PERMISSION-BASED CONTROL OF INTERFACING COMPONENTS WITH A MEDICAL DEVICE
Disclosed are embodiments directed to security methods applied to connections between components in a distributed (networked) system including medical and non-medical devices, providing secure authentication, authorization, patient and device data transfer, and patient data association and privacy for components of the system.
1 . (canceled)
2 . A wearable cardiac monitoring system, comprising:
a wearable medical device;
a processor; and
a memory in communication with the processor, wherein the processor is configured to:
receive a security certificate from a non-medical device requesting communication with the wearable medical device;
verify the security certificate to authenticate the non-medical device, wherein the verification includes checking that the security certificate is signed by a Certificate Authority;
initiate a secure communication between the wearable medical device and the non-medical device based on the verified security certificate, wherein the secure communication comprises encrypting data exchanged between the wearable medical device and the non-medical device using a public key from the security certificate; and
deny communication with the non-medical device when the security certificate is not attested to by the Certificate Authority.
3 . The wearable cardiac monitoring system of claim 2 , wherein the memory comprises a certificate store to store the security certificate, the security certificate comprising:
information that identifies the non-medical device with which the wearable medical device has secure communication,
the public key that enables encryption of data intended to be delivered to the non-medical device,
at least one data field associated with at least one function that the non-medical device can perform in connection with the wearable medical device, and
a signature that authenticates the security certificate as being attested to by the Certificate Authority.
4 . The wearable cardiac monitoring system of claim 3 , wherein the signature comprises a digital signature created by the Certificate Authority.
5 . The wearable cardiac monitoring system of claim 3 , wherein the at least one data field comprises information that identifies a set of permissions that are authorized to the non-medical device.
6 . The wearable cardiac monitoring system of claim 5 , wherein the information that identifies the set of permissions comprises an element type, and the wearable medical device authorizes the permissions to the non-medical device based on the element type.
7 . The wearable cardiac monitoring system of claim 2 , wherein the wearable medical device is a wearable cardioverter defibrillator (WCD), and the non-medical device is a mobile device or a fixed computing device.
8 . The wearable cardiac monitoring system of claim 2 , wherein the processor is further configured to deny communication with the non-medical device when the security certificate has been revoked.
9 . The wearable cardiac monitoring system of claim 2 , wherein the processor is further configured to retrieve a certificate revocation list (CRL) to determine whether the security certificate is revoked.
10 . The wearable cardiac monitoring system of claim 2 , wherein the Certificate Authority is associated with the wearable cardiac monitoring system for providing therapy.
11 . The wearable cardiac monitoring system of claim 2 , wherein the non-medical device is further configured to communicate data from the wearable medical device to a cloud-based server, the data comprising patient data and device data associated with the wearable medical device.
12 . The wearable cardiac monitoring system of claim 2 , wherein the secure communication further comprises transfer of patient physiological data that can be used to treat a medical condition.
13 . A method for enabling secure communication between a wearable medical device and a non-medical device, the method comprising:
receiving, by a processor of the wearable medical device, a security certificate from the non-medical device requesting communication with the wearable medical device;
verifying, by the processor, the security certificate to authenticate the non-medical device, wherein the verification includes checking that the security certificate is signed by a Certificate Authority;
initiating, by the processor, a secure communication between the wearable medical device and the non-medical device based on the verified certificate, wherein the secure communication comprises encrypting data exchanged between the wearable medical device and the non-medical device using a public key from the security certificate; and
denying, by the processor, communication with the non-medical device when the security certificate is not attested to by the Certificate Authority.
14 . The method of claim 13 , further comprising storing the security certificate in a certificate store residing in a memory of the wearable medical device, wherein the certificate store comprises:
information that identifies the non-medical device with which the wearable medical device has secure communication,
the public key that enables encryption of data intended to be delivered to the non-medical device,
at least one data field associated with at least one function that the non-medical device can perform in connection with the wearable medical device, and
a signature that authenticates the security certificate as being attested to by the Certificate Authority.
15 . The method of claim 14 , wherein the at least one data field comprises information that identifies a set of permissions that are authorized to the non-medical device.
16 . The method of claim 15 , wherein the information that identifies the set of permissions comprises an element type, and the wearable medical device authorizes permissions to the non-medical device based on the element type.
17 . The method of claim 13 , wherein the wearable medical device is a wearable cardioverter defibrillator (WCD), and the non-medical device is a mobile device or a fixed computing device.
18 . The method of claim 13 , further comprising retrieving a certificate revocation list (CRL) to determine whether the security certificate is revoked.
19 . The method of claim 13 , wherein after successfully establishing the secure communication, the method further comprises configuring the wearable medical device.
20 . The method of claim 13 , wherein the Certificate Authority is associated with the wearable medical device for providing therapy.
21 . The method of claim 13 , wherein the non-medical device is further configured to communicate data from the wearable medical device to a cloud-based server, the data comprising patient data and device data associated with the wearable medical device.