Operating Room Hub Role-Based Access for Shared Medical Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current operating rooms face security challenges due to networked medical devices that are shared across locations, increasing the risk of patient data compromise and adverse surgical outcomes, as they weaken the security posture of the operating room environment.

Innovation Solution

An Operating Room (OR) hub with an operations user interface (UI) that implements role-based security, authenticates users, and controls network connections to secure medical device operations, preventing unauthorized access and data breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If medical devices are connected to a network to enable sharing and rotation between locations, then device versatility and utilization are improved, but security posture and protection of patient data deteriorate

Engineering Contradiction:
Improvedevice sharing capabilityVSAvoidsecurity posture
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments access control by implementing role-based credentials (operator vs. administrator) that divide permissions into distinct levels. This allows the hub to selectively grant access rights based on user role, enabling device sharing while maintaining security through granular permission management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The operating room hub acts as an intermediary device between medical devices and the network. It mediates all connections and communications, providing a security layer that controls and monitors network access to medical devices, thereby protecting patient data while enabling controlled sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If medical devices are shared across different locations, then resource utilization is improved, but risk of unauthorized access and data compromise increases

Engineering Contradiction:
Improvedevice utilizationVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and credential verification before allowing any device interaction. Users must be authenticated through the operations UI before gaining access to medical devices, preventing unauthorized access before it can occur while still enabling legitimate device sharing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different security characteristics to different users based on their credentials. Operator credentials provide limited access for device operation, while administrator credentials provide broader access for configuration and management. This local quality approach allows device sharing while maintaining appropriate security controls for each user type.

Inventive Principle:
Principle #3Local quality

3Reliability

If an operations UI implements role-based security with authentication, then security control is improved, but ease of operation deteriorates due to additional authentication steps

Engineering Contradiction:
Improveaccess controlVSAvoiduser interaction complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements partial authentication by providing different levels of access based on credentials. Once authenticated, users gain appropriate access without requiring additional steps for routine operations. This partial action approach balances security with ease of operation by avoiding excessive authentication requirements for already-authenticated users.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250302554A1Operating devices in an operating room
Publication Date: 2025.10.02 STRYKER CORP
  • US20250302554A1 patent drawing
  • US20250302554A1 patent drawing
  • US20250302554A1 patent drawing

AI summary

Described are methods and systems for improving cybersecurity of an operating room. A user is prevented from interacting with one or more medical devices connected to an operating room (OR) hub until the user is authenticated through an operations user interface (UI) of the OR hub. The user is authenticated through the operations UI. Authenticating the user through the operations UI includes determining a type of credential possessed by the user. Based on a determination that the user possesses a hospital network administrator credential, the user is permitted to access a plurality of security functions, including enabling and disabling one or more communication ports to which the one or more medical devices are connected. Based on a determination that the user possesses an operator credential, the user is prevented from enabling and disabling the one or more communication ports.