发表机构
University of Lübeck(吕贝克大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对医疗环境,提出一个安全受限的SDC-to-MCP网关,将设备指标等暴露为只读资源,操作工具经策略验证且不执行设备操作,实验验证了其安全边界和语义元数据的有效性。
AI 中文摘要
模型上下文协议(MCP)提供了一个通用接口,AI应用程序通过该接口可以发现并使用外部资源和工具。它使语言模型智能体能够基于当前系统状态进行推理,并与异构服务交互。然而,在医疗环境中,暴露设备状态和操作能力需要对可能产生的影响施加确定性约束。我们提出了一种IEEE 11073面向服务的设备连接(SDC)到MCP的网关,该网关将指标、警报、上下文引用和语义元数据作为只读资源暴露,同时将选定的操作能力表示为经过策略验证的试运行工具。“安全受限”一词表示一种严格的“不执行”属性:面向智能体的请求不会触发任何SDC设备操作。一个Python原型支持模拟故障和生命周期实验、一条跨越独立Java和Python实现的软件参考协议路径、确定性基线、表示消融以及多模型智能体评估。结果表明,语义明确的资源暴露、对无效或过期状态的可见拒绝,以及在资源、提案和授权路径上均保持了“不执行”边界。与通用表示相比,显式语义元数据提高了结构化警报输出中对所需指标标识符的符合性,而保留的结构化输出失败则揭示了看似合理的叙述性答案与符合任务的机器可读结果之间的区别。
英文摘要
The Model Context Protocol (MCP) provides a common interface through which AI applications discover and use external resources and tools. It allows language-model agents to ground their reasoning in current system state and interact with heterogeneous services. In medical environments, however, exposing device state and action affordances requires deterministic constraints on possible effects. We present an IEEE 11073 Service-Oriented Device Connectivity (SDC)-to-MCP gateway that exposes metrics, alarms, context references, and semantic metadata as read-only resources, while representing selected action affordances as policy-validated dry-run tools. The term safety-bounded denotes a narrow no-execution property: agent-facing requests dispatch no SDC device operation. A Python prototype supports simulated fault and lifecycle experiments, a software-reference protocol path spanning independent Java and Python implementations, deterministic baselines, representation ablations, and multi-model agent evaluation. The results show semantically explicit resource exposure, visible rejection of invalid or outdated state, and preservation of the no-execution boundary across resource, proposal, and authorization paths. Explicit semantic metadata improved conformity to required metric identifiers in structured alarm outputs relative to a generic representation, while retained structured-output failures reveal a distinction between plausible narrative answers and task-compliant machine-readable results.
Comments18 pages. Code: https://github.com/fischesn/sdc-mcp-gateway . Software and evaluation artifacts: https://doi.org/10.5281/zenodo.22960634