SBOM Validation for Medical Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing medical devices lack effective cybersecurity measures to validate software and hardware updates, which can lead to vulnerabilities and cyber threats, compromising patient health and device reliability.

Innovation Solution

A Software Bill of Materials (SBOM) validation system using a blockchain to generate and validate device-specific SBOMs, ensuring secure installation and updates of software and hardware, involving a network of validator systems and a vulnerability database to assess and authorize changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing cybersecurity systems prevent installation of additional software or hardware on medical devices, then device security is improved, but device functionality and adaptability deteriorate

Engineering Contradiction:
Improvedevice securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary validation of software and hardware before installation by generating SBOMs, validating them against security policies, and obtaining approval in advance. This allows secure updates to be pre-approved while maintaining device security during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation system that acts as a mediator between security requirements and device functionality. The validator system with SBOM validation serves as the intermediary layer that enables controlled updates without directly compromising device security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manufacturers establish strict acceptable health configurations for software and hardware, then device reliability is improved, but ease of operation and customization deteriorate

Engineering Contradiction:
Improvedevice reliabilityVSAvoidcustomization ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts security validation based on the type of update and device state. Different validation levels are applied depending on whether the update is from an approved source, the criticality of the component, and the current device configuration, allowing flexibility within security constraints.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The validation system changes parameters such as validation strictness, approval requirements, and monitoring levels based on the specific software or hardware being updated. Less critical updates may require simpler validation, while critical components undergo more rigorous checks.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive validation of all software and hardware updates is performed, then cybersecurity is improved, but processing time and system complexity deteriorate

Engineering Contradiction:
ImprovecybersecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation system segments the validation process into distinct phases: SBOM generation, validation against security policies, approval workflows, and post-installation verification. Different components (software vs. hardware, critical vs. non-critical) are validated through appropriate segmented pathways.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial validation actions based on risk assessment. Not all updates require the full validation sequence - some may only require SBOM verification, while others need complete validation including security policy checks and approval workflows.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If real-time monitoring of installed components is implemented, then threat detection is improved, but energy consumption and processing load deteriorate

Engineering Contradiction:
Improvethreat detectionVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic monitoring at strategically chosen intervals rather than continuous monitoring. Validation occurs at key events such as boot-up, before and after updates, and at scheduled intervals, reducing energy consumption while maintaining effective threat detection.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The medical device itself performs self-validation by generating its own SBOM and validating it against stored security policies. This self-service approach reduces the processing burden on external systems and minimizes continuous energy consumption from external monitoring infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11150888B2Software bill of materials validation systems and methods
Publication Date: 2021.10.19 BEARD DANIEL IVAN
  • US11150888B2 patent drawing
  • US11150888B2 patent drawing
  • US11150888B2 patent drawing

AI summary

Each of a plurality of medical devices is configured to generate a device specific Software Bill of Materials (SBOM), and communicate the device specific SBOM to a validator system(s). A central authority system(s) is configured to authorize the validator system(s) to add a new block(s) to a SBOM blockchain. The SBOM blockchain is structured to contain updates to the device specific SBOM. The validator system(s) is configured to create a local copy of the SBOM blockchain, build a SBOM hash tree based on data in the SBOM blockchain, search the SBOM hash tree for the device specific SBOM, add a new block to the SBOM blockchain, the new block comprising an update(s) to the device specific SBOM, validate the update(s) in the device specific SBOM based on a vulnerability database, and communicate the new block to at least one other validator system.