such as cloud environments). Furthermore, not only computer program products, but also the hardware executing them can reside in local or cloud environments.
[0068] A computer-readable medium including instructions that, when executed by a computer system, cause a laboratory system to perform a method according to one or more embodiments disclosed herein.
[0069] A modulated data signal including instructions, when executed by a computer system, causes a laboratory system to perform a method according to one or more embodiments disclosed herein.
[0070] Referring to the computer implementation aspects of the disclosed methods, one or more method steps, or even all method steps, of the methods according to one or more embodiments disclosed herein can be performed using a computer or computer network. Therefore, generally, any method steps, including providing and / or manipulating data, can be performed using a computer or computer network. Typically, these method steps can include any method steps, generally except for method steps requiring manual work, such as providing samples and / or performing certain aspects of actual measurements.
[0071] It should be noted that terms such as “preferredly,” “usually,” and “typically” are not used herein to limit the scope of the claimed embodiments or to imply that certain features are critical, necessary, or even important to the structure or function of the claimed embodiments. Rather, these terms are intended only to highlight alternative or additional features that may or may not be utilized in particular embodiments of this disclosure.
[0072] Having been described in detail and with reference to specific embodiments thereof, it will be apparent that modifications and variations are possible without departing from the scope of the disclosure as defined in the appended claims. More specifically, although some aspects of the disclosure are identified herein as preferred or particularly advantageous, it is contemplated that the disclosure is not necessarily limited to these preferred aspects.
Claims
1. A system (5a, 6a) for providing network protection to medical devices (5b, 6b) in a medical environment, said system (5a, 6a) comprising: Medical devices (5b, 6b) include multiple software services (10); The backend server (1) is configured to maintain software updates for the software service (10) and provide the software updates to medical devices (5b, 6b), wherein the software updates are used to update the software library and software packages of the software service installed on the interface agent box; and An interface proxy box (7) is connected to medical devices (5b, 6b) and communicates with a backend server (1), wherein the interface proxy box (7) is configured to: identify the plurality of software services (10) residing on the medical devices (5b, 6b); install software libraries (2a-f) on the interface proxy box (7) associated with the plurality of software services (10) identified as residing on the medical devices (5b, 6b); and configure the installed software libraries (2a-f) to mirror the plurality of software services (10) residing on the medical devices (5b, 6b), wherein the interface proxy box (7) is configured to periodically communicate with the backend server (1) and receive software updates for the software services (10) and apply the software updates to the plurality of software libraries (2a-f) installed and configured on the interface proxy box (7), and wherein the medical devices (5b, 6b) are configured to utilize the updated software libraries (2a-f) on the interface proxy box (7).
2. The system (5a, 6a) according to claim 1, wherein, The interface proxy box (7) is internally connected to the medical device (5b, 6b).
3. The system according to claim 1 or 2 (5a, 6a), wherein, The interface proxy box (7) is externally connected to the medical device (5b, 6b).
4. The system according to claim 3 (5a, 6a), wherein, The interface agent box (7) is externally connected to the medical device (5b, 6b) via a wireless and / or wired connection (9).
5. The system according to claim 1 or 2 (5a, 6a) further comprises: An input device connected to an interface proxy box (7), wherein the interface proxy box (7) is configured to analyze the input before sending the input from the input device to the medical device (5b, 6b).
6. The system according to claim 5 (5a, 6a), wherein, The input device is a barcode scanner, an RFID receiver, a keyboard, a touchscreen, or a combination of the above.
7. An interface proxy box (7) included in the system of claim 1, the interface proxy box (7) comprising: A medical device interface is configured to communicate with medical devices (5b, 6b), wherein an interface proxy box (7) is configured to have software libraries (2a-f) installed and configured on the interface proxy box (7), the software libraries (2a-f) mirroring software services (10) residing on the medical devices (5b, 6b); and A backend server interface is configured to communicate periodically with a backend server (1), wherein the backend server (1) transmits software service updates for software libraries (2a-f) installed on an interface proxy box (7) via the backend server interface, wherein the interface proxy box (7) is configured to apply the software service updates to software libraries (2a-f) installed and configured on the interface proxy box (7), and wherein medical devices (5b, 6b) utilize the updated software libraries (2a-f) installed on the interface proxy box (7).
8. The interface proxy box according to claim 7, wherein, The interface proxy box (7) is reusable.
9. The interface proxy box according to claim 7 or 8, wherein, The software service (10) includes a software library (2a-f) for the medical devices (5b, 6b).
10. The interface agent box according to claim 7 or 8 further includes a virus scanner.