Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI...

20
Ken Fuchs Sr. Principal Architect Mindray North America October 4, 2012 Risk Management of Systems of Systems… The opinions expressed in this presentation are solely those of the author.

Transcript of Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI...

Page 1: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

Ken Fuchs Sr. Principal Architect

Mindray North America October 4, 2012

Risk Management of Systems of

Systems…

The opinions expressed in this presentation are solely those of the author.

Page 2: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Wireless – The Opportunity

• There is no question that interest in wireless is booming!

• Wireless solutions can enable many improvements in current healthcare technologies and will enable new ones.

• Unfortunately, like almost anything, we have to be careful to manage any new risks introduced by this technology…

Page 4: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Risk Assessment

• In general we need to assess various ‘wireless’ risks such as… – Risk of Interference – Risk of Lack of Bandwidth – Risk of Infrastructure Incompatibility – Risk of Lack of Coverage – Risk of System Failure – Risk of Poor Management – etc.

Page 5: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Wireless Technologies – Use Cases…

• We must look at risks in context. • For the sake of discussion, we can

look at: – WAN – Wide Area Network

• Primarily 3G / 4G “mobile” technologies – LAN – Local Area Network

• Primarily 802.11 -BT and Zigbee are applicable • Proprietary approaches especially in WMTS

– BAN – Body Area Network • Typical technologies are BT, ZigBee, ANT • Proprietary approaches very possible

Page 6: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Risk Assessment - WAN • These technologies own their spectrum so

there is minimal chance of interference • Dedication of bandwidth to your

application may be an issue • Infrastructure is controlled by the vendor • Coverage can vary widely from provider to

provider and within a location • System failures can occur but

considerable redundancy is built into the system

• Management of these systems is very controlled and professional

Page 7: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Risk Assessment – LAN – ISM Bands • Solutions share spectrum so there is

substantial chance of interference – Some of this interference can be controllable while

other interference can be out of your control • Dedication of bandwidth to an application

can be arranged – depend on infrastructure…

• Infrastructure is typically controlled by the hospital (More on next slide…)

• Coverage can be relatively well controlled • System failures can certainly occur… • Management of these systems depends

widely from one hospital to another

Page 8: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Risk Assessment – LAN – ISM Bands

• Infrastructure performance will differ from one vendor to another. – Roaming performance – Bandwidth management – Number of clients supported – Rogue AP detection mechanisms

• May also differ from one firmware release to another…

• How to mitigate? – How to manage?

Page 9: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Left as an Exercise to the “student”…

– Risk Assessment – LAN – Special Bands • WMTS in US • HINT:

Special Band solutions may reduce but do not shield you from wireless risks. However this is usually the responsibility of the vendor to manage.

– Risk Assessment – BAN – ISM Bands – Risk Assessment – BAN – Special Bands

• MBAN in US

Page 10: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Critical Care Wireless Body Area Networks The Future? (Scary…) BYOMD (Bring Your Own Medical Device?)

Page 11: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Critical Care Wireless Body Area Networks How Do We Manage This Scenario? (All the same same wireless protocol)

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

Risks: •Interfere

WABZ = WiFi or ANT or BT or ZB

Page 12: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Critical Care Wireless Body Area Networks Need to Consider this Scenario

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

Risks: •Interfere

WABZ = WiFi or ANT or BT or ZB

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

WABZ

Page 13: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Critical Care Wireless Body Area Networks How Do we Manage This Scenario? (All in the same spectrum band…)

BT

ZB

ANT+

Proprietary

DECT

DECT

BT

ZB

Proprietary

Risks: •Interfere

Page 14: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

What About Communications Interoperability?

Page 15: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

What About Communications Interoperability?

DECT Bluetooth

Zigbee WiFi Ant Etc.

Interoperability =

Page 16: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

What About Communications Interoperability? • A complete solution

requires answers to all layers of the ISO/OSI communications stack.

• Wireless is a Layer 1/2 choice. – Many more Layers to

address… • For Medical Devices Layer

7 (and up) is the “Wild West” …

Page 17: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

Interoperability – The Full Picture

None

Technical

Syntactic

Semantic

Pragmatic

Dynamic

Level 0

Level 1

Level 2

Level 3

Level 4

Level 5

Incr

easi

ng C

apab

ility

for I

nter

oper

atio

n

Asso

ciat

ion

Auth

entic

atio

n Au

thor

izat

ion

Dis

cove

ry

Safe

ty

Secu

rity

Cer

tific

atio

n Interfaceable

Integratable

Interoperable

Page 18: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

What About Interoperability?

• There are many organizations working on various aspects of Medical Device Communications Interoperability: – MDICC – IEEE 11073 – DICOM – HL7 – MDPnP (ASTM ICE Standard) – UL – IHE-PCD – Continua

Page 19: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

The Future…

• We have processes that can be followed to manage risk.

• However in the coming era of BYOMD the processes will not be followed…

• We will need interoperable Communication Standards based devices that when placed in Systems of Systems manage themselves! – This will become a major challenge…

Page 20: Risk Management of Systems of Systemss3.amazonaws.com/.../Fuchs_AAMI_Wireless_Workshop.pdf · AAMI Wireless Workshop - 2012 . Risk Assessment • In general we need to assess various

AAMI Wireless Workshop - 2012

To Summarize…