US2021377726A1PendingUtilityA1

Method and system for automatically associating a non-medical device with a medical device

Assignee: MEDTRONIC MINIMED INCPriority: May 27, 2020Filed: May 27, 2020Published: Dec 2, 2021
Est. expiryMay 27, 2040(~13.8 yrs left)· nominal 20-yr term from priority
Inventors:Samuel Finney
H04W 12/50H04W 12/08H04W 12/06H04W 12/108H04L 67/10H04L 9/3271H04L 9/3297A61M 2205/3584H04W 76/10H04W 12/71H04L 9/083H04W 12/04H04W 12/63H04L 2209/80A61M 2205/3561H04L 67/12H04L 9/3247H04W 12/03G16H 40/67H04W 12/001G05B 15/02A61M 5/172H04W 12/003G16H 20/17H04W 12/00512H04L 2209/88
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system are provided for authorizing a first device to communicate with a second device. One of the first device and the second device is a particular medical device for a patient, and the other one of the first device and the second device is a particular non-medical device associated with the patient. Prior to the second device being authorized to communicate with the first device, first identification information that identifies the second device can be provided to the first device via a cloud-based computing system. When the second device is prepared for use, it can broadcast second identification information. When the first device determines that the second identification information corresponds to the first identification information stored at the first device, the first device can automatically establish a secure communication link with the second device and the first device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for authorizing a first device to communicate with a second device, wherein one of the first device and the second device is a particular medical device for a patient and wherein the other one of the first device and the second device is a particular non-medical device associated with the patient, the method comprising:
 prior to the second device being authorized to communicate with the first device: providing, by a cloud-based computing system, first identification information to the first device and storing the first identification information at the first device, wherein the first identification information identifies the second device;   transmitting second identification information from the second device when the second device is prepared for use; and   processing the second identification information at the first device to automatically establish a secure communication link between the second device and the first device when the second identification information corresponds to the first identification information stored at the first device.   
     
     
         2 . The method of  claim 1 , wherein providing the identification information by the cloud-based computing system comprises:
 identifying the second device associated with the patient and retrieving the first identification information for the second device;   storing the first identification information in association to an account for the patient;   retrieving the first identification information for the second device when the account is accessed; and   prior to the second device being authorized to communicate with the first device, sending the first identification information to the first device of the patient to prepopulate the first device with the first identification information for the second device.   
     
     
         3 . The method of  claim 1 , wherein the first identification information is pairing information that is used to automatically pair the second device with the first device. 
     
     
         4 . The method of  claim 1 , wherein the first identification information comprises a unique identification information set for the second device that comprises one or more of: a device serial number associated with the second device; a numeric identifier associated with the second device; a cryptographic public signature verification key with a corresponding unique private signing key that was previously stored in the second device; or a cryptographic private payload decryption key with a corresponding unique public encryption key that was previously stored at the second device. 
     
     
         5 . The method of  claim 1 , wherein the cloud-based service provides the first device with wireless traffic encryption keys in addition to keying material used for identification and authentication. 
     
     
         6 . The method of  claim 1 , wherein the first device and the second device are required to complete a cryptographic challenge-response handshake process using the first identification information and the second identification information before a connection is established between the first device and the second device. 
     
     
         7 . The method of  claim 1 , wherein transmitting the second identification information from the second device comprises:
 broadcasting an association message from the second device, wherein the association message comprises the second identification information; and   wherein processing the second identification information at the first device to automatically establish the secure communication link between the second device and the first device, comprises:   receiving, at the first device, the association message and comparing, at the first device, the second identification information from the association message to the first identification information stored at the first device;   when the second identification information from the association message corresponds to the first identification information stored at the first device, automatically associating the first device with the second device and establishing the secure communication link between the second device and the first device.   
     
     
         8 . The method of  claim 7 , wherein automatically associating the first device with the second device and establishing the secure communication link between the second device and the first device, comprises:
 sending, from the first device, another request with appropriate authentication information or first identification information to the second device; and   processing, at the second device, the authentication information or the first identification information to determine whether the authentication information or the first identification information is valid; and   when the authentication information or the first identification information is determined to be valid, automatically associating with the first device by establishing at least one shared security attribute between the first device and the second device to support secure communications over the secure communication link between that first device and the second device.   
     
     
         9 . The method of  claim 7 , wherein the second identification information broadcast in each association message comprises at least one of: a device serial number associated with the second device or other numeric identifier associated with the second device; a deterministic function of a device serial number associated with the second device or other numeric identifier associated with the second device; a random number; a timestamp or other non-recurring value; a cryptographic signature; the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with a cryptographic key; the deterministic function of the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with the cryptographic key; the random number encrypted with the cryptographic key; the timestamp or other non-recurring value encrypted with the cryptographic key; the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with the cryptographic key and accompanied by a cryptographic signature; the deterministic function of the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with the cryptographic key and accompanied by the cryptographic signature; the random number encrypted with the cryptographic key and accompanied by the cryptographic signature; and the timestamp or other non-recurring value encrypted with the cryptographic key and accompanied by the cryptographic signature. 
     
     
         10 . The method of  claim 1 , wherein the first device is the particular medical device and wherein the second device is the particular non-medical client device. 
     
     
         11 . The method of  claim 10 , wherein the particular non-medical client device is configured to execute a medical control application that controls particular medical device. 
     
     
         12 . The method of  claim 1 , wherein the second device is the particular medical device, and wherein the first device is the particular non-medical client device that is configured to execute a medical control application that controls the particular medical device. 
     
     
         13 . The method of  claim 1 , wherein the first identification information for the second device is used by the first device, when the second device is within a threshold distance from the first device, to identify the second device and automatically associate with the second device by establishing at least one shared security attribute between the first device and the second device to support secure communications over the secure communication link between the second device and the first device without additional authentication processing being performed by the first device. 
     
     
         14 . A first device, comprising:
 at least one processor; and   a non-transitory processor-readable medium operatively associated with the at least one processor, the processor-readable medium comprising executable instructions configurable to cause the at least one processor to perform a method for authorizing the first device to communicate with a second device, wherein one of the first device and the second device is a particular medical device for a patient and wherein the other one of the first device and the second device is a particular non-medical device associated with the patient, the method comprising:
 storing first identification information that identifies the second device, wherein the first identification information is provided from a cloud-based computing system; 
 receiving the second identification information from the second device; and 
 processing the second identification information to automatically establish a secure communication link between the second device and the first device when the second identification information corresponds to the first identification information stored at the first device. 
   
     
     
         15 . The non-medical client device of  claim 14 , wherein pre-populating the first device, comprises:
 identifying the second device associated with the patient at the cloud-based computing system and retrieving first identification information for the second device;   storing the first identification information in association to an account for the patient;   retrieving the first identification information for the second device when the account is accessed; and   prior to the second device being authorized to communicate with the first device, sending the first identification information to the first device of the patient to prepopulate the first device with the first identification information for the second device.   
     
     
         16 . The non-medical client device of  claim 14 , wherein the second identification information is received in an association message broadcast from the second device, wherein the association message comprises the second identification information; and
 wherein processing the second identification information to automatically establish the secure communication link between the second device and the first device, comprises:   comparing the second identification information from the association message to the first identification information stored at the first device;   when second identification information from the association message corresponds to the first identification information stored at the first device, automatically associating the first device with the second device by establishing at least one shared security attribute between the first device and the second device to support secure communications over the secure communication link between the second device and the first device.   
     
     
         17 . The non-medical client device of  claim 16 , wherein automatically associating the first device with the second device and establishing the secure communication link between the second device and the first device, comprises:
 sending, from the first device, another request with appropriate authentication information or first identification information to the second device; and   processing, at the second device, the authentication information or the first identification information to determine whether that the authentication information or the first identification information is valid; and   when the authentication information or the first identification information is determined to be valid, automatically associating with the first device by establishing at least one shared security attribute between the first device and the second device to support secure communications over the secure communication link with between that first device and the second device.   
     
     
         18 . The non-medical client device of  claim 14 , wherein the first identification information for the second device is used by the first device to identify the second device and automatically associate with the second device so that the first device can securely communicate over the secure communication link between the second device and the first device without additional authentication processing being performed by the first device. 
     
     
         19 . The non-medical client device of  claim 16 , wherein the second identification information broadcast in each association message comprises at least one of: a device serial number associated with the second device or other numeric identifier associated with the second device; a deterministic function of a device serial number associated with the second device or other numeric identifier associated with the second device; a random number; a timestamp or other non-recurring value; a cryptographic signature; the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with a cryptographic key; the deterministic function of the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with the cryptographic key; the random number encrypted with the cryptographic key; the timestamp or other non-recurring value encrypted with the cryptographic key; the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with the cryptographic key and accompanied by a cryptographic signature; the deterministic function of the device serial number associated with the second device or other numeric identifier associated with the second device encrypted with the cryptographic key and accompanied by the cryptographic signature; the random number encrypted with the cryptographic key and accompanied by the cryptographic signature; and the timestamp or other non-recurring value encrypted with the cryptographic key and accompanied by the cryptographic signature. 
     
     
         20 . A wireless body area network for an insulin infusion system, comprising:
 a first device that is configurable to receive first identification information from a cloud-based computing system, wherein the first identification information identifies the second device; and   a second device that is configurable to transmit second identification information when the second device is prepared for use, wherein the first device is configurable to process the second identification information and automatically establish a secure communication link between the second device and the first device when the second identification information corresponds to the first identification information stored at the first device, and wherein one of the first device and the second device is a particular medical device for a patient and wherein the other one of the first device and the second device is a particular non-medical device associated with the patient.

Join the waitlist — get patent alerts

Track US2021377726A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.