Implantable Medical Device Secure Connection Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication solutions for implantable medical devices (IMDs) face challenges in maintaining secure and energy-efficient communication, particularly due to limitations in power consumption during active scanning attacks.

Innovation Solution

The implementation of a transceiver in IMDs that broadcasts a unique identifier and applies an advertising filter to authorize only approved external devices, thereby denying unauthorized scan responses and establishing secure communication sessions independently of scan requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the IMD responds to all scan requests from external devices, then device discoverability is improved, but power consumption increases and security is compromised

Engineering Contradiction:
Improvedevice discoverabilityVSAvoidpower consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The IMD performs preliminary authentication by checking if the external device's identifier is in the approved list before responding to scan requests. This preliminary action filters out unauthorized devices early, preventing unnecessary communication and power consumption while maintaining discoverability for authorized devices only.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The IMD applies different response behaviors to different external devices based on their authorization status. Authorized devices receive scan responses and can establish connections, while unauthorized devices are denied responses. This localized quality control optimizes power consumption by directing communication resources only to approved devices.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If the IMD uses traditional scan request-response communication, then device connectivity is established, but security vulnerabilities increase due to active scanning attacks

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by verifying the external device's identifier against an approved list before allowing scan request-response communication. This preliminary security check blocks unauthorized devices from initiating attacks while permitting legitimate devices to establish connections through the traditional scan mechanism.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism (advertising filter with approved device list) between the scan request and scan response. This intermediary layer verifies device authorization before allowing communication, preventing security vulnerabilities while maintaining connectivity for approved devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the IMD broadcasts advertising data packets frequently, then device discoverability is improved, but battery energy is depleted faster

Engineering Contradiction:
Improvedevice discoverabilityVSAvoidbattery energy
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The IMD dynamically adjusts advertising parameters based on authorization status. Advertising data packets are broadcast only to authorized external devices rather than all devices. This parameter change reduces the number of advertising transmissions required, thereby conserving battery energy while maintaining discoverability for approved devices.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If the IMD allows all external devices to establish communication sessions, then communication versatility is improved, but unauthorized access security risks increase

Engineering Contradiction:
Improvecommunication versatilityVSAvoidunauthorized access security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The IMD performs preliminary authentication by checking the external device's identifier against an approved list before allowing communication session establishment. This preliminary action ensures that only authorized devices can communicate with the IMD, preventing unauthorized access while maintaining versatility for approved devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different communication permissions to different external devices based on their authorization status. Authorized devices are granted full communication access, while unauthorized devices are completely blocked. This localized quality control maintains communication versatility for approved devices while eliminating security risks from unauthorized access.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250126549A1Implantable medical device with secure connection to an external instrument
Publication Date: 2025.04.17 PACESETTER INC
  • US20250126549A1 patent drawing
  • US20250126549A1 patent drawing
  • US20250126549A1 patent drawing

AI summary

An implantable medical device (IMD) that includes a transceiver configured to broadcast an advertising data packet that includes a unique identifier, and to receive a scan request data packet from an external device. A memory stores program instructions, and stores an approved device list, and one or more processors are configured to execute the program instructions to identify a device identifier (ID) from the scan request data packet received, apply an advertising filter to determine if the scan request data packet is from an authorized external device based on the device ID and the approved device list, based on the determination by the advertising filter, deny transmission of a scan response data packet from the transceiver when the advertising filter determines that the scan request data packet is from an unauthorized external device, and establish a communication session with an authorized external device independent of the scan request data packet.