Implantable Medical Device Far Field Communication Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for communicating with implantable medical devices (IMDs) during surgical implantation require frequent key exchanges via proximity communication, which introduces additional burdens and delays, as the external device needs to maintain proximity to the IMD within the sterile field to ensure correct communication.
Innovation Solution
The external device uses the last session key for far field communication when proximity communication fails, allowing it to maintain the key outside the sterile field and ensuring secure communication with the IMD without needing to reintroduce the proximity wand, thus streamlining the implantation process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proximity communication is used to exchange keys with the IMD, then secure communication is ensured, but additional procedural steps and time are required
Solution Approach 1:
The key exchange is performed in advance before the IMD is implanted into the sterile field. The external device obtains the IMD's identifier and uses it to generate and transmit a session key to the IMD via proximity communication while the IMD is still outside the sterile field. This preliminary key exchange eliminates the need for subsequent key exchanges inside the sterile field, reducing procedural time while maintaining security.
Solution Approach 2:
The patent uses the IMD's own identifier as an intermediary element to enable key exchange without requiring continuous physical proximity. The external device uses the IMD's identifier (obtained from the IMD itself) to generate a session key and transmit it to the IMD. This intermediary approach allows secure communication establishment without requiring the proximity wand to be repeatedly introduced into the sterile field.
2Reliability
If the proximity wand is repeatedly introduced into the sterile field for key exchange, then correct IMD communication is ensured, but the implantation process becomes more complex
Solution Approach 1:
All key exchange operations are completed before the IMD enters the sterile field. The external device performs proximity communication and key transmission while the IMD is still outside the sterile field, then closes the communication session. This eliminates the need for the proximity wand to be repeatedly introduced into the sterile field, simplifying the implantation process while ensuring correct IMD communication through the pre-established session key.
3Ease of operation
If far field communication is used after implantation, then the external device can communicate with the IMD, but the external device may accidentally communicate with other IMDs in range
Solution Approach 1:
The session key acts as an intermediary security mechanism that ensures communication accuracy. The external device uses the IMD's unique identifier to generate a session-specific key and transmits it to the target IMD. The IMD then uses this session key to authenticate and encrypt subsequent far field communications. This intermediary key mechanism allows the external device to communicate with IMDs at a distance while preventing accidental communication with other IMDs, as only the correct IMD possesses the matching session key.
Data Source
AI summary
An external device transfers a key to an implantable medical device over a proximity communication and then establishes a first far field communication session with the implantable medical device where the key is used for the first communication session. This first communication session may occur before implantation while the implantable medical device is positioned outside of the sterile field so that using a proximity communication is easily achieved. Once the implantable medical device is passed into the sterile field for implantation, the external device may then establish a second far field communication session with the implantable medical device where the last key that was used for the first communication session is again used for the second communication session which avoids the need for another proximity communication to occur within the sterile field.


