Secured Electronic Key for Medical Device Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Networked medical devices are vulnerable to malware and cyber threats, and regulatory requirements demand additional testing and threat analysis, while non-networked devices are less prone to obsolescence but lack data transfer capabilities.

Innovation Solution

Implementing a system that uses a secured electronic key with encrypted memory to control medical device usage, allowing secure data transfer and authorization through a cloud-based interface, with a public and private key pair for secure communication, and a treatment counter to limit device usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a medical device is connected to a computer network to enable data transfer and communication capabilities, then data transfer capability is improved, but vulnerability to malware and cyber threats increases

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidvulnerability to malware and cyber threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the medical device into networked and non-networked segments. The main device controller remains isolated from direct network access, while a separate communication module handles data transfer through secure interfaces. This segmentation allows data transfer capability while protecting the core medical functions from network vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure communication interface acts as an intermediary between the medical device and external networks. This intermediary layer filters and validates all data transfers, blocking malicious content while allowing legitimate medical data exchange. The interface includes encryption and authentication mechanisms to prevent unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a medical device is designed as non-networked to simplify the system and reduce obsolescence risk, then device complexity is reduced and reliability is improved, but data transfer capability is lost

Engineering Contradiction:
Improvedevice reliabilityVSAvoiddata transfer capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary data processing and validation at the device level before transfer. Critical medical data is prepared and encrypted locally, then transferred through secure channels when needed. This preliminary action ensures data integrity and reduces the need for continuous network connectivity, maintaining reliability while enabling periodic data exchange.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If authentication and encryption hardware is added to protect against unauthorized access, then security is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication and encryption functions are merged into the existing device controller rather than adding separate hardware modules. The controller integrates security protocols directly into its firmware, combining data processing and security functions in a single unified system. This reduces overall device complexity while maintaining strong security protections.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10148439B2Methods and systems for controlling medical device usage
Publication Date: 2018.12.04 GUIDED THERAPY SYSTEMS LLC
  • US10148439B2 patent drawing
  • US10148439B2 patent drawing
  • US10148439B2 patent drawing

AI summary

Various embodiments provide systems and methods for securely transferring data from a secured site to a medical device. Some embodiments provide systems and methods for securely uploading data from a medical device to a secured site. In some embodiments described herein, data can be downloaded from a secured site to a key and after severing communication with the secured site, key can be coupled to a device and download the data to the device, in some embodiments, a public and private key pair may be used to securely download data to a device.