MLchartDataset catalogue

Patent · US10313137B2 · B2 · US

Method for authenticating devices in a medical network

(11) Publication number
US10313137B2
(21) Application number
15/349,411
(22) Filing date
2016-11-11
(30) Priority date
2016-07-05
(43) Publication date
2019-06-04
(45) Date of grant
2019-06-04
(51) IPC
H04L 9/06; H04L 9/32
(52) CPC
  • H04L Transmission of digital information, e.g. telegraphic communication: 9/3271, 2209/805, 2209/88, 9/0643, 9/3234, 9/3236
(73) Assignee
General Electric Co
(72) Inventors
Lauri Tapio Aarnio; Ville Vartiovaara; Antti Paila
(54) Title
Method for authenticating devices in a medical network
(57) Abstract

A computer implemented method and system are provided for verifying authenticity of a medical component endpoint. The method is under control of one or more computer systems configured with specific executable instructions. The method receives, at a local medical equipment (LME) node, a cipher message combination that includes a challenge and a corresponding valid response, the LME node is unable to independently calculate the valid response. The method conveys the challenge, from the LME node, to a medical component endpoint that includes an authentication circuit, receives a candidate response from the component endpoint, where the candidate response is generated by the authentication circuit based on the challenge and determines whether the candidate response matches the valid response from the corresponding cipher message combination. The method further authenticates the component endpoint based on whether the candidate and valid responses match.

Full text
View on Google Patents

Claims (20)

  1. A computer implemented method for verifying authenticity of a medical component endpoint, the method comprising: under control of one or more computer systems configured with specific executable instructions, receive, at a local medical equipment (LME) node, a cipher message combination (CMC) that includes a challenge and a corresponding at least one of a valid response or hash function code (HFC) of a valid response, the LME node unable to independently calculate the valid response; convey the challenge, from the LME node, to a medical component endpoint that includes an authentication circuit; receive, at the LME node, a candidate response from the component endpoint, where the candidate response is generated by the authentication circuit based on the challenge; determine, at the LME node, whether the candidate response corresponds to the at least one of the valid response or HFC from the corresponding cipher message combination; and authenticating, at the LME node, the component endpoint based on whether the candidate response corresponds to the at least one of the valid response or HFC.
  2. The method of claim 1, wherein the component endpoint includes at least one of a patient monitoring sensor, an equipment sensor, or an equipment actuator.
  3. The method of claim 1, further comprising generating a set of cipher message combinations at a trusted authentication computing device located remote from the LME node, the trusted authentication computing device including an original authentication circuit that emulates the operation of the authentication circuit at the component endpoint.
  4. The method of claim 1, further comprising restricting access to the authentication circuit to component endpoint and a trusted authentication computing device.
  5. The method of claim 1, further comprising: receiving measurement data from the component endpoint, the measurement data being indicative of a patient characteristic of interest; and authenticating the measurement data based on whether the candidate response corresponds to at least one of the valid response or HFC of the cipher message combinations.
  6. The method of claim 5, further comprising logging the measurement data, prior to authentication, for a period of time, the measurement data being authenticated after the logging operation.
  7. The method of claim 1, further comprising calculating from the candidate response, a candidate HFC, and comparing candidate HFC to the HFC for the valid response.
  8. The method of claim 1, further comprising transmitting, from the component endpoint, a connection request and serial number to at least one of the LME node or a local medical network computing device during a registration sequence.
  9. The method of claim 1, further comprising registering the LME node with a trusted authentication (TA) computing device, the TA computing device providing the cipher message combination to the LME node.
  10. A system for verifying authenticity of a medical component endpoint, the system comprising: a local medical equipment (LEM) node comprising memory, one or more processors and an input/output (I/O) interface configured to be coupled to a medical component endpoint configured to perform at least one of: i) collect measurement data and ii) perform actions based on incoming operation commands; the memory configured to store a cipher message combination that includes a challenge and a corresponding valid response, wherein the valid response corresponds to a calculation performed by an authentication circuit based on the challenge; the one or more processors configured with specific executable instructions, to: convey the challenge to the component endpoint that includes an authentication circuit, the authentication circuit; receive a candidate response from the component endpoint; determine whether the candidate response corresponds to at least one of the valid response or HFC from the corresponding cipher message combination; and authenticating the component endpoint based on whether the candidate and valid responses match, wherein the one or more processors are unable to independently calculate the at least one of the valid response or HFC.
  11. The system of claim 10, further comprising a component endpoint that represents at least one of a patient monitoring sensor, an equipment sensor, or an equipment actuator.
  12. The system of claim 10, further comprising a trusted authentication computing device configured to generate the cipher message combination, the trusted authentication computing device located remotely from the one or more processors, the trusted authentication computing device including an original authentication circuit that emulates the operation of an authentication circuit at a valid component endpoint.
  13. The system of claim 10, further comprising a trusted authentication computing device and a valid component endpoint, that includes a common authentication circuit, the memory and one or more processors being housed within a local medical equipment (LME) node that does not have an authentication circuit corresponding to the common authentication circuit in the component endpoint and a trusted authentication computing device.
  14. The system of claim 10, wherein the one or more processors is further configured to: receive measurement data from the component endpoint, the measurement data being indicative of a patient characteristic of interest; and authenticate the measurement data based on whether the candidate response corresponds to the at least one of the valid response or HFC of the cipher message combinations.
  15. The system of claim 14, wherein the one or more processors is further configured to log the measurement data, prior to authentication, for a period of time, the measurement data being authenticated after the logging operation.
  16. The system of claim 10, wherein the candidate response represents a response hash code calculated based on a response key generated by the authentication circuit.
  17. The system of claim 10, wherein the one or more processors is further configured to receive, from the component endpoint, a connection request and serial number during a registration sequence.
  18. The system of claim 10, wherein the one or more processors is further configured comprising registering a local medical equipment (LME) node with a trusted authentication (TA) computing device, the TA computing device providing the cipher message combination to the LME node, the LME node including the one or more processors and memory.
  19. The system of claim 10, wherein the memory is configured to store a plurality of cipher message combinations that includes challenges and corresponding valid responses multiple component endpoints.
  20. The system of claim 10, wherein the authentication circuit comprises a microprocessor executing an authentication software algorithm.

Description

The subject matter herein relates generally to methods and systems for equipment authentication within a medical network, and more particularly to authenticating remote medical component endpoints utilizing secure symmetric device-specific keys.

Healthcare facilities utilize a variety of electronic equipment in connection with diagnosis, treatment, patient monitoring and other patient related healthcare services. Various types of medical electronic equipment utilize sensors, actuators and the like, generally referred to as component endpoints, that detect various types of information and perform various actions. For example, a medical component endpoint may represent a wearable sensor placed on a patient, an equipment or physiologic sensor within a life-support system, and the like. As one example, the component endpoints may convey sensor data to patient monitoring equipment. Over time component endpoints need to be replaced more often than other parts of the medical electronic equipment. For example, the leads for a patient monitor may break, while the remainder of the patient monitoring equipment operates properly. Also, additional component endpoints are added to equipment over time, such as when a new system is set up or at later points in operation.

It is desirable to verify the authenticity of component endpoints that control operation of medical electronic equipment, and/or generate data and other information regarding patients and the medical electronic equipment.

Citations (13)

  • US7840805B2
  • US20070113073A1
  • US7096359B2
  • US7171555B1
  • US7194763B2
  • US20060026671A1
  • US20070022469A1
  • US20080263647A1
  • DE102010010760A1
  • WO2011116589A1
  • US20140047242A1
  • US9031050B2
  • US20160330573A1
Record as JSON
{
  "publication_number": "US10313137B2",
  "country": "US",
  "kind": "B2",
  "title": "Method for authenticating devices in a medical network",
  "abstract": "A computer implemented method and system are provided for verifying authenticity of a medical component endpoint. The method is under control of one or more computer systems configured with specific executable instructions. The method receives, at a local medical equipment (LME) node, a cipher message combination that includes a challenge and a corresponding valid response, the LME node is unable to independently calculate the valid response. The method conveys the challenge, from the LME node, to a medical component endpoint that includes an authentication circuit, receives a candidate response from the component endpoint, where the candidate response is generated by the authentication circuit based on the challenge and determines whether the candidate response matches the valid response from the corresponding cipher message combination. The method further authenticates the component endpoint based on whether the candidate and valid responses match.",
  "claims": [
    "1. A computer implemented method for verifying authenticity of a medical component endpoint, the method comprising: under control of one or more computer systems configured with specific executable instructions, receive, at a local medical equipment (LME) node, a cipher message combination (CMC) that includes a challenge and a corresponding at least one of a valid response or hash function code (HFC) of a valid response, the LME node unable to independently calculate the valid response; convey the challenge, from the LME node, to a medical component endpoint that includes an authentication circuit; receive, at the LME node, a candidate response from the component endpoint, where the candidate response is generated by the authentication circuit based on the challenge; determine, at the LME node, whether the candidate response corresponds to the at least one of the valid response or HFC from the corresponding cipher message combination; and authenticating, at the LME node, the component endpoint based on whether the candidate response corresponds to the at least one of the valid response or HFC.",
    "2. The method of claim 1, wherein the component endpoint includes at least one of a patient monitoring sensor, an equipment sensor, or an equipment actuator.",
    "3. The method of claim 1, further comprising generating a set of cipher message combinations at a trusted authentication computing device located remote from the LME node, the trusted authentication computing device including an original authentication circuit that emulates the operation of the authentication circuit at the component endpoint.",
    "4. The method of claim 1, further comprising restricting access to the authentication circuit to component endpoint and a trusted authentication computing device.",
    "5. The method of claim 1, further comprising: receiving measurement data from the component endpoint, the measurement data being indicative of a patient characteristic of interest; and authenticating the measurement data based on whether the candidate response corresponds to at least one of the valid response or HFC of the cipher message combinations.",
    "6. The method of claim 5, further comprising logging the measurement data, prior to authentication, for a period of time, the measurement data being authenticated after the logging operation.",
    "7. The method of claim 1, further comprising calculating from the candidate response, a candidate HFC, and comparing candidate HFC to the HFC for the valid response.",
    "8. The method of claim 1, further comprising transmitting, from the component endpoint, a connection request and serial number to at least one of the LME node or a local medical network computing device during a registration sequence.",
    "9. The method of claim 1, further comprising registering the LME node with a trusted authentication (TA) computing device, the TA computing device providing the cipher message combination to the LME node.",
    "10. A system for verifying authenticity of a medical component endpoint, the system comprising: a local medical equipment (LEM) node comprising memory, one or more processors and an input/output (I/O) interface configured to be coupled to a medical component endpoint configured to perform at least one of: i) collect measurement data and ii) perform actions based on incoming operation commands; the memory configured to store a cipher message combination that includes a challenge and a corresponding valid response, wherein the valid response corresponds to a calculation performed by an authentication circuit based on the challenge; the one or more processors configured with specific executable instructions, to: convey the challenge to the component endpoint that includes an authentication circuit, the authentication circuit; receive a candidate response from the component endpoint; determine whether the candidate response corresponds to at least one of the valid response or HFC from the corresponding cipher message combination; and authenticating the component endpoint based on whether the candidate and valid responses match, wherein the one or more processors are unable to independently calculate the at least one of the valid response or HFC.",
    "11. The system of claim 10, further comprising a component endpoint that represents at least one of a patient monitoring sensor, an equipment sensor, or an equipment actuator.",
    "12. The system of claim 10, further comprising a trusted authentication computing device configured to generate the cipher message combination, the trusted authentication computing device located remotely from the one or more processors, the trusted authentication computing device including an original authentication circuit that emulates the operation of an authentication circuit at a valid component endpoint.",
    "13. The system of claim 10, further comprising a trusted authentication computing device and a valid component endpoint, that includes a common authentication circuit, the memory and one or more processors being housed within a local medical equipment (LME) node that does not have an authentication circuit corresponding to the common authentication circuit in the component endpoint and a trusted authentication computing device.",
    "14. The system of claim 10, wherein the one or more processors is further configured to: receive measurement data from the component endpoint, the measurement data being indicative of a patient characteristic of interest; and authenticate the measurement data based on whether the candidate response corresponds to the at least one of the valid response or HFC of the cipher message combinations.",
    "15. The system of claim 14, wherein the one or more processors is further configured to log the measurement data, prior to authentication, for a period of time, the measurement data being authenticated after the logging operation.",
    "16. The system of claim 10, wherein the candidate response represents a response hash code calculated based on a response key generated by the authentication circuit.",
    "17. The system of claim 10, wherein the one or more processors is further configured to receive, from the component endpoint, a connection request and serial number during a registration sequence.",
    "18. The system of claim 10, wherein the one or more processors is further configured comprising registering a local medical equipment (LME) node with a trusted authentication (TA) computing device, the TA computing device providing the cipher message combination to the LME node, the LME node including the one or more processors and memory.",
    "19. The system of claim 10, wherein the memory is configured to store a plurality of cipher message combinations that includes challenges and corresponding valid responses multiple component endpoints.",
    "20. The system of claim 10, wherein the authentication circuit comprises a microprocessor executing an authentication software algorithm."
  ],
  "description_excerpt": "The subject matter herein relates generally to methods and systems for equipment authentication within a medical network, and more particularly to authenticating remote medical component endpoints utilizing secure symmetric device-specific keys.\n\nHealthcare facilities utilize a variety of electronic equipment in connection with diagnosis, treatment, patient monitoring and other patient related healthcare services. Various types of medical electronic equipment utilize sensors, actuators and the like, generally referred to as component endpoints, that detect various types of information and perform various actions. For example, a medical component endpoint may represent a wearable sensor placed on a patient, an equipment or physiologic sensor within a life-support system, and the like. As one example, the component endpoints may convey sensor data to patient monitoring equipment. Over time component endpoints need to be replaced more often than other parts of the medical electronic equipment. For example, the leads for a patient monitor may break, while the remainder of the patient monitoring equipment operates properly. Also, additional component endpoints are added to equipment over time, such as when a new system is set up or at later points in operation.\n\nIt is desirable to verify the authenticity of component endpoints that control operation of medical electronic equipment, and/or generate data and other information regarding patients and the medical electronic equipment.",
  "cpc": [
    "H04L 9/3271",
    "H04L 2209/805",
    "H04L 2209/88",
    "H04L 9/0643",
    "H04L 9/3234",
    "H04L 9/3236"
  ],
  "ipc": [
    "H04L 9/06",
    "H04L 9/32"
  ],
  "assignees": [
    "General Electric Co"
  ],
  "inventors": [
    "Lauri Tapio Aarnio",
    "Ville Vartiovaara",
    "Antti Paila"
  ],
  "filing_date": "2016-11-11",
  "publication_date": "2019-06-04",
  "grant_date": "2019-06-04",
  "priority_date": "2016-07-05",
  "application_number": "US-201615349411-A",
  "family_id": "60911197",
  "cited_by_count": 245,
  "citations": [
    "US7840805B2",
    "US20070113073A1",
    "US7096359B2",
    "US7171555B1",
    "US7194763B2",
    "US20060026671A1",
    "US20070022469A1",
    "US20080263647A1",
    "DE102010010760A1",
    "WO2011116589A1",
    "US20140047242A1",
    "US9031050B2",
    "US20160330573A1"
  ]
}

Record 2,781 of 8,000 in Patents full text (MLC-0201). Request the full dataset.