TAN Server Authentication for Secure Medical Device Reprogramming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in ensuring that implantable medical devices, such as cardiac pacemakers or defibrillators, are not inadvertently or mistakenly reprogrammed due to erroneous data transmissions or misuse during remote programming processes.

Innovation Solution

A system utilizing a Transaction Number (TAN) server for authenticating and verifying programming instructions, which generates a unique transaction number for authentication and ensures that only authorized users can reprogram the device by matching the TAN stored on the device with the one transmitted via a secure communication channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If remote programming is enabled via central service center and patient intermediate device, then programming flexibility and accessibility are improved, but security risk and potential for erroneous reprogramming increase

Engineering Contradiction:
Improveprogramming flexibilityVSAvoidsecurity against erroneous reprogramming
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication by generating and verifying Transaction Numbers (TANs) before allowing any programming operation. The TAN is generated in advance, transmitted to the physician's device, and must be entered before programming can occur, preventing unauthorized changes regardless of when the programming attempt occurs

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The Transaction Number (TAN) serves as an intermediary authentication mechanism between the programming device and the implantable medical device. The TAN acts as a mediator that verifies the physician's identity and authorization before allowing programming instructions to be executed, blocking direct unauthenticated access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If programming instructions are transmitted remotely, then ease of operation and accessibility are improved, but risk of data transmission errors and misuse increases

Engineering Contradiction:
Improveremote programming accessibilityVSAvoiddata transmission errors and misuse
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback through the TAN verification process where the transmitted TAN is compared against the expected TAN stored in the implantable medical device. This feedback mechanism immediately detects and prevents erroneous or unauthorized programming attempts, providing real-time security verification before programming occurs

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8239025B2System and method for the remote programming of a personal medical device
Publication Date: 2012.08.07 BIOTRONIK SE & CO KG
  • US8239025B2 patent drawing
  • US8239025B2 patent drawing
  • US8239025B2 patent drawing

AI summary

The invention comprises a system for the secure remote programming of an implant. A TAN server is provided for this purpose, in which a user is first accredited and which then generates a TAN upon a request and provides it to the user on one hand and to a patient intermediate device assigned to the implant to be reprogrammed on the other hand.