Differential, Attested, and Clinically-Aware OTA for Android Medical Fleets: A Policy-Driven Orchestration Framework

Authors

  • Riddhi Patel

DOI:

https://doi.org/10.22399/ijcesen.4587

Keywords:

Over-The-Air Updates, Medical Device Security, Android Fleet Management, Software Bill Of Materials, Clinical Risk Management

Abstract

Healthcare organizations increasingly deploy Android devices as gateways and embedded systems in regulated environments. Fleet updates remain risky because defective patches can interrupt monitoring, breach compliance, or expose devices to known vulnerabilities. A regulated over-the-air orchestration framework tailored to medical fleets addresses these challenges. The framework combines differential patching using bsdiff-class algorithms with software bill of materials provenance. Android Verified Boot and attestation capabilities strengthen device integrity verification. Phased rollouts bound to clinical risk enable controlled deployment. Automatic rollback prevents widespread service disruption. Policies are enforced using Android Management API controls, including windowed updates, freeze periods, and kiosk constraints. Post-install health probes verify Bluetooth Low Energy reconnection, sensor latency, and application state. Content-risk scoring modulates rollout velocity based on whether changes affect kernel components or user interface elements. Software bill of materials components link directly to known vulnerabilities in public databases. Simulated and pilot deployments demonstrate reduced remediation latency and prevention of care-critical regressions compared with all-at-once update strategies. The design meets the FDA premarket cybersecurity requirements, and NIST Secure Software Development Framework, and attestation logs, software bill of materials, and risk score justifications support regulatory submissions and inspections.

References

1. Pian Qi, et al., "A blockchain-based secure Internet of medical things framework for stress detection," Information Sciences, 2023. [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S0020025523001354

2. Jenn Gile, "SBOM Requirements for Medical Devices," Endorlabs, 2023. [Online]. Available: https://www.endorlabs.com/learn/sbom-requirements-for-medical-devices

3. Saad El Jaouhari and Eric Bouvet, "Secure firmware Over-The-Air updates for IoT: Survey, challenges, and discussions," Internet of Things, 2022. [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S2542660522000142

4. Keke Gai, "Permissioned Blockchain and Edge Computing Empowered Privacy-Preserving Smart Grid Networks," IEEE Xplore, 2019. [Online]. Available: https://ieeexplore.ieee.org/document/8664577

5. Phillip Williams, et al., "A survey on security in the internet of things with a focus on the impact of emerging technologies," Internet of Things, 2022. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S2542660522000592

6. Haipeng Yao, et al., "Resource Trading in Blockchain-Based Industrial Internet of Things," IEEE Xplore, 2019. [Online]. Available: https://ieeexplore.ieee.org/document/8657779

7. Dinh C. Nguyen, et al., "Integration of Blockchain and Cloud of Things: Architecture, Applications and Challenges - 2020" S-Logix, 2020. [Online]. Available: https://slogix.in/blockchain-technology/integration-of-blockchain-and-cloud-of-things-architecture-applications-and-challenges/

8. Md. Rahat Hasan, et al., "Smart Contract-Based Access Control Framework for Internet of Things Devices," Computers, 2023. [Online]. Available: https://www.mdpi.com/2073-431X/12/11/240

9. Jatinder Singh, et al., "Twenty Security Considerations for Cloud-Supported Internet of Things," ResearchGate, 2016. [Online]. Available: https://www.researchgate.net/publication/280500892_Twenty_Security_Considerations_for_Cloud-Supported_Internet_of_Things

10. Kyeong Tae Kim, et al., "An IoT Device-trusted Remote Attestation Framework," ResearchGate, 2022. [Online]. Available: https://www.researchgate.net/publication/359191862_An_IoT_Device-trusted_Remote_Attestation_Framework

Downloads

Published

2025-12-25

How to Cite

Riddhi Patel. (2025). Differential, Attested, and Clinically-Aware OTA for Android Medical Fleets: A Policy-Driven Orchestration Framework. International Journal of Computational and Experimental Science and Engineering, 11(4). https://doi.org/10.22399/ijcesen.4587

Issue

Section

Research Article