Separated Cybersecurity and Safety Computing for Fast Medical Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing devices and systems face challenges in quickly updating cybersecurity functions without affecting safety functions, which are subject to rigorous regulatory approvals, leading to lengthy approval processes and potential delays in addressing cybersecurity threats.
Innovation Solution
A device with separate computing units for executing cybersecurity and safety functions, allowing for independent updates and changes to cybersecurity functions without impacting safety functions, thereby enabling rapid implementation of software updates and minimizing the need for new safety approvals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cybersecurity functions are updated frequently to address new threats, then security effectiveness is improved, but the approval process for safety functions is delayed due to regulatory requirements
Solution Approach 1:
The system is divided into two independent computing units: a first computing unit for cybersecurity functions and a second computing unit for safety functions. This segmentation allows cybersecurity functions to be updated independently without triggering safety function re-approval, resolving the contradiction between security updates and approval delays
Solution Approach 2:
Cybersecurity functions are extracted from the safety-critical system core and placed in a separate computing unit. This extraction enables cybersecurity updates to occur independently of safety function approvals, allowing frequent security updates without regulatory delays
2Productivity
If cybersecurity functions are updated independently of safety functions, then update speed is improved, but system integration complexity increases
Solution Approach 1:
The system architecture is segmented into independent computing units for cybersecurity and safety functions, each with separate software and hardware resources. This segmentation enables independent updates while managing integration complexity through defined interfaces
Solution Approach 2:
A communication module acts as an intermediary between the first computing unit (cybersecurity) and the second computing unit (safety functions). This intermediary manages data exchange and coordination, enabling independent updates while maintaining system integration
3Reliability
If safety functions are subject to rigorous regulatory approvals, then operational safety is ensured, but the time required for device maintenance and updates increases
Solution Approach 1:
Safety functions are segregated into a dedicated second computing unit that remains unchanged during cybersecurity updates. This segmentation ensures operational safety through regulatory compliance while reducing maintenance time by eliminating the need to re-approve safety functions during security updates
Solution Approach 2:
Safety functions are pre-approved through rigorous regulatory processes and then fixed in the second computing unit. This preliminary action ensures operational safety while subsequent cybersecurity updates in the first computing unit do not require additional approval, reducing overall maintenance time
Data Source
AI summary
A device (10) executes cybersecurity functions with respect to information security and safety functions with respect to operational safety. The device includes a first computing unit (1) for executing at least one of the cybersecurity functions and includes a second computing unit (2) for executing at least one of the safety functions. The first computing unit includes a communication module (3) which has a first interface (5) and is configured to check incoming data. The second computing unit includes an alarm module (4) which is configured to generate an information signal (INS). The first computing unit and the second computing unit are connected to one another via a second interface (6) for data exchange. A process executes cybersecurity functions and safety functions on such a device. A gas measuring device (20) and a ventilator or anesthesia device (30) are provided with such a device.


