🤖 AI Summary
This study addresses the absence of deterministic safety constraints when medical AI agents interface with clinical devices by proposing a "bounded safety" paradigm that establishes a secure gateway from the Service-oriented Device Connectivity (SDC) standard to the Model Context Protocol (MCP). Implemented via a Python prototype, the approach enforces a strict separation between semantically explicit resource exposure and action proposal. It exposes physiological metrics in a read-only manner and leverages policy validation tools to simulate operations, thereby ensuring a zero-execution safety boundary. Experimental results demonstrate that this mechanism effectively rejects invalid states and substantially improves structured output compliance. Furthermore, the findings elucidate the fundamental distinction between narrative plausibility and machine-readable compliance, offering critical insights for the safe integration of AI agents into regulated medical device ecosystems.
📝 Abstract
The Model Context Protocol (MCP) provides a common interface through which AI applications discover and use external resources and tools. It allows language-model agents to ground their reasoning in current system state and interact with heterogeneous services. In medical environments, however, exposing device state and action affordances requires deterministic constraints on possible effects. We present an IEEE 11073 Service-Oriented Device Connectivity (SDC)-to-MCP gateway that exposes metrics, alarms, context references, and semantic metadata as read-only resources, while representing selected action affordances as policy-validated dry-run tools. The term safety-bounded denotes a narrow no-execution property: agent-facing requests dispatch no SDC device operation. A Python prototype supports simulated fault and lifecycle experiments, a software-reference protocol path spanning independent Java and Python implementations, deterministic baselines, representation ablations, and multi-model agent evaluation. The results show semantically explicit resource exposure, visible rejection of invalid or outdated state, and preservation of the no-execution boundary across resource, proposal, and authorization paths. Explicit semantic metadata improved conformity to required metric identifiers in structured alarm outputs relative to a generic representation, while retained structured-output failures reveal a distinction between plausible narrative answers and task-compliant machine-readable results.