Medical Device Vulnerability Scoring and Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Healthcare delivery organizations face challenges in managing cyber-related vulnerabilities in medical devices due to lack of timely evaluation of patches by OEMs, unclear accountability, and absence of structured systems for vulnerability management, leading to increased risk and exposure of patient safety and operational disruptions.

Innovation Solution

A computer-implemented process for remediating cyber-related operability issues in special purpose electronic devices, including creating device profiles, generating verification and validation test plans, evaluating vulnerabilities using dynamic models, and prioritizing actions for mitigation, while also calculating security vulnerability scores and initiating remediation workflows to patch high-priority devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a structured vulnerability management system is implemented, then device security and patient safety are improved, but system complexity and implementation overhead increase

Engineering Contradiction:
Improvedevice securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vulnerability management system is segmented into distinct functional modules including device discovery, vulnerability assessment, risk scoring, patch management, and reporting components. Each module handles specific tasks independently, making the overall system more manageable and maintainable while providing comprehensive security coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as vulnerability management servers that act as mediators between medical devices, network infrastructure, and security teams. These intermediaries simplify complex interactions by providing standardized interfaces and automated coordination, reducing implementation overhead

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If comprehensive vulnerability assessment and prioritization processes are implemented, then remediation effectiveness is improved, but time and resource consumption increase

Engineering Contradiction:
Improveremediation effectivenessVSAvoidtime consumption
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary vulnerability assessments and risk scoring continuously in the background, maintaining up-to-date security postures of all devices before actual remediation actions are needed. This preliminary characterization enables rapid response when vulnerabilities are detected without requiring time-consuming evaluations at remediation time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic risk scoring that adjusts priority parameters based on changing conditions such as device criticality, vulnerability severity, exploit availability, and remediation difficulty. This parameter-based prioritization enables the system to focus resources on high-risk items while automatically adjusting assessment depth based on risk level

Inventive Principle:
Principle #35Parameter changes

3Productivity

If device-level prioritization based on dynamic vulnerability models is implemented, then resource allocation efficiency is improved, but computational requirements and processing time increase

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidcomputational requirements
Core Design Contradiction:
ProductivityVSPower

Solution Approach 1:

The vulnerability assessment system applies different levels of analysis depth and computational resources to different devices based on their local characteristics such as device type, network position, and operational criticality. High-criticality devices receive more thorough assessment while lower-risk devices use streamlined evaluation, optimizing computational resource allocation

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10992698B2Device vulnerability management
Publication Date: 2021.04.27 MEDITECHSAFE INC
  • US10992698B2 patent drawing
  • US10992698B2 patent drawing
  • US10992698B2 patent drawing

AI summary

A computer-implemented process of remediating device security vulnerabilities is carried out by determining identifications of electronic devices associated with an entity and calculating, for each device, a security cyber-vulnerability score. For instance, the cyber-vulnerability score is calculated by generating a device cyber-vulnerability score based upon known threats and vulnerabilities, generating a device level cyber-vulnerability score by augmenting the generated device cyber-vulnerability score based upon at least one device level parameter, generating an environmental cyber-vulnerability score, and computing an overall cyber-vulnerability score based upon the device level cyber-vulnerability score and the environmental cyber-vulnerability score. The computer-implemented process also comprises prioritizing the electronic devices based upon the computed overall cyber-vulnerability score, identifying whether a patch is available for at least one electronic device, and initiating a remediation/mitigation workflow to patch at least one electronic device.