Handset Code Authentication for Insulin Pump Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current insulin pump therapy systems face challenges in securely managing communications between handset devices and remote servers, particularly regarding patient data storage and access compliance with regional regulations, ensuring data integrity, and preventing unauthorized access.

Innovation Solution

A method and system that involves transmitting a unique identifier for the handset device, generating a handset-specific code, and requiring manual input of this code to associate the device with patient information, ensuring secure communication and compliance with regional data storage regulations by routing medical data to local servers, and allowing for customer support updates and data management states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If patient data is transmitted to a remote server for remote access by medical staff, then remote monitoring and diagnostic capabilities are improved, but data security and compliance with regional storage regulations are compromised

Engineering Contradiction:
Improveremote access capabilityVSAvoiddata security and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the server infrastructure into local/regional servers that store patient data within specific geographic jurisdictions. Each server handles data for its designated region, ensuring compliance with local regulations while maintaining remote access capabilities through the distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authentication mechanism using unique device identifiers and manually entered codes. This intermediary layer verifies device legitimacy before allowing data transmission, securing the communication channel between handset devices and servers without blocking legitimate remote access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a global server is used to store all patient data, then data centralization and access efficiency are improved, but compliance with regional data storage regulations is violated

Engineering Contradiction:
Improvedata access efficiencyVSAvoidregional compliance flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The monolithic global server is segmented into multiple regional servers distributed across different jurisdictions. Each server maintains data for its local region, enabling efficient local access while adhering to regional regulations. The segmented architecture preserves productivity through localized data proximity while gaining adaptability to diverse regulatory requirements.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If automatic data synchronization is implemented between handset and server, then data availability is improved, but risk of unauthorized access and data breaches is increased

Engineering Contradiction:
Improvedata availabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system introduces manual code entry as an intermediary authentication step between the handset device and server. This manual verification process acts as a mediator that prevents automatic unauthorized connections while still allowing legitimate data synchronization, reducing the risk of automated attacks and unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements preliminary authentication through unique device identifiers and manually entered verification codes before allowing any data transmission. This preliminary anti-action prevents unauthorized devices from establishing connections in the first place, countering potential attacks before they can execute.

Inventive Principle:
Principle #9Preliminary anti-action

4Ease of operation

If device association with patient information is simplified, then ease of setup is improved, but security and data integrity are compromised

Engineering Contradiction:
Improvedevice setup simplicityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements self-service through automatic generation of unique device identifiers and automated association with patient information in the database. This automation maintains data integrity through systematic processes while keeping the user experience simple, as users only need to enter their existing patient ID without manual configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses the patient ID as an intermediary that bridges the user and the system. Users provide their known patient ID, which serves as a verified intermediary identifier that automatically triggers secure device registration and association processes, maintaining both simplicity and integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10272200B2Managing communications to and from a handset device controlling a therapeutic product delivery device
Publication Date: 2019.04.30 INSULET NETHERLANDS BV
  • US10272200B2 patent drawing
  • US10272200B2 patent drawing
  • US10272200B2 patent drawing

AI summary

A communication method of managing communications to and from a handset device controlling a therapeutic product delivery device is described. The method comprises transmitting, to a server, at least part of a unique identifier for a handset device for controlling a therapeutic product delivery device, and patient information regarding a user to be associated with the handset device, and at the server, associating the handset device with the patient information, generating a handset specific code, and transmitting the handset specific code to the user. At the handset device, a manual input of the handset specific code is received, and the future transmission of data from the handset device to the server carried out in association with the handset specific code. In this way, the server can be sure that the user is in possession of the handset (because the user received the code via the secure portal, and was required to manually input it to the handset), and can therefore be confident that communications received in association with that code are associated with the correct user and handset.