Hearing Aid Service Access Control via Security Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for controlling access to hearing instrument services do not adequately enforce service access control on hearing aids, particularly in medical-class devices, where full access by client applications can be unsafe, and existing solutions require external entities or resource-intensive authentication processes.
Innovation Solution
Implementing a client-specific service access control method on the hearing aid that assigns security levels to services, uses various authorization methods such as user gestures, shared secrets, and trusted entities, and stores authorizations locally to enforce access control at runtime without external entities, while considering limited resources like memory and power consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If full access is granted to client applications on hearing instruments, then communication functionality is improved, but medical safety and security are compromised
Solution Approach 1:
The patent segments access rights by dividing services into different security levels (first security level for less critical services, second security level for more critical services). Client applications are granted access only to services at their authorized security level, preventing unauthorized access to critical medical functions while maintaining communication functionality.
Solution Approach 2:
The patent applies different security policies to different services based on their criticality. Each service is assigned a security level, and access control is enforced locally at each service boundary. This allows high-security services to be protected while low-security communication services remain accessible.
2Reliability
If external entities are used for authentication, then security is improved, but resource consumption and complexity increase
Solution Approach 1:
The patent performs authentication and authorization actions in advance during the pairing process. The hearing care professional authenticates the client application and assigns security levels before the client device connects to the hearing instrument. This preliminary authorization eliminates the need for continuous external authentication, reducing power consumption during normal operation.
Solution Approach 2:
The hearing instrument autonomously enforces access control based on stored authorization data. Once authenticated, the device independently determines whether to grant access to each service based on its security level and the client's authorized level, without requiring continuous external verification. This self-service approach reduces resource consumption compared to cloud-based authentication.
3Reliability
If cloud-based authentication is implemented, then access control is improved, but device complexity and resource requirements increase
Solution Approach 1:
The patent extracts the complex authentication and authorization logic from the hearing instrument to the hearing care professional's device. The hearing instrument only needs to store and verify simple authorization tokens and enforce security level-based access control. This extraction reduces device complexity while maintaining robust access control through the professional's authentication.
Data Source
AI summary
There is provided a method of controlling access of a client to a service of a hearing instrument, the method comprising the steps of: requesting access of the client to the service of the hearing instrument by providing a client authenticator to the hearing instrument; authenticating the client based on a validation of the provided client authenticator by the hearing instrument; upon successful authentication, comparing a security level associated with the service requested by the client with a highest security level assigned to the client by the hearing instrument, wherein the security level is selected from a plurality of hierarchically structured security levels, and granting access of the client to the service of the hearing instrument, if the requested security level is below or equal to the highest security level assigned to the client.


