Review the Architecture for Any Dependence on the Network
Safe Offline, Better Online Architecture Review
Companion to Medical Device Connectivity · Updated 2026-09-29
Use this at architecture review, before the design freezes, and again before any change that adds a network dependency. Systems architects, safety engineers, and security engineers run it together; “A Device’s Safety Should Never Depend on the Network” works it on the ventilator. Keep the completed review with the risk analysis and the software lifecycle records it feeds, as that chapter describes.
The review checks the design against the doctrine’s engineering target: local autonomy + external interoperability + deliberate degradation + durable synchronization + lifecycle manageability. Layers 1 to 4 form the local safety plane, and layers 5 to 8 form the network enhancement plane. Nothing in the enhancement plane may be required for essential function. Answer each layer’s question. Record the result in the last column as pass, fail, or open, with what the review found.
The Safe Offline, Better Online Architecture Review: eight layers, from the device outward, with the local safety plane first.
| Plane | Layer | Review question | Pass when | Finding |
|---|---|---|---|---|
| Local safety plane | 1. Essential clinical or process function | What must the device do with no network, gateway, cloud, or artificial intelligence (AI) service? | The essential local safety envelope is written down, traced to the risk analysis, and depends on nothing in layers 5 to 8. | |
| 2. Local identity | Can the device know its own identity and its operators with the identity provider unreachable? | Therapy changes, alarm acknowledgment, and stopping a therapy never depend on the identity provider or on a credential that can expire. A local operator identity or a local emergency (break-glass) path covers them, and the device logs each use for later reconciliation. Cached enterprise credentials govern only non-essential functions. | ||
| 3. Local durable event store | Does every event that can’t be lost reach durable local storage before the device sends it anywhere? | Each event is journaled in one atomic write that carries its own send state, with the device’s time, a time-quality flag, a monotonic counter, a sequence number within a journal epoch, and provenance. Records survive power loss, are append-only, and are hash-chained or signed so a receiver can detect alteration or deletion. The journal is sized for a documented worst-case outage, and the rule for a filling journal is defined. | ||
| 4. Device information model | Are events, states, commands, measurements, and identities defined independently of any protocol? | A written information model exists, and the device software uses it internally. | ||
| Network enhancement plane | 5. Connectivity abstraction | Can the team change a transport without changing layers 1 to 4? | Transport code sits behind a defined interface. A transport failure puts the device in a defined degraded mode and never faults essential function. Enhancement-plane software runs on a separate processor, or in a partition or process with bounded queues and enforced limits, so its crash, memory exhaustion, or message load can’t starve essential function. | |
| 6. Gateway and integration | Where do mappings to standards and enterprise interfaces live, and what happens when the gateway is gone? | Mappings live outside the device core. With the gateway down, the device journals and waits. | ||
| 7. Enterprise services | Which enterprise systems consume the device’s data or send it commands, and does any of them sit in the path of essential function? | None does. The device validates every command from an enterprise system locally and can refuse it. | ||
| 8. Cloud and AI services | What does each cloud or AI service add, and what happens without it? | Each one is an enhancement with a defined degraded mode. None is needed for essential function. Any AI advice is decision support a clinician acts on, shows the age of its inputs, and degrades to no advice when those inputs are stale. |
The review isn’t finished until the design names a degraded mode for each dependency failure below, and each one has a completed row in the Offline Failure Mode Worksheet:
- Enterprise network down
- Domain name system (DNS) failure
- Identity provider unavailable
- Vendor cloud unavailable
- Gateway unavailable
- Time service unavailable
- Credentials expired
- Software update incomplete
- Remote AI service unavailable
For a device that forwards alarms, the design also says how the device shows at the bedside that forwarding has stopped, and how the receiving system detects the silent device by missed heartbeats and escalates to a staffed fallback. One finding of an enhancement-plane dependency inside essential function fails the review. The fix is architectural, and it only gets more expensive after the design freezes.
