Authentication of medical device computing systems by using metadata signature
Inventors
Leinfellner, Norbert • Manakkil, Joseph Edwin Inase • Pochendorfer, Paolo
Assignees
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
Computer code embedded in an electronic component a medical device, such as a dialysis machine, can be authenticated by comparing a metadata signature derived from the computer code of the electronic component to a key derived from a pre-authenticated code associated with the electronic component. The metadata signature can be derived by running an error-check/error-correct algorithm (e.g., SHA256) on the computer code of the electronic component. A use of the metadata signature enables detection of any unauthorized changes to the computer code as compared to the pre-authenticated code.
Core Innovation
The invention provides security authentication for a medical-device computing system by using a security authentication engine that receives a metadata signature from an electronic component and generates first encrypted metadata based on the metadata signature received from the electronic component. The security authentication engine determines whether the first encrypted metadata is substantially different from a first key that is associated with the electronic component and is stored in the security authentication engine.
When the substantially-different condition is determined, the security authentication engine blocks operation of the electronic component from which the metadata signature was received. In addition, the security authentication engine stores, in a permanent memory, authentication failure information and error source information associated with the electronic component.
The invention further includes subsystem validation in which, in response to the mismatch, the security authentication engine determines that a subsystem associated with the electronic component is not a valid subsystem and causes the computing system to enter a hold state. The invention also supports key management such as storing the first key in a lookup table containing multiple keys with each key corresponding to a respective electronic component, and key-pair and embedded-code signature formation, including generating a metadata signature by decrypting a second key using computer code embedded in the electronic component.
Claims Coverage
The provided excerpt includes three independent claims: a method implemented by a security authentication engine, a computing system configured to perform security authentication engine operations, and a non-transitory computer-readable medium storing instructions. Across these independent claims, the core coverage centers on receiving a component metadata signature, generating encrypted metadata, comparing it to a stored component-associated key, blocking the component on mismatch, and recording authentication failure and error-source information in permanent memory.
Security authentication engine receiving component metadata signature and generating encrypted metadata
The security authentication engine receives a metadata signature from an electronic component of the computing system and generates first encrypted metadata based on the metadata signature received from the electronic component.
Encrypted metadata comparison to component-associated stored key and component blocking
In response to determining that the first encrypted metadata is substantially different from a first key that is associated with the electronic component and is stored in the security authentication engine, the security authentication engine blocks operation of the electronic component from which the metadata signature was received.
Permanent memory storage of authentication failure and error source information
The security authentication engine stores, in a permanent memory, authentication failure information and error source information associated with the electronic component.
Subsystem validity check with hold state on mismatch
The security authentication engine determines that a subsystem associated with the electronic component is not a valid subsystem and causes the computing system to enter a hold state.
Lookup-table storage of multiple component-associated keys
The first key is stored in a lookup table containing multiple keys, where each key corresponds to a specific electronic component of the computing system.
Key-pair relationship with embedded-code decryption signature generation
The first key is one key of a key pair for the electronic component, and the metadata signature is created by decrypting the second key using computer code embedded in the electronic component.
Checksum generation using error-check/error-correct code
The metadata signature is a checksum created by executing an error-checking/error-correcting code on an electronic component.
Dialysis-machine computing system context
The computing system includes a peritoneal dialysis machine or a hemodialysis machine.
Across the independent claims, the inventive concept is a security authentication engine-based flow that authenticates electronic components using encrypted metadata derived from received component metadata signatures and compares the result to component-associated stored first keys, blocks component operation on substantial mismatch, and records authentication failure and error source information in permanent memory.
Stated Advantages
Blocks operation of an electronic component when authenticated metadata is substantially different from a stored component-associated key.
Stores authentication failure information and error source information in permanent memory.
Causes the computing system to enter a hold state when a subsystem associated with the electronic component is not a valid subsystem.
Supports security authentication for computing systems including peritoneal dialysis machines and hemodialysis machines.
Documented Applications
A computing system that includes a peritoneal dialysis machine.
A computing system that includes a hemodialysis machine.
Interested in licensing this patent?