用物理单向通道实现医疗问诊本地化,杜绝网络攻击风险。
Sovereign AI at the Front Door of Care: A Physically Unidirectional Architecture for Secure Clinical Intelligence
- 所有诊断在设备端完成,数据仅单向流入不回传。
- 支持本地症状采集与生命体征整合,生成结构化病历。
- 适合资源受限或高安全要求的临床场景,如急诊室。
我们提出一种主权人工智能架构,用于临床分诊:所有推理在设备端完成,输入数据通过仅接收广播基础设施或经认证的硬件数据隔离器实现物理单向传输,无任何外部网络回传路径。该设计从构造上消除网络攻击面,而非依赖软件防护。系统支持对话式症状采集,融合设备获取的生命体征,于诊疗现场生成结构化、分诊对齐的临床记录。我们形式化定义了接收端单向性的安全属性,并证明该架构在广播与数据隔离器部署下均具备传输无关性。进一步分析威胁模型、执行机制与部署配置,表明物理单向数据流可在资源受限及高风险环境中实现高保障运行。本工作将物理单向通道确立为医疗前端智能的基石范式。
原文摘要 · Abstract (English)
We present a Sovereign AI architecture for clinical triage in which all inference is performed on-device and inbound data is delivered via a physically unidirectional channel, implemented using receive-only broadcast infrastructure or certified hardware data diodes, with no return path to any external network. This design removes the network-mediated attack surface by construction, rather than attempting to secure it through software controls. The system performs conversational symptom intake, integrates device-captured vitals, and produces structured, triage-aligned clinical records at the point of care. We formalize the security properties of receiver-side unidirectionality and show that the architecture is transport-agnostic across broadcast and diode-enforced deployments. We further analyze threat models, enforcement mechanisms, and deployment configurations, demonstrating how physical one-way data flow enables high-assurance operation in both resource-constrained and high-risk environments. This work positions physically unidirectional channels as a foundational primitive for sovereign, on-device clinical intelligence at the front door of care.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。