Medical Device Network Security Bridge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Medical devices integrated into communication networks face security risks due to potential attacks from insecure areas, which can compromise patient safety and device functionality, as existing security mechanisms are not adequately adapted to medical device requirements.

Innovation Solution

A device with transmission, monitoring, and interruption means to detect and disconnect communication packets between secure and insecure areas of the network, using packet filters and control logic to prevent harmful data transmission and ensure separation, thereby protecting medical devices from network-based threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If medical devices are integrated into communication networks to enable data exchange and system functionality, then productivity and adaptability are improved, but reliability and safety deteriorate due to exposure to network attacks and security threats

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoiddevice safety
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The communication network is divided into secure and insecure areas, with the medical device placed in the secure area. This segmentation isolates the medical device from direct exposure to network threats while allowing controlled communication through a bridge, thus maintaining productivity while improving reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A communication bridge is introduced as an intermediary component between the secure and insecure areas. The bridge selectively filters and transmits only authorized communication packets, enabling data exchange while blocking harmful inputs, thus resolving the contradiction between network connectivity and device safety.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security measures are implemented to protect medical devices from network attacks, then reliability is improved, but device complexity increases due to additional monitoring and filtering components

Engineering Contradiction:
Improveprotection against network attacksVSAvoidsecurity system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex security monitoring and filtering functions are extracted from the medical device itself and placed in the communication bridge. This allows the medical device to maintain simple, reliable operation while the bridge handles all security-related tasks, thus improving reliability without significantly increasing device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security functions (monitoring, filtering, packet validation) are merged into the communication bridge along with the data transmission function. This consolidation creates a single component that handles both communication and security, reducing overall system complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If all communication packets are blocked from insecure areas to ensure safety, then reliability is improved, but loss of information increases due to prevention of legitimate data transmission

Engineering Contradiction:
Improvepatient safetyVSAvoidlegitimate medical data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The communication bridge applies different quality rules to different packets: authorized medical data packets are transmitted with full fidelity, while unauthorized or harmful packets are blocked. This local differentiation ensures patient safety is maintained while preventing loss of legitimate medical information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The communication bridge performs preliminary validation and filtering of packets before they reach the medical device. By checking authorization and content in advance, legitimate data is allowed through while harmful data is blocked, thus ensuring safety without losing valid medical information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2381377B1Device and method for protecting a medical device and a patient being treated with one of these devices against dangerous effects from a communications network
Publication Date: 2018.01.03 B BRAUN MELSUNGEN AG
  • EP2381377B1 patent drawingFigure 1
  • EP2381377B1 patent drawingFigure 2
  • EP2381377B1 patent drawingFigure 3

AI summary

The interaction device (9) has a transfer unit (12) for transferring communication packet to and from the medical device (10) by the communication network (11). A monitoring unit (13) is provided for monitoring the position connection of the device with the network. An interruption unit (14) is provided to interrupt an existing connection between the protected area (11a) and the non-protected area (11b) of the network, in case position of the network connection is detected during monitoring which represents danger for a patient, treated by the device, for the correct functioning of the device. An independent claim is also included for the following: (1) medical system has multiple medical device (2) controlling method for a device.