Secure communication between implantable biomedical devices and authorized parties over the Internet
The gatekeeping device secures implantable biomedical device communication by encoding data, proximity pairing, and virtual mirroring to authenticate and verify authorized entities, addressing privacy and configuration risks.
Patent Information
- Application Number
- JP2021184867
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-11-25
- Filing Date
- 2021-11-12
- Publication Date
- 2025-11-06
- Estimated Expiration
- 2041-11-12
AI Technical Summary
Implantable biomedical devices face challenges in secure data communication, with sensed biometric data privacy risks and unauthorized configuration changes posing significant security threats.
A gatekeeping device ensures secure communication by encoding and decoding data using algorithms, proximity pairing, and virtual mirroring to authenticate and verify authorized entities, ensuring only safe updates are applied to the implantable device.
Enhances security by limiting data access to authorized parties, preventing unauthorized communication, and ensuring safe device configurations, thereby protecting patient privacy and device functionality.
Smart Images

Figure 0007765254000001 
Figure 0007765254000002 
Figure 0007765254000003
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application is related to the following concurrently filed U.S. patent applications: 1) U.S. Patent Application No. TBA, Attorney Docket No. C729-012027, entitled "Antennas for a Subcutaneous Device," by Yatheendhar D. Manicka. 2) U.S. Patent Application No. TBA, Attorney Docket No. M999-012028, entitled "Secure Communications between an Implantable Biomedical Device and Authorized Parties over the Internet," by Yatheendhar D. Manicka. and 3) U.S. Patent Application No. TBA, Attorney Docket No. M999-012029, entitled "Secure Communications between an Implantable Biomedical Device and Authorized Parties over the Internet," by Yatheendhar D. Manicka. Each of the above-cited and related US patent applications is incorporated herein by reference in its entirety. [Background technology]
[0002] Many different types of implantable biomedical devices are used to help patients for a variety of reasons. Some are used for mechanical purposes, such as joint replacements, lens replacements, and stents. Other implantable biomedical devices have electronic processing capabilities for data manipulation. These "smart" implantable biomedical devices may monitor biological functions and / or provide therapy to patients in whose presence the implantable biomedical device is located. For example, such "smart" implantable biomedical devices include cardiac monitors, pacemakers, implantable cardioverter-defibrillators, and neurostimulators. These implantable biomedical devices can sense biometric measurements from the body and use these measurements for diagnostic or therapeutic purposes. For example, such implantable biomedical devices can deliver electrical stimulation and / or drugs to the body for therapeutic purposes. For example, a pacemaker can sense a patient's heart rate, determine whether the heart is beating too fast or too slow, and deliver electrical stimulation to the heart to speed up or slow down the heart's chambers. An implantable cardioverter-defibrillator can sense a patient's heart rate, detect arrhythmias, and deliver an electrical shock to the patient to normalize the heart rate. Summary of the Invention [Problem to be solved by the invention]
[0003] Such “smart” implantable biomedical devices can be configured to transmit sensed biometric data to and receive various data from the external world. Such data communication to and / or from the implantable biomedical device can pose various risks. For example, the sensed biometric data may contain information that is private to the patient; therefore, communication of such sensed biometric data should be secure so that only intended and authorized recipients receive this sensitive data. Furthermore, configuration data sent to a “smart” implantable biomedical device may result in changes to the device's behavior and / or operation after reconfiguration. Such changes should be ordered only by authorized individuals responsible for the care of patients implanted with a “smart” implantable biomedical device. Such authorized individuals include, for example, the patient's physician and / or the manufacturer of the implantable biomedical device. [Means for solving the problem]
[0004] An apparatus and related method provide secure gatekeeping for communications from a remote internet-based website having an Internet Protocol (IP) address to an implantable biomedical device. The method includes receiving, by a gatekeeping device, a communication sent by the remote internet-based website, the received communication being encoded using a first encoding algorithm. The method includes decoding, by the gatekeeping device, the received communication. The method includes encoding, by the gatekeeping device, the decoded communication using a second encoding algorithm. The method includes wirelessly relaying, by the gatekeeping device, the communication encoded using the second encoding algorithm to the implantable biomedical device.
[0005] Some embodiments relate to a system for providing secure gatekeeping functionality for communications from a remote internet-based website having an Internet Protocol (IP) address to an implantable biomedical device. The system includes a gatekeeping device in communication with both the implantable biomedical device and the internet, and a computer-readable memory. The computer-readable memory is encoded with instructions for the gatekeeping device to cause the system to receive communications sent by the remote internet-based website. The wirelessly received communications are encoded using a first encoding algorithm. The computer-readable memory is encoded with instructions for the gatekeeping device to cause the system to decode the received communications. The computer-readable memory is encoded with instructions for the gatekeeping device to cause the system to encode the decoded communications using a second encoding algorithm. The computer-readable memory is encoded with instructions for the gatekeeping device to wirelessly relay the communications encoded using the second encoding algorithm to the implantable biomedical device. [Brief explanation of the drawings]
[0006] [Figure 1] 1 is a schematic diagram illustrating communication between an implantable biomedical device and a remote entity over Internet Protocol (IP).
[0007] [Figure 2] 1 is a flow chart illustrating a method for securely pairing a gatekeeping device with an implantable biomedical device.
[0008] [Figure 3] 1 is a flow chart illustrating a method for providing secure gatekeeping functionality in communications from an implantable biomedical device to a remote internet-based website.
[0009] [Figure 4] 1 is a flow chart illustrating a method for providing secure gatekeeping functionality in communications from a remote internet-based website to an implantable biomedical device.
[0010] [Figure 5] 1 is a flow chart illustrating a method for facilitating a remote internet-connected device to configure an implantable biomedical device. DETAILED DESCRIPTION OF THE INVENTION
[0011] Apparatus and related methods relate to communications between an implantable biomedical device and various authorized entities (real-world counterparts) over the Internet. These apparatus and related methods secure communications between the implantable biomedical device and entities on the Internet, which may have remote IP addresses. Security for such communications to and / or from the implantable biomedical device is ensured through various security measures, such as proximity pairing of the implantable biomedical device, directional security, and virtual mirroring. Communications between the implantable biomedical device and various entities, which may have these authorized IP addresses, such as the implantable biomedical device manufacturer or the patient's physician, can occur through a gatekeeping device, e.g., a paired near-field communication device such as the patient's mobile phone. Some such communications are permitted only when the gatekeeping device is in proximity to the implantable biomedical device. Furthermore, communications, such as updates or reconfigurations of the implantable biomedical device, can be limited to only those updates that increase patient safety (i.e., make the implantable device safer for the patient). Furthermore, these updates and / or reconfigurations are first performed on a virtual device that mirrors the actual implanted biomedical device. Such updates and / or reconfigurations can be modeled and / or simulated to ensure increased security of these changes to the implanted biomedical device. Security can be further enhanced using various additional methods, such as device authentication, encryption using public and private encryption keys, and restricting some communications via intranets, virtual private networks, firewalls, etc.
[0012] FIG. 1 is a schematic diagram illustrating Internet Protocol (IP) communications between an implantable biomedical device and a remote internet-based entity. In FIG. 1, a patient 10 has an implantable biomedical device 12 implanted subcutaneously. The patient 10 holds a gatekeeping device 14 in his or her hand. In the illustrated embodiment, the gatekeeping device 14 is a smartphone, although the gatekeeping device could be something other than a smartphone, such as a dedicated gatekeeping device manufactured specifically to perform such gatekeeping functions. The gatekeeping device 14 is shown facilitating communications between the implantable biomedical device 12 and an Internet cloud 16. Because the gatekeeping device 14 is a smartphone in the illustrated embodiment, communications between the Internet cloud 16 and the gatekeeping device 14 are transmitted via a cell phone tower 18. The gatekeeping device 14 is so named because it acts as the gatekeeper of various communications between the Internet cloud 16 and the implantable biomedical device 12 (i.e., "gatekeeping device"). Countless other devices and systems are configured to communicate with the Internet cloud 16, such as, for example, a hosting server 20, a medical device manufacturer 22, and a personal computer 24. The hosting server 20 may be configured to host, for example, a website 26, which may have an IP address on the Internet. The personal computer 24 may be used, for example, by a physician 26 of the patient 10.
[0013] The website 26, which may have an IP address, includes a virtual device 30 configured to accurately mirror the implantable biomedical device 12 implanted in the patient 10. The hosting server 20 is configured to use the virtual device 30 to model or simulate the operation of the implantable biomedical device 12. Such modeling may be performed to ensure safe operation of the implantable biomedical device 12 before updates and / or reconfigurations of the actual implantable biomedical device 12 are performed. The website 26, which may have an IP address, may have an IP address associated with the particular implantable biomedical device 12 implanted in the patient 10. In some embodiments, the IP address of the website 26, which may have an IP address, is a secret (e.g., known only by the manufacturer and possibly the patient and / or physician) static IP address. The implantable biomedical device 12 may also have a secret static IP address. The gatekeeping device may have either a static or dynamic IP address, depending on the configuration of the gatekeeping device.
[0014] Because the virtual device 30 is associated with the implantable biomedical device 12, the website 26, which may have an IP address, can appear to be the implantable biomedical device 12 to those who need to communicate with the implantable biomedical device 12. For example, if a physician 28 desires to update the configuration of the implantable biomedical device 12 of the patient 10, the physician 28 can communicate such desired updated configuration to the website 26 associated with the implantable biomedical device 12. The website 26, which may have an IP address, can then verify the safety of such updated and / or reconfigured implantable biomedical device 12 based on the modeling and / or simulation of the virtual device 30 prior to actually updating or reconfiguring the implantable biomedical device 12 in the future. Upon such safety verification, the website 26, which may have an IP address, can then transmit the configuration data to the actual implantable biomedical device 12 via the gatekeeping device 14. In this way, when communicating with the website 26, which may have an IP address, it appears to the physician 28 that the physician 28 is communicating with the implantable biomedical device 12. The virtual device 30 is described in more detail below in the section entitled "Virtual Image (the mirror image counterpart of the implantable biomedical device)."
[0015] The security direction for such updates and reconfigurations may be determined by the website 26, which may have an IP address, based on a simulation of the updated virtual device 30. If the security direction improves (i.e., the implantable biomedical device operates in a more secure manner after the update or reconfiguration than before the update or reconfiguration), the update or reconfiguration is transmitted from the website 26, which may have an IP address, to the implantable biomedical device 12 (e.g., via the gatekeeping device 14). However, if the security direction does not improve (i.e., the implantable biomedical device operates in a less secure manner after the update or reconfiguration than before the update or reconfiguration), the update or reconfiguration is not transmitted by the website 26, which may have an IP address. Directional security is described in more detail below in the section entitled "Directional Security." The gatekeeping device 14 provides security for communications between the implantable biomedical device 12 and the Internet cloud 16 via various methods and protocols. For example, the gatekeeping device 14 has previously been paired with the implantable biomedical device 12. The biomedical device 12 can be configured to ignore all attempted communications that do not originate from a device paired to it, such as, for example, the gatekeeping device 14. Securely pairing the implanted biomedical device 12 with one or more devices can prevent unauthorized communications from unauthorized devices. Additionally, communications to and / or from the implanted biomedical device can be restricted by proximity requirements. For example, the implanted biomedical device 12 can be configured to communicate only with devices within a predetermined range of the implanted biomedical device 12. Methods for proximity restricting communications to and / or from the implanted biomedical device 12 are described below.
[0016] In addition to using the virtual device 30 and the gatekeeping device 14, other security measures provide further security for communications between the implantable biomedical device 12 and authorized personnel. For example, data encryption between the gatekeeping device and the website 26, which may have an IP address, can be used to verify and / or validate the authorized source and destination of such communications and prevent unwanted parties from decrypting such sensitive and / or private data. Authentication of authorized entities can also be performed to limit the number of entities authorized to communicate with the implantable biomedical device 12. Such gatekeeping security measures are further described below in the section entitled "Proximity Pairing."
[0017] FIG. 2 is a flow chart illustrating a method for securely pairing a gatekeeping device with an implantable biomedical device. In FIG. 2, method 32 is described from the perspective of a processor of gatekeeping device 14 (shown in FIG. 1). In some embodiments, method 32 is performed before or after implantation of implantable biomedical device 12 into patient 10. Such secure pairing can occur, for example, at the hospital where implantation occurs or in a physician's office after implantation has occurred. Method 32 begins at step 34, where gatekeeping device 14 is associated with patient 10. Such association can include, for example, password or fingerprint protection of gatekeeping device 14 so that only patient 14 can operate gatekeeping device 14. After gatekeeping device 14 is associated with patient 10, method 32 proceeds to step 36, where communication software is received and installed on gatekeeping device 14. Such communications software supports the communications, encoding, authorization verification, and other operations used to facilitate communications between implantable biomedical device 10 and remote authorized entities over the Internet.
[0018] After so configuring the gatekeeping device 14, method 32 proceeds to step 38, where the processor of gatekeeping device 14 determines the location of the gatekeeping device (e.g., via a GPS location system). Next, in step 40, processor 36 compares the determined location to the authorized location or locations for pairing the gatekeeping device 14 with the implanted biomedical device 10. If, in step 40, the determined location does not correspond to the authorized location or locations for pairing, method 32 ends. However, if, in step 40, the determined location corresponds to the authorized location or locations for pairing, then, in step 42, gatekeeping device 14 transmits a media access control (MAC) address to the implanted biomedical device 10. The MAC address transmitted to the implanted biomedical device 10 corresponds to the communication channel used by the gatekeeping device 14 to communicate with the implanted biomedical device 10.
[0019] Method 32 then proceeds to step 44, where gatekeeping device 14 receives a unique identifier associated with implanted biomedical device 10. Such a unique identifier may be broadcast by implanted biomedical device 12, which may be provided by the manufacturer, physician, or hospital. For example, such a unique identifier may be transmitted by implanted biomedical device 10 in response to receiving the MAC address of gatekeeping device 14. In some embodiments, such a unique identifier may be manually keyed into gatekeeping device 14 or transmitted to gatekeeping device 14 over a communications channel from some other source (e.g., personal computer 24 used by physician 28). Method 32 then proceeds to step 46, where the gatekeeping device is provided with data associated with website 26 corresponding to implanted biomedical device 12. Then, in step 48, the gatekeeping device communicates with the website, which may have an IP address. Gatekeeping device 14 communicates using, for example, a public / private encoding algorithm. Gatekeeping device 14 may transmit information about website 26 associated with gatekeeping device 14 so that website 26, which may have an IP address, can verify that gatekeeping device 14 is authorized to communicate with website 26. Method 32 ends, as gatekeeping device 14 is now configured to provide gatekeeping functionality for communications between website 46, which may have an IP address, and implantable biomedical device 12.
[0020] Figures 3-6 describe communication methods used for communication between the implantable biomedical device 12 shown in Figure 1 and various authorized users. Figures 3-4 describe communication methods for the gatekeeping device 14. Figure 5 describes a method for facilitating remote internet-connected devices to configure the implantable biomedical device.
[0021] FIG. 3 is a flow chart illustrating a method for providing secure gatekeeping functionality in communications from an implanted biomedical device to a remote internet-based website. In FIG. 3, method 50 is described from the perspective of a processor in gatekeeping device 14 (shown in FIG. 1). Method 50 begins at step 52, where gatekeeping device 14 waits to receive a communication from the internet-based website. If no communication is received from the remote internet-based website at step 52, method 50 remains at (or returns to) step 52. However, if gatekeeping device 14 does receive a communication from the remote internet-based website at step 52, gatekeeping device 14 proceeds to step 54.
[0022] In step 54, gatekeeping device 14 compares the IP address corresponding to the received communication with the IP address corresponding to website 26, which may have an IP address, that is the website corresponding to implanted biomedical device 12. If, in step 54, gatekeeping device 14 determines that the received communication is from an IP address that does not correspond to website 26, which may have an IP address, method 50 returns to step 52 to await another communication over the Internet. However, if, in step 54, gatekeeping device 14 determines that the received communication is from an IP address that corresponds to website 26, which may have an IP address, method 50 proceeds to step 56.
[0023] In step 56, the gatekeeping device decrypts the received communication using the public key sent in the communication by the website 26, which may have an IP address, and the gatekeeping device's 14 private key. Using such public and private keys to decrypt the communication ensures that the communication originated from the website 26, which may have an IP address, and was intended to be received by the gatekeeping device 14. Next, in step 58, the gatekeeping device 14 encodes the decrypted communication according to the encryption algorithm used by the implanted biomedical device 10. Next, in step 60, the gatekeeping device performs a proximity test. The proximity test determines whether the gatekeeping device 14 is within a predetermined distance from the implanted biomedical device 10. Such proximity tests are described below. If, in step 60, the gatekeeping device determines that it is not proximate to the implanted biomedical device 12, method 50 remains at step 60 until it determines that the gatekeeping device 14 is proximate to the implanted biomedical device 12. However, if, at step 60 , the gatekeeping device determines that the gatekeeping device is in proximity to the implanted biomedical device 12 , then the method 50 proceeds to step 62 .
[0024] In step 62, the gatekeeping device 14 transmits the encoded communication to the implanted biomedical device 12. Method 50 then proceeds to step 64, where the gatekeeping device 14 waits for a confirming communication from the implanted biomedical device 12. If, in step 64, the gatekeeping device 14 does not receive a confirming communication from the implanted biomedical device 12 within a predetermined time, method 50 returns to step 60, where the gatekeeping device 14 performs the proximity test again. However, if, in step 64, the gatekeeping device 14 receives a confirming communication from the implanted biomedical device 12 within the predetermined time, method 50 proceeds to step 66, where the gatekeeping device 14 encodes and transmits the confirming communication to the website 26, which may have an IP address. Method 50 then returns to step 52 and waits for another communication from the website using the internet.
[0025] Figure 4 is a flow chart illustrating a method for providing secure gatekeeping functionality in communications from a remote internet-based website to an implanted biomedical device. In Figure 4, method 68 is described from the perspective of a processor in gatekeeping device 14 (shown in Figure 1). Method 68 begins at step 70, where gatekeeping device 14 waits to receive a communication from implanted biomedical device 12. If no communication is received from implanted biomedical device 12 at step 70, method 68 remains at (or returns to) step 70. However, if gatekeeping device 14 receives a communication from implanted biomedical device 12 at step 70, gatekeeping device 14 proceeds to step 72.
[0026] In step 72, the gatekeeping device 14 decrypts the communication received from the implanted biomedical device 12. Then, in step 74, the gatekeeping device 14 sends a confirmation to the implanted biomedical device 12. The method 68 then proceeds to step 76, where the gatekeeping device confirms the authenticity of the received communication as sent by the implanted biomedical device 12. Such authenticity confirmation is described in more detail below. If the authenticity of the received communication is not confirmed in step 76, the method 68 returns to step 70 to await another communication. However, if the authenticity of the received communication is confirmed in step 76, the method 68 proceeds to step 78, where the gatekeeping device 14 encodes the decoded communication using an encoding algorithm used for communications between the gatekeeping device 14 and the website 26, which may have an IP address. Next, in step 80, the gatekeeping device transmits the encoded communication to the website 26, which may have an IP address. The method 68 then returns to step 70 where the gatekeeping device waits for another communication to be sent by the implantable biomedical device 12 .
[0027] FIG. 5 is a flow chart illustrating a method for facilitating a remote internet-connected device to configure an implantable biomedical device. In FIG. 5, method 82 is described from the perspective of a processor of hosting server 20 (shown in FIG. 1), which hosts website 26, which may have an IP address. Method 82 begins at step 84, in which hosting server 20 hosts a virtual image 30 of implantable biomedical device 12 at its associated website 26. Website 26 may have an IP address. Such virtual image 30 of implantable biomedical device 12 may be configured to operate or function in the same manner as a corresponding actual implantable biomedical device 12. Method 82 then proceeds to step 86, in which website 26, which may have an IP address, receives configuration data for implantable biomedical device 12 at website 26, which may have an IP address, via the internet from a remote internet-connected device. Next, at step 88, hosting computer 20 confirms the remote entity's authorization to send the configuration data from the remote internet-connected device. If authorization is not confirmed in step 88 , the method 82 returns to step 86 to wait to receive another communication containing configuration data for the implantable biomedical device 12 .
[0028] However, if authorization is confirmed at step 88, then method 82 proceeds to step 90, where hosting server 20 updates virtual image 30. Method 82 then proceeds to step 92, where the safety of implantable biomedical device 12 is determined. Safety is determined based on the updated virtual image 30. In some embodiments, a simulation of virtual image 30 is performed. Such safety determination may include a directional safety determination, i.e., will such an update improve or impair safety? In some embodiments, an update is permitted on the actual implantable biomedical device 12 only if directional safety is improved. In some embodiments, a wait time for subsequent updates is required before the update is permitted to occur on the actual implantable biomedical device 10. If the update safety requirements are not met at step 92, then method 82 proceeds to step 94, where hosting server 20 restores virtual image 30 to its pre-update configuration, after which method 82 returns to step 86.
[0029] However, if the update security requirements are not met in step 92, method 82 proceeds to step 96, in which hosting server 20 transmits via the Internet from website 26, which may have an IP address, to implanted biomedical device 12. Such transmission is encoded via an encryption method used for transmission between website 26, which may have an IP address, and gatekeeping device 14, which acts as a gatekeeper for all communications with implanted biomedical device 12. Method 82 then returns to step 86, in which it awaits receipt of another communication from the remote Internet-connected device.
[0030] The various encoding, authorization, verification, and other security measures described in the methods corresponding to Figures 2-5 are described in more detail below. In various embodiments, more or fewer operational steps are used in one or all of the above methods 32, 50, 68, and 82. These above methods describe exemplary embodiments of the gatekeeping functions of gatekeeping device 14 and hosting server 20. Gatekeeping device 14 ensures that only authorized entities can transmit data (e.g., configuration data) to implanted biomedical device 12. Similarly, gatekeeping device 14 relays communications received from implanted biomedical device 12 only if the gatekeeping device can determine that such communications were sent by implanted biomedical device 12. Hosting server 20 secures configuration updates and restricts communications therefrom to implanted biomedical device 12.
[0031] Proximal Pairing
[0032] Proximity pairing can be used to provide a high level of security by requiring that some or all communications between the implantable biomedical device 12 and a remote authorized entity occur through a gatekeeping device 14 that is proximately paired with the implantable biomedical device 12. The gatekeeping device 14 can provide security for communications by restricting communications to and from the implantable biomedical device 12 to only paired (i.e., paired) devices that are proximate to the implantable biomedical device 12 and authorized to conduct such communications. Only such configured and authorized devices can facilitate these communications between the implantable biomedical device 12 and a remote authorized entity, and only when such configured and authorized devices are proximate to the implantable biomedical device 12. The implantable biomedical device 12 can be configured to have a limited range of wireless communications with a paired proximate device, such as the gatekeeping device 14. In this manner, such a paired proximate device can act as a gatekeeper for communications to and / or from the implantable biomedical device 12 with which it is paired. By requiring communications to be relayed by such paired proximate devices, such a gatekeeping role can block communication attempts to and / or from the implantable biomedical device 12 that are not made by an authorized remote entity.
[0033] Various types of devices can pair with the implanted biomedical device 12. For example, the manufacturer of the implanted biomedical device 12 can provide a complementary pairing device specifically designed for such gatekeeping roles. An exemplary pairing operation for such a gatekeeping device is described below. In some embodiments, the patient's 10 mobile phone can be configured to perform these gatekeeping operations. In various embodiments, communication between the implanted biomedical device 12 and the paired proximal device can occur using various protocols. For example, any protocol that provides short-range communication between the proximal device and the subcutaneously implanted biomedical device can be used. Some such communication protocols include Bluetooth®, Zigbee®, Near-Field Communication (NFC), Wide-Field Communication (WiFi), etc. These various communication protocols can be used in various ways to ensure fast and secure pairing and communication between the implanted biomedical device and the proximal device. For example, in some embodiments, NFC communication can initiate, for example, Bluetooth pairing.
[0034] Various methods of proximity pairing between the implantable biomedical device 12 and a gatekeeping device, such as the gatekeeping device 14, can be implemented, and various limits on the number of paired devices can be established. For example, a limit of one, two, or a limited number of devices can be paired with a particular implantable biomedical device. The one or few devices can be paired in a secure manner that prevents invasive pairing of other devices by unauthorized entities. Such secure pairing can be achieved using various secure pairing protocols. For example, the implantable biomedical device 12 can be configured to pair under limited and / or controlled conditions. Such limited and / or controlled conditions may include limiting the time during which pairing occurs, limiting the locations where pairing occurs, using pairing-permitting devices to permit pairing, and / or using secure communications between the implantable biomedical device 12 and the paired device (and any pairing-permitting devices).
[0035] The times during which pairing is permitted to occur can be limited in various ways. For example, pairing of the implantable biomedical device 12 to the gatekeeping device 14 can be limited to the time of implantation of the implantable biomedical device. Other permitted times for pairing of the implantable biomedical device 12 can be limited to times when certain other events occur. For example, pairing can be permitted to occur during a hospital visit and / or a doctor's appointment. In situations such as a hospital visit and / or a doctor's appointment, the devices can be paired using, for example, a physician's pairing key and / or a pairing-authorizing device. Pairing can be permitted upon receipt of a physician's pairing key, which can be, for example, a software or hardware key. This key can be communicated to the gatekeeping device 14, thereby permitting pairing to begin.
[0036] The locations where pairing is permitted can be restricted in various ways. For example, a GPS location sensor included in the proximity device paired with the implanted biomedical device 12 can be used to restrict pairing. A predetermined number of locations where pairing is permitted can be compared to the locations detected by the GPS location sensor of the paired proximity device. For example, the home address of the patient 10 in whom the implanted biomedical device 12 is implanted can be an allowable location where pairing can occur. Other allowable pairing locations can include the location of the manufacturer of the implanted biomedical device 12, the location of the doctor's office where treatment for the patient 10 with the implanted biomedical device 12 is performed, and / or the location of the hospital where such implanted biomedical device is implanted.
[0037] In some embodiments, the security of proximity pairing communications can be further enhanced using proximity detection and / or proximity testing. For example, proximity between the implantable biomedical device 12 and the gatekeeping device 14 can be detected using a proximity sensor. The proximity sensor can detect the relative proximity of the implantable biomedical device 12 to the gatekeeping device 14. Communications to and / or from the implantable biomedical device 12 can be enabled only if such relative proximity of the implantable biomedical device 12 to the gatekeeping device 14 meets a threshold condition. For example, if the gatekeeping device 14 is within a predetermined distance from the implantable biomedical device 12, communications therebetween can be enabled. Various types of proximity sensors can be employed for this purpose. For example, the implantable biomedical device 12 can have a reed switch configured to detect a magnetic field generated by a magnet or a magnetic field generated by an induction coil of the gatekeeping device 14. In other embodiments, the signal strength of an attempted wireless communication can be compared to a predetermined threshold to determine whether the gatekeeping device 14 is within a predetermined distance of the implantable biomedical device 12.
[0038] In some embodiments, pairing may occur as follows: Before implantation, the implantable biomedical device 12 is paired with the gatekeeping device 14. The gatekeeping device 14 includes a gatekeeping app programmed by the manufacturer of the implantable biomedical device 14. The gatekeeping app is configured to provide private encryption and decryption of communications between the gatekeeping device 14 and the implantable biomedical device 12. For example, in some embodiments, the implantable biomedical device uses a private encryption method based on a running timer that is started when the implantable biomedical device 12 is first powered on. Every minute, a counter advances and encryption changes based on the advanced count. The gatekeeping device 14 is provided with the time of first power-on during this pairing operation, and the gatekeeping device 14 synchronizes its counter to that of the implantable biomedical device 12. In this way, the gatekeeping device 14 can encrypt and decrypt communications in sync with the implantable biomedical device 12.
[0039] Directional Safety
[0040] Directional safety is a term that refers to whether a change in the configuration or programming of a device, such as an implantable biomedical device, increases or decreases safety. In the context of implantable biomedical devices, the safety referred to by the term "directional safety" is the safety of the patient in whom the implantable biomedical device is implanted. Some updates to the implantable device may not improve safety, but the patient's physician may desire such an update despite a negative (decreasing) directional safety. Such updates can be performed in a variety of secure ways. For example, if a physician desires to update and / or reconfigure an implantable device despite a neutral or negative directional safety, such updates and reconfigurations can be restricted to local settings. Distal internet communications can be prohibited from performing such updates and / or reconfigurations with neutral or negative directional safety.
[0041] Furthermore, devices communicating such neutral or negative directionally secure updates and / or reconfigurations can be limited to specialized devices manufactured by the implantable device manufacturer. A secret coding scheme can be used for communicating such neutral or negative directionally secure updates. Proximity requirements can be required between the programmer and the implantable biomedical device to ensure that only local secure communications perform such neutral or negative directionally secure updates and / or reconfigurations.
[0042] In some embodiments, any changes to firmware in an implantable biomedical device can be considered to have negative directional security (or at least a significant likelihood of negative directional security). Such firmware changes can be restricted to local secure communication methods, such as updates and reconfigurations, that have other neutral or negative directional security.
[0043] Communication Encryption
[0044] Data encryption may be used for communications between the implantable biomedical device 12 and a remote entity, and / or for communications between various intermediate devices facilitating such communications. For example, relatively simple encryption may be implemented for communications between the implantable biomedical device 12 and the gatekeeping device 14 to enable low-power operation of the implantable biomedical device 12. In some embodiments, communications between the implantable biomedical device 12 and the gatekeeping device 14 may be encrypted using a secret encryption method devised by the manufacturer but not made public. Such a secret encryption method may utilize the Machine Access Control (MAC) address of the communicating device(s), such as a Bluetooth chip. Furthermore, a clock algorithm may be used to encrypt short-range communications so that decryption is not possible with mere knowledge of such a MAC address.
[0045] Devices with higher power budgets, such as gatekeeping device 14 and enterprise-level devices that perform operations over the Internet, such as hosting server 20, can use encryption methods that require more power. Various such encryption methods can be used for communications between devices with higher power budgets. For example, public / private key encryption can be used for communications between gatekeeping device 14 and Internet-based servers, such as hosting server 20.
[0046] In some embodiments, such public keys can be exchanged once or at various intervals. For example, a new private key may be generated by the pair of proximity devices for each new day, each new hour, or every five minutes for communications between gatekeeping device 14 and the remote internet-based server. Gatekeeping device 14 can then generate a public key based on the generated private key. This public key can be communicated to a remote internet-based server, such as hosting server 20, for use in decrypting communications originating from gatekeeping device 14. Similarly, the remote internet-based server can also generate a private / public key pair and send the public key to gatekeeping device 14. By frequently changing these private / public key pairs, the time it takes a hacker to hack the private key can be limited to one day or less, a fraction of the time required to perform such a hack using today's most powerful computers.
[0047] Device Authentication
[0048] Proximity devices paired with the implantable biomedical device 12 can communicate with it using an authentication protocol. Such authentication can occur via a variety of secure authentication methods. For example, at the time of implantation, the implantable biomedical device 12 can be associated with the patient 10 via secure registration of the implantable biomedical device 12 with a manufacturer's secure internet site. The registration procedure can include, for example, providing information about the patient 10 and the serial number of the implantable biomedical device 12 to the manufacturer. In some embodiments, the manufacturer's website can require the provision of a login ID and password for the patient 10. The manufacturer's website can require information about the implantable biomedical device 12 and / or devices, such as the gatekeeping device 14, that are paired with the implantable biomedical device 12.
[0049] In some embodiments, after or during collection of information about the patient 10 and / or the implanted biomedical device 12, the manufacturer may communicate with the gatekeeping device 14 to be paired with the implanted biomedical device 12. Such communication may occur in a variety of ways. For example, if the gatekeeping device 14 is a mobile phone, the manufacturer may send a text or voice message to the mobile phone. In other embodiments, the manufacturer may display a key code for the user to use during the pairing procedure. For example, the manufacturer may display a key code that the patient enters into the device to be paired. This key code then enables pairing of the proximate device with the implanted biomedical device 12. In some embodiments, the manufacturer may maintain a log of all devices that are and / or have been paired with the implanted biomedical device 12.
[0050] In some embodiments, time-synchronized codes can be used for authentication and / or encryption purposes. The time sequence of the codes can be synchronized, for example, at the time of implantation and / or pairing. The code sequence can be synchronized between communicating devices so that the code communicated at a given time in the communication can be predicted by the device to which the code is communicated (e.g., the implantable biomedical device 12, the gatekeeping device 14, and / or the hosting server 20).
[0051] Virtual Image (the mirror image counterpart of an implanted biomedical device)
[0052] Communication between authorized entities can occur indirectly using the virtual image 30, which is a mirror image counterpart of the implanted biomedical device 12, or directly without such a virtual image. For example, updates to the programming of the implanted biomedical device 12 can be required to be first performed on the virtual image 30. For example, a physician may wish to change the treatment schedule that the implanted biomedical device 12 is administering to the patient 10. This change in the treatment schedule may be in response to sensed biometric data that has been provided by the implanted biomedical device 12 and that indicates the condition of the patient 10. The virtual image 30 can then transmit the updated treatment schedule to the implanted biomedical device 12 if it is determined that the updated treatment schedule meets certain safety requirements.
[0053] The virtual image 30 can mirror the actual implantable biomedical device 12, such that a simulation of the virtual image 30's operation can indicate the performance of the actual implantable biomedical device 12 after such updated treatment schedule has been programmed. Because any programming changes are first made to the virtual image 30, all such programming changes can be vetted to ensure that they will be safe for the patient 10 in whom the actual implantable biomedical device 12 is implanted when made to the actual implantable biomedical device 12. The virtual image 30 is hosted by the hosting computer 20 at a website, which may have an IP address. The hosting computer 20 is not power-constrained and therefore can have any processing power needed to perform its duties. In one embodiment, the hosting computer 20 can be an enterprise computer.
[0054] The enterprise computer typically used to perform such simulations has superior computing power to successfully execute complex algorithms, such as simulations of variously configured implantable biomedical devices 12. These simulations can be used to determine the directional safety of any updates and / or reconfigurations to the implantable biomedical device 12. The enterprise computer can then act as an arbiter for potential updates and / or reconfigurations of the implantable biomedical device 12. For example, the enterprise computer can accept or reject such potential changes based on the determined directional safety, which is determined based on a virtual simulation of a virtual image 30 virtually updated with such potential updates and / or reconfigurations.
[0055] The hosting computer 20 can be configured to run simulations of implantable biomedical devices for a large number of patients. For example, if a manufacturer wants to upgrade the firmware of all implantable biomedical devices of a particular type, the hosting computer 20 can run simulations based on all virtual devices corresponding to the implantable biomedical devices implanted in those patients. Based on such a large number of simulations, the manufacturer can decide whether to promote such updated firmware across the entire population of implantable biomedical devices.
[0056] Operation without a Gatekeeping Device
[0057] In some embodiments, secure communications may occur directly between the implantable biomedical device 12 and the Internet cloud 16. For example, the implantable biomedical device 12 may be configured to communicate directly with the Internet cloud 16 via 4G or 5G cellular communications protocols. In such a system, communications to and from the implantable biomedical device 12 may be limited to communications with websites 26, which may have IP addresses. The static IP addresses of the implantable biomedical device 12 and the websites 26, which may have IP addresses, may be kept secret so that they serve as a single set of information between authorized parties. Public / private key encryption may be used to provide additional security for such direct communications between the implantable biomedical device 12 and the websites 26, which may have IP addresses.
[0058] Direct communication between the implantable biomedical device 12 and the website 26, which may have an IP address, may incur power costs that may be greater than those associated with indirect communication via the gatekeeping device 14. Such power costs may be provided by a rechargeable battery that performs any therapeutic functions of the implantable biomedical device 12 and provides such direct communication. Because the therapeutic functions of the implantable biomedical device 12 should not be interrupted, the power provided for the therapeutic functions should not be interrupted. To ensure continuous power for the therapeutic functions, some embodiments include separate batteries, one to power the therapeutic functions and one to provide separate communications. In other embodiments, a single rechargeable battery may be virtually divided, with a first battery compartment reserved for powering the therapeutic functions and a second battery compartment reserved for communications. For example, if a communication is scheduled while the second battery compartment is depleted, the scheduled communication may be rescheduled for a later time slot to preserve the energy stored in the first battery compartment for powering the therapeutic functions.
[0059] To further reduce the power required for such direct communications, these direct communications can be limited to a limited time frame. For example, the implantable biomedical device 12 can wake up its receiver for a short time frame every five minutes to determine if a website 26, which may have an IP address, is sending it a communication or to send a communication to the website 26, which may have an IP address. The website 26, which may have an IP address, can maintain a schedule for such communications to synchronize transmission and reception with the implantable biomedical device 12.
[0060] Other power-saving measures may also facilitate such direct communication. For example, in the case of an implantable biomedical device implanted deep within the body of patient 10, the communication antenna of such a deeply implanted biomedical device may be positioned subcutaneously, just below the patient's skin layer. Such placement of the communication antenna may require lower power for a given signal strength than would be required for a more deeply implanted antenna. Such an antenna configuration is disclosed in U.S. patent application Ser. No. 16 / 355,236, entitled "Subcutaneous Device for Monitoring and / or Providing Therapies," by Yatheendhar D. Manicka, filed March 15, 2019, which is incorporated herein by reference in its entirety.
[0061] While the present invention has been described with reference to exemplary embodiments, those skilled in the art will recognize that various modifications can be made and equivalents can be substituted for elements thereof without departing from the scope of the invention. In addition, many modifications can be made to adapt a particular situation or material to the teachings of the invention without departing from the essential scope thereof. Therefore, it is not intended that the invention be limited to the particular embodiments disclosed, but rather, it is intended to include all embodiments falling within the scope of the appended claims.
Claims
1. A method for providing secure gatekeeping functionality for communications from a remote internet-based website having an Internet Protocol (IP) address to a specific implantable biomedical device, comprising: receiving, by a gatekeeping device, a communication transmitted by the remote internet-based website, the received communication being encoded using a first encoding algorithm; decrypting the received communication by the gatekeeping device; encoding the decoded communication content by the gatekeeping device using a second encoding algorithm; wirelessly relaying the communication content encoded using the second encoding algorithm by the gatekeeping device to the specific implantable biomedical device; comparing, by the gatekeeping device, the IP address of the remote internet-based web site with a predetermined static IP address corresponding to the implantable biomedical device; and rejecting, by the gatekeeping device, the communication sent by the remote internet-based website if the IP address is not the predetermined static IP address corresponding to the particular implantable biomedical device.
2. 2. The method of claim 1, wherein the wireless relaying step is performed by the gatekeeping device to wirelessly relay the communication encoded with the second encoding algorithm only if the IP address of the remote internet-based website is the predetermined static IP address corresponding to the particular implantable biomedical device.
3. 10. The method of claim 1, The method further comprising transmitting a proximity signal from the gatekeeping device to the particular implanted biomedical device, the proximity signal being used to determine proximity of the gatekeeping device to the particular implanted biomedical device.
4. The method of claim 3 , wherein the proximity signal is a magnetic field.
5. 4. The method of claim 3, wherein wireless receipt of the communication is conditioned on the proximity of the gatekeeping device to the particular implantable biomedical device being within a predetermined distance.
6. 10. The method of claim 1, and securely pairing the gatekeeping device with the particular implanted biomedical device such that the particular implanted biomedical device can reject communications sent to it by unpaired devices.
7. 7. The method of claim 6, wherein securely pairing the gatekeeping device with the particular implanted biomedical device comprises transmitting, by the gatekeeping device when in proximity to the particular implanted biomedical device, authentication information associated with the gatekeeping device to the implanted biomedical device.
8. 7. The method of claim 6, wherein securely pairing the gatekeeping device with the particular implanted biomedical device comprises receiving, by the gatekeeping device when in proximity to the particular implanted biomedical device, authentication information associated with the particular implanted biomedical device.
9. A system for providing secure gatekeeping functionality for communications from a remote internet-based website having an Internet Protocol (IP) address to a specific implantable biomedical device, comprising: a gatekeeping device in communication with both the particular implantable biomedical device and the Internet; a computer-readable memory encoded with instructions for the system to execute, instructions for receiving, by a gatekeeping device, a communication transmitted by the remote internet-based website, the wirelessly received communication being encoded using a first encoding algorithm; and instructions by the gatekeeping device to decrypt the received communication; instructions for encoding the decoded communication content by the gatekeeping device using a second encoding algorithm; a command to wirelessly relay, by the gatekeeping device, the communication content encoded using the second encoding algorithm to the implantable biomedical device; instructions for comparing, by the gatekeeping device, the IP address of the remote internet-based web site with a predetermined static IP address corresponding to the particular implantable biomedical device; instructions for refusing, by the gatekeeping device, the communication sent by the remote internet-based website if the IP address is not the predetermined static IP address corresponding to the particular implantable biomedical device; and a computer readable memory encoded with the
10. 10. The system of claim 9, wherein the wireless relaying instructions are executed by the gatekeeping device to wirelessly relay the communication encoded with the second encoding algorithm only if the IP address of the remote internet-based website is the predetermined static IP address corresponding to the particular implantable biomedical device.
11. 10. The system of claim 9, The computer-readable memory may further include instructions for the system to execute, and instructions encoded thereon for transmitting a proximity signal from the gatekeeping device to the particular implanted biomedical device, the proximity signal being used to determine proximity of the gatekeeping device to the particular implanted biomedical device.
12. 12. The system of claim 11, wherein the proximity signal is a magnetic field.
13. 12. The system of claim 11, wherein in addition to the instructions for wirelessly receiving a communication, the computer readable memory is encoded with further instructions for the system to execute to wirelessly receive, by a gatekeeping device, the communication transmitted by the remote internet-based website when the proximity of the gatekeeping device to the particular implantable biomedical device is within a predetermined distance, and the wirelessly received communication is encoded using a first encoding algorithm.
14. 10. The system of claim 9, The computer-readable memory may further include instructions for the system to execute, and instructions for securely pairing the gatekeeping device with the particular implantable biomedical device such that the particular implantable biomedical device can reject communications sent to it by unpaired devices.
15. 15. The system of claim 14, wherein the computer readable memory, in addition to the instructions for securely pairing the gatekeeping device with the implanted biomedical device, further instructions encoded on the computer readable memory cause the system to execute instructions for transmitting, by the gatekeeping device when in proximity to the particular implanted biomedical device, authentication information associated with the gatekeeping device to the particular implanted biomedical device.
16. 15. The system of claim 14, wherein the computer readable memory, in addition to the instructions for securely pairing the gatekeeping device with the implanted biomedical device, further instructions encoded on the computer for the system to execute are instructions for receiving, by the gatekeeping device when in proximity to the particular implanted biomedical device, authentication information associated with the particular implanted biomedical device.
Citation Information
Patent Citations
A platform for medical devices and secure communications
JP2018529405A
Secure medical apparatus communication
US20200313872A1