ABSTRACT
Abstract
A medical device of a medical system is configured for communicating with an external programmer over a wireless communications link. The medical device comprises a wireless communications module configured for receiving a first unencrypted version of a random number and a first encrypted version of the random number from the external programmer over the wireless communications link. The medical device further comprises control circuitry configured for performing an authentication procedure on the external programmer based on the first unencrypted version of the random number and the first encrypted version of the random number, and preventing the external programmer from commanding the medical device to perform an action unless the authentication procedure is successful.
Description
RELATED APPLICATION
The present application is a continuation of U.S. patent application Ser. No. 17/664,360, filed May 20, 2022, entitled, âSYSTEM AND METHOD FOR AUTHENTICATING WIRELESS PROGRAMMING DEVICES IN PROGRAMMABLE MEDICAL SYSTEMS,â which is a continuation of U.S. patent application Ser. No. 16/869,863, filed May 8, 2020, entitled, âSYSTEM AND METHOD FOR AUTHENTICATING WIRELESS PROGRAMMING DEVICES IN PROGRAMMABLE MEDICAL SYSTEMS,â which is a continuation of U.S. patent application Ser. No. 15/452,339, filed Mar. 7, 2017, entitled, âSYSTEM AND METHOD FOR AUTHENTICATING WIRELESS PROGRAMMING DEVICES IN PROGRAMMABLE MEDICAL SYSTEMS,â which claims priority from U.S. Provisional Patent Application Ser. No. 62/304,603, filed Mar. 7, 2016, which are expressly incorporated herein by reference.
FIELD OF THE INVENTION
The present invention generally relates to wireless programming techniques in medical systems, and specifically relates to authenticating wireless programming devices, such as clinician programmers, for use in programmable medical systems.
BACKGROUND OF THE INVENTION
Medical systems, such as implantable medical systems, typically comprise one or more implantable medical devices and an external telemetry controller capable of controlling operation of the implanted medical device(s) and acquiring physiological data or operational status data from the implanted medical device(s). Implantable medical systems may further comprise an external programmer, such as a clinician programmer or patient programmer, that may download operating parameters or programs into the telemetry controller to set or otherwise modify the operating configuration of the implantable medical system and/or upload information, such as the physiological data or operational status data, from the telemetry controller.
Communication between such an external programmer and telemetry controller of an implantable medical system may be conveniently accomplished through wireless means, such as radio frequency (RF) communication. One method of wirelessly communicating between an external programmer and a telemetry controller uses a short-range RF communications in accordance with Bluetooth technology. The external programmer and telemetry controller can be paired by exchanging or otherwise storing a shared secret key (referred to as a âlink keyâ) that is used to subsequently authenticate the external programmer and encrypt data and commands sent between the external programmer and telemetry controller. Thus, by design, only the external programmer and any previously paired external programmer are permitted to communicate with the telemetry controller.
However, present telemetry controllers that communicate with external programmers over a Bluetooth communications link may be susceptible to inadvertent or intentional hijacking by unauthorized users, because the link key may be surreptitiously acquired or otherwise generated as a default in some operational systems, such as Linux. Once acquired, the shared link key can be used by any device to communication with the telemetry controller. As such, a potential vulnerability from undesired modification of the operating configuration of medical equipment may arise.
There, thus, remains a need for preventing or otherwise deterring unauthorized programming of medical equipment, such as telemetry controllers used in implantable medical systems.
SUMMARY OF THE INVENTION
In accordance with a first aspect of the present inventions, a medical device of a medical system configured for communicating with an external programmer over a wireless communications link (e.g., one having a range of less than one hundred feet) is provided.
The medical device comprises a wireless communications module configured for receiving a first unencrypted version of a random number and a first encrypted version of the random number from the external programmer over the wireless communications link. In one embodiment, the wireless communications module is a radio frequency (RF) communications module, such as one that communicates with the external programmer in accordance with a Bluetooth or a Wi-Fi protocol.
The medical device further comprises control circuitry (e.g., a microcontroller) configured for performing an authentication procedure on the external programmer based on the first unencrypted version of the random number and the first encrypted version of the random number, and preventing the external programmer from commanding the medical device to perform an action (e.g., allowing modification of at least one operational parameter of the medical system) unless the authentication procedure is successful. The wireless communications module may be hardwired to the control circuitry. The wireless communications module may be configured for establishing the wireless communications link with the external programmer by authenticating the external programmer at a first security level, sending status messages to the control circuitry indicating the status of the wireless communications link with the external programmer, in which case, the control circuitry may be configured for performing the authentication procedure at a second security level.
In one embodiment, the control circuitry is configured for performing the authentication procedure by generating a second encrypted version of the random number from the first unencrypted version of the random number, comparing the first and second versions of the encrypted random number, and determining if the first and second versions of the encrypted random number match. In another embodiment, the control circuitry is configured for performing the authentication procedure by decrypting the first encrypted version of the random number to recover a second unencrypted version of the random number, comparing the first and second versions of the unencrypted random number, and determining if the first and second versions of the unencrypted random number match.
The wireless communications module may be configured for receiving a session request from the external programmer over the wireless communications link and sending the session request to the control circuitry, in which case, the control circuitry may be configured for performing the authentication procedure in response to receiving the session request. The control circuitry may be configured for instructing the wireless communications module to send an acknowledge command to the external programmer over the wireless communications link if the authentication procedure is successful, and for instructing the wireless communications module to send a non-acknowledge command to the external programmer over the wireless communications link if the authentication procedure fails.
In one embodiment for preventing the external programmer from commanding the medical device to perform the action, the medical device further comprises a power source configured for supplying power to the wireless communications module, and a wireless actuator configured for being triggered in response to a user action (e.g., a physical wireless actuator, such as a button, configured for being physically triggered in response to the user action), in which case, the control circuitry may be configured for permitting the supply of power from the power source to the wireless communications module in response to the triggering of the wireless actuator, and terminating the supply of power from the power source to the wireless communications module if the authentication procedure is not completed within a predetermined period of time and/or if the authentication procedure fails.
In this embodiment, the medical device may further comprise a switch coupled between the power source and the wireless communications module, in which case, the control circuitry may be configured for permitting the supply of power from the power source to the wireless communications module by closing the switch, and for terminating the supply of power from the power source to the wireless communications module by opening the switch. The control circuitry may comprise a timer configured for being started in response to the triggering of the wireless actuator, and for being stopped if the authentication procedure succeeds. The control circuitry may be configured for opening the switch if the timer indicates that the predetermined period of time has elapsed.
In another embodiment, the control circuitry is configured for preventing the external programmer from commanding the medical device to perform the action by instructing the wireless communications module to not forward commands received from the external programmer over the wireless communications link to the control circuitry. In still another embodiment, the wireless communications module is configured for forwarding commands received from the external programmer over the wireless communications link to the control circuitry, and the control circuitry is configured for preventing the external programmer from commanding the medical device to perform the action by ignoring the commands forwarded from the wireless communications module. In yet another embodiment, the control circuitry is configured for preventing the external programmer from commanding the medical device to perform the action by instructing the wireless communications module to terminate the wireless communication link.
In one specific embodiment, the medical device further comprises an external telemetry controller comprising the wireless communications module, the control circuitry, and telemetry circuitry configured for wirelessly communicating with at least one implantable medical device. In this case, the implantable medical device(s) may be configured for sensing physiological data of a patient, and the telemetry circuitry may be configured for wirelessly receiving the physiological data sensed by the implantable medical device(s). The medical device may comprise a prosthesis, and a prosthetic controller electrically coupled to the external telemetry controller for receiving the physiological data, and for controlling the bionic prosthesis based on the physiological data. The prosthesis may be, e.g., a bionic limb, the sensed physiological data is electromyogram (EMG) data, and the prosthetic controller may be configured for controlling movement of the bionic limb based on the sensed EMG data.
In accordance with a second aspect of the present inventions, a medical system comprises an external programmer configured for storing a first encryption algorithm, generating a first unencrypted version of the random number, encrypting the first unencrypted version of the random number in accordance with the first encryption algorithm to generate a first encrypted version of the random number, and transmitting the first unencrypted version of the random number and the first encrypted version of the random number over a wireless communication link (e.g., an RF communications link, such as, e.g., a Bluetooth or a Wi-Fi communications link, such as one in the range of less than one hundred feet).
The medical system further comprises a medical device configured for storing one of a second encryption algorithm that is identical to the first encryption algorithm, and a decryption algorithm that is complementary to the first encryption algorithm, receiving the first unencrypted version of the random number and the first encrypted version of the random number over a wireless communication link (e.g., an RF communications link, such as, e.g., a Bluetooth or a Wi-Fi communications link, such as one in the range of less than one hundred feet), performing an authentication procedure on the external programmer by applying the one of the second encryption algorithm and a decryption algorithm to the first unencrypted version of the random number and the first encrypted version of the random number, and preventing the external programmer from commanding the medical device to perform an action (e.g., allowing modification of at least one operational parameter of the medical system) unless the authentication procedure is successful. The medical device may be configured for establishing the wireless communications link with the external programmer by authenticating the external programmer at a first security level, and for performing the authentication procedure at a second security level.
In one embodiment, the medical device is configured for performing the authentication procedure by generating a second encrypted version of the random number from the first unencrypted version of the random number, comparing the first and second versions of the encrypted random number, and determining if the first and second versions of the encrypted random number match. In another embodiment, the medical device is configured for performing the authentication procedure by decrypting the first encrypted version of the random number to recover a second unencrypted version of the random number, comparing the first and second versions of the unencrypted random number, and determining if the first and second versions of the unencrypted random number match.
The external programmer may be configured for sending a session request over the wireless communication link, in which case, the medical device may be configured for receiving a session request over the wireless communications link, and for performing the authentication procedure in response to receiving the session request. The medical device may be configured for sending an acknowledge command over the wireless communications link if the authentication procedure is successful, and the external programmer may be configured for receiving the acknowledge command over the wireless communications link, and in response to receiving the acknowledge command, sending commands over the wireless communications link to command the medical device to perform the action. The medical device may be configured for sending a non-acknowledge command over the wireless communications link if the authentication procedure fails, and the external programmer may be configured for receiving the non-acknowledge command over the wireless communications link.
In one embodiment for preventing the external programmer from commanding the medical device to perform the action, the medical system further comprises a wireless communications module configured for establishing the wireless communication link, and a wireless actuator configured for being triggered in response to a user action (e.g., a physical wireless actuator, such as a button, configured for being physically triggered in response to the user action), in which case, the medical device may be configured for turning on the wireless communications module in response to the triggering of the wireless actuator, and turning off the wireless communications module if the authentication procedure is not completed within a predetermined period of time and/or if the authentication procedure fails.
In another embodiment for preventing the external programmer from commanding the medical device to perform the action, the external programmer is configured for sending commands to the medical device over the wireless communications link, and the medical device is configured for preventing the external programmer from commanding the medical device to perform the action by ignoring the commands received from the external programmer over the wireless communications link. In still another embodiment, the medical device is configured for preventing the external programmer from commanding the medical device to perform the action by terminating the wireless communications link.
In one specific embodiment, the medical system further comprises at least one implantable medical device, and the medical device further comprises an external telemetry controller configured for wirelessly communicating with the implantable medical device(s). In this case, the implantable medical device(s) may be configured for sensing physiological data of a patient, and the telemetry controller may be configured for wirelessly receiving the physiological data sensed by the implantable medical device(s). The medical system may further comprise a prosthesis, and a prosthetic controller electrically coupled to the external telemetry controller for receiving the physiological data, and for controlling the bionic prosthesis based on the physiological data. The prosthesis may be, e.g., a bionic limb, the sensed physiological data is electromyogram (EMG) data, and the prosthetic controller may be configured for controlling movement of the bionic limb based on the sensed EMG data.
In accordance with a third aspect of the present inventions, a method of communicating between a medical device and an external programmer of a medical system over a wireless communications link (e.g., an RF communications link, such as, e.g., a Bluetooth or a Wi-Fi communications link, such as one in the range of less
RELATED APPLICATION
The present application is a continuation of U.S. patent application Ser. No. 17/664,360, filed May 20, 2022, entitled, âSYSTEM AND METHOD FOR AUTHENTICATING WIRELESS PROGRAMMING DEVICES IN PROGRAMMABLE MEDICAL SYSTEMS,â which is a continuation of U.S. patent application Ser. No. 16/869,863, filed May 8, 2020, entitled, âSYSTEM AND METHOD FOR AUTHENTICATING WIRELESS PROGRAMMING DEVICES IN PROGRAMMABLE MEDICAL SYSTEMS,â which is a continuation of U.S. patent application Ser. No. 15/452,339, filed Mar. 7, 2017, entitled, âSYSTEM AND METHOD FOR AUTHENTICATING WIRELESS PROGRAMMING DEVICES IN PROGRAMMABLE MEDICAL SYSTEMS,â which claims priority from U.S. Provisional Patent Application Ser. No. 62/304,603, filed Mar. 7, 2016, which are expressly incorporated herein by reference.
FIELD OF THE INVENTION
The present invention generally relates to wireless programming techniques in medical systems, and specifically relates to authenticating wireless programming devices, such as clinician programmers, for use in programmable medical systems.
BACKGROUND OF THE INVENTION
Medical systems, such as implantable medical systems, typically comprise one or more implantable medical devices and an external telemetry controller capable of controlling operation of the implanted medical device(s) and acquiring physiological data or operational status data from the implanted medical device(s). Implantable medical systems may further comprise an external programmer, such as a clinician programmer or patient programmer, that may download operating parameters or programs into the telemetry controller to set or otherwise modify the operating configuration of the implantable medical system and/or upload information, such as the physiological data or operational status data, from the telemetry controller.
Communication between such an external programmer and telemetry controller of an implantable medical system may be conveniently accomplished through wireless means, such as radio frequency (RF) communication. One method of wirelessly communicating between an external programmer and a telemetry controller uses a short-range RF communications in accordance with Bluetooth technology. The external programmer and telemetry controller can be paired by exchanging or otherwise storing a shared secret key (referred to as a âlink keyâ) that is used to subsequently authenticate the external programmer and encrypt data and commands sent between the external programmer and telemetry controller. Thus, by design, only the external programmer and any previously paired external programmer are permitted to communicate with the telemetry controller.
However, present telemetry controllers that communicate with external programmers over a Bluetooth communications link may be susceptible to inadvertent or intentional hijacking by unauthorized users, because the link key may be surreptitiously acquired or otherwise generated as a default in some operational systems, such as Linux. Once acquired, the shared link key can be used by any device to communication with the telemetry controller. As such, a potential vulnerability from undesired modification of the operating configuration of medical equipment may arise.
There, thus, remains a need for preventing or otherwise deterring unauthorized programming of medical equipment, such as telemetry controllers used in implantable medical systems.
SUMMARY OF THE INVENTION
In accordance with a first aspect of the present inventions, a medical device of a medical system configured for communicating with an external programmer over a wireless communications link (e.g., one having a range of less than one hundred feet) is provided.
The medical device comprises a wireless communications module configured for receiving a first unencrypted version of a random number and a first encrypted version of the random number from the external programmer over the wireless communications link. In one embodiment, the wireless communications module is a radio frequency (RF) communications module, such as one that communicates with the external programmer in accordance with a Bluetooth or a Wi-Fi protocol.
The medical device further comprises control circuitry (e.g., a microcontroller) configured for performing an authentication procedure on the external programmer based on the first unencrypted version of the random number and the first encrypted version of the random number, and preventing the external programmer from commanding the medical device to perform an action (e.g., allowing modification of at least one operational parameter of the medical system) unless the authentication procedure is successful. The wireless communications module may be hardwired to the control circuitry. The wireless communications module may be configured for establishing the wireless communications link with the external programmer by authenticating the external programmer at a first security level, sending status messages to the control circuitry indicating the status of the wireless communications link with the external programmer, in which case, the control circuitry may be configured for performing the authentication procedure at a second security level.
In one embodiment, the control circuitry is configured for performing the authentication procedure by generating a second encrypted version of the random number from the first unencrypted version of the random number, comparing the first and second versions of the encrypted random number, and determining if the first and second versions of the encrypted random number match. In another embodiment, the control circuitry is configured for performing the authentication procedure by decrypting the first encrypted version of the random number to recover a second unencrypted version of the random number, comparing the first and second versions of the unencrypted random number, and determining if the first and second versions of the unencrypted random number match.
The wireless communications module may be configured for receiving a session request from the external programmer over the wireless communications link and sending the session request to the control circuitry, in which case, the control circuitry may be configured for performing the authentication procedure in response to receiving the session request. The control circuitry may be configured for instructing the wireless communications module to send an acknowledge command to the external programmer over the wireless communications link if the authentication procedure is successful, and for instructing the wireless communications module to send a non-acknowledge command to the external programmer over the wireless communications link if the authentication procedure fails.
In one embodiment for preventing the external programmer from commanding the medical device to perform the action, the medical device further comprises a power source configured for supplying power to the wireless communications module, and a wireless actuator configured for being triggered in response to a user action (e.g., a physical wireless actuator, such as a button, configured for being physically triggered in response to the user action), in which case, the control circuitry may be configured for permitting the supply of power from the power source to the wireless communications module in response to the triggering of the wireless actuator, and terminating the supply of power from the power source to the wireless communications module if the authentication procedure is not completed within a predetermined period of time and/or if the authentication procedure fails.
In this embodiment, the medical device may further comprise a switch coupled between the power source and the wireless communications module, in which case, the control circuitry may be configured for permitting the supply of power from the power source to the wireless communications module by closing the switch, and for terminating the supply of power from the power source to the wireless communications module by opening the switch. The control circuitry may comprise a timer configured for being started in response to the triggering of the wireless actuator, and for being stopped if the authentication procedure succeeds. The control circuitry may be configured for opening the switch if the timer indicates that the predetermined period of time has elapsed.
In another embodiment, the control circuitry is configured for preventing the external programmer from commanding the medical device to perform the action by instructing the wireless communications module to not forward commands received from the external programmer over the wireless communications link to the control circuitry. In still another embodiment, the wireless communications module is configured for forwarding commands received from the external programmer over the wireless communications link to the control circuitry, and the control circuitry is configured for preventing the external programmer from commanding the medical device to perform the action by ignoring the commands forwarded from the wireless communications module. In yet another embodiment, the control circuitry is configured for preventing the external programmer from commanding the medical device to perform the action by instructing the wireless communications module to terminate the wireless communication link.
In one specific embodiment, the medical device further comprises an external telemetry controller comprising the wireless communications module, the control circuitry, and telemetry circuitry configured for wirelessly communicating with at least one implantable medical device. In this case, the implantable medical device(s) may be configured for sensing physiological data of a patient, and the telemetry circuitry may be configured for wirelessly receiving the physiological data sensed by the implantable medical device(s). The medical device may comprise a prosthesis, and a prosthetic controller electrically coupled to the external telemetry controller for receiving the physiological data, and for controlling the bionic prosthesis based on the physiological data. The prosthesis may be, e.g., a bionic limb, the sensed physiological data is electromyogram (EMG) data, and the prosthetic controller may be configured for controlling movement of the bionic limb based on the sensed EMG data.
In accordance with a second aspect of the present inventions, a medical system comprises an external programmer configured for storing a first encryption algorithm, generating a first unencrypted version of the random number, encrypting the first unencrypted version of the random number in accordance with the first encryption algorithm to generate a first encrypted version of the random number, and transmitting the first unencrypted version of the random number and the first encrypted version of the random number over a wireless communication link (e.g., an RF communications link, such as, e.g., a Bluetooth or a Wi-Fi communications link, such as one in the range of less than one hundred feet).
The medical system further comprises a medical device configured for storing one of a second encryption algorithm that is identical to the first encryption algorithm, and a decryption algorithm that is complementary to the first encryption algorithm, receiving the first unencrypted version of the random number and the first encrypted version of the random number over a wireless communication link (e.g., an RF communications link, such as, e.g., a Bluetooth or a Wi-Fi communications link, such as one in the range of less than one hundred feet), performing an authentication procedure on the external programmer by applying the one of the second encryption algorithm and a decryption algorithm to the first unencrypted version of the random number and the first encrypted version of the random number, and preventing the external programmer from commanding the medical device to perform an action (e.g., allowing modification of at least one operational parameter of the medical system) unless the authentication procedure is successful. The medical device may be configured for establishing the wireless communications link with the external programmer by authenticating the external programmer at a first security level, and for performing the authentication procedure at a second security level.
In one embodiment, the medical device is configured for performing the authentication procedure by generating a second encrypted version of the random number from the first unencrypted version of the random number, comparing the first and second versions of the encrypted random number, and determining if the first and second versions of the encrypted random number match. In another embodiment, the medical device is configured for performing the authentication procedure by decrypting the first encrypted version of the random number to recover a second unencrypted version of the random number, comparing the first and second versions of the unencrypted random number, and determining if the first and second versions of the unencrypted random number match.
The external programmer may be configured for sending a session request over the wireless communication link, in which case, the medical device may be configured for receiving a session request over the wireless communications link, and for performing the authentication procedure in response to receiving the session request. The medical device may be configured for sending an acknowledge command over the wireless communications link if the authentication procedure is successful, and the external programmer may be configured for receiving the acknowledge command over the wireless communications link, and in response to receiving the acknowledge command, sending commands over the wireless communications link to command the medical device to perform the action. The medical device may be configured for sending a non-acknowledge command over the wireless communications link if the authentication procedure fails, and the external programmer may be configured for receiving the non-acknowledge command over the wireless communications link.
In one embodiment for preventing the external programmer from commanding the medical device to perform the action, the medical system further comprises a wireless communications module configured for establishing the wireless communication link, and a wireless actuator configured for being triggered in response to a user action (e.g., a physical wireless actuator, such as a button, configured for being physically triggered in response to the user action), in which case, the medical device may be configured for turning on the wireless communications module in response to the triggering of the wireless actuator, and turning off the wireless communications module if the authentication procedure is not completed within a predetermined period of time and/or if the authentication procedure fails.
In another embodiment for preventing the external programmer from commanding the medical device to perform the action, the external programmer is configured for sending commands to the medical device over the wireless communications link, and the medical device is configured for preventing the external programmer from commanding the medical device to perform the action by ignoring the commands received from the external programmer over the wireless communications link. In still another embodiment, the medical device is configured for preventing the external programmer from commanding the medical device to perform the action by terminating the wireless communications link.
In one specific embodiment, the medical system further comprises at least one implantable medical device, and the medical device further comprises an external telemetry controller configured for wirelessly communicating with the implantable medical device(s). In this case, the implantable medical device(s) may be configured for sensing physiological data of a patient, and the telemetry controller may be configured for wirelessly receiving the physiological data sensed by the implantable medical device(s). The medical system may further comprise a prosthesis, and a prosthetic controller electrically coupled to the external telemetry controller for receiving the physiological data, and for controlling the bionic prosthesis based on the physiological data. The prosthesis may be, e.g., a bionic limb, the sensed physiological data is electromyogram (EMG) data, and the prosthetic controller may be configured for controlling movement of the bionic limb based on the sensed EMG data.
In accordance with a third aspect of the present inventions, a method of communicating between a medical device and an external programmer of a medical system over a wireless communications link (e.g., an RF communications link, such as, e.g., a Bluetooth or a Wi-Fi communications link, such as one in the range of less than one hundred feet) is provided. The method comprises receiving a first unencrypted version of a random number and a first encrypted version of the random number from the external programmer over the wireless communications link, performing an authentication procedure on the external programmer based on the first unencrypted version of the random number and the first encrypted version of the random number, and preventing the external programmer from commanding the medical device to perform an action (e.g., allowing modification of at least one operational parameter of the medical system) unless the authentication procedure is successful. The method may further comprise establishing the wireless communications link between the medical device and external programmer by authenticating the external programmer at a first security level, in which case, the authentication procedure may be performed at a second security level.
One method further comprises storing a first encryption algorithm at the external programmer, generating the first unencrypted version of the random number, encrypting the first unencrypted version of the random number in accordance with the first encryption algorithm to generate the first encrypted version of the random number, transmitting the first unencrypted version of the random number and the first encrypted version of the random number over the wireless communication link, and storing one of a second encryption algorithm identical to the first encryption algorithm and a decryption algorithm complementary to the first encryption algorithm at the medical device.
In this case, the authentication procedure may be performed on the external programmer by respectively applying the second encryption algorithm or the decryption algorithm to the first unencrypted version of the random number or the first encrypted version of the random number. For example, the authentication procedure may be performed by generating a second encrypted version of the random number from the first unencrypted version of the random number, comparing the first and second versions of the encrypted random number, and determining if the first and second versions of the encrypted random number match. As another example, the authentication procedure is performed by decrypting the first encrypted version of the random number to recover a second unencrypted version of the random number, comparing the first and second versions of the unencrypted random number, and determining if the first and second versions of the unencrypted random number match.
Another method further comprises receiving a session request from the external programmer over the wireless communications link, in which case, the authentication procedure may be performed in response to receiving the session request. This method may further comprise sending an acknowledge command to the external programmer over the wireless communications link if the authentication procedure is successful, and in response to receiving the acknowledge command, sending commands from the external programmer to the medical device over the wireless communications link to command the medical device to perform the action. The method may further comprise sending a non-acknowledge command to the external programmer over the wireless communications link if the authentication procedure fails.
One method for preventing the external programmer from commanding the medical device to perform the action comprises receiving a trigger signal in response to a user action, turning on a wireless communications module in response to the trigger signal, establishing the wireless communications link with the wireless communications module, and turning off the wireless communications module if the authentication procedure is not completed within a predetermined period of time and/or if the authentication procedure fails. Another method for preventing the external programmer from commanding the medical device to perform the action comprises sending commands from the external programmer to the medical device over the wireless communications link, and ignoring the commands received from the external programmer over the wireless communications link. In still another method for preventing the external programmer form commanding the medical device to perform the action comprises terminating the wireless communications link.
In accordance with a fourth aspect of the present inventions, a medical device of a medical system configured for communicating with an external programmer over a wireless communications link (e.g., one having a range of less than one hundred feet) is provided. The medical device comprises a wireless communications module configured for establishing a wireless communications link (e.g., one having a range of less than one hundred feet) with the external programmer. In one embodiment, the wireless communications module is a radio frequency (RF) communications module, such as one that communicates with the external programmer in accordance with a Bluetooth or a Wi-Fi protocol.
The medical device further comprises a power source configured for supplying power to the wireless communications module, a wireless actuator configured for being triggered in response to a user action (e.g., a physical wireless actuator, such as a button, configured for being physically triggered in response to the user action), and control circuitry (e.g., a microcontroller) is configured for permitting the supply of power from the power source to the wireless communications module in response to the triggering of the wireless actuator, for performing an authentication procedure on the external programmer, and for terminating the supply of power to the wireless communications module if the authentication procedure is not completed within a predetermined period of time. The wireless communications module may be hardwired to the control circuitry. The wireless communications module may be configured for establishing the wireless communications link with the external programmer by authenticating the external programmer at a first security level, and the control circuitry may be configured for performing the authentication procedure at a second security level.
In one embodiment, the medical device further comprises a switch coupled between the power source and the wireless communications module, and the control circuitry is configured for permitting the supply of power from the power source to the wireless communications module by closing the switch, and for terminating the supply of power from the power source to the wireless communications module by opening the switch. The control circuitry may comprise a timer configured for being started in response to the triggering of the wireless actuator, and for being stopped if the authentication procedure succeeds. The control circuitry may be configured for opening the switch if the timer indicates that the predetermined period of time has elapsed. The control circuitry may be configured for preventing the external programmer from commanding the medical device to perform the action by terminating the supply of power from the power source to the wireless communications module if the authentication procedure fails.
In one specific embodiment, the medical device further comprises an external telemetry controller comprising the wireless communications module, the control circuitry, and telemetry circuitry configured for wirelessly communicating with at least one implantable medical device. In this case, the implantable medical device(s) may be configured for sensing physiological data of a patient, and the telemetry circuitry may be configured for wirelessly receiving the physiological data sensed by the implantable medical device(s). The medical device may comprise a prosthesis, and a prosthetic controller electrically coupled to the external telemetry controller for receiving the physiological data, and for controlling the bionic prosthesis based on the physiological data. The prosthesis may be, e.g., a bionic limb, the sensed physiological data is electromyogram (EMG) data, and the prosthetic controller may be configured for controlling movement of the bionic limb based on the sensed EMG data.
In accordance with a fifth aspect of the present inventions, a medical system comprises an external programmer configured for sending authentication information over a wireless communication link (e.g., an RF communications link, such as, e.g., a Bluetooth or a Wi-Fi communications link, such as one in the range of less than one hundred feet), a medical device, a wireless actuator configured for being triggered in response to a user action (e.g., a physical wireless actuator, such as a button, configured for being physically triggered in response to the user action), and a wireless communications module configured for establishing the wireless communication link between the external programmer and the medical device.
The medical device is configured for turning on the wireless communications module in response to the triggering of the wireless actuator, for performing an authentication procedure on the external programmer based on the authentication information sent by the external programmer, and for turning off the wireless communications module if the authentication procedure is not completed within a predetermined period of time. The medical device may be configured for establishing the wireless communications link with the external programmer by authenticating the external programmer at a first security level, and the medical device may be configured for performing the authentication procedure at a second security level. In one embodiment, the external programmer is configured for programming the medical device, and the medical device is configured for preventing the external programmer from commanding the medical device by turning off the wireless communications module if the authentication procedure fails.
In one specific embodiment, the medical system further comprises at least one implantable medical device, and the medical device further comprises an external telemetry controller configured for wirelessly communicating with the implantable medical device(s). In this case, the implantable medical device(s) may be configured for sensing physiological data of a patient, and the telemetry controller may be configured for wirelessly receiving the physiological data sensed by the implantable medical device(s). The medical system may further comprise a prosthesis, and a prosthetic controller electrically coupled to the external telemetry controller for receiving the physiological data, and for controlling the bionic prosthesis based on the physiological data. The prosthesis may be, e.g., a bionic limb, the sensed physiological data is electromyogram (EMG) data, and the prosthetic controller may be configured for controlling movement of the bionic limb based on the sensed EMG data.
In accordance with a sixth aspect of the present inventions, a method of communicating between a medical device and an external programmer of a medical system over a wireless communications link is provided. The method comprises receiving a trigger signal in response to a user action, turning on a wireless communications module in response to the trigger signal, establishing the wireless communications link with the wireless communications module, and preventing the external programmer from commanding the medical device by turning off the wireless communications module if the external programmer is not authenticated within a predetermined period of time. The method may further comprise receiving authentication information from the external programmer, and authenticating the external programmer based on the received authentication information. The method may further comprise establishing the wireless communications link between the medical device and external programmer by authenticating the external programmer at a first security level, and the external programmer is further authenticated at a second security level.
Other and further aspects and features of the invention will be evident from reading the following detailed description of the preferred embodiments, which are intended to illustrate, not limit, the invention.
BRIEF DESCRIPTION OF THE DRAWINGS
The drawings illustrate the design and utility of preferred embodiments of the present invention, in which similar elements are referred to by common reference numerals. In order to better appreciate how the above-recited and other advantages and objects of the present inventions are obtained, a more particular description of the present inventions briefly described above will be rendered by reference to specific embodiments thereof, which are illustrated in the accompanying drawings. Understanding that these drawings depict only typical embodiments of the invention and are not therefore to be considered limiting of its scope, the invention will be described and explained with additional specificity and detail through the use of the accompanying drawings in which:
FIG. 1 is a pictorial of a prosthetic control system constructed in accordance with one embodiment of the present inventions;
FIG. 2 is a block diagram of one embodiment of the telemetry controller used in the prosthetic control system of FIG. 1 ;
FIG. 3 is a block diagram of another embodiment of the telemetry controller used in the prosthetic control system of FIG. 1 ;
FIG. 4 is a block diagram of a one embodiment of a clinician programmer used in the prosthetic control system of FIG. 1 ;
FIGS. 5 a and 5 b is a flow diagram of illustrating one method of operating the telemetry controller of FIG. 2 to perform an authentication procedure on a wireless device, and preventing the wireless device from commanding the telemetry controller unless the authentication procedure is completed with a successful result; and
FIGS. 6 a and 6 b is a flow diagram of illustrating one method of operating the telemetry controller of FIG. 3 to perform an authentication procedure on a wireless device, and preventing the wireless device from commanding the telemetry controller unless the authentication procedure is completed with a successful result.
DETAILED DESCRIPTION OF THE EMBODIMENTS
Referring to FIG. 1 , an implantable medical system 100 constructed in accordance with one embodiment of the present inventions will now be described. The implantable medical system 100 generally comprises an external telemetry controller (TC) 102 and a plurality of implantable medical devices 104 . In the illustrated embodiment, the implantable medical system 100 takes the form of a prosthetic control system.
In this case, the implantable medical devices 104 may take the form of sensor devices that are implanted within a residual portion of an amputated limb 52 of a patient 50 respectively adjacent muscles of interest for detecting muscle contraction, for example, by monitoring electromyogram (EMG) signals of the muscles of interest. The prosthetic control system 100 comprises a bionic prosthesis 54 having a robotic forearm 56 and robotic hand 58 . The TC 102 may be incorporated into the bionic prosthesis 54 , and is configured for delivering power to and receiving EMG data from the sensor devices 104 . To facilitate power transfer and communications, the TC 102 comprises a primary coil 106 , which may be incorporated into the socket portion of the bionic prosthesis 54 in a manner that it surrounds the sensor devices 104 implanted within the residual limb portion 52 of the patient 50 . The TC 102 comprises power transfer and communication circuitry (described in further detail below) that inductively powers and communicates with the implanted sensor devices 104 via the primary coil 106 .
The prosthetic control system 100 further comprises a prosthetic controller 110 coupled to the TC 102 via a cable 112 for receiving EMG data from TC 102 , and is further coupled to motors (not shown) in the bionic prosthesis 54 to control movement of the robotic arm 56 and robotic hand 58 . The prosthetic controller 110 may be worn by the patient 50 , e.g., on the waist. The prosthetic control system 100 may further comprises one or more batteries (not shown), which may be physically integrated into the prosthesis 54 or otherwise contained in the prosthetic controller 110 , for providing power to the circuitry within the TC 102 and prosthetic controller 110 .
Thus, the prosthetic control system 100 allows the patient 50 to control the bionic forearm 56 and robotic hand 58 by attempting to contract the muscles in the residual limb portion 52 . Different muscles or different portions of the muscles would correspond to independently movable parts, such as the elbow, wrist, and fingers of the bionic prosthesis 54 . When a sensor device 104 detects contraction in a muscle or portion of a muscle, it communicates the resulting EMG data to the prosthetic controller 110 via the TC 102 that the muscle or portion of a muscle was contracted. The EMG data identifies the muscle that has been contracted, as well as the magnitude of the contraction. The prosthetic controller 110 then controls the bionic prosthesis 54 to move the independently movable part that corresponds with the muscle that was contracted according to the magnitude of the contraction.
Although the TC 102 and prosthetic controller 110 are shown as being separate physical units in FIG. 1 , it should be appreciated that the TC 102 and prosthetic controller 110 may be integrated into a single physical unit that is incorporated into the prosthesis 54 or otherwise worn by the patient 50 . It should also be appreciated that although the prosthetic control system 100 has been described as being a prosthetic control system, the prosthetic control system 100 can be any medical system that performs a diagnostic or therapeutic function. Likewise, although the implantable medical devices 102 are described as being EMG sensors, the implantable medical devices 102 may take the form of any medical device that performs a diagnostic or therapeutic function. Furthermore, although the TC 102 is described herein as being external to the patient 50 , it should be appreciated that the TC 102 may take the form of, or otherwise be incorporated into, an implantable device that communicates with the other sensor devices 104 .
Each of the sensor devices 104 may take the form of a miniaturized cylindrical sensing device, with the circuitry being implemented as a sub-assembly on a single-chip integrated circuit mounted on a ceramic substrate sandwiched between two halves of a cylindrical magnetic core around which the inductive coil is wound. The electronics are encapsulated in a cylindrical ceramic package that include two metal endcaps at opposite ends of the ceramic package that serve as the differential recording electrodes. Such an implantable sensor device allows the EMG signals to be detected at the implantation site of this device. An example of such an implantable sensor device 104 is the IMES® device manufactured by Alfred Mann Foundation and described in Implantable Myoelectric Sensors (IMESs) for Intramuscular Electromyogram Recording, IEEE Trans Biomed Eng. 2009 January, pp. 159-171. In an alternative embodiment, the sensor device 104 may include a lead (not shown) on which the electrodes are carried, so that EMG signals can be detected at a location remote from the implantation site of the body of the device.
The prosthetic control system 100 further comprises a clinician programmer (CP) 114 configured for being operated by a clinician to program the prosthetic controller 110 and/or sensor devices 14 via the TC 102 . In the illustrated embodiment, the CP 114 takes the form of a personal computer (PC), although in alternative embodiments, the CP 114 may take the form of a conventional Smartphone configured with a smartphone application with programming capabilities. As will be described in further detail below, the TC 102 and the CP 114 both comprise wireless communication interfaces (e.g., Bluetooth interfaces) that allow the CP 114 to send commands to the prosthetic controller 110 via the TC 102 , e.g., for modifying or selecting programs, within the prosthetic controller 110 , thereby modifying the operating configuration of the prosthetic control system 100 .
Although a third- party device 116 may potentially modify the operating configuration of the prosthetic control system 100 by sending commands to the TC 102 that would modify operational parameters within the sensor devices 104 and/or prosthetic controller 110 , the prosthetic control system 100 prevents, or at least minimizes, the chance that a third- party device 116 modifies the operating configuration of the prosthetic control system 100 by preventing the third- party device 116 from sending commands to the TC 102 or otherwise ignoring such commands.
As illustrated in FIG. 1 , the TC 102 and CP 114 are configured for communicating with each other over a wireless communications link 118 . The wireless communications link 118 is a short-range radio frequency (RF) communications link. In the illustrated embodiment, the RF communications link 118 is a point-to-point communications link, since it is desirable that prosthetic controller 110 be programmed by only one CP 114 at a time, and that the CP 114 program only one prosthetic controller 110 at a time, although there may be some scenarios where it may be desirable to program multiple prosthetic controllers 110 at the same time, in which case, the RF communications link 118 may be a point-to-multiple communications link.
In the illustrated embodiment described herein, the RF communications link 118 is established in accordance with a Bluetooth protocol, although in alternative embodiments, the RF communications link 118 may be established in accordance with other short-range RF protocols, such as a Wi-Fi protocol. The Bluetooth protocol is essentially a detailed specification for short-range (e.g., less than one hundred feet) wireless communications using the unlicensed industry, scientific, and medical (ISM) 2.4 GHz radio band. Bluetooth technology is fundamentally a cable replacement system that provides a universal mechanism for a variety of devices in various configuration that includes a master (in this case, the CP 114 ) and at least one slave (in this case, the TC 102 ). The master is defined as the device that initiates the connection procedure to establish the wireless communications link.
Prior to exchanging data, in accordance with the Bluetooth protocol, the CP 114 and telemetry controller 102 establ
CLAIMS
Claims ( 22 )
What is claimed is:
1. A method of communicating between a first device and a second device of a system over a wireless communications link, the method comprising:
receiving a trigger signal in response to a user action;
establishing a wireless communications link between the first device and the second device in response to the trigger signal;
initiating an authentication procedure on the second device over the established wireless communication link;
receiving a first unencrypted version of a random number and a first encrypted version of the random number from the second device over the wireless communications link; and
performing an authentication procedure on the second device based on the first unencrypted version of the random number and the first encrypted version of the random number; and
preventing the second device from commanding the first device to perform an action if the authentication procedure is not completed within a predetermined period of time after the wireless communication link has been established between the first device and the second device or if the authentication procedure fails within the predetermined period of time.
2. The method of claim 1 , further comprising:
storing a first encryption algorithm at the second device;
generating the first unencrypted version of the random number;
encrypting the first unencrypted version of the random number in accordance with the first encryption algorithm to generate the first encrypted version of the random number;
transmitting the first unencrypted version of the random number and the first encrypted version of the random number over the wireless communication link;
storing one of a second encryption algorithm and a decryption algorithm at the first device, the second encryption algorithm being identical to the first encryption algorithm, the decryption algorithm being complementary to the first encryption algorithm;
wherein the authentication procedure is performed on the second device by respectively applying the one of the second encryption algorithm and a decryption algorithm to the first unencrypted version of the random number and the first encrypted version of the random number.
3. The method of claim 1 , wherein the authentication procedure is performed by:
generating a second encrypted version of the random number from the first unencrypted version of the random number;
comparing the first and second versions of the encrypted random number; and
determining if the first and second versions of the encrypted random number match.
4. The method of claim 1 , wherein the authentication procedure is performed by:
decrypting the first encrypted version of the random number to recover a second unencrypted version of the random number;
comparing the first and second versions of the unencrypted random number; and
determining if the first and second versions of the unencrypted random number match.
5. The method of claim 1 , wherein the first unencrypted version of the random number and the first encrypted version of the random number are concurrently received from the second device over the wireless communications link.
6. The method of claim 1 , further comprising receiving a session request from the second device over the wireless communications link, wherein the authentication procedure is performed in response to receiving the session request.
7. The method of claim 6 , further comprising:
sending an acknowledge command to the second device over the wireless communications link if the authentication procedure is successful; and
in response to receiving the acknowledge command, sending commands from the second device to the first device over the wireless communications link to command the first device to perform the action.
8. The method of claim 6 , further comprising sending a non-acknowledge command to the second device over the wireless communications link if the authentication procedure fails.
9. The method of claim 1 , wherein the action is allowing modification of at least one operational parameter of the system.
10. The method of claim 1 , wherein the wireless communications link has a range less of than one hundred feet.
11. The method of claim 1 , wherein the wireless communications link is a radio frequency (RF) communications link.
12. The method of claim 11 , wherein the RF communications link is a Bluetooth or a Wi-Fi communications link.
13. The method of claim 1 , further comprising turning on a wireless communications module of the second device in response to the trigger signal, wherein the wireless communications link between the first device and the second device is established with the wireless communications module, and the second device is prevented from commanding the first device to perform the action by turning off the wireless communications module.
14. The method of claim 1 , wherein the second device is prevented from commanding the first device to perform the action if the authentication procedure is not completed within the predetermined period of time.
15. The method of claim 1 , wherein the second device is prevented from commanding the first device to perform the action by turning off the wireless communications module if the authentication procedure fails.
16. The method of claim 1 , further comprising sending commands from the second device to the first device over the wireless communications link, wherein the second device is prevented from commanding the first device to perform the action by ignoring the commands received from the second device over the wireless communications link.
17. The method of claim 1 , wherein the second device is prevented from commanding the first device to perform the action by terminating the wireless communications link.
18. The method of claim 1 , wherein the first device is an external telemetry controller, and the second device is an external programmer, the method further comprising wirelessly communicating between the telemetry controller and at least one medical device implanted within a patient.
19. The method of claim 18 , wherein the at least one medical device is implanted within a patient, and the telemetry controller is an external telemetry controller.
20. The method of claim 19 , further comprising:
sensing physiological data of the patient with the at least one implanted medical device; and
wirelessly transmitting the sensed physiological data from the at least one implanted device to the external telemetry controller.
21. The method of claim 20 , further comprising controlling a bionic prosthesis based on the sensed physiological data.
22. The method of claim 21 , wherein the bionic prosthesis is a bionic limb, the sensed physiological data is electromyogram (EMG) data, and controlling the bionic prosthesis comprises controlling movement of the bionic limb based on the sensed EMG data.
US17/664,411
2016-03-07
2022-05-21
System and method for authenticating wireless programming system and method for authenticating wireless programming devices in programmable medical systems
Active
US11871224B2
( en )
Priority Applications (1)
Application Number
Priority Date
Filing Date
Title
US17/664,411
US11871224B2
( en )
2016-03-07
2022-05-21
System and method for authenticating wireless programming system and method for authenticating wireless programming devices in programmable medical systems
Applications Claiming Priority (5)
Application Number
Priority Date
Filing Date
Title
US201662304603P
2016-03-07
2016-03-07
US15/452,339
US10652740B2
( en )
2016-03-07
2017-03-07
System and method for authenticating wireless programming devices in programmable medical systems
US16/869,863
US11375370B2
( en )
2016-03-07
2020-05-08
System and method for authenticating wireless programming devices in programmable medical systems
US17/664,360
US11805413B2
( en )
2016-03-07
2022-05-20
System and method for authenticating wireless programming devices in programmable medical systems
US17/664,411
US11871224B2
( en )
2016-03-07
2022-05-21
System and method for authenticating wireless programming system and method for authenticating wireless programming devices in programmable medical systems
Related Parent Applications (1)
Application Number
Title
Priority Date
Filing Date
US17/664,360
Continuation
US11805413B2
( en )
2016-03-07
2022-05-20
System and method for authenticating wireless programming devices in programmable medical systems
Publications (2)
Publication Number
Publication Date
US20220286849A1
US20220286849A1 ( en )
2022-09-08
US11871224B2
true
US11871224B2 ( en )
2024-01-09
Family
ID=58387909
Family Applications (4)
Application Number
Title
Priority Date
Filing Date
US15/452,339
Active
2037-12-25
US10652740B2
( en )
2016-03-07
2017-03-07
System and method for authenticating wireless programming devices in programmable medical systems
US16/869,863
Active
US11375370B2
( en )
2016-03-07
2020-05-08
System and method for authenticating wireless programming devices in programmable medical systems
US17/664,360
Active
US11805413B2
( en )
2016-03-07
2022-05-20
System and method for authenticating wireless programming devices in programmable medical systems
US17/664,411
Active
US11871224B2
( en )
2016-03-07
2022-05-21
System and method for authenticating wireless programming system and method for authenticating wireless programming devices in programmable medical systems
Family Applications Before (3)
Application Number
Title
Priority Date
Filing Date
US15/452,339
Active
2037-12-25
US10652740B2
( en )
2016-03-07
2017-03-07
System and method for authenticating wireless programming devices in programmable medical systems
US16/869,863
Active
US11375370B2
( en )
2016-03-07
2020-05-08
System and method for authenticating wireless programming devices in programmable medical systems
US17/664,360
Active
US11805413B2
( en )
2016-03-07
2022-05-20
System and method for authenticating wireless programming devices in programmable medical systems
Country Status (6)
Country
Link
US
( 4 )
US10652740B2
( en )
EP
( 1 )
EP3427463B1
( en )
CN
( 1 )
CN109076084B
( en )
AU
( 1 )
AU2017229360C1
( en )
CA
( 1 )
CA3016607C
( en )
WO
( 1 )
WO2017155986A1
( en )
Families Citing this family (22)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
WO2016172057A1
( en )
2015-04-20
2016-10-27
Ãssur Iceland Ehf
Electromyography with prosthetic or orthotic devices
US10173068B2
( en )
2017-02-02
2019-01-08
Pacesetter, Inc.
Mitigating false messaging in leadless dual-chamber pacing systems and other IMD systems
US10052491B1
( en )
*
2017-02-02
2018-08-21
Pacesetter, Inc.
Mitigating false messaging in leadless dual-chamber pacing systems and other IMD systems
EP3592217B1
( en )
*
2017-03-07
2023-07-19
The Alfred E. Mann Foundation for Scientific Research
Multiple implant communications with adjustable load modulation using modulation indices
US10956551B2
( en )
*
2017-08-07
2021-03-23
Clarius Mobile Health Corp.
Systems and methods for securing operation of an ultrasound scanner
US12491356B2
( en )
2018-03-20
2025-12-09
Second Heart Assist, Inc.
Circulatory assist pump
JP2021518249A
( en )
2018-03-20
2021-08-02
ã»ã«ã³ãã»ãã¼ãã»ã¢ã·ã¹ãã»ã¤ã³ã³ã¼ãã¬ã¤ããã
Circulation auxiliary pump
EP4376497A3
( en )
2018-06-12
2024-08-07
Impulse Dynamics NV
Power coupling modulation transmission
US11089475B2
( en )
*
2018-11-06
2021-08-10
Red Hat, Inc.
Booting and operating computing devices at designated locations
CN113169761A
( en )
*
2019-03-12
2021-07-23
èå²å¨åå ¬å¸
Secure short-range communication link for medical devices
US11239928B2
( en )
2019-06-21
2022-02-01
Pacesetter, Inc.
Dynamic sensitivity and strength control of communication signals between implantable medical devices
CN114727269A
( en )
*
2019-09-06
2022-07-08
åä¸ºææ¯æéå ¬å¸
Bluetooth connection method and related device
EP3793159A1
( en )
*
2019-09-10
2021-03-17
Connexcom Ag
Access control for private messages
US11801391B2
( en )
2019-09-27
2023-10-31
Pacesetter, Inc.
Mitigating false messages and effects thereof in multi-chamber leadless pacemaker systems and other IMD systems
EP3876239B1
( en )
*
2020-03-03
2024-05-01
W & H Dentalwerk Bürmoos GmbH
Method for wireless transmission of data in a medical or dental system and such medical or dental system
US12032666B2
( en )
*
2020-03-23
2024-07-09
Capital One Services, Llc
Wearable devices and related systems for authenticating a user with surface electromyogram (sEMG)-signals
JP7651896B2
( en )
*
2021-03-23
2025-03-27
ã»ã¤ã³ã¼ã¨ãã½ã³æ ªå¼ä¼ç¤¾
Electronic device and communication method
US12544560B2
( en )
2022-01-14
2026-02-10
Second Heart Assist, Inc.
Wireless chronic implant
EP4479870A1
( en )
*
2022-02-18
2024-12-25
Implantica Patent Ltd.
Methods and devices for secure communication with and operation of an implant
US11937089B2
( en )
*
2022-06-24
2024-03-19
CraniUS LLC
Medical implant software systems and methods
CN115844351B
( en )
*
2022-12-01
2023-07-04
æ¥é¦ç§æè¡ä»½å ¬å¸
Medical care system with data acquisition and transmission functions based on Internet of things technology
CN116211559A
( en )
*
2023-01-20
2023-06-06
䏿µ·äº¤é大å¦
A wireless flexible EMG acquisition system for prosthetic control
Citations (2)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20130054467A1
( en )
*
2006-07-19
2013-02-28
Mvisum, Inc.
System for remote review of clinical data
US20160007176A1
( en )
*
2014-07-07
2016-01-07
Broadcom Corporation
Emergency call handling in cellular networks after failed authentication
Family Cites Families (9)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US7228182B2
( en )
2004-03-15
2007-06-05
Cardiac Pacemakers, Inc.
Cryptographic authentication for telemetry with an implantable medical device
BRPI0822741B1
( en )
*
2008-05-26
2020-07-07
Nxp B.V.
reader and method of determining the validity of a connection to a transponder and computer-readable medium
US8762715B2
( en )
*
2009-11-24
2014-06-24
Sony Corporation
Event triggered pairing of wireless communication devices based on time measurements
US8588416B2
( en )
*
2012-01-12
2013-11-19
The Boeing Company
System and method for secure communication
CN103051731B
( en )
*
2013-01-17
2016-09-21
æ¸ å大å¦
The long distance control system of implantable medical devices
CN103391541B
( en )
*
2013-05-10
2016-12-28
å为ç»ç«¯æéå ¬å¸
The collocation method of wireless device and device, system
US9197414B1
( en )
*
2014-08-18
2015-11-24
Nymi Inc.
Cryptographic protocol for portable devices
CN104200177A
( en )
*
2014-09-12
2014-12-10
ç½æ»¡æ¸
Mobile medical sensitive data encryption method
CN104486758B
( en )
*
2014-12-30
2017-12-29
æµæ±å·¥ä¸å¤§å¦
The encryption method of radio sensing network in intelligent medical system
2017
2017-03-07
WO
PCT/US2017/021143
patent/WO2017155986A1/en
not_active
Ceased
2017-03-07
AU
AU2017229360A
patent/AU2017229360C1/en
active
Active
2017-03-07
EP
EP17712603.4A
patent/EP3427463B1/en
active
Active
2017-03-07
CA
CA3016607A
patent/CA3016607C/en
active
Active
2017-03-07
US
US15/452,339
patent/US10652740B2/en
active
Active
2017-03-07
CN
CN201780026458.6A
patent/CN109076084B/en
active
Active
2020
2020-05-08
US
US16/869,863
patent/US11375370B2/en
active
Active
2022
2022-05-20
US
US17/664,360
patent/US11805413B2/en
active
Active
2022-05-21
US
US17/664,411
patent/US11871224B2/en
active
Active
Patent Citations (2)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20130054467A1
( en )
*
2006-07-19
2013-02-28
Mvisum, Inc.
System for remote review of clinical data
US20160007176A1
( en )
*
2014-07-07
2016-01-07
Broadcom Corporation
Emergency call handling in cellular networks after failed authentication
Also Published As
Publication number
Publication date
US20200267550A1
( en )
2020-08-20
US20220286848A1
( en )
2022-09-08
CN109076084B
( en )
2021-11-23
EP3427463A1
( en )
2019-01-16
US20170257761A1
( en )
2017-09-07
WO2017155986A1
( en )
2017-09-14
AU2017229360A1
( en )
2018-09-20
CA3016607A1
( en )
2017-09-14
AU2017229360C1
( en )
2021-11-18
US11375370B2
( en )
2022-06-28
EP3427463B1
( en )
2026-05-06
CN109076084A
( en )
2018-12-21
US10652740B2
( en )
2020-05-12
US11805413B2
( en )
2023-10-31
CA3016607C
( en )
2023-08-29
AU2017229360B2
( en )
2021-07-29
US20220286849A1
( en )
2022-09-08
Similar Documents
Publication
Publication Date
Title
US11805413B2
( en )
2023-10-31
System and method for authenticating wireless programming devices in programmable medical systems
US12138463B2
( en )
2024-11-12
Facilitating trusted pairing of an implantable device and an external device
US20240001129A1
( en )
2024-01-04
Facilitating telemetry data communication security between an implantable device and an external device
US11582022B1
( en )
2023-02-14
Secure file transfer system and method
US20260057062A1
( en )
2026-02-26
Split key architecture for facilitating authentication between an implanted medical device and an external device
US20240181264A1
( en )
2024-06-06
Methods, devices, and systems for communicating with an implantable medical device of a last far field communication session during a subsequent far field communication session while using a same session key
Legal Events
Date
Code
Title
Description
2022-05-21
FEPP
Fee payment procedure
Free format text : ENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY
2022-06-09
STPP
Information on status: patent application and granting procedure in general
Free format text : DOCKETED NEW CASE - READY FOR EXAMINATION
2023-06-15
STPP
Information on status: patent application and granting procedure in general
Free format text : NON FINAL ACTION MAILED
2023-07-12
STPP
Information on status: patent application and granting procedure in general
Free format text : RESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINER
2023-09-18
STPP
Information on status: patent application and granting procedure in general
Free format text : NOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONS
2023-12-01
STPP
Information on status: patent application and granting procedure in general
Free format text : PUBLICATIONS -- ISSUE FEE PAYMENT RECEIVED
2023-12-07
STPP
Information on status: patent application and granting procedure in general
Free format text : PUBLICATIONS -- ISSUE FEE PAYMENT VERIFIED
2023-12-20
STCF
Information on status: patent grant
Free format text : PATENTED CASE