Edge Computing System for Secure Medical Device Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Medical devices in hospitals are vulnerable to exposure of sensitive information due to unsecured connections between the hospital network and the medical device, and configuring aftermarket computing devices to act as firewalls is challenging due to the variety of protocols used by different medical devices and hospital networks.

Innovation Solution

An edge computing system (ECS) is introduced to communicate with medical devices using their proprietary protocols while establishing an encrypted connection with remote computing devices, acting as a firewall to secure open ports and filter traffic, and configuring itself to adapt to various medical device and hospital network protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure VPN connection is established between the remote engineer's computer and the hospital's private network, then the connection between the engineer and the network is encrypted, but the connection between the hospital's private network and the medical device remains unsecured with open ports vulnerable to third-party exposure

Engineering Contradiction:
Improveconnection securityVSAvoidthird-party exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure tunnel or gateway component that acts as an intermediary between the remote engineer and the medical device. This intermediary establishes an encrypted connection to the medical device through the hospital network, preventing direct exposure of the device's open ports to third parties while maintaining secure remote access capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If aftermarket computing devices are configured to act as firewalls for medical devices, then security is improved by closing/securing open ports, but the device complexity and software configuration time increase due to highly specialized medical devices and varied protocols

Engineering Contradiction:
Improvedevice securityVSAvoidsoftware configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal firewall or gateway system that can work with multiple types of medical devices across different hospital networks. The system is designed to handle various specialized protocols and device types through a common architecture, reducing the need for custom software development for each device while maintaining effective security control

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If the computing device acts as a firewall to block unsecured traffic, then third-party exposure is reduced, but legitimate clinical data traffic may be blocked due to the varied and innumerable protocols used to communicate such data

Engineering Contradiction:
Improvethird-party exposureVSAvoidprotocol compatibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements a firewall system with protocol learning and adaptation capabilities. The system monitors and analyzes legitimate traffic patterns, automatically learning the varied protocols used for clinical data communication. This feedback mechanism allows the firewall to distinguish between legitimate medical traffic and malicious attempts, blocking third-party exposure while maintaining protocol compatibility

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary configuration and protocol registration before implementing strict firewall rules. By pre-establishing knowledge of legitimate protocols and communication patterns specific to each medical device and hospital network, the firewall can securely block unauthorized access without interfering with legitimate clinical operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11451567B2Systems and methods for providing secure remote data transfer for medical devices
Publication Date: 2022.09.20 GE PRECISION HEALTHCARE LLC
  • US11451567B2 patent drawing
  • US11451567B2 patent drawing
  • US11451567B2 patent drawing

AI summary

Methods and systems are provided for providing a secure connection to a medical device for remote servicing of the medical device. In one embodiment, a computing device is in communication with a medical device, the computing device comprising non-transitory memory including executable instructions for: communicating with the medical device via a first protocol; and communicating with a remote computing device via an encrypted, second protocol. The computing device also includes a processor for executing said executable instructions.