Medical Device Bluetooth Pairing Security via One-Time Password

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing medical devices, such as patch insulin pumps and glucose monitors, face security risks due to potential hacking threats when using wireless connections, which can compromise the health of the user if the insulin pump loses control.

Innovation Solution

Implementing a password-authenticated key agreement algorithm, specifically the J-PAKE algorithm, to establish a secure Bluetooth encryption key using a one-time password, which is used only once for pairing and then disabled to prevent repeated unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a wireless connection is made between the medical appliance and control unit, then the device can be operated remotely and monitored, but the connection becomes vulnerable to hacking attacks and security breaches

Engineering Contradiction:
Improveremote operation capabilityVSAvoidhacking vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by establishing a secure pairing process before wireless communication begins. The medical appliance and control unit perform mutual authentication and establish encryption keys in advance, ensuring that even if the wireless connection is accessible, unauthorized access is prevented without compromising remote operation capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic protocols as an intermediary layer between the medical appliance and control unit. This intermediary mechanism (security protocol) mediates the wireless communication by encrypting data transmissions and authenticating devices, allowing remote operation while blocking hacking attempts at the cryptographic layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the medical appliance stores authentication credentials for secure pairing, then security against unauthorized access is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism where the medical appliance can pair with multiple authorized control units using the same cryptographic protocol. The device stores multiple authentication credentials but uses a standardized pairing process for each, reducing the need for different authentication mechanisms for different devices and simplifying the overall system architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter of authentication from simple password-based systems to cryptographic key-based systems. By transforming the authentication mechanism into a mathematically secure parameter system (using encryption keys and cryptographic protocols), the patent achieves high security without significantly increasing operational complexity for the end user

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3230909B1Pairing of a medical apparatus with a control unit
Publication Date: 2022.09.14 ROCHE DIABETES CARE GMBH
  • EP3230909B1 patent drawingFigure 1
  • EP3230909B1 patent drawingFigure 2
  • EP3230909B1 patent drawingFigure 3

AI summary

The invention provides for method of operating a medical instrument (100, 200, 400, 500, 600, 700) comprising a battery powered medical appliance (104) and a control unit (102). Both have Bluetooth communication modules. A first memory of the medical appliance contains a onetime password (210) and of a password-authenticated key agreement algorithm (212). The control unit has a second memory (223) with an implementation of the password-authenticated key agreement algorithm (2121'). The method comprises entering (300) the onetime password into the data entry interface (140, 221, 504, 604) of the control unit. The method further comprises generating (302) a Bluetooth encryption key (218) by the medical appliance and the control unit with the onetime password by exchanging data across the wireless communication channel by executing the password-authenticated key agreement algorithm. The method further comprises storing (304) the Bluetooth encryption key in the first memory.