IP Library Granted Patent US 12,499,206
Granted Patent B2
US 12,499,206 · App. 18/648,504 · Granted Dec 16, 2025

Split key architecture for facilitating authentication between an implanted medical device and an external device

Inventors: Greg Creek (Prosper, TX); Scott DeBates (Frisco, TX)
Assignee: Advanced Neuromodulation Systems, Inc.
G06F21/445H04L9/3263H04L9/3273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,206
App. No.
18/648,504
Granted
Dec 16, 2025
Kind
B2
Abstract

A system and method for facilitating device and application authentication between an external device and an implanted medical device (IMD), wherein a therapy application executing on the external device is operative to communicate with the IMD via wireless telemetry communications. A device authentication parameter may be decomposed into two key components, wherein one component may be stored in a cloud key vault and the other component may be distributed to the external device as an obfuscated portion embedded in the therapy application. Upon receiving the therapy application, the external device is operative to separately retrieve both key components and reconstitute the original authentication parameter therefrom, which may be presented to the IMD for authentication.

Claims (43)

1 . A method of facilitating authentication between an external device (ED) and an implantable medical device (IMD) of a patient, the method comprising:

generating, a device authentication parameter;

decomposing, the device authentication parameter into a first key component and a second key component;

providing, the first key component to a cloud storage system;

embedding, the second key component into a therapy application that is executable on the external device, wherein the second key component is embedded into the therapy application via encoding in a non-descript string obfuscation; and

retrieving, the second key component from the therapy application, and the first key component from the cloud storage system, wherein the second key component is obtained via non-descript string de-obfuscation from the therapy application, and

generating, based on the retrieving, a reconstituted device authentication parameter from the first key component and the second key component and

authenticating the ED device by presenting the reconstituted device authentication parameter to the IMD.

2 . The method as recited in claim 1 , wherein the first key component comprises a random 128-bit value generated using OpenSSL.

3 . The method as recited in claim 2 , wherein the second key component comprises a value obtained by executing a reversible logic operation combining the random 128-bit value and a binary value of the device authentication parameter.

4 . The method as recited in claim 3 , wherein the reversible logic operation comprises a bitwise XOR operation between the random 128-bit value and the binary value.

5 . The method as recited in claim 1 , further comprising:

storing the reconstituted device authentication parameter in a device keychain; and

accessing the reconstituted device authentication parameter on at least one subsequent attempt to establish connection with the IMD.

6 . The method as recited in claim 1 , wherein the therapy application embedded with the second key component is distributed or otherwise obtained via at least one of a public app store, a private app store, a File Transfer Protocol (FTP) site, an enterprise device management system, a push mechanism or a pull mechanism.

7 . The method as recited in claim 1 , wherein the first key component is obtained from the cloud storage system responsive to an authenticated application programming interface (API) call over a Transport Layer Security (TLS) session.

8 . The method as recited in claim 1 , further comprising:

launching the therapy application and obtaining the second key component.

9 . The method as recited in claim 1 , further comprising configuring the ED one of a clinician programmer device, a patient controller device, or a delegated agent device.

10 . The method as recited in claim 1 , further comprising mutually authenticating between the therapy application of the external device and the IMD based on a pair of challenge-response sequences, each further based on exchanging respective public key infrastructure (PKI) credentials relating to the therapy application and the IMD.

11 . A method of using an external device (ED) operative to communicate with an implantable medical device (IMD) of a patient, the method comprising:

establishing, using communication circuitry of the external device, a wireless telemetry communication link with the IMD;

obtaining, at a therapy application stored in a persistent memory module of the external device, a first key component from a cloud storage system;

obtaining a second key component embedded in the therapy application, wherein the obtaining comprises non-descript string de-obfuscation of data stored in the therapy application;

generating a reconstituted device authentication parameter from the first and second key components to be presented to the IMD for authentication;

storing the reconstituted device authentication parameter in a device keychain; and

establishing a connection with the IMD based on the reconstituted device authentication parameter stored in the device keychain.

12 . The method as recited in claim 11 , wherein the first key component comprises a random 128-bit value generated using OpenSSL.

13 . The method as recited in claim 12 , wherein the second key component comprises a value obtained by executing a reversible logic operation combining the random 128-bit value and a binary value.

14 . The method as recited in claim 13 , wherein the reversible logic operation comprises a bitwise XOR operation between the random 128 -bit value and the binary value.

15 . The method as recited in claim 11 , wherein the persistent memory module includes program instructions for facilitating obtaining the therapy application including the embedded second key component via at least one of a public app store, a private app store, a File Transfer Protocol (FTP) site, an enterprise device management system, a push mechanism and/or a pull mechanism.

16 . The method as recited in claim 11 , wherein the persistent memory module includes program instructions for facilitating obtaining the first key component from the cloud storage system responsive to initiating an authenticated application programming interface (API) call over a Transport Layer Security (TLS) session.

17 . The method as recited in claim 11 , wherein the therapy application further includes program instructions for performing:

storing the reconstituted device authentication parameter in a device keychain; and

accessing the reconstituted device authentication parameter on an attempt to establish connection with the IMD.

18 . The method as recited in claim 11 , wherein the therapy application is configured with a privilege level for operating the external device as one of a clinician programmer device, a patient controller device, or a delegated agent device.

19 . A method of facilitating authentication between an external device (ED) and an implantable medical device (IMD) of a patient, the method comprising:

generating a device authentication parameter having a key strength;

decomposing the device authentication parameter into a first key component and a second key component, the second key component comprises a value obtained by executing a reversible logic operation combining a random value and a binary value of the device authentication parameter;

providing the first key component to a cloud storage system;

embedding the second key component into a therapy application executable on the ED;

responsive to obtaining the first key component from the cloud storage system, retrieving from the therapy application the second key component via non-descript string de-obfuscation, and generating a reconstituted device authentication parameter from the first key component and the second key components; and

authenticating the ED device by presenting the reconstituted device authentication parameter to the IMD.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2024
From: CREEK, GREG; DEBATES, SCOTT
To: ADVANCED NEUROMODULATION SYSTEMS, INC.
Reel/Frame 067975/0929 →
Continuity (3)
Continuation 17527943 · Nov 16, 2021
Provisional Application 63131139 · Dec 28, 2020
Related Publication 20240281517A1 · Aug 22, 2024
References Cited (166)
US 5987519A · Peifer et al. · 1999 [cited by applicant]
US 6085333A · DeKoning et al. · 2000 [cited by applicant]
US 6622050B2 · Thompson · 2003 [cited by applicant]
US 6880085B1 · Balczewski et al. · 2005 [cited by applicant]
US 7027872B2 · Thompson · 2006 [cited by applicant]
US 7039810B1 · Nichols · 2006 [cited by applicant]
US 7155290B2 · Von Arx et al. · 2006 [cited by applicant]
US 7228179B2 · Campen et al. · 2007 [cited by applicant]
US 7228182B2 · Healy et al. · 2007 [cited by applicant]
US 7369897B2 · Boveja · 2008 [cited by applicant]
US 7475245B1 · Healy et al. · 2009 [cited by applicant]
US 7664553B2 · Roberts · 2010 [cited by applicant]
US 7801611B2 · Persen et al. · 2010 [cited by applicant]
US 7818067B2 · Healy et al. · 2010 [cited by applicant]
US 7831828B2 · Von Arx et al. · 2010 [cited by applicant]
US 7890180B2 · Quiles · 2011 [cited by applicant]
US 7930543B2 · Corndorf · 2011 [cited by applicant]
US 7940933B2 · Corndorf · 2011 [cited by applicant]
US 8102999B2 · Corndorf · 2012 [cited by applicant]
US 8218445B2 · Katz et al. · 2012 [cited by applicant]
US 8331563B2 · Healy et al. · 2012 [cited by applicant]
US 8332041B2 · Skelton et al. · 2012 [cited by applicant]
US 8568356B2 · Lebel et al. · 2013 [cited by applicant]
US 8649757B2 · Roberts et al. · 2014 [cited by applicant]
US 8682437B2 · Kalpin et al. · 2014 [cited by applicant]
US 8922330B2 · Moberg et al. · 2014 [cited by applicant]
US 9215075B1 · Poltorak · 2015 [cited by applicant]
US 9288614B1 · Young et al. · 2016 [cited by applicant]
US 9348974B2 · Goetz · 2016 [cited by applicant]
US 9401894B2 · Kalpin et al. · 2016 [cited by applicant]
US 9445264B2 · Young et al. · 2016 [cited by applicant]
US 9446252B2 · Benson · 2016 [cited by applicant]
US 9649049B2 · Pless et al. · 2017 [cited by applicant]
US 9722803B1 · Ellingson et al. · 2017 [cited by applicant]
US 9773060B2 · Gerst et al. · 2017 [cited by applicant]
US 9855433B2 · Shahandeh et al. · 2018 [cited by applicant]
US 9893961B2 · Keith, Jr. · 2018 [cited by applicant]
US 9906360B2 · Johnson · 2018 [cited by examiner]
US 9942051B1 · Poltorak · 2018 [cited by applicant]
US 9974108B2 · Polefko · 2018 [cited by applicant]
US 10086202B2 · Seim et al. · 2018 [cited by applicant]
US 10117580B1 · Puryear · 2018 [cited by applicant]
US 10124177B2 · Kumar · 2018 [cited by applicant]
US 10147502B2 · Paffel et al. · 2018 [cited by applicant]
US 10306472B2 · Battiwalla et al. · 2019 [cited by applicant]
US 10493287B2 · Yoder et al. · 2019 [cited by applicant]
US 10511436B1 · Machani · 2019 [cited by examiner]
US 10516527B1 · Machani · 2019 [cited by applicant]
US 10554632B2 · Lange · 2020 [cited by applicant]
US 10576290B2 · Schilling et al. · 2020 [cited by applicant]
US 10599814B2 · Landrum et al. · 2020 [cited by applicant]
US 11007370B2 · Shahandeh et al. · 2021 [cited by applicant]
US 11364386B2 · Ibarrola · 2022 [cited by applicant]
US 20020015401A1 · Subramanian et al. · 2002 [cited by applicant]
US 20020072785A1 · Nelson et al. · 2002 [cited by applicant]
US 20020082665A1 · Haller et al. · 2002 [cited by applicant]
US 20030083719A1 · Shankar et al. · 2003 [cited by applicant]
US 20030088295A1 · Cox · 2003 [cited by applicant]
US 20030093127A1 · Dalal · 2003 [cited by applicant]
US 20040117206A1 · Steinberger et al. · 2004 [cited by applicant]
US 20040167587A1 · Thompson · 2004 [cited by applicant]
US 20050033369A1 · Badelt · 2005 [cited by applicant]
US 20050203582A1 · Healy et al. · 2005 [cited by applicant]
US 20050261934A1 · Thompson · 2005 [cited by applicant]
US 20050283210A1 · Blischak et al. · 2005 [cited by applicant]
US 20050288736A1 · Persen et al. · 2005 [cited by applicant]
US 20060030904A1 · Quiles · 2006 [cited by applicant]
US 20060189854A1 · Webb et al. · 2006 [cited by applicant]
US 20060265022A1 · John et al. · 2006 [cited by applicant]
US 20070016257A1 · Brown et al. · 2007 [cited by applicant]
US 20070038867A1 · Verbauwhede · 2007 [cited by examiner]
US 20070136098A1 · Smythe et al. · 2007 [cited by applicant]
US 20070150013A1 · Ding et al. · 2007 [cited by applicant]
US 20080140163A1 · Keacher et al. · 2008 [cited by applicant]
US 20080163361A1 · Davis et al. · 2008 [cited by applicant]
US 20080215119A1 · Woods et al. · 2008 [cited by applicant]
US 20080288029A1 · Healy et al. · 2008 [cited by applicant]
US 20090048644A1 · Stahmann et al. · 2009 [cited by applicant]
US 20090069867A1 · Kenknight et al. · 2009 [cited by applicant]
US 20090281598A1 · Haubrich et al. · 2009 [cited by applicant]
US 20090326608A1 · Huynh et al. · 2009 [cited by applicant]
US 20100010572A1 · Skelton et al. · 2010 [cited by applicant]
US 20100066500A1 · Ljungstrom et al. · 2010 [cited by applicant]
US 20100211135A1 · Caparso · 2010 [cited by applicant]
US 20110009916A1 · Efimov et al. · 2011 [cited by applicant]
US 20110145588A1 · Stubbs et al. · 2011 [cited by applicant]
US 20110171905A1 · Roberts et al. · 2011 [cited by applicant]
US 20110172740A1 · Matos · 2011 [cited by applicant]
US 20120197347A1 · Olson et al. · 2012 [cited by applicant]
US 20130154851A1 · Gaskill et al. · 2013 [cited by applicant]
US 20130185783A1 · Jelatis · 2013 [cited by examiner]
US 20130218582A1 · Lalonde · 2013 [cited by applicant]
US 20130246084A1 · Parmanto et al. · 2013 [cited by applicant]
US 20140055230A1 · Hoyme et al. · 2014 [cited by applicant]
US 20140122120A1 · Doudian · 2014 [cited by applicant]
US 20140185805A1 · Andersen · 2014 [cited by applicant]
US 20140244305A1 · Schoenberg · 2014 [cited by applicant]
US 20140273824A1 · Fenner et al. · 2014 [cited by applicant]
US 20150032633A1 · Haider et al. · 2015 [cited by applicant]
US 20150033365A1 · Mellor et al. · 2015 [cited by applicant]
US 20150089590A1 · Krishnan et al. · 2015 [cited by applicant]
US 20150117645A1 · Carlson et al. · 2015 [cited by applicant]
US 20150149787A1 · Panchapakesan · 2015 [cited by examiner]
US 20150281285A1 · Bharali et al. · 2015 [cited by applicant]
US 20150321003A1 · Pless et al. · 2015 [cited by applicant]
US 20150343229A1 · Peterson et al. · 2015 [cited by applicant]
US 20150358583A1 · Lee et al. · 2015 [cited by applicant]
US 20160330573A1 · Masoud et al. · 2016 [cited by applicant]
US 20160342762A1 · Goetz · 2016 [cited by applicant]
US 20170032092A1 · Mink et al. · 2017 [cited by applicant]
US 20170111488A1 · Mazar et al. · 2017 [cited by applicant]
US 20170203111A1 · Pless · 2017 [cited by examiner]
US 20170259072A1 · Newham et al. · 2017 [cited by applicant]
US 20170296076A1 · Mahajan et al. · 2017 [cited by applicant]
US 20170304636A1 · Steinke et al. · 2017 [cited by applicant]
US 20170325091A1 · Freeman · 2017 [cited by applicant]
US 20180028827A1 · Schilling et al. · 2018 [cited by applicant]
US 20180110475A1 · Shaya · 2018 [cited by applicant]
US 20180241564A1 · Peterson · 2018 [cited by applicant]
US 20180243573A1 · Yoder · 2018 [cited by applicant]
US 20180309766A1 · Marnfeldt · 2018 [cited by applicant]
US 20180325463A1 · Walsh · 2018 [cited by applicant]
US 20180361153A1 · Heldman et al. · 2018 [cited by applicant]
US 20190182617A1 · Zamber · 2019 [cited by applicant]
US 20190365228A1 · Rondini · 2019 [cited by applicant]
US 20200086128A1 · Rondini · 2020 [cited by applicant]
US 20200228349A1 · Basu · 2020 [cited by applicant]
US 20200398063A1 · DeBates et al. · 2020 [cited by applicant]
US 20200402656A1 · DeBates et al. · 2020 [cited by applicant]
US 20200402674A1 · DeBates et al. · 2020 [cited by applicant]
US 20210058257A1 · Pepin · 2021 [cited by examiner]
US 20210367767A1 · Saravanan · 2021 [cited by applicant]
US 20220337403A1 · Nagai · 2022 [cited by applicant]
US 20230201607A1 · Nin · 2023 [cited by examiner]
EP 3091459A1 · 2016 [cited by applicant]
EP 3466484A1 · 2019 [cited by applicant]
WO WO0193953A1 · 2001 [cited by applicant]
WO WO2017165717A1 · 2017 [cited by applicant]
WO WO2019032788A1 · 2019 [cited by applicant]
Chan et al., “On the Distribution and Revocation of Cryptographic Keys in Sensor Networks,” IEEE Transactions on Dependable and Secure Computer, vol. 2, issue 3, Jul.-Sep. 2005, pp. 233-247, 2005. [cited by applicant]
Epstein, M. A. et al. “Security for the Digital Information Age of Medicine: Issues, Applications, and Implementation,” Journal of Digital Imaging, vol. 11, No. 1, Feb. 1998, 12 pages. [cited by applicant]
European Patent Office, Communication, Extended European Search Report for Patent Application No. 19878741.8, dated Jun. 22, 2022, 6 pages. [cited by applicant]
European Patent Office, Communication, Extended European Search Report for Patent Application No. 19879674.0, dated Jul. 1, 2022, 6 pages. [cited by applicant]
European Patent Office, Communication, Extended European Search Report for Patent Application No. 19880173.0, dated Jun. 22, 2022, 7 pages. [cited by applicant]
European Patent Office, Communication, Extended European Search Report for Patent Application No. 19880409.8, dated Jun. 22, 2022, 7 pages. [cited by applicant]
Halperin, Daniel, et al. “Security and Privacy for Implantable Medical Devices,” IEEE Pervasive Computing vol. 7, No. 1 (2008): 30-39. 11 pages. [cited by applicant]
Intemational Search Report for PCT/US2019/59485; dated Feb. 3, 2020; 8 pgs. [cited by applicant]
Intemational Search Report for PCT/US2019/59489; dated Feb. 4, 2020; 9 pgs. [cited by applicant]
Intemational Search Report for PCT/US2019/59497; dated Feb. 4, 2020; 9 pgs. [cited by applicant]
Intemational Search Report for PCT/US2019/59501; dated Feb. 4, 2020; 14 pgs. [cited by applicant]
Intemational Search Report for PCT/US2019/59507; dated Feb. 6, 2020; 8 pgs. [cited by applicant]
NPL Search Terms—reconciling software configuration changes, reconciling software configuration changes medical devices (Year: 2023); 1 page. [cited by applicant]
NPL Search Terms—implantable medical device security key, reconciling configuration changes medical devices (Year: 2023); 1 page. [cited by applicant]
Park, Chang-Seop, “Security Mechanism Based on Hospital Authentication Server for Secure Application of Implantable Medical Devices,” BioMed Research International, vol. 2014, Hindawi Publishing Corporation, Jul. 2014, … [cited by applicant]
Xu, F. et al. “IMDGuard: Securing Implantable Medical Devices With the External Wearable Guardian,” 2011 Proceedings IEEE INFOCOM, Shanghai, China, Apr. 10-15, 2011, 9 pages. [cited by applicant]
USPTO, Notice of Allowance, U.S. Appl. No. 16/901,368, May 13, 2021, 5 pgs. [cited by applicant]
International Search Report for PCT/US2020/034519; dated Sep. 21, 2020; 16 pgs. [cited by applicant]
International Search Report for PCT/US2020/037180; dated Sep. 4, 2020; 11 pgs. [cited by applicant]
International Search Report for PCT/US2020/038165; dated Sep. 11, 2020; 25 pgs. [cited by applicant]
International Search Report for PCT/US2020/038434; dated Sep. 10, 2020; 20 pgs. [cited by applicant]
Kim et al., Self-Organizing Peer-to-Peer Middleware for Healthcare Monitoring in Real-time, Sensors, Nov. 17, 2017, pp. 1-19, MDPI. [cited by applicant]
Ricci et al., Home Monitoring Remote Control of Pacemaker and Implantable Cardioverter Defibrillator Patients in Clinical Practice: Impact on medical Management and Heal-Care Resource Ultization, Europace, Jan. 16, 2008… [cited by applicant]
Sundaravadivel et al., “Everything You Wanted to Know About Smart Health Care,” IEEE Consumer Electronics Magazine, Dec. 13, 2017, pp. 18-28, IEEE Consumer Technology Society. [cited by applicant]
Vegesna et al., “Remote Patient Monitoring via Non-Invasive Digital Technolgies: A Systematic Review,” Telemedicine and e-Health, Jan. 2017, pp. 3-17, Mary Ann Liebert, Inc. [cited by applicant]
Wazid et al., “A Novel Authentication and Key Agreement Scheme for Implantable Medical Devices Deployment,” IEEE Journal of Biomedical and Health Informatics, vol. 22, No. 4, pp. 1299-1309, 2018. [cited by applicant]
Gordon, “Simple Introduction to Using OpenSSI on Command Line,” 2013, http://sandilands.info/simple-introduction-to-using-openssi-on-command-line, 2013. [cited by applicant]