IEEE 11073 Medical Device Security Role Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current diabetes management systems lack structured procedures for collecting and interpreting blood glucose data, leading to reduced value for clinicians and increased risk of complications due to unstructured data collection, and there is a need for enhanced security in communication protocols among medical devices.

Innovation Solution

A diabetes management system employing a communication protocol with enhanced security, using IEEE standard 11073, that allows for varying security roles and access to different commands, enabling secure data access and manipulation among medical devices, and structured data collection procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a standard communication protocol (IEEE 11073) is used for data communication among medical devices, then interoperability and ease of operation are improved, but security is insufficient due to lack of role-based access control

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the command set into multiple security roles (e.g., patient role, clinician role, device role), where each role has access to only the commands necessary for its function. This segmentation allows the system to maintain interoperability through the standard IEEE 11073 protocol while enhancing security by restricting command access based on role, thereby resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If all commands are made accessible to all applications, then ease of operation is improved, but security is compromised due to unauthorized access risks

Engineering Contradiction:
ImproveaccessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different access permissions to different applications based on their security roles. Each application receives only the specific commands it needs to perform its function, rather than universal access. This localized access control maintains operational ease for authorized functions while preventing unauthorized access, thereby resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #3Local quality

3Reliability

If role-based security access control is implemented, then security is improved, but device complexity increases due to additional security management layers

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security role framework that can be applied across multiple medical devices and applications. The role-based access control mechanism serves multiple functions: it secures command access, manages application permissions, and maintains protocol compliance. This multi-functional security layer reduces the need for device-specific security implementations, thereby mitigating the increase in complexity while maintaining enhanced security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9218456B2Communication protocol for medical devices that supports enhanced security
Publication Date: 2015.12.22 ROCHE DIABETES CARE INC
  • US9218456B2 patent drawing
  • US9218456B2 patent drawing
  • US9218456B2 patent drawing

AI summary

A diabetes management system is provided that employs a communication protocol with enhanced security. The diabetes management system includes: a medical device operable to perform a diabetes care function in relation to a patient and store data related to the operation thereof; and a diabetes care manager in data communication with the medical device using a communication protocol defined in accordance with IEEE standard 11073. The diabetes care manager is able to request access to a given security role supported by the medical device, where the given security role is associated with a set of commands that are defined as a private extension of the communication protocol.