Automated Network Provisioning of Medical Devices

By preconfiguring information in medical equipment and automatically configuring medical equipment to connect to medical networks using a temporary supply network, the problem of long and difficult to ensure safety of medical equipment network configuration in the prior art is solved, and efficient and secure automatic network configuration is achieved.

CN113632177BActive Publication Date: 2025-05-06CAREFUSION 303 INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080018976.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-03-06
Filing Date
2020-03-05
Publication Date
2025-05-06
Estimated Expiration
2040-03-05

AI Technical Summary

Technical Problem

In the prior art, network configuration of medical equipment needs to be performed manually, resulting in long and expensive configuration time and difficulty in ensuring security.

Method used

Security and efficiency are ensured by preconfiguring information in medical devices, including temporary supply network connection information and device identifiers. The temporary supply network is automatically configured to connect to the medical network using the temporary supply network.

Benefits of technology

Automatic network configuration of medical equipment is realized, reducing configuration time, improving configuration efficiency, and ensuring the security of medical network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113632177B_ABST
    Figure CN113632177B_ABST
Patent Text Reader

Abstract

One or more medical devices are configured to connect to a predetermined temporary provisioning network of a medical institution, which is different from a medical network of the medical institution. After the medical institution receives the device and powers it on for the first time, a device identifier corresponding to the medical device is received from the temporary provisioning network at a server remote from the medical institution, along with an indication that the medical device requests access to a management server within the medical network of the medical institution. Upon determining that the medical device is predetermined to receive access to the management server, the provisioning service configures the medical device to access and communicate with the management server via the temporary provisioning network, and notifies the management server that the medical device has been configured to access and communicate with the management server.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application claims the benefit of U.S. Provisional Application Serial No. 62 / 814,765, filed on March 6, 2019, entitled “AUTOMATIC NETWORK PROVISIONING OF A MEDICAL DEVICE,” the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present application generally relates to the automated provisioning of medical devices, such as infusion devices, to a medical network of a medical institution. Background Art

[0004] Medical devices purchased for use in healthcare facilities, such as infusion devices, often require manual configuration to connect to the facility's medical network. Typically, operators configure and install the necessary security certificates and updates for compliant use on the medical network. The process of setting up each medical device is often difficult and time-consuming.

[0005] As the demand for new advanced medical devices continues to grow, the need to automatically connect other medical devices to the medical network is also increasing. Efficient provisioning methods are needed to connect multiple medical devices to the medical network. Summary of the invention

[0006] Configuring dozens of medical devices for use on a medical network is laborious and time-consuming. A major issue for healthcare organizations includes reducing the setup time for medical devices while maintaining strict security protocols. Traditionally, each medical device is manually configured by an operator to access the medical network.

[0007] Therefore, there is a need for methods and systems that can automatically configure medical devices to appropriate medical networks without manual intervention. The disclosed embodiments can safely and efficiently provision multiple devices for use on a medical network.

[0008] The disclosed subject matter relates to a method for automatically provisioning multiple medical devices over a network. According to some embodiments, the method includes configuring one or more medical devices to connect to a predetermined temporary provisioning network of a medical institution. The temporary provisioning network is different from the medical network of the medical institution. After the medical institution receives the device and powers it on for the first time, a device identifier corresponding to the medical device is received from the temporary provisioning network at a server remote from the medical institution, along with an indication that the medical device requests access to a management server within the medical network of the medical institution. Upon determining that the medical device is predetermined to receive access to the management server, the provisioning service configures the medical device to access and communicate with the management server via the temporary provisioning network, and notifies the management server that the medical device has been configured to access and communicate with the management server.

[0009] The disclosed subject matter also relates to a machine-readable medium containing instructions that, when executed by a machine, enable the machine to perform the methods for automatic network provisioning described herein.

[0010] The disclosed subject matter also relates to a system for automatic network provisioning. The system includes one or more processors and a memory including instructions that, when executed by the one or more processors, cause the one or more processors to perform the steps of the method described herein.

[0011] The subject technology provides a system for automatically supplying medical devices, including one or more processors and a memory. The memory includes instructions, which, when executed by the one or more processors, cause the one or more processors to: configure one or more medical devices to connect to a predetermined temporary supply network of a medical institution in response to the one or more medical devices being powered on for the first time, the temporary supply network being different from the medical network of the medical institution; receive one or more device identifiers corresponding to the one or more medical devices and an indication that the one or more medical devices request access to the medical network from the temporary supply network; based on receiving the one or more device identifiers, determine that the received one or more device identifiers correspond to the corresponding medical devices that are predetermined to receive access to a management server within the medical network; based on determining that the one or more medical devices are predetermined to receive access to the medical network and the management server: configure the medical devices to access and communicate with the management server through the temporary supply network, and confirm that the one or more medical devices have been configured to access and communicate with the management server. Other aspects include corresponding methods, apparatuses, and computer program products for implementing corresponding systems and features thereof.

[0012] According to other aspects, the subject technology provides a medical device that includes a non-volatile data storage unit that stores (a) predetermined supply network connection information and (b) identification information that uniquely identifies the medical device, one or more processors, and a memory. The memory includes instructions that, when executed by the one or more processors, cause the one or more processors to: upon activating the medical device, determine that the activation is an initial activation at a medical facility based at least in part on an activation indicator stored by the medical device; in response to determining that the activation is an initial activation, establish a first network connection with a supply network based at least in part on the predetermined supply network connection information; transmit identification information that uniquely identifies the medical device via the first network connection; receive facility network connection information for accessing and communicating with a management server associated with the medical facility via the first network connection; and after receiving the facility network connection information, establish a second network connection with the management server based at least in part on the facility network connection information using a second network different from the supply network.

[0013] It should be understood that other configurations of the subject technology will be readily apparent to those skilled in the art from the following detailed description, wherein various configurations of the subject technology are shown and described by way of illustration. As will be appreciated, the subject technology can have other different configurations, and its several details can be modified in other aspects, all of which will not depart from the scope of the subject technology. Therefore, the drawings and detailed description are to be considered illustrative rather than restrictive in nature. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] For a better understanding of the various embodiments described, reference should be made to the following description of the embodiments in conjunction with the following drawings. Throughout the drawings and description, like reference numerals refer to corresponding parts.

[0015] Figure 1 An example of an institutional patient care system for a medical institution in accordance with aspects of the subject technology is depicted.

[0016] Figure 2 Depicted are examples of information flows between various elements of an institutional patient care system and provisioning services in accordance with aspects of the subject technology.

[0017] Figure 3 An example process for automatically provisioning medical devices to a medical network in accordance with aspects of the subject technology is depicted.

[0018] Figure 4 is a conceptual diagram illustrating an example electronic system 400 for automated provisioning of medical devices in accordance with aspects of the subject technology. DETAILED DESCRIPTION

[0019] Reference will now be made to embodiments, examples of which are illustrated in the accompanying drawings. In the following description, numerous specific details are set forth to provide an understanding of the various embodiments described. However, it will be apparent to one of ordinary skill in the art that the various embodiments described may be practiced without these specific details. In other cases, well-known methods, processes, components, circuits, and networks are not described in detail to avoid unnecessarily obscuring aspects of the implementation.

[0020] Medical devices are pre-configured to efficiently configure themselves when first powered on. Medical devices may be pre-configured during manufacturing or by a vendor to include information that allows for automatic provisioning of the device, including installation of software to connect to a private medical network. For example, when a hospital places an order for a new medical device, the new medical device may be pre-configured (e.g., during manufacturing) to connect (e.g., wirelessly) to a special provisioning network operated by the hospital. This temporary provisioning network is publicly accessible and separate from the main network, allowing the main network to remain protected from unauthorized access. The device then uses the provisioning network to self-configure when powered on, by installing the software and security information required to access the hospital's main network.

[0021] Any required security certificates and / or software updates are implemented by the medical network through the temporary provisioning network. Once the medical device complies with the medical network's requirements, the medical device is granted access to the medical network and the temporary provisioning network connection may be terminated. The temporary provisioning network can act as a safeguard to protect security breaches while the medical device is being configured to access the medical network.

[0022] Figure 1 An example of an institutional patient care system 100 for a medical institution in accordance with aspects of the subject technology is depicted. Figure 1 , patient care devices 12 are connected to the hospital network 10. The term patient care device (or "PCD") may be used interchangeably with the term patient care unit (or "PCU"), both of which may include a variety of medical devices, such as infusion pumps, vital signs monitors, medication dispensing equipment (e.g., cabinets, totes), medication preparation equipment, automatic dispensing equipment, a module coupled to one of the above devices (e.g., a syringe pump module configured to be attached to an infusion pump), or other similar equipment. Each element 12 is connected to the medical network 10 via a transmission channel 32. The transmission channel 32 is any wired or wireless transmission channel, such as an 802.11 wireless local area network (LAN). In some embodiments, the network 10 also includes computer systems located in various departments throughout the hospital. For example, Figure 1The network 10 optionally includes computer systems associated with an admissions department, a billing department, a biomedical engineering department, a clinical laboratory, a central supply department, one or more unit station computers, and / or a medical decision support system. As further described below, the network 10 may include discrete subnets. In the depicted example, the network 10 includes a device network 40 through which the patient care devices 12 (and other devices) communicate in accordance with normal operations, and a supply network 42 through which the devices can connect at startup to load certain parameters required for operation within the institutional patient care system 100 environment. According to some embodiments, the devices and supporting services of the network 10 or a portion thereof may be cloud-based, for example, servers and services (e.g., databases, APIs, etc.) are remote from the hospital and / or distributed across multiple remote locations or regions.

[0023] In addition, the institutional patient care system 100 may include a separate device management server 30, the functionality of which will be described in more detail below. In addition, although the device management server 30 is shown as a separate server, the functionality and programs of the device management server 30 can be incorporated into another computer, such as a hospital information system server or a cloud-based server, if the engineers designing the institutional information system wish to do so. The institutional patient care system 100 may also include one or more device terminals 32 for connecting to and communicating with the device management server 30. The device terminal 32 may include a personal computer, a personal data assistant, a mobile device such as a laptop computer, a tablet computer, an augmented reality device, or a smart phone, which is configured with software for communicating with the device management server 30 via the network 10.

[0024] The patient care device 12 includes a system for providing patient care, such as the system described in U.S. Patent 5,713,856 to Eggers et al., which is incorporated herein by reference for this purpose. The patient care device 12 may include or include pumps, physiological monitors (e.g., heart rate, blood pressure, ECG, EEG, pulse oximeters and other patient monitors), therapeutic devices and other drug delivery devices, which can be used according to the teachings described herein. In the depicted example, the patient care device 12 includes a control module 14 connected to one or more functional modules 16, 18, 20, 22, also referred to as an interface unit 14. The interface unit 14 includes a central processing unit (CPU) 50 connected to a memory, such as a random access memory (RAM) 58, and one or more interface devices, such as a user interface device 54, an encoded data input device 60, a network connection 52, and an auxiliary interface 62 for communicating with additional modules or devices. The interface unit 14 also includes a main non-volatile storage unit 56 for storing software and data, such as a hard drive or non-volatile flash memory, and one or more internal buses 64 for interconnecting the above elements, although this is not required.

[0025] In various embodiments, the user interface device 54 is a touch screen for displaying information to a user and allowing the user to input information by touching defined areas of the screen. Additionally or alternatively, the user interface device 54 may include any device for displaying and inputting information, such as a monitor, printer, keyboard, soft keys, mouse, trackball, and / or light pen. The data input device 60 may be a bar code reader capable of scanning and interpreting data printed in a bar code format. Additionally or alternatively, the data input device 60 may be any device for inputting encoded data into a computer, such as a device for reading a magnetic strip, a radio frequency identification (RFID) device, wherein the digital data encoded in an RFID tag or smart tag (defined below) is captured by the reader 60 via radio waves, a PCMCIA smart card, a radio frequency card, a memory stick, a CD, a DVD, or any other analog or digital storage medium. Other examples of the data input device 60 include a voice activation or recognition device or a portable personal data assistant (PDA). Depending on the type of interface device used, the user interface device 54 and the data input device 60 may be the same device. Although Figure 1 The data input device 60 shown in FIG. 1 is disposed within the interface unit 14, but it should be appreciated that the data input device 60 may be integrated within the pharmacy system 34 or located externally and communicate with the pharmacy system 34 via an RS-232 serial interface or any other suitable communication means. The auxiliary interface 62 may be an RS-232 communication interface, but any other means for communicating with peripheral devices (e.g., printers, patient monitors, infusion pumps, or other medical devices) may be used without departing from the subject technology. In addition, the data input device 60 may be a separate functional module, such as modules 16, 18, 20, and 22, and configured to communicate with the controller 14 or any other system on the network using appropriate programming and communication protocols.

[0026] The network connection 52 may be a wired or wireless connection, such as via Ethernet, WiFi, BLUETOOTH, an integrated services digital network (ISDN) connection, a digital subscriber line (DSL) modem, or a cable modem. Any direct or indirect network connection may be used, including but not limited to a telephone modem, a MIB system, an RS232 interface, an auxiliary interface, an optical link, an infrared link, a radio frequency link, a microwave link, or a WLANS connection or other wireless connection.

[0027] Functional modules 16, 18, 20, 22 are any devices associated with control module 14 for providing care to a patient or for monitoring a patient's condition. Figure 1As shown, at least one of the functional modules 16, 18, 20, 22 can be an infusion pump module, such as an intravenous infusion pump for delivering drugs or other fluids to a patient. For the purposes of this discussion, the functional module 16 is an infusion pump module. Each of the functional modules 18, 20, 22 can be any patient treatment or monitoring device, including but not limited to an infusion pump, a syringe pump, a PCA pump, an epidural pump, an enteral pump, a blood pressure monitor, a pulse oximeter, an electrocardiogram monitor, an electroencephalogram monitor, a heart rate monitor, or an intracranial pressure monitor, etc. The functional modules 18, 20 and / or 22 can be printers, scanners, barcode readers, or any other peripheral input, output, or input / output devices.

[0028] Each functional module 16, 18, 20, 22 communicates directly or indirectly with the interface unit 14, which provides overall monitoring and control of the device 12. The functional modules 16, 18, 20, 22 may be physically and electronically connected to one or both ends of the interface unit 14 in a serial manner, such as Figure 1 , or as described by Eggers et al. However, it should be appreciated that other means of connecting the functional modules to the interface unit may be utilized without departing from the subject technology. It should also be appreciated that a device such as a pump or patient monitoring device that provides sufficient programmability and connectivity may operate as a standalone device and may communicate directly with the network without being connected through a separate interface unit or control unit 14. As described above, additional medical devices or peripheral devices may be connected to the patient care device 12 via one or more auxiliary interfaces 62.

[0029] Each functional module 16, 18, 20, 22 may include module specific components 76, a microprocessor 70, a volatile memory 72, and a non-volatile memory 74 for storing information. In some embodiments, the functional module may include hardware components similar to those of the control unit 14, including but not limited to a CPU 50 connected to a memory, a RAM 58, one or more interface devices, such as a user interface device 54, an encoded data input device 60, a network connection 52, and an auxiliary interface 62 for communicating with additional modules or devices. It should be noted that although Figure 1 Four functional modules are shown, but any number of devices can be directly or indirectly connected to the central controller 14. The number and type of functional modules described here are intended to be illustrative and do not limit the scope of the subject technology in any way. Module-specific components 76 include any components required to operate a specific module, such as a pumping mechanism for an infusion pump module 16.

[0030] According to various embodiments, while each functional module may be capable of operating independently (e.g., as described with respect to control unit 14 and its hardware components), interface unit 14 is configured to monitor and control the overall operation of device 12. For example, as will be described in more detail below, interface unit 14 may provide programming instructions to functional modules 16, 18, 20, 22 and monitor the status of each module.

[0031] The patient care device 12 may be able to operate in several different modes or characteristics, each defined by a configuration database. A particular configuration database may be selected based at least in part on patient-specific information such as patient location, age, physical characteristics, or medical characteristics. Medical characteristics include, but are not limited to, patient diagnosis, treatment prescriptions, medical history, medical records, patient care provider identity, physiological characteristics, or psychological characteristics. As used herein, patient-specific information also includes care provider information (e.g., physician identity) or the location of the patient care device 10 in a hospital or hospital computer network. Patient care information can be input through interface devices 52, 54, 60, 62 and can originate from anywhere in the network 10, such as from a pharmacy server, an admission server, a laboratory server, etc.

[0032] Data in and out of various data sources can be converted to network-compatible data using existing techniques, and information movement between medical devices and the network can be achieved in a variety of ways. For example, patient care devices 12 and network 10 can communicate through automatic interaction, manual interaction, or a combination of automatic and manual interaction. Automatic interaction can be continuous or intermittent, and can be achieved through direct network connection 54 (such as Figure 1 As shown) or through an RS232 link, MIB system, RF link, such as Bluetooth, IR link, WLANS, digital cable system, telephone modem or other wired or wireless communication means. Manual interaction between the patient care device 12 and the network 10 involves the physical transfer of data between the systems intermittently or periodically using, for example, a user interface device 54, a coded data input device 60, a bar code, a computer disk, a portable data assistant, a memory card or any other medium for storing data. The communication means in all aspects are bidirectional and data can be accessed from as many points as possible from distributed data sources. Decisions can occur in multiple places within the network 10. For example, but not limited to, decisions can be made in the HIS server 30, decision support 48, a remote data server 49, a hospital department or unit station 46, or within the patient care device 12 itself.

[0033] Figure 2An example of information flow between various elements of an institutional patient care system 100 and a supply service 202 according to aspects of the subject technology is depicted. As shown, a device management server 30 communicates with one or more different patient-related devices 12, such as an infusion pump, a point-of-care unit, an injection pump, a vital sign monitor, an automatic dispensing machine, or other medical equipment. Each of these patient-related devices provides treatment to a patient or monitors a patient's vital signs or condition, and provides information about the patient's status and the patient's treatment to the server. A network monitoring application 35 provides an interface with the server, and in turn, all assets that communicate with the server. Using the network application 35, users such as pharmacists, nurses, doctors, and biomedical technicians can view information provided to the server by various patient assets, can adjust the treatment provided to the patient, or can monitor the operation of the patient's assets. This system is particularly useful because it provides a way for qualified biomedical technicians to change or update the software configuration of patient assets.

[0034] A client-server environment incorporating aspects of the subject technology may include at least one central server (e.g., device management server 30) accessible to clients via a computer network. In more complex systems, the central server may be accessed by at least one local server via a computer network, such as an Ethernet network, a wireless network, or the Internet, which in turn may be accessed by the clients. Various computer network transmission protocols, including but not limited to TCP / IP, may be used to communicate between the central server, any local servers, and client devices configured with communication capabilities compatible with the communication protocol used on the network.

[0035] The device management server 30 typically includes or uses a central database 37, such as a SQL server application executed thereon, etc. The device management server 30 can ensure that the local server runs the latest version of the knowledge base, and can also store all patient data and perform various management functions, including adding and deleting local servers and users to the system. The device management server 30 can also provide authorization before a user can use a local server or client medical device. As previously described, in the example integrated system, patient data can be stored on the device management server 30, thereby providing a central repository for patient data. However, it is understood that patient data can be stored on a local server or local storage medium, or on another hospital or institutional server or information system, where it can be accessed as needed by various elements of the system, i.e., by a local server or client.

[0036] Local servers (and the services they provide) can be implemented in conjunction with the device management server 30. For example, each local server can provide services to multiple users in a specific geographic location. Examples of such local servers can include servers located in hospital wards, nurse stations, or off-site or remote locations, used as primary or backup information collection, routing, analysis, and / or storage systems. Each local server can include a server application, one or more knowledge bases, and a local database. Each local server can also include a reasoning system that can interact with a rule set or practice standard to ensure that appropriate medical and drug delivery and prescription practices are followed. Each local server can also perform artificial intelligence processing to perform the operation of the subject technology. When a user logs in to the local server through a client, the user can be authenticated by an identification and password. Once authenticated, the user is allowed to access the system and certain administrative permissions are assigned to the user. Additionally or alternatively, the system can be programmed to operate so that various patient, caregiver, and drug identification devices (e.g., barcode labels, radio frequency identification tags or devices) or other intelligent, passive, or active identification devices can be used to identify users of the system and allow access to the system to diagnose and treat patients. Scanning of such devices can be performed at the patient care device 12, for example, using a data input device 60.

[0037] Each local server may also communicate with the device management server 30 to verify that the latest versions of the knowledge base and application are running on the requesting local server. If not, the requesting local server downloads the latest verified knowledge base and / or application from the device management server 30 before establishing a user session. Although in certain embodiments of the subject technology, most of the computationally intensive work (e.g., data and artificial intelligence processing) is performed on the local server, thereby allowing for a "thin" client (i.e., a computing device with minimal hardware) and optimizing system speed, the subject technology is also intended to include a system that performs data processing and rule processing on the client, thereby freeing the central system or local server from such tasks.

[0038] Each local client or medical device also includes a client application, which may include a graphical user interface (GUI), although this is not required on many medical devices, and a middle-tier program that communicates with the central or local server. The program code of the client application may be executed entirely on the local client, or partially on the local client and partially on the central or local server.

[0039] Computer program code for carrying out operations of the subject technology may be written in an object-oriented programming language, such as Smalltalk or C++. However, the computer program code for performing operations of the subject technology may also be written in a traditional procedural programming language (e.g., the "C" programming language), an interpreted scripting language (e.g., Perl), or a functional (or fourth generation language) programming language (e.g., Lisp, SML, Forth, etc.). The software may also be written to be compatible with HLA-7 requirements.

[0040] Medical devices incorporating aspects of the subject technology may be equipped with a network interface module (NIM) that allows the medical device to participate as a node in a network. Although for clarity, the subject technology will be described as operating in an Ethernet network environment using the Internet Protocol (IP), it should be understood that the concepts of the subject technology are equally applicable to other network environments and such environments are also within the scope of the subject technology.

[0041] All direct communications with medical devices operating on a network according to the subject technology may be performed through a device management server 30, referred to as a remote data server (RDS). According to aspects of the subject technology, a network interface module incorporated into a medical device (e.g., an infusion pump or a vital sign measurement device) ignores all network traffic that is not from an authenticated RDS. The primary responsibility of the subject technology RDS is to track the location and status of all networked medical devices with a NIM and maintain an open communication channel with them.

[0042] Prior to implementation within the institutional patient care system 100, the patient care device 12 may be configured during its manufacture using default network information to allow the device to connect to a designated provisioning service to receive specific configuration information for normal operation within the institutional patient care system 100, including, for example, network information and / or security information for connecting to the network 10 and the device management server 30.

[0043] When patient care devices 12 are received at a medical facility of a medical institution, an administrator can create records for these devices in a database 37 through a terminal device 32. In this regard, each record can include a unique identification (ID) of the corresponding device 12 (e.g., a serial number, a media access control address, a mobile device identifier, a device name, etc.). The unique ID can be affixed to the device (e.g., as a printed label or an RFID tag) or stored in an internal memory and captured by a scanner device such as a barcode reader or an RFID reader device. In some embodiments, a wireless connection (e.g., Bluetooth) can be used to transmit the unique ID. The corresponding record created for the device can map the unique ID to specific configuration information. As further described below, the configuration information and mapping are then provided to a provisioning service, which will be accessed by the device when it is powered on. In some embodiments, the unique ID of the device can be received electronically by the device management server 30, for example, via an external network 203 such as the Internet or other WAN. The device management server 30 can provide a user interface for accepting and / or confirming that the device receives the configuration information before providing the configuration information to the provisioning service 202.

[0044] According to various embodiments, the device management server 30 may be responsible for managing access of the patient-care device 12 to the network system of the institutional patient care system 100, communications between various devices over the network 10, and routine management of the patient-care device 12. In this regard, the device management server 30 may provide a user interface for assigning one or more device identifiers to one or more security certificates via the terminal device 32. Once installed on the patient-care device 12, the security certificate enables the patient-care device to access and communicate with the device management server 30 and / or other devices within the institutional patient care system 100.

[0045] In some embodiments, a user interface provided by the management server can facilitate assigning device identifiers and security certificates to respective facilities within the medical organization. In this regard, configuring the patient-care device 12 to access and communicate with the device management server 30 includes configuring the patient-care device 12 to communicate via the network 10 (or transmission channel 32) within the respective facility using an encrypted security certificate specific to the respective facility.

[0046] Figure 2 Depicted is the flow of information between various elements of an institutional patient care system 100 and a provisioning service 202 in accordance with various aspects of the subject technology. In example step 1, a patient care device 12 is manufactured 201 in a factory or other manufacturing environment 200. The patient care device is manufactured with default network information that allows the device to connect to a provisioning service 202 when it is first powered on. The default network information can be a global default or a default for an intended recipient of the patient care device.

[0047] According to various embodiments, the patient-care device 12 is preconfigured to seek a known SSID (Service Set Identifier for a WiFi network) or other provisioning address (e.g., an IP or IP subnet address) in response to power-on while in use at a medical facility (e.g., within an institutional patient care system 100). The manufacturer or supplier can notify all facilities that will operate the patient-care device to use the provisioning mechanism so that the device will recognize the provisioning mechanism out of the box and be able to communicate with the provisioning service 202 over an external network 203 (e.g., a WAN or the Internet). In some embodiments, the patient-care device will be programmed to connect to the provisioning service using the provisioning address when a network connection is detected, such as when connected to the network 10, WAN, or the Internet (e.g., via an Ethernet or WiFi connection).

[0048] The provisioning service 202 can implement an interface for each medical facility to program its own internal medical network information. The patient care device 12 is preconfigured to turn on and, if local network connection information and credentials have not been previously provided, communicate with the provisioning service 202 through a predetermined provisioning network 42, download information for the corresponding internal medical network, and then reconfigure to connect through the medical network 40 and continue to operate with the internal server of the medical facility (including, for example, the device management server 30) through the medical network 40. Preconfiguration can include setting an activation indicator (e.g., a flag) within the non-volatile storage unit 56 of the patient care device 12, and then the CPU 50 will check the activation indicator (e.g., a flag) at power-on to determine that the activation is an initial activation.

[0049] According to various embodiments, the provisioning service 202 may be implemented by a server external to the medical network 10. For example, the provisioning service may be implemented by software executed on the production service 204 within the manufacturing environment 200. In some embodiments, the provisioning service 202 may be implemented as software executed on the device management server 30. The provisioning service 202 may further implement or be connected to a provisioning database 206.

[0050] Prior to or in parallel with manufacturing the patient care device 12, as shown in step 2, an administrator enters specific configuration information (e.g., using a user interface provided to the terminal device 32) to enable the device to operate within the institutional patient care system 100, including, for example, network information and / or security information for connecting to the network 10 and the device management server 30. The network information can be assigned to a specific facility within the medical institution responsible for the institutional patient care system 100. In addition, the administrator can provide specific predetermined network connection information (e.g., Internet Protocol (IP) address, subnet address, SSID, network password or other connection credentials, etc.) for the provisioning network 42 and the device network 40. Each patient care device 12 can be pre-configured with network information for the provisioning network 42 during the manufacturing process or by a supplier prior to transfer to the medical institution. For example, the patient care device 12 can store predetermined network connection information and identification information that uniquely identifies the patient care device 12 in the non-volatile storage unit 56.

[0051] Steps 3 and 4 are described as being sequential, but may occur in any particular order. In step 3, the unique ID associated with each device is further associated with network information, such as an SSID, security information, IP address, subnet address, DHCP server, DNS server, etc., to which the patient care device can connect during normal operation. This can be accomplished by entering the ID on the terminal device 32, scanning the device itself, or receiving the ID from the manufacturer or supplier of the device in an electronic transmission to the institutional patient care system 100 (e.g., received at the device management server 30). In some embodiments, when the medical institution receives the device ID, the device ID can be assigned to each device (e.g., an assignment of device ID to serial number). The assigned device / unique ID is then available to the provisioning service 202 (e.g., the provisioning database 206). For example, the data can be pushed to the provisioning service 202, or the provisioning service 202 can be integrated with the device management server 30 so that once entered, the provisioning service 202 can look up the information when an indication is received that the data is available.

[0052] In step 4, the medical institution receives the patient care device 12. The supply network 42 is specially configured in advance for the device to connect to the supply service 202 through the network 10 (e.g., outside the medical institution via the external network 203). The supply network can be publicly accessible, can be separate from the hospital's main network, or can include a portion of the hospital's main network (e.g., a subnet). According to the depicted example, each device is configured at the factory (or by the supplier) to connect to the supply network 42 and to the supply service 202. The connection (e.g., within the network 10) can be through Ethernet, WiFi, BLUETOOTH or other network connection. In step 5, the corresponding device is powered on and automatically connected to the supply service 202 via the supply mechanism using a predetermined supply mechanism. For example, when activating the device 12, the device can determine that the activation is an initial activation at the medical facility based at least in part on an activation indicator stored by the device. The device 12 can then establish a network connection with the supply network 42 in response to determining that the activation is an initial activation based at least in part on the predetermined supply network connection information stored in the non-volatile storage unit 56.

[0053] Once connected to the provisioning service 202, the patient-care device 12 can transmit information including the unique ID (e.g., via the provisioning network 42 and the external network 203). The provisioning service 202 (e.g., operating on the server 204) receives the information including the unique ID from the device and determines, based on the received information, that the device is scheduled to receive access to the device management server 30 within the institutional patient care system 100.

[0054] Based on this determination, the provisioning service 202 configures the corresponding patient-care device 12 to access and communicate with the device management server 30 via the temporary provisioning network 42. In this regard, the provisioning service 202 provides the device with specific facility network connection information assigned to the unique ID. The connection information is received by the device 12 for accessing and communicating with the management server 30. Each patient-care device 12 can send its own corresponding device identifier to the management server 30 via the temporary provisioning network 42. The management server 30 determines whether the patient-care device 12 and its device identifier have been pre-determined to receive access to the medical network 40. If the patient-care device 12 is to receive access, the management server 30 can send one or more security certificates to be installed on the patient-care device 12. The management server 30 can also send optional device configuration files, firmware updates, software updates, and / or other security protocols to be installed on the patient-care device 12. The management server 30 can then request confirmation of the configuration from the patient-care device 12 from the provisioning service 202.

[0055] After the device is configured, the provisioning service 202, as shown in step 6, reports the configuration status to the device management server 30. The report can be initiated automatically by the provisioning service 202 or can be provided in response to a request from the device management server 30. Therefore, the device management server 30 can be configured to prevent (e.g., block) the connection and / or communication of the device - even if previously assigned to the network information by the server 30 through the device network 40, until the device management 30 receives confirmation from the provisioning service 202 that the device configuration has been completed. Preventing connection or communication may include dynamically configuring the network hardware (e.g., routers, access points, gateways, etc.) of the medical network 10 to change the connectivity or packet processing associated with the device. Dynamic configuration may include sending control signals to the network hardware or updating configuration information used by the network hardware (e.g., adding an identifier of the device to a block list, updating a network address routing table).

[0056] The management server 30 may also receive an indication that the security certificate has been successfully installed on the requesting patient-care device 12. In some embodiments, if the management server 30 does not receive an indication that the security certificate has been successfully installed, the management server 30 may deny access to the medical network. In some other embodiments, the management server 30 may resend the security certificate for installation.

[0057] Through the temporary provisioning network, the patient care devices 12 can receive access to communicate directly with the management server. In some embodiments, the patient care devices 12 also receive access to the medical network 40. According to various embodiments, once the patient care devices 12 have been properly configured by the provisioning service 202 and are granted access to the medical network 40, the connection to the temporary provisioning network 202 via the provisioning network 42 is terminated. As shown in step 7, the patient care devices 12 can then connect to the device management server 30 (e.g., for the first time) as a fully configured device (e.g., via the network 10). In this regard, each device 12 can establish a completely new and different network connection with the management server 30 using the medical network 40 based at least in part on previously received facility network connection information.

[0058] In some embodiments, during the aforementioned provisioning process, the patient-care device 12 can be configured to identify its location within the patient care system 100 and transmit the location as part of the information transmitted to the provisioning service 202. In this regard, WiFi connection information within the system can be used to detect the location (e.g., mapping the SSID to the location), or the device 12 can include location hardware (e.g., GPS) for identifying specific coordinates, which it can then send to the provisioning service 202. Upon receiving this information, the provisioning service 202 can select a specific server within the network 10 based on the location to which the patient-care device 12 should connect for normal operation, and send configuration information (including, for example, the previously described connection information and / or security credentials, etc.) to the patient-care device 12 specific to the selected server.

[0059] Figure 3 An example process for automatically provisioning medical devices to a medical network according to aspects of the subject technology is depicted. For purposes of explanation, the various blocks of the example process 300 are referred to herein. Figure 1 and 2 As well as the components and / or processes described herein, it is described.One or more blocks of process 300 can be implemented, for example, by one or more computing devices, including, for example, other computing devices in production service 202 and / or production server 204 and / or factory or other manufacturing environment 200. In some embodiments, one or more blocks can be separated from other blocks and implemented by one or more different processors or devices. Further for the purpose of explanation, the blocks of example process 300 are described as continuous or linear occurrence. However, multiple blocks of example process 300 can occur in parallel. In addition, the blocks of example process 300 do not need to be executed in the order shown and / or one or more blocks in the blocks of example process 300 do not need to be executed.

[0060] In the depicted example, one or more medical devices are configured to connect to a predetermined temporary provisioning network of a medical facility when the device is first powered on (302). According to various embodiments, the temporary provisioning network is different from the medical network of the medical facility. The temporary provisioning network can be configured to broadcast a service set identifier (SSID) that is preconfigured to be known to the medical devices, and the medical devices are configured to look for the SSID before being powered on for the first time at the medical facility. In some embodiments, provisioning can be triggered when the device is powered on, a network connection is detected, and the facility connection information of the medical network is unspecified or has expired. If the device determines that the facility connection information does not exist or is no longer valid, the medical device can use the stored provisioning information to connect to the predetermined temporary provisioning network.

[0061] For example, one or more medical devices may be configured by a production server 204 that is different from a management server and outside of a medical institution. The medical device may be configured during the manufacturing process 201 or by a supplier of the device, or in some embodiments of the subject technology, by personnel or systems of the medical institution when the device is received by the medical institution.

[0062] After the medical devices are transferred to and received by the medical institution, one or more device identifiers corresponding to one or more medical devices and an indication that one or more medical devices request access to the medical network are received from the temporary provisioning network 42 at a server remote from the medical institution (304). The remote server may be, for example, a production server 204 or other server implementing the provisioning service 202. According to various aspects, the medical institution creates the temporary provisioning network 42 for the purpose of installing security certificates and / or updating software on various devices 12 to connect the medical devices to the main device network 40. In some embodiments, the device identifier is a serial number of the device, or some other unique identifier associated with the device. The device identifier may be a network address of the corresponding medical device or any other device identifier capable of identifying the device.

[0063] In response to receiving the one or more device identifiers, the provisioning service 202 determines that the received one or more device identifiers correspond to respective medical devices that are scheduled to receive access to the management server within the medical network (306). In this regard, prior to this determination, the production service 202 may receive one or more security certificates assigned to the one or more device identifiers from the device management server 30.

[0064] Based on a determination that the one or more medical devices are scheduled to receive access to the management server, the provisioning service 202 facilitates configuring the medical devices to access and communicate with the management server via the temporary provisioning network 42 (308). This may include, for example, sending (e.g., electronically transmitting) to the one or more medical devices via the temporary provisioning network one or more security credentials for installation on the medical devices to access the management server to configure the medical devices to access and communicate with the management server. This may include transmitting network credentials or configuration information, such as a DNS server, a DHCP server, an IP address, a subnet address, an SSID, an access control list (e.g., a whitelist or a blacklist), etc.

[0065] After configuration is complete, the provisioning service 202 notifies the management server 30 (e.g., by sending an electronic communication to the server 30) that the one or more medical devices have been configured to access and communicate with the management server (310). In some embodiments, a server associated with the provisioning service 202 (e.g., the production server 204) confirms that the one or more medical devices have been configured to access and communicate with the management server.

[0066] In some embodiments, a production server 202 that is distinct from the management server and external to the medical facility configures one or more medical devices. For example, during the manufacture of the medical device, a production server associated with the manufacturing process configures the medical device. In some embodiments, the temporary supply network is configured to broadcast a service set identifier (SSID) that is preconfigured to be known to the medical device, and the medical device is configured to look for the SSID before first powering on. Similarly, the medical device can be preconfigured at the production server to look for the SSID of the temporary supply network. In some embodiments, the temporary supply network is an Ethernet network, and the medical network of the medical facility is a local area network (LAN).

[0067] In some embodiments, the temporary supply network can be a personal area network, such as a ZigBee or Bluetooth compatible network. In this case, the medical device can look for a unique identifier associated with a compatible network. Once the medical device is connected to the personal area network, the medical device can continue to be supplied as described. The personal area network can be managed by a hotspot or other access point device. The hotspot or access point can be carried to the site by a field service technician to facilitate the deployment of the medical device. The hotspot or other access point device can be used as a communication conduit between the medical device and the supply server. Once the supply is completed, the hotspot or access point device can be disabled or removed from the site. It may be necessary to use a personal area temporary supply network to ensure that the medical device is supplied to a geographically limited area (e.g., within the coverage area of ​​a PAN) and allow the hotspot or access point device to communicate with a wider network (e.g., the Internet).

[0068] In some embodiments, the management server is configured to receive an assignment of one or more device identifiers to one or more security certificates via a user interface provided by the management server, and the management server is further configured to provide the one or more security certificates of the one or more medical devices to a supply server outside the medical institution when the medical device is powered on, and to communicate with the one or more medical devices after being informed that the one or more medical devices have been configured to access and communicate with the management server.

[0069] In some embodiments, the management server is configured to receive, via a user interface provided by the management server, an assignment of one or more device identifiers and one or more security certificates to a corresponding facility in a plurality of facilities within the medical institution. Configuring the one or more medical devices to access and communicate with the management server includes configuring the one or more medical devices to communicate via a local network within the corresponding facility. The one or more security certificates are specific to the corresponding facility.

[0070] In some embodiments, the method includes receiving one or more security certificates assigned to one or more device identifiers from a management server, and receiving the one or more security certificates before determining that the received one or more device identifiers correspond to respective medical devices that are scheduled to receive access to the management server. The method also includes sending one or more security certificates for installation on the medical devices to access the management server to the one or more medical devices via a temporary provisioning network to configure the medical devices to access and communicate with the management server. In some embodiments, the one or more medical devices include an infusion device, a ventilator device, or an automatic dispensing device.

[0071] In some embodiments, configuring the medical device to access and communicate with the management server includes downloading one or more security certificates, installing the one or more security certificates, verifying that the security certificates have been successfully installed, and determining that security standards of the medical network have been met.

[0072] In some embodiments, configuring the medical device includes receiving an indication that the medical device has been successfully configured to access and communicate with the management server, and terminating network access of the medical device to the predetermined temporary provisioning network.

[0073] If it is determined that one or more medical devices are not indicated as being scheduled to receive access to the medical network and the management server, the server may not grant access to the medical network.

[0074] In some embodiments, functions can be implemented to securely control medical devices. For example, facility network configuration information or certificates can be associated with an expiration time. The expiration time can be set as part of the provisioning process. In some embodiments, the device management server can send a message to revoke or expire connection information globally or for a specific device. In some embodiments, the medical device can be reset to the factory default configuration, for example by activating a physical control (e.g., a button) on the medical device. In this case, the medical device can determine that the facility network configuration is expired or unspecified when it is powered on. Based on such a determination, the medical device can initiate a connection to a temporary provisioning network to obtain the facility network configuration. This allows the facility to disable access to the facility network for devices that may have been stolen. A user can access the device management server to specify an identifier for a lost device. The lost message can be transmitted to the provisioning server to prevent subsequent provisioning of the identifier. These functions can be used to disable recalled or maintenance-required devices before further use. For example, a manufacturer of a medical device can provide a list of identifiers for recalled devices.

[0075] The supply server can be configured to compare the unique identifier of the received medical device with a list of identifiers of stolen or recalled devices. If the request includes an identifier included in the list, the supply server can send a message to the requesting device indicating an associated condition that blocks the supply (e.g., the device is disabled, the device requires maintenance, the device is recalled, etc.). If the condition that blocks the supply is that the facility has not yet transmitted network information of the unique identifier, the supply server can, in response to receiving a request from the medical device, transmit a message indicating that no site-specific information is provided to supply the medical device associated with the identifier. The supply server can be integrated with a transaction data store to identify a point of contact for a user responsible for the medical device. In such an embodiment, the supply server can cause a message to be transmitted to the user indicating that information indicating that a specific medical device needs to be supplied.

[0076] Many of the above examples 300 and related features and applications may also be implemented as a software process designated as a set of instructions recorded on a computer-readable storage medium (also referred to as a computer-readable medium) and may be executed automatically (e.g., without user intervention). When these instructions are executed by one or more processing units (e.g., one or more processors, processor cores, or other processing units), they cause the processing units to perform the actions indicated in the instructions. Examples of computer-readable media include, but are not limited to, CD-ROMs, flash drives, RAM chips, hard drives, EPROMs, and the like. Computer-readable media do not include carrier waves and electronic signals transmitted wirelessly or via wired connections.

[0077] Where appropriate, the term "software" is intended to include firmware residing in read-only memory or application programs stored in magnetic storage that can be read into memory for processing by a processor. In addition, in some embodiments, multiple software aspects of the present disclosure can be implemented as sub-parts of a larger program while retaining different software aspects of the present disclosure. In some embodiments, multiple software aspects can also be implemented as separate programs. Finally, any combination of separate programs that together implement the software aspects described herein are within the scope of the present subject disclosure. In some embodiments, the software program, when installed to run on one or more electronic systems, defines one or more specific machine implementations for executing and performing the operations of the software program.

[0078] A computer program (also referred to as a program, software, software application, script, or code) may be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but need not, correspond to a file in a file system. A program may be stored as part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program, or in multiple coordinated files (e.g., files that store one or more modules, subroutines, or portions of code). A computer program may be deployed for execution on a single computer or on multiple computers located at a single site or distributed across multiple sites and interconnected by a communications network.

[0079] Figure 4 4 is a conceptual diagram illustrating an example electronic system 400 for automatic provisioning of medical devices according to aspects of the subject technology. The electronic system 400 may be a computer program product for performing one or more portions or steps of the process 400 or Figure 1-3 The components and processes associated with the software provided are provided on a computing device, including but not limited to a device management server 30, a production server 204, computing hardware within a patient care device 12, or a terminal device 37. Figure 1-3 4. The electronic system 400 may be representative of the disclosure of the present invention. In this regard, the electronic system 400 may be a personal computer or a mobile device such as a smart phone, a tablet computer, a laptop computer, a PDA, an augmented reality device, a wearable device such as a watch or a band or glasses, or a combination thereof, or a touch screen or a television in which one or more processors are embedded or coupled thereto, or any other type of computer-related electronic device with network connectivity.

[0080] The electronic system 400 may include various types of computer-readable media and interfaces for various other types of computer-readable media. In the depicted example, the electronic system 400 includes a bus 408, a processing unit 412, a system memory 404, a read-only memory (ROM) 410, a permanent storage device 402, an input device interface 614, an output device interface 406, and one or more network interfaces 416. In some implementations, the electronic system 400 may include or be integrated with other computing devices or circuits for operating the various components and processes previously described.

[0081] The bus 408 is collectively referred to as all system, peripheral, and chipset buses that communicatively connect the numerous internal devices of the electronic system 400. For example, the bus 408 communicatively connects the processing unit 412 with the ROM 410, the system memory 404, and the permanent storage device 402.

[0082] From these various memory units, processing unit 412 retrieves instructions to execute and data to process in order to perform the processes of the subject disclosure. In various implementations, the processing unit may be a single processor or a multi-core processor.

[0083] ROM 410 stores static data and instructions required by processing unit 412 and other modules of the electronic system. On the other hand, permanent storage device 402 is a read-write memory device. This device is a non-volatile memory unit that can store instructions and data even when electronic system 400 is turned off. Some embodiments of the subject disclosure use a mass storage device (such as a magnetic disk or optical disk and its corresponding disk drive) as permanent storage device 402.

[0084] Other implementations use removable storage devices (e.g., floppy disks, flash drives, and their corresponding disk drives) as permanent storage devices 402. Similar to permanent storage devices 402, system memory 404 is a read-write memory device. However, unlike storage devices 402, system memory 404 is a volatile read-write memory, such as random access memory. System memory 404 stores some instructions and data that the processor needs at runtime. In some embodiments, the processes of the present disclosure are stored in system memory 404, permanent storage devices 402, and / or ROM 410. From these different memory units, processing unit 412 retrieves instructions to be executed and data to be processed in order to perform the processes of some embodiments.

[0085] The bus 408 is also connected to input and output device interfaces 414 and 406. The input device interface 414 enables a user to transmit information and select commands to the electronic system. Input devices used with the input device interface 414 include, for example, an alphanumeric keyboard and a pointing device (also referred to as a "cursor control device"). For example, the output device interface 406 can display images generated by the electronic system 400. Output devices used with the output device interface 406 include, for example, a printer and a display device, such as a cathode ray tube (CRT) or a liquid crystal display (LCD). Some embodiments include devices used as input and output devices, such as a touch screen.

[0086] In addition, if Figure 4As shown, bus 408 also couples electronic system 400 to a network (not shown) via network interface 416. Network interface 416 may include, for example, a wireless access point (e.g., Bluetooth or WiFi) or a radio circuit for connecting to a wireless access point. Network interface 416 may also include hardware (e.g., Ethernet hardware) for connecting a computer to a portion of a computer network (e.g., a local area network ("LAN"), a wide area network ("WAN"), a wireless local area network or intranet, or a network of networks, such as the Internet). Any or all components of electronic system 400 may be used in conjunction with the subject disclosure. .

[0087] These functions can be implemented in computer software, firmware or hardware. One or more computer program products can be used to implement these techniques. Programmable processors and computers can be included in or packaged as mobile devices. Processes and logic flows can be performed by one or more programmable processors and one or more programmable logic circuits. General and special computing devices and storage devices can be interconnected through communication networks.

[0088] Some embodiments include electronic components, such as microprocessors, memory, and storage, which store computer program instructions in machine-readable or computer-readable media (also referred to as computer-readable storage media, machine-readable media, or machine-readable storage media). Some examples of such computer-readable media include RAM, ROM, compact disk-read only (CD-ROM), compact disk-recordable (CD-R), compact disk-rewritable (CD-RW), read-only digital versatile disk (e.g., DVD-ROM, dual-layer DVD-ROM), various recordable / rewritable DVDs (e.g., DVD-RAM, DVD-RW, DVD+RW, etc.), flash memory (e.g., SD card, mini-SD card, micro SD card, etc.), magnetic and / or solid-state hard drives, read-only and recordable A compact disc, an ultra-density compact disc, any other optical or magnetic medium, and a floppy disk. A computer readable medium may store a computer program that is executable by at least one processing unit and includes a set of instructions for performing various operations. Examples of computer programs or computer codes include machine code, such as produced by a compiler, and files including high-level code that is executed by a computer, an electronic component, or a microprocessor using an interpreter.

[0089] Although the above discussion refers primarily to microprocessors or multi-core processors that execute software, some implementations are performed by one or more integrated circuits, such as application specific integrated circuits (ASICs) or field programmable gate arrays (FPGAs). In some implementations, such integrated circuits execute instructions stored on the circuits themselves.

[0090] The terms "computer," "server," "processor," and "memory" as used in this specification and any claims of this application refer to electronic or other technical devices. These terms do not include people or groups of people. For the purposes of this specification, the term display means display on an electronic device. As used in this specification and any claims of this application, the terms "computer-readable medium" and "computer-readable media" are entirely limited to tangible physical objects that store information in a computer-readable form. These terms do not include any wireless signals, wired download signals, and any other temporary signals.

[0091] To provide for interaction with a user, embodiments of the subject matter described in this specification may be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user, as well as a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices may also be used to provide for interaction with a user; for example, feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback; and input from the user may be received in any form, including acoustic, voice, or tactile input. In addition, a computer may interact with a user by sending documents to and receiving documents from a device used by the user; for example, sending a web page to a web browser on a user's client device in response to a request received from the web browser.

[0092] Embodiments of the subject matter described in this specification may be implemented in a computing system that includes a back-end component, e.g., as a data server, or includes a middleware component, e.g., an application server, or includes a front-end component, e.g., a client computer with a graphical user interface or a web browser through which a user can interact with embodiments of the subject matter described in this specification, or any combination of one or more such back-end, middleware, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include local area networks ("LANs") and wide area networks ("WANs"), interconnected networks (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks).

[0093] A computing system may include a client and a server. The client and the server are usually remote from each other and may interact via a communication network. The relationship between the client and the server is generated by means of a computer program running on each computer, and has a client-server relationship with each other. In some embodiments, the server transmits data (e.g., an HTML page) to a client device (e.g., for the purpose of displaying data to a user interacting with the client device and receiving user input from a user interacting with the client device). Data generated at the client device (e.g., a result of a user interaction) may be received from the client device at the server.

[0094] Those skilled in the art will appreciate that the various illustrative blocks, modules, elements, components, methods and algorithms described herein can be implemented as electronic hardware, computer software or a combination of the two. In order to illustrate this interchangeability of hardware and software, various illustrative blocks, modules, elements, components, methods and algorithms have been generally described above according to their functions. Whether this function is implemented as hardware or software depends on the specific application and the design constraints imposed on the entire system. The described functions can be implemented in different ways for each specific application. Without departing from the scope of the subject technology, various components and blocks can be arranged differently (e.g., arranged in different orders, or divided in different ways).

[0095] It should be understood that the specific order or hierarchy of steps in the disclosed processes is an illustration of example methods. Based on design preferences, it is understood that the specific order or hierarchy of steps in the process can be rearranged. Some steps can be performed simultaneously. The accompanying method claims present elements of the various steps in an example order and are not meant to be limited to the specific order or hierarchy presented.

[0096] The previous description is provided to enable any person skilled in the art to practice the various aspects described herein. The foregoing description provides various examples of the subject technology, and the subject technology is not limited to these examples. Various modifications to these aspects will be apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects. Therefore, the claims are not intended to be limited to the aspects shown herein, but to the full scope consistent with the language claims, wherein, unless otherwise specified, references to singular elements do not mean "one and only one", but "one or more". Unless otherwise specifically stated, the term "some" refers to one or more. Positive pronouns (e.g., he) include negative and neuter (e.g., she and it), and vice versa. Titles and subtitles (if any) are used for convenience only and do not limit the invention described herein.

[0097] As used herein, the term "website" may include any aspect of a website, including one or more web pages, one or more servers for hosting or storing web-related content, and the like. Thus, the term "website" may be used interchangeably with the terms "web page" and "server." The predicate words "configured to," "operable to," and "programmed to" do not imply any specific tangible or intangible modification to the subject matter, but are intended to be used interchangeably. For example, a processor configured to monitor and control an operation or component may also refer to a processor programmed to monitor and control an operation or a processor operable to monitor and control an operation. Similarly, a processor configured to execute code may be interpreted as a processor programmed to execute code or operable to execute code.

[0098] The term "automatically" as used herein may include the performance of a computer or machine without user intervention; for example, by responding to instructions of a predicate action of the computer or machine or other initiating mechanism. The word "exemplary" as used herein means "serving as an example or illustration." Any aspect or design described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other aspects or designs.

[0099] Phrases such as "aspects" do not imply that the aspect is essential to the subject technology or that the aspect applies to all configurations of the subject technology. Disclosures related to an aspect may apply to all configurations, or one or more configurations. An aspect may provide one or more examples. Phrases such as "aspects" may refer to one or more aspects, and vice versa. Phrases such as "embodiments" do not imply that such embodiments are essential to the subject technology or that such embodiments apply to all configurations of the subject technology. Disclosures related to embodiments may apply to all embodiments, or one or more embodiments. An embodiment may provide one or more examples. Phrases such as "embodiments" may refer to one or more embodiments, and vice versa. Phrases such as "configurations" do not imply that such configurations are essential to the subject technology or that such configurations apply to all configurations of the subject technology. Disclosures related to configurations may apply to all configurations, or one or more configurations. A configuration may provide one or more examples. Phrases such as "configurations" may refer to one or more configurations, and vice versa.

Claims

1. A method comprising: in response to one or more medical devices being powered on for the first time by the medical facility, configuring the one or more medical devices to connect to a predetermined temporary provisioning network, the temporary provisioning network being distinct from a medical network of the medical facility, wherein the temporary provisioning network is publicly accessible and separate from the medical network while maintaining protection of the medical network from unauthorized access; receiving, at a server remote from the medical facility, from the temporary provisioning network one or more device identifiers corresponding to the one or more medical devices and an indication that the one or more medical devices request access to the medical network; based on receiving the one or more device identifiers, determining that the received one or more device identifiers correspond to respective medical devices that are predetermined to receive access to a management server within the medical network; Based on determining that the one or more medical devices are scheduled to receive access to the management server: Through the temporary provisioning network, configuring information for the one or more medical devices to access the medical network, and communicating with the management server on the medical network using a new network connection based on the configured information; as well as terminating communications between the one or more medical devices and the temporary provisioning network, and An electronic signal is sent to notify the management server that the one or more medical devices have been configured to access and communicate with the management server, wherein configuring the one or more medical devices to connect to a predetermined temporary supply network is performed by a production server that is different from the management server and outside the medical institution.

2. The method of claim 1, wherein configuring the one or more medical devices to connect to the predetermined temporary provisioning network is performed by a production server that is different from the management server and is coupled to the medical institution via a network external to the medical institution.

3. The method of claim 1, wherein the temporary provisioning network is configured to broadcast a service set identifier (SSID) that is preconfigured to be known by the medical device, and the medical device is configured to look for the SSID prior to first powering on.

4. The method according to claim 1, further comprising: receiving, from a credential server, one or more security credentials assigned to the one or more device identifiers, the one or more security credentials being received prior to determining that the received one or more device identifiers correspond to respective medical devices that are predetermined to receive access to the management server; and One or more security certificates for installation on the medical devices to access the management server are sent to the one or more medical devices through the temporary provisioning network to configure the medical devices to access and communicate with the management server.

5. The method according to claim 4, wherein the management server is configured to receive the assignment of the one or more device identifiers to the one or more security certificates via a user interface provided by the management server, and the management server is further configured to provide the one or more security certificates of the one or more medical devices to a supply server outside the medical institution when the medical device is powered on; and communicate with the one or more medical devices after being informed that the one or more medical devices have been configured to access and communicate with the management server.

6. The method according to claim 5, wherein the management server is configured to receive, through a user interface provided by the management server, an assignment of the one or more device identifiers and the one or more security certificates to corresponding facilities among a plurality of facilities within the medical institution, and wherein, Configuring the one or more medical devices to access and communicate with the management server includes configuring the one or more medical devices to communicate via a local network within the respective facility, wherein the one or more security certificates are specific to the respective facility. The method of claim 1 , wherein the one or more device identifiers are network addresses of corresponding medical devices.

8. The method of claim 1, wherein the indication that the one or more medical devices request access to a medical network is received by the management server when the medical devices are powered on.

9. The method of claim 1, wherein the one or more medical devices include an infusion device, a ventilator device, a drug dispensing device, a drug preparation device, or an automatic dispensing device, or a device coupled to an infusion device, a ventilator device, a drug dispensing device, a drug preparation device, or an automatic dispensing device.

10. The method of claim 4, wherein configuring the medical device to access and communicate with a management server further comprises: transmitting one or more security credentials to the medical device; installing the one or more security certificates on the medical device; Verifying, by the medical device, that the security certificate has been successfully installed; and A message is sent to a server remote from the medical institution indicating that the security standards of the medical network have been met.

11. The method of claim 1 , wherein configuring the medical device further comprises: receiving an indication that the medical device has been successfully configured to access and communicate with the management server; and The network access of the medical device to the predetermined temporary provisioning network is terminated.

12. A non-transitory machine-readable storage medium embodying instructions that, when executed by a machine, allow the machine to perform a method for automatic network provisioning, the method comprising: in response to one or more medical devices being powered on for the first time, configuring the one or more medical devices to connect to a predetermined temporary provisioning network, the temporary provisioning network being distinct from a medical network of a medical facility, wherein the temporary provisioning network is publicly accessible and separate from the medical network while maintaining protection of the medical network from unauthorized access; receiving, from the temporary provisioning network, one or more device identifiers corresponding to the one or more medical devices and an indication that the one or more medical devices request access to the medical network; based on receiving the one or more device identifiers, determining that the received one or more device identifiers correspond to respective medical devices that are predetermined to receive access to a management server within the medical network; Based on determining that the one or more medical devices are scheduled to receive access to the medical network and the management server: configuring information for accessing the medical network for the medical device through the temporary provisioning network, and communicating with the management server on the medical network using a new network connection based on the configured information, and Providing confirmation to the management server that the one or more medical devices have been configured to access and communicate with the management server, wherein configuring the one or more medical devices to connect to the predetermined temporary provisioning network is performed by a production server different from the management server and outside the medical institution.

13. The machine-readable storage medium of claim 12, wherein configuring the one or more medical devices to connect to the predetermined temporary provisioning network is performed by a production server that is distinct from the management server and external to the medical institution.

14. The machine-readable storage medium of claim 12, wherein the temporary provisioning network is configured to broadcast a service set identifier (SSID) that is preconfigured to be known by the medical device, and the medical device is configured to look for the SSID prior to first powering on.

15. The machine-readable storage medium of claim 12, further comprising: receiving one or more security credentials assigned to the one or more device identifiers, the one or more security credentials being received prior to determining that the received one or more device identifiers correspond to respective medical devices that are predetermined to receive access to the management server; and One or more security credentials for installation on the medical device to access the management server are sent to configure the medical device to access and communicate with the management server.

16. A machine-readable storage medium according to claim 15, wherein the management server is configured to receive the assignment of the one or more device identifiers to the one or more security certificates via a user interface provided by the management server, and the management server is further configured to provide the one or more security certificates of the one or more medical devices to a supply server outside the medical institution when the medical device is powered on, and to communicate with the one or more medical devices after being informed that the one or more medical devices have been configured to access and communicate with the management server.

17. The machine-readable storage medium of claim 16, wherein the management server is configured to receive, through a user interface provided by the management server, assignment of the one or more device identifiers and the one or more security certificates to corresponding facilities among a plurality of facilities within the medical institution, and wherein, Configuring the one or more medical devices to access and communicate with the management server includes configuring the one or more medical devices to communicate via a local network within the respective facility, wherein the one or more security certificates are specific to the respective facility.

18. The machine-readable storage medium of claim 15, wherein configuring the medical device to access and communicate with a management server further comprises: downloading the one or more security certificates; installing the one or more security certificates; Verifying that the security certificate has been successfully installed; and Verify that security standards for healthcare networks are met.

19. The machine-readable storage medium of claim 12, wherein the one or more device identifiers are network addresses of corresponding medical devices.

20. The machine-readable storage medium of claim 12, wherein the indication that the one or more medical devices request access to a medical network is received by the management server when the medical devices are powered on.

21. The machine-readable storage medium of claim 12, wherein configuring the medical device further comprises: receiving an indication that the medical device has been successfully configured to access and communicate with the management server; and The predetermined temporary supply network is terminated.

22. A system comprising: one or more processors; as well as A memory comprising instructions that, when executed by one or more processors, cause the one or more processors to: in response to one or more medical devices being powered on for the first time, configuring the one or more medical devices to connect to a predetermined temporary provisioning network, the temporary provisioning network being distinct from a medical network of a medical facility, wherein the temporary provisioning network is publicly accessible and separate from the medical network while maintaining protection of the medical network from unauthorized access; receiving, from the temporary provisioning network, one or more device identifiers corresponding to the one or more medical devices and an indication that the one or more medical devices request access to the medical network; based on receiving the one or more device identifiers, determining that the received one or more device identifiers correspond to respective medical devices that are predetermined to receive access to a management server within the medical network; Based on determining that the one or more medical devices are scheduled to receive access to the medical network and the management server: configuring information for accessing the medical network for the one or more medical devices through the temporary supply network, and communicating with the management server on the medical network using a new network connection based on the configured information, wherein configuring the one or more medical devices to connect to the predetermined temporary supply network is performed by a production server different from the management server and outside the medical institution, and A confirmation is provided to the management server that the one or more medical devices have been configured to access and communicate with the management server.

23. A medical device comprising: a non-volatile data storage unit storing (a) predetermined supply network connection information and (b) identification information uniquely identifying the medical device; one or more processors; and A memory comprising instructions that, when executed by one or more processors, cause the one or more processors to: upon activating the medical device, determining that the activation is an initial activation at a medical facility based at least in part on an activation indicator stored by the medical device; In response to determining that the activation is an initial activation, establishing a first network connection with a supply network based at least in part on the predetermined supply network connection information; transmitting, via the first network connection, the identification information that uniquely identifies the medical device; receiving, via the first network connection, facility network connection information for accessing a second network different from the supply network and communicating with a management server associated with the medical facility, wherein the facility network connection information is received from a production server different from the management server and external to the medical facility, the supply network being publicly accessible and separate from the main network so that the main network remains protected from unauthorized access; terminating a first network connection with the supply network; and After receiving the facility network connection information and after terminating the first network connection, a second network connection is established with the management server based at least in part on the facility network connection information.

24. The medical device of claim 23, wherein the provisioning network connection information comprises a service set identifier (SSID), and wherein establishing the first network connection comprises wirelessly scanning for broadcast messages comprising the SSID.

25. The medical device of claim 23, wherein the facility network connection information includes a security credential, and wherein establishing the second network connection is also based at least in part on the security credential.

26. The medical device of claim 23, wherein the memory includes instructions further causing the one or more processors to close the first network connection when the second network connection is established.

Citation Information

Patent Citations

  • Modular patient care system

    US5713856A

  • Securely joining a secure wireless communications network

    CN104685851A

  • Automatic configuration method and system for medical devices

    US20100138523A1