Facilitating persistent connectivity to remote analyte monitoring systems

By executing applications on mobile devices to detect communication channel availability between the analyte monitoring system and the server, the communication interruption and data loss problems of users when using the in vivo analyte monitoring system are solved, and the system reliability and user experience are improved.

CN120077446APending Publication Date: 2025-05-30ABBOTT DIABETES CARE INC
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202380074104.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-24
Filing Date
2023-10-18
Publication Date
2025-05-30

Smart Images

  • Figure CN120077446A_ABST
    Figure CN120077446A_ABST
Patent Text Reader

Abstract

Embodiments described herein include an analyte monitoring system that includes an application executing on a mobile device and an analyte monitoring system server. The application program is configured to detect that a communication channel between the application program and the analyte monitoring system server is unresponsive, and take measures to respond or recommend options to correct the unresponsive communication channel. Technologies include receiving, via a notification service server, a notification from an analyte monitoring system server. In response to receiving the notification, output of the first connection alert is cancelled. Further, in response to receiving the notification, output of the second connected alarm is arranged to output when the timer expires unless the mobile device receives a second notification from the analyte monitoring system server. Upon output, a second connection alert indicates that the application does not establish a connection with the analyte monitoring system server for a period of time.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Priority

[0002] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 380,609, filed Oct. 24, 2022, which is incorporated herein by reference. Technical Field

[0003] The subject matter described herein relates to systems and methods for facilitating communication between devices and for facilitating maintaining a communication session between devices, e.g., with respect to the operation of a handheld device and a remote server forming part of an in vivo analyte monitoring system. Background Art

[0004] Detecting the concentration level of glucose or other analytes in certain individuals using medical sensors may be beneficial to their health. For example, monitoring glucose levels is important for individuals with diabetes or pre-diabetes. Diabetic patients may need to monitor their glucose levels to determine when they need medication (e.g., insulin) to lower their glucose levels or when they need additional glucose.

[0005] Devices and systems have been developed for automating the monitoring of analyte concentrations (such as glucose levels) in body fluids (such as in the bloodstream or interstitial fluid). Some of these analyte level measurement devices are configured such that at least a portion of the device is located beneath the user's skin surface, e.g., in the user's blood vessels or subcutaneous tissue. As used herein, the term analyte monitoring system is used to refer to any type of in vivo monitoring system that uses at least a portion disposed subcutaneously to automatically measure and store sensor data representative of analyte concentration levels over time. An analyte monitoring system may include a transmission sensor to a processor / display unit for further processing and / or display to the user.

[0006] Frequent monitoring and management of analyte levels (such as glucose, ketones, lactate, oxygen, hemoglobin A1C, etc.) can improve people's overall health, especially that of diabetic patients. As an example, diabetic patients typically need to monitor their glucose levels to ensure that they are kept within clinically safe ranges and can also use this information to determine when they need insulin to manage the glucose levels in their body or when they need glucose to raise the glucose levels in their body. Clinical data shows a strong correlation between glucose monitoring frequency and glycemic control. However, despite such a correlation, many individuals diagnosed with diabetes do not monitor their glucose levels as frequently as they should, due to a combination of factors including convenience, test discretion, pain associated with glucose detection, and cost.

[0007] To increase a patient's compliance with a frequent glucose monitoring program, an in vivo analyte monitoring system can be utilized, where a sensor control device can be worn on the body of an individual in need of analyte monitoring. The sensor control device can also be configured to transmit analyte data to one or more data receiving devices, from which the individual, their healthcare provider ("HCP"), or others can view the data and make treatment decisions. The data receiving device can include a variety of hardware components to enable processing of the analyte data received from the sensor control device and must include telecommunications components to enable communication with the sensor control device. The data receiving device can also include additional testing or sending hardware to assist the individual or their HCP in making treatment decisions.

[0008] Data received from the sensor control device can be further relayed by one or more other devices to a central application server associated with the analyte monitoring system. The central application server can perform additional data analysis and provide that analysis to the user of the sensor control device. In some cases, the central application server can also provide some data- and analysis-based information to other users of the analyte monitoring system. However, users relying on receiving such data from a remote application server to monitor the health of a user wearing a sensor control device may experience interruptions or other gaps in the data they receive. The user may have difficulty determining whether the interruption is due to a problem with the sensor control device, the analyte monitoring system, or the user wearing the sensor control device. In most cases, the user will be in the dark without additional information until current sensor data is provided again.

[0009] Accordingly, it would be beneficial to introduce alternative mechanisms for users of a monitoring application associated with an analyte monitoring system to determine when there are communication problems with the central application server. Additionally, it would be further beneficial to provide systems and methods to facilitate responses to these communication problems. SUMMARY OF THE INVENTION

[0010] The objects and advantages of the disclosed subject matter will be set forth in the description which follows and will be apparent from the description, or may be learned by practice of the disclosed subject matter. Additional advantages of the disclosed subject matter will be realized and attained by means of the methods and systems particularly pointed out in the written description and claims hereof as well as from the appended drawings.

[0011] Embodiments described herein include an analyte monitoring system. The analyte monitoring system is configured to use various systems and methods to facilitate the transfer of analyte data and derivative data derived from the analyte data to a data monitoring device. Certain embodiments include mechanisms for detecting the availability of a communication channel between a data monitoring device and one or more remote servers associated with or used by the analyte monitoring system. Specifically, certain embodiments include techniques for detecting that a communication channel between an application executed on a mobile device and an analyte monitoring system server is unresponsive. Certain embodiments also include providing a response to detecting that the communication channel is unresponsive.

[0012] To achieve these and other advantages, and in accordance with the purpose of the disclosed subject matter, as embodied and broadly described, the disclosed subject matter includes an analyte monitoring device and a computer program product stored on a computer-readable medium for monitoring an analyte to detect that a communication channel between an application and an analyte monitoring system server is unresponsive. Exemplary systems and methods may include an analyte monitoring system. The analyte monitoring system may include a mobile device having one or more processors and a memory communicatively coupled to the one or more processors. The memory may include instructions that, when executed by the one or more processors, are configured to cause the one or more processors to execute an application associated with the analyte monitoring system. The analyte monitoring system may include an analyte monitoring system server configured to be communicatively coupled to the application. When the instructions are executed, the application associated with the analyte monitoring system is configured to detect that a communication channel between the application and the analyte monitoring system server is unresponsive by performing certain operations. The application may receive a notification from the analyte monitoring system server via a notification service server. The notification service server may be configured to be communicatively coupled to the application and the analyte monitoring system server. The application may cancel outputting a first connection alert in response to receiving the notification, wherein outputting the first connection alert was scheduled prior to receiving the notification. The application may schedule outputting a second connection alert in response to receiving the notification. Outputting the second connection alert may be scheduled when a timer expires, unless the mobile device receives a second notification from the analyte monitoring system server. The application may determine that the timer has expired. The application may output a second connection alert indicating that the application has not established a connection with the analyte monitoring system server within a predetermined period of time.

[0013] In some embodiments, the application can receive a request to establish an arrangement for monitoring a communication channel between the application and the analyte monitoring system server before receiving a notification from the analyte monitoring system server. The application can arrange to output a first connection alert in response to receiving the request. In some embodiments, the amount of time associated with the timer is based on user input to the application associated with the analyte monitoring system. In some embodiments, the application is a monitoring application of the analyte monitoring system. Through this application, a first user receives information related to the analyte level of a second user.

[0014] In some embodiments, the application is further configured to attempt to initiate a communication session with the analyte monitoring system server using the communication channel or an alternate communication channel before outputting a second connection alert. In some embodiments, the application is further configured to receive a second notification from the analyte monitoring system server, cancel outputting the second connection alert, and arrange to output a third connection alert before determining that the timer has expired. Output of the third connection alert can be arranged when a second timer expires, unless the mobile device receives a third notification from the analyte monitoring system server. In some embodiments, the application is further configured to receive other data from the analyte monitoring system server, cancel outputting the second connection alert, and arrange to output a third connection alert before determining that the timer has expired. Output of the third connection alert can be arranged when a second timer expires, unless the mobile device receives a third notification from the analyte monitoring system server.

[0015] In other aspects of the disclosed subject matter, systems and methods can include systems and methods for responding to detecting that a communication channel between an application and an analyte monitoring system is unresponsive. Exemplary systems and methods can include an analyte monitoring system. The analyte monitoring system can include a mobile device having one or more processors and a memory communicatively coupled to the one or more processors. The memory includes instructions that, when executed by the one or more processors, are configured to cause the one or more processors to execute an application associated with the analyte monitoring system. The analyte monitoring system can also include an analyte monitoring system server configured to be communicatively coupled to the application. When the instructions are executed, the application associated with the analyte monitoring system can be configured to receive, via a communication channel between the application and the analyte monitoring system server, one or more current values associated with an analyte level and one or more historical values associated with the analyte level. The application can detect that the communication channel between the application and the analyte monitoring system server is unresponsive. The application can determine one or more possible causes for the communication channel being unresponsive. The application can modify an output of the application based on the communication channel being unresponsive. The application can display a notification based on one or more possible causes for the communication channel being unresponsive. The notification can include additional information for resolving the unresponsive communication channel. In some embodiments, the application is a monitoring application of the analyte monitoring system. Through the application, a first user receives information regarding an analyte level of a second user.

[0016] In some embodiments, modifying the output of the application includes: restricting the functionality of the application when the communication channel is unresponsive. In some embodiments, the application can store historical values. Modifying the output of the application can include: displaying the historical values until the application detects that the communication channel is unresponsive. In some embodiments, the application is further configured to encrypt the historical values before storing. In some embodiments, the application is further configured to de-identify the historical values before storing. In some embodiments, the application is further configured to erase the historical values after a predetermined period of time has passed.

[0017] In some embodiments, modifying the output of the application includes: displaying the last known state of the analyte level. In some embodiments, the application is further configured to determine the last known state of the analyte level by comparing one or more current values with one or more thresholds, each threshold corresponding to a respective last known state. In some embodiments, while the communication channel is unresponsive, the application continuously displays a notification. In some embodiments, the notification identifies an error in the application or the system state of the mobile device. In some embodiments, the notification identifies an error in the analyte monitoring system server. In some embodiments, the notification includes a recommendation to use a second communication channel between the application and the analyte monitoring system server.

[0018] In some embodiments, the application is further configured to, after displaying the notification, detect that the communication channel between the application and the analyte monitoring system server is responsive and receive additional historical values associated with the analyte corresponding to the period during which the communication channel was unresponsive. In some embodiments, the application is further configured to determine the geographical location of the mobile device when detecting that the communication channel is unresponsive. The application may detect that the communication channel between the application and the analyte monitoring system server is responsive after displaying the notification and provide the geographical location of the mobile device to the analyte monitoring system server when detecting that the communication channel is unresponsive.

[0019] The embodiments described herein include an analyte monitoring system that includes an application executed on a mobile device and an analyte monitoring system server. The application is configured to detect that the communication channel between the application and the analyte monitoring system server is unresponsive and take measures to respond or recommend options to correct the unresponsive communication channel. The techniques include: receiving a notification from the analyte monitoring system server via a notification service server. In response to receiving the notification, canceling the output of a first connection alert. Additionally, in response to receiving the notification, the output of a second connection alert is scheduled to be output when a timer expires, unless the mobile device receives a second notification from the analyte monitoring system server. When output, the second connection alert indicates that the application has not established a connection with the analyte monitoring system server for a period of time.

[0020] Other systems, methods, features, and advantages of the subject matter described herein will be or will become apparent to those skilled in the art upon examination of the following drawings and detailed description. All such additional systems, methods, features, and advantages are included within this specification, within the scope of the subject matter described herein, and are protected by the appended claims. In the absence of express statement of these features in the claims, the features of the exemplary embodiments should in no way be construed as limiting the appended claims.

[0021] It should be understood that the foregoing general description and the following detailed description are exemplary and are intended to provide further explanation of the disclosed subject matter. The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate and provide a further understanding of the methods and systems of the disclosed subject matter. The drawings, together with the specification, explain the principles of the disclosed subject matter. Description of the Drawings

[0022] By studying the drawings, the details (both with respect to its structure and operation) of the subject matter set forth herein may become apparent, in which like reference numerals refer to like parts. The components in the figures are not necessarily drawn to scale, but rather emphasis is placed upon illustrating the principles of the subject matter. In addition, all illustrations are intended to convey concepts, where relative sizes, shapes, and other detailed attributes may be illustrated schematically rather than literally or precisely.

[0023] Figure 1A is a system overview of a sensor applicator, a reader device, a monitoring system, a network, and a remote system.

[0024] Figure 1B is a schematic diagram showing an operating environment of an exemplary analyte monitoring system for use with the techniques described herein.

[0025] Figure 2A is a block diagram depicting an exemplary implementation of a reader device.

[0026] Figure 2B is a block diagram showing an exemplary data receiving device for communicating with a sensor according to an exemplary implementation of the disclosed subject matter.

[0027] Figure 2C and Figure 2D is a block diagram depicting an exemplary implementation of a sensor control device.

[0028] Figure 2E is a block diagram showing an exemplary analyte sensor according to an exemplary implementation of the disclosed subject matter.

[0029] Figure 3A is a proximal perspective view depicting an exemplary implementation of a user preparing a tray for assembly.

[0030] Figure 3B is a side view depicting an exemplary implementation of a user preparing an applicator device for assembly.

[0031] Figure 3C is a proximal perspective view depicting an exemplary implementation of a user inserting an applicator device into a tray during assembly.

[0032] Figure 3Dis a proximal perspective view depicting an exemplary embodiment of a user removing an applicator device from a tray during assembly.

[0033] Figure 3E is a proximal perspective view depicting an exemplary embodiment of a patient using an applicator device to apply a sensor.

[0034] Figure 3F is a proximal perspective view depicting an exemplary embodiment of a patient with an applied sensor and the applicator device in use.

[0035] Figure 4A is a side view depicting an exemplary embodiment of an applicator device coupled to a cap.

[0036] Figure 4B is a side perspective view depicting an exemplary embodiment of a decoupled applicator device and cap.

[0037] Figure 4C is a perspective view depicting an exemplary embodiment of the distal end of an applicator device and an electronic device housing.

[0038] Figure 4D is a top perspective view of an exemplary applicator device according to the disclosed subject matter.

[0039] Figure 4E is Figure 4D a bottom perspective view of the applicator device.

[0040] Figure 4F is Figure 4D an exploded view of the applicator device.

[0041] Figure 4G is Figure 4D a side cross-sectional view of the applicator device.

[0042] Figure 5 is a proximal perspective view depicting an exemplary embodiment of a tray with a coupled sterilization cap.

[0043] Figure 6A is a proximal perspective cross-sectional view depicting an exemplary embodiment of a tray with a sensor delivery component.

[0044] Figure 6B is a proximal perspective view depicting the sensor delivery component.

[0045] Figure 7A and Figure 7B are respectively an isometric exploded top view and a bottom view of an exemplary sensor control device.

[0046] Figures 8A to 8C is an assembly and cross-sectional view of a body-worn device including an integrated connector for a sensor assembly.

[0047] Figure 9A and Figure 9B are respectively Figure 1A a side view and a cross-sectional side view of an exemplary embodiment of a sensor applicator, wherein Figure 2C a cap of

[0048] Figure 10A and Figure 10B are respectively an isometric view and a side view of another exemplary sensor control device.

[0049] Figures 11A to 11C is a progressive cross-sectional side view showing the assembly of the sensor applicator of a sensor control device having Figures 10A to 10B

[0050] Figures 12A to 12C is a progressive cross-sectional side view showing the assembly and disassembly of an exemplary embodiment of a sensor applicator of a sensor control device having Figures 10A to 10B

[0051] Figures 13A to 13F shows a cross-sectional view depicting an exemplary embodiment of the applicator during the deployment phase.

[0052] Figure 14 is a graph depicting an example of the in vitro sensitivity of an analyte sensor.

[0053] Figure 15 is a schematic diagram showing an exemplary operating state of a sensor according to an exemplary embodiment of the disclosed subject matter.

[0054] Figure 16 is a schematic diagram showing an exemplary operation and data flow for over-the-air programming of a sensor according to the disclosed subject matter.

[0055] Figure 17 is a schematic diagram showing an exemplary data flow for secure data exchange between two devices according to the disclosed subject matter.

[0056] Figure 18 is a schematic diagram showing the data flow between various components of an exemplary analyte monitoring system according to the techniques described herein.

[0057] Figure 19 shows an exemplary method for providing a notification of no available communication channel between devices of an analyte monitoring system according to certain embodiments.

[0058] Figure 20A and Figure 20B ​​Illustrates an exemplary method for determining the availability of a communication channel between devices of an analyte monitoring system according to certain embodiments.

[0059] Figure 21 Illustrates an exemplary method for providing notification of no available communication channel between devices of an analyte monitoring system according to certain embodiments.

[0060] Figure 22 Illustrates an exemplary method for providing notification of no available communication channel between devices of an analyte monitoring system according to certain embodiments.

[0061] Figure 23 Illustrates an exemplary user interface executed by an application according to certain embodiments.

[0062] Figure 24 Illustrates an exemplary user interface executed by an application according to certain embodiments.

[0063] Figure 25 Illustrates an exemplary user interface executed by an application according to certain embodiments. Detailed Description

[0064] Reference will now be made in detail to various exemplary embodiments of the disclosed subject matter, the exemplary embodiments of which are illustrated in the accompanying drawings.

[0065] Before the detailed description of the subject matter, it should be understood that the present disclosure is not limited to the particular embodiments described, as these may of course vary. It should also be understood that the terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting, since the scope of the present disclosure will be limited only by the appended claims.

[0066] As used herein and in the appended claims, the singular forms "a", "an", and "the" include plural references unless the context clearly dictates otherwise.

[0067] The publications discussed herein are for the purpose of disclosure only prior to the filing date of the present application. Nothing herein is to be construed as an admission that the present disclosure is not entitled to antedate such disclosure by virtue of prior disclosure. Further, the provided publication dates may differ from the actual publication dates, which may require independent verification.

[0068] Generally, embodiments of the present disclosure include systems, devices, and methods for an analyte sensor for use with an in vivo analyte monitoring system. Many embodiments include an in vivo analyte sensor that is configured structurally such that at least a portion of the sensor is positioned or can be positioned within a user's body to obtain information about at least one analyte of the body. However, it should be noted that the embodiments disclosed herein can be used with in vivo analyte monitoring systems that incorporate in vitro capabilities as well as pure in vitro or ex vivo analyte monitoring systems (including fully non-invasive systems).

[0069] The applicator can be provided to the user in a sterile package that contains at least the electronic device housing of the sensor control device. According to some embodiments, a structure separate from the applicator (such as a container) can also be provided to the user in a sterile package that contains the sensor module and the lancet module. To apply the sensor, the user can couple the sensor module to the electronic device housing and can couple the lancet to the applicator through an assembly process that involves inserting the applicator into the container in a specific manner. In other embodiments, the applicator, the sensor control device, the sensor module, and the lancet module can be provided in a single package. The applicator can be used to position the sensor control device on the human body such that the sensor is in contact with the wearer's body fluid.

[0070] Furthermore, many embodiments include an in vivo analyte sensor that is configured structurally such that at least a portion of the sensor is positioned or can be positioned within a user's body to obtain information about at least one analyte of the body. However, it should be noted that the embodiments disclosed herein can be used with in vivo analyte monitoring systems that incorporate in vitro capabilities as well as pure in vitro or ex vivo analyte monitoring systems (including fully non-invasive systems).

[0071] For each embodiment of the methods disclosed herein, systems and devices capable of performing each of these embodiments are covered within the scope of the present disclosure. For example, embodiments of the sensor control device are disclosed, and these devices can have one or more sensors, analyte monitoring circuitry (e.g., analog circuitry), memory (e.g., for storing instructions), a power source, communication circuitry, a transmitter, a receiver, a processor, and / or a controller (e.g., for executing instructions) that can perform any and all method steps or facilitate the performance of any and all method steps. These sensor control device embodiments can be used and are capable of being used to implement those steps performed by the sensor control device according to any and all methods described herein.

[0072] In addition, the systems and methods presented herein can be used for the operation of sensors used in analyte monitoring systems, such as but not limited to health, fitness, diet, research, information, or any purpose involving the sensing of analytes over time. As used herein, a "sensor" can refer to any device capable of receiving sensor information from a user, including (for illustrative purposes) but not limited to a body temperature sensor, a blood pressure sensor, a pulse or heart rate sensor, a glucose level sensor, an analyte sensor, a body activity sensor, a body movement sensor, or any other sensor for collecting physical or biological information. Analytes measured by an analyte sensor can include (by way of example and not limitation) glucose, ketones, lactate, oxygen, hemoglobin A1C, albumin, alcohol, alkaline phosphatase, alanine transaminase, aspartate transaminase, bilirubin, blood urea nitrogen, calcium, carbon dioxide, chloride, creatinine, hematocrit, lactate, magnesium, oxygen, pH, phosphorus, potassium, sodium, total protein, uric acid, and the like.

[0073] However, before describing these aspects of the embodiments in detail, it is first desirable to describe examples of devices that may be present within, for example, an in vivo analyte monitoring system, and examples of their operation, all of which may be used in conjunction with the embodiments described herein.

[0074] There are various types of in vivo analyte monitoring systems. For example, a "continuous analyte monitoring" system (or "continuous glucose monitoring" system) can continuously transmit data from a sensor control device to a reader device without prompting (e.g., automatically according to a schedule). As another example, a "transient analyte monitoring" system (or "transient glucose monitoring" system or simply "transient" system) can transmit data from a sensor control device in response to a scan or data request from a reader device, such as via a near field communication (NFC) or radio frequency identification (RFID) protocol. In vivo analyte monitoring systems can also operate without the need for fingerstick calibration.

[0075] An in vivo analyte monitoring system can be distinguished from an "in vitro" system that contacts an ex vivo (or "ex vivo") biological sample, and the system typically includes a meter device having a port for receiving an analyte test strip carrying a user's body fluid, which can be analyzed to determine the user's blood glucose level.

[0076] An in vivo monitoring system may include a sensor that, when positioned in vivo, contacts a user's body fluid and senses the level of an analyte contained therein. The sensor may be part of a sensor control device located on the user's body and includes electronic devices and a power source capable of enabling and controlling analyte sensing. The sensor control device and its variations may also be referred to as a "sensor control unit", an "on-body electronic device" device or unit, an "on-body" device or unit, or a "sensor data communication" device or unit, to name a few.

[0077] The in vivo monitoring system may also include a data receiving device that receives the sensed analyte data from the sensor control device and processes and / or displays the sensed analyte data to the user in any number of forms. This device and its variations may be referred to as a "handheld reader device", a "reader device" (or simply "reader"), a "handheld electronic device" (or simply "handheld"), a "portable data processing" device or unit, a "data receiver", a "receiver" device or unit (or simply "receiver"), or a "remote" device or unit, to name a few. Other devices (such as personal computers) have also been used with or incorporated into in vivo and in vitro monitoring systems. The data receiving device may also be configured to provide the sensed analyte data received from the sensor control device to a remote application server associated with the analyte monitoring system. The remote application server (or servers) may perform further analysis of the data. Additionally, the remote application server may be configured to distribute, with the user's permission, the analyte data or other information derived from the analyte data to one or more other devices, which may be referred to as "data monitoring devices".

[0078] Figure 1A is a conceptual diagram depicting an exemplary embodiment of an analyte monitoring system 100 that includes a sensor applicator 150, a sensor control device 102, and a data receiving device 120. Here, the sensor applicator 150 may be used to deliver the sensor control device 102 to a monitoring location on the user's skin, where the sensor 104 remains in place for a period of time via an adhesive patch 105. The sensor control device 102 is in Figure 2B and Figure 2Cis further described and can communicate with the data receiving device 120 via a communication path 140 using wired or wireless technology. Exemplary wireless protocols include Bluetooth, Bluetooth Low Energy (BLE, BTLE, Bluetooth SMART, etc.), Near Field Communication (NFC), and others. The user can use the screen 122 and the input 121 to monitor application programs in the memory installed on the data receiving device 120, and the device battery can be recharged using the power port 123. More details regarding the data receiving device 120 are set forth below with respect to Figure 2A The data receiving device 120 can communicate with the local computer system 170 via a communication path 141 using wired or wireless technology. The local computer system 170 can include one or more of a laptop computer, a desktop computer, a tablet computer, a flat panel television, a smart phone, a set-top box, a video game console, or other computing devices, and the wireless communication can include any one of a plurality of suitable wireless networking protocols including Bluetooth, Bluetooth Low Energy (BTLE), Wi-Fi, or others. The local computer system 170 can communicate with the network 190 via a communication path 143, similar to the way the data receiving device 120 can communicate with the network 190 via a communication path 142 using wired or wireless technology as previously described. The network 190 can be any one of many networks, such as a private network and a public network, a local area network, or a wide area network, etc. The trusted computer system 180 can include a server and can provide authentication services and secure data storage, and can communicate with the network 190 via a communication path 144 using wired or wireless technology.

[0079] Figure 1B Another exemplary embodiment of the operating environment of the analyte monitoring system 100 capable of implementing the techniques described herein is shown. As shown, the analyte monitoring system 100 can include a system of components designed to provide monitoring of parameters (such as analyte levels) of a human or animal body, or can provide other operations based on the configuration of the various components. As implemented herein, the system can include a low-power sensor control device 102 worn by the user or attached to the body from which information is being collected. As implemented herein, the sensor control device 102 can be a sealed, disposable device having a predetermined useful life (e.g., 1 day, 14 days, 30 days, etc.). The sensor control device 102 can be applied to the skin of the user's body and remain adhered for the duration of the sensor life, or can be designed to be selectively removed and remain functional when reapplied. The analyte monitoring system 100 can also include a data reading device 120 or a multi-purpose hardware device 130 configured as described herein to facilitate the retrieval and conveyance of data (including analyte data) from the sensor control device 102.

[0080] The sensor control device 102 can communicate with the data receiving device 120 or the multi-purpose hardware device 130 using wired or wireless technologies. Exemplary wireless protocols include Bluetooth, Bluetooth Low Energy (BLE, BTLE, Bluetooth SMART, etc.), Near Field Communication (NFC), and others. The data receiving device 120 can also communicate with the multi-purpose hardware device 130 or another user device 140 using wired or wireless technologies. The user device 140 can include one or more of a laptop computer, a desktop computer, a tablet computer, a flat-panel television, a smart phone, a set-top box, a video game console, or other computing devices, and the wireless communication can include any one of a plurality of applicable wireless networking protocols including Bluetooth, Bluetooth Low Energy (BTLE), Wi-Fi, or others. The user computing device 140 can communicate with a network, similar to the way the data receiving device 120 can communicate via wired or wireless technologies as previously described. The multi-purpose hardware device 130 and the user device 140 can communicate with a remote application server 155 to provide data such as analyte data from the sensor control device 102, identification data from the sensor control device 102 or the sending device, and derivative data based on the analyte data. Further, as described herein, the remote application server 155 can communicate certain data with the data monitoring device 135 according to permissions and instructions set by or on behalf of the user. The data monitoring device 135 is described in detail herein.

[0081] As implemented herein, the analyte monitoring system 100 can include, for example, a software or firmware library or application provided to a third party via the remote application server 155 and incorporated into the multi-purpose hardware device 130 (such as a mobile phone, a tablet computer, a personal computing device, or other similar computing devices capable of communicating with the sensor control device 102 via a communication link). The multi-purpose hardware can also include an embedded device, including but not limited to an insulin pump or an insulin pen, which has an embedded library configured to communicate with the sensor control device 102. Although the illustrated embodiments of the analyte monitoring system 100 include only one of each of the illustrated devices, the present disclosure contemplates that the analyte monitoring system 100 incorporates multiples of each component that interact with each other throughout the system. For example but not limited to, as implemented herein, the data receiving device 120 and / or the multi-purpose hardware device 130 can include multiples of each. As implemented herein, the multi-purpose hardware device 130 can communicate directly with the sensor control device 102 as described herein. Additionally or alternatively, the data receiving device 120 can communicate with an auxiliary data receiving device 130 to provide analyte data, or visualization or analysis of data, for secondary display to the user or other authorized parties.

[0082] The analyte monitoring system 100 may also include, for example, a software or firmware library or application program provided via a remote application server 155 to other multi-purpose hardware devices that do not directly receive data from the sensor control device 102. These data monitoring devices 135 instead receive data originating from the sensor control device 102 via the remote application service 155 or other associated services. In certain embodiments, the software library or application program provided for the data monitoring devices 135 is the same as the application program provided for the multi-purpose device 130, but is used in a different environment. In certain embodiments, they are separate application programs for their intended purposes only.

[0083] Figure 2A FIG. is a block diagram depicting an exemplary embodiment of a data receiving device 120 configured as a smart phone. Here, the data receiving device 120 may include a display 122, an input component 121, and a processing core 206 that includes a communication processor 222 coupled to a memory 223 and an application processor 224 coupled to a memory 225. A separate memory 230, an RF transceiver 228 having an antenna 229, and a power supply 226 having a power management module 238 may also be included. A multi-functional transceiver 232 may also be included, which may communicate with an antenna 234 via Wi-Fi, NFC, Bluetooth, BTLE, and GPS. As will be understood by those skilled in the art, these components are electrically and communicatively coupled in a manner that forms a functional device.

[0084] The data receiving device 120 may be a mobile communication device, such as, for example, a smart phone, a tablet computer, or a personal digital assistant (PDA) that supports Wi-Fi or the Internet. Examples of smart phones may include, but are not limited to, those phones based on various commercial operating systems that have a data network connection function for data communication via the Internet connection and / or a local area network (LAN).

[0085] The data receiving device 120 may also be configured as a mobile intelligent wearable electronic device component, such as an optical component (e.g., smart glasses) worn above or near the user's eyes. The optical component may have a transparent display that displays information about the user's analyte level (as described herein) to the user while allowing the user to view through the display, such that the user's overall vision is minimally obstructed. The optical component is capable of wireless communication similar to that of a smart phone. Other examples of wearable electronic devices include devices worn around or near the user's wrist (e.g., smart watch, etc.), neck (e.g., necklace, etc.), head (e.g., headband, hat, etc.), chest, etc.

[0086] For purposes of illustration and not limitation, reference is made to those used in connection with Figure 2BAnother exemplary embodiment of the data receiving device 120 for use with the disclosed subject matter shown herein. The data receiving device 120 and the associated multi-purpose data receiving device 130 include components that are closely related to the discussion of the sensor control device 102 and its operation, and may include additional components. In a particular embodiment, the data receiving device 120 and the multi-purpose data receiving device 130 may be or include components provided by a third party and need not be limited to including devices manufactured by the same manufacturer as the sensor control device 102.

[0087] As Figure 2B shown, the data receiving device 120 includes an ASIC 4000 that includes a microcontroller 4010, a memory 4020, and a storage device 4030, and is communicatively coupled to a communication module 4040. Power for the components of the data receiving device 120 may be delivered by a power module 4050, which, as implemented herein, may include a rechargeable battery. The data receiving device 120 may also include a display 4070 for facilitating viewing of analyte data received from the sensor control device 102 or other devices (e.g., the user device 145 or the remote application server 155). The data receiving device 120 may include separate user interface components (e.g., physical keys, light sensors, microphones, etc.).

[0088] The communication module 4040 may include a BLE 4041 module and an NFC module 4042. The data receiving device 120 may be configured to wirelessly couple to the sensor control device 102 and transmit commands to and receive data from the sensor control device 102. As implemented herein, the data receiving device 120 may be configured to operate as an NFC scanner and a BLE endpoint via a particular module of the communication module 4040 (e.g., the BLE module 4042 or the NFC module 4043) with respect to the sensor control device 102 as described herein. For example, the data receiving device 120 may use a first module of the communication module 4040 to issue commands to the sensor control device 102 (e.g., an activation command for the data broadcast mode of the sensor; a pairing command for identifying the data receiving device 120), and use a second module of the communication module 4040 to receive data from and transmit data to the sensor control device 102. The data receiving device 120 may be configured to communicate with the user device 145 via a universal serial bus (USB) module 4045 of the communication module 4040.

[0089] As another example, communication module 4040 may include, for example, cellular radio module 4044. Cellular radio module 4044 may include one or more radio transceivers for communicating using a broadband cellular network, including but not limited to third generation (3G), fourth generation (4G), and fifth generation (5G) networks. Additionally, communication module 4040 of data receiving device 120 may include a Wi-Fi radio module 4043 for communicating using a wireless local area network according to one or more of the IEEE 802.11 standards (e.g., 802.11a, 802.11b, 802.11g, 802.11n (also known as Wi-Fi 4), 802.11ac (also known as Wi-Fi 5), 802.11ax (also known as Wi-Fi 6)). Using cellular radio module 4044 or Wi-Fi radio module 4043, data receiving device 120 may communicate with remote application server 155 to receive analyte data or provide (e.g., via one or more user interfaces) updates or inputs received from a user. Although not shown, communication module 5040 of analyte sensor 120 may similarly include a cellular radio module or a Wi-Fi radio module.

[0090] As implemented herein, on-board storage 4030 of data receiving device 120 may store analyte data received from sensor control device 102. Additionally, data receiving device 120, multipurpose data receiving device 130, or user device 145 may be configured to communicate with remote application server 155 via a wide area network. As implemented herein, sensor control device 102 may provide data to data receiving device 120 or multipurpose data receiving device 130. Data receiving device 120 may transmit the data to user computing device 145. User computing device 145 (or multipurpose data receiving device 130) may then transmit the data to remote application server 155 for processing and analysis.

[0091] As implemented herein, data receiving device 120 may also include sensing hardware 4060 similar to or an extension of sensing hardware 5060 of sensor control device 102. In a particular implementation, data receiving device 120 may be configured to coordinate with sensor control device 102 and operate based on analyte data received from sensor control device 102. As an example, in the case where sensor control device 102 is a glucose sensor, data receiving device 120 may be or include an insulin pump or an insulin injection pen. Collaboratively, compatible device 130 may adjust the user's insulin dose based on the glucose value received from the analyte sensor.

[0092] Figure 2C andFigure 2D is a block diagram depicting an exemplary embodiment of a sensor control device 102 having an analyte sensor 104 and sensor electronics 160 (including analyte monitoring circuitry), the sensor electronics of which may have most of the processing power for presenting final result data suitable for display to a user. In Figure 2C , a single semiconductor chip 161 is depicted, which may be a custom application specific integrated circuit (ASIC). Shown within the ASIC 161 are certain high-level functional units, including an analog front end (AFE) 162, a power management (or control) circuit 164, a processor 166, and a communication circuit 168 (which may be implemented as a transmitter, receiver, transceiver, passive circuit, or otherwise according to a communication protocol). In this embodiment, both the AFE 162 and the processor 166 serve as analyte monitoring circuitry, but in other embodiments, either circuit may perform the analyte monitoring function. The processor 166 may include one or more processors, microprocessors, controllers, and / or microcontrollers, each of which may be a discrete chip or distributed among multiple different chips (and portions thereof).

[0093] A memory 163 is also included within the ASIC 161 and may be shared by the various functional units present within the ASIC 161 or may be distributed among two or more of them. The memory 163 may also be a separate chip. The memory 163 may be volatile and / or non-volatile memory. In this embodiment, the ASIC 161 is coupled to a power source 172, which may be a coin cell battery or the like. The AFE 162 interfaces with the in vivo analyte sensor 104, receives measurement data therefrom, and outputs the data in digital form to the processor 166, which in turn processes the data to arrive at final result glucose discrete values and trend values, etc. The data may then be provided to the communication circuit 168 for transmission via an antenna 171 to a data receiving device 120 (not shown), e.g., in the data receiving device, the resident software application requires minimal further processing to display the data.

[0094] Figure 2D Similar to Figure 2C, but instead includes two discrete semiconductor chips 162 and 174, which may be packaged together or separately. Here, the AFE 162 resides on the ASIC 161. The processor 166 is integrated with the power management circuit 164 and the communication circuit 168 on the chip 174. The AFE 162 includes a memory 163, and the chip 174 includes a memory 165, which may be isolated or distributed therein. In one exemplary embodiment, the AFE 162, the power management circuit 164, and the processor 166 are combined on one chip, while the communication circuit 168 is on a separate chip. In another exemplary embodiment, both the AFE 162 and the communication circuit 168 are on one chip, and the processor 166 and the power management circuit 164 are on another chip. It should be noted that other chip combinations are possible, including three or more chips, each of which assumes the responsibility for the described individual functions or shares one or more functions to achieve fail-safe redundancy.

[0095] For purposes of illustration and not limitation, Figure 2E depicts another exemplary embodiment of a sensor control device 102 that is compatible with the security architecture and communication scheme described herein.

[0096] As implemented herein, the sensor control device 102 may include an application specific integrated circuit (“ASIC”) 5000 communicatively coupled to a communication module 5040. The ASIC 5000 may include a microcontroller core 5010, on-board memory 5020, and storage memory 5030. The storage memory 5030 may store data used in an authentication and encryption security architecture. The storage memory 5030 may store programming instructions for the sensor control device 102. As implemented herein, certain communication chipsets may be embedded in the ASIC 5000 (e.g., NFC transceiver 5025). The ASIC 5000 may receive power from a power module 5050 (such as an on-board battery) or from an NFC pulse. The storage memory 5030 of the ASIC 5000 may be programmed to include information such as an identifier of the sensor control device 102 for identification and tracking purposes. The storage memory 5030 may also be programmed with configuration or calibration parameters for use by the sensor control device 102 and its various components. The storage memory 5030 may include rewritable or one-time programmable (OTP) memory. The storage memory 5030 may be updated using the techniques described herein to extend the usefulness of the sensor control device 102.

[0097] As implemented herein, the communication module 5040 of the sensor control device 102 can be or include one or more modules to support communication with other devices of the analyte monitoring system 100. By way of example only and not limitation, the exemplary communication module 5040 can include a Bluetooth Low Energy (“BLE”) module 5041. As used throughout this disclosure, BLE refers to a short-range communication protocol that is optimized to make pairing of Bluetooth devices simple for the end user. The communication module 5040 can transmit and receive data and commands via interaction with communication modules of similar capabilities of the data receiving device 120 or the user device 145. The communication module 5040 can include additional or alternative chip sets for use in similar short-range communication schemes such as personal area networks according to the IEEE802.15 protocol, IEEE 802.11 protocol, infrared communication according to the Infrared Data Association standard (IrDA), etc.

[0098] To perform its functions, the sensor control device 102 can also include suitable sensing hardware 5060 appropriate for its functions. As implemented herein, the sensing hardware 5060 can include an analyte sensor positioned transcutaneously or subcutaneously to contact the body fluid of a subject. The analyte sensor can generate sensor data containing values corresponding to the levels of one or more analytes in the body fluid.

[0099] The components of the sensor control device 102 can be obtained by the user in multiple packages that require the user to perform a final assembly before transporting to the appropriate user location. Figures 3A to 3D An exemplary embodiment of the assembly process for the sensor control device 102 by the user is depicted, including preparing individual components before coupling the components in order to ready the sensor for transport. Figures 3E to 3F An exemplary embodiment of transporting the sensor control device 102 to the appropriate user location is depicted by selecting an appropriate transport location and applying the device 102 to that location.

[0100] Figure 3A is a proximal perspective view depicting an exemplary embodiment of a user preparing a container 810 for the assembly process, which container is configured herein as a tray (although other packages can be used). The user can complete this preparation by removing a lid 812 from the tray 810 to expose a platform 808 (e.g., by peeling an unadhered portion of the lid 812 from the tray 810 such that the adhered portion of the lid 812 is removed). Removal of the lid 812 is appropriate in various embodiments as long as the platform 808 is sufficiently exposed within the tray 810. The lid 812 can then be set aside.

[0101] Figure 3Bis a side view depicting an exemplary embodiment of a user preparing an applicator device 150 for assembly. The applicator device 150 may be provided in a sterile package sealed by an applicator cap 708. Preparation of the applicator device 150 may include decoupling the housing 702 from the applicator cap 708 to expose the sheath 704( Figure 3C ). This may be accomplished by unscrewing (or otherwise decoupling) the applicator cap 708 from the housing 702. The applicator cap 708 may then be set aside.

[0102] Figure 3C is a proximal perspective view depicting an exemplary embodiment of a user inserting the applicator device 150 into a tray 810 during assembly. Initially, after aligning the housing orientation feature 1302 (or slot or recess) and the tray orientation feature 924 (adjacency or pawl), the user may insert the sheath 704 into the platform 808 inside the tray 810. Inserting the sheath 704 into the platform 808 temporarily unlocks the sheath 704 relative to the housing 702 and also temporarily unlocks the platform 808 relative to the tray 810. At this stage, removing the applicator device 150 from the tray 810 will result in the same state as before the applicator device 150 was initially inserted into the tray 810 (i.e., the process may be reversed or aborted at this point and then repeated without consequence).

[0103] The sheath 704 may remain in position within the platform 808 relative to the housing 702 as the housing 702 is advanced distally, coupling with the platform 808 to advance the platform 808 distally relative to the tray 810. This step unlocks the platform 808 within the tray 810 and causes it to collapse. The sheath 704 may contact and disengage a locking feature (not shown) within the tray 810 that unlocks the sheath 704 relative to the housing 702 and prevents the sheath 704 from moving (relatively) as the housing 702 continues to advance the platform 808 distally. At the end of the advancement of the housing 702 and the platform 808, the sheath 704 is permanently unlocked relative to the housing 702. A sharp and a sensor (not shown) within the tray 810 may couple with an electronic device housing (not shown) within the housing 702 at the end of the distal advancement of the housing 702. The operation and interaction of the applicator device 150 and the tray 810 are further described below.

[0104] Figure 3Dis a proximal perspective view depicting an exemplary embodiment in which a user removes applicator device 150 from a tray 810 during assembly. The user can remove applicator 150 from tray 810 by advancing housing 702 proximally relative to tray 810 or other movement having the same ultimate effect of decoupling applicator 150 and tray 810. Applicator device 150 is removed such that sensor control device 102 (not shown) is fully assembled (sharps, sensor, electronics) therein and positioned for delivery.

[0105] Figure 3E is a proximal perspective view depicting an exemplary embodiment in which a patient uses applicator device 150 to apply sensor control device 102 to a target area of skin (e.g., on the abdomen or other suitable location). Advancing housing 702 distally collapses sheath 704 within housing 702 and applies the sensor to the target location such that an adhesive layer on the underside of sensor control device 102 adheres to the skin. When housing 702 is fully advanced, the sharp automatically retracts while the sensor (not shown) remains in place to measure analyte levels.

[0106] Figure 3F is a proximal perspective view depicting an exemplary embodiment of a patient with sensor control device 102 in an applied position. The user can then remove applicator 150 from the application site.

[0107] Compared to prior art systems, with respect to Figures 3A to 3F and system 100 described elsewhere herein, the possible accidental breakage, permanent deformation, or incorrect assembly of applicator components can be reduced or eliminated. Since housing 702 of the applicator directly engages platform 808 when sheath 704 is unlocked, rather than indirectly via sheath 704, the relative angle between sheath 704 and housing 702 will not cause breakage or permanent deformation of the arm or other components. The likelihood of relatively high forces during assembly (such as in conventional devices) will be reduced, which in turn reduces the likelihood of unsuccessful assembly by the user.

[0108] Figure 4A is a side view depicting an exemplary embodiment of applicator device 150 coupled to a screw applicator cap 708. This is an example of how applicator 150 is shipped to and received by the user prior to assembly with the sensor. Figure 4B is a side perspective view depicting applicator 150 and applicator cap 708 after decoupling. Figure 4C is a perspective view depicting an exemplary embodiment of the distal end of applicator device 150 with applicator cap 708 in place, where electronics housing 706 and adhesive patch 105 are removed from their positions within sensor carrier 710 of sheath 704.

[0109] For purposes of illustration and not limitation, reference is made to Figures 4D to 4G , another exemplary embodiment of applicator device 20150 may be provided to a user as a single integrated component. Figure 4D And Figure 4E respectively provide a perspective top view and a perspective bottom view of applicator device 20150, Figure 4F provides an exploded view of applicator device 20150, and Figure 4G provides a side cross-sectional view. The perspective view shows how applicator 20150 is delivered to and received by a user. The exploded view and the cross-sectional view show the components of applicator device 20150. Applicator device 20150 may include a housing 20702, a gasket 20701, a sheath 20704, a lancet carrier 201102, a spring 205612, a sensor carrier 20710 (also referred to as a “calibrator carrier”), a lancet base 205014, a sensor control device (also referred to as a “calibrator”) 20102, an adhesive patch 20105, a desiccant 20502, an applicator cap 20708, a sequence label 20709, and a tamper-resistant feature 20712. In some embodiments, when received by a user, only the housing 20702, the applicator cap 20708, the tamper-resistant feature 20712, and the label 20709 are visible. The tamper-resistant feature 20712 may be, for example, a sticker coupled to each of the housing 20702 and the applicator cap 20708, and the tamper-resistant feature 20712 may be irreparably damaged, for example, by decoupling the housing 20702 from the applicator cap 20708, thereby indicating to the user that the housing 20702 and the applicator cap 20708 have been previously decoupled. These features will be described in more detail below.

[0110] Figure 5 is a proximal perspective view depicting an exemplary embodiment of tray 810, with a sterilization cover 812 removably coupled thereto, which may represent how the package is delivered to and received by a user prior to assembly.

[0111] Figure 6A is a proximal perspective cross-sectional view depicting a sensor delivery component within tray 810. Platform 808 is slidably coupled within tray 810. Desiccant 502 is stationary relative to tray 810. Sensor module 504 is mounted within tray 810.

[0112] Figure 6B is a proximal perspective view depicting sensor module 504 in more detail. Here, the retaining arm extension 1834 of platform 808 releasably secures sensor module 504 in place. Module 2200 is coupled to connector 2300, lancet module 2500, and a sensor (not shown) such that they may be removed together as sensor module 504 during assembly.

[0113] Referring briefly again to Figure 1A and Figure 3A FIGS. 3A through 3G, for a two-piece architecture system, the sensor tray 810 and the sensor applicator 150 are provided to the user as separate packages, thus requiring the user to open each package and ultimately assemble the system. In some applications, the separate sealed packages allow the sensor tray 810 and the sensor applicator 150 to be sterilized in separate sterilization processes that are unique to the contents of each package and are otherwise incompatible with the contents of the other. More specifically, the sensor tray 810, which includes the plug assembly 207 (including the sensor 104 and the stylet 220), can be sterilized using radiation sterilization such as electron beam (or “e-beam”) irradiation. Suitable radiation sterilization processes include, but are not limited to, electron beam irradiation, gamma ray irradiation, X-ray irradiation, or any combination thereof. However, radiation sterilization can damage the electrical components disposed within the electronic device housing of the sensor control device 102. Thus, if the sensor applicator 150, which includes the electronic device housing of the sensor control device 102, needs to be sterilized, it can be sterilized via another method such as gas chemical sterilization using, for example, ethylene oxide. However, gas chemical sterilization may damage the enzymes or other chemical substances and biological agents included on the sensor 104. Due to this sterilization incompatibility, the sensor tray 810 and the sensor applicator 150 are typically sterilized in separate sterilization processes and then packaged separately, which requires the user to ultimately assemble the components for use.

[0114] Figure 7A and Figure 7B are, respectively, an exploded top view and an exploded bottom view of a sensor control device 3702 according to one or more embodiments. The housing 3706 and the support 3708 operate as opposing flip-top halves that enclose or otherwise substantially encapsulate the various electronic components of the sensor control device 3702. As shown, the sensor control device 3702 can include a printed circuit board assembly (PCBA) 3802 that includes a printed circuit board (PCB) 3804 having a plurality of electronic modules 3806 coupled thereto. Exemplary electronic modules 3806 include, but are not limited to, resistors, transistors, capacitors, inductors, diodes, and switches. Existing sensor control devices typically stack PCB components only on one side of the PCB. In contrast, the PCB components 3806 in the sensor control device 3702 can be dispersed around the surface areas on both sides (i.e., the top surface and the bottom surface) of the PCB 3804.

[0115] In addition to the electronic module 3806, the PCBA 3802 may also include a data processing unit 3808 mounted to the PCB 3804. The data processing unit 3808 may include, for example, an application specific integrated circuit (ASIC) configured to implement one or more functions or routines associated with the operation of the sensor control device 3702. More specifically, the data processing unit 3808 may be configured to perform data processing functions, where such functions may include, but are not limited to, filtering and encoding of data signals, where each data signal corresponds to the sampled analyte level of the user. The data processing unit 3808 may also include an antenna for communicating with the reader device 106 or otherwise communicating with the antenna.

[0116] A battery aperture 3810 may be defined in the PCB 3804 and sized to receive and house a battery 3812 configured to power the sensor control device 3702. Axial battery contacts 3814a and radial battery contacts 3814b may be coupled to the PCB 3804 and extend into the battery aperture 3810 to facilitate the transfer of power from the battery 3812 to the PCB 3804. As the name implies, the axial battery contacts 3814a may be configured to provide axial contacts for the battery 3812, while the radial battery contacts 3814b may provide radial contacts for the battery 3812. Positioning the battery 3812 within the battery aperture 3810 together with the battery contacts 3814a, 3814b helps to reduce the height H of the sensor control device 3702, which allows the PCB 3804 to be centered and its components to be dispersed on both sides (i.e., the top surface and the bottom surface). This also helps to facilitate the provision of a chamfer 3718 on the electronic device housing 3704.

[0117] The sensor 3716 may be centered relative to the PCB 3804 and include a tail 3816, a marker 3818, and a neck 3820 interconnecting the tail 3816 and the marker 3818. The tail 3816 may be configured to extend through a central aperture 3720 of the support 3708 for percutaneous reception under the skin of the user. Additionally, the tail 3816 may have an enzyme or other chemical substance included thereon to help facilitate analyte monitoring.

[0118] The marker 3818 may include a generally flat surface having one or more sensor contacts 3822 ( Figure 7B three are shown) disposed thereon. The sensor contacts 3822 may be configured to engage corresponding one or more circuit contacts 3824 ( Figure 7AThree are shown aligned and joined. In some embodiments, the sensor contact 3822 may include a carbon-impregnated polymer printed or otherwise digitally applied to the marker 3818. Existing sensor control devices typically include a connector made of silicone rubber that encapsulates one or more compliant carbon-impregnated polymer modules that serve as conductive contacts between the sensor and the PCB. In contrast, the presently disclosed sensor contact 3822 provides a direct connection between the sensor 3716 and the connection to the PCB 3804, which eliminates the need for prior art connectors and advantageously reduces the height H. Additionally, eliminating the compliant carbon-impregnated polymer module eliminates significant circuit resistance and thus improves circuit conductivity.

[0119] The sensor control device 3702 may also include a compliant member 3826 that may be arranged to be interposed between the marker 3818 and the inner surface of the housing 3706. More specifically, when the housing 3706 and the support 3708 are assembled with each other, the compliant member 3826 may be configured to provide a passive biasing load against the marker 3818 that forces the sensor contact 3822 into continuous engagement with the corresponding circuit contact 3824. In the illustrated embodiment, the compliant member 3826 is an elastomeric O-ring, but may alternatively include any other type of biasing device or mechanism, such as a compression spring, etc., without departing from the scope of the present disclosure.

[0120] The sensor control device 3702 may also include one or more electromagnetic shields, shown as a first shield 3828a and a second shield. The housing 3706 may provide or otherwise define a first clock receiving portion 3830a ( Figure 7B ) and a second clock receiving portion 3830b ( Figure 7B ), and the support 3708 may provide or otherwise define a first clock post 3832a ( Figure 7A ) and a second clock post 3832b ( Figure 7A ). Cooperating the first clock receiving portion 3830a and the second clock receiving portion 3830b with the first clock post 3832a and the second clock post 3832b, respectively, will properly align the housing 3706 with the support 3708.

[0121] Specific reference Figure 7A, the inner surface of the support 3708 may provide or otherwise define a plurality of pockets or depressions configured to receive various component parts of the sensor control device 3702 when the housing 3706 mates with the support 3708. For example, the inner surface of the support 3708 may define a battery locator 3834 configured to receive a portion of the battery 3812 during assembly of the sensor control device 3702. An adjacent contact pocket 3836 may be configured to receive a portion of the axial contact 3814a.

[0122] In addition, a plurality of module pockets 3838 may be defined in the inner surface of the support 3708 to receive various electronic modules 3806 disposed on the bottom of the PCB 3804. Further, a shield locator 3840 may be defined in the inner surface of the support 3708 to receive at least a portion of the second shield 3828b during assembly of the sensor control device 3702. The battery locator 3834, the contact pocket 3836, the module pockets 3838, and the shield locator 3840 all extend a short distance into the inner surface of the support 3708, and thus, the overall height H of the sensor control device 3702 may be reduced compared to existing sensor control devices. The module pockets 3838 may also help minimize the diameter of the PCB 3804 by allowing PCB components to be disposed on both sides (i.e., the top surface and the bottom surface).

[0123] Still referring to Figure 7A , the support 3708 may further include a plurality of carrier grip features 3842 (two are shown) defined around the outer perimeter of the support 3708. The carrier grip features 3842 are axially offset from the bottom 3844 of the support 3708, where a transfer adhesive (not shown) may be applied during assembly. Compared to existing sensor control devices that typically include conical carrier grip features that intersect the bottom of the support, the presently disclosed carrier grip features 3842 are offset from the plane (i.e., the bottom 3844) where the transfer adhesive is applied. This may prove beneficial in ensuring that the conveyance system does not inadvertently adhere to the transfer adhesive during assembly. Further, the presently disclosed carrier grip features 3842 eliminate the need for a fan-shaped transfer adhesive, which simplifies the manufacture of the transfer adhesive and eliminates the need to precisely time the transfer adhesive relative to the support 3708. This also increases the bonding area and thus increases the bonding strength.

[0124] Referring to Figure 7B, the bottom 3844 of the support 3708 may provide or otherwise define a plurality of grooves 3846, which may be defined at or near the outer periphery of the support 3708 and are equally spaced from each other. A transfer adhesive (not shown) may be coupled to the bottom 3844, and the grooves 3846 may be configured to help convey (transfer) moisture away from the sensor control device 3702 and toward the periphery of the support 3708 during use. In some embodiments, the spacing of the grooves 3846 may be between the module grooves 3838 defined on opposite sides (inner surfaces) of the support 3708 ( Figure 7A ). As will be appreciated, the alternation of the positions of the grooves 3846 and the module grooves 3838 ensures that the opposing features on either side of the support 3708 do not extend into each other. This may help maximize the use of material for the support 3708 and thus help maintain the minimum height H of the sensor control device 3702. The module grooves 3838 may also significantly reduce die sinking and improve the flatness of the bottom 3844 to which the transfer adhesive binds.

[0125] Still referring to Figure 7B , the inner surface of the housing 3706 may also provide or otherwise define a plurality of grooves or recesses configured to receive various component parts of the sensor control device 3702 when the housing 3706 mates with the support 3708. For example, the inner surface of the housing 3706 may define opposing battery locators 3848 that are arranged opposite the battery locators 3834 of the support 3708 ( Figure 7A ) and are configured to receive a portion of the battery 3812 when assembling the sensor control device 3702. The opposing battery locators 3848 extend a short distance into the inner surface of the housing 3706, which helps reduce the overall height H of the sensor control device 3702.

[0126] The spike and sensor locator 3852 may also be provided by or otherwise defined on the inner surface of the housing 3706. The spike and sensor locator 3852 may be configured to receive a spike (not shown) and a portion of the sensor 3716. Additionally, the spike and sensor locator 3852 may be configured to align and / or mate with corresponding spike and sensor locators 2054 provided on the inner surface of the support 3708 ( Figure 7A ).

[0127] According to an embodiment of the present disclosure, in Figures 8A to 8CAn alternative sensor component / electronic device component connection method is shown. As shown, the sensor component 14702 includes a sensor 14704, a connector support 14706, and a pointed object 14708. Notably, a recess or receiving portion 14710 may be defined in the bottom of the support of the electronic device component 14712, and provides a location where the sensor component 14702 can be received and coupled to the electronic device component 14712, and thus fully assemble the sensor control device. The profile of the sensor component 14702 may match or be shaped in a complementary manner to the receiving portion 14710, which includes an elastomeric seal member 14714 (including conductive material coupled to a circuit board and aligned with the electrical contacts of the sensor 14704). Thus, when the sensor component 14702 is snap - fit or otherwise adhered to the electronic device component 14712 by driving the sensor component 14702 into the recess 14710 integrally formed in the electronic device component 14712, the body - mounted device 14714 depicted in Figure 8C is formed. This embodiment provides an integrated connector for the sensor component 14702 within the electronic device component 14712.

[0128] Additional information regarding sensor components is provided in U.S. Publication No. 2013 / 0150691 and U.S. Publication No. 2021 / 0204841, each of which is incorporated herein by reference in its entirety.

[0129] According to an embodiment of the present disclosure, the sensor control device 102 can be modified to provide a one - piece architecture that can withstand sterilization techniques specifically designed for one - piece architecture sensor control devices. The one - piece architecture allows the sensor applicator 150 and the sensor control device 102 to be shipped to the user in a single sealed package without any end - user assembly steps. Instead, the user only needs to open one package and then transport the sensor control device 102 to the target monitoring location. The one - piece system architecture described herein can prove to be advantageous in eliminating component parts, various manufacturing process steps, and user assembly steps. Thus, packaging and waste are reduced, and the likelihood of user error or contamination of the system is alleviated.

[0130] Figure 9A and Figure 9B are a side view and a cross - sectional side view, respectively, of an exemplary embodiment of the sensor applicator 150, where the applicator cap 708 is coupled to the sensor applicator. More specifically, Figure 9A depicts how the sensor applicator 150 can be shipped to and received by the user, and Figure 9BDepicts a sensor control device 4402 disposed within a sensor applicator 150. Thus, the fully assembled sensor control device 4402 can be assembled and installed within the sensor applicator 150 before being delivered to the user, thereby eliminating any additional assembly steps that the user would otherwise have to perform.

[0131] The fully assembled sensor control device 4402 can be loaded into the sensor applicator 150, and an applicator cap 708 can then be coupled to the sensor applicator 150. In some embodiments, the applicator cap 708 can be threadedly coupled to the housing 702 and includes a tamper-evident ring 4702. When the applicator cap 708 is rotated (e.g., unscrewed) relative to the housing 702, the tamper-evident ring 4702 can shear and thereby release the applicator cap 708 from the sensor applicator 150.

[0132] According to the present disclosure, when loaded within the sensor applicator 150, the sensor control device 4402 can be subjected to gaseous chemical sterilization 4704 that is configured to sterilize the electronic device housing 4404 and any other exposed portions of the sensor control device 4402. To achieve this, a chemical can be injected into a sterilization chamber 4706 that is jointly defined by the sensor applicator 150 and the interconnect cap 210. In some applications, the chemical can be injected into the sterilization chamber 4706 via one or more air vents 4708 defined in the applicator cap 708 at the proximal end 610 thereof. Exemplary chemicals that can be used for gaseous chemical sterilization 4704 include, but are not limited to, ethylene oxide, vaporized hydrogen peroxide, nitrogen oxides (e.g., nitrous oxide, nitrogen dioxide, etc.), and vapors.

[0133] Since the distal portions of the sensor 4410 and the sharp 4412 are sealed within the sensor cap 4416, the chemicals used during the gaseous chemical sterilization process do not interact with the enzymes, chemicals, and biological agents disposed on the tail 4524 and other sensor components (such as the membrane coating that regulates the inflow of the analyte).

[0134] Once a desired level of sterility assurance has been achieved within the sterilization chamber 4706, the gaseous solution can be removed, and the sterilization chamber 4706 can be inflated. Inflation can be achieved by a series of vacuums and then circulating a gas (e.g., nitrogen) or filtered air through the sterilization chamber 4706. Once the sterilization chamber 4706 is properly inflated, the air vents 4708 can be sealed with a seal 4712 (shown in dashed lines).

[0135] In some embodiments, the seal 4712 may include two or more layers of different materials. The first layer may be made of a synthetic material (e.g., spunbonded high density polyethylene fibers), such as obtainable from obtained having high durability and puncture resistance and allowing vapor permeation. The layer may be applied before the gas chemical sterilization process, and after the gas chemical sterilization process, a layer of foil or other vapor and moisture resistant material may be sealed (e.g., heat sealed) over the layer to prevent contaminants and moisture from entering the sterilization chamber 4706. In other embodiments, the seal 4712 may include only a single protective layer applied to the applicator cap 708. In such embodiments, the single layer may be breathable for the sterilization process, but once the sterilization process is complete, the single layer is also capable of preventing moisture and other harmful elements.

[0136] With the seal 4712 in place, the applicator cap 708 provides a barrier against external contamination and thus maintains a sterile environment for the assembled sensor control device 4402 until the user removes (unscrews) the applicator cap 708. The applicator cap 708 may also create a dust-free environment during shipping and storage, preventing the adhesive patch 4714 from getting dirty.

[0137] Figure 10A and Figure 10B are an isometric view and a side view, respectively, of another exemplary sensor control device 5002 according to one or more embodiments of the present disclosure. The sensor control device 5002 may be similar in some aspects to the Figure 1A sensor control device 102 and may thus be best understood with reference to that sensor control device. Additionally, the sensor control device 5002 may replace the Figure 1A sensor control device 102 and may thus be used in conjunction with the Figure 1A sensing applicator 150 which may deliver the sensor control device 5002 to a target monitoring location on the user's skin.

[0138] However, unlike the Figure 1A sensor control device 102, the sensor control device 5002 may include an integrated system architecture that does not require the user to open multiple packages and finally assemble the sensor control device 5002 before application. Instead, upon receipt by the user, the sensor control device 5002 may already be fully assembled and properly positioned within the sensor applicator 150 (FIG. 1). To use the sensor control device 5002, the user only needs to open one barrier (e.g., Figure 3Bthe applicator cap 708), and then the sensor control device 5002 is rapidly transported to the target monitoring position for use.

[0139] As shown, the sensor control device 5002 includes an electronic device housing 5004, which is generally disk-shaped and may have a circular cross-section. However, in other embodiments, without departing from the scope of the present disclosure, the electronic device housing 5004 may assume other cross-sectional shapes, such as oval or polygonal. The electronic device housing 5004 may be configured to house or otherwise contain various electrical components for operating the sensor control device 5002. In at least one embodiment, an adhesive patch (not shown) may be disposed at the bottom of the electronic device housing 5004. The adhesive patch may be similar to Figure 1A the adhesive patch 105, and thus may help adhere the sensor control device 5002 to the user's skin for use.

[0140] As shown, the sensor control device 5002 includes an electronic device housing 5004, which includes an outer shell 5006 and a support 5008 that can cooperate with the outer shell 5006. The outer shell 5006 can be fixed to the support 5008 via various means, such as snap-fit engagement, interference fit, sonic welding, one or more mechanical fasteners (e.g., screws), washers, adhesives, or any combination thereof. In some cases, the outer shell 5006 can be fixed to the support 5008 such that a sealed interface is created therebetween.

[0141] The sensor control device 5002 may further include a sensor 5010 (partially visible) and a sharp object 5012 (partially visible) for assisting in the transdermal delivery of the sensor 5010 under the user's skin during the application of the sensor control device 5002. As shown, the corresponding portions of the sensor 5010 and the sharp object 5012 extend distally from the bottom of the electronic device housing 5004 (e.g., the support 5008). The sharp object 5012 may include a sharp object base 5014, which is configured to secure and carry the sharp object 5012. As best seen in Figure 10B the sharp object base 5014 may include or otherwise define a mating member 5016. To couple the sharp object 5012 to the sensor control device 5002, the sharp object 5012 may be axially advanced through the electronic device housing 5004 until the sharp object base 5014 engages the upper surface of the outer shell 5006 and the mating member 5016 extends distally from the bottom of the support 5008. When the sharp object 5012 penetrates the electronic device housing 5004, the exposed portion of the sensor 5010 may be received within the hollow or recessed (arcuate) portion of the sharp object 5012. The remaining portion of the sensor 5010 is disposed inside the electronic device housing 5004.

[0142] The sensor control device 5002 may also include a sensor cap 5018, shown in Figures 10A to 10B exploded or separated from the electronic device housing 5004. The sensor cap 5018 may be removably coupled to the sensor control device 5002 (e.g., the electronic device housing 5004) at or near the bottom of the support 5008. The sensor cap 5018 may help provide a sealing barrier that surrounds and protects the sensor 5010 and the exposed portion of the stylet 5012 from gas chemical sterilization. As shown, the sensor cap 5018 may include a generally cylindrical body having a first end 5020a and a second end 5020b opposite the first end 5020a. The first end 5020a may be open to provide access to an internal chamber 5022 defined within the body. In contrast, the second end 5020b may be closed and may provide or otherwise define engagement features 5024. As described herein, the engagement features 5024 may help mate the sensor cap 5018 to a cap (e.g., Figure 3A the applicator cap 708 of FIGS. 1 and Figure 3B to 3G) of the sensor applicator (e.g., the sensor applicator 150), and may help remove the sensor cap 5018 from the sensor control device 5002 when the cap is removed from the sensor applicator 150.

[0143] The sensor cap 5018 may be removably coupled to the electronic device housing 5004 at or near the bottom of the support 5008. More specifically, the sensor cap 5018 may be removably coupled to a mating member 5016 that extends distally from the bottom of the support 5008. In at least one embodiment, for example, the mating member 5016 may define a set of external threads 5026a ( Figure 10B ), which can mate with a set of internal threads 5026b ( Figure 10A ) defined by the sensor cap 5018. In some embodiments, the external threads 5026a and the internal threads 5026b may include a flat thread design (e.g., no helical curvature), which may prove advantageous when molding parts. Alternatively, the external threads 5026a and the internal threads 5026b may include helical thread engagement. Thus, the sensor cap 5018 may be threadably coupled to the sensor control device 5002 at the mating member 5016 of the stylet base 5014. In other embodiments, the sensor cap 5018 may be removably coupled to the mating member 5016 via other types of engagement, including but not limited to an interference fit or a friction fit, or a frangible member or substance that can be broken with a minimal separating force (e.g., an axial force or a rotational force).

[0144] In some embodiments, the sensor cap 5018 may include a monolithic (single) structure extending between a first end 5020a and a second end 5020b. However, in other embodiments, the sensor cap 5018 may include two or more component parts. In the illustrated embodiment, for example, the sensor cap 5018 may include a sealing ring 5028 positioned at the first end 5020a and a desiccant cap 5030 disposed at the second end 5020b. The sealing ring 5028 may be configured to assist in sealing the inner chamber 5022, as described in more detail below. In at least one embodiment, the sealing ring 5028 may include an elastomeric O-ring. The desiccant cap 5030 may house or include a desiccant to help maintain a preferred humidity level within the inner chamber 5022. The desiccant cap 5030 may also define or otherwise provide the engagement feature 5024 of the sensor cap 5018.

[0145] Figures 11A to 11C is a progressive cross-sectional side view showing the assembly of a sensor applicator 150 having a sensor control device 5002 according to one or more embodiments. Once the sensor control device 5002 is fully assembled, it can be loaded into the sensor applicator 150. Referring Figure 11A , the stylet base 5014 may include or otherwise define a base claw 5302 that is configured to assist in coupling the sensor control device 5002 to the sensor applicator 150. More specifically, the sensor control device 5002 may be advanced into the interior of the sensor applicator 150, and the base claw 5302 may be positioned to be received by a corresponding arm 5304 of a stylet carrier 5306 within the sensor applicator 150.

[0146] In Figure 11B , the sensor control device 5002 is shown being received by the stylet carrier 5306 and thus being secured within the sensor applicator 150. Once the sensor control device 5002 is loaded into the sensor applicator 150, an applicator cap 708 may be coupled to the sensor applicator 150. In some embodiments, the applicator cap 708 and the housing 702 may have opposing, mating sets of threads 5308 that enable the applicator cap 708 to be screwed onto the housing 702 in a clockwise (or counterclockwise) direction and thereby secure the applicator cap 708 to the sensor applicator 150.

[0147] As shown, the sheath 704 is also positioned within the sensor applicator 150, and the sensor applicator 150 can include a sheath locking mechanism 5310 configured to ensure that the sheath 704 does not prematurely collapse during an impact event. In the illustrated embodiment, the sheath locking mechanism 5310 can include a threaded engagement between the applicator cap 708 and the sheath 704. More specifically, one or more internal threads 5312a can be defined or otherwise provided on the inner surface of the applicator cap 708, and one or more external threads 5312b can be defined or otherwise provided on the sheath 704. The internal threads 5312a and the external threads 5312b can be configured to engage in a threaded fit when the applicator cap 708 is threadably coupled to the sensor applicator 150 at the threads 5308. The internal threads 5312a and the external threads 5312b can have the same pitch as the threads 5308 that enable the applicator cap 708 to be screwed onto the housing 702.

[0148] In Figure 11C it, the applicator cap 708 is shown as being fully threadably coupled (coupled) to the housing 702. As shown, the applicator cap 708 can also provide and otherwise define a cap post 5314 that is centered within the applicator cap 708 and extends proximally from its bottom. The cap post 5314 can be configured to receive at least a portion of the sensor cap 5018 when the applicator cap 708 is screwed onto the housing 702.

[0149] With the sensor control device 5002 loaded within the sensor applicator 150 and the applicator cap 708 properly secured, the sensor control device 5002 can then be subjected to gas chemical sterilization configured to sterilize the electronic device housing 5004 and any other exposed portions of the sensor control device 5002. Since the distal portions of the sensor 5010 and the sharp 5012 are sealed within the sensor cap 5018, the chemicals used during the gas chemical sterilization process do not interact with the enzymes, chemicals, and biological agents disposed on the tail 5104 and other sensor components such as the membrane coating that regulates the inflow of the analyte.

[0150] Figures 12A to 12C is a progressive cross-sectional side view showing the assembly and disassembly of an alternative embodiment of the sensor applicator 150 with the sensor control device 5002 according to one or more additional embodiments. The fully assembled sensor control device 5002 can be loaded into the sensor applicator 150 by coupling the base jaws 5302 to the arms 5304 of the sharp carrier 5306 positioned within the sensor applicator 150, as generally described above.

[0151] In the illustrated embodiment, the sheath arm 5604 of the sheath 704 can be configured to interact with a first pawl 5702a and a second pawl 5702b defined inside the housing 702. The first pawl 5702a can alternatively be referred to as the "locking" pawl, and the second pawl 5702b can alternatively be referred to as the "firing" pawl. When the sensor control device 5002 is initially installed in the sensor applicator 150, the sheath arm 5604 can be received within the first pawl 5702a. As discussed below, the sheath 704 can be actuated to move the sheath arm 5604 to the second pawl 5702b, which places the sensor applicator 150 in the firing position.

[0152] In Figure 12B , the applicator cap 708 is aligned with the housing 702 and advanced toward the housing 702 such that the sheath 704 is received within the applicator cap 708. Instead of rotating the applicator cap 708 relative to the housing 702, the threads 708 of the applicator cap can snap onto corresponding threads of the housing 702 to couple the applicator cap 708 to the housing 702. An axial cut or slot 5703 (one shown) defined in the applicator cap 708 can allow a portion of the applicator cap 708 near its threads to bend outwardly, thereby snapping into engagement with the threads of the housing 702. When the applicator cap 708 snaps onto the housing 702, the sensor cap 5018 can correspondingly snap into the cap post 5314.

[0153] Similar to Figures 11A to 11C embodiments, the sensor applicator 150 can include a sheath locking mechanism configured to ensure that the sheath 704 does not collapse prematurely during an impact event. In the illustrated embodiment, the sheath locking mechanism includes one or more ribs 5704 (one shown) defined near the base of the sheath 704 and configured to interact with one or more ribs 5706 (two shown) and a shoulder 5708 defined near the base of the applicator cap 708. The ribs 5704 can be configured to interlock between the ribs 5706 and the shoulder 5708 while attaching the applicator cap 708 to the housing 702. More specifically, once the applicator cap 708 snaps onto the housing 702, the applicator cap 708 can be rotated (e.g., clockwise), which positions the ribs 5704 of the sheath 704 between the ribs 5706 and the shoulder 5708 of the applicator cap 708, and thereby "locks" the applicator cap 708 in place until the user rotates the applicator cap 708 in the reverse direction to remove the applicator cap 708 for use. Engaging the ribs 5704 between the ribs 5706 and the shoulder 5708 of the applicator cap 708 can also prevent the sheath 704 from collapsing prematurely.

[0154] In Figure 12CRemove the applicator cap 708 from the housing 702. As with Figures 12A to 12C the embodiment of, the applicator cap 708 can be removed by rotating the applicator cap 708 in the reverse direction, which correspondingly rotates the cap post 5314 in the same direction and screws the sensor cap 5018 off the mating member 5016, as generally described above. Additionally, separating the sensor cap 5018 from the sensor control device 5002 exposes the distal portion of the sensor 5010 and the sharp 5012.

[0155] When the applicator cap 708 is unscrewed from the housing 702, the ribs 5704 defined on the sheath 704 can slidably engage the top of the ribs 5706 defined on the applicator cap 708. The top of the ribs 5706 can provide a corresponding inclined surface that causes the sheath 704 to be displaced upward as the applicator cap 708 rotates, and moving the sheath 704 upward causes the sheath arm 5604 to bend to disengage from the first pawl 5702a and be received within the second pawl 5702b. When the sheath 704 moves to the second pawl 5702b, the radial shoulder 5614 moves out of radial engagement with the carrier arm 5608, which allows the passive spring force of the spring 5612 to push the sharp carrier 5306 upward and force the carrier arm 5608 to disengage from the groove 5610. When the sharp carrier 5306 moves upward within the housing 702, the mating member 5016 can correspondingly retract until it becomes flush, substantially flush, or sub-flush with the bottom of the sensor control device 5002. At this time, the sensor applicator 150 is in the firing position. Thus, in this embodiment, removing the applicator cap 708 correspondingly causes the mating member 5016 to retract.

[0156] Figures 13 to Figure 13F illustrate exemplary details of an embodiment of an internal device mechanism that "fires" the applicator 150 to apply the sensor control device 102 to a user and includes safely retracting the sharp 1030 into the used applicator 150. In summary, these figures represent an exemplary sequence of driving the sharp 1030 (a sensor supported and coupled to the sensor control device 102) into the user's skin, withdrawing the sharp while leaving the sensor behind in operative contact with the user's interstitial fluid, and adhering the sensor control device to the user's skin with an adhesive. Those skilled in the art can understand modifications to such activities for use with alternative applicator assembly embodiments and components. Additionally, the applicator 150 can be a sensor applicator having a one-piece architecture or a two-piece architecture as disclosed herein.

[0157] Now turning to Figure 13A, the sensor 1102 is supported within the stylet 1030, just above the user's skin 1104. Tracks 1106 (optionally, three of them) of the upper guiding portion 1108 may be provided to control the movement of the applicator 150 relative to the sheath 704. The sheath 704 is held by a ratchet feature 1110 within the applicator 150 such that an appropriate downward force along the longitudinal axis of the applicator 150 will cause the resistance provided by the ratchet feature 1110 to be overcome, such that the stylet 1030 and the sensor control device 102 may be translated along the longitudinal axis into the user's skin 1104 (and onto the user's skin). Additionally, the capture arm 1112 of the sensor carrier 1022 engages the stylet retraction assembly 1024 to hold the stylet 1030 in position relative to the sensor control device 102.

[0158] In Figure 13B , a user force is applied to overcome or override the ratchet feature 1110, and the sheath 704 collapses into the housing 702, thereby driving the sensor control device 102 (along with associated components) to translate downward along the longitudinal axis as shown by arrow L. The inner diameter of the upper guiding portion 1108 of the sheath 704 constrains the position of the carrier arm 1112 throughout the stroke of the sensor / stylet insertion process. The stop surface 1114 of the carrier arm 1112 holds against the complementary surface 1116 of the stylet retraction assembly 1024 to hold the member in position with the return spring 1118 fully energized. According to an embodiment, the housing 702 may include a button (such as but not limited to a push button) that activates a drive spring (such as but not limited to a helical spring) to drive the sensor control device 102, rather than using a user force to drive the sensor control device 102 to translate downward along the longitudinal axis as shown by arrow L.

[0159] In Figure 13C , the sensor 1102 and the stylet 1030 have reached the full insertion depth. By doing so, the carrier arm 1112 clears the inner diameter of the upper guiding portion 1108. Then, as shown by the arrow R in Figure 13D , the compressive force of the helical return spring 1118 radially outward drives the angled stop surface 1114, releasing force to drive the stylet carrier 1102 of the stylet retraction assembly 1024, thereby pulling the (slotted or otherwise configured) stylet 1030 out of the user and away from the sensor 1102.

[0160] As Figure 13E shown, in the case where the stylet 1030 is fully retracted, the upper guiding portion 1108 of the sheath 704 is provided with a final locking feature 1120. As Figure 13FAs shown, the used applicator assembly 150 is removed from the insertion site, leaving the sensor control device 102, and the lancet 1030 is securely fixed inside the applicator assembly 150. The used applicator assembly 150 is now ready for disposal.

[0161] When the sensor control device 102 is applied, the operation of the applicator 150 is designed to provide the user with the sensation that both the insertion and retraction of the lancet 1030 are automatically performed by the internal mechanism of the applicator 150. In other words, the present invention avoids the user experiencing the feeling that he is manually driving the lancet 1030 into his skin. Thus, once the user applies sufficient force to overcome the resistance from the ratchet feature of the applicator 150, the resulting action of the applicator 150 is considered an automatic response to the applicator being "triggered" Although all of the driving force is provided by the user and no additional biasing / driving means are used to insert the lancet 1030, the user does not perceive that he is providing additional force to drive the lancet 1030 through his skin. As described in detail above in Figure 13C The retraction of the lancet 1030 is automatically performed by the helical return spring 1118 of the applicator 150.

[0162] Regarding any applicator embodiments described herein and any of its components (including but not limited to lancet, lancet module, and sensor module embodiments), those skilled in the art will understand that the embodiment can be sized and configured for use with a sensor configured to sense the level of an analyte in the body fluid of the epidermis, dermis, or subcutaneous tissue of a subject. In some embodiments, for example, both the lancet and the distal portion of the analyte sensor disclosed herein can be sized and configured to be positioned at a specific end depth (i.e., the farthest penetration point in the tissue or layer of the subject's body, e.g., in the epidermis, dermis, or subcutaneous tissue). Regarding some applicator embodiments, those skilled in the art will understand that certain embodiments of the lancet can be sized and configured to be positioned at different end depths within the subject's body relative to the final end depth of the analyte sensor. In some embodiments, for example, before retraction, the lancet can be positioned at a first end depth in the epidermis of the subject, while the distal portion of the analyte sensor can be positioned at a second end depth in the dermis of the subject. In other embodiments, before retraction, the lancet can be positioned at a first end depth in the dermis of the subject, while the distal portion of the analyte sensor can be positioned at a second end depth in the subcutaneous tissue of the subject. In still other embodiments, the lancet can be positioned at a first end depth before retraction, and the analyte sensor can be positioned at a second end depth, where both the first end depth and the second end depth are in the same layer or tissue of the subject's body.

[0163] Additionally, with respect to any applicator embodiment described herein, those skilled in the art will understand that the analyte sensor and one or more structural components coupled thereto (including but not limited to one or more spring mechanisms) may be disposed at an eccentric position within the applicator relative to one or more axes of the applicator. In some applicator embodiments, for example, the analyte sensor and the spring mechanism may be disposed at a first eccentric position relative to the axis of the applicator on a first side of the applicator, and the sensor electronics may be disposed at a second eccentric position with respect to the axis of the applicator on a second side of the applicator. In other applicator embodiments, the analyte sensor, the spring mechanism, and the sensor electronics may be disposed at eccentric positions on the same side relative to the axis of the applicator. Those skilled in the art will understand that other arrangements and configurations are possible in which any one or all of the analyte sensor, the spring mechanism, the sensor electronics, and other components of the applicator are disposed at a centered or eccentric position relative to one or more axes of the applicator and are fully within the scope of this disclosure.

[0164] Additional details of suitable devices, systems, methods, components, and their operations, as well as related features, are set forth in International Publication Nos. WO2018 / 136898 by Rao et al., WO2019 / 236850 by Thomas et al., WO2019 / 236859 by Thomas et al., WO2019 / 236876 by Thomas et al., and U.S. Patent Publication No. 2020 / 0196919, each of which is incorporated herein by reference in its entirety. Additional details regarding applicator embodiments, their components, and their variations are described in U.S. Patent Publication Nos. 2013 / 0150691, 2016 / 0331283, and 2018 / 0235520, all of which are incorporated herein by reference in their entirety and for all purposes. Additional details regarding embodiments of lancet modules, lancets, their components, and their variations are described in U.S. Patent Publication No. 2014 / 0171771, which is incorporated herein by reference in its entirety and for all purposes.

[0165] Biochemical sensors can be described by one or more sensing characteristics. A common sensing characteristic is referred to as the sensitivity of the biochemical sensor, which is a measure of the responsiveness of the sensor to the concentration of a chemical or component that it is designed to detect. For an electrochemical sensor, this response can be in the form of current (amperes) or charge (coulombs). For other types of sensors, the response can be in a different form, such as photon intensity (e.g., optical light). The sensitivity of a biochemical analyte sensor can vary depending on many factors, including whether the sensor is in an in vitro or in vivo state.

[0166] Figure 14 It is a graph depicting the in vitro sensitivity of an amperometric analyte sensor. The in vitro sensitivity can be obtained by performing in vitro tests on the sensor at various analyte concentrations and then performing regression (e.g., linear or non-linear) or other curve fitting on the resulting data. In this example, the sensitivity of the analyte sensor is linear or substantially linear and can be modeled according to the equation y = mx + b, where y is the electrical output current of the sensor, x is the analyte level (or concentration), m is the slope of the sensitivity, and b is the intercept of the sensitivity, where the intercept typically corresponds to the background signal (e.g., noise). For a sensor with a linear or substantially linear response, the analyte level corresponding to a given current can be determined based on the slope and intercept of the sensitivity. A sensor with non-linear sensitivity requires additional information to determine the analyte level resulting from the output current of the sensor, and those of ordinary skill in the art are familiar with the ways of modeling non-linear sensitivity. In certain embodiments of in vivo sensors, the in vitro sensitivity can be the same as the in vivo sensitivity, but in other embodiments, a transfer (or conversion) function is used to convert the in vitro sensitivity into an in vivo sensitivity suitable for the intended in vivo use of the sensor.

[0167] Calibration is a technique for improving or maintaining accuracy by adjusting the measured output of a sensor to reduce the difference from the expected output of the sensor. One or more parameters (such as its sensitivity) describing the sensing characteristics of the sensor are established for calibration adjustment.

[0168] Some in vivo analyte monitoring systems require calibration to be performed either through user interaction or automatically by the system itself after the sensor is implanted into a user or patient. For example, when user interaction is required, the user performs an in vitro measurement (e.g., a blood glucose (BG) measurement using a fingertip and an in vitro test strip) and inputs it into the system while the analyte sensor is implanted. The system then compares the in vitro measurement value with the in vivo signal and uses the difference to determine an estimate of the in vivo sensitivity of the sensor. The in vivo sensitivity can then be used in an algorithmic process to convert the data collected using the sensor into a value indicating the analyte level of the user. This process and other processes that require user operation to perform calibration are referred to as "user calibration". Due to the instability of the sensitivity of the sensor such that the sensitivity drifts or changes over time, the system may require user calibration. Thus, multiple user calibrations (e.g., according to a regular (e.g., daily) schedule, a variable schedule, or as needed) may be required to maintain accuracy. Although the embodiments described herein may incorporate a certain degree of user calibration for a particular implementation, this is generally not preferred because it requires the user to perform painful or otherwise burdensome BG measurements and may introduce user error.

[0169] Some in vivo analyte monitoring systems can periodically adjust calibration parameters by using automatic measurements of the characteristics of the sensor made by the system itself (e.g., a processing circuit that executes software). Repeated adjustment of the sensitivity of the sensor based on variables measured by the system (rather than the user) is commonly referred to as “system” (or automatic) calibration and can be performed in the case of user calibration (such as an early BG measurement) or without user calibration. As in the case of repeated user calibration, repeated system calibration is typically necessary as the sensitivity of the sensor drifts over time. Thus, while the embodiments described herein can be used with a degree of automatic system calibration, preferably, the sensitivity of the sensor is relatively stable over time such that post-implant calibration is not required.

[0170] Some in vivo analyte monitoring systems operate with factory-calibrated sensors. Factory calibration refers to determining or estimating one or more calibration parameters prior to distribution to a user or healthcare professional (HCP). The calibration parameters can be determined by the sensor manufacturer (or, if the two entities are different, by the manufacturer of other components of the sensor control device). Many in vivo sensor manufacturing processes produce sensors in groups or batches (referred to as production batches, manufacturing phase batches, or simply batches). A single batch can include thousands of sensors.

[0171] The sensor can include calibration codes or parameters that can be derived or determined during one or more sensor manufacturing processes and, as part of the manufacturing process, encoded or programmed in the data processing device of the analyte monitoring system or provided on the sensor itself, such as a barcode, laser tag, RFID tag, or other machine-readable information provided on the sensor. If the code is provided to the receiver (or other data processing device), user calibration during in vivo use of the sensor can be avoided, or the frequency of in vivo calibration during sensor wear can be reduced. In embodiments where the calibration code or parameters are provided on the sensor itself, the calibration code or parameters can be automatically transmitted or provided to the data processing device in the analyte monitoring system prior to or at the start of sensor use.

[0172] Some in vivo analyte monitoring systems operate with a sensor that can be one or more of factory-calibrated, system-calibrated, and / or user-calibrated. For example, the sensor can be provided with calibration codes or parameters that can permit factory calibration. If information is provided to the receiver (e.g., entered by the user), the sensor can operate as a factory-calibrated sensor. If the information is not provided to the receiver, the sensor can operate as a user-calibrated sensor and / or a system-calibrated sensor.

[0173] In another aspect, programming or executable instructions may be provided or stored in the data processing device and / or the receiver / controller unit of the analyte monitoring system to provide a time-varying adjustment algorithm to the in vivo sensor during use. For example, based on retrospective statistical analysis of the analyte sensor used in vivo and the corresponding glucose level feedback, a predefined or analyzed curve or database may be generated that is time-based and configured to provide additional adjustment to one or more in vivo sensor parameters to compensate for potential sensor drift or other factors in the stability profile.

[0174] According to the disclosed subject matter, the analyte monitoring system may be configured to compensate for or adjust sensor sensitivity based on a sensor drift profile. A time-varying parameter P(t) may be defined or determined based on analysis of sensor behavior during in vivo use, and a time-varying drift profile may be determined. In some aspects, compensation or adjustment of sensor sensitivity may be programmed in the receiver unit, controller, or data processor of the analyte monitoring system such that when sensor data is received from the analyte sensor, compensation or adjustment or both may be performed automatically and / or iteratively. According to the disclosed subject matter, the adjustment or compensation algorithm may be initiated or performed by the user (rather than self-initiated or performed) such that adjustment or compensation of the analyte sensor sensitivity profile is made or performed when the user initiates or activates the corresponding function or routine, or when the user enters a sensor calibration code.

[0175] According to the disclosed subject matter, each sensor in a batch of sensors (in some cases, excluding sample sensors for in vitro testing) can be inspected without damage to determine or measure its characteristics (such as the membrane thickness at one or more points of the sensor), and other characteristics including physical characteristics (such as the surface area / volume of the effective area) can be measured or determined. Such measurement or determination can be performed automatically using, for example, an optical scanner or other suitable measurement device or system, and the determined sensor characteristics of each sensor in the sensor batch are compared with the corresponding average values based on the sample sensors to make possible corrections to the calibration parameters or codes assigned to each sensor. For example, for a calibration parameter defined as the sensor sensitivity, the sensitivity is approximately inversely proportional to the membrane thickness, such that, for example, a sensor having a measured membrane thickness approximately 4% greater than the average membrane thickness of the sampling sensors from the same sensor batch as the sensor, in one embodiment, the sensitivity assigned to the sensor is the average sensitivity determined from the sampling sensors divided by 1.04. Similarly, since the sensitivity is approximately proportional to the effective area of the sensor, and the measured effective area of the sensor is approximately 3% lower than the average effective area of the sampling sensors from the same sensor batch, the sensitivity assigned to the sensor is the average sensitivity multiplied by 0.97. By making multiple successive adjustments for each inspection or measurement of the sensor, the assigned sensitivity can be determined based on the average sensitivity of the sampling sensors. In certain embodiments, the inspection or measurement of each sensor can include a measurement of the membrane consistency or texture in addition to the membrane thickness and / or the surface area or volume of the effective sensing area.

[0176] Additional information regarding sensor calibration is provided in U.S. Publication No. 2010 / 0230285 and U.S. Publication No. 2019 / 0274598, each of which is incorporated herein by reference in its entirety.

[0177] The storage memory 5030 of the sensor control device 102 may include software blocks related to the communication protocols of the communication module. For example, the storage memory 5030 may include a BLE service software block that has the function of providing an interface to make the BLE module 5041 available to the computing hardware of the sensor control device 102. These software functions may include a BLE logic interface and an interface parser. The BLE services provided by the communication module 5040 may include a Generic Access Profile service, a Generic Attribute service, a Generic Access service, a Device Information service, a Data Transfer service, and a Security service. The Data Transfer service may be the primary service for transferring data, such as sensor control data, sensor status data, analyte measurement data (historical and current), and event log data. The sensor status data may include error data, current activation time, and software status. The analyte measurement data may include information such as current and historical raw measurements, current and historical values after being processed using appropriate algorithms or models, predictions and trends of measurement levels, comparisons of other values with patient-specific averages, action requirements determined by algorithms or models, and other similar types of data.

[0178] In accordance with aspects of the disclosed subject matter and as implemented herein, the sensor control device 102 may be configured to communicate with multiple devices simultaneously by adapting the characteristics of the communication protocols or media supported by the hardware and radio of the sensor control device 102. As an example, the BLE module 5041 of the communication module 5040 may be provided with software or firmware to enable multiple concurrent connections between the sensor control device 102 acting as a central device and other devices acting as peripheral devices, or as a peripheral device to another device acting as a central device.

[0179] The connection and subsequent communication session between two devices using a communication protocol such as BLE may be characterized by a similar physical channel operating between the two devices (e.g., the sensor control device 102 and the data receiving device 120). The physical channel may include a single channel or a series of channels, including for example but not limited to using an agreed-upon series of channels determined by a common clock and channel or a frequency hopping sequence. The communication session may use a similar amount of available communication spectrum, and multiple such communication sessions may be in close proximity. In certain embodiments, each set of devices in a communication session uses a different physical channel or series of channels to manage interference from the same closely located devices.

[0180] For purposes of illustration and not limitation, reference is made to an exemplary embodiment of a process for sensor-receiver connection for use with the disclosed subject matter. First, the sensor control device 102 repeatedly advertises its connection information to its environment when searching for the data receiving device 120. The sensor control device 102 may repeatedly advertise at regular intervals until a connection is established. The data receiving device 120 detects the advertisement packet and scans and filters the sensor control device 102 to connect via the data provided in the advertisement packet. Next, the data receiving device 120 sends a scan request command, and the sensor control device 102 responds with a scan response packet providing additional details. Then, the data receiving device 120 sends a connection request using the Bluetooth device address associated with the data receiving device 120. The data receiving device 120 may also continuously request to establish a connection to the sensor control device 102 having a specific Bluetooth device address. Then, the devices establish an initial connection, allowing them to start exchanging data. These devices start the process of initializing the data exchange service and performing the mutual authentication process.

[0181] During a first connection between the sensor control device 102 and the data receiving device 120, the data receiving device 120 may initialize the service, characteristic, and attribute discovery process. The data receiving device 120 may evaluate these characteristics of the sensor control device 102 and store them for use during subsequent connections. Next, the devices enable the notification of a customized security service for mutual authentication of the sensor control device 102 and the data receiving device 120. The mutual authentication process may be automated and does not require user interaction. After the mutual authentication process is successfully completed, the sensor control device 102 sends a connection parameter update to request that the data receiving device 120 use the connection parameter settings preferred by the sensor control device 102 and configured for maximum lifetime.

[0182] The data receiving device 120 then performs a sensor control process to backfill historical data, current data, event logs, and plant data. As an example, for each type of data, the data receiving device 120 sends a request to initiate the backfill process. The request may appropriately specify a record range defined based on, for example, measurement values, timestamps, etc. The sensor control device 102 responds with the requested data until all previously unsent data in the memory of the sensor control device 102 has been transmitted to the data receiving device 120. The sensor control device 102 may respond to the backfill request from the data receiving device 120 that all data has been sent. Once the backfill is complete, the data receiving device 120 can notify the sensor control device 102 that it is ready to receive regular measurement readings. The sensor control device 102 may send readings on a repeating basis across multiple notification results. As implemented herein, the multiple notifications may be redundant notifications to ensure that data is correctly transmitted. Alternatively, the multiple notifications may form a single payload.

[0183] For purposes of illustration and not limitation, reference is made to an exemplary implementation of the process of sending a shutdown command to the sensor control device 102. If the sensor control device 102 is in, for example, an error state, an insertion failure state, or a sensor expiration state, a shutdown operation is performed. If the sensor control device 102 is not in these states, the sensor control device 102 may record the command and perform a shutdown when the sensor control device 102 transitions to an error state or a sensor expiration state. The data receiving device 120 sends a properly formatted shutdown command to the sensor control device 102. If the sensor control device 102 is actively processing another command, the sensor control device 102 will respond with a standard error response indicating that the sensor control device 102 is busy. Otherwise, the sensor control device 102 sends a response upon receiving the command. Additionally, the sensor control device 102 sends a success notification via the sensor control feature to confirm that the sensor control device 102 has received the command. The sensor control device 102 registers the shutdown command. At the next appropriate time (e.g., depending on the current sensor state as described herein), the sensor control device 102 will shut down.

[0184] For purposes of illustration and not limitation, reference is made to as Figure 15An exemplary embodiment of a high-level description of a state machine representation 6000 of actions that the sensor control device 102 shown in [figure] can take. After initialization, the sensor enters a state 6005 related to the manufacture of the sensor control device 102. In the manufacturing state 6005, the sensor control device 102 can be configured for operation. For example, the storage memory 5030 can be written. At different times when in state 6005, the sensor control device 102 checks for a received command to enter the storage state 6015. When entering the storage state 6015, the sensor performs a software integrity check. When in the storage state 6015, the sensor can also receive an activation request command before proceeding to the insertion detection state 6025.

[0185] When entering state 6025, the sensor control device 102 can store information related to a device authenticated to communicate with the sensor during activation, or initialize algorithms related to making and interpreting measurements from the sensing hardware 5060. The sensor control device 102 can also initialize a life cycle timer that is responsible for maintaining a valid count of the operating time of the sensor control device 102 and start communicating with the authenticated device to transmit the recorded data. When in the insertion detection state 6025, the sensor can enter a state 6030 where the sensor control device 102 checks whether the operating time is equal to a predetermined threshold. This operating time threshold can correspond to a timeout function for determining whether the insertion was successful. If the operating time has reached the threshold, the sensor control device 102 proceeds to a state 6035 where the sensor control device 102 checks whether the average data reading is greater than a threshold amount corresponding to an expected data read amount for triggering detection of a successful insertion. If the data read amount is below the threshold in state 6035, the sensor proceeds to a state 6040 corresponding to an insertion failure. If the data read amount meets the threshold, the sensor proceeds to the valid pairing state 6055.

[0186] The valid pairing state 6055 of the sensor control device 102 reflects the state when the sensor control device 102 is operating normally by recording measurement values, processing the measurement values, and reporting the measurement values appropriately. When in the valid pairing state 6055, the sensor control device 102 sends measurement results or attempts to establish a connection with the receiving device 120. The sensor control device 102 also increments the operating time. Once the sensor control device 102 reaches a predetermined threshold operating time (e.g., once the operating time reaches a predetermined threshold), the sensor control device 102 transitions to the valid expiration state 6065. The valid expiration state 6065 of the sensor control device 102 reflects the state when the sensor control device 102 has operated for its maximum predetermined amount of time.

[0187] When in the active expiration state 6065, the sensor control device 102 can generally perform operations related to a gradual reduction operation and ensure that the collected measurement values have been securely transmitted to the receiving device as required. For example, when in the active expiration state 6065, the sensor control device 102 can transmit the collected data and, if no connection is available, can increase the effort to discover nearby authenticated devices and establish a connection with them. When in the active expiration state 6065, the sensor control device 102 can receive a shutdown command at state 6070. If no shutdown command is received, the sensor control device 102 can also check at state 6075 whether the operation time has exceeded the final operation threshold. The final operation threshold can be based on the battery life of the sensor control device 102. The normal termination state 6080 corresponds to the final operation of the sensor control device 102 and finally shuts down the sensor control device 102.

[0188] Before the sensor is activated, the ASIC 5000 is in a low-power storage mode state. For example, when an incoming RF field (e.g., NFC field) drives the power supply voltage of the ASIC 5000 above the reset threshold, the activation process can begin, which causes the sensor control device 102 to enter the wake-up state. When in the wake-up state, the ASIC 5000 enters the activation sequence state. The ASIC 5000 then wakes up the communication module 5040. The communication module 5040 is initialized, thereby triggering a power-on self-test. The power-on self-test can include the ASIC 5000 communicating with the communication module 5040 using a predefined sequence of reading and writing data to verify that the memory and one-time programmable memory are not damaged.

[0189] When the ASIC 5000 first enters the measurement mode, an insertion detection sequence is executed to verify that the sensor control device 102 has been properly installed on the patient's body before appropriate measurements can be made. First, the sensor control device 102 interprets the command to activate the measurement configuration process, causing the ASIC 5000 to enter the measurement command mode. The sensor control device 102 then temporarily enters the measurement life cycle state to run multiple consecutive measurements to test whether the insertion has been successful. The communication module 5040 or the ASIC 5000 evaluates the measurement results to determine the success of the insertion. When the insertion is considered successful, the sensor control device 102 enters the measurement state, in which the sensor control device 102 begins to make regular measurements using the sensing hardware 5060. If the sensor control device 102 determines that the insertion is not successful, the sensor control device 102 is triggered to enter the insertion failure mode, in which the ASIC 5000 is commanded to return to the storage mode while the communication module 5040 disables itself.

[0190] Figure 1BAn exemplary operating environment for providing over-the-air (“OTA”) updates for use with the techniques described herein is further shown. An operator of the analyte monitoring system 100 can bundle updates to the data receiving device 120 or the sensor control device 102 into an update to an application that executes on the multi-purpose data receiving device 130. Using the available communication channels between the data receiving device 120, the multi-purpose data receiving device 130, and the sensor control device 102, the multi-purpose data receiving device 130 can receive periodic updates to the data receiving device 120 or the sensor control device 102 and initiate installation of the updates on the data receiving device 120 or the sensor control device 102. The multi-purpose data receiving device 130 serves as an installation or update platform for the data receiving device 120 or the sensor control device 102 because an application that enables the multi-purpose data receiving device 130 to communicate with the sensor control device 102, the data receiving device 120, and / or the remote application server 155 can update the software or firmware on the data receiving device 120 or the sensor control device 102 without wide area network capabilities.

[0191] As implemented herein, the remote application server 155, operated by the manufacturer of the sensor control device 102 and / or the operator of the analyte monitoring system 100, can provide software and firmware updates to the devices of the analyte monitoring system 100. In a particular implementation, the remote application server 155 can provide updated software and firmware to the user device 145 or directly to the multi-purpose data receiving device. As implemented herein, the remote application server 155 can also provide application software updates to the application store server 160 using an interface provided by the application store. The multi-purpose data receiving device 130 can periodically contact the application store server 160 to download and install the updates.

[0192] After the multi-purpose data receiving device 130 downloads an application update that includes a firmware or software update for the data receiving device 120 or the sensor control device 102, the data receiving device 120 or the sensor control device 102 and the multi-purpose data receiving device 130 establish a connection. The multi-purpose data receiving device 130 determines that a firmware or software update is available for the data receiving device 120 or the sensor control device 102. The multi-purpose data receiving device 130 may prepare the software or firmware update for transmission to the data receiving device 120 or the sensor control device 102. As an example, the multi-purpose data receiving device 130 may compress or segment data associated with the software or firmware update, may encrypt or decrypt the firmware or software update, or may perform an integrity check of the firmware or software update. The multi-purpose data receiving device 130 sends data for the firmware or software update to the data receiving device 120 or the sensor control device 102. The multi-purpose data receiving device 130 may also send a command to the data receiving device 120 or the sensor control device 102 to initiate the update. Additionally or alternatively, the multi-purpose data receiving device 130 may provide a notification to the user of the multi-purpose data receiving device 130 and include instructions for facilitating the update, such as instructions to keep the data receiving device 120 and the multi-purpose data receiving device 130 connected to power and in close proximity until the update is complete.

[0193] The data receiving device 120 or the sensor control device 102 receives the data for the update and the command to initiate the update from the multi-purpose data receiving device 130. The data receiving device 120 may then install the firmware or software update. To install the update, the data receiving device 120 or the sensor control device 102 may place or restart itself in a so-called "safe" mode with limited operating capabilities. Once the update is complete, the data receiving device 120 or the sensor control device 102 re-enters or resets to the standard operating mode. The data receiving device 120 or the sensor control device 102 may perform one or more self-checks to determine that the firmware or software update has been successfully installed. The multi-purpose data receiving device 130 may receive a notification of a successful update. The multi-purpose data receiving device 130 may then report the confirmation of the successful update to the remote application server 155.

[0194] In a particular embodiment, the storage memory 5030 of the sensor control device 102 includes a one-time programmable (OTP) memory. The term OTP memory may refer to a memory that includes access restrictions and security to facilitate writing to a particular address or section in the memory a predetermined number of times. The memory 5030 may be pre-arranged into a plurality of pre-allocated memory blocks or containers. The containers are pre-allocated to a fixed size. If the storage memory 5030 is a one-time programmable memory, the containers may be considered to be in a non-programmable state. Additional containers that have not been written to may be placed in a programmable or writable state. Containerizing the storage memory 5030 in this manner may improve the transportability of the code and data to be written to the storage memory 5030. Updating the software of a device (e.g., the sensor device described herein) stored in the OTP memory may be performed by replacing the code in only a particular previously written one or more containers with updated code written to one or more new containers rather than replacing the entire code in the memory. In a second embodiment, the memory is not pre-arranged. Instead, the space allocated for data is dynamically allocated or determined as needed. Since containers of different sizes may be defined in anticipation of updates, incremental updates may be issued.

[0195] Figure 16 is a schematic diagram showing exemplary operations and data flows for over-the-air (OTA) programming of the storage memory 5030 in the sensor control device 102 according to the disclosed subject matter and the use of the memory after OTA programming during execution by the sensor device 110. In Figure 16 the exemplary OTA programming 500 shown, a request is sent from an external device (e.g., the data receiving device 130) to initiate OTA programming (or reprogramming). At 511, the communication module 5040 of the sensor device 110 receives the OTA programming command. The communication module 5040 sends the OTA programming command to the microcontroller 5010 of the sensor device 110.

[0196] At 531, after receiving an OTA programming command, the microcontroller 5010 verifies the OTA programming command. The microcontroller 5010 can determine, for example, whether the OTA programming command is signed with an appropriate digital signature token. When determining that the OTA programming command is valid, the microcontroller 5010 can set the sensor device into the OTA programming mode. At 532, the microcontroller 5010 can verify the OTA programming data. At 533, the microcontroller 5010 can reset the sensor device 110 to re-initialize the sensor device 110 to a programming state. Once the sensor device 110 has been transitioned to the OTA programming state, the microcontroller 5010 can start writing data to the rewritable memory 540 (e.g., memory 5020) of the sensor device at 534 and write data to the OTP memory 550 (e.g., storage memory 5030) of the sensor device at 535. The data written by the microcontroller 5010 can be based on the verified OTA programming data. The microcontroller 5010 can write data such that one or more programming blocks or regions of the OTP memory 550 are marked as invalid or inaccessible. The data written to the free or unused portion of the OTP memory can be used to replace the invalid or inaccessible programming blocks of the OTP memory 550. After the microcontroller 5010 writes data to the respective memories at 534 and 535, the microcontroller 5010 can perform one or more software integrity checks to ensure that errors are not introduced into the programming blocks during the writing process. Once the microcontroller 5010 can determine that the data has been written without errors, the microcontroller 5010 can resume the standard operation of the sensor device.

[0197] In the execution mode, at 536, the microcontroller 5010 can retrieve a programming manifest or configuration file from the rewritable memory 540. The programming manifest or configuration file can include a list of valid software programming blocks and can include guidelines for program execution of the sensor control device 102. By following the programming manifest or configuration file, the microcontroller 5010 can determine which memory blocks of the OTP memory 550 are suitable for execution and avoid executing obsolete or invalid programming blocks or referring to obsolete data. At 537, the microcontroller 5010 can selectively retrieve memory blocks from the OTP memory 550. At 538, the microcontroller 5010 can use the retrieved memory blocks by executing stored programming code or using variables stored in the memory.

[0198] As implemented herein, a first security layer for communication between the sensor control device 102 and other devices can be established based on a security protocol specified by and integrated within the communication protocol for communication. Another security layer can be based on a communication protocol that requires close proximity of the communication devices. Additionally, certain packets and / or certain data included within a packet can be encrypted, while other packets and / or data within the packet are encrypted in other ways or not encrypted. Additionally or alternatively, application layer encryption can be used in conjunction with one or more block ciphers or stream ciphers to establish mutual authentication and communication encryption with other devices in the analyte monitoring system 100.

[0199] The ASIC 5000 of the sensor control device 102 can be configured to dynamically generate authentication and encryption keys using data held within the storage memory 5030. The storage memory 5030 can also be pre-programmed with a set of valid authentication and encryption keys for use with a particular kind of device. The ASIC 5000 can also be configured to use the received data to perform an authentication process with other devices and apply the generated keys to sensitive data before transmission of the sensitive data. The generated keys can be unique to the sensor control device 102, unique to a pair of devices, unique to a communication session between the sensor control device 102 and other devices, unique to a message sent during the communication session, or unique to a data block included within the message.

[0200] Both the sensor control device 102 and the data receiving device 120 can ensure the authorization of the other party in a communication session to, for example, issue commands or receive data. In a particular implementation, authentication can be performed by two features. First, the party declaring its identity provides a verified certificate signed by the manufacturer of the device or the operator of the analyte monitoring system 100. Second, authentication can be implemented by using public and private keys established by the devices of the analyte monitoring system 100 or established by the operator of the analyte monitoring system 100 and the shared secret derived therefrom. To confirm the identity of the other party, that party can provide evidence that it has control of its private key.

[0201] The manufacturer of the sensor control device 102, the data receiving device 120, or the provider of the application of the multi-purpose data receiving device 130 can provide, through secure programming and updates, the information and programming required for the devices to communicate securely. For example, the manufacturer can provide information that can be used to generate encryption keys for each device, including a security root key for the sensor control device 102 and optionally for the data receiving device 120, which can be combined with device-specific information and operational data (e.g., entropy-based random values) to generate encryption values unique to the device, session, or data transmission as needed.

[0202] Analyte data associated with a user is sensitive data, at least in part because the information can be used for multiple purposes, including health monitoring and pharmaceutical administration decisions. In addition to user data, the analyte monitoring system 100 can also strengthen security against reverse engineering efforts by external parties. The communication connection can be encrypted using a device-unique or session-unique encryption key. A transmission integrity check built into the communication can be utilized to verify encrypted or unencrypted communication between any two devices. The operation of the sensor control device 102 can be protected from tampering by restricting access to the read and write functions of the memory 5020 via the communication interface. The sensor can be configured to grant access only to known or "trusted" devices provided in a "whitelist", or only to devices that can provide a predetermined code associated with the manufacturer or otherwise authenticated user. The whitelist can represent an exclusive range, meaning that no connection identifiers other than those included in the whitelist will be used, or a preferred range in which the whitelist is searched first, but other devices can still be used. If the requester cannot complete the login process via the communication interface within a predetermined period (e.g., within four seconds), the sensor control device 102 can also reject and close the connection request. These features prevent specific denial-of-service attacks, and especially denial-of-service attacks on the BLE interface.

[0203] As implemented herein, the analyte monitoring system 100 can employ periodic key rotation to further reduce the likelihood of key leakage and exploitation. The key rotation strategy employed by the analyte monitoring system 100 can be designed to support backward compatibility for field-deployed or distributed devices. As an example, the analyte monitoring system 100 can employ a key for downstream devices (e.g., devices in the field or that cannot practically provide updates) that is designed to be compatible with multiple generations of keys used by upstream devices.

[0204] For purposes of illustration and not limitation, reference is made to those used in connection with Figure 17An exemplary embodiment of a message sequence diagram 600 for use with the disclosed subject matter shown in FIG. 6, and shows an exemplary data exchange between a pair of devices, particularly a sensor control device 102 and a data receiving device 120. As implemented herein, the data receiving device 120 may be the data receiving device 120 or the multi-purpose data receiving device 130. At step 605, the data receiving device 120 may transmit a sensor activation command 605 to the sensor control device 102, for example, via a short-range communication protocol. Prior to step 605, the sensor control device 102 may be in a primary sleep state, conserving its battery until full activation is required. After activation during step 610, the sensor control device 102 may collect data or perform other operations suitable for the sensing hardware 5060 of the sensor control device 102. At step 615, the data receiving device 120 may initiate an authentication request command 615. In response to the authentication request command 615, both the sensor control device 102 and the data receiving device 120 may participate in a mutual authentication process 620. The mutual authentication process 620 may involve the transfer of data, including challenge parameters that allow the sensor control device 102 and the data receiving device 120 to ensure that the other device is sufficiently capable of complying with the agreed-upon security framework described herein. Mutual authentication may be based on a mechanism for mutual authentication of two or more entities, with or without an online trusted third party, to establish a verified key via challenge response. Mutual authentication may be performed using two, three, four, or five authentications or similar versions thereof.

[0205] After a successful mutual authentication process 620, at step 625, the sensor control device 102 may provide a sensor key 625 to the data receiving device 120. The sensor key may include a sensor unique value and may be derived from a random value generated during manufacturing. The sensor key may be encrypted before or during transmission to prevent third party access to the secret. The sensor key 625 may be encrypted via one or more of the keys generated by or in response to the mutual authentication process 620. At step 630, the data receiving device 120 may derive a sensor unique encryption key from the sensor key. The sensor unique encryption key may also be session unique. Thus, the sensor unique encryption key may be determined by each device without transmission between the sensor control device 102 or the data receiving device 120. At step 635, the sensor control device 102 may encrypt the data to be included in the payload. At step 640, the sensor control device 102 may transmit the encrypted payload 640 to the data receiving device 120 using a communication link established between the appropriate communication models of the sensor control device 102 and the data receiving device 120. At step 645, the data receiving device 120 may decrypt the payload using the sensor unique encryption key derived during step 630. After step 645, the sensor control device 102 may transmit additional (including newly collected) data, and the data receiving device 120 may appropriately process the received data.

[0206] As discussed herein, the sensor control device 102 may be a device with limited processing power, battery supply, and storage. The encryption technology (e.g., choice of cryptographic algorithm or implementation of the algorithm) used by the sensor control device 102 may be selected at least in part based on these limitations. The data receiving device 120 may be a more powerful device with fewer such property limitations. Thus, the data receiving device 120 may employ more complex, computationally intensive encryption technologies such as cryptographic algorithms and implementations.

[0207] The sensor control device 102 can be configured to alter its discoverable behavior to attempt to increase the probability that a receiving device receives an appropriate data packet and / or provide an acknowledgment signal, or otherwise reduce limitations that may result in the non-receipt of an acknowledgment signal. Altering the discoverable behavior of the sensor control device 102 can include (by way of example but not limitation): changing the frequency at which connection data is included in data packets, changing the frequency at which data packets are generally transmitted, lengthening or shortening the broadcast window for data packets, changing the amount of time the sensor control device 102 listens for an acknowledgment or scan signal after broadcasting, including directed transmissions to one or more devices that have previously communicated with the sensor control device 102 and / or to one or more devices on a whitelist (e.g., via one or more attempted transmissions), changing the transmission power associated with the communication module when broadcasting data packets (e.g., to increase the range of the broadcast or reduce the energy consumed and extend the life of the analyte sensor's battery), changing the rate at which data packets are prepared and broadcast, or a combination of one or more other changes. Additionally or alternatively, the receiving device can similarly adjust parameters related to the listening behavior of the device to increase the likelihood of receiving a data packet that includes connection data.

[0208] As implemented herein, the sensor control device 102 can be configured to broadcast data packets using two types of windows. The first window refers to the rate at which the sensor control device 102 is configured to operate the communication hardware. The second window refers to the rate at which the sensor control device 102 is configured to actively transmit data packets (e.g., broadcast). By way of example, the first window can indicate that the sensor control device 102 operates the communication hardware to send and / or receive data packets (including connection data) during the first 2 seconds of each 60-second period. The second window can indicate that, during each 2-second window, the sensor control device 102 transmits one data packet every 60 milliseconds. During the remaining time of the 2-second window, the sensor control device 102 is scanning. The sensor control device 102 can lengthen or shorten either window to modify the discoverable behavior of the sensor control device 102.

[0209] In certain embodiments, the discoverable behavior of the analyte sensor can be stored in a discoverability profile and can be changed based on one or more factors, such as the state of the sensor control device 102 and / or by applying rules based on the state of the sensor control device 102. For example, when the battery level of the sensor control device 102 is below a certain amount, the rules can cause the sensor control device 102 to reduce the power consumed by the broadcast process. As another example, the configuration settings associated with broadcasting or otherwise transmitting packets can be adjusted based on the ambient temperature, the temperature of the sensor control device 102, or the temperature of certain components of the communication hardware of the sensor control device 102. In addition to modifying the transmission power, other parameters associated with the transmission capabilities or processes of the communication hardware of the sensor control device 102 can be modified, including but not limited to transmission rate, frequency, and timing. As another example, when the analyte data indicates that the subject is experiencing or about to experience a negative health event, the rules can cause the sensor control device 102 to increase its discoverability to alert the receiving device of the negative health event.

[0210] As implemented herein, certain calibration features of the sensing hardware 5060 of the sensor control device 102 can be adjusted based on external or ambient environmental characteristics, as well as to compensate for the decay of the sensing hardware 5060 during periods of non-use (e.g., "shelf time" prior to use). The calibration features of the sensing hardware 5060 can be adjusted autonomously by the sensor control device 102 (e.g., by operating the ASIC 5000 to modify the features in the memory 5020 or storage device 5030), or can be adjusted by other devices of the analyte monitoring system 100.

[0211] As an example, the sensor sensitivity of the sensing hardware 5060 can be adjusted based on external temperature data or the time since manufacture. When monitoring the external temperature during storage of the sensor, the disclosed subject matter can adaptively change the compensation for sensor sensitivity over time when the device experiences changing storage conditions. For purposes of illustration and not limitation, the adaptive sensitivity adjustment can be performed in an “active” storage mode, where the sensor control device 102 periodically wakes up to measure the temperature. These features can conserve the battery of the analyte device and extend the life of the analyte sensor. At each temperature measurement, the sensor control device 102 can calculate the sensitivity adjustment for that time period based on the measured temperature. Then, the temperature weighted adjustments can be accumulated over the active storage mode period to calculate the total sensor sensitivity adjustment value at the end of the active storage mode (e.g., upon insertion). Similarly, upon insertion, the sensor control device 102 can determine the time difference between the manufacture of the sensor control device 102 (which can be written to the storage device 5030 of the ASIC 5000) and the sensing hardware 5060, and modify the sensor sensitivity or other calibration characteristics according to one or more known decay rates or formulas.

[0212] Additionally, for purposes of illustration and not limitation, as implemented herein, the sensor sensitivity adjustment can take into account other sensor conditions, such as sensor drift. During manufacture, for example in the case of sensor drift, the sensor sensitivity adjustment can be hard coded into the sensor control device 102 based on an estimate of how much the average sensor can drift. The sensor control device 102 can use a calibration function that has time-varying functions for sensor offset and gain, which can account for drift during the wear period of the sensor. Thus, the sensor control device 102 can utilize a function for converting interstitial current to interstitial glucose that utilizes a device-related function that describes the drift of the sensor control device 102 over time, and that function can represent the sensor sensitivity and can be device-specific, combined with a baseline of the glucose profile. Such a function that takes into account sensor sensitivity and drift can improve the accuracy of the sensor control device 102 during the wear period without involving user calibration.

[0213] The sensor control device 102 detects raw measurements from the sensing hardware 5060. On-sensor processing may be performed, such as by one or more models trained to interpret the raw measurements. The models may be machine learning models trained outside of the device to detect, predict, or interpret the raw measurements to detect, predict, or interpret the levels of one or more analytes. Additional training models may operate on the output of machine learning models trained to interact with the raw measurements. As an example, the models may be used to detect, predict, or recommend events based on the raw measurements detected by the sensing hardware 5060 and the type of analyte. Events may include the start or completion of physical activity, meals, administration of medical treatments or medications, emergency health events, and other events of a similar nature.

[0214] During manufacturing or during firmware or software updates, models may be provided to the sensor control device 102, the data receiving device 120, or the multi-purpose data receiving device 130. Based on data received jointly from the sensor control device 102 and the data receiving devices of a single user or multiple users, the models may be periodically refined, such as by the manufacturer of the sensor control device 102 or the operator of the analyte monitoring system 100. In some embodiments, the sensor control device 102 includes sufficient computing components to assist in further training or refining the machine learning models, such as based on unique characteristics of the user to whom the sensor control device 102 is attached. By way of example and not limitation, the machine learning models may include models trained using or including decision tree analysis, gradient boosting, ada boosting, artificial neural networks or variants thereof, linear discriminant analysis, nearest neighbor analysis, support vector machines, supervised or unsupervised classification, and the like. In addition to machine learning models, the models may also include models based on algorithms or rules. When receiving data from the sensor control device 102 (or other downstream devices), model-based processing may be performed by other devices including the data receiving device 120 or the multi-purpose data receiving device 130.

[0215] Data transmitted between the sensor control device 102 and the data receiving device 120 may include raw or processed measurements. Data transmitted between the sensor control device 102 and the data receiving device 120 may also include alerts or notifications for display to a user. The data receiving device 120 may display or otherwise communicate a notification based on the raw or processed measurements, or may display an alert when received from the sensor control device 102. Alerts that may be triggered for display to a user include alerts based on direct analyte values (e.g., a one-time reading that exceeds or fails to meet a threshold), analyte value trends (e.g., an average reading over a set period of time that exceeds or fails to meet a threshold; slope); analyte value predictions (e.g., an algorithmic calculation based on analyte values that exceeds or fails to meet a threshold), sensor alerts (e.g., a suspected fault is detected), communication alerts (e.g., no communication between the sensor control device 102 and the data receiving device 120 within a threshold time period; an unknown device attempts or fails to initiate a communication session with the sensor control device 102), reminders (e.g., a reminder to charge the data receiving device 120; a reminder to take a medication or perform other activity) and other alerts of a similar nature. For purposes of illustration and not limitation, as implemented herein, the alert parameters described herein may be user-configurable, or may be fixed during manufacturing, or a combination of user-settable and non-user-settable parameters.

[0216] As described herein, a software library integrated within software executing on a receiving device may facilitate communication with an analyte sensor and allow third party applications access to sensor data for medically necessary applications or applications related to a user's health. The software library may be implemented independent of the sensor and integrated within third party applications to allow access to sensor data. The sensor control module may also communicate with sensor components in such a way as to receive data from multiple such sensor components simultaneously or substantially simultaneously. The system also enables transfer of sensor information from the sensor control module to a remote management module.

[0217] Figure 18 A data flow between various components of an exemplary environment 1800 and an exemplary analyte monitoring system 100 in accordance with the techniques described herein is shown.

[0218] The environment 1800 includes a remote application server 155 associated with the analyte monitoring system 100, the multi-purpose device 130, and the data monitoring device 135. The multi-purpose device 130 is executing a monitoring application 1810a associated with the analyte monitoring system 100. The data monitoring device 135 is executing a monitoring application 1810b. In some embodiments, the data monitoring application 1810a and the data monitoring application 1810b may be the same application provided by the analyte monitoring system 100. In some embodiments, the data monitoring application 1810a and the data monitoring application 1810b may be applications customized to execute specifically on their respective devices or operating systems.

[0219] As described herein, the multi-purpose device 130 may be a personal device of a user wearing the sensor control device 102. The sensor control device 102 may provide data to the multi-purpose device 130 directly or indirectly (e.g., via the data receiving device 120). The multi-purpose device 130 may include, for example, the user's smartphone or smartwatch that executes one or more applications or software libraries provided by the analyte monitoring system 100. The multi-purpose device 130 provides functions specifically associated with the analyte monitoring system 100 and other functions for the user. In some embodiments, the multi-purpose device 130 may include additional sensing or other hardware to implement functions associated with the analyte monitored by the sensor control device 102. As an example, the multi-purpose device may include an insulin pump or a connected insulin pen, and the analyte being monitored may be glucose or other analyte related to managing diabetes or other related conditions.

[0220] The data monitoring device 135 may be a personal device of a user not wearing the sensor control device 102. Specifically, the data monitoring device 135 may refer to a device that receives information about the analyte level of the monitored user via the remote application server 155. Specifically, the remote application server 155 may be configured to transmit the analyte level, alerts based on the analyte level, and other information to the monitoring application 1810b for viewing by the user of the data monitoring device 135. Additionally, the data monitoring device 135 may be similar to the multi-purpose device 130 in that, in addition to receiving the monitored analyte level, the data monitoring device 135 may also implement other functions for the user of the data monitoring device 135.

[0221] The environment 1800 further includes a notification service 1820. The notification service 1820 may be a service operated by a third party to facilitate the timely and effective delivery of messages to the multi-purpose device 130 and the data monitoring device 135 (or, in some embodiments, any device executing an instance of the data monitoring application 1810).

[0222] According to certain embodiments, the analyte monitoring system 100 can provide features that facilitate sharing certain information between a user wearing the sensor control device 102 and one or more monitoring users. The user of the sensor control device 102 or another authorized user can identify the specific users or data monitoring devices 135 that will receive the information and select what information to share. Then, when the multi-purpose device 130 or the user device 140 provides data from the user's sensor control device 102 to the remote application server 155, the remote application server can cause some or all of the information to be transmitted to the identified data monitoring devices 135. In one example, a user can enable their parents to receive the current value of a specific analyte level measured by the sensor control device 102. Additionally, a user can enable their parents to receive certain alerts based on the level of a specific analyte, such as an alert triggered when the level of the analyte exceeds one or more preselected thresholds. In certain embodiments, a user can customize the alerts to be sent to the data monitoring device 135 if a problem is allowed to persist for a threshold period of time. As described herein, many other types of alerts can also be transmitted to the data monitoring device 135. If the users of the data monitoring device 135 have enabled some or all of the alerts to be displayed as alerts or notifications on their data monitoring device 135, the remote application server 155 can cause a notification to be transmitted to the data monitoring device 135 when the alert condition is met. The notification can be transmitted via the notification service 1820.

[0223] In certain embodiments, the notification service 1820 can be operated or assisted by the provider of the multi-purpose device 130 or the data monitoring device 135 or by the operating systems and other software environments executing on the multi-purpose device 130 and the data monitoring device 135. The notification service can be a more efficient system for providing certain push notifications to the data monitoring device. In certain embodiments, the provider of the data monitoring device 135 can only allow push notifications to be transmitted to the data monitoring device 135 via the notification service 1820 or an equivalent. Certain embodiments discussed herein enable the remote application server 155 to utilize the notification service 1820 as intended.

[0224] In certain embodiments, the notification service 1820 can alternatively or additionally be provided by or as part of the analyte monitoring system 100. Additionally, for the sake of brevity, the notification service 1820 is shown as a single entity. It should be understood that the notification service 1820 can include multiple competing or cooperating notification services 1820 (e.g., for different device platforms or operating systems). Additionally, the notification service can include multiple servers that work together and can be geographically distinct.

[0225] In certain embodiments, the notification service 1820 can be configured to receive requests from the remote application server 155 to send notifications to one or more devices executing an instance of the monitoring application 1810. The requests can vary based on the number of messages to be sent, whether the messages are repeated or recurring, and the number and selection of devices to receive one or more specific messages. As an example, a request from the remote application server 155 can include a request to send a single notification to a single device. As another example, the request can include a request to send a single notification to multiple devices simultaneously. As another example, the request can include a request to send multiple notifications to a single device at one time. As another example, the request can include a request to send one or more notifications to a single device on a recurring basis (e.g., every hour, every five hours, every twelve hours, every twenty-four hours, once a week, etc.). Other combinations of these factors can also be included in the request.

[0226] Additionally or alternatively, the requests can be customized based on which devices are selected to receive the notifications. As an example, the remote application server 155 can determine that a particular data monitoring device 135 is to receive a notification as soon as possible. Such a notification can be an alert based on the condition of a user wearing a particular sensor control device 102 or based on the status of the sensor control device 102 itself. As another example, the remote application server 155 can determine that all data monitoring devices 135 manufactured by a particular manufacturer, executing a particular operating system, or executing a particular version of the monitoring application 1810 are to receive a notification. Such a notification can be a recommendation to update the instances of the monitoring application 135 executing on the data monitoring devices 135. As another example, the remote application server 155 can determine that all data monitoring devices 135 communicating with the analyte monitoring system 100 should receive notifications on a regular basis. As described herein, such notifications can include system-wide announcements or so-called "heartbeat" notifications to confirm an available active communication channel between the remote application server 155 and the data monitoring devices 135.

[0227] Figure 19 An exemplary method 1900 for providing notifications of an unavailable communication channel or alternatively an unresponsive communication channel between devices of an analyte monitoring system is shown. The method 1900 can be performed by Figure 18 devices within the operating environment 1800 shown, where the analyte monitoring system 100 uses the notification service 1820 to facilitate distribution of notifications to multiple data monitoring devices 135 or multi-purpose devices 130 executing multiple instances of the monitoring application 1810a or 1810b. For purposes of readability, Figure 19 only a single instance of the monitoring application 1810 is shown. However, it should be understood that these techniques apply to environments where multiple instances are executed by multiple devices.

[0228] At 1901, the remote application server 155 arranges for a silent notification for a connection alert. As described herein, a connection alert is provided when the communication channel between the remote application server 155 and its monitoring application 1810 is unresponsive, such that the end user can be explicitly notified via their monitoring application 1810. The communication channel may be unresponsive for various reasons, including those originating from or caused by the device executing the monitoring application 1810 or the remote application server 155. As described, the analyte monitoring system 100 uses a notification server 1820 to facilitate efficient notification delivery to instances of the monitoring application 1810. In some cases, the notifications are associated with individual or personal data, and thus the notifications generated by the remote application server 155 for distribution via the notification server 1820 can have a limited audience (e.g., one recipient). In some cases, the notifications are general or system-wide. Using the notification server 1820, the remote application server 155 can arrange for two types of notifications by sending a single configuration message to the notification service.

[0229] At 1911, the notification service 1820 (e.g., its server) receives a request that includes a command to arrange for a silent notification for a connection alert. The notification service 1820 configures the notification for distribution to the appropriate application instance. The request from the remote application server 155 can identify the appropriate application instance or can indicate the population that is to receive the notification. In the example of a connection alert notification, the intended audience can include (by way of example) all users or all users who remotely monitor the analyte levels of another user. The intended audience can be further restricted based on technical limitations or constraints. As an example, the remote application server 155 can first arrange for an alert for users of a first mobile device operating system before arranging for an alert for users of a second mobile device operating system. Configuring the notification can also include: selecting how the recipient device will handle the notification. In the case of a silent notification for a connection alert, the notification service 1820 can determine that the recipient device (or instance of the monitoring application 1810) will not take any user-facing action (e.g., will not issue a visual, audible, or tactile alert), but will take certain steps consistent with those discussed herein.

[0230] At 1913, the notification service 1913 pushes the configured notification to the appropriate application instance. As an example, the notification can be pushed to all devices that are instances of a particular version of the monitoring application 1810 being executed.

[0231] At 1921, after receiving a notification from the notification server 1820, the monitoring application determines the type of the notification. In the example shown, the type of the notification indicates that it is a silent notification from the remote application server 155 for tracking the status of the communication channel between the remote application server 155 and an instance of the monitoring application 1810. In some embodiments, such a notification may also be referred to as a heartbeat notification.

[0232] After determining that the notification is a heartbeat notification, the monitoring application 1810 cancels any previously scheduled user-facing connection alerts. As described herein, the monitoring application 1810 has been configured to operate a timer that effectively calculates the time since the monitoring application 1810 last received communication from the remote application server 155. When the application receives new communication from the remote application server 155, the timer is restarted. To restart the timer, the monitoring application 1810 may delete any pending user-facing alerts.

[0233] At 1922, the monitoring application starts a new timer by scheduling a new user-facing connection alert. The connection alert may be associated with the new timer and may be determined based on, for example, hard-coded values, values provided by the remote application server 155 (e.g., in a request to schedule new communication), values provided by the notification service 1820 (e.g., based on rate limits imposed by the notification service 1820), or values provided by a user of the monitoring application 1810, the amount of time associated with the timer. The new connection alert may be scheduled such that the monitoring application 1810 displays a user-facing notification. The connection alert may warn the user that the monitoring application 1810 has been unable to communicate with the remote application server 155 for an extended period of time (or a user-defined period, as the case may be), or that the communication channel between the remote application server 155 and the monitoring application 1810 has otherwise become unresponsive.

[0234] Method 1900 may be repeated periodically, where the remote application server 155 periodically schedules the provision of silent notifications of connection alerts to an instance of the monitoring application 1810 such that the monitoring application 1810 can determine whether the communication channel between the remote application server 155 and the monitoring application 1810 remains active and available. As an example, the time associated with the connection alert may be set to 30 minutes. The remote application server 155 may send a silent "heartbeat" notification that coincides with the timer (e.g., also every 30 minutes). In a particular embodiment, the remote application server 155 may use a shorter time period than the timer (e.g., 5 minutes shorter than the timer; half of the timer period) to avoid or pre-empt intermittent interruptions.

[0235] Figure 20AAn exemplary method for determining the availability of communication channels between devices of an analyte monitoring system and providing notification of a connection loss or alternatively an unresponsive communication channel according to certain embodiments is shown. Method 2000a may be performed by a device within the operating environment 1800 shown in Figure 18 wherein the analyte monitoring system 100 uses a notification service 1820 to facilitate distributing notifications to a plurality of data monitoring devices 135 or multi-purpose devices 130 executing multiple instances of a monitoring application 1810a or 1810b. For purposes of readability, Figure 20A only a single instance of the monitoring application 1810 is shown. However, it should be understood that these techniques apply to an environment where multiple instances are executed by multiple devices.

[0236] At 2001, the remote application server 155 receives sensor data originating from the sensor control device 102. In certain embodiments, the sensor data may be transmitted directly from the sensor control device 102 or may be transmitted through the multi-purpose device 130 or the user device 140. As described, the remote application server 155 may perform post-processing of the data and provide an alert to be transmitted to certain users (including those other than the user wearing the sensor control device 102) when certain conditions are met.

[0237] At 2002, the remote application server 155 processes the data and detects that an alert condition is met based on the data. As an example, the sensor data may be associated with a value of an analyte level detected in the body fluid of the user wearing the sensor control device 102. The alert condition may specify a threshold level of the analyte associated with a dangerous high or low level, a rate of change of the analyte level, an expected or predicted high or low level or rate of change, a level associated with a specific time, and other similar conditions. The remote application server 155 may be configured to provide alert condition information to one or more users executing the monitoring application 1810 on the multi-purpose device 130 or other data monitoring devices 135, for example, based on user permissions and instructions received from the user wearing the sensor control device 102. To this end, the remote application server 155 may request that an alert notification be pushed to the monitoring application 1810 via the notification service 1820.

[0238] At 2011, the notification service 1820 receives a request to push an alert notification from the remote application server 155. The request from the remote application server 155 may identify one or more instances of the monitoring application 1810 to receive the alert notification, specify the text of the alert notification, and provide other details to enable the notification service to customize and present the alert notification.

[0239] At 2012, for example, the notification service pushes an alert notification to an appropriate instance of the monitoring application in accordance with a request from the remote application server.

[0240] At 2021, the monitoring application 1810 receives the alert notification and outputs a user-facing component of the alert notification. For example, the monitoring application 1810 may provide a one-time or repeating visual, audible, or tactile output to a user of the monitoring application after querying user settings related to the type and severity of the alert.

[0241] Meanwhile, the monitoring application 1810 may interpret the notification from the remote application server 155 as evidence that the communication channel between the remote application server 155 and the monitoring application 1810 is active. At 2022, the monitoring application cancels any previously arranged user-facing connection alert. Thus, the operation at 2022 may be similar to the operation at 1921 in method 1900. When the application receives any new communication from the remote application server 155, including an alert notification from the remote application server 155, the timer is restarted.

[0242] At 2023, the monitoring application starts a new timer by arranging a new user-facing connection alert, similar to the operation performed at 1922 in method 1900.

[0243] Figure 20B Another exemplary method for providing notification of an unavailable communication channel or alternatively a non-responsive communication channel between devices in an analyte monitoring system is shown. Method 2000a may be performed by Figure 18 devices within the operating environment 1800 shown, where the analyte monitoring system 100 uses a notification service 1820 to facilitate distribution of notifications to a plurality of data monitoring devices 135 or multi-purpose devices 130 that execute multiple instances of the monitoring application 1810a or 1810b. For purposes of readability, Figure 20B only a single instance of the monitoring application 1810 is shown. However, it should be understood that these techniques apply to environments where multiple instances are executed by multiple devices.

[0244] As discussed herein, when the monitoring application 1810 receives any communication originating from the remote application server 155, a timer used by the monitoring application 1810 can be reset or replaced. As an example, in some embodiments, the remote application server 155 can send additional data (e.g., non-alert data) to an instance of the monitoring application 1810. Exemplary data can include data having normal analyte levels or other sensitive patient information. Since the data is received directly from or on behalf of the remote application server 155, the monitoring application 1810 can interpret the transmission of the data as evidence that the communication channel is active and available.

[0245] At 2024, the monitoring application 1810 can request data from the remote application server 155. As an example, the monitoring application 1810 can detect that a timer related to data freshness has expired and stop waiting for data to be pushed from the remote application server 155 to the monitoring application. Instead, the monitoring application can proactively request the missing data. As another example, a user of the monitoring application 1810 can manually request a data refresh.

[0246] At 2003, the remote application server 155 can receive and process a request from the monitoring application 1810. By way of example only and not limitation, processing the request can include determining whether there is additional data available for the monitoring application 1810 based on the request.

[0247] In some examples, the notification service 1820 receives a request for the remote application server 155 from the monitoring application 1810 and sends the request for data to the remote application server 155 on behalf of the monitoring application 1810. In such an embodiment, the notification service 1820 acts as a middleman on behalf of the remote application server 155. This provides greater flexibility in the configuration of the remote application server 155, which can notify the notification service 1820 of changes as to where such requests should be forwarded without having to inform the monitoring application 1810.

[0248] At 2004, the remote application server 155 can send the requested data to an application instance of the monitoring application 1810. In some examples, the data is sent to the monitoring application 1810 via the notification service 1820. As an example, sending the requested data to the monitoring application 1810 can include: sending the data to the notification service 1820 addressed to the monitoring application 1810. At 2013, the notification service 1820 receives data for the monitoring application 1810 from the remote application server 155. Then, the notification service 1820 forwards the data to the monitoring application 1810 on behalf of the remote application server 155. In some examples not shown, the data can be sent directly to the monitoring application 1810, skipping the notification service 1820 and reducing the potential latency between the remote application server 155 sending the data and the monitoring application 1810 receiving the data.

[0249] At 2025, the monitoring application 1810 receives the requested data from the remote application server 155. As described herein, the receipt of this data can also serve as proof to the monitoring application 1810 that the connection between the remote application server 155 and the monitoring application 1810 is active and available. Thus, at 2026, as at 2022, the monitoring application 1810 can cancel a pending connection alert. Additionally, at 2027, as at 2023, the monitoring application 1810 can schedule a new connection alert.

[0250] The monitoring application can cancel a prior user-facing connection alert at 2022 and schedule a new connection alert 2023 consistent with the techniques described herein. In some examples, the data can be pushed by the remote application server 155. In some examples, the data can be requested by the monitoring application.

[0251] Figure 21 An exemplary method for providing notification of an unavailable communication channel or an unresponsive communication channel between devices of an analyte monitoring system according to certain embodiments is shown. Method 2100 can be performed by any device in the analyte monitoring system 100 that directly displays data and notifications to a user of the analyte monitoring system. In certain embodiments, method 2100 is performed by the data monitoring device 135 that receives data from a remote application server 155 of the analyte monitoring system (as opposed to a device that receives data directly from the sensor control device 102). In a particular embodiment, method 2100 is performed by an instance of the monitoring application 1810 provided by the analyte monitoring system 100.

[0252] At 2110, the application checks the status of the local "heartbeat" timer. The heartbeat timer is so named because it serves as a mechanism for checking the lifespan of, for example, the communication channel between the application and the remote application server 155. In the exemplary method 2100, the heartbeat timer is locally maintained by an instance of the monitoring application 1810. According to the embodiments disclosed herein, the heartbeat timer can be started.

[0253] At 2115, the application determines whether the local heartbeat timer has expired. As an example, the heartbeat timer can be a decrement timer, and determining whether the timer has expired can include: checking whether the value is less than or equal to 0. The decrement timer can be started with a preset value. As an example, the heartbeat timer can be an increment timer, and determining whether the timer has expired can include: checking whether the value is greater than or equal to the preset value. As another example, the heartbeat timer can be determined by comparing the recorded start time (e.g., the start time saved by the application when the heartbeat timer is started) with the current time and determining whether the difference between the start time and the current time exceeds the preset value. In all instances, the preset value is associated with the length of the heartbeat timer. The length of the heartbeat timer can be determined based on, for example: a hard-coded value, a value provided by the remote application server 155 (e.g., in a request to schedule a new communication), a value provided by the notification service 1820 (e.g., based on a rate limit imposed by the notification service 1820), or a value provided by the user of the monitoring application 1810.

[0254] If the heartbeat timer has not expired, then at 2120, the application advances the local heartbeat timer. For example, the current value of an increment timer can be increased, or the current value of a decrement timer can be decreased. If the monitoring application 1810 was in a sleep or low-power state prior to the operation at 2110, the monitoring application 1810 can return to the sleep or low-power state until the application performs the operation at 2110 again next time.

[0255] If the heartbeat timer has expired, at 2115, the communication channel between the monitoring application 1810 and the remote application server 155 is suspected of being unresponsive or otherwise unavailable. The monitoring application 1810 can optionally take one or more affirmative steps to establish or test the communication channel with the remote application server. As an example, the monitoring application can attempt at 2125 to establish an auxiliary connection between the monitoring application 1810 and the remote application server 155. For instance, the monitoring application 1810 can attempt to affirmatively establish the connection (e.g., rather than waiting for a notification or data transfer from the remote application server 155). Additionally or alternatively, the monitoring application 1810 can attempt to establish a communication channel with another remote application server 155 associated with the analyte monitoring system 100. For example, the application monitoring system 100 can include various remote application servers 155 that are geographically distributed to improve latency and responsiveness. The monitoring application 1810 can attempt to connect to one or more designated alternate remote application servers 155. In some embodiments, the analyte monitoring system 100 can automatically designate the alternate remote application server 155, e.g., in a cloud server architecture.

[0256] If the monitoring application 1810 is able to establish an auxiliary server connection, at 2130, the monitoring application 1810 can report the server connection problem to the remote application server 155. The monitoring application 1810 can also reset the local heartbeat timer.

[0257] If the monitoring application 1810 fails to establish an auxiliary server connection, at 2140, the monitoring application 1810 outputs a server connection alert. As an example, the monitoring application 1810 can output a notification to the user of the monitoring application 1810 indicating that there may be a problem with the communication channel between the remote application server 155 and the monitoring application 1810, or that the communication channel has become unresponsive. The notification can indicate one or more possible causes of the problem and, depending on the possible cause, suggest possible solutions to re - establish or repair the communication channel. The notification can be provided on the data monitoring device 135 as a visual, audible, or tactile alert. When the communication channel is unresponsive (e.g., until an alternative communication channel is established or the existing communication channel is corrected), the notification can be provided within the monitoring application 1810 as a banner or other style of notification. The notification can further inform the user of the potential consequences of the unresponsive communication channel (e.g., temporarily unavailable), including but not limited to: data on the analyte level of the monitored user will not be transmitted, alerts related to the analyte level will not be transmitted, and recommendations based on the analyte level will not be transmitted. The notification can also suggest that the user contact the monitored user if possible. For example, the notification can indicate the last known value of the analyte level or the last known state of the monitored user and indicate that if the last known value or last known state is concerning, they should contact the user using traditional communication mechanisms.

[0258] Figure 22 An exemplary method for providing notification of an unavailable communication channel (e.g., an unresponsive communication channel) between devices of an analyte monitoring system in accordance with certain embodiments is shown. While Figure 21 an example of an initial response of the monitoring application 1810 to the expiration of a local heartbeat timer is provided, Figure 22 the method 2200 in

[0259] At 2205, the monitoring application 1810 receives data corresponding to the status of the monitored user from the remote application server 155. As an illustrative example, the monitoring application 1810 receives the current (e.g., latest) value and historical values of the analyte level being monitored by the monitored user. The historical values can be used, for example, to fill in missing data and / or provide more complex analysis and tracking than just recording the "current" value. Additionally or alternatively, the "current" value can be associated with a different retrieval rate or sampling rate than the historical data and thus cannot be directly compared. Although described for illustrative purposes as values of analyte levels, the current data and historical data can include other information provided by or associated with the monitored user. As an example, in addition to the values of analyte levels, the data can include detected or predicted alert conditions, events associated with the health of the monitored user that may be associated with the analyte level (e.g., administration of a drug or food intake).

[0260] In certain embodiments, the monitoring application 1810 is configured to store historical values of the analyte level for a predetermined period of time. As will be described, in certain cases, these stored historical values can be used to supplement missing data. Thus, at 2210, the monitoring application 1810 can optionally prepare the historical values for storage. Preparing the historical values can include: using the data or performing one or more operations on the data to facilitate secure storage on the data monitoring device 135. As an example, the monitoring application 1810 can encrypt the historical values, de-identify the historical values, tag the historical values, associate certain events with the historical values, apply additional timestamps to the historical values, or perform other operations to improve the quality and security of the analyte level data.

[0261] At 2215, the monitoring application 1810 can store the historical values in the memory of the data monitoring device 135. In a particular embodiment, the historical values are stored for a predetermined period of time or until the historical values are associated with a particular period. For example, the historical values can be automatically erased after 30 days, 14 days, 7 days, etc. As another example, the historical values can be automatically erased after they have been stored for a particular period of time.

[0262] At 2220, the monitoring application 1810 displays the current value and / or historical values in the user interface of the monitoring application 1810.

[0263] At 2225, the monitoring application 1810 detects that the communication channel between the remote application server 155 and the monitoring application 1810 is unresponsive or otherwise unavailable. The monitoring application 1810 can perform this detection using techniques consistent with those discussed herein. In some embodiments, when the connection is first determined to be unresponsive, the monitoring application may record the current geographical location of the data monitoring device 135. In some embodiments, when the connection is restored, this geographical location information can be provided to the remote application server 155. The remote application service 155 can use general or precise geographical location data to suggest data loss mitigation techniques to the user, such as determining that the user is approaching an area known to cause data loss.

[0264] At 2230, the monitoring application 1810 determines one or more possible causes for the communication channel becoming unresponsive. Depending on the type of problem, the monitoring application 1810 prepares one or more notifications to be displayed as connection alerts, thereby informing the user of the monitoring application 1810 that the communication channel is unresponsive and providing suggestions on how to correct the possible causes.

[0265] At 2235, the monitoring application 1810 has determined that the possible causes include one or more device or application problems. As an example, the monitoring application 1810 may determine that an error has occurred within the monitoring application that may prevent the communication channel from responding. As another example, the monitoring application 1810 may determine that the monitoring application 1810 does not have the appropriate permissions to use certain functions of the data monitoring device 135 that are necessary for the operation of the monitoring application 1810. As another example, the monitoring application 1810 may determine that the data monitoring device 135 does not have an active Internet connection or has airplane mode enabled.

[0266] At 2240, the monitoring application 1810 prepares a notification to be displayed as or with a connection alert that includes steps that may resolve one or more device or application problems. In this case, the user may be able to resolve these problems because the applications and devices are under their control. Thus, the notification can include a preliminary identification of the possible problems and simple steps to resolve them.

[0267] At 2265, the monitoring application 1810 modifies some form of its output in response to detecting that the communication channel between the monitoring application 1810 and the remote application server 155 is unresponsive. As an example, modifying the output of the monitoring application 1810 can include: restricting the output of certain information, such as values associated with current sensor data or historical sensor data, to indicate that the active communication channel is unavailable. As another example, modifying the output of the monitoring application 1810 can include: restricting or preventing certain functions of the monitoring application 1810. These functions can include the ability to view historical data associated with certain time periods or the ability to change settings related to the analyte monitoring system 100. As another example, modifying the output of the monitoring application 1810 can include: determining and displaying the last known state of the sensor data or the corresponding sensor control device 102. The last known state can indicate that the current state (or sensor data) is unavailable, but includes a timestamp to indicate the period of the last known state, such that the user can respond accordingly. As an example, the last known state can be determined based on comparing the value of the most recent sensor data with one or more thresholds, each threshold associated with a corresponding last known state.

[0268] At 2270, the monitoring application outputs a readiness notification. As an example, the notification can be a visual notification that is temporarily or persistently displayed in the monitoring application 2270 (e.g., until the communication channel is re-established or is found to be responsive again). As another example, the notification can be a visual notification that is displayed on one or more screens of the data monitoring device 135 (e.g., lock screen, home screen, message screen, etc.). As another example, the notification can include one or more non-visual components, including but not limited to auditory or tactile components, to further warn the user that the communication channel is unresponsive and that data and alerts will be delayed while the problem persists. The notification can include additional information prepared in step 2240, 2255, or 2260, depending on the type and nature of the possible cause of the communication channel between the remote application server 155 and the monitoring application 1810.

[0269] Returning to 2230, the monitoring application 1810 can determine that possible causes include server issues. At 2245, the monitoring application 1810 has determined that possible causes include server issues. Severe issues can include expected or unexpected interruptions within the remote application server 155 (or other servers of the analyte monitoring system 100). As an example, the remote application server 155 can notify the user in advance of scheduled maintenance. The monitoring application 1810 can determine whether the conditions and context of the unresponsive communication channel correspond to a scheduled server outage. Additionally, the monitoring application 1810 can determine that there are no known conditions associated with the data monitoring device 135 or the monitoring application 1810 and infer that this may be a server problem.

[0270] At 2250, the monitoring application 1810 determines whether an alternate communication channel between the monitoring application 1810 and the remote application server 155 is available. As an example, the alternate communication channel can include using a different communication protocol to receive sensor data. The alternate communication channel can include, for example, an SMS message provided to the user of the data monitoring device 135 at the request and with the permission of the user wearing the sensor control device 102. As another example, the alternate communication channel can include communication with a different remote application server 155 within the analyte monitoring system 100. For example, the analyte monitoring system 100 can provide multiple geographically distinct remote application servers 155. Although the nearby remote application server 155 can be preferentially used, the monitoring application 135 can attempt to communicate with a more distant remote application server 155 or a remote application server 155 in another country, provided that only one remote application server 155 or a cluster of remote application servers 155 is unavailable.

[0271] If the alternate channel is available, then at 2255, the monitoring application prepares a notification to be displayed as a connection alert or along with a connection alert, the notification including a notice that a potential problem with the connection between the monitoring application 1810 and the remote application 155 has been detected. However, due to the availability of an alternate communication channel, the notification can further indicate that data from the remote application server 155, such as current values or alerts, may be delayed but can still be transmitted.

[0272] If there is no available alternate channel, at 2260, the monitoring application prepares a notification to be displayed as a connection alert or in conjunction with a connection alert, which includes a notification that a potential problem with the connection between the monitoring application 1810 and the remote application 155 has been detected. Since there is no available alternate communication channel, the notification indicates that data from the remote application 155 will not be available until the problem is resolved. The notification prepared at 2255 and 2260 may further include steps to contact the provider of the remote application server 155 to determine if there are other possible steps to resolve the detected problem.

[0273] Figures 23 to 25 An exemplary user interface of an application associated with an analyte monitoring system and executed on a data monitoring device 135 is shown.

[0274] Figure 23 A first user interface 2300 is shown, which shows a notification 2305 that can be displayed on the data monitoring device 135 when a communication channel between the data monitoring device 135 and the remote application server 155 is unresponsive. Specifically, the notification 2305 indicates that the data monitoring device 135 has lost its connection to the remote application server 155 and has not received data for a certain period of time. The notification 2305 indicates that the data monitoring device 135 is not receiving sensor data until the problem is resolved.

[0275] Figure 23 A second user interface 2310 is also shown, which shows a notification 2315 that can be displayed when the connection between the data monitoring device 135 and the remote application server 155 is restored or otherwise determined to be responsive again. In some embodiments, when the connection is restored, the remote application server 155 may cause the current value and missing historical data (e.g., data corresponding to the period when the connection was unresponsive) to be sent to the monitoring application 1810 for viewing and storage.

[0276] As described herein, both the notification 2305 and the notification 2315 can be displayed on the lock screen of the data monitoring device 135, on the home screen of the data monitoring device 135 (e.g., when the data monitoring device 135 is active but not executing a specific application in the foreground), as a banner notification when different applications are executing in the foreground, or as a notification in the monitoring application 1810 when the monitoring application is executing in the foreground. Additionally, the notifications 2305 and 2315 can be displayed using different form factors inherent to the specific operating system or environment of the data monitoring device 135. In some embodiments, when the communication channel remains unresponsive, the notification 2305 can be continuously displayed in the user interface of the data monitoring device 135 (e.g., displayed in the monitoring application 1810 or as a notification on another application).

[0277] Figure 24 Shows a first user interface 2400 that, when the communication channel between the data monitoring device 135 and the remote application server 155 is unresponsive, shows an exemplary main screen of the monitoring application 1810. The main screen includes a plurality of indicators that indicate that the most recent data is unavailable and otherwise indicate that the communication channel is unresponsive. As an example, instead of showing no values and indicating that there is no latest data available, the first panel 2403 of the main screen typically displays the most recently received analyte levels received from the remote application server 155. In some embodiments, the first panel 2403 may display the most recent values associated with a timestamp or other indicator of a period of values, rather than showing no values. In this way, in cases where the information prompts the user to take additional action, the user of the data monitoring device 135 can be alerted to the last known state of the user of the sensor control device 102 that wears the measurement values. The last known state information may also include the last known trend information of the analyte value (e.g., rising, falling, rapidly falling) or predict the current value based on the last known trend information and other activity information. As another example, the second panel 2405 typically shows a graph of the historical values of the analyte level over time, rather than just showing a set of empty axes to indicate that the historical values are also unavailable.

[0278] Another user interface element includes a button 2407 that the user can select to access the log of the monitoring application 1810. In some embodiments, even when the communication channel between the remote application server 155 and the data monitoring device 135 is unavailable, the user of the monitoring application 1810 can access certain historical values. In this example, these historical values can be accessed through different screens to reduce the chance that the user of the data monitoring device 135 is confused about the status of the historical data. As described herein, the historical data can be encrypted, de-identified, quantified, or otherwise prepared for more secure long-term storage on the data monitoring device 135.

[0279] Figure 24A second user interface 2410 is also shown that informs the user of one or more possible sources of error that may cause the communication channel to become unresponsive. As an example, the notification may suggest a series of potential causes, ranging from a system-wide service interruption, a loss of the Internet connection between the devices relaying data from the sensor control device 102 to the remote application server 155 or from the remote application server 155 to the data monitoring device 135, to a loss of communication between the sensor control device 102 and the device expected to relay sensor data to the remote application server 155. In some embodiments, the monitoring application 1810 may include only possible causes relevant based on detection conditions within the operating environment of the analyte monitoring system. As an example, the monitoring application 1810 may determine that the data monitoring device 135 does not have an active Internet connection or is in airplane mode. Accordingly, the notification may suggest that the data monitoring device 135 is the cause of the problem and suggest moving to an area with strong cellular service or connecting to a wireless network. As another example, the monitoring application 1810 may determine that there is an interruption in the remote application server 155, or within the remote application server, or in the notification service 1820. Accordingly, the notification may provide information indicating that the possible cause may be related to the remote application server 155 and not the data monitoring device 135.

[0280] In some embodiments, the notification may include a suggestion to use an alternate communication mode between the data monitoring device 135 and the remote application server 155 to receive updated sensor data. As an example, the remote application server 155 may provide an alternate service where the user wearing the sensor control device 102 can authorize the user to receive SMS messages with certain sensor data in the event of a service interruption. As another example, the notification may include a suggestion to use an alternate communication mode between the data monitoring device 135 and the device expected to upload sensor data for the sensor control device 102. As an example, the notification may identify the multi-purpose device 130 of the user wearing the sensor control device 102 as the one that last uploaded the data sent to the data monitoring device 135. The notification may also identify the phone number associated with the multi-purpose device 130 such that the user of the data monitoring device 135 can easily contact the user of the multi-purpose device 130.

[0281] Figure 25The first user interface 2500 is shown, through which a user of the data monitoring device 135 can customize the alerts to be received via the monitoring application. As an example, the user can determine whether they wish to receive an alert when the glucose level measured by the sensor control device 102 exceeds a low glucose threshold. The user can control and customize the alert via the user interface element 2510. Similarly, and as another example, the user can determine whether they want to receive an alert when the glucose level exceeds a high glucose threshold, which can be controlled and customized via the user interface element 2520. As another example, the user can control whether and how they want to receive an alert corresponding to the monitoring application 1810 not receiving the latest data within a threshold duration. The user can control the alert via the user interface element 2530. As another example, the user can control whether they want to receive a lost connection alert corresponding to when the communication channel between the data monitoring device 135 and the remote application server 155 is unresponsive. The lost connection alert can be controlled and customized via the user interface element 2540. The user can select an additional user interface element 2545 to access additional settings for the lost connection alert.

[0282] Figure 25 The second user interface 2550 is also shown, which shows a detailed settings page for the lost connection alert. The first interface element 2555 includes a description of the lost connection alert. The second interface element 2560 enables the user to customize the length of time that will trigger the lost connection alert. As an example, the user's selection can be used to set the length of time for triggering a heartbeat notification. In some embodiments, the remote application server 155 can also change the length of time for requesting that a heartbeat notification be sent to the monitoring application 1810 based on the selection.

[0283] It should be noted that all features, elements, components, functions, and steps described with respect to any embodiment provided herein are intended to be freely combinable and substitutable with those from any other embodiment. If a certain feature, element, component, function, or step is described only with respect to one embodiment, it should be understood that, unless otherwise explicitly stated, that feature, element, component, function, or step can be used with every other embodiment described herein. Thus, this paragraph serves as a preamble basis and written support for introducing claims at any time that combine the features, elements, components, functions, and steps of different embodiments, or substitute those of one embodiment with the features, elements, components, functions, and steps of another embodiment, even if the following description does not explicitly state so, but such combinations or substitutions are possible in certain circumstances. Therefore, for purposes of illustration and description, the foregoing description of specific embodiments of the disclosed subject matter has been presented. It is expressly recognized that formulating every possible combination and substitution would be overly cumbersome, especially considering that the permissibility of each such combination and substitution would be readily recognized by those of ordinary skill in the art.

[0284] Although the embodiments are susceptible to various modifications and alternative forms, specific examples thereof have been shown in the drawings and described in detail herein. It will be apparent to those skilled in the art that various modifications and variations can be made to the methods and systems of the disclosed subject matter without departing from the spirit or scope of the disclosed subject matter. Accordingly, the disclosed subject matter is intended to cover modifications and variations within the scope of the appended claims and their equivalents. Additionally, any feature, function, step, or element of an embodiment can be enumerated or added to the claims, as well as negative limitations that define the scope of the invention of the claims by features, functions, steps, or elements not within that scope.

[0285] Exemplary embodiments are set forth in the following numbered clauses:

[0286] 1. An analyte monitoring system, comprising:

[0287] A mobile device, comprising one or more processors and a memory communicatively coupled to the one or more processors, the memory comprising instructions that, when executed by the one or more processors, are configured to cause the one or more processors to execute an application associated with the analyte monitoring system; and

[0288] An analyte monitoring system server, configured to be communicatively coupled to the application,

[0289] wherein, when the instructions are executed, the application associated with the analyte monitoring system is configured to detect a non-responsive communication channel between the application and the analyte monitoring system server by performing operations including the following:

[0290] Receive a notification from the analyte monitoring system server via a notification service server, wherein

[0291] the notification service server is configured to be communicatively coupled to an application and the analyte monitoring system server;

[0292] In response to receiving the notification, cancel the output of a first connection alert, wherein the output of the first connection alert was scheduled before the notification was received;

[0293] In response to receiving the notification, schedule the output of a second connection alert, wherein the second connection alert is scheduled to be output when a timer expires, unless the mobile device receives a second notification from the analyte monitoring system server;

[0294] Determine that the timer has expired; and

[0295] Output the second connection alert, wherein the second connection alert indicates that the application has not established a connection with the analyte monitoring system server within a predetermined period of time.

[0296] 2. The analyte monitoring system according to clause 1, wherein, before receiving the notification from the analyte monitoring system server, the application is further configured to perform operations that further include the following:

[0297] Receive a request to establish an arrangement for monitoring a communication channel between the application and the analyte monitoring system server; and

[0298] In response to receiving the request, schedule the output of the first connection alert.

[0299] 3. The analyte monitoring system according to clause 1 or 2, wherein the amount of time associated with the timer is based on user input to an application associated with the analyte monitoring system.

[0300] 4. The analyte monitoring system according to clause 1, 2, or 3, wherein the application is a monitoring application of the analyte monitoring system, and wherein, via the application, a first user receives information related to the analyte level of a second user.

[0301] 5. The analyte monitoring system according to any one of the preceding clauses, wherein the application is further configured to perform operations that further include the following: Before outputting the second connection alert, attempt to initiate a communication session with the analyte monitoring system server using the communication channel or an alternate communication channel.

[0302] 6. The analyte monitoring system according to any one of the preceding clauses, wherein the application is further configured to perform operations that further include the following:

[0303] Receive a second notification from the analyte monitoring system server before determining that the timer has expired;

[0304] Cancel output of the second connection alert;

[0305] Schedule output of a third connection alert, where the third connection alert is scheduled to be output when a second timer expires, unless the mobile device receives a third notification from the analyte monitoring system server.

[0306] 7. The analyte monitoring system according to any of the preceding clauses, wherein the application is further configured to perform operations further including the following:

[0307] Receive other data from the analyte monitoring system server before determining that the timer has expired;

[0308] Cancel output of the second connection alert; and

[0309] Schedule output of a third connection alert, where the third connection alert is scheduled to be output when a second timer expires, unless the mobile device receives a third notification from the analyte monitoring system server.

[0310] 8. An analyte monitoring system, comprising:

[0311] A mobile device, including one or more processors and a memory communicatively coupled to the one or more processors, the memory including instructions that, when executed by the one or more processors, are configured to cause the one or more processors to execute an application associated with the analyte monitoring system; and

[0312] An analyte monitoring system server, configured to be communicatively coupled to the application,

[0313] wherein, when the instructions are executed, the application associated with the analyte monitoring system is configured to perform operations including the following:

[0314] Receive, via the application and through a communication channel between the application and the analyte monitoring system server, one or more current values associated with an analyte level and one or more historical values associated with the analyte level;

[0315] Detect that the communication channel between the application and the analyte monitoring system server is unresponsive;

[0316] Determine one or more possible causes for the unresponsiveness of the communication channel;

[0317] Modify the output of the application based on the unresponsiveness of the communication channel; and

[0318] Display a notification based on one or more possible causes for the unresponsiveness of the communication channel, where

[0319] The notification includes additional information for resolving an unresponsive communication channel.

[0320] 9. The analyte monitoring system according to clause 8, wherein the application is a monitoring application of the analyte monitoring system, and wherein, through the application, a first user receives information related to the analyte level of a second user.

[0321] 10. The analyte monitoring system according to clause 8 or 9, wherein modifying the output of the application includes: restricting the functionality of the application when the communication channel is unresponsive.

[0322] 11. The analyte monitoring system according to clause 8, 9 or 10, wherein the application stores historical values, and modifying the output of the application includes: displaying the historical values until the application detects that the communication channel is unresponsive.

[0323] 12. The analyte monitoring system according to clause 11, wherein the application is further configured to perform operations including: encrypting the historical values before storage.

[0324] 13. The analyte monitoring system according to clause 11 or 12, wherein the application is further configured to perform operations including: de-identifying the historical values before storage.

[0325] 14. The analyte monitoring system according to clause 11, 12 or 13, wherein the application is further configured to perform operations including: erasing the historical values after a predetermined period of time.

[0326] 15. The analyte monitoring system according to any one of clauses 8 to 14, wherein modifying the output of the application includes: displaying the last known state of the analyte level.

[0327] 16. The analyte monitoring system according to clause 15, wherein the application is further configured to perform operations including: determining the last known state of the analyte level by comparing one or more current values with one or more thresholds, each threshold corresponding to a respective last known state.

[0328] 17. The analyte monitoring system according to any one of clauses 8 to 16, wherein while the communication channel is unresponsive, the application continuously displays a notification.

[0329] 18. The analyte monitoring system according to any one of clauses 8 to 17, wherein the notification identifies an error in the application or the system state of the mobile device.

[0330] 19. The analyte monitoring system according to any one of clauses 8 to 18, wherein the notification identifies an error in the analyte monitoring system server.

[0331] 20. The analyte monitoring system according to any one of clauses 8 to 19, wherein the notification includes a recommendation to use a second communication channel between the application and the analyte monitoring system server.

[0332] 21. The analyte monitoring system according to any one of clauses 8 to 20, wherein the application is further configured to perform operations including the following:

[0333] After displaying the notification, detecting a response on the communication channel between the application and the analyte monitoring system server; and

[0334] Receiving additional historical values associated with the analyte corresponding to the period when the communication channel is unresponsive.

[0335] 22. The analyte monitoring system according to any one of clauses 8 to 21, wherein the application is further configured to perform operations including the following:

[0336] When detecting that the communication channel is unresponsive, determining the geographical location of the mobile device;

[0337] After displaying the notification, detecting a response on the communication channel between the application and the analyte monitoring system server; and

[0338] Providing the geographical location of the mobile device to the analyte monitoring system server when detecting that the communication channel is unresponsive.

Claims

1. An analyte monitoring system, comprising: a mobile device including one or more processors and a memory communicatively coupled to the one or more processors, the memory including instructions which, when executed by the one or more processors, are configured to cause the one or more processors to execute an application associated with the analyte monitoring system; and an analyte monitoring system server configured to be communicatively coupled to the application, wherein, when the instructions are executed, the application associated with the analyte monitoring system is configured to detect a non-responsive communication channel between the application and the analyte monitoring system server by performing operations including the following: receiving a notification from the analyte monitoring system server via a notification service server, wherein the notification service server is configured to be communicatively coupled to the application and the analyte monitoring system server; in response to receiving the notification, canceling the output of a first connection alert, wherein the output of the first connection alert is scheduled before receiving the notification; in response to receiving the notification, scheduling the output of a second connection alert, wherein the second connection alert is scheduled to be output when a timer expires, unless the mobile device receives a second notification from the analyte monitoring system server; determining that the timer has expired; and outputting the second connection alert, wherein the second connection alert indicates that the application has not established a connection with the analyte monitoring system server within a predetermined period of time.

2. The analyte monitoring system according to claim 1, wherein, before receiving the notification from the analyte monitoring system server, the application is further configured to perform operations further including the following: receiving a request to establish an arrangement for monitoring the communication channel between the application and the analyte monitoring system server; and in response to receiving the request, scheduling the output of the first connection alert.

3. The analyte monitoring system according to claim 1, wherein, the amount of time associated with the timer is based on user input to the application associated with the analyte monitoring system.

4. The analyte monitoring system according to claim 1, wherein, the application is a monitoring application of the analyte monitoring system, and wherein, through the application, a first user receives information related to the analyte level of a second user.

5. The analyte monitoring system according to claim 1, wherein, the application is further configured to perform operations further including the following: before outputting the second connection alert, attempt to initiate a communication session with the analyte monitoring system server using the communication channel or an alternate communication channel.

6. The analyte monitoring system according to claim 1, wherein, the application is further configured to perform operations further including the following: receiving the second notification from the analyte monitoring system server before determining that the timer has expired; canceling the output of the second connection alert; Arrange to output a third connection alert, where the third connection alert is arranged to be output when a second timer expires, unless the mobile device receives a third notification from the analyte monitoring system server.

7. The analyte monitoring system according to claim 1, wherein, the application is further configured to perform operations that further include the following: Receive other data from the analyte monitoring system server before determining that the timer has expired; Cancel the output of the second connection alert; and Arrange to output a third connection alert, where the third connection alert is arranged to be output when a second timer expires, unless the mobile device receives a third notification from the analyte monitoring system server.

8. An analyte monitoring system, comprising: A mobile device, including one or more processors and a memory communicatively coupled to the one or more processors, the memory including instructions that, when executed by the one or more processors, are configured to cause the one or more processors to execute an application associated with the analyte monitoring system; and An analyte monitoring system server, configured to be communicatively coupled to the application, wherein, when the instructions are executed, the application associated with the analyte monitoring system is configured to perform operations including the following: Receive, via the application and through a communication channel between the application and the analyte monitoring system server, one or more current values associated with the analyte level and one or more historical values associated with the analyte level; Detect that the communication channel between the application and the analyte monitoring system server is unresponsive; Determine one or more possible causes for the unresponsiveness of the communication channel; Modify the output of the application based on the unresponsiveness of the communication channel; and Display a notification based on the one or more possible causes of the unresponsiveness of the communication channel, where the notification includes additional information for resolving the unresponsive communication channel.

9. The analyte monitoring system according to claim 8, wherein, the application is a monitoring application of the analyte monitoring system, and wherein, through the application, a first user receives information related to the analyte level of a second user.

10. The analyte monitoring system according to claim 8, wherein, modifying the output of the application includes: restricting the functionality of the application when the communication channel is unresponsive.

11. The analyte monitoring system according to claim 8, wherein, the application stores the historical values, and modifying the output of the application includes: displaying the historical values until the application detects that the communication channel is unresponsive.

12. The analyte monitoring system according to claim 11, wherein, the application is further configured to perform operations including the following: encrypting the historical values before storage.

13. The analyte monitoring system according to claim 11, wherein, The application is further configured to perform operations including: de-identifying the historical values prior to storage.

14. The analyte monitoring system according to claim 11, wherein, The application is further configured to perform operations including: erasing the historical values after a predetermined period of time.

15. The analyte monitoring system according to claim 8, wherein, Modifying the output of the application includes: displaying the last known state of the analyte level.

16. The analyte monitoring system according to claim 15, wherein, The application is further configured to perform operations including: determining the last known state of the analyte level by comparing the one or more current values with one or more thresholds, each threshold corresponding to a respective last known state.

17. The analyte monitoring system according to claim 8, wherein, While the communication channel is unresponsive, the application continuously displays the notification.

18. The analyte monitoring system according to claim 8, wherein, The notification identifies an error in the application or the system state of the mobile device.

19. The analyte monitoring system according to claim 8, wherein, The notification identifies an error in the analyte monitoring system server.

20. The analyte monitoring system according to claim 8, wherein, The notification includes a recommendation to use a second communication channel between the application and the analyte monitoring system server.

21. The analyte monitoring system according to claim 8, wherein, The application is further configured to perform operations including the following: After displaying the notification, detecting that the communication channel between the application and the analyte monitoring system server is responsive; and Receiving and associating additional historical values of the analyte corresponding to the period when the communication channel was unresponsive.

22. The analyte monitoring system according to claim 8, wherein, The application is further configured to perform operations including the following: When detecting that the communication channel is unresponsive, determining the geographical location of the mobile device; After displaying the notification, detecting that the communication channel between the application and the analyte monitoring system server is responsive; and Providing the geographical location of the mobile device to the analyte monitoring system server when detecting that the communication channel is unresponsive.

Citation Information

Patent Citations

  • Analyte Sensors and Methods of Making and Using the Same

    US20100230285A1

  • Analyte Sensor Devices, Connections, and Methods

    US20130150691A1

  • Dermal layer analyte sensing devices and methods

    US20140171771A1

  • Systems, devices, and methods for assembling an applicator and sensor control device

    US20160331283A1

  • Systems, devices and methods for analyte sensor insertion

    US20180235520A1