Medical instrument monitoring method and system
Through quantum public key and speckle fingerprint curing design identity, combined with optical domain supervector and process feature encryption, digital twin predicts residuals, the device-level anti-counterfeiting and online micro-defect detection of medical devices is realized, ensuring causal closed loop and automatic CAPA, and solving the problems of easy replication, insufficient micro-defect capture and data tampering in the existing technology.
Patent Information
- Application Number
- CN202510560846.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-12
AI Technical Summary
Existing medical device monitoring systems rely on visual tags to be easily copied or worn, and cannot capture microscopic defects. Data storage lacks a causal chain across design-manufacturing-defects, resulting in manual inspection of root location and long shutdown time. Using conventional symmetric encryption between tags and cloud databases can easily lead to data tampering.
The design identity is designed using quantum public key and speckle fingerprint curing. The optical domain supervector and process features are encrypted and uploaded in the manufacturing stage. The digital twin predicts the sequence and calculates the normalized residuals. The super-threshold triggers holographic convolution-diffusion reconstruction, outputs defect semantics, and writes them into the hypergraph ledger through zero knowledge, and periodically calls the causal inference model to achieve a closed loop of quality.
It realizes device-level anti-counterfeiting, realizes online micro-defect detection, ensures privacy across design-manufacturing-defect causal closed loop, and minimizes automatic CAPA and downtime losses.
Smart Images

Figure CN120473104A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of medical device quality management, and in particular to a monitoring method and system for medical devices. Background Art
[0002] From medical device design and production to logistics, clinical use, and retirement, any loss of control at any stage can lead to quality risks and compliance failures. Establishing a management and monitoring system covering the entire lifecycle can improve safety and operational efficiency across four key areas: source anti-counterfeiting, production quality control, post-market monitoring, and recall traceability.
[0003] Existing technology uses RFID tags, barcode scanners, and IoT gateways to collect device information, which is then stored in a central database and determined using a rules engine. This approach relies on visible tags, which are susceptible to copying and wear. During the production phase, only batch numbers are recorded, failing to capture microscopic defects. Data is stored in a two-dimensional table of device and time, lacking a causal chain that spans design, manufacturing, and defects. This results in manual root cause identification and long production downtime. Conventional symmetric encryption is used between the tags and the cloud database, and a compromised key could result in data tampering throughout the entire chain. Summary of the Invention
[0004] To address the numerous issues with the aforementioned existing technologies, the present invention provides a medical device monitoring method and system. This method uses quantum public keys and speckle fingerprints to solidify the design identity. During the manufacturing phase, optical supervectors and process characteristics are encrypted and uploaded. A digital twin predicts the sequence and calculates the normalized residual. Exceeding a threshold triggers holographic convolution-diffusion reconstruction, outputting defect semantics that are written to a hypergraph ledger using zero-knowledge. A causal inference model analyzes the three-part hypergraph at fixed intervals and automatically issues torque and temperature corrections, achieving closed-loop quality control and regulatory compliance.
[0005] A method for monitoring a medical device comprises the following steps:
[0006] Generate design genetic data including model code, physical unclonable fingerprint and quantum public key at the design freeze node, and write it into the Twin-DNA chip to establish the unique identification of the device;
[0007] During the manufacturing phase, process parameters and scattered optical data are collected, and a light domain supervector is constructed based on the scattered optical data. The light domain supervector is then concatenated with the process embedded features derived from the process parameters to form manufacturing embedded feature data, which is then sent to the corresponding digital twin to update the device management status.
[0008] The digital twin calculates the residual between the embedded feature data and the predicted feature. If the residual reaches a threshold, vector holographic convolution and diffusion generation operations are performed to obtain the residual vector, which is input into the supervector transformer to obtain the defect semantic data and written into the hypergraph causal ledger indexed by the quantum public key in a zero-knowledge manner.
[0009] The hypergraph attention network and neural relationship inference model are periodically called to perform causal analysis on the three-part hypergraph composed of the design gene data, manufacturing process data and defect semantic data, generate corrective and preventive data, write it back to the manufacturing execution system and write it into the hypergraph causal ledger to achieve quality closed loop, business decision-making and regulatory delivery.
[0010] Preferably, the designed gene data further includes a quantum private key and a hash value calculated from the tolerance mapping matrix of the three-dimensional design model, and the quantum private key and the hash value are written into the write-only storage area of the Twin-DNA chip.
[0011] Preferably, the physical unclonable fingerprint generates a grayscale speckle matrix by irradiating a key surface of a medical device with coherent light and collecting an interference speckle image, and the grayscale speckle matrix is stored together with the designed gene data.
[0012] Preferably, the scattered optical data is composed of a scattered wave vector sequence collected synchronously by multiple spectral channels, the scattered wave vector sequence is calculated by optical domain phase shift to obtain an optical domain super vector, and the optical domain super vector is spliced with the process embedded feature.
[0013] Preferably, the manufacturing embedded characteristic data is encrypted by a block encryption algorithm before being sent, and an integrity check mark is attached, and the integrity check mark is transmitted together with the manufacturing embedded characteristic data.
[0014] Preferably, the residual is obtained by calculating the Euclidean distance between the embedded feature data and the corresponding predicted feature, and the Euclidean distance is statistically normalized with the residual mean and standard deviation of the recent sliding window. When the normalization result exceeds a preset threshold, the vector holographic convolution and diffusion generation operation is triggered.
[0015] Preferably, the vector holographic convolution is realized by performing cyclic shift and bitwise XOR operation on the binary light domain supervector, and the diffusion generation operation gradually denoises the light domain supervector through multi-level noise scheduling to obtain the ideal light domain supervector.
[0016] Preferably, the hypergraph causal ledger constructs a three-part hypergraph structure with the quantum public key as the root node, and uses a zero-knowledge proof protocol to verify the integrity and confidentiality of the defect semantic data before writing the defect semantic data.
[0017] Preferably, the periodic call executes the hypergraph neural network and neural relationship inference model at fixed time intervals, and the generated correction and prevention data is used to adjust the assembly torque setting value and heating temperature setting value in the manufacturing execution system, and the hash value of the correction and prevention data is written into the hypergraph causal ledger.
[0018] A monitoring system for medical devices, for implementing the method described above, comprising:
[0019] A gene writing module is used to generate designed gene data including a model code, a physical unclonable fingerprint, and a quantum public key at a design freezing node, and write the designed gene data into a Twin-DNA chip to establish a unique identification for the medical device;
[0020] A manufacturing acquisition module is used to collect process parameters and scattered optical data during the manufacturing stage, construct a light domain supervector based on the scattered optical data, concatenate the light domain supervector with the process embedded features obtained from the process parameters to form manufacturing embedded feature data, and send the manufacturing embedded feature data to the corresponding digital twin to update the medical device management status;
[0021] An abnormal reasoning module is used to calculate the residual between the manufacturing embedded feature data and the predicted feature by the digital twin, perform vector holographic convolution and diffusion generation operations to obtain a residual vector when the residual reaches a threshold, input the residual vector into the supervector transformer to obtain defect semantic data, and write the defect semantic data into a hypergraph causal ledger indexed by the quantum public key in a zero-knowledge manner;
[0022] The causal closed loop module is used to call the hypergraph attention network and the neural relationship inference model according to a set cycle, perform causal analysis on the three-part hypergraph composed of the design gene data, manufacturing process data and defect semantic data, generate corrective and preventive data, write the corrective and preventive data back to the manufacturing execution system and write it into the hypergraph causal ledger to achieve quality closed loop, operational decision-making and regulatory delivery.
[0023] Compared with the prior art, the advantages and beneficial effects of the present invention are:
[0024] The present invention achieves device-level anti-counterfeiting through quantum random public and private keys and light scattering physical unclonable fingerprints;
[0025] The present invention realizes online micro-defect detection by embedding and splicing optical domain supervectors with process and synchronizing digital twins in real time;
[0026] This invention uses a three-part hypergraph ledger and zero-knowledge commitment to achieve a causal closed loop across design, manufacturing, and defects while ensuring privacy.
[0027] The present invention realizes automatic CAPA and minimization of downtime losses by periodic causal inference driving torque and temperature self-correction. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 Schematic diagram of the process of the present invention;
[0029] Figure 2 This is a schematic diagram of generating a light domain supervector according to the present invention;
[0030] Figure 3 This is a schematic diagram of the correction and prevention closed loop and evidence storage of the present invention;
[0031] Figure 4 It is a structural block diagram of the system of the present invention. DETAILED DESCRIPTION
[0032] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure.
[0033] like Figure 1 As shown, a method for monitoring a medical device includes the following steps:
[0034] Generate design genetic data including model code, physical unclonable fingerprint and quantum public key at the design freeze node, and write it into the Twin-DNA chip to establish the unique identification of the device;
[0035] The lifecycle management of medical devices usually spans multiple stages including design, manufacturing, logistics, clinical application, maintenance and decommissioning. Identity confusion in any link will undermine the quality traceability chain. The present invention introduces design gene data at the "design freeze node" and writes it into the Twin-DNA chip in binary form, binding the static identity of the device with all subsequent dynamic behaviors, laying the root index for full-process management. The design gene data consists of three types of information: "model code", "physical unclonable fingerprint" and "quantum public key". Each field is stored in a fixed order within the chip, and only the public key and hash fingerprint are exposed externally, thereby avoiding the leakage of sensitive structural features.
[0036] The model code is automatically generated by the enterprise PLM system and can be uniquely mapped to the functional configuration, version number and assembly list of the device. The physical unclonable fingerprint (PUF) uses the speckle interference image generated when a coherent laser is irradiated on a specific surface of the device. Its texture distribution is determined by the micro-roughness and internal lattice defects, and is naturally random and non-replicable. The system selects the cavity shielding surface as the collection area and uses a 405nm laser pulse for 10ms to obtain a speckle image with a signal-to-noise ratio greater than 30dB, which is then converted into a grayscale matrix P i,j To eliminate batch gain differences, the global gain g and local contrast weight w are implemented on the matrix i,j Calibration, the core calculation is:
[0037] P′ i,j =gw i,j P i,j
[0038] Where i, j are pixel coordinates, g is the full-width gain constant, and w i,j The calibrated matrix P′ is calculated in real time by the pixel neighborhood variance. i,j The fingerprint summary F is compressed into 256 bytes after mapping. This summary does not contain any geometric information and only retains high entropy texture features for subsequent hash verification.
[0039] Quantum public key K pub The quantum random number generator driven by spontaneous emission noise of erbium-doped fiber generates a number with a deviation of no more than 10 -6 Private key K pri Saved in the hardware security module and only used to sign the internal state. The system combines the model code M, fingerprint summary F and quantum public key K pub Splice into byte stream S and calculate the global hash:
[0040] H=SHA256(M||F||K pub )
[0041] Where M represents the model code, F represents the physical unclonable fingerprint summary, K pub represents the quantum public key, and the symbol ||·|| indicates sequential concatenation. The hash H acts as a high-entropy index for the ledger, allowing any node to verify its authenticity through a single hash comparison without exposing the original fingerprint.
[0042] The Twin-DNA chip uses a write-only fuse architecture, meaning each byte cannot be modified after being programmed. The writing order is M, F, Kpub, and H. Upon completion, the chip's built-in CRC check is triggered. If the check fails, the fuse protects the device from leaving the factory. The chip also provides a quantum public key-based challenge-response interface, capable of outputting a signed response to an external random challenge, enabling offline authentication.
[0043] After introducing the design gene data, the subsequent manufacturing acquisition module simply associates the real-time embedded manufacturing feature data with the ledger node corresponding to H in the chip, completing identity verification in milliseconds. Logistics, clinical practice, and maintenance processes can also call upon the same hash node to avoid duplicate registration. Compared to traditional labeling or serial numbering solutions, this method can complete local authenticity verification without the need for additional tamper-evident film or network connectivity.
[0044] Example: A 20mm square area on the inner wall of the laparoscopic device model "AL-Lap-23" is selected as the PUF surface. The laser irradiation parameter is a 10ms single pulse, and the matrix P' is obtained. i,j After calibration with the above formula, the summary F is generated. pubThe hash H is obtained by splicing and written into Twin-DNA. After the device enters the after-sales center, it is repeatedly collected to obtain F' and calculated: H = SHA256 (M||F'||K pub ) is established, confirming that the device has not been replaced. If the hashes are inconsistent, an exception is recorded and subsequent digital twin synchronization is blocked, preventing counterfeit devices from entering the quality closed loop.
[0045] After writing, the genetic data is designed not to be modified, ensuring that each lifecycle node references the same root index even when running concurrently on multiple nodes. To address the risk of surface wear, the acquisition surface was designed to avoid high-friction areas and store a local fingerprint template on the chip. This allows for slight offsets to be corrected using a displacement registration algorithm without compromising hash consistency.
[0046] Preferably, the designed gene data further includes a quantum private key and a hash value calculated from the tolerance mapping matrix of the three-dimensional design model, and the quantum private key and the hash value are written into the write-only storage area of the Twin-DNA chip.
[0047] Quantum public key K pub Already stored in the designed gene data, used for ledger indexing and identity disclosure. The corresponding quantum private key K pri Generated by the same quantum random number generator, placed in a secure key isolation environment, and only called within the Twin-DNA chip. The chip integrates the elliptic curve digital signature algorithm control logic, and the external system can submit any message hash h m , the chip returns the signature:
[0048]
[0049] Because K pri Without ever leaving the hardware boundary, any active node only needs to verify:
[0050] Verify(K pub ,h m ,S)=true
[0051] This confirms that the device is the original certified by the designer and that the chip has not been replaced to date. The quantum random number source ensures that the key entropy is much higher than that of a classical PRNG, and is not vulnerable to post-quantum cracking threats from symmetric encryption or elliptic curves. Tolerance Mapping Matrix Hash Value Generation: When the 3D design model is frozen, the dimensional limit deviations of all parts are represented as a multidimensional tolerance set, such as hole diameter deviation, coaxiality, and surface error. This invention maps this independent tolerance information into a sparse matrix:
[0052] C=[c i,j ]
[0053] where c i,jCharacterizes the tolerance between the i-th feature and the j-th assembly datum, and the unit is unified in millimeters. In order to be consistent with the actual measurement in the subsequent manufacturing process, the matrix elements are linearly normalized:
[0054]
[0055] where c min with c max are the global minimum and maximum values of all tolerances in the current device design file, respectively. The normalized matrix is flattened into a vector in row-major order and the hash is calculated:
[0056]
[0057] Among them, c i,j Indicates the original tolerance value; represents the normalized tolerance value; vec(·) represents the matrix row expansion operation; H C Represents the tolerance matrix hash value. This hash value does not reveal any specific geometric information, but corresponds to each process tolerance. Subsequent quality inspections can quickly verify the consistency of design and manufacturing by calculating the hash value of the measured tolerance matrix using the same process.
[0058] The Twin-DNA chip uses a fuse array to achieve permanent one-time writing. Writing order: quantum private key K pri ; Tolerance hash H C A bit mask is also recorded inside the chip. If the writing process is interrupted, a lock is triggered to prevent incomplete data from causing signature invalidation. pri Place it in the signature engine's read-only domain, so other logic cannot access the original private key.
[0059] Through the present invention, the public key-private key pair provides active signature function, and the hash value provides passive hash verification function; combined with the physical unclonable fingerprint, a three-factor identity is formed. C Any modification that exceeds the tolerance can be found without rereading the entire drawing. pub and H C If the chip is cloned but the tolerance hash does not match, the ledger verification will fail immediately. The private key is permanently stored in the fuse array, with no debug port readout path, and interaction with the external bus is only through the signature interface.
[0060] In the embodiment, the outer tube thickness tolerance of a cardiovascular intervention balloon catheter is +0.02mm, and the catheter tip ovality tolerance is 0.015mm. The enterprise determines the model code "CV-BCA-14" for this product. The steps include:
[0061] 1. After the design is frozen, extract all dimensional tolerances and construct C.
[0062] 2. Unified Computing And generate H C .
[0063] 3. The quantum random number generator outputs the private key K pri With the public key K pub .
[0064] 4. Programming fixture will K pri With H C Melt and write to the chip in sequence.
[0065] 5. The chip starts self-test and returns a signature After passing the factory verification, the data is recorded in the quality control database. Usage scenario: The catheter is sent to a third-party sterilization center. When receiving the goods, the quality inspection instrument scans the chip and randomly challenges the string h m The chip is returned with signature S. Sterilization center verification:
[0066] Verify(K pub ,h m ,S)=true
[0067] Prove that the private key exists and has not been leaked. Then measure the key size to generate H′ C Ledger comparison H′ C =H C Establish, confirm the geometric integrity before and after sterilization. Record and write back to form a complete monitoring.
[0068] If the catheter is accidentally deformed and H' C =H C , the quality inspection system will immediately alarm and prevent the chip from entering the warehouse; if the chip is forged and only the public key is cloned but there is no private key, the signature verification will also fail, achieving double interception.
[0069] Preferably, the physical unclonable fingerprint generates a grayscale speckle matrix by irradiating a key surface of a medical device with coherent light and collecting an interference speckle image, and the grayscale speckle matrix is stored together with the designed gene data.
[0070] The physical unclonable function (PUF) of medical devices utilizes the randomly formed rough texture features on the device surface at the nanometer-micrometer scale. These features originate from the entropy increase process during injection molding, machining, or electrochemical processing. Even if two devices are manufactured using identical processes, their surface speckle patterns still exhibit statistically independent distributions. At the design freeze point, this method selects "critical surfaces"—locations that minimize friction and corrosion during subsequent use and can be directly observed before assembly—and applies a single coherent light irradiation to them. This generates a unique and unclonable speckle grayscale matrix. This matrix is compressed and stored together with the designed genetic data on a Twin-DNA chip, providing a hardware-level identity anchor for subsequent monitoring and management.
[0071] The coherent light source uses a semiconductor laser with a central wavelength of 405nm and a linewidth of <0.1nm. The divergence angle is controlled at 2.5° by fan-out optical elements. The laser beam is incident vertically on a 4mm×4mm square area of the sampling surface. The rough surface scatters the incident light at multiple points, which are superimposed under coherent conditions to form a speckle interference field. The CMOS linear array detector obtains a raw speckle image P with a signal-to-noise ratio higher than 30dB within a 10ms exposure time. i,j , pixel size 4μm.
[0072] In order to offset the laser power drift and the uneven brightness of the detector, the present invention uses a gain-contrast dual correction model to correct the P i,j Perform preprocessing:
[0073] P′ i,j =gw i,j P i,j
[0074] Among them, P i,j Represents the original grayscale value, P′ i,j represents the grayscale value after correction, g is the global gain coefficient, measured by the whiteboard reference frame, and w i,j is the local contrast weight, which is defined as the ratio of the variance of the pixel neighborhood to the variance of the entire image.
[0075] The corrected matrix is divided into 32×32 grid blocks, and the average of each block is calculated to obtain a 1024-dimensional vector v. The vector elements are then binary quantized:
[0076]
[0077] Where μv is the global mean of v. Quantization results F1,…,F 1024 The fingerprint is packed into a 128-byte digest F. This digest meets the following security criteria: the expected Hamming distance between two independent instruments' fingerprints is approximately 512 bits; the average coincidence rate of repeated measurements of the same instrument is greater than 98%. The system then performs hashing:
[0078] H P =SHA256(F)
[0079] H P The fingerprint index is written into the Twin-DNA chip along with other designed genetic fields (model code, quantum public key, etc.). The chip fuse area cannot be rewritten once written, ensuring that the baseline fingerprint remains unchanged throughout life.
[0080] The application of the above-mentioned processing in the full life cycle monitoring of medical devices includes:
[0081] Manufacturing process traceability: After the key process is completed, the production line quickly scans the sampling area, generates F' again, and compares SHA256 (F') with the H in the chip. P If a match fails, potential replacement parts are immediately eliminated to prevent counterfeit parts from entering the batch.
[0082] During the acceptance of the logistics link, the warehouse or third-party sterilization center uses a portable speckle collector to repeat the above process, and uses the account book records to determine whether any substitution occurred during the transportation process.
[0083] During clinical use and maintenance, fingerprint digests are collected once before and after the device is returned to the factory for overhaul. If SHA256(F″)≠H P This indicates that the structural parts have been over-polished or corroded, and the twin parameters need to be recalibrated.
[0084] To prevent decommissioning and gray market, a one-time signature is executed before destruction and the chain is written to mark the "retired" status; if a device of the same model and with a matching fingerprint hash appears in the subsequent market, the source of illegal circulation can be traced.
[0085] Example: A certain brand of knee joint milling saw has a shell side wall of 4mm 2 The area is used as the PUF surface, and batch sampling is performed to obtain an average brightness of 128ADU and a variance of 42ADU. 2 The speckle matrix was processed using the algorithm presented in this paper to produce the fingerprint summary A0F3…2C (hexadecimal abbreviation). Two years later, the same device was retested at a surgical instrument cleaning center. The collected speckle pattern, after binary quantization, had a Hamming distance of 9 bits from the original fingerprint, meeting the ≤2% tolerance threshold, indicating no detectable damage to the housing surface and the device could continue to operate.
[0086] like Figure 2 As shown, during the manufacturing stage, process parameters and scattered optical data are collected, and a light domain supervector is constructed based on the scattered optical data. The light domain supervector is then concatenated with the process embedded features obtained from the process parameters to form manufacturing embedded feature data, which is then sent to the corresponding digital twin to update the equipment management status.
[0087] In the assembly area of a manufacturing line, medical devices undergo multiple processes, including tightening, welding, and hot pressing. This invention configures an edge-to-cloud data path for each device: the edge collects multimodal signals from the workstation, and the cloud-side digital twin receives the embedded vectors and corrects the device status in real time. The collected data is divided into two categories: process parameter flow and scattered optical flow.
[0088] like Figure 3 As shown, the process parameter stream is provided by the PLC and torque sensor, including torque, rotation angle, solder joint temperature, pressure, and defect level of the AOI image frame. The equipment reads these values at a 40Hz cycle and forms a time series matrix. To avoid gradient explosion caused by channel scale differences, the edge first performs zero-mean normalization. The sequence is then input into a deep 18-layer convolution-attention network, which outputs a fixed-length process embedding vector e. The convolution kernel size is three and the stride is one, ensuring that sub-second process fluctuations can be captured. The attention layer assigns learnable weights to different workstation features, so that channels that have a significant impact on finished product quality occupy higher dimensions in the embedding space.
[0089] The scattered optical flux originates from the molecular quantum dot metasurface above the device housing. After assembly, the robot positions the device in the optical inspection chamber. A 405nm laser illuminates the four-square-millimeter surface vertically, and the metasurface modulates the phase using a subwavelength grid, generating a 64-channel scattering spectrum. The original spectrum is then processed through logarithmic amplification and dark current subtraction to form a column vector. To achieve efficient compression in edge chips, the present invention uses a set of random orthogonal projection matrices F∈{-1,+1} 1024×384 , mapping the spectral signal to a thousand-dimensional supervector space:
[0090] m=sgn(Fs)
[0091] where sgn(·) is an element-by-element sign function that outputs {-1, +1}. Here, s represents the preprocessed scattered optical vector, F represents the orthogonal projection matrix, pre-programmed into the chip, and m represents the optical domain supervector, with a dimension of 1,000, used to amplify small phase perturbations.
[0092] The generated m and the process embedding vector e are bitwise concatenated to form the manufacturing embedded feature data z = [m‖e]. Before transmission, the edge performs AES-GCM encryption and calculates the SHA-256 integrity hash. Then, z, the timestamp, and the quantum public key in the chip are sent to the campus 5G industrial gateway in one UWB pulse frame.
[0093] After receiving the ciphertext, the cloud-based digital twin decrypts and verifies the signature, storing z in a time window buffer. The twin uses a time-series graph convolutional network to predict the embedding trajectory for the next hour, calculates the residual, and decides whether to enter the exception reasoning process. If the residual is within the statistical threshold, indicating that the current process has not caused irreversible deviations in the device's morphology and mechanical state, the twin directly writes the "compliant" mark to the ledger. If the residual grows superlinearly, the exception reasoning module is immediately notified to trigger diffusion reconstruction and causal analysis, and the edge PLC also receives a speed reduction or retest instruction. This allows for early detection of micro-deformations or material defects during the assembly phase, preventing the continued circulation of defective products.
[0094] The greatest advantage of introducing optical domain supervectors lies in their ability to achieve both compression efficiency and sensitivity. Traditional machine vision requires the transmission of 300,000-pixel grayscale images, which are then segmented and reconstructed in the cloud. This solution only transmits a 1,000-dimensional binary vector, and its Hamming distance sensitivity to surface phase disturbances is theoretically improved by more than ten times that of traditional grayscale comparisons. Furthermore, the process embedding vector projects multi-station parameters into a unified feature space. The convolutional receptive field of the twin can simultaneously capture cross-station coupling, such as excessive welding temperature causing subsequent tightening torque drift, thereby shifting quality control from the "final inspection" stage to the "online" stage.
[0095] Preferably, the scattered optical data is composed of a scattered wave vector sequence collected synchronously by multiple spectral channels, the scattered wave vector sequence is calculated by optical domain phase shift to obtain an optical domain super vector, and the optical domain super vector is spliced with the process embedded feature.
[0096] There are random phase fluctuations on the surface of medical devices that cannot be replicated at the micron scale. After irradiation with coherent laser, the wave vector k of the scattered field p (p is the channel number) will drift slightly with micro-defects in processing. The present invention sets a molecular quantum dot metasurface detector above the manufacturing station, uses a structural color filter layer to divide the reflected light into 64 independent spectral channels, and simultaneously collects the scattered wave vector sequence of these 64 channels at the same time, which is recorded as a column vector:
[0097] s=[k1,k2,…,k 64 ] T
[0098] where k p represents the wave vector modulus corresponding to the pth channel. After dark current subtraction and logarithmic amplification, vector s is sent to a dedicated optical domain phase shift unit. This unit internally solidifies a set of 1,000 rows and 64 columns of orthogonal projection matrix F, linearly rotates s, and then applies symbolic quantization to obtain the optical domain supervector:
[0099] m=sgn(Fs)
[0100] where sgn is an element-wise sign function with an output dimension of one thousand and elements ranging from {-1, +1}. The letters have the following meanings: F represents the orthogonal projection matrix, generated from a preshared pseudorandom sequence; s represents the column vector of the preprocessed scattering wave vector; and m represents the optical domain supervector, a high-dimensional amplified representation of the surface phase perturbation.
[0101] The parallel collected process parameters (torque, temperature, pressure, AOI defect level, etc.) are encoded into a process embedding feature e of length 512 through a convolutional attention network. The system concatenates the binary supervector m with the floating-point embedding e bit by bit:
[0102] z=[m||e]
[0103] Manufacturing embedding feature data is obtained. The edge performs AES-GCM encryption on z, calculates a SHA-256 hash, and sends it to the cloud-based digital twin. The twin stacks z in chronological order and uses a time-series graph convolutional network to predict future embedding trajectories. If the residual exceeds a threshold, exception reasoning is immediately triggered and scheduling instructions are issued to the workstation, achieving a real-time quality closed loop.
[0104] Optical domain supervectors offer two management advantages. First, the data volume is constant at 1,000 bits, compared to at least hundreds of thousands of pixels for traditional spectra or grayscale images, reducing edge-to-cloud communication bandwidth by three orders of magnitude. Second, orthogonal random projection maps surface phase perturbations into Hilbert space before binarization. Any single-channel phase drift generates multiple bit flips in high-dimensional space, exponentially amplifying micro-defects across the Hamming distance and improving early detection sensitivity.
[0105] Example: When mass-producing disposable bone drill handles, if the titanium coating on the surface is etched 30 nanometers, the single-channel wave vector will shift by about 4×10 -4 Measured vector m test With the ideal vector m ref The Hamming distance reached 121, exceeding the empirical threshold of 96, and the system identified it as a "coating anomaly." A line stop signal was returned via the cloud, and the workstation automatically paused. Inspection revealed an abnormally high sandblasting pressure, enabling timely adjustments to prevent the entire batch from being scrapped.
[0106] Through the deep integration of scattered optical high-dimensional encoding and process parameters, the present invention realizes low-bandwidth and high-sensitivity monitoring in the manufacturing stage, providing high-entropy input for the subsequent residual-driven anomaly generation-discrimination link, while ensuring that the digital twin can update the medical device management status at the millisecond level, supporting the timeliness and accuracy of full life cycle monitoring.
[0107] Preferably, the manufacturing embedded characteristic data is encrypted by a block encryption algorithm before being sent, and an integrity check mark is attached, and the integrity check mark is transmitted together with the manufacturing embedded characteristic data.
[0108] Before the manufacturing embedded feature data z enters the digital twin through the edge-cloud channel, two security goals need to be met simultaneously: one is to prevent external eavesdroppers from inferring the scattering phase information and process conditions of the instrument surface; the other is to block the middleman from tampering with the network frame and causing the twin state to be distorted. The present invention uses the authenticated encryption mode of the block encryption algorithm to complete "encryption + integrity verification" at the edge side at one time, and encapsulates the authentication tag and ciphertext in the same data message to ensure that the cloud cannot access the plaintext before verification. This process does not require an additional replay protection channel, reduces deployment complexity, and is suitable for the real-time needs of high-beat assembly lines.
[0109] During each sampling period, the edge node retrieves the session key K from the key storage area. This key is generated through an ECDH handshake between the quantum private key in the device chip and a random challenge in the cloud. Its lifespan is limited to one hour to prevent key exhaustion in high-concurrency scenarios. The node also generates a random number (Nonce) N, derived from the XOR of a high-resolution hardware counter and a physical noise entropy pool, ensuring global uniqueness.
[0110] When using GCM (Galois / CounterMode), the plaintext z first enters the counter encryptor to obtain the ciphertext:
[0111] C=Enc K (N,z)
[0112] Where Enc K This means that the counter block is encrypted with the key K and XORed with the plaintext; N is used to construct the initial value of the counter. Then, the header field A (such as the device serial number and sampling timestamp) associated with the application layer but not requiring encryption is input into the Galois multiplier to obtain the authentication tag:
[0113] T=Tag K (N,A,z)
[0114] Among them, Tag K Indicates GF(2 128 )The message authentication code obtained by polynomial multiplication.
[0115] The final message structure is [N||A||C||T]. After receiving it, the digital twin first recovers the session key K using the same derivation method, and then calls Tag K Recalculate label T * Only when T * = T and the random number N is not reused, the system enters the decryption process; otherwise, the message is immediately discarded and the security event is recorded.
[0116] Integration with medical device monitoring and management includes:
[0117] Design-manufacturing connection, the derivation process of the session key is bound to the quantum private key in the chip, so the decryption party must hold the matching quantum public key. Any unauthorized edge device will not be able to establish a legitimate key with the cloud, thereby avoiding the injection of counterfeit devices.
[0118] Manufacturing-logistics extension: the timestamp in the message header is confirmed by the cloud and written into the ledger, becoming the starting point for logistics node traceability. If a message is lost, the potential packet loss can be inferred through the random number gap and edge retransmission can be triggered without relying on additional handshakes.
[0119] For cloud-side anomaly detection, only data that passes integrity verification can update the twin; once an attacker modifies the ciphertext (for example, trying to cover up screw torque anomalies), the authentication tag verification will inevitably fail, ensuring that the twin reasoning script is not contaminated.
[0120] For decommissioning and evidence collection, all ciphertext-tag pairs are written to the chain for evidence storage. Upon decommissioning, the chip's private key can be used to generate a termination signature, proving the end of the key lifecycle. For later legal evidence collection, the decryption can be replayed without the private key to verify data authenticity.
[0121] In this example, an orthopedic drill assembly line runs at 25 units per minute. Edge nodes must complete encryption and transmission within a 40Hz sampling period, leaving the encryption algorithm with a total latency of less than 5ms. The device uses a 128-bit block encryption core and hardware-implemented Galois multiplication, achieving a single-round latency of 220ns, meeting real-time requirements. The processing flow includes:
[0122] At the beginning of the sampling period, z (length 1512 bytes) is generated, and the random number counter is incremented to generate 96 bits of N.
[0123] The hardware AES-GCMIP core is called, and the encryption takes 1.3ms to obtain the ciphertext C and tag T.
[0124] The sequence number and timestamp are added to the message as header field A, with a total length of 1616 bytes.
[0125] Broadcast to the campus base station in one go via UWB pulse-position modulation; the average link layer packet loss rate is 0.2%.
[0126] It takes 0.9ms to decrypt the cloud twin and it is written to the manufacturing process node after verification.
[0127] The entire link achieved an end-to-end latency of 4.1ms, meeting a 40Hz sampling window. After randomly inserting 5,000 bit-flip attacks, the authentication tag detected and discarded all illegal packets with a false positive rate of 0. Compared to traditional plaintext transmission solutions, statistics show that false alarms from twin residual calculations decreased by 96%, significantly reducing downtime bandwidth and manual re-inspection costs.
[0128] The digital twin calculates the residual between the embedded feature data and the predicted feature. If the residual reaches a threshold, vector holographic convolution and diffusion generation operations are performed to obtain the residual vector, which is input into the supervector transformer to obtain the defect semantic data and written into the hypergraph causal ledger indexed by the quantum public key in a zero-knowledge manner.
[0129] The digital twin resides in the cloud and maintains the time series state vector of each medical device in real time. t Upon arrival, the twin first calls a three-layer temporal graph convolutional network to recursively extrapolate the embedded sequence within the last sixty-second window to obtain a one-step forward prediction vector The Euclidean distance between the two:
[0130]
[0131] is the instantaneous residual, where z t Indicates the current manufacturing embedded feature data, Denotes the prediction feature, and ||·||2 is the two-norm. The twin maintains the residual mean μ in the sliding window ε and standard deviation σ ε , and calculate the normalized score:
[0132]
[0133] When s t When it is greater than the empirical threshold of 2.5, it indicates that the surface phase, process load, or a combination of the two of the current instrument has an abnormal deviation, and the system enters the depth judgment link.
[0134] The first step of the link is vector holographic convolution. The twin retains the optical domain supervector m at the previous moment. t-1 , and compare it with the current light domain supervector m t Perform a circular shift and do a bitwise XOR to get a difference vector of length one thousand:
[0135] h t =XOR(m t ,Shift(m t-1 ,r))
[0136] Shift(·,r) represents a right shift of r bits, where r is locked by a random number seed. The purpose of holographic convolution is to spread the fine-grained phase shift to the entire vector domain so that it can be captured by subsequent models. t Input diffusion generation module. The diffusion generation module contains eight levels of noise scheduling, each level is h t Weighted Gaussian noise is injected and the denoising target is predicted by a lightweight U-Net. After the reverse inference is completed, the ideal super vector is obtained. Then, the residual vector is constructed by taking the difference with the measured supervector:
[0137]
[0138] The residual vector is concatenated to the process differential feature (e t For current process embedding, The transformer uses a six-layer multi-head self-attention architecture with a hidden dimension of 256 per layer. The spatial position code and the physical channel code are injected simultaneously through the residual connection. The network outputs a multi-hot vector c t , where each bit corresponds to a semantic label of the defect dictionary; and outputs the real-valued confidence p t The system will c t 、p t and the residual amplitude ε t Combined into defect semantic data block D t .
[0139] In order to write the test results into the account book without revealing any production details, the present invention adopts the Bulletproofs-Plus zero-knowledge protocol based on elliptic curves. t Hash to get fingerprint H d , and then use the device quantum private key K pri Generate a promise:
[0140] π t =BP(K pri ,H d )
[0141] Commitment π t Prove that the defective data does exist and can be verified by the corresponding public key, but does not expose D t Content. Then the quantum public key K pub As the root node, the key-value pair <H d ,π t The data is written as a child node into the hypergraph causal ledger. This ledger uses a three-part hypergraph model: one for the design node, one for the manufacturing node, and one for the defect node. During writes, the system associates the defect node with both the current manufacturing node hash and the design gene hash, forming a ternary hyperedge. This ensures tamper-proofing while enabling the root cause of the defect to be traced in subsequent causal inference.
[0142] The advantages of introducing vector holographic convolution and diffusion generation are: 1. Any single-bit phase disturbance will spread into multi-bit flips in the convolution-diffusion link, and the Hamming distance will be amplified exponentially, making micro-defects significantly prominent in high-dimensional space; 2. The diffusion network implicitly learns the ideal distribution during the noise scheduling process and can quickly migrate the scattering characteristics of new models or new materials; 3. Compared with classical image segmentation or one-dimensional threshold methods, this link does not rely on manual thresholding, but can be adaptively triggered according to statistical residuals.
[0143] Preferably, the residual is obtained by calculating the Euclidean distance between the embedded feature data and the corresponding predicted feature, and the Euclidean distance is statistically normalized with the residual mean and standard deviation of the recent sliding window. When the normalization result exceeds a preset threshold, the vector holographic convolution and diffusion generation operation is triggered.
[0144] On the Digital Twin side, a chronologically ordered sequence of manufacturing embedding features is maintained for each medical device. The embedding vector arriving at the current time t is denoted as z t The twin body uses convolution-gated loop prediction of the vector of the past L moments to obtain a one-step forward estimate The Euclidean distance between the two is defined as the instantaneous residual:
[0145]
[0146] Where ||·||2 is the two-norm; z t represents the actual collected manufacturing embedding feature vector; Represents the model prediction vector. Different from the static threshold, the present invention introduces a sliding window statistical normalization mechanism. The system calculates the mean μ for the latest W residual samples. ε and standard deviation σ ε , and get the standardized score:
[0147]
[0148] Just as s t ≥τ (τ is the preset threshold), the current device state is determined to deviate from the normal statistical distribution, triggering the subsequent vector holographic convolution and diffusion generation operation. ε and σ ε Updated in real time by window, this method can automatically adapt to changes in production line rhythm or seasonal process drift, avoiding excessive alarms or missed detections caused by static thresholds.
[0149] Residual normalization has two functions: first, it eliminates the scale differences between different equipment models and different assembly lines into dimensionless space, so that the same threshold τ can be reused across models; second, it amplifies the time gradient of abnormal increments under continuous sampling conditions, so that multiple slight drifts are accumulated to form a higher s t Outbreak, providing lead time for quality engineers.
[0150] When s t Breaking through the threshold, the system can achieve the super vector m in the light domain. t and the supervector m at the previous moment t-1 Perform circular shift XOR to generate the holographic difference vector:
[0151] h t=XOR(m t ,Shift(m t-1 ,r))
[0152] Shift(·,r) means right shift by r bits, where r is locked by the random number seed. The holographic difference vector is converted to the ideal state by the eight-level noise scheduling diffusion denoising network. Reconstruct the residual vector:
[0153]
[0154] The residual vector and the synchronized process differential features are input into the supervector transformer to output the defect semantics D t At this point, the complete link from statistical deviation → depth reconstruction → semantic judgment is realized.
[0155] Compared with the traditional single-threshold alarm method, the sliding normalization of the present invention shows higher adaptability and accuracy in the full monitoring and management of medical devices. First, it eliminates batch differences: when processing bone saw handles of different lengths or materials on the same daily production line, static thresholds are difficult to take into account, while the normalized score can adapt to local distribution. Second, it has time-series sensitivity: continuous small drifts will not be masked by isolated errors, but will increase s through cumulative effects. t , providing a basis for early warning. Finally, this mechanism can share indirect feedback with the digital twin - when CAPA (corrective and preventive actions) are implemented, the residual distribution will narrow rapidly, μ ε and σ ε Automatically adjust downward to form a closed loop.
[0156] Example: The disposable hemostatic forceps assembly line runs at a rate of 20 pieces per minute. The system sets W = 150 (corresponding to a 7.5-second sampling window) and a threshold value τ = 2.5. During the morning shift, the viscosity of the lubricating oil decreases due to the room temperature, causing the assembly torque to slowly increase. t The value increased from 0.015 to 0.027 within 120 seconds. The window mean and standard deviation were 0.012 and 0.006, respectively. Therefore, the normalized score increased from 0.5 to 2.5, triggering an anomaly. The convolution-diffusion link recognized the "torque is too high" semantics within 180 milliseconds. The MES immediately issued a temperature control increment command, and the torque distribution fell back. ε and σ ε The force is then adjusted downwards to avoid repeated alarms during the night shift. If a fixed threshold of 0.03 N·m is used, the alarm will not be triggered until the deviation becomes more severe, and hundreds of defective products may have been assembled.
[0157] In the zero-knowledge chain writing phase, the system only hashes the defect fingerprint H d and zero-knowledge proof π tBy storing data in a hypergraph causal ledger indexed by a quantum public key, cloud-based or third-party auditors can verify the authenticity of events without accessing production details. This is crucial for complying with medical device regulations, which require the preservation of a complete quality track without disclosing commercial secrets.
[0158] Through the three steps of "sliding normalized residual → deep holographic diffusion → zero-knowledge evidence", the present invention organically couples statistical monitoring, pattern reconstruction and compliance writing chain to construct a highly sensitive, low false alarm and auditable online quality perception hub, providing real-time decision-making basis for medical device monitoring and management throughout manufacturing, use and maintenance.
[0159] Preferably, the vector holographic convolution is realized by performing cyclic shift and bitwise XOR operation on the binary light domain supervector, and the diffusion generation operation gradually denoises the light domain supervector through multi-level noise scheduling to obtain the ideal light domain supervector.
[0160] In the fabrication of embedded feature sequences, the optical domain supervector m t The instantaneous phase response of a quantum dot metasurface on a medical device to a coherent light wavefront was recorded. Because machining errors often manifest as slight phase shifts in a single channel, direct comparison of Hamming distances only detects amplitude flips while ignoring phase shifts. This method first applies a cyclic shift—a bitwise XOR combination—to binary supervectors at consecutive moments, constructing a time-domain vector holographic convolution difference. This diffuses local phase shifts into global bit flips, significantly amplifying the separability of defect signals in high-dimensional space.
[0161] Let m t ∈{-1,+1} 1024 represents the light domain supervector collected at time t, m t-1 Indicates the vector at the previous moment, Shift(m t-1 ,r) is a right shift operation of r bits, r is locked by a pseudo-random sequence to ensure that the convolution path of each device is consistent. The holographic convolution difference is defined as:
[0162] h t =XOR(m t ,Shift(m t-1 ,r))
[0163] The symbol XOR represents bitwise exclusive OR. t Represents the current light domain supervector; m t-1 represents the light domain supervector at the previous moment; r represents the fixed shift amount; h t Represents the holographic convolution difference vector (length 1024).
[0164] The cyclic shift causes the previously localized phase misalignment to be projected to multiple locations along the entire vector after XOR. If the defect is at the tail of a high-dimensional vector and the prediction is at the head, the shift can align the two, making the XOR output 1. Experiments show that when retesting the same device, h t The mean Hamming weight is less than 20, but it can rise to 120 when a 30nm crack appears in the titanium coating, which is four times more resolvable than traditional direct differential.
[0165] In obtaining h t Finally, the system restores the "ideal" optical domain supervector through a multi-level noise scheduling diffusion network. The idea of diffusion denoising comes from the thermodynamic random process: first, Gaussian noise is injected into the observation vector in stages, and then the network is trained to gradually denoise the inverse process, so as to learn the probability flow of the vector distribution. The present invention adopts an eight-level linear noise schedule, with the noise variance β at each level i follow:
[0166]
[0167] Where T = 8 represents the number of diffusion steps. The network structure is a single-channel U-Net-Lite with 1.1M parameters, which can process a thousand-dimensional binary vector within 0.5ms on the cloud-side GPU. Denoised output Approximate the optical domain response that the device should exhibit in the absence of random noise. The final residual vector:
[0168]
[0169] It contains two types of information: phase anomaly caused by processing defects and process load coupling anomaly. t In comparison, r t Speckle noise and systematic displacement errors are suppressed, allowing the subsequent supervector converter to focus on the pattern differences that truly affect quality.
[0170] r t After being concatenated with the synchronous process differential vector, it is fed into a six-layer multi-head self-attention network, which outputs a semantic label and confidence level for the defect. Zero-knowledge commitments are then written into the ledger using the quantum public key index. This link enables immediate identification of the cause of machining errors while they are still at the microscopic stage, and protects sensitive process data from being leaked through non-interactive zero-knowledge proofs.
[0171] Effect verification: A ±5°C random temperature drift was introduced into the hot pressing station of the ear tube, and the system observed t The average Hamming weight increases from 18 to 53. After diffusion denoising, ||r t ||1 increases by 3.8 times. Traditional direct threshold methods require waiting for visible deformation due to temperature drift before issuing an alarm, resulting in a delay of approximately 12 minutes. The link in this invention has an average response delay of 220ms, enabling potential risks to be detected and PID curves to be corrected 11 minutes in advance.
[0172] By amplifying the signal through holographic convolution of binary cyclic shift XOR and combining it with multi-level diffusion denoising to accurately extract anomalies, the present invention achieves ultra-early, low-latency, and highly robust detection of the surface and process status of medical devices. At the same time, combined with zero-knowledge evidence, it provides a reliable and privacy-friendly defect semantic flow for full life cycle monitoring.
[0173] Preferably, the hypergraph causal ledger constructs a three-part hypergraph structure with the quantum public key as the root node, and uses a zero-knowledge proof protocol to verify the integrity and confidentiality of the defect semantic data before writing the defect semantic data.
[0174] Medical devices generate multi-source heterogeneous data throughout their life cycle: design gene data formed by design frozen nodes, manufacturing embedded feature data generated in the manufacturing stage, and defect semantic data output by the anomaly detection link. If written in a linear blockchain sequence, the causal dependencies between each type of data can only be recorded with additional indexes. When querying, the table must be returned to rebuild the path, and the computational complexity increases linearly with the chain length. The present invention proposes a hypergraph causal ledger (HCL), which uses a three-part hypergraph to naturally represent the many-to-many relationship between the three types of nodes of "design-manufacturing-defect", and uses the device quantum public key as the root node to solidify all subsequent events into the same topological subgraph, which not only ensures query efficiency, but also can run causal inference algorithms directly on the graph structure.
[0175] The HCL defines three non-overlapping vertex sets:
[0176] V design ,V manufacture ,V defect
[0177] Design Vertex V d ∈v design Corresponding to the design gene data hash of a single device; manufacturing vertex v m ∈V manufacture Corresponding to the manufacturing process hash at a certain timestamp; defect vertex v c ∈V defect The hash fingerprint corresponding to the defect semantic data.
[0178] Each hyperedge e= <v d ,v m ,v c >Simultaneously connect three types of vertices to form a ternary association. Since the tripartite hypergraph allows multiple manufacturing nodes to be connected to a defect node, and also allows multiple defect nodes to point to the same design vertex, it naturally fits the "multiple process acquisitions for the same device - multiple anomaly detection" scenario. Quantum public key K pubAs the root key, it is recorded in the top-level index table of the chain. All vertex hashes are stored in the memory MerkleTrie as K pub As a prefix, the query complexity of a single device is guaranteed to be logarithmic.
[0179] Chain writing process and zero-knowledge proof, defect semantic data D t It may contain sensitive process terms and workstation numbers. In order to allow external regulators to verify its existence without leaking details, the system uses the Bulletproofs-Plus protocol to generate zero-knowledge commitments. Specific steps:
[0180] Calculate defect fingerprint:
[0181] H c =SHA256(D t )
[0182] SHA256 is a 256-bit hash function, H c Defective vertex identification.
[0183] Use the device quantum private key K pri For H c Generate a promise:
[0184] π t =BP(K pri ,H c )
[0185] Where BP represents the Bulletproofs-Plus generation algorithm, and outputs π t The length is about 4KB, and only statistical dimension and range information is exposed.
[0186] Will <H c ,π t >with the current vertex hash H m And the device design vertex hash H d Assemble into a hyperedge and call the HCL insertion interface:
[0187] insertEdge(K pub ,H d ,H m ,H c ,π t )
[0188] On-chain validators can use Verify(K pub ,H c ,π t )=true determines that the defect record is valid, but cannot infer D t The specific content complies with the regulatory requirements for the protection of confidential medical device processes.
[0189] Causal inference and query efficiency: Traditional blockchain queries such as "Which processes did a certain defect originate from?" require traversing all blocks and matching foreign keys. HCL directly runs a hypergraph attention network and neural relationship inference model on the three-part hypergraph.
[0190] The three types of vertices are embedded in a 128-dimensional Euclidean space, and the edge weights are initialized as a function of time difference and process similarity.
[0191] Adaptively learn edge weights through hypergraph attention layers;
[0192] The neural relationship inference algorithm is executed in the embedding space to output the potential causal subgraph and obtain the association probability between the work station number, material batch number and defect semantics.
[0193] Because the query subgraph is much smaller than the full chain, model inference time remains in milliseconds, with no impact on real-time CAPA processes. The top-of-ledger index, K, public key -> design hash -> defect hash, requires only three hops, allowing operators or regulators to quickly retrieve the entire device's history. If a device is disassembled and reassembled, the original design information can still be traced on-chain, as the defect vertex points to the original design hash, preventing the mixing of gray market parts.
[0194] Through the present invention, for the same defect, it can be d ·E m ) complexity to output all possible root causes; traditional relational storage requires O(n 2 ) Cascade query. Zero-knowledge commitments protect defect semantics, meet the MDR (EU Medical Device Regulation) requirements for encrypted storage of manufacturing secrets, and support third-party audits. The three-part hypergraph is stored in a node-sharded manner, significantly reducing the latency of new block verification. Quantitative testing shows that the CPU usage of chain nodes is less than 40% at 4,000 writes per second. Before each defect is written, the public-private key pair and the validity of the commitment must be verified to prevent malicious manufacturing nodes from forging or repeatedly reporting defect samples, ensuring a closed CAPA loop.
[0195] In the embodiment, in a heart valve stent production line, a batch of scattered optical residual anomalies occurred. The system writes the defect fingerprint H c Within two hours of the commitment, a quality engineer conducted a causal edge analysis on HCL and determined that the defect had a causal edge weight of 0.87 for the "electropolishing flow deviation" workstation and a causal edge weight of 0.31 for "excessive pickling time." After on-site calibration of the electropolishing valve assembly, the same defect did not recur in the subsequent ten batches of products. The entire analysis process did not involve the use of raw scatter vectors or specific hypervector data, and the authenticity of the commitment can be verified by a third-party audit.
[0196] The hypergraph attention network and neural relationship inference model are periodically called to perform causal analysis on the three-part hypergraph composed of the design gene data, manufacturing process data and defect semantic data, generate corrective and preventive data, write it back to the manufacturing execution system and write it into the hypergraph causal ledger to achieve quality closed loop, business decision-making and regulatory delivery.
[0197] Periodic causal analysis is the final step in the closed-loop quality management process. During the manufacturing phase, the digital twin continuously writes three types of nodes to the hypergraph causal ledger: design gene nodes record dimensions, tolerances, and material source data; manufacturing process nodes record the hash of embedded manufacturing features for each step; and defect semantic nodes record anomaly labels confirmed by zero-knowledge commitment. Once the ledger is constructed as a three-part hypergraph rooted in the quantum public key, unified reasoning can be performed on the multi-hop design-manufacturing-defect relationships generated by the same medical device. Reasoning tasks are scheduled every 24 hours and completed in three phases: hypergraph attention feature extraction, neural relationship inference, and corrective-preventive generation.
[0198] Phase 1: Hypergraph attention feature extraction. The system constructs a sparse adjacency tensor for the three-part hypergraph and records the design nodes as a set V d , the manufacturing node is recorded as V m , the defective node is denoted as V c The graph attention layer is used to calculate the triple hyperedge <v d ,v m ,v c >Calculate attention weights:
[0199]
[0200] where h d ,h m ,h c is the initial node embedding, W is the linear mapping matrix, a is the trainable vector, and σ is the LeakyReLU. This illustrates the core computation; the meanings of the letters are given in the formula. Multi-head attention couples design attributes (e.g., material grade) and manufacturing loads (e.g., temperature time series) at different scales into a semantically rich node representation, facilitating subsequent causal direction determination.
[0201] Phase 2: Neural Relationship Inference. The improved NOTEARS-NRI network feeds the weighted adjacency tensor into a differentiable operator, directly optimizing the acyclic constraints and outputting the causal direction matrix R. To avoid overfitting, the loss function adds a "regulatory consistency regularization term" in addition to the structural risk, using known necessary causal factors in regulations (such as the strong correlation between implantable materials and surface roughness) to softly constrain the network output. After the iteration, the system extracts a set of root causes based on a confidence threshold of 0.85. Each root cause entry includes the workstation number, material batch number, and weighted confidence level of the environmental factor.
[0202] Phase 3: Corrective-Preventive Action Generation. The system searches for matching entries in the CAPA (Corrective And Preventive Action) template library. For example, if the root cause set points to "low electropolishing flow rate," the template library returns two measures: "adjust the flow control valve threshold" and "increase online flow monitoring." The generated corrective-preventive data, along with implementation milestones, is packaged and distributed to the corresponding workstations via the Manufacturing Execution System (MES) REST interface. After execution, the MES writes back the actual adjustment parameters and timestamp, forming a closed-loop evidence loop. The CAPA data is also signed and hashed and written to the Hypergraph ledger, becoming the prior for the next round of reasoning.
[0203] The direct effect of a closed-loop quality system is adaptive convergence in the manufacturing process. When CAPA is incorporated into the production recipe, the hypergraph's attention weights automatically weaken old defect edges, and during the next training phase, NRI shifts its root cause attention to new weak links, creating a rolling iteration. Indirect effects are reflected at both the operational and regulatory levels. Operational decision-makers use accumulated CAPA statistics to drive capacity reallocation or spare parts procurement. Regulatory compliance teams can directly reference CAPA records and defect closure rates in the ledger when generating the annual performance review report (PSUR), eliminating the need for manual compilation.
[0204] Preferably, the periodic call executes the hypergraph neural network and neural relationship inference model at fixed time intervals, and the generated correction and prevention data is used to adjust the assembly torque setting value and heating temperature setting value in the manufacturing execution system, and the hash value of the correction and prevention data is written into the hypergraph causal ledger.
[0205] The scheduler uses the quantum public key as a key to read the newly added design nodes, manufacturing nodes, and defective nodes in the most recent cycle. The node embeddings are processed by a hypergraph attention network (HG-GAT) to obtain a 128-dimensional vector representation that reflects the changes in edge weights.
[0206] The neural relationship inference model (improved NOTEARS-NRI) outputs a causal direction matrix while maintaining the acyclic constraint. When the causal weight of a manufacturing node pointing to a defect node is greater than 0.85, it is considered the primary root cause of the current batch.
[0207] The root-cause manufacturing node embedding and the corresponding defect node embedding are projected into the process parameter space to obtain the correction value Δτ for the assembly torque and ΔT for the heating temperature. For example, the recommended torque value is approximately 0.18 N·m lower than the original setting, and the recommended temperature value is approximately 3.4°C higher than the original setting. Following the Manufacturing Execution System (MES) interface specifications, the system generates a parameter package containing the workstation number, two new setpoints, and causal weighting instructions.
[0208] The new torque setting of 2.82 N·m and the new temperature setting of 153.4°C are immediately issued through the MES workstation parameter write interface, taking effect on the next shift. Upon completion, the MES returns a confirmation receipt and the actual execution time.
[0209] Assemble the parameter package and receipt into a string and calculate the SHA-256 hash value H CAPA . Use the quantum private key corresponding to the device to create a zero-knowledge commitment and use the quantum public key, H CAPA 〉Write the hypergraph causal ledger for the vertex, and establish a ternary hyperedge with the triggering defect node to form a traceable quality closed-loop record.
[0210] After the above adjustments, the defect rate of "high torque" in subsequent products of the same batch dropped from 1.5% to 0.2%. The auditors conducted random inspections two weeks later and automatically retrieved the stored hash H through the quantum public key index. CAPA and compare it with the actual parameter package in the MES log. If they match, it proves that the record has not been tampered with.
[0211] Through the four-step process of "periodic scheduling - causal inference - parameter distribution - hash evidence storage", the present invention continuously connects design, manufacturing and defect information into a highly reliable closed-loop data chain without leaking any process details, while taking into account production efficiency, business decision-making and regulatory compliance requirements.
[0212] like Figure 4 As shown, a medical device monitoring system is used to implement the method described above, the system comprising:
[0213] The gene writing module is used to generate designed gene data including model code, physical unclonable fingerprint and quantum public key at the design freezing node, and write the designed gene data into the Twin-DNA chip to establish the unique identification of the medical device; it consists of an integrated laser speckle acquisition head, a quantum random number board and a fuse writing core tooling, and collects the fingerprint of the device surface, generates quantum public and private keys and burns the designed gene data into the Twin-DNA chip at the design station at one time.
[0214] The manufacturing acquisition module is used to collect process parameters and scattered optical data during the manufacturing stage, construct a light domain supervector based on the scattered optical data, splice the light domain supervector with the process embedded features obtained from the process parameters to form manufacturing embedded feature data, and send the manufacturing embedded feature data to the corresponding digital twin to update the medical device management status; the edge box installed next to the assembly line contains a multi-channel sensing ADC, a quantum dot metasurface spectral probe and a SoCFPGA, which can synchronously capture process parameters such as torque-temperature and 64-way scattered spectra, generate light domain supervectors on site and send them to the cloud in encrypted form.
[0215] The abnormal reasoning module is used to calculate the residual of the manufacturing embedded feature data and the predicted feature by the digital twin, and when the residual reaches a threshold, perform vector holographic convolution and diffusion generation operations to obtain a residual vector, input the residual vector into the supervector transformer to obtain defect semantic data, and write the defect semantic data into the hypergraph causal classification ledger indexed by the quantum public key in a zero-knowledge manner; deployed on the cloud-side GPU-FPGA server, first use the timing model to calculate the residual, then use hardware XOR to implement holographic convolution, use a small diffusion network for denoising and reconstruction, output the defect semantics and write it into the hypergraph ledger through zero-knowledge commitment.
[0216] The causal closed loop module is designed to periodically invoke the hypergraph attention network and neural relationship inference model to perform causal analysis on the three-part hypergraph composed of design genetic data, manufacturing process data, and defect semantic data. This module generates corrective and preventative data, which is then written back to the manufacturing execution system and into the hypergraph causal ledger to achieve a closed quality loop, operational decision-making, and regulatory compliance. Running on a cluster of graph databases and GNN accelerator cards, it regularly performs causal inference on the three-part hypergraph, generating correction values for torque, temperature, and other parameters, and pushes them to the MES. After execution, the MES sends a hashed write chain, forming a traceable quality closed loop.
[0217] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware.
[0218] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included within the scope of the claims of the present application.
Claims
1. A method for monitoring a medical device, characterized in that: The following steps are involved: Generate design genetic data including model code, physical unclonable fingerprint and quantum public key at the design freeze node, and write it into the Twin-DNA chip to establish the unique identification of the device; During the manufacturing phase, process parameters and scattered optical data are collected, and a light domain supervector is constructed based on the scattered optical data. The light domain supervector is then concatenated with the process embedded features derived from the process parameters to form manufacturing embedded feature data, which is then sent to the corresponding digital twin to update the device management status. The digital twin calculates the residual between the embedded feature data and the predicted feature. If the residual reaches a threshold, vector holographic convolution and diffusion generation operations are performed to obtain the residual vector, which is input into the supervector transformer to obtain the defect semantic data and written into the hypergraph causal ledger indexed by the quantum public key in a zero-knowledge manner. The hypergraph attention network and neural relationship inference model are periodically called to perform causal analysis on the three-part hypergraph composed of the design gene data, manufacturing process data and defect semantic data, generate corrective and preventive data, write it back to the manufacturing execution system and write it into the hypergraph causal ledger to achieve quality closed loop, business decision-making and regulatory delivery.
2. The method according to claim 1, characterized in that The designed gene data further includes a quantum private key and a hash value calculated from a tolerance mapping matrix of a three-dimensional design model, and the quantum private key and the hash value are written into a write-only storage area of the Twin-DNA chip.
3. The method according to claim 2, characterized in that The physical unclonable fingerprint generates a grayscale speckle matrix by irradiating a key surface of a medical device with coherent light and collecting an interference speckle image, and stores the grayscale speckle matrix together with the designed gene data.
4. The method according to claim 1, wherein The scattered optical data is composed of a scattered wave vector sequence collected synchronously by multiple spectral channels. The scattered wave vector sequence is calculated through optical domain phase shift to obtain an optical domain super vector, and the optical domain super vector is spliced with the process embedded feature.
5. The method according to claim 2, characterized in that The manufacturing embedded characteristic data is encrypted by a block encryption algorithm before being sent, and an integrity check mark is added. The integrity check mark is transmitted together with the manufacturing embedded characteristic data.
6. The method according to claim 2, characterized in that The residual is obtained by calculating the Euclidean distance between the embedded feature data and the corresponding predicted feature, and the Euclidean distance is statistically normalized with the residual mean and standard deviation of the recent sliding window. When the normalization result exceeds the preset threshold, the vector holographic convolution and diffusion generation operation is triggered.
7. The method according to claim 6, characterized in that The vector holographic convolution is achieved by performing cyclic shift and bitwise XOR operations on the binary light domain supervector, and the diffusion generation operation gradually denoises the light domain supervector through multi-level noise scheduling to obtain an ideal light domain supervector.
8. The method according to claim 1, characterized in that The hypergraph causal ledger constructs a three-part hypergraph structure with the quantum public key as the root node, and uses a zero-knowledge proof protocol to verify the integrity and confidentiality of the defect semantic data before writing it.
9. The method according to claim 8, characterized in that The periodic call executes the hypergraph neural network and neural relationship inference model at fixed time intervals, and the generated correction and prevention data is used to adjust the assembly torque setting value and heating temperature setting value in the manufacturing execution system, and the hash value of the correction and prevention data is written into the hypergraph causal ledger.
10. A medical device monitoring system, used to implement the method according to any one of claims 1 to 9, characterized in that: The system includes: A gene writing module is used to generate designed gene data including a model code, a physical unclonable fingerprint, and a quantum public key at a design freezing node, and write the designed gene data into a Twin-DNA chip to establish a unique identification for the medical device; A manufacturing acquisition module is used to collect process parameters and scattered optical data during the manufacturing stage, construct a light domain supervector based on the scattered optical data, concatenate the light domain supervector with the process embedded features obtained from the process parameters to form manufacturing embedded feature data, and send the manufacturing embedded feature data to the corresponding digital twin to update the medical device management status; An abnormal reasoning module is used to calculate the residual between the manufacturing embedded feature data and the predicted feature by the digital twin, perform vector holographic convolution and diffusion generation operations to obtain a residual vector when the residual reaches a threshold, input the residual vector into the supervector transformer to obtain defect semantic data, and write the defect semantic data into a hypergraph causal ledger indexed by the quantum public key in a zero-knowledge manner; The causal closed loop module is used to call the hypergraph attention network and the neural relationship inference model according to a set cycle, perform causal analysis on the three-part hypergraph composed of the design gene data, manufacturing process data and defect semantic data, generate corrective and preventive data, write the corrective and preventive data back to the manufacturing execution system and write it into the hypergraph causal ledger to achieve quality closed loop, operational decision-making and regulatory delivery.
Citation Information
Cited By
Network security inspection system based on big data
CN121239435A