Method and apparatus for transmitting a system identifier and method for operating with an authorization component
By introducing tamper-proof circuitry into the system to detect and disable the functions of removed components, the system performance and security issues caused by the replacement of third-party components were resolved, ensuring system integrity and patient safety, and protecting the interests of the OEM.
Patent Information
- Application Number
- CN202010245574.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-03-05
- Filing Date
- 2019-08-27
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2039-08-27
AI Technical Summary
In the prior art, third-party suppliers may replace or install incompatible components, leading to system performance problems and potential security risks, especially in computed tomography (CT) and X-ray systems, where old or damaged components cannot be identified or repaired after installation, affecting system functionality and image quality.
The system incorporates anti-tampering circuitry to detect the installation status of components through mechanical, electrical, or magnetic coupling. If a component is removed, the anti-tampering circuitry disables related functions, such as erasing memory data or activating a fuse to deactivate the circuit, ensuring that components can only be used under authorized conditions.
It effectively prevents the installation of incompatible components, ensures the integrity of system functions and image quality, reduces the risk of misdiagnosis, protects patient safety, and safeguards the OEM's service contract revenue.
Smart Images

Figure CN112115526B_ABST
Abstract
Description
[0001] This application is a Continuation-In-Part of International Application No. PCT / US2019 / 048258, International Filing Date 27-Aug-2019, entered into the National Stage in China on 07-Jan-2020, Chinese National Application No. 201980003466.8, entitled “Tamper-Resistant Circuit” and having a filing date of 27-Aug-2019. BACKGROUND
[0002] Systems can be formed from a variety of different devices. Manufacturers, system integrators, or the like can design and install a particular system with authorized components. However, third-party vendors can swap devices on similar systems, install used components, or third-party components that can cause performance issues and / or cause damage to components of the system. BRIEF DESCRIPTION OF DRAWINGS
[0003] Figures 1A-1C is a block diagram of a system including a device with a tamper-resistant circuit according to some embodiments.
[0004] Figure 2 is a block diagram of a device with a tamper-resistant circuit according to some embodiments.
[0005] Figures 3A-3C is a block diagram of a circuit of a device with a tamper-resistant circuit according to some embodiments.
[0006] Figures 4A-4B is a cross-sectional view illustrating installation of a device with a tamper-resistant circuit on an external component according to some embodiments.
[0007] Figures 5A-5D is a schematic diagram of a circuit of a tamper-resistant circuit according to some embodiments.
[0008] Figure 6A and Figure 6B is a flowchart illustrating techniques of operating a device with a tamper-resistant circuit according to some embodiments.
[0009] Figure 7 is a block diagram of an x-ray system according to some embodiments.
[0010] Figures 8A-8B is a block diagram of a system including an authorized system according to some embodiments.
[0011] Figures 9A-10C is a flowchart illustrating an example of techniques of operating an authorized system according to some embodiments. DETAILED DESCRIPTION
[0012] Before any embodiments of the application are explained in detail, it is to be understood that the application is not limited in its application to the details of construction and the arrangement of components set forth in the following description or illustrated in the following drawings. The application is capable of other embodiments and of being practiced or of being carried out in various ways. The data provided in the flow diagrams and processes are provided for clarity of explanation only and are not necessarily indicative of a particular order or sequence. Unless otherwise defined, the term "or" can refer to a selection of alternatives (e.g., exclusive OR or XOR) or a combination of alternatives (e.g., the union operator and / or logical OR Boolean OR).
[0013] Some embodiments generally relate to mechanisms, methods, and systems for disabling a component authentication system after removal of a component. Some embodiments generally relate to switches and disabling components and / or circuits.
[0014] Electronic devices can be used in an attempt to block the use of third party components in systems such as computed tomography (CT) and x-ray systems. However, these electronic devices can be removed from systems that include old, broken, junked components such as x-ray tubes. The electronic devices can thus be installed on third party or used tubes for sale for use in original equipment manufacturer (OEM) systems. For example, a third party can acquire an old, used, or broken x-ray tube from which the electronic devices can be removed. The electronic devices can thus be installed on a new, used, or third party tube to enable the tube to mimic a true tube in the system.
[0015] As described herein, the anti-tamper circuitry can not prevent removal of the component or electronic device itself, but can disable at least some or all of the functionality of the device, such as disabling authentication or other functions, deleting configuration information, or the like. As a result, the electronic device can not be able to perform those functions without reprogramming of the device by a manufacturer or authorized service representative. Thus, an unauthorized party can no longer be able to reuse the electronic device and access some or all of the functionality. As will be described in greater detail below, the effects of losing some or all of the functionality can range from a warning message to disabling of the electronic device or system including the electronic device.
[0016] In some implementations, the X-ray tube designed and manufactured by the manufacturer in an X-ray system may include tube-specific information that is used in conjunction with a tube auxiliary unit (TAU) that has appropriate imaging capabilities and does not damage the tube. This tube-specific information may reside in non-volatile random access memory (NVRAM) of the TAU, such as flash memory or solid-state storage. Because some of the information stored in the TAU is tube-specific, if the TAU is swapped to a different tube, the tube-specific information of the TAU will no longer match the specific X-ray tube. If used, this mismatch can lead to image quality problems and / or irreparable X-ray tube damage. Tamper-proof circuitry can reduce or eliminate the chance of swapping TAUs between different X-ray tubes and providing the system with incorrect tube-specific information.
[0017] Figures 1A-1C It is a block diagram of a system including a device with tamper-proof circuitry according to some implementation schemes. Figure 2 It is a block diagram of a device with tamper-proof circuitry according to some implementation schemes.
[0018] refer to Figure 1A and Figure 2 System 100a includes a device 102 configured to be mounted on an external component 104. Device 102 includes tamper-proof circuitry 110 and circuitry 112.
[0019] Examples of device 102 include a device having circuitry 112, which may include custom components, firmware, software, data, or the like. The firmware or software may include instructions that utilize additional circuitry 122 or 120 of external component 104 to implement proprietary communication and / or control technologies. In other embodiments, data may include authentication information, cryptographic information, performance data, or the like. Specific examples of device 102 include authentication circuitry for a system, control circuitry for an X-ray tube, or the like.
[0020] External component 104 may include fully structural components and / or circuitry with certain functional capabilities. For example, in some embodiments, external component 104 is the housing of a system including device 102. Device 102 may be mounted to said housing, and thus to external component 104.
[0021] Device 102 includes a housing 116 configured to restrict access to deequip tamper-proof circuit 110 when device 102 is mounted to external component 104. For example, housing 116 may include a sealed enclosure surrounding tamper-proof circuit 110 and circuit 112. When housing 116 is mounted to external component 104, the combination of housing 116 with external component 104, such as the wall 124 of external component 104, can completely enclose tamper-proof circuit 110 and circuit 112. In some embodiments, the combination can sufficiently enclose tamper-proof circuit 110 and circuit 112 to prevent access to tamper-proof circuit 110 or circuit 112 without significant modification or damage to housing 116. The combination of housing 116 and external component 104 can be configured such that access to tamper-proof circuit 110 or circuit 112 is significantly more difficult than removing device 102 from external component 104.
[0022] Device 102 includes a tamper-proof circuit 110 electrically connected to circuit 112. The tamper-proof circuit 110 is configured to disable at least one function of circuit 112 when device 102 is removed from external component 104. Specifically, the tamper-proof circuit 110 is coupled to external component 104 via coupling 114. This coupling 114 can be mechanical, electrical, optical, magnetic, other similar couplings, or a combination of these couplings. For example, a switch can be toggled when device 102 is mounted on external component 104. Toggling can refer to a transition from an on state to a off state, or from a off state to an on state. The switch can have mechanically or magnetically switchable poles. The state of the switch can change depending on whether device 102 is mounted on external component 104 or whether device 102 is being removed from external component 104. In other embodiments, the switch can change its state when fasteners used to mount device 102 on external component 104 are removed. In other embodiments, the electrical circuit can be established via a portion of external component 104, such as via a metal portion of wall 124. The removal of an external component of device 102 can be detected by a break in the circuit. Although some circuits and structures have been used as examples of configurations in which tamper-proof circuit 110 can be used to sense the removal of device 102 from external component 104, tamper-proof circuit 110 can be used in other ways to sense removal.
[0023] The implementation described herein can be used anywhere that device 102 should remain physically paired to system 100a, external component circuitry 120, other circuitry 122, or another component or device to which said circuitry is mounted and / or associated. Pairing in this sense can mean physical contact with, proximity to, communication with, integration into, or similar to the device.
[0024] In response to the removal of the tamper-proof circuit 110 from the external component 104, the tamper-proof circuit 110 can be configured to disable at least one function of the circuit 112. Specific functions of the circuit 112 may include general processing capabilities, use of specific data, ability to appropriately respond to authentication challenges, or similar functions. In some embodiments, data stored in the circuit 112 may be erased. The data may include password information, authentication information, identification information, operational information, firmware, software, or the like. In some embodiments, the non-volatile memory of the circuit 112 may be erased to disable at least one function. In other embodiments, a fuse affecting the operation of the circuit 112 may be blown to disable at least one function. While some embodiments may disable at least one function, in other embodiments, the tamper-proof circuit 110 may be configured to disable all functions of the circuit 112 or the entire device 102.
[0025] In some implementations, circuit 112 is configured to control the external component. Circuit 112 may be coupled to external component circuitry 120. In a particular example, circuit 112 may include control circuitry for the x-ray tube. External component circuitry 120 may include an anode, cathode, filament, emitter, motor, steering electronics, focusing electronics, or other circuitry that may be part of the x-ray tube.
[0026] In some implementations, other technologies for preventing reuse can be triggered by radio frequency identification (RFID) sensors, optical sensors, proximity sensors, barcode readers, cameras that process serial numbers or other identification features, tripwires, tamper-proof mounting devices, or any combination of these technologies. These technologies can be paired with the capability of at least one function of the deactivation circuit 112 of the tamper-proof circuit 110 as described herein.
[0027] refer to Figure 1B and Figure 2 In some implementations, external component 104 may be another device 106. For example, device 106 may be an interface board configured to provide an interface between the system control component and other components of the system. In a particular instance, device 106 may be an interface board that converts control and / or communication between the system controller for the x-ray system and a specific subsystem, such as an x-ray generation subsystem, power subsystem, detector subsystem, cooling subsystem, user interface subsystem, or the like.
[0028] Device 102 may be an authentication daughter board (ADB) configured to store authentication information, perform authentication functions, negotiate authentication between the system controller and other subsystems of device 106 or system 100b, or perform similar processing.
[0029] refer to Figure 1C In some embodiments, more than one device 102 may be mounted on the external component 104. In this example, N devices 102 are mounted on the external component 104. Devices 102-1 to 102-N may be the same, similar, or different. However, some or all of devices 102-1 to 102-N may include the tamper-proof circuitry 110 described herein.
[0030] In some implementations, the tamper-proof circuit 110 prevents the device 102 from being reused, modified, tampered with, replaced, or reinstalled on third-party components by a third party. As described above, the device 102 may be part of an authentication system. The authentication system may be configured to determine whether a component is a genuine manufacturer or OEM component by sending a cryptographic challenge question to cryptographic electronics on a component in the system. The component in the system may be the device 102, an external component 104, or another component.
[0031] In a particular instance, device 102 may include a cryptographic electronic device as part of circuitry 112. Device 102 includes circuitry controlling external component 104. If the cryptographic electronic device can be removed from the genuine component and installed on a counterfeit component, the authentication system can be defeated. However, tamper-proof circuitry 110 is triggered after device 102 is removed. At least one function of the deactivated circuitry 112 may include authentication functionality, authentication information, or the like. After tamper-proof circuitry 110 is triggered, the cryptographic electronic device will no longer respond appropriately to authentication requests. As a result, system 100 may have an indication that it no longer believes device 102 and / or external component 104 to be a genuine manufacturer or OEM component.
[0032] In some implementations, service contracts can be a significant source of revenue for OEMs. The tamper-proof circuit 110, as described herein, can be used by OEMs to reduce or eliminate the ability of third-party manufacturers or intermediaries to install competing or replacement products or incompatible components that could cause performance and patient safety issues.
[0033] Figures 3A-3CThis is a block diagram of a device with tamper-proof circuitry according to some embodiments. In these embodiments, the circuitry includes an tamper-proof circuitry 110 similar to the tamper-proof circuitry described above, a processor 113, and a memory 118. The processor 113 and the memory 118 are examples of the circuitry 112 described above.
[0034] Processor 113 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a microcontroller, a programmable logic device, a discrete circuit, a combination of these devices, or the like. Processor 113 may include internal portions such as registers, cache memory, volatile memory, non-volatile memory, a processing core, or similar portions, and may also include external interfaces such as address and data bus interfaces, interrupt interfaces, or similar portions. Although only one processor 113 is illustrated, multiple processors 113 may exist. Additionally, other interface devices such as logic chipsets, hubs, memory controllers, communication interfaces, or the like may be included to connect processor 113 to internal and external components.
[0035] Processor 113 is coupled to memory 118. Memory 118 includes data, such as cryptographic information, authentication information, identification information, operational information, firmware, software, or the like as described above. Tamper-proof circuitry 110 is configured to erase at least a portion of memory 118 used by processor 113 when device 102 is removed from external component 104. In some embodiments, erasure may be applied to all such data. In other embodiments, erasure may be applied to a sufficient quantity and quality of data to render device 102 inoperable, such as erasure of secret information, for example, a cryptographic key.
[0036] refer to Figure 3A In some implementations, the processor 113 includes on-chip or otherwise integrated memory 118a. As a result, when the tamper-proof circuitry 110 erases at least a portion of the memory 118a, the erased memory is memory integrated with the processor 113.
[0037] refer to Figure 3BIn some embodiments, tamper-proof circuitry 110 is coupled to processor 113. Processor 113 is coupled to external memory 118b. Tamper-proof circuitry 110 can be configured to boot processor 113 and cause processor 113 to execute commands to erase at least a portion of external memory 118b. For example, tamper-proof circuitry 110 can cause the processor to execute an interrupt service routine to erase a portion of memory 118b. In another instance, tamper-proof circuitry 110 can be configured to boot processor 113 in a mode specifically designed to erase a portion of memory 118b. Although processor 113 is illustrated as being directly coupled to memory 118b, in other embodiments, other intervening circuitry, such as a memory controller, may be present.
[0038] refer to Figure 3C In some implementations, the tamper-proof circuit 110 can be configured to access the memory 118c without accessing the processor 113. Accordingly, the tamper-proof circuit 110 can be configured to erase portions of the memory by controlling the memory 118c.
[0039] Although various configurations of the tamper-proof circuit 110, processor 113, and memory 118 have been described above, in other embodiments, the tamper-proof circuit 110, processor 113, and memory 118 may be coupled in any way such that the tamper-proof circuit 110 can erase portions of the memory 118 used by the processor 113.
[0040] Figures 4A-4B It is a cross-sectional view of a device with tamper-proof circuitry installed on an external component, based on some implementation scheme diagrams. Figure 4A The illustration shows the state of device 102 and external component 104 before device 102 is installed onto external component 104 or after device 102 is removed from external component 104. Figure 4B The diagram shows the state of device 102 and external component 104 when device 102 is installed on external component 104.
[0041] refer to Figure 4A and Figure 4BIn some embodiments, device 102 includes a housing 116. Device 102 includes a switch 220. Switch 220 is coupled to housing 116. Although housing 116 is illustrated as an example of a mounting structure for device 102, in other embodiments, the mounting structure can be a structure other than housing 116. The mounting structure can be any structure, plate, component, or the like that is attached to device 102 as it moves relative to external component 104. The housing includes a flange 212. Fastener 214 can be used to attach housing 116 to wall 124 of external component 104. Although mounting components such as flange 212 and fastener 214 have been used as examples, different mounting techniques may be used in other embodiments.
[0042] Switch 220 is configured to switch when device 102 is removed from external component 104. When device 102 is in... Figure 4A In the state illustrated, switch 220 has pole 222 in the first state. In a particular instance, switch 220 may be a normally closed switch that is momentarily closed. Therefore, in Figure 4A In the state shown in the diagram, switch 220 is closed.
[0043] When device 102 is mounted on external component 104, such as Figure 4B As illustrated, the structure 204 of the external component 104 causes the pole 222 of the switch 220 to switch. Therefore, the switch 220 is turned on.
[0044] In some embodiments, structure 204 is a protrusion, wall, rib, node, fastener, or the like. Structure 204 is mounted on external component 104 such that when device 102 is mounted on external component 104, structure 204 changes the state of switch 220.
[0045] Although the specific structures of device 102, external component 104, and switch 220 have been used as examples, any mechanism and associated structure that places switch 220 in a first state during installation and in a second state during removal can be used. In particular, the mechanism and associated structure can be configured such that switch 220 changes state before it can access tamper-proof circuit 110 to disable tamper-proof circuit 110 or otherwise prevent tamper-proof circuit 112 from disabling at least one function, as described above.
[0046] Furthermore, switch 220 does not need to be switched mechanically. For example, switch 220 can be switched magnetically. Structure 204 may include a magnet or ferromagnetic material depending on the structure of switch 220, so that switch 220 changes state when device 102 is installed on or removed from external component 104.
[0047] Although a single switch 220 has been used as an example, in other embodiments, multiple switches 220 may be used in different locations and / or with different configurations. In some embodiments, any of these switches 220 may be used by the tamper-proof circuit 110 to disable at least one function of the circuit 112.
[0048] Figures 5A-5D This is a schematic diagram of an anti-tampering circuit based on some implementation schemes. (Reference) Figure 5A The tamper-proof circuit 110a includes a power supply 502 and a deactivation circuit 504. The power supply 502 is configured to generate power that can be used by the deactivation circuit 504 and a portion of the possible circuit 112.
[0049] A power supply 502 is housed within device 102. Power supply 502 is configured to provide power upon detection of device 102's removal from external component 104. Power supply 502 may include a battery, capacitor, supercapacitor, or any other energy storage device that may be housed within device 102. In some embodiments, power supply 502 may be charged by an external power source 506.
[0050] In some implementations, the power supply 502 may include a switch that connects the power supply 502 to other components of the tamper-proof circuit 110 when the device 102 is removed from the external component 104.
[0051] The deactivation circuit 504 is a circuit configured to deactivate at least one function of the circuit 112. In this example, the deactivation circuit 504 includes an erase output. The erase output is a signal coupled to an erase input on the processor, memory, or the like of the circuit 112, which may initiate an erase command for erasing memory or otherwise deactivating at least one function.
[0052] In some implementations, the power supply (PWR) may also be provided to some components of circuit 112. Specifically, device 102 may not be connected to an external power source, or the external power source may be disabled while device 102 is being removed from external component 104. Power supply 502 may be modified to supply the power required to allow circuit 504 to disable at least one function of circuit 112.
[0053] refer to Figure 5BThe tamper-proof circuit 110b includes a battery B1 and a switch SW1. A single battery B1 is illustrated; however, multiple batteries may be used in other embodiments. Switch SW1 is a double-pole double-throw (DPDT) switch. Switch SW1 is coupled such that, in the illustrated configuration, 3.3V is coupled to VDD_CPU, and no connection to ERASE_CPU is formed. In another configuration, VDD_CPU and ERASE_CPU are coupled to battery B1.
[0054] VDD_CPU is the processor's power supply, which may be part of circuit 112. ERASE_CPU is a signal that commands the processor of circuit 112 to erase some or all of its memory. As a result, at least one function of circuit 112 can be disabled. Switch SW1 is illustrated in the state when the corresponding device 102 is mounted on external component 104. When removed, switch SW1 will transition to another state in which the switch supplies power to the processor via VDD_CPU and supplies the erase signal via ERASE_CPU.
[0055] Isolator I is a movable structure configured to disconnect battery B1 from the switch. When in place, battery B1 is disconnected and will not supply power to switch SW1. Therefore, ERASE_CPU will not start. Isolator I can be in place during installation to disable the tamper-proof circuit 110b.
[0056] The other circuits illustrated can provide a status indicator for multiple states. R1 is coupled to VDD_CPU and pulls its input down to AND gate U1. Another input to AND gate U1 is the error signal ERROR_N. When device 102 is being installed and 3.3V power is applied, switch SW1 will be in the opposite state. However, due to the presence of isolator I, the battery will not activate ERASE_CPU. VDD_CPU will not be coupled to 3.3V and will be pulled down by R1. Therefore, the output of AND gate U1 will be low, thus turning on LED D1. Once device 102 is properly installed, switch SW1 changes to the illustrated state, and VDD_CPU will be set to 3.3V. The output of AND gate U1 will switch high, assuming there is no error indicated by the low ERROR_N. The high output will turn off LED D1. As a result, the installer will receive a visual indication that device 102 has been installed such that switch SW1 is in the illustrated state.
[0057] After installation, isolator I can be removed. ERROR_N will control whether the output of AND gate U1 and LED D1 are turned on. Therefore, LED D1 will act as an error indicator. However, if device 102 is removed, switch SW1 will change state, thereby activating VDD_CPU and ERASE_CPU.
[0058] In one example, the SW1 switch is a normally closed (NC) double-pole double-throw (DPDT) switch, wherein the closed state couples the battery B1 to the ERASE_CPU. The switch is capable of being normally closed (NC) and opening when the switch is pressed, for example, when device 102 is installed and a feature of external component 104 is pressed against the switch.
[0059] refer to Figure 5C The operation can be similar to Figure 5B The operation is as follows. However, VCC_INSTALL is the power voltage supplied during installation, which may be invalid when 3.3V is not available. For VCC_INSTALL or 3.3V, resistors R3 and R4 are connected in series with LED D2. Therefore, LED D2 will turn on when the cathode of LED D2 is pulled low. Buffer U2 is an open-drain buffer. Inverter U3 is an open-drain inverter. Therefore, LED D2 will turn on if the input to U2 is low or if the input to U3 is high.
[0060] When the switch is in the mounted state, ERASE_CPU and the node coupled to resistors R5, R6, R7, and Q1 are pulled to ground, and transistor Q1 is turned off. However, once device 102 is removed from external component 104, switch SW1 changes state, causing the voltage at node N1 to increase and ERASE_CPU to pulse until C1 is charged. R5 and C1 are selected to provide sufficient pulses to erase a portion of the memory to disable at least one function.
[0061] refer to Figure 5D The operation of U2, U3, resistors R8, R9 and R10, diodes D3 and D4, and LED D5 can be similar to Figure 5C The operation is as follows. Here, diodes D3 and D4 can isolate VCC_INSTALL from 3.3V. The operation of the tamper-proof circuit 110d can be similar to... Figure 5C The tamper-proof circuit 110c has an error.
[0062] Although 3.3V has been used as an example of the supply voltage, the supply voltage may be different in other implementations.
[0063] Figure 6A and Figure 6B This is a flowchart illustrating the technology of operating a device with tamper-proof circuitry according to some embodiments. (Reference) Figure 6A In step 604, the removal of device 102 from external component 104 is detected. As described above, various techniques can be used to detect the removal of device 102. For example, a change in the state of a switch, a change in the magnetic field, a break in a circuit, or similar conditions can provide an indication of whether device 102 is being removed from external component 104.
[0064] In 606, at least one function of device 102 is disabled. As described above, at least one function can be disabled by erasing data, disconnecting components such as processors, or similar operations. Various forms of tamper-proof circuitry 110 can be used to perform the disabling.
[0065] In some implementations, the removal of the detection device 102 may include the physical separation of the structure of the detection device 102 from the structure of the external component 104. For example, the switch 220 may detect when the device 102 moves relative to the external component 104.
[0066] refer to Figure 6B In step 600, device 102 is mounted on external component 104. For example, device 102 can be prepared and mounted on external component 104 during authorized installation, partial replacement, and / or system maintenance. During installation, tamper-proof circuit 110 can be de-equipped. For example, as described above, a movable isolator I, such as an insulating strip, can be placed between the contacts of power supply 502 and deactivation circuit 504.
[0067] In step 602, the tamper-proof circuit 110 can be equipped. For example, once the device 102 is installed, the insulating tape can be removed to equip the tamper-proof circuit 110. Before removing the insulating tape, the device 102 can be repeatedly installed and removed without engaging the tamper-proof circuit 110. However, once removed, the tamper-proof circuit 110 is equipped, and in operations 604 and 606, any attempt to remove the device 102 from the external component 104 can be detected and used to disable at least the on function of the circuit 112 of the device 102.
[0068] Once the tamper-proof circuit 110 has been triggered and at least one function of circuit 112 has been disabled, in step 608, device 102 can be reset. Resetting device 102 includes operations that return device 102 to a state where the device can be re-installed or operated in an authorized manner. For example, device 102 can be returned to an authorized repair facility. Eroded data can be restored to device 102, disabled components can be reactivated, disabled components can be replaced, the aforementioned isolator I can be reinstalled, or similar operations can be performed to place device 102 in a state similar to that of device 102 where at least one function of circuit 112 has not been disabled. Although returning device 102 to an authorized repair facility has been used as an example, the reset of device 102 can be performed by an authorized repair technician using appropriate data and / or components. An unauthorized party may not have the appropriate data and / or components and may not be able to restore device 102 to its operating condition.
[0069] Figure 7 This is a block diagram of an x-ray system according to some implementation schemes. The x-ray system 700 includes a main controller 702, an interface board (IFB) 704, a tube auxiliary unit (TAU) 732, and an x-ray tube 736. These components can be mounted on a rotatable frame 710.
[0070] In some embodiments, device 102 is or a part of IFB 704. External component 104 may be rack 710. Therefore, if IFB 704 is removed from the rack, at least one function of IFB 704 can be disabled if the interface board is removed from rack 710. IFB 704 may include firmware, software, calibration data, secret information such as keys, IDs or other cryptographic information, or the like that can be erased to disable at least one function.
[0071] In some embodiments, device 102 is an identification subboard (ADB) 703 mounted on IFB 704. External component 104 may be IFB 704. If ADB 703 is removed from IFB 704, information such as that described above can be erased.
[0072] In some embodiments, device 102 is a TAU 732. The TAU 732 may be mounted on an x-ray tube 736. External component 104 may be the x-ray tube 736. Therefore, if the TAU 732 is removed from the x-ray tube 736, at least its on / off function can be disabled. The TAU 732 may include erasable data or firmware similar to IFB 704 or ADB 703.
[0073] In some implementations, the host controller 702 is configured to control the operation of components such as rack 710, IFB 704, and x-ray tube 736 via TAU 732. Although these components are used as examples, other components may be present, such as image detectors, high-voltage (HV) generators, heat exchangers, or similar devices. The host controller 702 may also be configured to communicate with IFB 704 and perform various actions other than controlling the boot system 700, such as identification, authentication, or similar actions.
[0074] As described above, in some implementations, the IFB 704 includes an ADB 703. This configuration allows for easier retrofitting of the ADB 703 to fit existing CT systems. The IFB 704 has a communication link to the host controller 702 and another communication link to the TAU 732. The ADB 703 contains cryptographic authentication hardware / firmware that allows encrypted communication with both the host controller 702 and the TAU 732. The IFB 704 is a means of maintaining and powering the ADB 703 and translating communications to the ADB 703's native communication protocol.
[0075] The TAU 732 contains cryptographic authentication hardware / firmware that allows encrypted communication with the IFB 704 / ADB 703 and is attached to the X-ray tube 736. When a hospital installs a new X-ray tube with the TAU 732 attached, the IFB 704 / ADB 703 can challenge the TAU 732 to verify whether it is a genuine manufacturer or OEM X-ray tube.
[0076] In some embodiments, the authentication unit of TAU 732 is mounted to the x-ray tube 736, but the authentication unit may also be a part of the main body of the x-ray tube 736. The tamper-proof circuitry 110 may be part of the authentication unit. Similarly, other components of the device 102 may be included where it may be beneficial to render the device unusable after it has been removed from its initial mounting position, such as x-ray detectors or imagers, accelerators, or other devices. Each of these devices may have an associated tamper-proof circuitry 110.
[0077] In one particular instance, it is possible to prevent the removal of used X-ray tubes, X-ray detectors, or imagers from an X-ray or mammography system for resale to another system. After device 102 is removed, a switch in tamper-proof circuitry 110 can be triggered, and authentication functions can be disabled, firmware rendered unusable, communication blocked, or any other essential functions that would allow further use of device 102.
[0078] In some embodiments, the tamper-proof circuitry 110 can also be used to enhance the software / firmware (SW / FW) license of the TAU 732, X-ray tube 736, detector, or other device software sold to a specific customer, according to a licensing agreement that would only allow the original purchaser to utilize the firmware / software (FW / SW) or hardware. In this embodiment, the corresponding FW / SW can be automatically erased when the device is removed.
[0079] Although a CT system with a rotatable gantry 710 has been used as an example of an x-ray system 700, the x-ray system 700 may take other forms.
[0080] Some implementations typically involve mechanisms, methods, and systems that use encrypted system identifiers (IDs) (or device IDs) for components.
[0081] In some implementations, the mechanisms, methods, and systems described herein allow manufacturers or OEMs to detect unauthorized installations of components into their systems. Currently, third-party vendors are able to replace components in a system with used OEM or third-party parts, which can cause warranty issues, quality problems, and, in the case of imaging systems, image quality problems, diagnostic problems, and misdiagnosis. The implementations described herein allow for the detection of these unauthorized component changes to ensure system integrity.
[0082] In systems lacking systems like those described herein, third parties can purchase used components and resell them to customers, thus weakening OEM service contracts. Conversely, the embodiments described herein allow OEM-hosted systems to determine whether their components have been replaced without authorization and / or prevent the installation of old, obsolete, or compromised components into the system that could affect operation, such as replacing components in an imaging system that could impact patient diagnosis. Defective or suboptimal functional components can cause misdiagnosis and, in extreme cases, permanent harm or even death to patients.
[0083] Figures 8A-8B This is a block diagram of a system, including an authorization system, based on some implementation schemes. (Reference) Figure 8A System 800a includes a first device 802 and a second device 804. Devices 802 and 804 are coupled via a communication link 806. The communication link can be any medium that allows devices 802 and 804 to communicate. For example, communication link 806 may include a serial link, a parallel link, and an automatic communication link, such as a Mod bus, a CAN bus, or the like; a computer bus, such as a Fast External Component Interconnect (PCIe), Fast Non-Volatile Memory (NVMe), or the like; and / or a network, such as an Ethernet network, a Fibre Channel network, or the like.
[0084] The second device 804 includes non-volatile memory 808. Memory 808 may include any variety of non-volatile memories, such as static random access memory (SRAM), flash memory, electrically erasable programmable read-only memory (EEPROM), magnetic storage devices, or the like. In particular, memory 808 includes at least a portion that can be operated in a write-once manner. Memory 808 may include other non-volatile and / or volatile memories not configured for write-once operation, such as dynamic random access memory (DRAM) according to various standards such as DDR, DDR2, DDR3, and DDR4, and double data rate synchronous dynamic random access memory (DDR SDRAM).
[0085] Write-once means that a portion of memory 808 can only be written to once during a normal write operation. In some implementations, write-once access 808 cannot be erased by any other means. As a result, changing the value stored in memory 808 would require replacing memory 808. However, in other implementations, a portion of memory 808 can be erased by erasing the entire access 808.
[0086] Memory 808 is configured to store a system identifier (ID) in a write-once portion. The system ID is an identifier associated with system 800a. The system ID may be unique to system 800a, for example, as a universally unique ID (UUID) or globally unique ID (GUID). The system ID used for all devices 804 and 812 may be the same. However, in other embodiments, the system ID used for a particular device 804 or 812 may be unique to both system 800a and said device 804 or 812. In some embodiments, the system ID may include a portion unique to system 800a and a portion unique to a particular device 804 or 812, a particular type of device 804 or 812, or the like.
[0087] The system ID value can take many forms. For example, the system ID can exist in its raw form, where the stored data is the system ID. However, in other instances, the system ID can be stored in an encrypted form, a hash of the system ID, or another representation of the system ID, and processed using appropriate decoding or other manipulations.
[0088] As will be described in more detail below, a system ID can be stored on device 804 in system 800a. First device 802 can verify that the system ID stored on second device 804 or third device 812 matches an expected system ID, such as the system ID associated with system 800a. A matching system ID can indicate that second device 804 or third device 812 is the genuine component intended and originally installed on system 800a. If the system ID does not match, device 804 or 812 may have been supplied or installed by an unauthorized party. As a result, it is possible to detect devices swapped from other systems of the same manufacturer or from a third party.
[0089] In some implementations, the first device 802 may be coupled to a plurality of second devices 804-1 to 804-N. Each second device 804 may be coupled to zero or more third devices 812-1 to 812-M.
[0090] Figures 9A-10C This is a flowchart illustrating an example of an operating authorization system technology according to some implementation schemes. In the following description of the operating system technology, Figure 8A The operation of the first device 802, the second device 804 and the third device 812 will be used as examples.
[0091] refer to Figure 8A and Figure 9A In step 902, the first device 802 transmits a request for a system ID stored on the second device 804 to the second device. In step 903, the second device 804 receives the request. This transmission and other similar operations can occur via communication link 806.
[0092] In step 904, the second device 804 determines whether the system ID stored on the second device has a null value. A null value indicates that the second device 804 has not stored the system ID in memory 808. An actual value may not be stored in memory 808. In fact, a flag, register, status, or the like can indicate that the system ID has not yet been programmed into memory 808. Checking this indicator can be part of determining whether the system ID has a null value. The processor of the second device 804 can be configured to attempt to read the system ID, flag, register, status, or the like to make a determination.
[0093] In step 906, a null-based response is transmitted to the first device 802. In some embodiments, the response may be a system ID with special meaning. For example, all zeros or all ones may be specified as a null value for the system ID. In other embodiments, one or more specific values of the system ID may be specified as null. The specific value may be specific to the second device 804 or a second device 804 of the aforementioned type, specific to system 800a or a system 800a of the aforementioned type, or similar. In any case, the specific value is a value that the first device 802 will recognize as indicating that the second device 804 has not stored a system ID or that the system ID is null.
[0094] In other implementations, a null response can be a different type of message format used to transmit the actual system ID. For example, a null response can be an error message. An error message can have an error number or code indicating that the system ID is null.
[0095] In step 908, a null response is received by the first device 802. In response, in step 910, the first device 802 transmits the system ID to the second device 804. In step 912, the second device 804 receives the system ID and stores it in a write-once portion of the memory 808. Once the system ID is stored, the memory 808 cannot be reprogrammed with a different system ID without the aforementioned unusual steps. As a result, the second device 804 is paired with system 800a. If the second device 804 is removed from system 800a and placed in another system, or even the same system, the system IDs cannot match.
[0096] If it is determined in 904 that the system ID will be stored at the second device 804, then in 914, a response based on the system ID is transmitted back to the first device 802. For example, the second device 804 may read the system ID, encrypt the system ID, and transmit the encrypted system ID to the first device 802.
[0097] In 916, the first device 802 receives a response based on a system ID stored at the second device 804, and in 918 determines whether the response indicates that the system ID stored at the second device 804 matches the actual system ID. For example, the first device 802 may extract the system ID by: reading the system ID from the response; decoding an encrypted response or similar; and comparing the system ID with the system ID stored on the first device 802. As mentioned above, the system ID can be stored or encoded in various formats. The comparison can be performed in a manner suitable for different formats.
[0098] If the system ID indicated by the response from the second device 804 is incorrect, if the second device 804 fails to respond or times out, if the second device 804 returns an inappropriate response, or similar circumstances, then in 920, preventative measures may be implemented. These preventative measures can take various forms. For example, in some embodiments, system 800a may be shut down, devices 802, 804, 816, or similar devices may be temporarily or permanently disabled, specific functions may be disabled, the scope of operation may be reduced or limited, or similar circumstances may occur. In other embodiments, notifications, warnings, or other communications regarding mismatched system IDs may be provided to the user of system 800a, reported via a network, or similar actions may be taken. In other embodiments, information related to the mismatched system ID may be recorded in the memory 808 of the first device 802 and / or the second device 804. This relevant information may include a timestamp, the model and / or serial number of the first device 802 and / or the second device 804, the number of times the system ID mismatch occurred, the mismatched system ID, the entire response received in 916, or similar.
[0099] In some implementations, the communication can be encrypted when a system ID-based response is transmitted from the second device 804 to the first device 802 in 914. For example, a secure communication link can be established between the first device 802 and the second device 804, the response or multiple parts of the response can be encrypted, the system ID stored on the second device 804 can be encrypted, or similar operations can be performed. As a result, it may be more difficult for an eavesdropper to obtain the correct system ID response from the second device 804.
[0100] System 800a may be a hierarchical system, including a third device or multiple devices 812 downstream of an associated second device 804. In some embodiments, some or all communication between the first device 802 and the third device 812 may be transmitted via or manipulated by the associated second device 804. However, in other embodiments, only communication relating to the system ID may be transmitted via or manipulated by the associated second device 804.
[0101] In some implementations, the interaction between the second device 804 and the third device 812 can be the same as or similar to the operation described with respect to the first device 802 and the second device 804. That is, once the second device 804 stores the system ID, requests for the system ID, storage status checks, and verifications can be performed between the second device 804 and the third device 812.
[0102] refer to Figure 8A , Figure 9A and Figure 9BIn some implementations, once the second device 804 has transmitted the system ID in 914, the second device 804 can begin the above-mentioned... Figure 9B The described operation. In 922, a request for a system ID stored on the third device 812 can be transmitted from the second device 804 to the third device 812. In 924, the third device 812 can receive a request for a system ID stored on the third device 812. Similar to... Figure 9A In operations 904 and 906, and in 926 and 928, the third device 812 can determine whether the system ID is null or has not yet been stored; if so, it returns a null response. This is similar to... Figure 9A In operations 908 and 910, and in 930 and 932, the second device 803 receives a response indicating that the system ID stored on the third device 812 has a null value, and transmits the system ID in the response. In 934, the third device 812 stores the system ID in memory 808. Similar to operations 914 and 916, in 936 and 938, the third device 812 may transmit a response based on the system ID stored on the third device 812, and the response is received by the second device 804. Although the operations of the second device 804 and the third device 812 have been described as similar to the operations of the first device 802 and the second device 804, in other embodiments, the operations may differ. For example, different encodings of the system ID, encryption used in transmission, response formats, specific protocols, or the like may be used.
[0103] In 940, the second device 804 can prepare a verification response based on the response from the third device 812. In some embodiments, the verification response may include a system ID response from the third device 812 itself. In other embodiments, the second device 804 can determine whether the system ID stored on the third device 812 matches the system ID stored on the second device 804, which is similar to... Figure 9A The interaction of the first device 802 in 918. The verification response may include an indication of whether the system ID stored on the third device 812 is a correct system ID.
[0104] refer to Figure 8A and Figures 9A-9CIn some implementations, if it is determined in 918 that the system ID stored on the second device 804 is a correct system ID, then in 941, the first device 802 transmits a verification request to the second device 804. In 942, the second device 804 receives the verification request. As described above, in 940, the second device 804 may prepare a verification response. This verification response may be transmitted by the second device 804 to the first device 802 in 944. In 946, the first device 802 receives the verification response and in 948 determines whether the verification was successful based on the response. If the verification is successful, the operation continues in 952.
[0105] However, if verification fails, preventative measures can be implemented in 950. These preventative measures can be similar to those described with respect to 920. However, since the verification response can be associated with a third device 812, the preventative measures can also be applied to the third device 812. For example, the third device 812 can be disabled, a notification identifying the third device 812 can be provided, or similar actions can be taken.
[0106] refer to Figure 8A , Figure 9A , Figure 9B and Figure 9D In some implementations, once the second device 804 has prepared the verification response in 940, the second device 804 can transmit the verification response to the first device 802 in 944 without waiting for the transmission request in 941. The operation of the first device 802 in 946, 948, 950, and 952 can be similar to the operation described above.
[0107] Although the operation of the first device 802 and the second device 804 has been described in the context of communication between the first device 802 and a second device, the same or similar communication can occur between the first device 802 and a plurality of second devices 804-1 to 804-N. That is, the first device 802 can request a system ID for each of the second devices 804-1 to 804-N and perform operations similar to those described above. The operations of different second devices 804-1 to 804-N can be performed serially or in parallel. A decision can be made based on the response of only one, some, or all of the responses of the second devices 804-1 to 804-N. The results of system ID matching or mismatch for different second devices 803-1 to 804-N can be the same, similar, or different. The operation described between the second device 804 and the third device 812 can be performed in a similar manner by a plurality of third devices 812. Furthermore, although a three-tier hierarchy has been used as an example, the hierarchy of the device can be part of system 800a, in which the first device 802 queries other devices for a system ID.
[0108] refer to Figure 8B In some implementations, the x-ray system 800b includes a host controller 822, an ADB 824, a TAU 832, and an x-ray tube 836. The host controller 822 may be the system controller of the x-ray system 800b. The host controller 822 may act as... Figure 8A The first device 802, and performs in Figures 9A-9D The associated operations described in [the document].
[0109] The ADB 824 can be a circuit for managing the system ID and the authentication operation of the system 800b. The ADB 824 may include a memory 808. The ADB 824 can act as... Figure 8A The second device 804, and performs in Figures 9A-9D The associated operations described in [the document].
[0110] TAU 832 is a circuit configured to control the operation of x-ray tube 836. For example, TAU 832 can be configured to set cathode voltage / current, anode voltage / current, resistance wire voltage / current, focusing electronics, steering electronics, motor, or the like depending on the specific x-ray tube 836. TAU 832 includes memory 808 and can function as... Figure 8A The third device 812 and performs in Figures 9A-9D The associated operations described in [the document].
[0111] Although TAU 832 has been used as an example of a device operable using a system ID in an x-ray system 800b as described herein, other devices in the x-ray system 800b may operate in a similar manner. For example, heat exchanger 840, detector 842, high-voltage (HV) power supply 844, accelerator 846, or the like may operate using a system ID as described herein.
[0112] In some implementations, during initialization or installation, the system ID can be transferred from the host controller 822 to the ADB 824 and stored in memory 808. The ADB 824 can similarly propagate the system ID to other devices 832, 840, 842, 844, 846, 848, or the like, for storage in the corresponding memory 808 of those devices. Therefore, devices of system 800b can be paired with system 800b. During normal operation, the device will report the correct system ID, and system 800b can continue to operate. However, if a component with a different existing system ID is provided in an unauthorized manner, the precautions described above can be implemented.
[0113] In some implementations, the host controller uses the ADB 824 to communicate with the remainder of the manufacturer's or OEM's components in system 800b. In some implementations, the only components paired with system 800b are the ADB 824 and TAU 832.
[0114] The use of system IDs described herein in x-ray system 800b can provide for the safety and / or lifespan of system 800b. Specifically, for a particular x-ray system 800b, components of system 800b can be aligned, calibrated, or otherwise configured. When system 800b is initially installed, empty system IDs in the various devices of x-ray system 800b can be initialized to system IDs unique to that particular x-ray system 800b. If a device in x-ray system 800b is replaced by a device from another system with a different system ID, the operation of x-ray system 800b may differ and may become hazardous due to, for example, the device of x-ray tube 836. As described above, x-ray system 800b can take precautions upon detecting this situation, such as notifying the user, shutting down x-ray system 800b or components, or similar operations. As a result, the chance of x-ray system 800b operating under conditions that could cause erroneous results and / or hazards can be reduced or eliminated.
[0115] In some implementations, the storage and verification of system IDs, as described herein, can limit the ability of a manufacturer's or supplier's customers to swap parts themselves or via a third party. The verification process checks whether the ADB 824, TAU832, or similar is a genuine manufacturer's or OEM product and whether it has been swapped into / from other x-ray systems. This prevents third-party service organizations from purchasing used x-ray tubes from the open market, refurbishing them, and then reselling them to customers, such as hospitals. Manufacturers, suppliers, system integrators, or the like can reduce the chance that their systems can be modified by devices from other systems, modifications that could lead to unwanted or dangerous results.
[0116] In some implementations, the use of a system ID, as described herein, can reduce the chance of a modified device being installed in a system where the device is not intended for use. For example, a device already paired with a system and having a system ID can be returned for repair, update, or similar operation. The device can be programmed with the original system ID, or the system ID can remain intact. As a result, when the device is supplied to a customer or installer, the system ID will match the original system's system ID. If the device is installed in a different system, even a similar or the same type of system, the system ID will not match, and the precautions described above can be implemented. In some implementations, if a known customer or installer reinstalls the device in the same system, the system ID can remain unprogrammed.
[0117] refer to Figure 8A and Figures 9A-10C In some implementations, the authentication operation can be performed after successful verification as described in 948 above. For example, in 1002, the first device 802 transmits the authentication request to the second device 804. In 1004, the second device 804 receives the authentication request. In 1006, the second device 804 transmits the authentication request to the third device 812.
[0118] In step 1008, the third device 812 receives the authentication request. In step 1010, the third device generates an authentication response, and in step 1012, the authentication response is transmitted to the second device 804.
[0119] In step 1014, the second device 804 receives the authentication response from the third device 812. The second device 804 analyzes the authentication response 1016, records a failure in step 1018, and generates its own authentication response in step 1020. The authentication response generated in step 1020 may be an aggregation of authentication responses or multiple responses received from one or more third devices 812, and the authentication response of the second device 804 itself.
[0120] In step 1022, the first device 802 can transmit a request for the authentication status, which will be received by the second device in step 1024, as follows. Figure 10B As illustrated in the diagram. In response, at 1026, the second device 804 transmits the authentication response to the first device 802. Alternatively, after generating the authentication response at 1020, the second device 804 may transmit the authentication response to the first device 802 at 1026, as shown in the diagram. Figure 10A and Figure 10C As shown in the diagram.
[0121] Once the authentication response is received in 1028, it can be analyzed to determine in 1030 whether the authentication was successful. If successful, the operation can continue in 1034. If unsuccessful, preventative measures similar to those described above can be implemented in 1032.
[0122] Various techniques can be used to authenticate devices 804 and 812. In some implementations, authentication can be performed using a challenge with hidden numbers. Encryption algorithms can use an initialization vector (IV) and an encryption key (key). First device 802 and / or second device 804 can create a challenge (mathematical problem) using the device's IV and key, and send the challenge to downstream second device 804 or third device 812. If the devices have the same key and IV, they can perform the same mathematical problem and obtain the same result. The challenged second device 804 or third device 812 can then send back the "answer" to the mathematical problem in encrypted form, and the initiating component can determine that the device has correctly answered the challenge. If the initiating component receives a correct answer, first device 802 and / or second device 804 can consider the corresponding second device 804 or third device 812 as the genuine part.
[0123] In some implementations, the IV and key are stored in the restricted memory of the cryptographic authentication integrated circuit. For example, the ATSHA integrated circuit may include such restricted memory and may be able to perform computations related to encrypted communication. Authentication operations can be more secure if the IV and key are stored in such restricted memory.
[0124] In some implementations, the authentication process can be used to ensure that all required components are present in the system, designed for a specific customer, and / or are genuine manufacturer or OEM components. Different customers may have customer-specific encryption keys, preventing third parties from obtaining components designed for one customer and selling them to another. Any missing components will fail the authentication process because a missing component cannot prove its existence. The authentication process can prevent third-party supply of parts of the system. If an entire computed tomography (CT) system is designed with five manufacturer or OEM components, and only four of these components are genuine, while the fifth component originates from a third party, the authentication process will identify the fifth component as not genuine.
[0125] As described above, more than one second device 804 and more than one third device 812 may exist in system 800a. The identification of each of these devices is as described with respect to a single second device 804 and a single third device 812.
[0126] Despite Figure 8A The system 800a is used as an example, but the above text about Figures 10A-10C The described identification operation can be performed by, for example... Figure 8B The X-ray system 800b is implemented using other systems.
[0127] Some embodiments include a device 102 comprising: a mounting structure configured to mount the device 102 to an external component 104; a first circuit 112; and a tamper-proof circuit electrically connected to the first circuit 112 and configured to deactivate at least one function of the first circuit 112 when the device 102 is removed from the external component 104. In some embodiments, the external component 104 may include a wall, housing, or other structure not controlled by the first circuit 112.
[0128] In some embodiments, the first circuit 112 is configured to control the external component 104. In some embodiments, at least one function of the first circuit 112 includes functions unrelated to the control of the external component 104.
[0129] In some implementations, at least one function of the first circuit 112 includes the function of controlling the external component 104.
[0130] In some embodiments, device 102 further includes a housing 116 coupled to the mounting structure, wherein housing 116 is configured to restrict access to de-equip the tamper-proof circuit when device 102 is mounted to external component 104.
[0131] In some implementations, the tamper-proof circuit 110 includes a switch 220 or SW1, which is coupled to the mounting structure 116 and configured to switch when the device 102 is removed from the external component 104.
[0132] In some implementations, switch 220 or SW1 is configured to be switched via the structure of external component 104 when mounted on external component 104.
[0133] In some embodiments, the tamper-proof circuit 110 includes: a power supply 502 disposed within the device 102 and configured to supply power after detection of removal of the device 102 from the external component 104; and a circuit 504 configured to disable at least one function of the first circuit 112; wherein a switch 220 or SW1 is configured to electrically connect the power supply 502 to the disable circuit 504 when the device 102 is removed from the external component 104.
[0134] In some embodiments, the first circuit 112 includes a processor 113; and the tamper-proof circuit 110 is configured to erase at least a portion of the memory 118 or 808 used by the processor 113 when the device 102 is removed from the external component 104.
[0135] In some implementations, at least a portion of the memory 118 or 808 used by the processor 113 includes the memory 118 or 808 integrated with the processor 113.
[0136] In some implementations, at least a portion of the memory 118 or 808 used by processor 113 stores password information.
[0137] In some embodiments, device 102 is part of an electronic device associated with an x-ray system; and external component 104 is the x-ray tube 736 or 836 of the x-ray system 700 or 800b.
[0138] In some embodiments, device 102 is part of a component identification system associated with x-ray system 700 or 800b.
[0139] Some implementations include a method comprising: detecting by device 102 the removal of device 102 from component 104 outside device 102; and deactivating at least one function of circuitry 112 of device 102 in response to detecting the removal of device 102 from component 104.
[0140] In some embodiments, the removal of the device 102 from the component 104 by the device 102 includes the physical separation of the structure of the detection device 102 from the structure of the component 104 which is outside the device 102.
[0141] In some embodiments, at least one function of the circuit 112 of the deactivation device 102 includes: supplying power to the deactivation circuit 504 from the internal power supply 502; and using the deactivation circuit 504 to deactivate at least one function of the circuit of the device 102.
[0142] In some embodiments, the removal of the device 102 from the component 104 by the device 102 includes the physical separation of the structure of the detection device 102 from the structure of the component 104 which is outside the device 102.
[0143] In some embodiments, the method further includes: mounting the device 102 on the component 104; and equipping it with a tamper-proof circuit 110 that enables at least one function of the circuit configured to disable the device 102.
[0144] In some embodiments, the method further includes: tamper-proof circuitry 110 that resets at least one function of circuitry 112 configured to disable device 102.
[0145] Some embodiments include an apparatus comprising: means for detecting the removal of the apparatus from a component outside the apparatus; and means for deactivating at least one function of a circuitry of the apparatus in response to the means for detecting the removal of the apparatus from the component. Examples of the means for detection include tamper-proof circuitry 110, switch 220 or SW1 or similar means. Examples of the means for deactivating at least one function of the circuitry of the apparatus include tamper-proof circuitry 110, processor 113, memory 118 or 808 or similar means.
[0146] In some embodiments, the apparatus further includes: means for detecting physical separation of the device from the component; and means for erasing at least a portion of the memory of the circuit in response to the means for detecting physical separation of the device 102 from the component. Examples of the means for detecting physical separation of the device from the component include tamper-proof circuit 110, switch 220 or SW1 or similar means. Examples of the means for erasing at least a portion of the memory of the circuit include tamper-proof circuit 110, processor 113, memory 118 or 808 or similar means.
[0147] Some implementations include a method comprising: receiving, at a second device 804, a request from a first device 802 for a system identifier (ID) stored on the second device 804; determining, by the second device 804, whether the system ID stored on the second device 804 has a null value; and, when the system ID stored on the second device 804 does not have the null value, transmitting, by the second device 804, a response based on the system ID stored on the second device 804 to the first device 802.
[0148] In some embodiments, the method further includes: when the system ID stored on the second device 804 has the null value, the second device 804 transmits the information that the system ID stored on the second device 804 has the null value to the first device 802.
[0149] In some embodiments, the method further includes: receiving a system ID from a first device 802 by a second device 804; and storing the system ID received from the first device 802 by the second device 804 as a system ID stored on the second device 804.
[0150] In some implementations, the system ID received from the first device 802 is stored by the second device 804 as a system ID stored on the second device 804, including the system ID received from the first device 802 being stored by the second device 804 in a write-once memory 808.
[0151] In some implementations, the transmission of the response based on the system ID stored on the second device 804 to the first device 802 by the second device 804 includes encrypting the system ID stored on the second device 804 and transmitting the encrypted system ID to the first device 802 by the second device 804.
[0152] In some embodiments, the method further includes: the second device 804 transmitting a request for a system ID stored on the third device 812 to the third device 812; and the second device 804 receiving a response from the third device 812 for the request for the system ID stored on the third device 812.
[0153] In some embodiments, the method further includes: the second device 804 transmitting a response based on a request for a system ID stored on a third device 812 to the first device 802.
[0154] In some embodiments, the method further includes: determining by the third device 812 whether the system ID stored on the third device 812 has the null value; and when the system ID stored on the third device 812 has the null value, the third device 812 transmits the information that the system ID stored on the third device 812 has the null value to the second device 804.
[0155] In some embodiments, the method further includes: storing the system ID received from the second device 804 by the third device 812 as a system ID stored on the third device 812.
[0156] In some embodiments, the second device 804 is an identification device for the x-ray system 800b; and the third device 812 is a control device for the x-ray tube 836 of the x-ray system 800b.
[0157] Some implementations include a method comprising: transmitting a request for a system identifier (ID) stored on a second device 804 from a first device 802 to the second device 804; receiving a response from the first device 802 to the second device 804 for the request for the system ID stored on the second device 804; determining, by the first device 802, whether the system ID stored on the second device 804 is a correct system ID of a system including the second device 804; and operating, by the first device 802, the system including the second device 804 based on whether the system ID stored on the second device 804 is a correct system ID of a system including the second device 804.
[0158] In some implementations, the operation of a system including the second device 804 includes implementing safeguards when the system ID stored on the second device 804 is not the correct system ID of the system including the second device 804.
[0159] In some implementations, the preventative measures include knowledge of one of the following: disabling the second device 804; disabling the system including the second device 804; and presenting a warning to the user that the system ID stored on the second device 804 and the correct system ID of the system including the second device 804 do not match.
[0160] In some implementations, the operation of a system including a second device 804 includes, when a system ID stored on the second device 804 matches the correct system ID of a system including the second device 804, a request for verification of a device belonging to the second device 804 is transmitted by the first device 802 to the second device 804.
[0161] In some embodiments, the method further includes: receiving, by the first device 802, a response from the second device 804 to a request for verification of a device subordinate to the second device 804; wherein operating a system including the second device 804 includes operating the system based on a response to a request for verification of at least one device subordinate to the second device 804.
[0162] In some embodiments, the second device 804 is an identification device for the x-ray system 800b; and at least one device subordinate to the second device 804 is a control device for the x-ray tube 836 of the x-ray system 800b.
[0163] In some embodiments, the method further includes: transmitting a request to authenticate the second device 804 from the first device 802 to the second device 804; and receiving a response from the first device 802 to the request to authenticate the second device 804 from the second device 804; wherein operating a system including the second device 804 includes operating a system including the second device 804 based on the response to the request to authenticate the second device 804.
[0164] Some embodiments include an apparatus comprising: means for receiving a request for a system identifier (ID) stored on the apparatus from a first external device; means for determining whether the system ID stored on the apparatus has a null value; and means for transmitting a response based on the system ID stored on the apparatus to the first device when the system ID stored on the apparatus does not have the null value. Examples of the means for receiving the request for the system identifier from the first external device and the means for transmitting a response based on the system ID to the first device include a second means 804, a third means 812, or similar means.
[0165] In some embodiments, the apparatus further includes: means for transmitting a request for a system ID stored on a second external device to the second external device; and means for receiving a response from a third device to the request for the system ID stored on the second external device. Examples of the means for transmitting the request for the system ID to the second external device and the means for receiving a response from the third device to the request for the system ID include a second device 804, a third device 812, or similar means.
[0166] Some implementations include at least one non-transitory machine-readable storage medium, which includes a plurality of instructions suitable for execution to implement the methods described above.
[0167] The overview provided above is illustrative and is in no way intended to be limiting. Other aspects, features, and advantages of the invention, in addition to the examples described above, will become apparent from reference to the drawings, the following detailed description, and the appended claims.
[0168] A circuit can include hardware, firmware, program code, executable code, computer instructions, and / or software. A non-transitory computer-readable storage medium can be a computer-readable storage medium that does not include signals.
[0169] The operations described above can be implemented in a variety of circuits. For example, the operations can be implemented as hardware circuitry including custom very large-scale integration (VLSI) circuitry or gate arrays, including but not limited to logic chips, transistors, or other components. The operations can also be implemented in programmable hardware devices, including but not limited to field-programmable gate arrays (FPGAs), programmable array logic, programmable logic devices, or similar devices.
[0170] References to "example" or "implementation" in the specification mean that a particular feature, structure, or characteristic described in connection with the example is included in at least one embodiment of the invention. Therefore, the appearance of the words "example" or "implementation" in various places in the specification does not necessarily refer to the same embodiment.
[0171] Furthermore, the described features, structures, or characteristics can be combined in suitable ways in one or more embodiments. In the following description, numerous specific details (e.g., examples of layouts and designs) are provided to provide a thorough understanding of embodiments of the invention. However, those skilled in the art will recognize that the invention can be practiced without one or more of the specific details or using other methods, components, layouts, etc. In other instances, well-known structures, components, or operations have not been shown or described in detail so as not to obscure aspects of the invention.
[0172] The means to add functionality to the format of the specially listed elements, if they exist, are intended to be in accordance with 35 U.SC §112 6. It is interpreted as covering the corresponding structures, operations, or actions described in this article, as well as their equivalents.
[0173] While the preceding examples illustrate the principles of the invention in one or more specific applications, those skilled in the art will understand that various modifications can be made to the form, use, and details of the implementations without inventive step and without departing from the principles and concepts of the invention. Accordingly, the invention is not intended to be limited. Various features and advantages of the invention are set forth in the claims.
Claims
1. A method comprising: receiving, at a second device from a first device, a request for a system identifier (ID) stored on the second device; determining, by the second device, whether the system ID stored on the second device has a null value, wherein the null value represents a state of the second device in which no value is stored as the system ID; communicating, by the second device to the first device, that the system ID stored on the second device has the null value when the system ID stored on the second device has the null value; and receiving, by the second device from the first device, the system ID in response to the communication that the system ID stored on the second device has the null value.
2. The method of claim 1, further comprising: storing, by the second device, the system ID received from the first device as the system ID stored on the second device.
3. The method of claim 2, wherein: storing, by the second device, the system ID received from the first device as the system ID stored on the second device comprises storing, by the second device, the system ID received from the first device in a write-once memory.
4. The method of claim 1, further comprising: transmitting, by the second device to the first device, a response based on the system ID stored on the second device by encrypting the system ID stored on the second device and transmitting, by the second device to the first device, the encrypted system ID.
5. The method of claim 1, further comprising: transmitting, by the second device to a third device, a request for a system ID stored on the third device; and receiving, by the second device from the third device, a response to the request for the system ID stored on the third device.
6. The method of claim 5, further comprising: transmitting, by the second device to the first device, a response based on the response to the request for the system ID stored on the third device.
7. The method of claim 5, further comprising: determining, by the third device, whether the system ID stored on the third device has the null value; and communicating, by the third device to the second device, that the system ID stored on the third device has the null value when the system ID stored on the third device has the null value.
8. The method of claim 7, further comprising: storing, by the third device, the system ID received from the second device as the system ID stored on the third device.
9. The method of claim 5, wherein: the second device is an authentication device for an x-ray system; and the third device is a control device for an x-ray tube of the x-ray system. 10. At least one non-transitory machine-readable storage medium comprising a plurality of instructions adapted to be executed to implement the method of claim 1.
11. A method comprising: transmitting, from a first device to a second device, a request for a system identifier (ID) stored on the second device; receiving, by the first device from the second device, a response to the request for the system ID stored on the second device; determining, by the first device, whether the system ID stored on the second device is a correct system ID for a system comprising the second device; operating, by the first device, the system comprising the second device based on whether the system ID stored on the second device is the correct system ID for the system comprising the second device; wherein operating the system comprising the second device comprises transmitting, by the first device to the second device, a request to authenticate a device subordinate to the second device when the system ID stored on the second device matches the correct system ID for the system comprising the second device; sending, from the second device to the device subordinate to the second device, a request for a subordinate system ID stored on the device subordinate to the second device; and authenticating, by the first device, whether the subordinate system ID matches an expected system ID.
12. The method of claim 11, wherein: operating the system comprising the second device comprises implementing a countermeasure when the system ID stored on the second device is not the correct system ID for the system comprising the second device.
13. The method of claim 12, wherein: the countermeasure comprises at least one of the following operations: deactivating the second device; deactivating the system comprising the second device; presenting a warning to a user that the system ID stored on the second device and the correct system ID for the system comprising the second device do not match.
14. The method of claim 11, further comprising: receiving, by the first device from the second device, a response to the request to authenticate a device subordinate to the second device; wherein operating the system comprising the second device comprises operating the system based on the response to the request to authenticate at least one device subordinate to the second device.
15. The method of claim 14, wherein: the second device is an authentication device for an x-ray system; and the at least one device subordinate to the second device is a control device for an x-ray tube of the x-ray system.
16. The method of claim 11, further comprising: transmitting, from the first device to the second device, a request to authenticate the second device; and receiving, by the first device from the second device, a response to the request to authenticate the second device; wherein the operations comprising the system of the second device include operating the system comprising the second device based on the response to the request to authenticate the second device.
17. An apparatus, the apparatus comprising: means for receiving, from a first external device, a request for a system identifier (ID) stored on the apparatus; means for determining whether the system ID stored on the apparatus has a null value, wherein the null value represents a state of no value stored on the apparatus as the system ID; means for communicating, to the first external device, a response of the system ID stored on the apparatus when the system ID stored on the apparatus has the null value; means for receiving, from the first external device, a new system ID in response to the communication that the system ID stored on the apparatus has the null value; and means for storing, in the apparatus, the new system ID received from the first external device.
18. The apparatus of claim 17, the apparatus further comprising: means for transmitting, to a second external device, a request for a system ID stored on the second external device; and means for receiving, from the second external device, a response to the request for the system ID stored on the second external device.
Citation Information
Patent Citations
Controlling the Configuration of Computer Systems
US20150199204A1
Hybrid x-ray system with detachable radiation shield
US20170027532A1
X-ray system comprising an x-ray source
US20180214244A1