IP Library › Granted Patent US 11,683,690
Granted Patent B2
US 11,683,690 · App. 16/358,540 · Granted Jun 20, 2023

Methods and systems for secure operation of implantable devices

Inventor: Ahmad Arash Obaidi (Issaquah, WA)
Assignee: T-Mobile USA, Inc.
H04W12/088A61F2/022A61F2/14A61F2/38A61M5/14276A61N1/37254G06F16/22G06F21/575G16H40/67H04W12/50A61B5/14532A61F2002/183A61F2002/3067A61F2250/0002A61M2205/3523A61N1/36046A61N1/3956G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,683,690
App. No.
16/358,540
Granted
Jun 20, 2023
Kind
B2
Abstract

Implantable devices, such as artificial organs, increasingly incorporate hardware, software, firmware, and/or wireless communication capabilities. For example, such implantable devices can utilize wireless technology to allow for efficient configuration, maintenance, and operational analysis. As these implantable devices become more connected, electronic security will become more important. This disclosure relates to implantable devices that may utilize a secure boot process and secure communication, both between artificial devices in the human body and between these devices and the external world. This disclosure provides secure communication approaches for maintaining the digital privacy and integrity of artificial devices, for protecting the individual from malicious hacking of data, and for controlling of such implantable devices.

Claims (52)

1. A system comprising:

a first implantable device configured to be implanted subcutaneously in a body;

a second implantable device configured to be implanted subcutaneously in the body; and

a control component coupled to the first implantable device, the control component including a processor having computer instructions that when executed cause the processor to perform operations comprising:

establishing a secure boot process of the first implantable device implanted subcutaneously in the body;

wherein a key is compared to authorized keys as a gating function for completion of the secure boot process, wherein confirmation of the key unique to the first implantable device facilitates the security of the secure boot process;

identifying an authorized device;

establishing a first secure communication pathway between the first implantable device and the authorized device;

identifying an unauthorized device;

blocking communications between the first implantable device and the unauthorized device;

establishing a direct peer-to-peer secure communication pathway between the first implantable device and the second implantable device; and

exchanging data between the first implantable device and the second implantable device via the direct peer-to-peer secure communication pathway.

2. The system of claim 1 , further comprising:

a firewall component;

an operation and maintenance component;

a deactivation component; and

a key database component.

3. The system of claim 1 , wherein the secure boot process of the first implantable device includes:

receiving the key;

determining the key is an authorized key; and

in response to determining the key is an authorized key, booting the first implantable device.

4. The system of claim 1 , further comprising a gateway coupled to the first secure communication pathway.

5. The system of claim 1 , wherein the first secure communication pathway operates according to a secure communication protocol, the secure communication protocol including a handshaking protocol that utilizes the key.

6. The system of claim 1 , wherein the first secure communication pathway includes a secure communication channel between the first implantable device and the authorized device.

7. The system of claim 1 , wherein the first secure communication pathway includes a first secure communication channel between a gateway and the first implantable device and a second secure communication channel between the gateway and the authorized device.

8. The system of claim 1 , wherein the first implantable device is at least one of a pacemaker, a cardioverter defibrillator, an artificial pancreas, a glucose monitor, an insulin pump, an artificial kidney, a cochlear implant, an artificial joint, an artificial knee, an artificial elbow, a retina implant, or an iris implant.

9. The system of claim 8 , wherein the first secure communication pathway is a wireless communication channel compliant with at least one of a 802.11 family of protocols, Bluetooth, Zigbee, LTE, Wi-MAX, Wi-Fi, near field communication, or frequency hopping.

10. A method comprising:

providing power to a first implantable device and a second implantable device, the first implantable device and the second implantable device implanted subcutaneously in a body;

obtaining an authorization key unique to the first implantable device;

confirming the authorization key unique to the first implantable device, wherein the authorization key is compared to authorized keys as a gating function for completion of a secure boot process, wherein confirmation of the authorization key unique to the first implantable device facilitates the security of the secure boot process;

in response to confirming the authorization key:

booting an operating system of the first implantable device, and establishing a first secure communication channel between the first implantable device and a second device;

establishing a direct peer-to-peer secure communication channel between the first implantable device and the second implantable device; and

exchanging data between the first implantable device and the second implantable device via the direct peer-to-peer secure communication channel.

11. The method of claim 10 , further comprising communicating between the first implantable device and the second device over the first secure communication channel.

12. The method of claim 10 , further comprising:

detecting an abnormal condition of the first implantable device.

13. The method of claim 10 , wherein the second device is at least one of a gateway device or an external device.

14. A method for operating a first implantable device performed by a processor of a control component executing computer instruction, the control component coupled to the first implantable device and a second implantable device, the method comprising:

securely booting the first implantable device, the first implantable device configured to be implanted subcutaneously in a body, wherein a key is compared to authorized keys as a gating function for completion of the secure boot process, wherein confirmation of the key unique to the first implantable device facilitates the security of the secure boot process;

identifying an authorized device;

identifying an unauthorized device;

communicating securely between the authorized device and the first implantable device via a first secure communication link, wherein the unauthorized device is prevented from accessing the first secure communication link;

blocking communications between the first implantable device and the unauthorized device;

establishing a direct peer-to-peer secure communication link between the first implantable device and the second implantable device, the second implantable device configured to be implanted subcutaneously in the body; and

exchanging data between the first implantable device and the second implantable device via the direct peer-to-peer secure communication link.

15. The method of claim 14 , wherein communicating securely with the first implantable device includes operating according to a secure communication protocol, the secure communication protocol including a handshake protocol that utilizes a key.

16. The method of claim 14 , wherein the authorized device is a gateway device.

17. The method of claim 14 , wherein the first secure communication link includes a first secure communication channel between a gateway and the first implantable device and a second secure communication channel between the gateway and the authorized device.

18. The method of claim 14 , wherein the first secure communication link is a wireless communication channel compliant with at least one of 802.11 family of protocols, Bluetooth, Zigbee, LTE, Wi-Fi, near field communication, and frequency hopping.

19. The method of claim 14 , further comprising initiating a firewall.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2019
From: OBAIDI, AHMAD ARASH
To: T-MOBILE USA, INC.
Reel/Frame 048641/0777 →
Continuity (1)
Related Publication 20200305000A1 · Sep 24, 2020