Biological information processing system and relay device
By introducing relay devices with network settings and encryption functions into the biological information processing system, the problem that medical device networks are difficult to meet legal security requirements when facing external attacks are solved, and the security and compliance of data transmission are achieved.
Patent Information
- Application Number
- JP2023185854
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-30
- Publication Date
- 2025-05-14
AI Technical Summary
The cybersecurity of existing medical equipment is difficult to meet the three legal requirements when facing external cyber attacks: confidentiality, authenticity and integrity.
A biological information processing system and relay device are designed. The relay device ensures the security of data during transmission by setting up network information of medical equipment and has encryption and decryption functions.
Through encryption and decryption functions, the security of medical equipment network is enhanced, data is prevented from being eavesdropped, and the legal requirements for network security are met.
Smart Images

Figure 2025074802000001_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a biometric information processing system and a relay device. [Background technology]
[0002] In medical institutions, various information devices, including medical devices, are used in a network environment. Since medical devices are used on the human body, secure system management is required in the network environment.
[0003] For example, Patent Document 1 discloses a management system that notifies alarm information when a specific event occurs in an encryption protocol for network communication of medical devices, such as an incorrect password entry. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] U.S. Patent No. 11,558,261 Summary of the Invention [Problem to be solved by the invention]
[0005] Meanwhile, recent legal regulations require strengthening the network security of medical devices against external cyber attacks. Specifically, medical devices are required to meet three requirements (confidentiality, authenticity, and integrity). To meet these requirements, it is necessary to encrypt packets to prevent eavesdropping on communication data and strengthen network security.
[0006] An object of the present disclosure is to provide a biometric information processing system and a relay device with enhanced network security. [Means for solving the problem]
[0007] A biological information processing system according to one aspect of the present disclosure includes: A first information processing device that processes biometric information; at least one second information processing device; A relay device that controls network communication between the first information processing device and the second information processing device; Equipped with The relay device includes a network setting unit that sets network information of the first information processing device as network information of the relay device.
[0008] In addition, in a biological information processing system according to an aspect of the present disclosure, After the network setting unit sets the network information of the first information processing device as the network information of the relay device, the relay device may encrypt a packet sent from the first information processing device and transmit it to the second information processing device.
[0009] In addition, in a biological information processing system according to an aspect of the present disclosure, After the network setting unit sets the network information of the first information processing device as the network information of the relay device, the relay device may decrypt a packet transmitted from the second information processing device and transmit it to the first information processing device.
[0010] In addition, in a biological information processing system according to an aspect of the present disclosure, The relay device may include an encryption setting unit that sets an encryption mode of a packet transmitted by the relay device based on encryption mode information included in the packet transmitted from the second information processing device.
[0011] In addition, in a biological information processing system according to an aspect of the present disclosure, The encryption setting unit may be capable of setting a first mode that corresponds to non-encrypted packets but does not correspond to encrypted packets, a second mode that corresponds to both encrypted packets and non-encrypted packets, or a third mode that corresponds to the encrypted packets but does not correspond to the non-encrypted packets.
[0012] In addition, in a biological information processing system according to an aspect of the present disclosure, The second information processing device may process biometric information.
[0013] A relay device according to one aspect of the present disclosure includes: A relay device that relays network communication between a first information processing device that processes biometric information and a second information processing device, The relay device further includes a network setting unit for setting network information of the first information processing device as network information of the relay device. Effect of the Invention
[0014] According to the present disclosure, it is possible to provide a biometric information processing system and a relay device with enhanced network security. [Brief description of the drawings]
[0015] [Figure 1] 1 is a configuration diagram of a biological information processing system according to an embodiment of the present disclosure. [Diagram 2] FIG. 2 is a block diagram of a relay device. [Diagram 3] FIG. 2 is a diagram illustrating the configuration of a communication packet. [Figure 4] FIG. 13 is a schematic diagram of a user operation screen for encryption setting. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0016] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.
[0017] FIG. 1 is a configuration diagram of a biometric information processing system according to an embodiment of the present disclosure. As shown in FIG. 1, the biometric information processing system 1 includes a relay device 100, biometric information processing devices 200 and 300, and a peripheral device 400. The biometric information processing device 300 and the peripheral device 400 are directly connected to a network N, and the biometric information processing device 200 is connected to the network N via the relay device 100. The network N is, for example, a local area network (LAN) and is configured with one or both of wired and wireless. In addition, the protocol may be a general-purpose communication protocol such as TCP / IP (Transmission Control Protocol / Internet Protocol), or a communication protocol dedicated to the medical field such as DICOM (Digital Imaging and Communications in Medicine). In addition, an encrypted communication protocol such as SSL / TLS (Secure Sockets Layer / Transport Layer Security) or DTLS (Datagram Transport Layer Security) is used in the transport layer. The biometric information processing devices 200 and 300 and the peripheral device 400 transmit and receive communication packets to each other using any one of unicast, multicast, and broadcast communication methods.
[0018] The bioinformation processing devices 200 and 300 are, for example, a central monitor, a bedside monitor, a central unit, a medical telemeter, etc., and are medical devices that process bioinformation. The peripheral device 400 is, for example, a printer, a server, etc., and is a device that does not fall under the category of medical devices. Hereinafter, the bioinformation processing device 200 is also referred to as a first information processing device, and the bioinformation processing device 300 and the peripheral device 400 are collectively referred to as a second information processing device. In this example, the second information processing device includes the bioinformation processing device 300 and the peripheral device 400, but may include only one of the bioinformation processing device 300 or the peripheral device 400. In this example, the bioinformation processing device 300 and the peripheral device 400 are connected to the network N, but may be connected to a plurality of bioinformation processing devices 300 or a plurality of peripheral devices 400. The relay device 100 is a repeater that controls network communication between the first information processing device and the second information processing device. In the case where the first information processing device does not have a monitoring system for encryption and decryption of communication packets, the relay device 100 has the function of the system.
[0019] 2 is a block diagram of the relay device 100. The relay device 100 includes a network setting unit 10, a first packet receiving unit 20, a first packet transmitting unit 30, a second packet receiving unit 40, a second packet transmitting unit 50, and a manual encryption setting unit 60. The network setting unit 10 includes an encryption setting unit 11. The encryption setting unit 11 includes a packet encryption unit 12 and a packet decryption unit 13.
[0020] The first packet receiving unit 20 receives a communication packet from the biometric information processing device 200, which is a first information processing device. The first packet transmitting unit 30 transmits the communication packet received by the first packet receiving unit 20 to at least one of the biometric information processing device 300 and the peripheral device 400, which are second information processing devices. The second packet receiving unit 40 receives a communication packet from at least one of the biometric information processing device 300 and the peripheral device 400. The second packet transmitting unit 50 transmits the communication packet received by the second packet receiving unit 40 to the biometric information processing device 200.
[0021] Here, the configuration of a communication packet will be described with reference to Fig. 3. A communication packet transmitted by the first information processing device and the second information processing device is composed of a plurality of fields.
[0022] As shown in Fig. 3, one field of a communication packet contains network information of the first information processing device which is the source of the packet. The network information indicates, for example, the MAC address or IP address of the first information processing device.
[0023] As shown in FIG. 3, other fields of the communication packet include encryption mode information of the packet sender (first information processing device or second information processing device). The encryption mode information indicates whether the packet sender can handle encrypted packets, and includes, for example, a first mode that supports non-encrypted packets but does not support encrypted packets, a second mode that supports encrypted and non-encrypted packets, and a third mode that supports encrypted packets but does not support non-encrypted packets. When the packet sender device is in the first mode, if the packet destination device is in the first mode or the second mode, communication is performed using non-encrypted packets, and if the packet destination device is in the third mode, packet communication is not performed. When the packet sender device is in the second mode, if the packet destination device is in the first mode, communication is performed using non-encrypted packets, and if the packet destination device is in the second mode or the third mode, communication is performed using encrypted packets. Furthermore, when the device that transmits the packet is in the third mode, if the device that transmits the packet is in the second or third mode, communication is performed using encrypted packets, and if the device that transmits the packet is in the first mode, packet communication is not performed. Note that the encryption mode information may be included in a field in the body of the communication packet, or may be included in a field in the header.
[0024] Returning to the description of FIG. 2, the network setting unit 10 refers to the communication packet from the first information processing device received by the first packet receiving unit 20, and acquires the network information of the first information processing device. Furthermore, the network setting unit 10 sets the acquired network information of the first information processing device as the network information of the relay device 100. In other words, the network setting unit 10 clones the network information of the first information processing device to the network information of the relay device 100. This allows the relay device 100 and the second information processing device to perform packet communication as if the first information processing device and the second information processing device were directly performing packet communication. Therefore, the relay device 100 can perform encrypted packet communication on behalf of the first information processing device.
[0025] The encryption setting unit 11 refers to a communication packet received by the first packet receiving unit 20 from the first information processing device, and acquires first encryption mode information. Based on the acquired first encryption mode information, the encryption setting unit 11 sets a first encryption mode, which is an encryption mode of packets to be transmitted by the first packet transmitting unit 30. Here, the encryption setting unit 11 can set a first mode that does not correspond to encrypted packets, a second mode that corresponds to encrypted packets and non-encrypted packets, and a third mode that corresponds to encrypted packets but not non-encrypted packets.
[0026] Furthermore, the encryption setting unit 11 refers to the communication packet received by the second packet receiving unit 40 from the second information processing device, and acquires second encryption mode information. Based on the acquired second encryption mode information, the encryption setting unit 11 sets a second encryption mode, which is the encryption mode of the packet to be transmitted by the second packet transmitting unit 50. Here, the encryption setting unit 11 is capable of setting the first to third modes, similarly to the case of the first encryption mode information.
[0027] After the network setting unit 10 sets the network information of the first information processing device as the network information of the relay device 100, the packet encryption unit 12 encrypts a non-encrypted packet transmitted from the first information processing device based on the first encryption mode and the second encryption mode set by the encryption setting unit 11. As a result, when, for example, the first information processing device is in a first mode in which it cannot transmit encrypted packets and the second information processing device is in a third mode in which it can only receive encrypted packets, the relay device 100 encrypts the non-encrypted packet on behalf of the first information processing device and transmits the encrypted packet to the second information processing device, thereby enabling encrypted packet communication.
[0028] After the network setting unit 10 sets the network information of the first information processing device as the network information of the relay device 100, the packet decryption unit 13 decrypts the encrypted packet transmitted from the second information processing device based on the first encryption mode and the second encryption mode set by the encryption setting unit 11. As a result, when, for example, the first information processing device is in the first mode in which it cannot decrypt encrypted packets and the second information processing device is in the third mode in which it can only transmit encrypted packets, the relay device 100 decrypts the encrypted packet on behalf of the first information processing device and transmits the decrypted packet to the first information processing device, thereby enabling encrypted packet communication.
[0029] After the network link is established, the first information processing device and the second information processing device periodically receive communication packets by broadcasting in order to notify other devices of their own device information and operating status. Therefore, it is preferable that at least one of the first encryption mode and the second encryption mode is included in the communication packet in the broadcast so that the relay device 100 can perform the initial setting and update setting of the encryption modes of the first information processing device and the second information processing device at an appropriate timing.
[0030] The manual encryption setting unit 60 is an interface that allows a user to set an encryption mode (first to third modes) of the first information processing device. Specifically, as shown in FIG. 4, the encryption mode of the first information processing device can be set or changed by a radio button method or the like on a user operation screen for encryption setting. The packet encryption unit 12 encrypts a non-encrypted packet transmitted from the first information processing device based on the encryption mode set in the manual encryption setting unit 60. Note that, when the packet encryption unit 12 sets the first encryption mode based on the first encryption mode information and the encryption mode is set by the manual encryption setting unit 60, the packet encryption unit 12 may preferentially perform packet encryption based on the encryption mode set in the manual encryption setting unit 60.
[0031] As described above, the biometric information processing system and the relay device according to the embodiment of the present disclosure can enable an information processing device that does not support encrypted communication to perform pseudo-encrypted communication by encrypting or decrypting a communication packet in the relay device. This makes it possible to prevent eavesdropping of communication data and enhance network security.
[0032] Although the embodiment of the present disclosure has been described above, it goes without saying that the technical scope of the present disclosure should not be interpreted as being limited by the description of the embodiment. The present embodiment is merely an example, and it is understood by those skilled in the art that various modifications of the embodiment are possible within the scope of the invention described in the claims. The technical scope of the present disclosure should be determined based on the scope of the invention described in the claims and its equivalents.
[0033] Moreover, each process in the biological information processing system 1 according to this embodiment can be realized as a computer program that runs on the relay device 100. That is, the relay device 100 is assumed to include a processor such as a CPU and a memory.
[0034] The program can be stored in a non-transitory computer-readable medium and read by the computer. Examples of the non-transitory computer-readable medium include a magnetic recording medium, a magneto-optical recording medium, a CD-ROM, a CD-R, a CD-R / W, and a semiconductor memory (including an EPROM and a flash ROM). The program may also be read by the computer by various types of temporary computer-readable media. Examples of the temporary computer-readable medium include an electric signal, an optical signal, and an electromagnetic wave. The temporary computer-readable medium can supply the program to the computer via a wired communication path such as an electric wire and an optical fiber, or via a wireless communication path. [Explanation of symbols]
[0035] 1: Biometric information processing system 10: Network settings section 11: Encryption settings section 12: Packet encryption section 13: Packet decoding unit 20: First packet receiver 30: First packet transmitter 40: Second packet receiving unit 50: Second packet transmitter 60: Encryption manual setting section 100: Relay device 200, 300: Biometric information processing device 400: Peripheral devices N: Network
Claims
1. A first information processing device that processes biometric information; At least one second information processing device; a relay device that controls network communication between the first information processing device and the second information processing device; Equipped with The relay device is A biometric information processing system comprising: a network setting unit that sets network information of the first information processing device as network information of the relay device.
2. 2. The biometric information processing system of claim 1, wherein after the network setting unit sets the network information of the first information processing device as the network information of the relay device, the relay device encrypts a packet sent from the first information processing device and transmits it to the second information processing device.
3. 2. The biometric information processing system of claim 1, wherein after the network setting unit sets the network information of the first information processing device as the network information of the relay device, the relay device decrypts a packet transmitted from the second information processing device and transmits it to the first information processing device.
4. 2. The biometric information processing system according to claim 1, wherein the relay device has an encryption setting unit that sets an encryption mode of a packet transmitted by the relay device based on encryption mode information included in the packet transmitted from the second information processing device.
5. The biometric information processing system of claim 4, wherein the encryption setting unit is capable of setting a first mode that corresponds to non-encrypted packets but not to encrypted packets, a second mode that corresponds to the encrypted packets and non-encrypted packets, or a third mode that corresponds to the encrypted packets but not to the non-encrypted packets.
6. The biological information processing system according to claim 1 , wherein the second information processing device processes biological information.
7. A relay device that relays network communication between a first information processing device that processes biometric information and a second information processing device, The relay device includes a network setting unit that sets network information of the first information processing device as network information of the relay device.
Citation Information
Patent Citations
Network device and medical system for the detection of at least one network problem
US11558261B2