Trusted Execution Environment for Medical Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of personal devices for managing multiple medical devices introduces cybersecurity risks due to shared resources and vulnerabilities, compromising the security of medical applications and communication between devices.

Innovation Solution

A secure communication system is established using a trusted environment on personal devices with a processor that executes operations within a secure element, employing zero-knowledge password proofs, certificates, and cloud authentication tokens to create a chain of trust and encrypt communications, thereby isolating medical applications from untrusted environments and preventing malicious control of medical devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If personal devices are used to manage multiple medical devices, then device versatility and ease of operation are improved, but cybersecurity risks and reliability are worsened

Engineering Contradiction:
Improvedevice versatilityVSAvoidcybersecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The personal device is segmented into a trusted execution environment and an untrusted environment. The trusted environment isolates medical applications and their communication channels from other applications and system resources, creating security boundaries that prevent malware and viruses from compromising medical device communications while allowing the personal device to run multiple applications for versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted execution environment acts as an intermediary between the personal device and medical devices. It establishes secure communication channels and performs authentication using zero-knowledge password proofs, certificates, and cloud authentication tokens, mediating all interactions to ensure security while enabling the personal device to manage multiple medical devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple dedicated devices are used for each medical device, then cybersecurity reliability is improved, but device complexity and ease of operation are worsened

Engineering Contradiction:
Improvecybersecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The personal device is designed to universally manage multiple medical devices through a single application in the trusted execution environment. This multi-functional approach allows one device to replace multiple dedicated devices, reducing system complexity while maintaining security through isolated communication channels for each medical device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple dedicated devices are merged into a single personal device with a trusted execution environment. The trusted environment consolidates the security functions that were previously distributed across multiple devices, reducing complexity while maintaining the security isolation needed for reliable medical device management.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple applications run on the same personal device environment, then device versatility is improved, but cybersecurity risks are worsened

Engineering Contradiction:
Improveapplication versatilityVSAvoidcybersecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The personal device environment is segmented into a trusted execution environment and an untrusted environment. The trusted environment isolates medical applications and their communication resources from other applications, preventing malware and viruses running in the untrusted environment from compromising medical device communications while allowing multiple applications to run for versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted execution environment provides specialized security properties locally for medical applications, including isolated communication channels and authentication mechanisms. This local quality enhancement ensures that even if other applications on the personal device are compromised, the medical applications maintain their security and communication integrity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11297050B2Secure communication for medical devices
Publication Date: 2022.04.05 THIRDWAYV INC
  • US11297050B2 patent drawing
  • US11297050B2 patent drawing
  • US11297050B2 patent drawing

AI summary

Methods, systems, and apparatus for providing secure communication. The device includes a trusted environment having a memory that is configured to store an application. The device includes one or more processors configured to perform operations of the application that execute within the trusted environment. The operations include sending an access request to connect with a second device, receiving an authentication request from the second device that requests the application to provide a zero-knowledge password proof and obtaining the zero-knowledge password proof. The operations also include sending the zero-knowledge password proof to the second device and establishing a communication channel with the second device.