Split-Key Authentication for Secure IMD Wireless Pairing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial wireless protocols used for communication between implantable medical devices (IMDs) and external devices have limited security, making them vulnerable to breaches due to insecure pairing procedures and access by non-intended applications on commercial off-the-shelf devices.
Innovation Solution
A split key architecture is employed to authenticate external devices with IMDs, where a device authentication parameter is decomposed into two key components, with one component stored in cloud storage and the other embedded in the therapy application, requiring reconstitution for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If commercial wireless protocols are used for communication between external devices and IMDs, then ease of operation and device compatibility are improved, but security and vulnerability to breaches deteriorate
Solution Approach 1:
The authentication parameter is segmented into multiple key components that are stored in different locations (cloud storage system and therapy application). This segmentation ensures that no single point of failure exists and that unauthorized access to one component does not compromise the entire authentication mechanism, thereby improving security while maintaining ease of operation through automated reconstitution.
Solution Approach 2:
A cloud storage system is introduced as an intermediary to store and manage key components. This intermediary enables secure distribution and retrieval of authentication data without requiring direct peer-to-peer security negotiations between external devices and IMDs, simplifying the security architecture while enhancing protection against breaches.
2Device complexity
If a single authentication parameter is stored in one location, then device complexity is reduced, but security and vulnerability to breaches worsen
Solution Approach 1:
The authentication parameter is divided into multiple key components stored in different locations (cloud storage and therapy application). This segmentation distributes security risk across multiple storage locations, ensuring that compromise of one location does not lead to complete system breach, thereby improving security without significantly increasing device complexity through automated management processes.
Solution Approach 2:
The authentication architecture transitions from a single-dimensional storage model to a multi-dimensional distribution model, where key components are stored across different dimensions (cloud infrastructure and local application). This dimensional expansion enhances security through geographic and architectural distribution while maintaining operational simplicity through automated reconstitution processes.
3Ease of operation
If security keys are exposed through user interface for pairing, then ease of operation is improved, but security and risk of unauthorized access worsen
Solution Approach 1:
The system implements self-service authentication where the therapy application automatically retrieves key components and reconstitutes the authentication parameter without requiring manual user input or exposure of security keys through the user interface. This automated process eliminates the security vulnerability of key exposure while maintaining ease of operation through seamless background execution.
Solution Approach 2:
Key components are pre-distributed to the cloud storage system and therapy application before any authentication event occurs. This preliminary distribution eliminates the need for real-time key exchange or user interface exposure during pairing, as all authentication data is already in place and ready for automated reconstitution, thereby preventing unauthorized access while maintaining operational simplicity.
Data Source
AI summary
A system and method for facilitating device and application authentication between an external device and an implanted medical device (IMD), wherein a therapy application executing on the external device is operative to communicate with the IMD via wireless telemetry communications. A device authentication parameter may be decomposed into two key components, wherein one component may be stored in a cloud key vault and the other component may be distributed to the external device as an obfuscated portion embedded in the therapy application. Upon receiving the therapy application, the external device is operative to separately retrieve both key components and reconstitute the original authentication parameter therefrom, which may be presented to the IMD for authentication.


