Implantable Pulse Generator Secure Pairing via Dynamic Seed
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial wireless protocols used for implantable medical devices (IMDs) have limited pairing procedures for establishing secure communication links, often requiring user interfaces for security keys or passkeys, which is inefficient and insecure.
Innovation Solution
A method and system that configures a pulse generator device and an external device to establish a secure bi-directional communication session using a defined bonding procedure, involving the transmission of a static identification and dynamic seed through a dedicated advertisement channel, and generating passkeys from a pre-defined algorithm to initiate a secure communication link.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If commercial wireless protocols are used for IMD communication, then compatibility with external devices is improved, but security and pairing procedure reliability deteriorate
Solution Approach 1:
The patent implements preliminary actions by pre-configuring bonding procedures and security parameters in the IMD before actual communication occurs. The device stores bonding information and security keys in advance, enabling automatic secure pairing without requiring real-time user input or complex authentication procedures during communication establishment.
Solution Approach 2:
The IMD performs self-service by automatically generating and managing security keys, bonding information, and authentication parameters without requiring external device intervention. The device independently handles the bonding procedure, security parameter exchange, and authentication processes, eliminating the need for manual user configuration or external device control during pairing.
2Reliability
If user interfaces are required for security keys or passkeys, then security authentication is improved, but ease of operation deteriorates
Solution Approach 1:
The IMD performs self-service by automatically generating and managing security keys, bonding information, and authentication parameters without requiring external device intervention. The device independently handles the bonding procedure, security parameter exchange, and authentication processes, eliminating the need for manual user configuration or external device control during pairing.
Solution Approach 2:
The patent implements preliminary actions by pre-configuring bonding procedures and security parameters in the IMD before actual communication occurs. The device stores bonding information and security keys in advance, enabling automatic secure pairing without requiring real-time user input or complex authentication procedures during communication establishment.
3Reliability
If manual pairing procedures are used, then security control is improved, but productivity and efficiency deteriorate
Solution Approach 1:
The patent implements preliminary actions by pre-configuring bonding procedures and security parameters in the IMD before actual communication occurs. The device stores bonding information and security keys in advance, enabling automatic secure pairing without requiring real-time user input or complex authentication procedures during communication establishment.
Solution Approach 2:
The IMD performs self-service by automatically generating and managing security keys, bonding information, and authentication parameters without requiring external device intervention. The device independently handles the bonding procedure, security parameter exchange, and authentication processes, eliminating the need for manual user configuration or external device control during pairing.
Data Source
AI summary
A system and method are provided for initiating a secured bi-directional communication session with an implantable medical device. The system and method include configuring a pulse generator (PG) device and an external device to establish a communication link there between through a wireless protocol with a defined bonding procedure. The system and method also include transmitting a static identification and dynamic seed from the PG device through a dedicated advertisement channel to the external device and generating a passkey from a pre-defined algorithm based on the dynamic seed and a static identification. Further, the system and method include starting the defined bonding procedure.


