COMMUNICATION AND AUTHENTICATION PROCEDURES OF RADIO-CONNECTED MEDICAL DEVICES TO A COMMUNICATION NETWORK-CONNECTED ORDERING SYSTEM

DE502023004591D1Active Publication Date: 2026-07-30B BRAUN MELSUNGEN AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
B BRAUN MELSUNGEN AG
Filing Date
2023-04-06
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

Existing wireless communication systems for infusion pumps in medical settings are vulnerable to data security threats due to insecure data transmission protocols, particularly infrared-based communication buses, which can be exploited.

Method used

A secure authentication procedure is implemented using a direct point-to-point connection between medical devices and a central communication device, involving the generation and exchange of local and global secrets to establish a secure wireless connection, such as Wi-Fi, through cryptographic hash functions like HMAC-SHA256, ensuring data integrity and confidentiality.

Benefits of technology

Enhances data security for sensitive patient information and medication control by establishing a secure wireless connection, protecting against unauthorized access and ensuring reliable communication between infusion pumps and hospital networks.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The present disclosure relates to a communication and authentication method of wireless medical devices, e.g. infusion pumps, to an organizational system, e.g. a rack, which physically houses the wireless medical devices and which in turn is integrated into a communication network, e.g. a hospital network. Background of the invention

[0002] Developments in modern medicine, particularly in intensive care, have led to infusion therapies that require the targeted use and precise dosing of highly effective medications. Depending on the patient's condition, these therapies often necessitate the administration of multiple medications and, optionally, parenteral nutrition. In medical and therapeutic settings, this frequently involves the interconnection of several different medical devices. Infusion pumps for the intravenous administration of medications or nutrients are an example of this and have become indispensable in areas such as operating rooms, intensive care units, oncology, pain management, clinical nutrition, and more. Both single infusion pumps and multiple interconnected pumps can be used, allowing for the infusion of various substances and dosages, as well as specific configurations for different infusion therapies for a single patient.

[0003] To simplify the bundling of various medical devices for a patient, and to be able to group them together physically or spatially, e.g. next to the bed of the patient concerned, various organizational systems exist, e.g. racks.

[0004] From WO 2015 / 124670 A1 or EP 3 108 390, a rack for infusion pumps is known that is connected to a hospital network (via an access point) via a wireless Wi-Fi connection. Each infusion pump is connected to a data bus of the rack upon insertion. The infusion pumps are also Wi-Fi-enabled, so that, for example, in the event of a communication error within the rack, they can switch to or fall back on a direct Wi-Fi connection to the hospital network (via the access point).

[0005] A rack containing infusion pumps is known from the company's internal state of the art, whereby the rack and the infusion pumps use a data bus for communication that operates via infrared. This data transmission is vulnerable to attack.

[0006] US 2023 / 038869 A1 discloses a computer-implemented method that includes determining the position of a plurality of infusion pumps in a pump stack containing the plurality of infusion pumps and a fluid supply associated with each of the plurality of infusion pumps. Further prior art is known from US 2017 / 149567 A1 and US 2015 / 351847 A1. Brief description of the invention

[0007] The purpose of this disclosure is to increase data security for a wireless connection, e.g., WIFI, between an organizational system, e.g., a rack, and a medical device, e.g., an infusion pump.

[0008] This problem is solved by the combination of features of claim 1.

[0009] The arrangement according to the disclosure comprises one or preferably several medical devices, e.g., infusion pumps, and further, at least one storage system, e.g., a rack or column, or several racks or columns, with at least one or preferably several receptacles for the medical device(s). Each medical device has a device, and each receptacle of the storage system has a comparable device, for generating a direct point-to-point connection. The storage system includes a central communication device (ComSystem).The communication device and the medical device, in particular a communication module of the medical device, are configured and programmed such that, after the establishment of the direct point-to-point connection, a communication channel is first established between the communication device and the medical device, in particular its communication module (the communication channel is still unsecured at this point), and then data for calculating a security key, with a local secret, e.g., a signature, is transmitted from the communication device via the communication channel to the medical device, in particular to its communication module. Furthermore, the medical device, in particular its communication module, is configured and programmed to then use the data for calculating the security key with the local secret and a global secret uniformly assigned to the entire system, e.g., a signature, to generate a security key.A certificate is used to calculate a security key, for example, a Pre-Shared Key (PSK). This security key is then used to establish a secure wireless connection between the communication device and the medical device, specifically its communication module. This secure wireless connection is used to transmit medical data and / or control data (e.g., for the infusion pump) and / or status data (e.g., of the infusion pump) between the medical device and the communication device.

[0010] The arrangement, as revealed, uses the system as a transmission medium for the local secret and then establishes the encrypted radio connection. Furthermore, the radio connection is established whenever the medical device is plugged into the system and it is detected that a communication device is connected to it.

[0011] In other words, the disclosure provides an authentication procedure for medical devices, e.g., infusion pumps, that are inserted into an organizational system, e.g., a rack of the system. Upon approach or insertion, a first, initially insecure and potentially slower, direct point-to-point connection is established between the medical device, in particular its communication module, and the communication device of the organizational system. Following the establishment of this connection, a communication channel is created between the medical device, in particular its communication module, and the communication device, whereby this communication channel is unsecured.The authentication process is started or triggered by the establishment of this communication channel in order to subsequently establish a secure radio connection between the medical device, in particular its communication module, and the communication device.

[0012] This authentication procedure ensures data security for sensitive patient-specific data, such as the transmission of sensitive patient data, medications, and infusion pump flow rates.

[0013] The direct point-to-point connection can be implemented optically, via cable, or wirelessly. In one specific implementation, this is an infrared connection.

[0014] In the case of particularly advanced training or expansion of the system, the communication device is connected to a hospital network. This enables centralized control of multiple medical devices included in the system. This allows for the centralization of expertise in operating the devices and precisely considering patient-specific data, such as the appropriate setting of the various flow rates of the infusion pumps within the hospital.

[0015] Special data security is ensured when the connection between the communication device and the hospital network is wired.

[0016] The authentication procedure is preferably further developed in such a way that the local secret is specifically stored and generated in advance on the communication device, and that a global secret (Hospital Secret) is also stored in advance on the medical devices, in particular their communication modules and the communication device.

[0017] Hospitals often have multiple racks and therefore multiple communication devices. The arrangement according to the disclosure then includes this plurality of racks with their respective associated communication devices. In this case, the same global secret is pre-stored on all communication devices.

[0018] To save time during authentication, the data for calculating the security key is preferably pre-calculated and stored on the at least one communication device based on the global secret and the local secret.

[0019] The word "vorab" used several times here means "before the creation of the wired connection".

[0020] The following refers to only one communication device and one medical device, although—as explained—multiple devices may be involved, in which case the aforementioned training should be provided for all medical devices or all communication devices. The local secret differs on different communication devices. Only the global secret is identical for all participating devices (in the arrangement).

[0021] Preferably, the security key is calculated on the communication device and on the medical device by means of a respective key generation unit or key generator. In the case of the medical device, this is preferably located on its communication module and / or programmed there.

[0022] It is particularly preferred if the two key generation units or key generators are HASH-based key generation units or HASH-based key generators, in particular programmed with an HMAC-SHA256 approach.

[0023] Preferably, the data used to calculate the security key is encrypted, meaning it is not transmitted in plaintext from the communication device. Similarly, the data used to calculate the security key is preferably decrypted on the medical device. This further enhances data security.

[0024] It is particularly preferred that the medical device be configured and programmed to request the data for calculating the security key via the communication channel after the direct point-to-point connection has been established and the communication channel has been set up. The data for calculating the security key is then transmitted from the communication device to the medical device.

[0025] In a particularly preferred further development of the open-type arrangement, the communication device is configured and programmed so that the data for calculating the security key includes an identifier of the communication device or the radio network. This can be done together with the local secret in a common data envelope.

[0026] The secure wireless connection is preferably a WIFI or WLAN connection that is secured according to a WLAN security standard, e.g. WIFI Protected Access 2 (WPA2).

[0027] If the identifier of the communication device or radio network and the further development of the radio connection are intended to be a Wi-Fi or WLAN connection, then the identifier is a Service Set Identifier (SSID). In this case, it is particularly preferred, if the communication device and the medical device are configured and programmed, that the data for calculating the security key also includes the identifier of the communication device or radio network, in particular the Service Set Identifier (SSID), in order to transmit the Service Set Identifier (SSID) together with the local secret from the communication device to the medical device via the communication channel.

[0028] The secure wireless connection can also be a Bluetooth connection or a mobile network connection, e.g. 3G, 4G or LTE.

[0029] Data security is further increased if the medical device, in particular its communication module, is programmed and configured to detect a physical separation of the two devices and subsequently interrupt the secure radio connection. Brief description of the characters

[0030] Fig. 1 shows an arrangement according to the embodiment shown in the present disclosure; Fig. 2 shows a section of the rack from Fig. 1 without infusion pumps; Fig. 3 schematically shows the distribution of the global secret across the devices of the arrangement. Fig. 1 ; and Fig. 4 schematically shows the arrangement of Fig. 1 with the two secrets of the communication device. Fig. 5 schematically shows an overview of the communication and authentication process according to an embodiment of the present disclosure; Description of the exemplary embodiment

[0031] An embodiment of the present disclosure is described below on the basis of the accompanying figures.

[0032] The in Fig. 1 The illustrated embodiment of the arrangement has four infusion pumps 1, each with a processor (not shown) and with a (in Fig. 3 (Schematically depicted) communication module 2 according to the WIFI standard. The arrangement also includes an organizational system designed as a single rack 3 and a communication device 4 (ComSystem) connected to or integrated into the rack 3. The communication device 4 enables a wired (e.g., Ethernet) or wireless connection via cable 5 to a hospital network.

[0033] This arrangement is designed to stand next to a patient's bed and to supply the patient (in this case four) with various fluids, especially medications, via the respective infusion pumps 1.

[0034] In the illustrated embodiment, the communication device 4 can be represented as a kind of WIFI access point for the infusion pumps 1 placed in the rack 3.

[0035] Fig. 2 shows a section of Rack 3 from Fig. 1 without infusion pumps 1. Therefore, the recordings 6 of rack 3 are for the (in Fig. 1 The infusion pumps 1 shown are recognizable. Each inset 6 has an infrared-based optical device 8, which is designed to establish a connection between the communication module 2 and a communication bus of the rack 3 by means of a corresponding pump-side optical device also based on infrared (not shown).

[0036] Fig. 3 This shows that during the initial setup of the arrangement, a global secret 9 (Hospital Secret) is generated using a random method and stored in a secure data storage location on the communication device 4. The global secret 9 is generated on one communication device 4 and can subsequently be used on all other devices in the arrangement. This global secret 9 can be downloaded in encrypted form from the communication device 4 by a service technician in order to later distribute it to the communication modules 2 of the infusion pumps 1 that are to be connected to the communication device 4.

[0037] According to Fig. 4 Does the communication device 4 additionally generate a local secret 12, e.g., a device signature of the communication device 4, and a Service Set Identifier (SSID) during or before authentication? Fig. 4 (not shown). This data is also stored in the secure data storage of communication device 4.

[0038] Fig. 5 Figure 1 shows an overview of a communication and authentication process. When an infusion pump 1 is plugged into a slot 6 of rack 3, the communication module 2 of the infusion pump 1 detects the communication device 4 connected to the rack 3. A communication channel 7 is then established between the communication device 4 and the communication module 2 of the infusion pump 1. A handshake takes place between the communication module 2 of the infusion pump 1 and the communication device 4 via communication channel 7 to establish a secure, encrypted Wi-Fi connection between the communication module 2 and the communication device 4.

[0039] Following successful authentication, the exchange of medical data and / or patient-related data and / or pump data between infusion pump 1 and the hospital's preferably wired network is enabled. This data exchange takes place between the communication module 2 of infusion pump 1 and the hospital network via the communication device 4 of rack 3. A wireless connection, secured, for example, by Wi-Fi Protected Access II (WPA2), exists between communication module 2 and communication device 4.

[0040] The local secret 12 and the global secret 9 form the input parameters for a hash-based key generator, which uses an HMAC-SHA256 approach to generate the pre-shared key. The pre-shared key is used to establish the Wi-Fi access point to which the infusion pumps 1 can connect via their communication modules 2. In addition to the pre-shared key, the service set identifier (SSID) is also required for the wireless connection between the communication device 4 and the communication modules 2.

[0041] Communication device 4 generates and stores the data necessary for calculating the pre-shared key. The first request for this data occurs after infusion pump 1 is plugged into rack 3 and via communication channel 7. Communication module 2 of infusion pump 1 requests the data required for calculating the pre-shared key from communication device 4 via the data bus of rack 3, which in turn forwards this data to communication module 2.

[0042] To maximize data security, the data used to generate the secret is neither transmitted nor stored in plaintext. Similarly, the data exchanged is not directly used as the secret; that is, the transmitted data does not correspond to the secret. The transmitted data is merely used as input to generate the pre-shared key using cryptographic hash functions (e.g., a key derivation function). Once this key exists or has been generated, the aforementioned encrypted / secure wireless connection can be established.

[0043] When the infusion pump is removed from rack 3, this is detected by infusion pump 1 and this information is forwarded to its communication module 2. Communication module 2 then terminates the existing radio connection between infusion pump 1 and communication device 4.

[0044] If a hospital uses more than one organizational system 3 with its corresponding communication device 4, which is common practice, this Wi-Fi access point mechanism can be used to connect additional infusion pumps 1 to further communication devices 4. Crucially, the same global secret 9 (Hospital Secret) of the first communication device 4 is used on the additional communication devices 4 to enable the connection of all infusion pumps 1 in different organizational systems 3. After the global secret 9 has been distributed to the additional communication devices 4, each generates its own Service Set Identifier (SSID) and Pre-Shared Key. When an infusion pump 1 is plugged into a different organizational system 3 with a different communication device 4, the authentication method described above is applied. Each organizational system 3 can be a single rack or column, or multiple racks or columns. Reference symbol list:

[0045] 1 Medical device / Infusion pump 2 Communication module 3 Organization system / Rack 4 Communication device 5 Cable 6 Recording 7 Communication channel 8 Device for creating a direct point-to-point connection 9 Global secret 12 Local secret

Claims

1. An assembly with at least one medical device (1), in particular an infusion pump, which comprises a device for generating a direct point-to-point connection, and with an organization system (3), which comprises at least one receptacle (6) for the medical device (1) and a device (8) for generating the direct point-to-point connection, wherein the organization system (3) further comprises a communication device (4), characterized in that the communication device (4) and the medical device (1) are configured and programmed to set up a communication channel (7) after the direct point-to-point connection has been generated and to transmit data for calculating a security key with a local secret (12) from the communication device (4) to the medical device (1) via the communication channel (7), wherein the medical device (1) is configured and programmed to calculate the security key, in particular a pre-shared key, from the transmitted data for calculating the security key with the local secret (12) and from a global secret (9), in order to generate a secure radio connection for transmitting medical data and / or control data between the medical device (1) and the communication device (4).

2. The assembly according to claim 1, characterized in that the communication device (4) is connectable or connected to a hospital network via a cable (5).

3. The assembly according to one of the preceding claims, characterized in that the global secret (9) is stored in advance on the medical device (1) and on the communication device (4), and that the local secret (12) is stored in advance on the communication device (4).

4. The assembly according to one of the preceding claims, characterized in that the assembly comprises a plurality of organization systems (3) with a respective communication device (4) and / or a plurality of medical devices (1), wherein the exactly one global secret (9) is stored in advance on the communication devices (4) and on the medical devices (1), and that a respective local secret (12) is stored in advance on each communication device (4).

5. The assembly according to one of the preceding claims, characterized in that the security key is also calculated and stored in advance on the communication device (4) based on the global secret (9) and the local secret (12).

6. The assembly according to claim 5, characterized in that the security key is or are or will be calculated on the communication device (4) and on the medical device (1) via a respective key generator.

7. The assembly according to claim 6, characterized in that the two key generators are programmed with an HMAC-SHA256 approach.

8. The assembly according to one of the preceding claims, characterized in that the communication device (4) and the medical device (1) are configured and programmed, that the data for calculating the security key further comprise an identifier of the communication device (4) from the communication device (4).

9. The assembly according to one of the preceding claims, characterized in that the secured radio connection is a WIFI or WLAN connection.

10. The assembly according to claims 8 and 9, characterized in that the identifier of the communication device (4) is a service set identifier, SSID.

11. The assembly according to one of the preceding claims, characterized in that the communication device (4) and the medical device (1) are configured and programmed such that the data for calculating the security key are transmitted in encrypted form from the communication device via the communication channel to the medical device (1).

12. The assembly according to one of the preceding claims, characterized in that the communication device (4) and the medical device (1) are configured and programmed such that the data for calculating the security key are decrypted on the medical device (1).

13. The assembly according to one of claims 1 to 8, characterized in that the secured radio connection is a Bluetooth connection or a mobile radio connection.

14. The assembly according to one of the preceding claims, characterized in that the medical device (1) is programmed and set up to detect a physical separation of the two devices (8) and then to interrupt the secured radio connection.

15. A communication and authentication method of radio-bound medical devices (1) to an organization system (3) connected to a communication network, comprising the following: - generating a direct point-to-point connection between the organization system (3) and the at least one medical device (1); - setting up a communication channel (7) between the organization system (3) and the medical device (1) via the direct point-to-point connection; - transmitting data, from the organization system (3) via the communication channel (7) to the medical device (1), for calculating a security key, wherein the transmitted data comprise a local secret (12), ; - generating the security key on the medical device (1) using the local secret (12) and a global secret (9), which is stored on the medical device (1), wherein the security key is in particular a pre-shared key; and - setting up a secured radio connection using the generated security key for transmitting medical data and / or control data between the organization system (3) and the medical device (1).