Secure Software Update Architecture for Medical Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Medical devices like defibrillators face reliability and safety issues due to user access for software updates, which can lead to malware installation and compromised software integrity, potentially affecting their core functionality and patient safety.

Innovation Solution

Implementing a secure software update process with multiple integrity checks before and after software installation, including a staging area for new software to ensure it has not been compromised, and isolating the execution of critical software applications from non-critical ones to prevent unauthorized changes or malware intrusion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are allowed to install their own software or hardware, then ease of operation is improved, but reliability deteriorates

Engineering Contradiction:
Improveuser access for software updatesVSAvoiddevice reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the software update process into distinct phases: download phase (storing software in first memory), installation phase (copying to second memory), and verification phase (integrity checks). This segmentation allows user-initiated updates while maintaining system reliability through controlled execution of each phase with appropriate security measures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary verification mechanism that acts between the user-installed software and the core device functions. Integrity checks using hash values and digital signatures serve as intermediaries to validate software authenticity, allowing user access while preventing malicious software from compromising device reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of repair

If service technicians service the defibrillator, then ease of repair is improved, but security deteriorates due to risk of malware installation

Engineering Contradiction:
Improveservice technician accessVSAvoidmalware installation risk
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary actions by service technicians to verify their credentials and the integrity of software before installation. The system performs preliminary integrity checks on software updates before allowing installation, preventing malware from being installed during legitimate service activities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously monitors and verifies software integrity after installation. Integrity checks provide feedback to confirm that installed software has not been compromised, allowing service technicians to perform repairs while preventing malware installation through ongoing verification.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple software applications are installed to provide enhanced functions, then adaptability is improved, but reliability deteriorates due to potential interference with core functionality

Engineering Contradiction:
Improvesoftware functionalityVSAvoidcore functionality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments software applications into critical and non-critical categories, with critical applications having higher priority and protected status. This segmentation allows multiple applications to coexist while ensuring that critical functions maintaining device reliability are not interfered with by non-critical enhanced features.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary anti-action by isolating execution of critical software applications from non-critical ones. The system预先 establishes execution isolation mechanisms that prevent non-critical applications from interfering with critical functions, allowing adaptability through multiple applications while protecting core reliability.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS20240420835A1Secure software updates and architectures
Publication Date: 2024.12.19 STRYKER CORP
  • US20240420835A1 patent drawing
  • US20240420835A1 patent drawing
  • US20240420835A1 patent drawing

AI summary

Systems and techniques to ensure reliable operation of devices, such as medical devices, that are configured to execute installed software are described. A secure software update process for the device utilizes multiple integrity checks in order to prove that software integrity has not been compromised before the device is allowed to be put into service with the software installed thereon. Also described is a computer architecture for an external defibrillator that isolates the execution of installed software applications by separately compiling the code for those applications and by executing the separately-compiled applications on different processors of the defibrillator. Among other things, this allows the defibrillator to be “brought online” faster, such as to deliver a shock to a patient.