IEEE 11073 Medical Device Security Role Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current diabetes management systems lack structured procedures for collecting and interpreting blood glucose data, leading to reduced value for clinicians and increased risk of complications due to unstructured data collection, and there is a need for enhanced security in communication protocols among medical devices.
Innovation Solution
A diabetes management system employing a communication protocol with enhanced security, using IEEE standard 11073, that allows for varying security roles and access to different commands, enabling secure data access and manipulation among medical devices, and structured data collection procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a standard communication protocol (IEEE 11073) is used for data communication among medical devices, then interoperability and ease of operation are improved, but security is insufficient due to lack of role-based access control
Solution Approach 1:
The patent segments the command set into multiple security roles (e.g., patient role, clinician role, device role), where each role has access to only the commands necessary for its function. This segmentation allows the system to maintain interoperability through the standard IEEE 11073 protocol while enhancing security by restricting command access based on role, thereby resolving the contradiction between ease of operation and security.
2Ease of operation
If all commands are made accessible to all applications, then ease of operation is improved, but security is compromised due to unauthorized access risks
Solution Approach 1:
The patent applies local quality by assigning different access permissions to different applications based on their security roles. Each application receives only the specific commands it needs to perform its function, rather than universal access. This localized access control maintains operational ease for authorized functions while preventing unauthorized access, thereby resolving the contradiction between accessibility and security.
3Reliability
If role-based security access control is implemented, then security is improved, but device complexity increases due to additional security management layers
Solution Approach 1:
The patent implements a universal security role framework that can be applied across multiple medical devices and applications. The role-based access control mechanism serves multiple functions: it secures command access, manages application permissions, and maintains protocol compliance. This multi-functional security layer reduces the need for device-specific security implementations, thereby mitigating the increase in complexity while maintaining enhanced security.
Data Source
AI summary
A diabetes management system is provided that employs a communication protocol with enhanced security. The diabetes management system includes: a medical device operable to perform a diabetes care function in relation to a patient and store data related to the operation thereof; and a diabetes care manager in data communication with the medical device using a communication protocol defined in accordance with IEEE standard 11073. The diabetes care manager is able to request access to a given security role supported by the medical device, where the given security role is associated with a set of commands that are defined as a private extension of the communication protocol.


