Medical System Access Control via Digital Signature Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current safety critical medical systems lack sufficient file system access control, making them vulnerable to corruption and unauthorized access through open external data interfaces like USB ports, which can lead to devastating consequences in medical environments.

Innovation Solution

A method and system that utilize digital signatures and cryptographic hashing algorithms to verify the authenticity of files on external storage devices, preventing unauthorized access and ensuring only validated software applications can execute on the medical system, with encryption further securing the signature files to prevent alteration or substitution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If open external data interfaces like USB ports are provided for flexibility and additional functionality, then ease of operation and adaptability are improved, but system security and reliability deteriorate due to vulnerability to corruption and unauthorized access

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an access control mechanism as an intermediary layer between the external USB interface and the medical system's file system. This mechanism includes a keylock feature that physically or logically blocks access to the USB port, and a password-protected file system that requires authentication before allowing access to stored data or applications. These intermediary controls allow the system to maintain open USB ports for flexibility while preventing unauthorized access that would compromise security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If password protection is implemented to prevent unauthorized access, then system security is improved, but ease of operation deteriorates due to password management complexity and potential loss

Engineering Contradiction:
Improvesystem securityVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by establishing robust password protection and access control mechanisms before any unauthorized access can occur. The system requires authentication credentials to be entered before allowing access to the file system or executing applications from USB devices. This preliminary security check ensures that even if users forget passwords or lose keys, the system maintains its security posture and can be restored through established recovery procedures rather than being vulnerable to immediate compromise.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If physical protection devices with keys are used to block USB ports, then system security is improved, but ease of operation deteriorates due to key management and potential loss

Engineering Contradiction:
Improvesystem securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent employs physical protection devices with keys as an intermediary control mechanism. The keylock feature acts as a physical barrier that must be unlocked with an authorized key before the USB port becomes accessible. This creates a layered security approach where the physical key serves as the first line of defense, preventing even attempted access without proper authorization. The key mechanism is integrated into the system design, allowing authorized users to maintain convenient access while preventing unauthorized use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8555070B2External interface access control for medical systems
Publication Date: 2013.10.08 JOHNSON & JOHNSON SURGICAL VISION INC
  • US8555070B2 patent drawing
  • US8555070B2 patent drawing
  • US8555070B2 patent drawing

AI summary

A method and system of controlling access to a system in a medical environment is provided. The method includes calculating a signature value for at least one file usable with the medical system, transferring the calculated signature value to a signature file, and providing at least one signature value in the signature file and at least one associated file to a file system configured to be received by the medical system. At least one signature value and at least one associated file are inspected by the medical system to verify the associated file is a known medical software application asset. The medical system comprises an input/output data port configured to receive the external memory storage device, and an operating system capable of reading medical system data from and writing medical system data to the memory storage device.