Smart infusion pumps deliver potent analgesics and cardiac medications under closed-loop control. A corrupted telemetry packet altering infusion rates by fractions of a milliliter can lead to fatal patient outcomes. This engineering paper evaluates mutual TLS session anchoring, cryptographic hardware checksums, and CAN/Ethernet bridge security under FDA draft guidance on medical device cybersecurity.
Man-in-the-middle attacks targeting serial-to-Wi-Fi converter chips frequently bypass unauthenticated RTOS sockets. By implementing hardware-enforced AES-GCM message authentication codes (MAC) with monotonic sequence counters, replay attacks and rate injection are definitively prevented.
If cryptographic validation fails twice consecutively, the pump firmware immediately defaults to a hardcoded minimal basal rate and triggers an audible IEC 60601-1-8 high-priority alarm, completely decoupling physical motor actuators from network telemetry.