IP Library › Granted Patent US 11,727,155
Granted Patent B2
US 11,727,155 · App. 17/399,209 · Granted Aug 15, 2023

Authentication of medical device computing systems by using metadata signature

Inventors: Norbert Leinfellner (Livermore, CA); Joseph Edwin Inase Manakkil (San Ramon, CA); Paolo Pochendorfer (Pleasanton, CA)
Assignee: Fresenius Medical Care Holdings, Inc.
G06F21/73G06F21/70G06F21/71G06F21/76H04L9/0819H04L9/0861H04L9/0894H04L9/14G06F21/30G06F21/57H04L9/0866H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,727,155
App. No.
17/399,209
Granted
Aug 15, 2023
Kind
B2
Abstract

Computer code embedded in an electronic component (e.g., a processor, a sensor, etc.) of a medical device, such as a dialysis machine, can be authenticated by comparing a metadata signature derived from the computer code of the electronic component to a key derived from a pre-authenticated code associated with the electronic component. The metadata signature can be derived by running an error-check/error-correct algorithm (e.g., SHA256) on the computer code of the electronic component. A use of the metadata signature enables detection of any unauthorized changes to the computer code as compared to the pre-authenticated code.

Claims (48)

1. A computer-implemented method comprising:

receiving, by a security authentication engine (SAE) of a computing system, a metadata signature from an electronic component of the computing system;

encrypting, by the SAE, the metadata signature to generate a first encrypted metadata; and

determining, by the SAE, that the first encrypted metadata substantially matches a first key associated with the electronic component and stored in the SAE, and in response:

providing, by the SAE, the first key to the electronic component as a validation key to be used by the electronic component in communications with other electronic components of the computing system.

2. The method of claim 1 , wherein the first key is stored in a lookup table, the lookup table including a plurality of keys, each key of the plurality of keys being associated with a respective electronic component of the computing system.

3. The method of claim 1 , wherein the first key is part of a key pair associated with the electronic component, the key pair including a second key, and wherein the metadata signature is generated by decrypting the second key based on computer code embedded in the electronic component.

4. The method of claim 1 , wherein the computing system includes a plurality of subsystems and the electronic component resides on a first subsystem of the plurality of subsystems, and

wherein the SAE requests the metadata signature in response to determining that the first subsystem is a valid subsystem of the computing system.

5. The method of claim 4 , wherein the determining that the first subsystem is a valid system comprises:

receiving, by the SAE and from the electronic component, a first identification data of the first subsystem;

encrypting, by the SAE, the first identification data to generate a first encrypted identification data; and

determining, by the SAE, that the first encrypted identification data is listed in a lookup table stored on the SAE, the lookup table including a plurality of encrypted identifications associated with the plurality of subsystems.

6. The method of claim 1 , wherein the metadata signature is a checksum obtained by running a error-check/error-correct code on the electronic component.

7. The method of claim 1 , wherein the first key is removed from the electronic component upon a shutdown or a reboot of the computing system.

8. The method of claim 1 , wherein the computing system is a peritoneal dialysis machine or a hemodialysis machine.

9. The method of claim 1 , further comprising determining, by the SAE, that the first encrypted metadata does not substantially match any key stored in a lookup table, and in response communicating with a central security system to verify whether an authorized change was made on computer code of the electronic component.

10. The method of claim 9 , further comprising:

receiving a message from the central security system confirming that an authorized change was made on the computer code; and

storing a new key in the lookup table for the electronic component, the new key being generated based on the metadata signature.

11. A non-transitory, computer-readable medium storing one or more instructions executable by a computing system to perform operations comprising:

receiving, by a security authentication engine (SAE) of the computing system, a metadata signature from an electronic component of the computing system;

encrypting, by the SAE, the metadata signature to generate a first encrypted metadata; and

determining, by the SAE, that the first encrypted metadata substantially matches a first key associated with the electronic component and stored in the SAE, and in response:

providing, by the SAE, the first key to the electronic component as a validation key to be used by the electronic component in communications with other electronic components of the computing system.

12. The non-transitory, computer-readable medium of claim 11 , wherein the first key is stored in a lookup table, the lookup table including a plurality of keys, each key of the plurality of keys being associated with a respective electronic component of the computing system.

13. The non-transitory, computer-readable medium of claim 11 , wherein the first key is part of a key pair associated with the electronic component, the key pair including a second key, and wherein the metadata signature is generated by decrypting the second key based on computer code embedded in the electronic component.

14. The non-transitory, computer-readable medium of claim 11 , wherein the computing system includes a plurality of subsystems and the electronic component resides on a first subsystem of the plurality of subsystems, and

wherein the SAE requests the metadata signature in response to determining that the first subsystem is a valid subsystem of the computing system.

15. The non-transitory, computer-readable medium of claim 14 , wherein the determining that the first subsystem is a valid system comprises:

receiving, by the SAE and from the electronic component, a first identification data of the first subsystem;

encrypting, by the SAE, the first identification data to generate a first encrypted identification data; and

determining, by the SAE, that the first encrypted identification data is listed in a lookup table stored on the SAE, the lookup table including a plurality of encrypted identifications associated with the plurality of subsystems.

16. A system comprising:

a security authentication engine (SAE) comprising one or more field-programmable gate arrays (FPGA); and

a computer-readable storage device coupled to the SAE and having instructions stored thereon which, when executed by the SAE, cause the SAE to perform operations comprising:

receiving a metadata signature from an electronic component of a computing system;

encrypting the metadata signature to generate a first encrypted metadata; and

determining that the first encrypted metadata substantially matches a first key associated with the electronic component and stored in the SAE, and in response:

providing the first key to the electronic component as a validation key to be used by the electronic component in communications with other electronic components of the computing system.

17. The system of claim 16 , wherein the first key is stored in a lookup table, the lookup table including a plurality of keys, each key of the plurality of keys being associated with a respective electronic component of the computing system.

18. The system of claim 16 , wherein the first key is part of a key pair associated with the electronic component, the key pair including a second key, and wherein the metadata signature is generated by decrypting the second key based on computer code embedded in the electronic component.

19. The system of claim 16 , wherein the computing system includes a plurality of subsystems and the electronic component resides on a first subsystem of the plurality of subsystems, and

wherein the SAE requests the metadata signature in response to determining that the first subsystem is a valid subsystem of the computing system.

20. The system of claim 19 , wherein the determining that the first subsystem is a valid system comprises:

receiving, by the SAE and from the electronic component, a first identification data of the first subsystem;

encrypting, by the SAE, the first identification data to generate a first encrypted identification data; and

determining, by the SAE, that the first encrypted identification data is listed in a lookup table stored on the SAE, the lookup table including a plurality of encrypted identifications associated with the plurality of subsystems.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2021
From: LEINFELLNER, NORBERT; MANAKKIL, JOSEPH EDWIN INASE; POCHENDORFER, PAOLO
To: FRESENIUS MEDICAL CARE HOLDINGS, INC.
Reel/Frame 057634/0937 →
Continuity (2)
Continuation 16560534 · Sep 4, 2019
Related Publication 20210374288A1 · Dec 2, 2021
Cited By (1)
US 12,694,156