Implantable Medical Device Secure Connection Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication solutions for implantable medical devices (IMDs) face challenges in maintaining secure and energy-efficient communication, particularly due to limitations in power consumption during active scanning attacks.
Innovation Solution
The implementation of a transceiver in IMDs that broadcasts a unique identifier and applies an advertising filter to authorize only approved external devices, thereby denying unauthorized scan responses and establishing secure communication sessions independently of scan requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the IMD responds to all scan requests from external devices, then device discoverability is improved, but power consumption increases and security is compromised
Solution Approach 1:
The IMD performs preliminary authentication by checking if the external device's identifier is in the approved list before responding to scan requests. This preliminary action filters out unauthorized devices early, preventing unnecessary communication and power consumption while maintaining discoverability for authorized devices only.
Solution Approach 2:
The IMD applies different response behaviors to different external devices based on their authorization status. Authorized devices receive scan responses and can establish connections, while unauthorized devices are denied responses. This localized quality control optimizes power consumption by directing communication resources only to approved devices.
2Ease of operation
If the IMD uses traditional scan request-response communication, then device connectivity is established, but security vulnerabilities increase due to active scanning attacks
Solution Approach 1:
The system performs preliminary authentication by verifying the external device's identifier against an approved list before allowing scan request-response communication. This preliminary security check blocks unauthorized devices from initiating attacks while permitting legitimate devices to establish connections through the traditional scan mechanism.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism (advertising filter with approved device list) between the scan request and scan response. This intermediary layer verifies device authorization before allowing communication, preventing security vulnerabilities while maintaining connectivity for approved devices.
3Ease of operation
If the IMD broadcasts advertising data packets frequently, then device discoverability is improved, but battery energy is depleted faster
Solution Approach 1:
The IMD dynamically adjusts advertising parameters based on authorization status. Advertising data packets are broadcast only to authorized external devices rather than all devices. This parameter change reduces the number of advertising transmissions required, thereby conserving battery energy while maintaining discoverability for approved devices.
4Adaptability or versatility
If the IMD allows all external devices to establish communication sessions, then communication versatility is improved, but unauthorized access security risks increase
Solution Approach 1:
The IMD performs preliminary authentication by checking the external device's identifier against an approved list before allowing communication session establishment. This preliminary action ensures that only authorized devices can communicate with the IMD, preventing unauthorized access while maintaining versatility for approved devices.
Solution Approach 2:
The system applies different communication permissions to different external devices based on their authorization status. Authorized devices are granted full communication access, while unauthorized devices are completely blocked. This localized quality control maintains communication versatility for approved devices while eliminating security risks from unauthorized access.
Data Source
AI summary
An implantable medical device (IMD) that includes a transceiver configured to broadcast an advertising data packet that includes a unique identifier, and to receive a scan request data packet from an external device. A memory stores program instructions, and stores an approved device list, and one or more processors are configured to execute the program instructions to identify a device identifier (ID) from the scan request data packet received, apply an advertising filter to determine if the scan request data packet is from an authorized external device based on the device ID and the approved device list, based on the determination by the advertising filter, deny transmission of a scan response data packet from the transceiver when the advertising filter determines that the scan request data packet is from an unauthorized external device, and establish a communication session with an authorized external device independent of the scan request data packet.


