Bluetooth connection method for portable medical device and computer device

By generating and verifying digital signatures, the problem of low security in Bluetooth connections for portable medical devices is solved, enabling authentication and connection of legitimate clients and preventing unauthorized devices from accessing the network.

CN116961934BActive Publication Date: 2026-07-21WUHAN UNITED IMAGING HEALTHCARE SURGICAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WUHAN UNITED IMAGING HEALTHCARE SURGICAL TECH CO LTD
Filing Date
2022-04-14
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Bluetooth connections for portable medical devices have low security, and unauthorized devices can easily impersonate clients to establish connections with the devices.

Method used

The client key is obtained by sending encrypted information from the client. A digital signature is generated based on the pairing code and the client identifier. The signature is then verified using a pre-set digital certificate to establish a legitimate connection.

Benefits of technology

Improved Bluetooth connectivity security for portable medical devices, ensuring that only legitimate clients can connect to the device and preventing attacks from unauthorized devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116961934B_ABST
    Figure CN116961934B_ABST
Patent Text Reader

Abstract

The application relates to a Bluetooth connection method of a portable medical device and a computer device. The method comprises the following steps: a client acquires a pairing code broadcasted by the portable medical device through Bluetooth, encrypts the pairing code to obtain encrypted information, and sends the encrypted information to a server; the server searches for a client key according to a client identifier carried by the encrypted information, decrypts the encrypted information based on the client key to obtain the pairing code, generates a digital signature based on the pairing code and the client identifier, and sends the digital signature to the client; the client sends the digital signature to the portable medical device; the portable medical device verifies the digital signature according to a preset digital certificate, and establishes Bluetooth connection between the portable medical device and the client after verification. The method can improve the security of Bluetooth connection of the portable medical device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology for portable medical devices, and in particular to Bluetooth connection methods and computer equipment for portable medical devices. Background Technology

[0002] Bluetooth is a wireless technology that enables short-range communication between devices, allowing for wireless information exchange between numerous devices. Bluetooth technology effectively simplifies communication between devices and between devices and the Internet, making data transmission faster and more efficient.

[0003] The client can connect to portable medical devices via Bluetooth. Currently, most portable medical devices have simple functions. The way the client establishes a Bluetooth connection with the portable medical device is: the portable medical device sends a Bluetooth broadcast. Any client that receives the Bluetooth broadcast can establish a Bluetooth connection with the portable medical device. Therefore, unauthorized devices can easily simulate the client to establish a Bluetooth connection with the portable medical device, resulting in low security of the Bluetooth connection of the portable medical device. Summary of the Invention

[0004] Therefore, it is necessary to provide a Bluetooth connection method and computer device for portable medical devices that can improve the security of Bluetooth connections for portable medical devices, addressing the aforementioned technical problems.

[0005] Firstly, this application provides a Bluetooth connection method for a portable medical device. The method includes:

[0006] The client receives encrypted information and searches for the client key based on the client identifier carried in the encrypted information. The encrypted information is obtained by the client through Bluetooth broadcasting and encrypting the pairing code. The pairing code is sent by the portable medical device through Bluetooth broadcasting.

[0007] The encrypted information is decrypted based on the client key to obtain the pairing code;

[0008] A digital signature is generated based on the pairing code and the client identifier, and the digital signature is sent to the client so that the client sends the digital signature to the portable medical device so that the portable medical device verifies the digital signature based on a pre-set digital certificate, and establishes a Bluetooth connection between the portable medical device and the client after successful verification.

[0009] In one embodiment, generating a digital signature based on the pairing code and the client identifier includes:

[0010] Locate the portable medical device identifier associated with the client identifier;

[0011] Find the private key associated with the portable medical device identifier, and encrypt the pairing code based on the found private key to obtain a digital signature.

[0012] In one embodiment, before obtaining the encrypted information sent by the client, the method further includes:

[0013] Obtain the authentication request sent by the client, and obtain the portable medical device identifier and client identifier carried in the authentication request;

[0014] If the portable medical device corresponding to the portable medical device identifier is not in a bound state, a client key is generated based on the portable medical device identifier and the client identifier, and the client key, the portable medical device identifier, and the client identifier are associated and saved.

[0015] In one embodiment, if the portable medical device corresponding to the portable medical device identifier is not in a bound state, generating a client key based on the portable medical device identifier and the client identifier includes:

[0016] Locate the client identifier associated with the portable medical device identifier;

[0017] If not found, it is determined that the portable medical device corresponding to the portable medical device identifier is not in a bound state, and a client key is generated based on the portable medical device identifier and the client identifier.

[0018] In one embodiment, before obtaining the authentication request sent by the client, the method further includes:

[0019] Obtain the portable medical device identifier of the portable medical device, generate the public key and private key of the portable medical device, and associate and save the private key and the portable medical device identifier;

[0020] A digital certificate is generated based on the portable medical device identifier and the public key.

[0021] Secondly, this application provides a Bluetooth connection method for a portable medical device. The method includes:

[0022] The pairing code is obtained via Bluetooth broadcast, encrypted to obtain encrypted information, and sent to the server so that the server can find the client key based on the client identifier carried in the encrypted information, decrypt the encrypted information based on the client key to obtain the pairing code, generate a digital signature based on the pairing code and the client identifier, and send the digital signature to the client. The pairing code is sent by the portable medical device via Bluetooth broadcast.

[0023] The system obtains the digital signature sent by the server, sends the digital signature to the portable medical device, so that the portable medical device can verify the digital signature based on a pre-set digital certificate, and establishes a Bluetooth connection between the portable medical device and the client after successful verification.

[0024] In one embodiment, prior to obtaining the pairing code via Bluetooth broadcast, the method further includes:

[0025] Obtain the portable medical device identifier of the portable medical device, and generate a client key based on the client identifier and the portable medical device identifier;

[0026] An authentication request is sent to the server so that the server can obtain the portable medical device identifier and client identifier carried in the authentication request. If the portable medical device corresponding to the portable medical device identifier is not in a bound state, a client key is generated based on the portable medical device identifier and the client identifier, and the client key, the portable medical device identifier and the client identifier are associated and stored.

[0027] In one embodiment, encrypting the pairing code to obtain encrypted information includes:

[0028] The pairing code is encrypted using the client key to obtain encrypted information.

[0029] Thirdly, this application provides a Bluetooth connection method for a portable medical device. The method includes:

[0030] A pairing code is broadcast via Bluetooth so that the client can obtain the pairing code, encrypt the pairing code to obtain encrypted information, and send the encrypted information to the server so that the server can find the client key based on the client identifier carried in the encrypted information, decrypt the encrypted information based on the client key to obtain the pairing code, generate a digital signature based on the pairing code and the client identifier, and send the digital signature to the client.

[0031] The device obtains the digital signature sent by the client, verifies the digital signature based on a pre-set digital certificate, and establishes a Bluetooth connection between the portable medical device and the client after successful verification.

[0032] In one embodiment, the step of verifying the digital signature based on a pre-set digital certificate and establishing a Bluetooth connection between the portable medical device and the client after successful verification includes:

[0033] The digital signature is decrypted using the pre-set digital certificate and the pairing code. If the decryption is successful, a Bluetooth connection is established between the portable medical device and the client corresponding to the client identifier.

[0034] Fourthly, this application provides a Bluetooth connection system. The system includes: a portable medical device, a client, and a server;

[0035] The portable medical device is used to broadcast a pairing code via Bluetooth.

[0036] The client is configured to obtain a pairing code via Bluetooth broadcast, encrypt the pairing code to obtain encrypted information, and send the encrypted information to the server.

[0037] The server is configured to obtain encrypted information sent by the client, find the client key based on the client identifier carried in the encrypted information, decrypt the encrypted information based on the client key to obtain the pairing code, generate a digital signature based on the pairing code and the client identifier, and send the digital signature to the client.

[0038] The client is also used to obtain the digital signature sent by the server and send the digital signature to the portable medical device;

[0039] The portable medical device is also used to obtain the digital signature sent by the client, verify the digital signature based on a pre-set digital certificate, and establish a Bluetooth connection between the portable medical device and the client after successful verification.

[0040] Fifthly, this application also provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps executed by the server, the client, or the portable medical device in the Bluetooth connection method for a portable medical device described above.

[0041] Sixthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the steps executed by the server, the client, or the portable medical device in the Bluetooth connection method for a portable medical device described above.

[0042] Seventhly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps executed by the server, the client, or the portable medical device in the Bluetooth connection method for a portable medical device described above.

[0043] The Bluetooth connection method for the aforementioned portable medical device involves the portable medical device broadcasting a pairing code via Bluetooth. The client obtains the pairing code via Bluetooth broadcast, encrypts the obtained pairing code using its client key, and sends the encrypted information to the server. The server searches for the client key corresponding to the client identifier, decrypts the encrypted information using the found client key, and obtains the pairing code. The server generates a digital signature based on the pairing code and the client identifier, and sends the digital signature to the client. The client sends the digital signature to the portable medical device, which verifies the digital signature using a pre-set digital certificate. After successful verification, a Bluetooth connection is established between the portable medical device and the client. Only when the client has completed authentication with the server can the server find the client key corresponding to the client identifier and send the digital signature to the client. If an unauthorized device obtains the pairing code, the server cannot find the key corresponding to the unauthorized device's identifier, and therefore the unauthorized device cannot obtain the digital signature sent by the server. If an unauthorized device forges a digital signature and sends the forged digital signature to the portable medical device, the forged digital signature cannot pass the verification of the digital certificate, and therefore the unauthorized device cannot connect to the portable medical device via Bluetooth. The above-described Bluetooth connection method for portable medical devices ensures that only legitimate clients can connect to the portable medical devices via Bluetooth, thus improving the security of Bluetooth connections for portable medical devices. Attached Figure Description

[0044] Figure 1 This is a schematic diagram of a Bluetooth connection system in one embodiment;

[0045] Figure 2 This is a flowchart illustrating a Bluetooth connection method for a portable medical device in one embodiment.

[0046] Figure 3 This is a flowchart illustrating the Bluetooth connection method of a portable medical device when the portable medical device is an insulin pump, as shown in one embodiment.

[0047] Figure 4 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0048] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0049] The Bluetooth connection method for portable medical devices provided in this application embodiment can be applied to, for example... Figure 1The Bluetooth connection system shown includes a portable medical device 102, a client 104, and a server 106. The portable medical device 102 sends a pairing code via Bluetooth broadcast. The client 104 obtains the pairing code via Bluetooth broadcast, encrypts the pairing code to obtain encrypted information, and sends the encrypted information to the server 106. The server 106 obtains the encrypted information sent by the client 104, finds the client key based on the client identifier carried in the encrypted information, and decrypts the encrypted information based on the client key to obtain the pairing code. It generates a digital signature based on the pairing code and the client identifier and sends the digital signature to the client 104. The client 104 obtains the digital signature sent by the server 106 and sends the digital signature to the portable medical device 102. The portable medical device 102 obtains the digital signature sent by the client 104, verifies the digital signature according to a pre-set digital certificate, and establishes a Bluetooth connection between the portable medical device 102 and the client 104 after successful verification. Among them, portable medical device 102 is a medical device that supports Bluetooth technology, and may be, but is not limited to, an insulin pump; client 104 may be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. Portable wearable devices may include smartwatches, smart bracelets, head-mounted devices, etc.; server 106 can be implemented using a standalone server or a server cluster composed of multiple servers.

[0050] In one embodiment, such as Figure 2 As shown, a Bluetooth connection method for a portable medical device is provided, which can be applied to... Figure 1 The following steps are used as an example of a Bluetooth connection system:

[0051] S201. Portable medical devices send pairing codes via Bluetooth broadcast.

[0052] Among them, portable medical devices support Bluetooth technology, including but not limited to Bluetooth 1.0 to Bluetooth 5.0. Bluetooth 4.0 includes three Bluetooth technologies: classic Bluetooth, high-speed Bluetooth, and Bluetooth Low Energy (BLE). Bluetooth Low Energy (BLE) has ultra-low operating power consumption and standby power consumption, as well as low cost, backward compatibility, and strong cross-vendor interoperability.

[0053] Bluetooth broadcasting is a broadcast sent by a portable medical device via Bluetooth. Bluetooth broadcasting can be a low-power Bluetooth broadcast sent by the portable medical device via BLE. The pairing code can be a Universally Unique Identifier (UUID), which is different for the same device at different times; the pairing code can also be multiple randomly generated random numbers, for example, using a randomly generated random number of 4 digits or more as the pairing code.

[0054] Specifically, the portable medical device generates a pairing code and periodically sends broadcast data, including the pairing code, from the broadcast channel via Bluetooth.

[0055] S202. The client obtains the pairing code via Bluetooth broadcast, encrypts the pairing code to obtain encrypted information, and sends the encrypted information to the server.

[0056] Specifically, the client supports Bluetooth technology, including but not limited to Bluetooth versions 1.0 to 5.0, and Bluetooth broadcasting can be low-power Bluetooth broadcasts sent by portable medical devices via BLE.

[0057] The client enables Bluetooth to receive Bluetooth broadcasts within its communication range and obtains a pairing code via these broadcasts. It then encrypts the pairing code using a pre-generated client key to obtain encrypted information, retrieves the client's identifier, and sends encrypted information carrying this identifier to the server. The client identifier is a unique identifier for the client and can be its MAC address (Media Access Control Address). When the client is a mobile phone, the client identifier can also be its International Mobile Equipment Identity (IMEI).

[0058] In one embodiment, after the client enables Bluetooth, it may receive multiple pairing codes broadcast via Bluetooth. In response to a selection operation triggered by any pairing code, the client encrypts any pairing code that triggers the selection operation to obtain encrypted information.

[0059] S203. The server obtains the encrypted information sent by the client and searches for the client key based on the client identifier carried in the encrypted information.

[0060] Specifically, the server pre-stores multiple clients and their associated client keys, with each client and key corresponding one-to-one. When the server receives encrypted information sent by a client, it can look up the client key associated with the client identifier in its own memory or in the server's data storage system. The client key found by the server based on the client identifier is the same as the client key used by the client to encrypt the pairing code.

[0061] In one embodiment, if the server cannot find the client key associated with the client identifier, it indicates that the client has not been pre-authenticated with the server, and the client may be an unauthorized device. The server will not further process the encrypted information. In another implementation, if the server cannot find the client key associated with the client identifier, the server may send first information to the client to indicate that the client has not been authenticated.

[0062] S204. The server decrypts the encrypted information based on the client key to obtain the pairing code.

[0063] S205. The server generates a digital signature based on the pairing code and the client identifier, and sends the digital signature to the client.

[0064] Specifically, the server locates the portable medical device identifier that is bound to the client identifier, encrypts the pairing code using the private key associated with the portable medical device identifier, and obtains a digital signature. The server can locate the portable medical device identifier bound to the client identifier and the associated private key from its own memory, or it can locate the portable medical device identifier bound to the client identifier and the associated private key from the server's data storage system.

[0065] A portable medical device identifier is a unique identifier for a portable medical device, and can be the MAC address (Media Access Control Address) of the portable medical device. The private key associated with the portable medical device identifier is the private key of the portable medical device corresponding to the identifier.

[0066] In one embodiment, the client completes authentication on the server, that is, the server completes the binding of the client to a portable medical device. If the server finds the client key associated with the client identifier, the server can also find the portable medical device identifier associated with the client identifier.

[0067] If the server cannot find the private key associated with the portable medical device identifier, it means that the portable medical device corresponding to the identifier has not been pre-authenticated on the server, and therefore the server has not stored the private key of the portable medical device. In one implementation, if the server cannot find the private key associated with the portable medical device identifier, the server can send a second message to the client, which indicates that the portable medical device has not been authenticated.

[0068] S206. The client obtains the digital signature sent by the server and sends the digital signature to the portable medical device.

[0069] Specifically, the client receives the digital signature sent by the server and forwards the digital signature to the portable medical device that sent the pairing code.

[0070] S207. The portable medical device obtains the digital signature sent by the client, verifies the digital signature based on a pre-set digital certificate, and establishes a Bluetooth connection between the portable medical device and the client after successful verification.

[0071] Specifically, the portable medical device is pre-authenticated on the server, enabling the server to generate a digital certificate for the portable medical device, which is then pre-installed on the device. When a digital signature is generated using the attached method, the portable medical device can decrypt the digital signature based on the pre-installed digital certificate. If decryption is successful, a Bluetooth connection is established between the portable medical device and the client that sent the digital certificate. When a digital signature is generated using the detached or RAW (raw signature) method, the portable medical device can decrypt the digital signature based on the pre-installed digital certificate and pairing code. If decryption is successful, a Bluetooth connection is established between the portable medical device and the client that sent the digital certificate.

[0072] In one embodiment, if the digital signature is generated via attached and decryption fails, it indicates that the private key corresponding to the digital signature sent by the client (i.e., the private key used to generate the digital signature) is not the private key of the portable medical device. Therefore, the digital certificate of the portable medical device cannot decrypt the digital signature, and the digital signature may be a forged digital signature by an unauthorized device. The portable medical device will not establish a Bluetooth connection with the client that sent the digital signature. Similarly, if the digital signature is generated via detached or RAW, and decryption fails, it indicates that the private key corresponding to the digital signature sent by the client (i.e., the private key used to generate the digital signature) is not the private key of the portable medical device, and / or the pairing code used to generate the digital signature is inconsistent with the pairing code sent by the portable medical device. Therefore, the digital certificate and pairing code of the portable medical device cannot decrypt the digital signature, and the digital signature may be a forged digital signature by an unauthorized device, or the pairing code obtained by the client is not the pairing code sent by the portable medical device. The portable medical device will not establish a Bluetooth connection with the client that sent the digital signature.

[0073] The Bluetooth connection method for the aforementioned portable medical device involves the portable medical device broadcasting a pairing code via Bluetooth. The client obtains the pairing code via Bluetooth broadcast, encrypts the obtained pairing code using its client key, and sends the encrypted information to the server. The server searches for the client key corresponding to the client identifier, decrypts the encrypted information using the found client key, and obtains the pairing code. The server generates a digital signature based on the pairing code and the client identifier, and sends the digital signature to the client. The client sends the digital signature to the portable medical device, which verifies the digital signature using a pre-set digital certificate. After successful verification, a Bluetooth connection is established between the portable medical device and the client. Only when the client has completed authentication with the server can the server find the client key corresponding to the client identifier and send the digital signature to the client. If an unauthorized device obtains the pairing code, the server cannot find the key corresponding to the unauthorized device's identifier, and therefore the unauthorized device cannot obtain the digital signature sent by the server. If an unauthorized device forges a digital signature and sends the forged digital signature to the portable medical device, the forged digital signature cannot pass the verification of the digital certificate, and therefore the unauthorized device cannot connect to the portable medical device via Bluetooth. The above-described Bluetooth connection method for portable medical devices ensures that only legitimate clients can connect to the portable medical devices via Bluetooth, thus improving the security of Bluetooth connections for portable medical devices.

[0074] In one embodiment, the portable medical device first authenticates with the server to obtain a digital certificate generated by the server. Before the server obtains the encrypted information sent by the client, the Bluetooth connection method of the portable medical device further includes: the server obtaining the portable medical device identifier, generating a public key and a private key for the portable medical device, associating and storing the private key and the portable medical device identifier; and generating a digital certificate based on the portable medical device identifier and the public key.

[0075] The process of the server obtaining the portable medical device identifier can be achieved either by a third-party device acquiring the identifier and sending it to the server, or by the portable medical device itself sending its identifier to the server upon initial startup. The server then derives the public and private keys of the portable medical device based on this identifier.

[0076] The server functions as a certificate authority. The public key of the portable medical device is used by the server to generate a digital certificate. The server encrypts the public key and the identifier of the portable medical device using its private key to obtain the digital certificate. The server associates and stores the private key and identifier of the portable medical device. The private key of the portable medical device is used by the server to generate a digital signature.

[0077] After the server generates a digital certificate for the portable medical device, it can send the digital certificate to a third-party device, copy the digital certificate from the third-party device, and then import the digital certificate into the portable medical device. Alternatively, the server can distribute the digital certificate to the portable medical device.

[0078] The process of the server associating and storing the private key and identifier of the portable medical device, and generating a digital certificate based on the identifier and public key of the portable medical device, can be performed before the portable medical device leaves the factory, so that all portable medical devices after leaving the factory have been authenticated by the server.

[0079] In the above embodiments, the server obtains the portable medical device identifier, generates a public key and a private key for the portable medical device based on the identifier, associates and saves the private key and the identifier, and generates a digital certificate based on the public key and identifier, thus completing the authentication of the portable medical device. This enables the portable medical device to obtain a digital certificate, providing a foundation for the server to generate a digital signature and for the portable medical device to verify the digital signature based on the digital certificate.

[0080] In some application scenarios, portable medical devices establish a Bluetooth connection with only one client, ensuring that only one client can control the portable medical device via Bluetooth and guaranteeing the security of its use. In one embodiment, before the client obtains the pairing code via Bluetooth broadcast, the Bluetooth connection method for the portable medical device further includes: the client obtaining the portable medical device identifier, generating a client key based on the client identifier and the portable medical device identifier; sending an authentication request to the server; the server obtaining the authentication request sent by the client, and obtaining the portable medical device identifier and client identifier carried in the authentication request; if the portable medical device corresponding to the portable medical device identifier is not in a bound state, then generating a client key based on the portable medical device identifier and the client identifier, and associating and storing the client key, the portable medical device identifier, and the client identifier.

[0081] The authentication request sent by the client is used to bind the client and the portable medical device corresponding to the portable medical device identifier carried in the authentication request. The client key generated by the client is the same as the client key generated by the server.

[0082] Specifically, the client obtains the portable medical device identifier. In response to the authentication operation based on the portable medical device identifier, the client sends an authentication request to the server carrying the portable medical device identifier and the client identifier. The server obtains the authentication request and, based on the portable medical device identifier carried in the authentication request, determines whether the portable medical device corresponding to the portable medical device identifier is in a bound state. If the portable medical device is not in a bound state, it means that the portable medical device is not bound to any client. The server generates a client key based on the portable medical device identifier and the client identifier, and saves the client key, the portable medical device identifier, and the client identifier together to bind the client (corresponding to the client identifier) ​​and the portable medical device (corresponding to the portable medical device identifier).

[0083] The client can obtain the portable medical device identifier by either obtaining the identifier input by the user or by scanning the device's QR code. This application embodiment does not specifically limit this method.

[0084] In one implementation, the authentication request carries a key algorithm identifier. If the portable medical device corresponding to the portable medical device identifier is not in a bound state, the server uses the key algorithm corresponding to the key algorithm identifier to generate a client key based on the portable medical device identifier and the client identifier. The key algorithm identifier is the identifier corresponding to the key algorithm used by the client to generate the client key. The client carries the key algorithm identifier in the authentication request so that the server uses the same key algorithm as the client to generate the client key based on the portable medical device identifier and the client identifier, thereby ensuring that the client key generated by the client is the same as the client key generated by the server.

[0085] The server obtains the portable medical device identifier carried in the authentication request and determines whether the portable medical device corresponding to the portable medical device identifier is in a bound state. This includes: the server searching for the client identifier associated with the portable medical device identifier; if not found, it is determined that the portable medical device corresponding to the portable medical device identifier is not in a bound state.

[0086] In one embodiment, the server searches for a client identifier associated with the portable medical device identifier. If found, it determines whether the found client identifier matches the client identifier carried in the authentication request. If they do not match, it determines that the portable medical device corresponding to the portable medical device identifier is in a bound state. The fact that the portable medical device is bound indicates that the portable medical device has been bound to a client, and that client is not the client that sent the authentication request. In another implementation, if it is determined that the portable medical device corresponding to the portable medical device identifier is in a bound state, the server can return third-party information to the client. This third-party information is used to indicate that the client is not the specified device of the portable medical device and cannot be bound.

[0087] If the found client identifier matches the client identifier carried in the authentication request, it is determined that the portable medical device corresponding to the portable medical device identifier has been bound to the client that sent the authentication request, and the server does not need to repeat the binding operation. In one implementation, if the portable medical device corresponding to the portable medical device identifier has been bound to the client that sent the authentication request, the server can return a fourth piece of information to the client, which is used to indicate to the client that it has been bound to the portable medical device.

[0088] In the above embodiments, since the client and the portable medical device are pre-bound before the client establishes a communication connection with the portable medical device, one portable medical device can only be bound to one client. This allows the server to obtain the portable medical device identifier bound to the client identifier and generate a digital signature based on the private key associated with the portable medical device identifier. If the portable medical device identifier sending the pairing code verifies the digital signature, the portable medical device establishes a Bluetooth connection with the client. In other words, the portable medical device can only establish a Bluetooth connection with its bound client, and thus only one client can control the portable medical device via Bluetooth, improving the security of the Bluetooth connection of the portable medical device.

[0089] In one embodiment, the server generates a digital signature based on the pairing code and the client identifier, including: finding a portable medical device identifier associated with the client identifier; finding a private key associated with the portable medical device identifier; and encrypting the pairing code based on the found private key to obtain the digital signature.

[0090] Specifically, the server pre-associates and stores multiple portable medical device identifiers with multiple client identifiers, ensuring a one-to-one correspondence between the portable medical device identifiers and client identifiers. The server also pre-associates and stores multiple portable medical device identifiers with their private keys, ensuring a one-to-one correspondence between the portable medical device identifiers and their private keys. The server finds the portable medical device identifier associated with a client identifier, then finds the private key associated with that portable medical device identifier, encrypts the pairing code using the found private key, obtains a digital signature, and sends the digital signature to the client.

[0091] It should be noted that the portable medical device identifier associated with the client identifier may not be the same as the portable medical device identifier of the portable medical device that sends the pairing code. In other words, the portable medical device that sends the pairing code may not be the same device as the portable medical device that is pre-bound to the client.

[0092] In one embodiment, if the server does not find a portable medical device identifier associated with the client identifier, it means that the client has not been pre-bound to any portable medical device, and the server will not generate a digital certificate. If the server does not find a portable medical device identifier associated with the client identifier, the server can return second information to the client. After receiving the second information, the client can send an authentication request carrying the portable medical device identifier to the server, bind the client to the portable medical device through the authentication request, and then send encrypted information to the server.

[0093] In the above embodiments, the server encrypts the pairing code to obtain encrypted information based on the private key associated with the portable medical device identifier bound to the client identifier. If the private key associated with the portable medical device identifier bound to the client identifier is not the private key associated with the portable medical device identifier that sent the pairing code, the digital signature cannot pass the verification of the portable medical device. In other words, a Bluetooth connection can only be established with the portable medical device if the portable medical device that sent the pairing code is the same device as the portable medical device that was previously bound to the client. Thus, only one client can control the portable medical device via Bluetooth, which improves the security of the portable medical device using Bluetooth connection.

[0094] In one embodiment, a portable medical device not bound to a client cannot establish a Bluetooth connection with the client. If the portable medical device is bound to another client, it can be unbound from the other client first. After unbinding, the client sends an authentication request carrying the portable medical device's identifier to the server, and binds the client to the portable medical device through the authentication request.

[0095] Unbinding a portable medical device from other clients can be achieved by the user resetting the portable medical device, thus removing it from the bound state (unbinding the portable medical device from other clients), or by the user unbinding the portable medical device from another client, thus removing it from the bound state.

[0096] In this embodiment, the portable medical device completes authentication on the server, enabling the server to associate and save the portable medical device's private key and identifier. The server generates a digital certificate for the portable medical device and places the digital certificate into the portable medical device. The client obtains the portable medical device identifier and sends an authentication request carrying the portable medical device identifier and client identifier to the server. The server generates a client key based on the portable medical device identifier and client identifier, and associates and saves the client key, portable medical device identifier, and client identifier to bind the client and portable medical device. The client obtains a pairing code via Bluetooth broadcast, encrypts the pairing code to obtain encrypted information, and sends the encrypted information carrying the client identifier to the server. The server generates a digital signature based on the pairing code and client identifier, and sends the digital signature through the client. The device is sent to a portable medical device, which verifies the digital signature using a pre-installed digital certificate. Upon successful verification, a Bluetooth connection is established between the portable medical device and the client. This Bluetooth connection is only established when the portable medical device has completed authentication on the server, the portable medical device and the client are mutually bound, and the portable medical device bound to the client is the same device that sent the pairing code. Unauthorized devices cannot complete authentication on the server, thus preventing the binding of unauthorized devices to the portable medical device, making the portable medical device less vulnerable to attacks. Furthermore, the portable medical device can only establish a Bluetooth connection with its bound client, meaning only one client can control the portable medical device via Bluetooth, enhancing the security of Bluetooth connections.

[0097] In one embodiment, such as Figure 3 As shown, the portable medical device is an insulin pump. The insulin pump sends Bluetooth broadcasts via Bluetooth, and the Bluetooth broadcasts can be Bluetooth Low Energy broadcasts. Accordingly, the Bluetooth connection method of the portable medical device includes:

[0098] The server obtains the insulin pump identifier, generates the public and private keys for the insulin pump, associates and saves the private key with the insulin pump identifier, and generates a digital certificate based on the insulin pump identifier and public key.

[0099] Insert digital certificates into insulin pumps;

[0100] The client obtains the insulin pump identifier from the insulin pump and generates a client key based on the client identifier and the insulin pump identifier;

[0101] The client sends an authentication request to the server;

[0102] The server obtains the authentication request sent by the client, and retrieves the insulin pump identifier and client identifier carried in the authentication request. If the insulin pump corresponding to the insulin pump identifier is not in a bound state, the server generates a client key based on the insulin pump identifier and client identifier, and saves the client key, insulin pump identifier, and client identifier together.

[0103] The insulin pump broadcasts a pairing code via Bluetooth.

[0104] The client obtains the pairing code via Bluetooth broadcast, encrypts the pairing code with the client key to obtain encrypted information, and sends the encrypted information to the server.

[0105] The server obtains the encrypted information sent by the client, finds the client key based on the client identifier carried in the encrypted information, decrypts the encrypted information based on the client key to obtain the pairing code, finds the insulin pump identifier associated with the client identifier, finds the private key of the insulin pump identifier, encrypts the pairing code with the private key of the insulin pump to obtain a digital signature, and sends the digital signature to the client.

[0106] The client sends a digital signature to the insulin pump. The insulin pump verifies the digital signature based on a pre-set digital certificate and establishes a Bluetooth connection between the insulin pump and the client after successful verification.

[0107] The Bluetooth connection method for portable medical devices described above can prevent unauthorized devices from simulating client connections with the insulin pump via Bluetooth. Furthermore, the insulin pump can only connect to one client via Bluetooth, ensuring that only one client can control the insulin pump through Bluetooth, thus improving the security of using Bluetooth connections with the insulin pump.

[0108] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0109] Based on the same inventive concept, this application also provides a Bluetooth connection system for implementing the Bluetooth connection method for portable medical devices described above. The solution provided by this system is similar to the implementation described in the above method; therefore, the specific limitations in the Bluetooth connection system embodiments provided below can be found in the limitations of the Bluetooth connection method for portable medical devices described above, and will not be repeated here.

[0110] In one embodiment, a Bluetooth connectivity system is provided, including a portable medical device, a client, and a server;

[0111] The portable medical device is used to broadcast a pairing code via Bluetooth.

[0112] The client is configured to obtain a pairing code via Bluetooth broadcast, encrypt the pairing code to obtain encrypted information, and send the encrypted information to the server.

[0113] The server is configured to obtain encrypted information sent by the client, find the client key based on the client identifier carried in the encrypted information, decrypt the encrypted information based on the client key to obtain the pairing code, generate a digital signature based on the pairing code and the client identifier, and send the digital signature to the client.

[0114] The client is also used to obtain the digital signature sent by the server and send the digital signature to the portable medical device;

[0115] The portable medical device is also used to obtain the digital signature sent by the client, verify the digital signature based on a pre-set digital certificate, and establish a Bluetooth connection between the portable medical device and the client after successful verification.

[0116] In one embodiment, the server includes:

[0117] The digital signature generation module is used to find the portable medical device identifier associated with the client identifier; find the private key associated with the portable medical device identifier; and encrypt the pairing code based on the found private key to obtain a digital signature.

[0118] In one embodiment, the server includes:

[0119] The first authentication module is used to obtain the authentication request sent by the client, and obtain the portable medical device identifier and the client identifier carried in the authentication request; if the portable medical device corresponding to the portable medical device identifier is not in a bound state, a client key is generated based on the portable medical device identifier and the client identifier, and the client key, the portable medical device identifier and the client identifier are associated and saved.

[0120] In one embodiment, the first authentication module includes:

[0121] The second search unit is used to search for the client identifier associated with the portable medical device identifier. If no client identifier is found, it is determined that the portable medical device corresponding to the portable medical device identifier is not in a bound state, and a client key is generated based on the portable medical device identifier and the client identifier.

[0122] In one embodiment, the server includes:

[0123] The second authentication module is used to obtain the portable medical device identifier of the portable medical device, generate the public key and private key of the portable medical device, associate and save the private key and the portable medical device identifier; and generate a digital certificate based on the portable medical device identifier and the public key.

[0124] In one embodiment, the client includes:

[0125] The authentication request module is used to obtain the portable medical device identifier of the portable medical device, generate a client key based on the client identifier and the portable medical device identifier, send an authentication request to the server so that the server obtains the portable medical device identifier and the client identifier carried in the authentication request, and, if the portable medical device corresponding to the portable medical device identifier is not in a bound state, generate a client key based on the portable medical device identifier and the client identifier, and associate and save the client key, the portable medical device identifier and the client identifier.

[0126] In one embodiment, the client includes:

[0127] An encryption module is used to encrypt the pairing code using the client key to obtain encrypted information.

[0128] In one embodiment, the portable medical device includes:

[0129] The verification module is used to decrypt the digital signature based on the preset digital certificate and the pairing code, and establish a Bluetooth connection between the portable medical device and the client corresponding to the client identifier if the decryption is successful.

[0130] In one embodiment, the portable medical device is an insulin pump.

[0131] The modules in the aforementioned Bluetooth connectivity system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0132] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor, memory, communication interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it performs the steps executed by the server, the client, or the portable medical device in the Bluetooth connection method for a portable medical device described above. The display screen can be an LCD screen or an e-ink screen. The input device can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the device's casing, or an external keyboard, touchpad, or mouse.

[0133] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0134] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps executed by the server, the steps executed by the client, or the steps executed by the portable medical device in the Bluetooth connection method of the portable medical device described above.

[0135] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps executed by the server, the steps executed by the client, or the steps executed by the portable medical device in the Bluetooth connection method for a portable medical device described above.

[0136] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps executed by the server, the steps executed by the client, or the steps executed by the portable medical device in the Bluetooth connection method for a portable medical device described above.

[0137] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0138] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0139] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0140] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A Bluetooth connection method for a portable medical device, characterized in that, The method includes: The client receives encrypted information and searches for the client key based on the client identifier carried in the encrypted information. The encrypted information is obtained by the client through Bluetooth broadcasting and encrypting the pairing code. The pairing code is sent by the portable medical device through Bluetooth broadcasting. The encrypted information is decrypted based on the client key to obtain the pairing code; A digital signature is generated based on the pairing code and the client identifier, and the digital signature is sent to the client so that the client sends the digital signature to the portable medical device so that the portable medical device verifies the digital signature based on a pre-set digital certificate and establishes a Bluetooth connection between the portable medical device and the client after successful verification. The step of generating a digital signature based on the pairing code and the client identifier includes: Find the portable medical device identifier associated with the client identifier; find the private key associated with the portable medical device identifier; encrypt the pairing code based on the found private key to obtain a digital signature.

2. The method according to claim 1, characterized in that, Before obtaining the encrypted information sent by the client, the process also includes: Obtain the authentication request sent by the client, and obtain the portable medical device identifier and client identifier carried in the authentication request; If the portable medical device corresponding to the portable medical device identifier is not in a bound state, a client key is generated based on the portable medical device identifier and the client identifier, and the client key, the portable medical device identifier, and the client identifier are associated and saved.

3. The method according to claim 2, characterized in that, If the portable medical device corresponding to the portable medical device identifier is not in a bound state, then a client key is generated based on the portable medical device identifier and the client identifier, including: Locate the client identifier associated with the portable medical device identifier; If not found, it is determined that the portable medical device corresponding to the portable medical device identifier is not in a bound state, and a client key is generated based on the portable medical device identifier and the client identifier.

4. The method according to claim 2, characterized in that, Before obtaining the authentication request sent by the client, the method further includes: Obtain the portable medical device identifier of the portable medical device, generate the public key and private key of the portable medical device, and associate and save the private key and the portable medical device identifier; A digital certificate is generated based on the portable medical device identifier and the public key.

5. A Bluetooth connection method for a portable medical device, characterized in that, The method includes: The pairing code is obtained via Bluetooth broadcast, encrypted to obtain encrypted information, and sent to the server so that the server can find the client key based on the client identifier carried in the encrypted information, decrypt the encrypted information based on the client key to obtain the pairing code, generate a digital signature based on the pairing code and the client identifier, and send the digital signature to the client. The pairing code is sent by the portable medical device via Bluetooth broadcast. Obtain the digital signature sent by the server, send the digital signature to the portable medical device, so that the portable medical device can verify the digital signature based on a pre-set digital certificate, and establish a Bluetooth connection between the portable medical device and the client after successful verification; The step of generating a digital signature based on the pairing code and the client identifier includes: Find the portable medical device identifier associated with the client identifier; find the private key associated with the portable medical device identifier; encrypt the pairing code based on the found private key to obtain a digital signature.

6. The method according to claim 5, characterized in that, Before obtaining the pairing code via Bluetooth broadcast, the process also includes: Obtain the portable medical device identifier of the portable medical device, and generate a client key based on the client identifier and the portable medical device identifier; An authentication request is sent to the server so that the server can obtain the portable medical device identifier and client identifier carried in the authentication request. If the portable medical device corresponding to the portable medical device identifier is not in a bound state, a client key is generated based on the portable medical device identifier and the client identifier, and the client key, the portable medical device identifier and the client identifier are associated and stored.

7. The method according to claim 6, characterized in that, The step of encrypting the pairing code to obtain encrypted information includes: The pairing code is encrypted using the client key to obtain encrypted information.

8. A Bluetooth connection method for a portable medical device, characterized in that, The method includes: A pairing code is broadcast via Bluetooth so that the client can obtain the pairing code, encrypt the pairing code to obtain encrypted information, and send the encrypted information to the server so that the server can find the client key based on the client identifier carried in the encrypted information, decrypt the encrypted information based on the client key to obtain the pairing code, generate a digital signature based on the pairing code and the client identifier, and send the digital signature to the client. The system obtains the digital signature sent by the client, verifies the digital signature based on a pre-set digital certificate, and establishes a Bluetooth connection between the portable medical device and the client after successful verification. The step of generating a digital signature based on the pairing code and the client identifier includes: Find the portable medical device identifier associated with the client identifier; find the private key associated with the portable medical device identifier; encrypt the pairing code based on the found private key to obtain a digital signature.

9. The method according to claim 8, characterized in that, The process of verifying the digital signature based on a pre-set digital certificate and establishing a Bluetooth connection between the portable medical device and the client after successful verification includes: The digital signature is decrypted using the pre-set digital certificate and the pairing code. If the decryption is successful, a Bluetooth connection is established between the portable medical device and the client corresponding to the client identifier.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 4, or the method of any one of claims 5 to 7, or the steps of the method of claim 8 or 9.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 4, or the method of any one of claims 5 to 7, or the steps of the method of claim 8 or 9.