Medical Device Control via Context-Verified Input Units
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current medical device control systems in operating theaters face security challenges due to extensive network structures, making it difficult to guarantee the necessary safety requirements, especially for security class C according to the IEC 62304 standard, without a separate release switch.
Innovation Solution
A method that uses an input unit communicating with a verification unit via a communication channel to establish a clear association between the input unit and the medical device, ensuring secure control by detecting specific user interactions and verifying the context and displacement information to authenticate and authorize control commands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate enable switch is assigned to each control unit with a logically and physically separate signal path, then safety requirements (IEC 62304 class C) are met, but device complexity increases
Solution Approach 1:
The patent merges the control command transmission and verification functions into a single communication channel between control unit and medical device. The context information (including unique device identifiers and cryptographic keys) is transmitted through this unified channel, eliminating the need for a separate physical enable switch signal path while maintaining security class C requirements.
Solution Approach 2:
The patent introduces context information as an intermediary element that mediates between the control unit and medical device. This context information contains verification data that allows the medical device to authenticate control commands without requiring a separate physical enable switch, thus simplifying the system architecture while preserving safety.
2Adaptability or versatility
If network infrastructure is used to control medical devices, then flexibility in control unit placement is improved, but safety requirements become difficult to guarantee
Solution Approach 1:
The patent applies local quality by implementing device-specific context information containing unique identifiers and cryptographic keys for each medical device. This localized security approach within the network infrastructure ensures that each device-m control unit communication is individually authenticated, maintaining safety requirements while preserving network flexibility.
Solution Approach 2:
The patent performs preliminary action by pre-transmitting context information (including cryptographic keys and device identifiers) from the control unit to the medical device before control operations begin. This preliminary authentication setup enables secure communication over the network infrastructure without compromising safety requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Method (10) for the safe control of a medical device (50) via an input unit (50) using a verification unit (54), wherein the input unit (52) communicates with the verification unit (54) via a communication channel (56a, 56b). Furthermore, a corresponding system (48) is disclosed.