Securing Telemetry Pipelines in Connected Infusion Pumps Against Micro-Bolus Spoofing

Smart infusion pumps deliver potent analgesics and cardiac medications under closed-loop control. A corrupted telemetry packet altering infusion rates by fractions of a milliliter can lead to fatal patient outcomes. This engineering paper evaluates mutual TLS session anchoring, cryptographic hardware checksums, and CAN/Ethernet bridge security under FDA draft guidance on medical device cybersecurity.

Attack Vectors and Physical Packet Tampering

Man-in-the-middle attacks targeting serial-to-Wi-Fi converter chips frequently bypass unauthenticated RTOS sockets. By implementing hardware-enforced AES-GCM message authentication codes (MAC) with monotonic sequence counters, replay attacks and rate injection are definitively prevented.

Cryptographic Interlocks and Failsafe Firmware

If cryptographic validation fails twice consecutively, the pump firmware immediately defaults to a hardcoded minimal basal rate and triggers an audible IEC 60601-1-8 high-priority alarm, completely decoupling physical motor actuators from network telemetry.

Explore Health Domain Portfolio