Method for configuration management of at least one laboratory analysis system
By implementing a configuration management method in the laboratory analysis system, and using cryptographic functions to generate and store security information items, the issues of system component traceability and data security are resolved, thereby achieving system configuration reliability and maintainability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- F HOFFMANN LA ROCHE & CO AG
- Filing Date
- 2024-10-29
- Publication Date
- 2026-05-29
AI Technical Summary
In in vitro diagnostic laboratory analysis systems, existing technologies cannot effectively trace the configuration of system components, resulting in a lack of good control over the field system and challenges in data management and storage security.
By implementing a configuration management approach in the laboratory analysis system, using cryptographic functions to generate security information items, and storing them in both laboratory and remote central databases, the encryption and security of data content are ensured.
It improves the traceability of system components and the security of data management, ensures a complete chain of system configuration records and updates, and supports the reliability and maintainability of hardware and software status.
Smart Images

Figure CN122122586A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a computer-implemented method for configuration management of at least one laboratory analytical system, a computer-implemented method for generating full-channel measurement results of at least one laboratory analytical system, an infrastructure, a computer program, a computer-readable storage medium, and a computer program product. Background Technology
[0002] In known in vitro diagnostic (IVD) laboratory analytical systems, configuration management only tracks combinations of multiple analytical units (AUs) and control or core units, and at the individual AU level, it tracks instrument IDs and major hardware changes and system configurations (consumables and reagents) used for assays. However, the combination of measurement data with detailed system configurations (a historical and current list of spare parts and built-in components installed in the system, in addition to the chemicals used) is not available. Because of this, technical issues may arise regarding the traceability of system components, making it impossible to reach a stage of better control of the system in the field, and the number of configurations installed in the field is also unknown (the complexity of component interference). Furthermore, the combination of results and configurations presents additional technical challenges, requiring the implementation of secure technologies (inaccessible to third parties) for data management and storage (at both the manufacturer and the customer) at the data processing level.
[0003] US10521805 B2 describes the determination of the qualification status of a device in a system. It determines the occurrence of a triggering event for the device. The triggering event is caused by the occurrence of any of the following: a time-based event, a performance-based event, a usage-based event, and an unplanned event. In response to this occurrence, a user notification is provided to perform a first action. The first action is an operation performed for any of the following: maintenance activities, repair activities, and testing of the device. The qualification status of the device is updated based on the first action.
[0004] US 2017 / 220756 A1 describes a mobile unit with memory temporarily connected to a medical technology device and temporarily connected to a central storage device for data transfer. When the mobile unit is connected to the medical technology device, the actual configuration of the medical technology device is compared with a local virtual image of the configuration of the medical technology device held in the memory of the mobile unit. Based on this comparison, the local configuration and / or the actual configuration is updated. When the mobile unit is connected to the central storage device, the local configuration is compared with a central virtual image of the configuration of the medical technology device. Based on this comparison, the central configuration and / or the local configuration is updated.
[0005] Problems to be solved Therefore, the object of the present invention is to provide a computer-implemented method for configuration management of at least one laboratory analytical system, a computer-implemented method for generating full-channel measurement results for at least one laboratory analytical system, an infrastructure, a computer program, a computer-readable storage medium, and a computer program product that avoids the aforementioned disadvantages of known methods, apparatuses, computer programs, and computer program products. In particular, the method and apparatus should allow for improved traceability of system components. Summary of the Invention
[0006] This problem is addressed by a computer-implemented method for configuration management of at least one laboratory analytical system, a computer-implemented method for generating full-channel measurement results for at least one laboratory analytical system, an infrastructure, a computer program, a computer-readable storage medium, and a computer program product, having the features of the independent claims. Advantageous embodiments that can be implemented individually or in any combination are set forth in the dependent claims and throughout the specification.
[0007] As used below, the terms “have,” “contain,” or “include,” or any grammatical variations thereof, are used in a non-exclusive manner. Thus, these terms can refer either to a situation where no other features exist in the entity described in this context besides those introduced by these terms, or to a situation where one or more other features exist. For example, the statements “A has B,” “A includes B,” and “A contains B” can refer to a situation where no other elements exist in A besides B (i.e., where A is solely and uniquely composed of B); or to a situation where one or more other elements (such as element C, element D, or even other elements) exist in entity A besides B.
[0008] Furthermore, it should be noted that the terms "at least one," "one or more," or similar expressions indicating that a feature or element may exist once or more are generally used only once when introducing the corresponding feature or element. In the following text, in most cases, when referring to the corresponding feature or element, the expressions "at least one" or "one or more" will not be used repeatedly, even though the corresponding feature or element may exist only once or more.
[0009] Furthermore, as used below, the terms “preferredly,” “more preferably,” “particularly / specifically,” “more particularly / more specifically,” “specifically,” “more specifically,” or similar terms are used in combination with optional features without limiting the possibility of alternatives. Therefore, features introduced by these terms are optional features and are not intended to limit the scope of the claims in any way. As those skilled in the art will recognize, the invention can be carried out by using alternative features. Similarly, features or similar expressions introduced by “in one embodiment of the invention” are intended to be optional features without limiting alternative embodiments of the invention, without limiting the scope of the invention, and without limiting the possibility of combining features introduced in this way with other optional or non-optional features of the invention.
[0010] In a first aspect, a computer-implemented method for configuration management of at least one laboratory analysis system including at least one analysis unit is disclosed.
[0011] As used herein, the term "computer-implemented" is a broad term and should be given its common and customary meaning to those skilled in the art, and should not be limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, methods involving at least one computer and / or at least one computer network. The computer and / or computer network may include at least one processor configured to perform at least one method step in the method according to the invention. Preferably, each method step is performed by a computer and / or computer network. The method may be performed entirely automatically (e.g., without user interaction). As used herein, the term "automatically" is a broad term and is given its common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, processes performed entirely by means of at least one computer and / or at least one computer network and / or at least one machine, particularly those requiring no manual operation and / or user interaction.
[0012] As used herein, the term "laboratory analytical system" is a broad term and should be given the common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, at least one environment including at least one analytical unit, such as multiple laboratory instruments, such as at least one analyzer, and / or at least one instrument configured to analyze at least one sample, particularly at least one biological sample. A laboratory analytical system may be configured for in vitro diagnostics (IVD), for example, a laboratory analytical system may be configured to perform in vitro examination of at least one sample derived from a human body, and / or be configured to provide information for diagnostic, monitoring, or compatibility purposes. As used herein, the term "system" generally may refer to any set of interactive components configured to interact to perform at least one common task. Specifically, components of a laboratory system may interact with each other to perform at least one laboratory task. At least two components may be processed independently, or may be coupled or interconnected. A laboratory analytical system may specifically be or may include automated laboratory systems configured to automatically or semi-automatically process multiple samples, particularly large numbers of samples. As an example, a laboratory analytical system may be or may include an automated laboratory analyzer. Laboratory analytical systems can be used in medical laboratory fields such as clinical laboratories or forensic laboratories and / or chemical laboratory fields such as analytical laboratories. Exemplary embodiments of laboratory analytical systems (with modifications as discussed herein) that can also be used in the context of this invention may include, for example, the Roche cobas® pro analyzer series or other analytical systems. However, other laboratory analytical systems may also be used.
[0013] A laboratory analysis system includes at least one analytical unit, or, for example, multiple analytical units.
[0014] As used herein, the term "unit" is a broad term and is given its common and conventional meaning to those skilled in the art, and is not limited to any particular or custom-defined meaning. Specifically, the term may refer to, for example, but not limited to, a module in a modular system.
[0015] As used herein, the term "analytical unit (AU)" is a broad term and should be given its common and customary meaning to those skilled in the art, and is not limited to any particular or customary meaning. Specifically, the term may refer, for example, but not limited to, a unit of a laboratory analytical system configured to perform at least one analytical function (e.g., configured to analyze at least one sample). An analytical unit may be designed, for example, to use a sample or a portion thereof, along with reagents, to generate a measurable signal based on which the presence of an analyte can be determined, and, if necessary, its concentration. An analytical unit comprises multiple modules and / or sub-units, each module and / or sub-unit including at least one hardware element. An analytical unit may use multiple consumables, such as multiwell plates, containers, liquids, pipette tips, columns, spare parts, etc. At least some of the modules and / or sub-units are operable to perform one or more processing steps or workflow steps on one or more samples. Processing steps may include physically performing steps such as centrifugation, aliquoting, sample analysis, etc.
[0016] An analytical unit may include at least one mass analyzer. As used herein, the term "mass analyzer" is a broad term and should be given the common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, any analytical device configured to determine or measure the mass-to-charge ratio of ions. Measurement results may specifically be presented as mass spectra, such as graphs of intensity as a function of mass-to-charge ratio and / or intensity as a function of mass transitions. Analyzer readout may also be based on other physical processes, such as absorption, transmission, scattering, phosphorescence, and fluorescence, and combinations thereof. Furthermore, the determination of functional readout may be combined with other orthogonal methods to improve sensitivity or minimize interference.
[0017] As used herein, the term "sample" is a broad term and is given a common and customary meaning to those skilled in the art, and is not limited to a specific or custom-defined meaning. Specifically, the term may refer to, but is not limited to, material suspected of containing the analyte of interest. Samples can be from any biological source, such as physiological fluids, including blood, saliva, lens fluid, cerebrospinal fluid, sweat, urine, milk, ascites, mucus, synovial fluid, peritoneal fluid, amniotic fluid, tissue, cells, etc. Samples may be pretreated before use, such as preparing plasma from blood, diluting viscous fluids, lysing, etc.; treatment methods may involve filtration, distillation, concentration, inactivation of interfering components, and addition of reagents. Samples may be used directly after being obtained from their source, or they may be pretreated to alter their properties, for example, after dilution with another solution or after mixing with reagents, for example, to perform one or more diagnostic tests, such as clinical chemistry tests, immunoassays, coagulation tests, nucleic acid detection, etc. Therefore, as used herein, the term "sample" refers not only to the original sample but also to a sample that has been processed (e.g., pipetting, dilution, mixing with reagents, enrichment, purification, amplification, etc.). As used herein, the term "analyte" can refer to a compound or composition to be detected or measured.
[0018] A laboratory analytical system may include other units, such as at least one database, at least one control and / or processing unit, and / or other laboratory instruments. The term "laboratory instrument" may encompass, for example, pre-analytical instruments, post-analytical instruments, and / or analytical instruments. Pre-analytical instruments are typically used for the preliminary handling of samples or sample vessels. Post-analytical instruments are typically used for post-processing of samples, such as sample archiving. A laboratory analytical system and / or analytical unit may include at least one laboratory instrument selected from the group consisting of: pipetting devices and other devices for transferring samples, such as sorting devices for sorting samples or sample vessels, cap removal devices for removing caps or closures from sample vessels, cap mounting devices for attaching caps or closures to sample vessels, aliquoting devices for aliquoting samples, centrifuging devices for centrifuging samples, heating devices for heating samples, cooling devices for cooling samples, mixing devices for mixing samples, separation devices for separating analytes from samples, storage devices for storing samples, archiving devices for archiving samples, sample vessel type determination devices for determining sample vessel type, and sample quality determination devices for determining sample quality.
[0019] As used herein, the term "configuration" is a broad term and is given a common and conventional meaning to those skilled in the art, and is not limited to a specific or customary meaning. The term may specifically refer to, but is not limited to, hardware and / or software states.
[0020] As used herein, the term "configuration management" is a broad term and should be given a common and conventional meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, at least one process for establishing and / or maintaining the performance consistency of a laboratory analytical system. Configuration management may include managing changes throughout the laboratory analytical system. Configuration management may include recording changes. Configuration management may allow ensuring the traceability of hardware and / or software status. Configuration management may include repeatedly checking the status of information. Configuration management may include making updated and historical information available within at least one database. Configuration management may include providing a complete chain of recorded hardware and / or software status and / or changes. Configuration management may allow modification of functionality, improvement of performance, reliability or maintainability, extension of lifespan, reduction of costs, and may allow for the correction of defects.
[0021] The method includes the following steps: a) Retrieve at least one information item regarding the configuration of at least one analytical unit of the laboratory analytical system; b) Apply at least one cryptographic function to an information item relating to the configuration of the analysis unit, thereby generating a security information item relating to the configuration of the analysis unit; c) Provide the security information items related to the configuration of the analysis unit to at least one database of the laboratory analysis system and / or to at least one remote central database, wherein the remote central database is located at the manufacturer's site and / or cloud database.
[0022] The method steps can be performed in a given order or in a different order. Furthermore, there may be one or more additional method steps not listed. Furthermore, one, more than one, or even all method steps may be performed repeatedly.
[0023] This invention allows for the encryption of data content using at least one cryptographic function (e.g., a hash function), specifically encrypting information about the configuration of at least one analytical unit within a laboratory analytical system. Communication technologies using VPNs (e.g., as disclosed in US 2017 / 220756 A1) involve encryption of the transmission type rather than the data content. In other words, it is possible to eavesdrop on communications in US 2017 / 220756 A1 and decode or understand all the information if the corresponding key is available. In contrast, the encryption of data content as proposed in this application ensures that even after decrypting the communication channel, only an undecryptable hash is found, which cannot be decoded with limited computing power.
[0024] As described above, step a) includes retrieving at least one information item regarding the configuration of at least one analytical unit of the laboratory analytical system.
[0025] As used herein, the term "analysis unit configuration" is a broad term and should be given its common and customary meaning to those skilled in the art, and is not limited to any particular or custom meaning. Specifically, the term may refer to, but is not limited to, the configuration of the hardware and / or software associated with the analysis unit. For example, information items related to the analysis unit configuration may include information about at least one element selected from the group consisting of: software version; firmware version; hardware configuration; test batch, consumable batch; module information; unit information; sub-units of the analysis unit; sub-unit identifier; location information; location of at least one item or spare part; serial number; batch number; sub-unit identifier; installation date; unique operating identifier; type of analysis unit; operator or maintenance technician; defined maintenance or repair operation protocol; timestamp; location; or dynamic counter.
[0026] As used herein, the term "module information" is a broad term and should be given a common and conventional meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, information used to distinguish modules, such as in the presence of more than one analysis unit.
[0027] As used herein, the term "unit information" is a broad term and should be given a meaning that is common and customary to those skilled in the art, and is not limited to a specific or custom-defined meaning. Specifically, the term may refer to, but is not limited to, information used to distinguish different units of an analytical unit, such as at least one unit for liquid chromatography (LC) or at least one unit for mass spectrometry (MS). As used herein, the term "information about a subunit" is a broad term and should be given a meaning that is common and customary to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, information about an element of an analytical unit, such as one of the high-performance liquid chromatography (HPLC) subunits of an LC unit to further describe it.
[0028] Information about the sub-unit identifier (ID) can refer to the ID that uniquely describes the sub-unit.
[0029] Information about the type of analysis unit can include a series of information about the analysis unit.
[0030] The serial number of an item or spare part may include a unique number defined by the manufacturer for each individual item or spare part. An item or spare part can be a physical entity required for the hardware and / or software and / or firmware functionality of the analyzer. Items or spare parts may have a direct impact on overall measurement results or may be used to control the overall state of the analyzer. These include, for example, nozzles, pipettes, incubators, temperature control units, sensors, detectors, pumps, syringes, seals, tubing, pipes, microcontrollers, boards, and cables.
[0031] Location information can include a unique name for the location and coordinates in three-dimensional physical space. Only a single item or spare part can be assigned to a specific location. Items and spare parts can be defined by the manufacturer.
[0032] Information regarding serial numbers and / or lot numbers can refer to a unique number defined by the manufacturer for each individual spare part. In the absence of a serial number, a lot number may also apply, for example, to plastic parts.
[0033] Information about the installation date can refer to the date the item or spare part was installed at that specific location. This information may be updated when the spare part is replaced, and may trigger a counter reset.
[0034] Information regarding the unique operation ID can refer to a link used to connect local instrument data to at least one external database (Cube, CIR, etc.). The operation ID can describe the operation performed on the analysis unit and optionally additional metadata. This information can be stored externally. This information may include comments, relevant personnel, timestamps, etc.
[0035] For example, step a) includes providing at least one information item about general data, such as a timestamp, a sample unique identifier, a system unique identifier, a system configuration unique identifier, a one-way function, or a location, or more of these.
[0036] For example, step a) includes providing at least one information item about the system configuration, such as information about at least one analytical unit (e.g., a unique identifier), by combining information about reagents and consumables (e.g., information about reagents such as batch and / or unique identifiers) and information about consumables such as batch and / or unique identifiers).
[0037] Information items regarding the configuration of the analysis unit can be retrieved in the form of data. As used herein, the term "data" is a broad term and should be given a common and conventional meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, information and / or machine-readable signals or symbols representing information. Data may specifically be or may include one or both of digital data and analog data. Data can have various data types, such as integers, strings, etc. Data may be encrypted data.
[0038] As used herein, the term "retrieval" is a broad term and should be given the common and conventional meaning to those skilled in the art, and is not limited to a specific or customary meaning. The term may specifically refer to, but is not limited to, the process of obtaining data from a data source. However, the data source may vary depending on the specific application. Retrieval can be performed by at least one of the following: downloading data from a database (such as from at least one data storage device); downloading data from a network-based or cloud-based data storage device; obtaining data via at least one computer network (such as the Internet); or obtaining data via at least one wired and / or wireless interface. For example, the retrieval in step a) includes providing information items about the configuration of the analysis unit via at least one user input through at least one human-machine interface and / or receiving information items about the configuration of the analysis unit from a database. Retrieval can be performed fully or partially automatically, such as through automatic downloading and / or can be performed fully or partially manually. Semi-automatic retrieval processes are also feasible.
[0039] As described above, step b) includes applying at least one cryptographic function to an information item about the configuration of the analysis unit, thereby generating a security information item about the configuration of the analysis unit.
[0040] As used herein, the term "secure" is a broad term and should be given a common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, information that is inaccessible to one or more of the transmitting entity, receiving entity, or a third party. As used herein, the term "secure information item" is a broad term and should be given a common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, immutable information generated using one or more cryptographic techniques (e.g., blockchain technology, certificate-public / private keys, hash codes, etc.). For example, a secure information item may be a hash value. As used herein, the term "cryptographic function" is a broad term and should be given a common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, an algorithm configured for cryptographic applications. For example, in step b), the cryptographic function includes at least one cryptographic hash function. The method includes applying at least one cryptographic hash function to an information item related to the configuration of the analysis unit to generate a hash value. A hash function can be any function that can be used to map data of any size to a fixed-size value. A hash function can be a secure hash algorithm (SHA), such as SHA-1, SHA-2, SHA-3, SHA-256, or a message digest algorithm (MD), such as MD5, RIPEMD-160, Tiger, HAVAL, or Whirlpool. Non-cryptographic hash functions (such as xxHash) and cryptographic hash functions can also be used. The value returned by a hash function is called a hash value. As used herein, the term "hash value" (also referred to as hash) is a broad term and should be given a common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term can refer to, but is not limited to, a fixed-length numerical value that uniquely represents data. Decryption is likely possible if the cryptographic function used to generate the secure information item is known.
[0041] Information items related to the configuration of the analysis unit can have various data types, such as integers, strings, etc. The information regarding the configuration of the analysis unit can be structured or unstructured. Furthermore, the information can contain various data types, such as integers, strings, characters, booleans, arrays, dates, and timestamps. Information data structures can also be nested. In this case, the data is flattened before being converted into a data string. Step b) can include converting the information items related to the configuration of the analysis unit into at least one data string, converting the data string into bytes, and applying a cryptographic hash function to the bytes to generate a hash value. For example, the information items related to the configuration of the analysis unit can be converted into a plain string for conversion into bytes. Then, a cryptographic hash function (such as SHA256) can be applied to the bytes, resulting in a unique hash. The hash can also be converted to hexadecimal or any other format. Furthermore, other functions of the SHA family or MD5 can be used for hash creation, as described above.
[0042] Step c) includes providing security information items related to the configuration of the analysis unit to at least one database of the laboratory analysis system and / or to at least one remote central database.
[0043] As used herein, the term "provide" is a broad term and should be given a meaning that is common and customary to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, the transmission of security information items in an analysis unit configuration, for example, for storage and / or further use.
[0044] As used herein, the term "database" is a broad term and is given a common and conventional meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, an organized collection of data typically stored and accessed electronically from a computer or computer system. A database may include, or may consist of, data storage devices. A database may include at least one database management system that includes software running on a computer or computer system that allows interaction with one or more of the users, applications, or the database itself, such as to capture and analyze data contained in the database. A database management system may further encompass facilities used to manage the database. Thus, a database containing data may consist of a database system that, in addition to including the data, includes one or more associated applications.
[0045] The database can be configured to store security information items related to the configuration of the analytical unit. The database may include information about permitted configurations and at least one library. The library may include individual cation IDs permitted for individual components (e.g., analytical units) of the laboratory analytical system. Furthermore, the database can be configured to store secret keys.
[0046] As mentioned above, safety information items can be provided to the database of the laboratory analysis system, such as an internal database. The internal database could be a log.
[0047] Alternatively or concurrently, security information items regarding the configuration of the analytical unit are provided to a remote central database. As used herein, the term "remote database" is a broad term and should be given the common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. The term may specifically refer to, but is not limited to, a database external to the laboratory analytical system. For example, a remote central database may reside at the manufacturer's site and / or in a cloud database. A remote central database may be the manufacturer's own remote central database.
[0048] A laboratory analysis system, a service computer, and a remote central database form a communication network, wherein the laboratory analysis system, the service computer, and the remote central database are nodes of the communication network. As used herein, the term "central database" is a broad term and should be given its common and conventional meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, a database configured to communicate with multiple elements of the communication network (e.g., with all participants in the communication network). For example, a remote central database may be configured to communicate with the laboratory analysis system and the service computer.
[0049] For example, security information items can be provided according to standards used for the electronic exchange of medical, administrative, and financial data between healthcare information systems. Security information items can be provided, for example, in the z-segment of a Health Level (HL) 7 application layer or a z-segment of a system status message. Typically, an HL7 segment includes MSH (message header), PID (patient information), NK1 (close relatives), and PV1 (patient visits). Various healthcare-related information can be communicated to a wide variety of different systems via HL7 messages. Sometimes HL7 messages need to contain custom data that cannot be included in any of the defined segments for its message type. To accommodate this, the HL7 standard allows system vendors to create z-segments with custom fields to transmit this data. At least one of these custom fields can be used for security information items, such as as a string. Z-segments can be placed anywhere in an HL7 message, but are typically the last segment in the message. Hashes can also be incorporated into official standards and / or regulatory requirements. HL7 is an international standard for ANSI (American National Standards Institute) members and is part of the ISO standardization of UN specifications. It forms the basis of universal communication and helps reduce misunderstandings. Z-segments, for example, are defined in HL7-v2 for country or company-related segments. Z-segments are locally defined message segments, not part of the HL7 standard. Z-segments are part of the reason the HL7 standard is considered a "flexible" standard. You may find that you need to create new fields to support your Z-segment needs.
[0050] The provision of security information items related to the configuration of the analysis unit can be made via at least one communication interface. As used herein, the term "communication interface" is a broad term and will be given a meaning common and customary to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, an object or element forming a boundary configured for transmitting information. A communication interface may be configured to transmit information from a computing device (e.g., a computer), such as to send or output information to, for example, another device. Additionally or alternatively, a communication interface may be configured to transmit information to a computing device (e.g., to a computer), such as to receive information. A communication interface may specifically provide a means for transmitting or exchanging information. A communication interface may provide a data transmission connection, such as a WAN, LAN, Bluetooth, NFC, inductive coupling, etc. As an example, a communication interface may be or may include at least one port, including one or more of a network or Internet port, a USB port, and a disk drive. For example, a communication interface may be at least one Web interface. For example, data transmission may be via the Internet.
[0051] Steps a) through c) can be performed by at least one service computer, for example, as part of a repair workflow and / or maintenance workflow. As used herein, the term "service computer" is a broad term and should be given the common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. The term can specifically refer to, but is not limited to, any processing device used to perform repair and / or maintenance workflows. A service computer can be a PC, tablet computer, etc.
[0052] As used herein, the term "maintenance workflow and / or repair workflow" is a broad term and should be given a common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, any activity aimed at keeping or restoring a functional unit to a specified state in which the unit can perform its required functions and / or intended purposes. For example, a maintenance workflow and / or repair workflow may include at least one operation selected from the group consisting of: at least one test, at least one measurement, at least one replacement, at least one adjustment, and at least one repair. For example, a maintenance workflow and / or repair workflow may include one or more of the installation, updating, repair, and maintenance of at least one spare part. Maintenance and / or repair operations may include physical replacement and / or repair of spare parts or sub-units, complete / partial updates or changes to the software and / or firmware of the analysis unit. Furthermore, predictive and preventative maintenance operations based on predefined procedures may modify the analysis unit.
[0053] For example, maintenance workflows and / or repair workflows include - Perform at least one repair and / or maintenance operation on at least one analysis unit; - Generate updated information items regarding the configuration of the analysis unit; - Apply the cryptographic function to the update information item about the analysis unit configuration to generate an update security information item about the analysis unit configuration; - Provide updated safety information items related to the configuration of the analysis unit to the database of the laboratory analysis system and the remote central database.
[0054] The method may further include providing a laboratory information management system (LIMS) with security information items regarding the configuration of the analysis unit. The LIMS can be configured to electronically record measurement results generated by at least one analysis unit of the laboratory analysis system. The security information items regarding the analysis unit configuration can be transmitted from a service computer to the LIMS and / or from a control unit of the laboratory system to the LIMS. The LIMS can transmit the security information items to a remote central database.
[0055] This method may include using static hashing, such as generating a hash at the server computer and providing it to the database without alteration. Alternatively, the method may use dynamic hashing. For example, additional information may be added to the hash generated at the server computer, and it may be subsequently encrypted, for example, by applying a cryptographic function or other cryptographic function to generate the hash value. The hash value may be sent to the database. Decryption may be possible if the cryptographic function used to generate the dynamic hash is known.
[0056] The method may include steps a) through c) during the installation of the laboratory system to establish initial safety information items regarding the configuration of the analytical unit.
[0057] The steps of this method can be repeated. For example, the method can be repeated upon subsequent changes and / or at other predefined times to generate updated safety information items regarding the configuration of the analytical unit. Step c) may include replacing the safety information items regarding the configuration of the analytical unit with the updated information items regarding the configuration of the analytical unit in the database of the laboratory analytical system, and providing the updated information items regarding the configuration of the analytical unit to a remote central database.
[0058] For example, the method may include creating a set of dynamic counters to trigger different maintenance operations, such as different analytes and / or the general use of a spare part, to influence the timing of maintenance.
[0059] For example, the method may include generating at least one root hash. The root hash may be the top hash of a hash tree, also referred to as the main hash. Generating the root hash may include repeating steps a) to b) using other information items related to the configuration of the analysis unit, generating other hash values, and aggregating hash values and other hash values. The method may further include generating a blockchain. The method may include generating multiple subsequently linked blocks of the blockchain. As used herein, the term "block" is a broad term and should be given a common and customary meaning to those skilled in the art, and is not limited to a specific or custom meaning. The term may specifically refer to, but is not limited to, components or elements of a blockchain. A blockchain can be defined as a blockchain that can store certain records, and these blocks are linked together using cryptographic principles, for example, en.wikipedia.org / wiki / Blockchain. A blockchain may include multiple linked blocks. Blocks can be linked by including the hash values of previous blocks. Each block may include the cryptographic hash of the previous block. Each block may further include a timestamp. Each block may include the hash of the previous block, the timestamp, and optionally other data.
[0060] This method may include an integrity test. The integrity test may include retrieving actual safety information items related to the configuration of the analysis unit from a database stored in the laboratory analysis system and from a remote central database. The integrity test may include comparing the actual safety information items related to the configuration of the analysis unit stored in the database of the laboratory analysis system and from the actual safety information items related to the configuration of the analysis unit stored in the remote central database. If the actual safety information items related to the configuration of the analysis unit stored in the database of the laboratory analysis system and the actual safety information items related to the configuration of the analysis unit stored in the remote central database are different, the integrity test fails; otherwise, the integrity test passes.
[0061] This invention allows the creation of security information items such as hash values (i.e., configuration strings), which facilitate the easy identification of past, current, and future advanced analytics unit configuration states. This allows for simultaneous coverage of two paths: historical documentation of every change and branch tracing highlighting major changes. As will be outlined in more detail below, security information items can be assigned to each measurement result.
[0062] On the other hand, a computer-implemented method for generating full-channel measurement results for at least one laboratory analytical system is disclosed. The method includes the following steps: i) Provide at least one measurement result generated by at least one analytical unit of the laboratory analysis system; ii) By using at least one control unit of the laboratory analysis system, the measurement results are associated with a security information item relating to the configuration of the analysis unit generated by performing the method for configuration management according to the invention, such as according to any of the embodiments disclosed with respect to the above method and / or according to any of the embodiments disclosed in further detail below, thereby generating full-channel measurement results.
[0063] Regarding embodiments and definitions, refer to the definitions and embodiments given in relation to the method for configuration management according to the present invention (such as any of the embodiments disclosed with respect to the above method and / or any of the embodiments further detailed below).
[0064] As used herein, the term "providing at least one measurement result" is a broad term and should be given a meaning common and customary to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, performing at least one measurement with the analysis unit and / or retrieving at least one measurement result from a database (e.g., a database of the analysis unit).
[0065] This method may include correlating measurement results with additional information obtained from at least one other internal sensor and / or at least one other external sensor. The method may also include correlating measurement results with at least one additional environmental readout. The additional environmental readout may include one or more of current, voltage, temperature, pressure, humidity, light conditions, etc. This readout may be provided by sensors that are part of the analysis unit, for example, and may exist on the analysis unit as a log file, and / or may also include data from sensors located close to the analysis unit. This reading can be used to weight component usage, such as different climatic conditions. This reading can be used to identify potential out-of-specification usage, such as the effect of different temperatures on pipetting performance. For example, additional information may be retrieved from a remote central database. For example, the additional information may include information about one or more of the following: components, various sensors, overall device efficiency, and information from a fault indication system.
[0066] This method may include correlating measurement results with additional information obtained through advanced analysis, such as using internal sensor storage and / or advanced sensor interpretation.
[0067] As used herein, the term "control unit" is a broad term and should be given a common and conventional meaning to those skilled in the art, and should not be limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, any unit configured to perform a specified operation, preferably by means of at least one data processing device, and more preferably by means of at least one processor and / or at least one application-specific integrated circuit (ASIC). Thus, by way of example, at least one control unit may include at least one data processing device having software code stored thereon, the software code comprising a plurality of computer commands. The control unit may provide one or more hardware elements for performing one or more specified operations, and / or may provide software running thereon to one or more processors for performing one or more specified operations. The control unit may include one or more programmable devices, such as one or more computers, application-specific integrated circuits (ASICs), digital signal processors (DSPs), or field-programmable gate arrays (FPGAs), configured to perform control functions. The control unit may include at least one computer. The computer may be an embedded computer, such as a microcontroller or a programmable logic device such as an FPGA. However, additionally or alternatively, the control unit may also be implemented entirely or partially in hardware.
[0068] As used herein, the term "association" is a broad term and should be given a meaning that is common and customary to those skilled in the art, and is not limited to a specific or customary meaning. Specifically, the term may refer to, but is not limited to, combining, connecting, fusing, attaching, aggregating measurement results and security information items, or more of them. For example, configuration information may be stored on a single memory device, while measurement results are received, processed, and stored on a detector unit. A core unit may request two separate pieces of information, combine them, and send them to an external device.
[0069] As used herein, the term "channel" is a broad term and should be given a common and customary meaning to those skilled in the art, and is not limited to a specific or customary meaning. The term may specifically refer to, but is not limited to, a source of information. An analysis unit may provide a channel called a measurement channel. Information items relating to the configuration of the analysis unit may be provided by at least one channel other than the measurement channel. Information items relating to the configuration of the analysis unit may be provided by at least one channel designed for performing the method for configuration management according to the present invention. A channel other than the measurement channel may include at least one data source selected from the group consisting of: at least one database (such as a remote central database or a database of a laboratory analysis system), log files, at least one input from a service client or maintenance technician via a service computer, etc. As used herein, the term "full-channel measurement result" is a broad term and should be given a common and customary meaning to those skilled in the art, and should not be limited to a specific or customary meaning. The term may specifically refer to, but is not limited to, measurement results provided by a measurement channel that include additional information from at least one other channel.
[0070] The method may include one or more of the following: transmitting full-channel measurement results to at least one other device, recording and / or storing and / or post-processing full-channel measurement results in at least one database, performing at least one maintenance operation based on the full-channel measurement results, and further analyzing the full-channel measurement results, such as for weighting and / or verifying the measurement results for component use and / or confirming potential out-of-specification use.
[0071] This invention allows for the creation of associations between each measurement result and the analysis unit configuration. For example, measurement results may include at least information about the materials used, such as the measurement batch, consumable batch, software version, etc., and / or detailed diagnostic analyzer hardware configurations, such as instrument ID, operator or maintenance technician, defined maintenance / repair operation protocols, location, spare part UID, timestamp, and location. By using cryptographic technologies such as blockchain, certificate-public / private keys, hash codes, etc., to ensure secure data transmission and immutable and permanent storage, measurement results can be securely associated with the aforementioned additional information. This allows for improved maintainability of laboratory analytical systems through the use of configuration management and spare part analysis supported by advanced empirical data.
[0072] This invention offers the following advantages: It ensures complete traceability and logging of all information contributing to patient outcomes. Compliance with regulatory requirements (medical devices) is possible. Full-channel measurement results ensure a higher standard of patient outcome safety. Faster maintainability in the field (system status known) can be ensured, and improved preventative maintenance procedures can be defined. Performing only necessary maintenance to the required extent (i.e., dynamic maintenance) may be possible, for example, by breaking down and / or defining maintenance procedures based on individual usage and / or status (such as combinations of different counters and / or the status of components used in this operation, such as variations in acid concentration used for cleaning to the necessary amount without overdoing it, to extend system life). Predictive maintenance automatically orders spare parts for the expected end of their lifespan until the next maintenance visit, thereby extending instrument uptime. Internal instrument technology and logs can be protected from third-party access while keeping information available in the field.
[0073] On the other hand, an infrastructure was disclosed. The infrastructure includes... - At least one service computer configured to perform a method for configuration management according to the present invention (such as any of the embodiments disclosed with respect to the above method and / or any of the embodiments disclosed in further detail below); -At least one remote central database; - At least one laboratory analysis system, comprising at least one analysis unit, wherein the analysis unit includes at least one analytical instrument, wherein the laboratory analysis system includes at least one control unit and at least one database, wherein the laboratory analysis system includes at least one communication interface configured to communicate with a remote central database; The infrastructure is configured to use the analysis unit and control unit of the laboratory analysis system to perform a method for generating full-channel measurement results according to the present invention (such as any of the embodiments disclosed with respect to the above method and / or any of the embodiments disclosed in further detail below).
[0074] Regarding embodiments and definitions, refer to the definitions and embodiments given in relation to the methods according to the present invention (such as any of the embodiments disclosed with respect to the methods described above and / or any of the embodiments disclosed in further detail below).
[0075] This document further discloses and proposes a computer program comprising computer-executable instructions for performing, when executed on a computer or computer network, a method for configuration management and / or a method for generating full-channel measurement results according to the invention, in one or more of the embodiments appended herein. Specifically, the computer program may be stored on a computer-readable data carrier and / or a computer-readable storage medium.
[0076] As used herein, the terms "computer-readable data carrier" and "computer-readable storage medium" can specifically refer to non-transitory data storage devices, such as hardware storage media having computer-executable instructions stored thereon. Computer-readable data carriers or storage media can specifically be or can include storage media such as random access memory (RAM) and / or read-only memory (ROM).
[0077] Therefore, specifically, one, more than one, or even all of the method steps indicated above can be performed by using a computer or computer network, preferably by using a computer program.
[0078] This document further discloses and proposes a computer program product having program code means for performing, when executed on a computer or computer network, methods for configuration management and / or methods for generating full-channel measurement results according to the invention, in one or more of the embodiments appended herein. Specifically, the program code tools may be stored on a computer-readable data carrier and / or a computer-readable storage medium.
[0079] This document further discloses and proposes a data carrier having a data structure stored thereon, which, after being loaded into a computer or computer network (such as into the working memory or main memory of the computer or computer network), can execute one or more of the methods for configuration management and / or for generating full-channel measurement results according to the embodiments disclosed herein.
[0080] This document further discloses and proposes a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform methods for configuration management and / or methods for generating full-channel measurement results.
[0081] This document further discloses and proposes a computer program product having program code means stored on a machine-readable medium for performing, when executed on a computer or computer network, one or more methods for configuration management and / or methods for generating full-channel measurement results according to the embodiments disclosed herein. As used herein, a computer program product refers to a program that is a tradable product. The product can generally exist in any format (such as paper format) or reside on a computer-readable data carrier and / or a computer-readable storage medium. Specifically, the computer program product can be distributed on a data network.
[0082] Finally, this document discloses and proposes a modulated data signal containing instructions readable by a computer system or computer network for performing one or more of the methods for configuration management and / or for generating full-channel measurement results according to the embodiments disclosed herein.
[0083] Referring to the computer implementation aspects of the present invention, one or more method steps, or even all method steps, of the methods for configuration management and / or for generating full-channel measurement results according to one or more embodiments disclosed herein can be performed using a computer or computer network. Therefore, in general, any method steps, including providing and / or manipulating data, can be performed using a computer or computer network. Generally, these method steps can include any method steps that typically require manual work, such as providing samples and / or performing certain aspects of actual measurements.
[0084] Specifically, this article further discloses the following: - A computer or computer network comprising at least one processor, wherein the processor is adapted to perform one or both of the methods described in the embodiments of this specification. - A computer-loadable data structure adapted to perform one or both of the methods described in the embodiments of this specification when the data structure is executed on the computer. - A computer program, wherein the computer program is adapted, when executed on a computer, to perform one or both of the methods described in the embodiments of this specification. - A computer program, comprising program means for performing one or both of the methods described in the embodiments of this specification, when executed on a computer or on a computer network. - A computer program, comprising program means according to the foregoing embodiments, wherein the program means is stored on a computer-readable storage medium. - A storage medium, wherein a data structure is stored on the storage medium and wherein the data structure is adapted to be, after being loaded into the main memory and / or working memory of a computer or computer network, to be subjected to one or both of the methods described in one of the embodiments of this specification, and - A computer program product having program code means, wherein the program code means can be stored or stored on a storage medium for performing one or both of the methods described in the embodiments of this specification if the program code means is executed on a computer or a computer network.
[0085] In summary, and without excluding other possible embodiments, the following embodiments are conceivable: Example 1. A computer-implemented method for configuration management of at least one laboratory analytical system including at least one analytical unit, wherein the method includes the following steps: a) Retrieve at least one information item regarding the configuration of at least one analytical unit of the laboratory analytical system; b) Apply at least one cryptographic function to an information item relating to the configuration of the analysis unit, thereby generating a security information item relating to the configuration of the analysis unit; c) Provide the security information items related to the configuration of the analysis unit to at least one database of the laboratory analysis system and / or to at least one remote central database, wherein the remote central database is located at the manufacturer's site and / or cloud database.
[0086] Example 2. According to the method described in the foregoing embodiments, the information items related to the configuration of the analysis unit include information about at least one element selected from the group consisting of: software version; firmware version; hardware configuration; measurement batch, consumable batch; module information; unit information; sub-units of the analysis unit; sub-unit identifier; location information; location of at least one item or spare part; serial number of the item or spare part; batch number; installation date; unique operating identifier; type of analysis unit; operator or maintenance technician; defined maintenance or repair operation protocol; timestamp; location; or dynamic counter.
[0087] Example 3. The method according to any one of the foregoing embodiments, wherein the retrieval in step a) includes providing the information item concerning the configuration of the analysis unit via at least one user input through at least one human-machine interface and / or receiving the information item concerning the configuration of the analysis unit from a database.
[0088] Example 4. The method according to any one of the foregoing embodiments, wherein the method includes using dynamic hashing, wherein additional information is added to the hash generated in step b) and then encrypted to generate a hash value.
[0089] Example 5. The method according to any one of the foregoing embodiments, wherein in step b), the cryptographic function includes at least one cryptographic hash function, and the method includes applying at least one cryptographic hash function to information items related to the configuration of the analysis unit to generate a hash value.
[0090] Example 6. The method according to the foregoing embodiment, wherein step b) includes converting the information item related to the configuration of the analysis unit into at least one data string, converting the data string into bytes, and applying a cryptographic hash function to the bytes to generate a hash value.
[0091] Example 7. The method according to any one of the foregoing two embodiments, wherein the method further includes generating at least one root hash, wherein generating the root hash includes repeating steps a) to b) using other information items configured about the analysis unit, generating other hash values, and aggregating the hash values and the other hash values.
[0092] Example 8. The method according to any one of the foregoing three embodiments, wherein the method further includes generating a blockchain, wherein the method includes generating a plurality of subsequently linked blocks of the blockchain, wherein each block includes a hash of a previous block and a timestamp.
[0093] Example 9. The method according to any one of the foregoing embodiments, wherein the method further comprises providing safety information items related to the configuration of the analysis unit to a laboratory information management system (LIMS), wherein the LIMS is configured to electronically record measurement results generated by the at least one analysis unit of the laboratory analysis system.
[0094] Example 10. The method according to any one of the foregoing embodiments, wherein the security information item is provided in the z segment of the HL7 application layer or the z segment of the system status message.
[0095] Example 11. The method according to any one of the foregoing embodiments, wherein the method includes performing steps a) to c) during the installation of the laboratory system to establish an initial safety information item regarding the configuration of the analytical unit.
[0096] Example 12. The method according to any one of the foregoing embodiments, wherein the method includes at least one maintenance workflow and / or repair workflow, wherein the method includes - Perform at least one repair and / or maintenance operation on at least one analysis unit; - Generate updated information items regarding the configuration of the analysis unit; - Apply the cryptographic function to the update information item about the analysis unit configuration to generate an update security information item about the analysis unit configuration; - Provide updated safety information items related to the configuration of the analysis unit to the database of the laboratory analysis system and the remote central database.
[0097] Example 13. The method according to any one of the foregoing embodiments, wherein the method includes an integrity test, wherein the integrity test includes retrieving actual security information items related to the configuration of the analysis unit stored in the database of the laboratory analysis system and actual security information items related to the configuration of the analysis unit stored in the remote central database, wherein the integrity test includes comparing the actual security information items related to the configuration of the analysis unit stored in the database of the laboratory analysis system and the actual security information items related to the configuration of the analysis unit stored in the remote central database, wherein if the actual security information items related to the configuration of the analysis unit stored in the database of the laboratory analysis system and the actual security information items related to the configuration of the analysis unit stored in the remote central database are different, the integrity test fails; otherwise, the integrity test passes.
[0098] Example 14. The method according to any one of the preceding embodiments, wherein the method is repeated upon subsequent changes and / or at other predefined times to generate an updated security information item regarding the configuration of the analysis unit, wherein step c) includes replacing the security information item regarding the configuration of the analysis unit with the updated information item regarding the configuration of the analysis unit in the database of the laboratory analysis system, and providing the updated information item regarding the configuration of the analysis unit to the remote central database.
[0099] Example 15. The method according to any one of the preceding embodiments, wherein step a) includes retrieving at least one information item about general data, such as one or more of a timestamp, sample unique identifier, system unique identifier, system configuration unique identifier, one-way function, or location.
[0100] Example 16. The method according to any one of the foregoing embodiments, wherein step a) includes retrieving at least one information item about the system configuration, such as information about at least one analytical unit (e.g., a unique identifier), by combining information about reagents and consumables (e.g., information about reagents (such as batch and / or unique identifiers) and information about consumables (such as batch and / or unique identifiers)).
[0101] Example 17. A computer-implemented method for generating full-channel measurement results for at least one laboratory analysis system, wherein the method includes the following steps: i) Provide at least one measurement result generated by at least one analytical unit of the laboratory analysis system; ii) The full-channel measurement results are generated by associating the measurement results with a safety information item relating to the configuration of the analysis unit generated by performing the configuration management method according to any one of the foregoing embodiments using at least one control unit of the laboratory analysis system.
[0102] Example 18. The method according to the foregoing embodiments, wherein the method includes associating the measurement result with at least one additional environmental readout, wherein the additional environmental readout includes one or more of current, voltage, temperature, pressure, humidity, light conditions, etc.
[0103] Example 19. The method according to any one of the foregoing embodiments, wherein the method comprises one or more of the following: transmitting the full-channel measurement results to at least one other device, recording and / or storing and / or post-processing the full-channel measurement results in at least one database, performing at least one maintenance operation based on the full-channel measurement results, and further analyzing the full-channel measurement results, such as for weighting the use of components and / or verifying the measurement results and / or confirming potential out-of-specification use.
[0104] Example 20. An infrastructure comprising - At least one service computer configured to perform the method according to any one of embodiments 1 to 16; -At least one remote central database; - At least one laboratory analysis system, comprising at least one analysis unit, wherein the analysis unit includes at least one analytical instrument, wherein the laboratory analysis system includes at least one control unit and at least one database, wherein the laboratory analysis system includes at least one communication interface configured to communicate with a remote central database; The infrastructure is configured to perform the method according to any one of Examples 17 to 19 using the analysis unit and control unit of the laboratory analysis system.
[0105] Example 21. A computer program comprising instructions that, when executed by a processing unit such as a service computer, cause the processing unit to perform the method according to any one of Examples 1 to 16.
[0106] Example 22. A computer-readable storage medium comprising instructions that, when executed by a processing unit such as a service computer, cause the processing unit to perform the method according to any one of Examples 1 to 16.
[0107] Example 23. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of Examples 1 to 16.
[0108] Example 24. A computer program comprising instructions that, when the program is executed by an infrastructure according to any of the preceding embodiments relating to the infrastructure, cause the infrastructure to perform the method according to any one of Examples 17 to 19.
[0109] Example 25. A computer-readable storage medium comprising instructions that, when executed by an infrastructure according to any of the preceding embodiments relating to an infrastructure, cause the infrastructure to perform a method according to any one of Examples 17 to 19.
[0110] Example 26. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of Examples 17 to 19. Attached Figure Description
[0111] Other optional features and embodiments will be disclosed in more detail in the following description of embodiments, in conjunction with the dependent claims. As those skilled in the art will recognize, each optional feature can be implemented individually and in any feasible combination. The scope of the invention is not limited to the preferred embodiments. Embodiments are schematically depicted in the accompanying drawings. In these drawings, the same reference numerals refer to the same or functionally equivalent elements.
[0112] In the attached diagram: Figure 1 shows an overview of the infrastructure; Figure 2 shows a flowchart of an exemplary embodiment of the method for configuration management; Figure 3 shows a flowchart outlining the workflow for configuration management methods; Figure 4 illustrates an embodiment of step a) of a method for retrieving information items related to the configuration of the analysis unit; Figure 5 illustrates an embodiment of the method for generating full-channel measurement results; and Figure 6 illustrates an embodiment of the analysis unit configuration. Detailed Implementation
[0113] Figure 1 An overview of infrastructure 110 is shown. Infrastructure 110 includes at least one service computer 112 configured to perform a computer implementation method for configuration management of at least one laboratory analysis system 114.
[0114] Laboratory analysis system 114 can be configured for in vitro diagnostics (IVD), for example, laboratory analysis system 114 can be configured to perform in vitro examination of at least one sample derived from the human body, and / or be configured to provide information for diagnostic, monitoring, or compatibility purposes. Laboratory analysis system 114 can be or can include automated laboratory systems configured to automatically or semi-automatically process multiple samples, specifically large numbers of samples. As an example, laboratory analysis system 114 can be or can include automated laboratory analyzers. Laboratory analysis system 114 can specifically be used in the fields of medical laboratories (such as clinical laboratories or forensic laboratories) and / or chemical laboratories (such as analytical laboratories). Laboratory analysis system 114 includes at least one analytical unit (AU) 116, for example, a plurality (n) of analytical units 116 (n ≥ 1). For example, analytical unit 116 can include at least one quality analyzer. Samples can be from any biological source, such as physiological fluids including blood, saliva, lens fluid, cerebrospinal fluid, sweat, urine, milk, ascites, mucus, synovial fluid, peritoneal fluid, amniotic fluid, tissue, cells, etc. The sample can be pretreated before use, such as preparing plasma from blood, diluting viscous liquids, lysing, etc.; processing methods may involve filtration, distillation, concentration, inactivation of interfering components, and addition of reagents. The laboratory analytical system 114 may include other units and other laboratory instruments, such as pre-analytical instruments, post-analytical instruments, and / or analytical instruments.
[0115] Infrastructure 110 further includes at least one remote central database 118. The remote central database 118 may be external to the laboratory analysis system 114. For example, the remote central database 118 may be located at a manufacturer's site and / or cloud database. The laboratory analysis system 114, the service computer 112, and the remote central database 118 form a communication network 124, wherein the laboratory analysis system 114, the service computer 112, and the remote central database 118 are nodes of the communication network 124. The remote central database 118 may be configured to communicate with all participants in the communication network 124. For example, the remote central database 118 may be configured to communicate with the laboratory analysis system 114 and the service computer 112, for example, via WAN communication.
[0116] As shown in Figure 1, the laboratory analysis system 114 includes at least one control unit 120 and at least one database 122. The laboratory analysis system 114 may include a laboratory information management system (LIMS) 126. The LIMS 126 may be configured to electronically record measurement results generated by at least one analysis unit 116. The laboratory analysis system 114 may include an internal communication network 128 configured for communication between components of the laboratory analysis system 114, such as communication between the analysis unit 116, control unit 120, and database 122, for example via a LAN. The laboratory analysis system 114 includes at least one communication interface configured to communicate with a remote central database 118. For example, as... Figure 1 As shown, the laboratory analysis system 114 can communicate with the remote central database 118 via LIMS 126.
[0117] Figure 2 shows a flowchart of an exemplary embodiment of a configuration management method performed by infrastructure 110 as shown in Figure 1. The configuration management method utilizes at least one cryptographic function to record the configuration and history of the analysis unit 116. In Figure 2, exemplarily, the method steps are divided into steps performed by the analysis unit 116 and the service computer 112. A workflow overview from the perspective of a maintenance technician or field system engineer (FSE) is shown.
[0118] In the first step, such as during instrument installation, the instrument's unique identifier can be defined by the manufacturer. Additionally, an initial analysis unit configuration can be generated, including information such as location, unique identifier (UID), timestamp, and information about the FSE. For example, as shown in Figure 2, the initial analysis unit configuration includes information about three (spare) components at locations 1 to 3 with UIDs "123", "234", and "789", the software (SW1) at location 4, and the firmware (firmware 2) at location 5, as well as information about the three FSEs involved. An initial hash ("unique initial hash on the instrument") can be established by applying a cryptographic hash function (e.g., SHA 256) to the information items related to the analysis unit configuration. For example, the initial hash in Figure 2 is "dwcua1n3h53m". The initial hash can be stored in database 122.
[0119] For example, as part of a maintenance and / or repair workflow, FSE “m” may change a component of analysis unit 116 at some point, such as a component at location x. This could involve changing the analysis unit configuration in the log, generating a hash value based on this action, such as “63nnlg2cko4m”. This hash value, along with the last available hash from database 122 (e.g., “3mk37xp2asd”), is used to create an update hash. Changes on the system are stored on analysis unit 116, for example, within the log. Therefore, each change obtains a unique hash based at least on the timestamp, instrument ID, operation description, and last available hash. Additionally, the hash is stored at a remote central database 118. Any changes on analysis unit 116 will destroy the hash and be revealed by meaningless log entries.
[0120] For example, as shown in Figure 1, hashes can be provided according to standards used for the electronic exchange of one or more medical, administrative, and financial data between healthcare information systems. For instance, hashes can be provided in z-segments of Health Level (HL) 7 application layers or in z-segments of system status messages. Typically, HL7 segments include MSH (message header), PID (patient information), NK1 (close relatives), and PV1 (patient visits). Various healthcare-related information can be communicated to a wide variety of different systems via HL7 messages. Sometimes HL7 messages need to contain custom data that cannot be included in any of the defined segments for their message type. To accommodate this, the HL7 standard allows system vendors to create z-segments with custom fields to transmit this data. At least one of these custom fields can be used for hashing, for example, as a string. Z-segments can be placed anywhere in an HL7 message, but are typically the last segment in the message.
[0121] As shown in Figure 1, the service computer 112 can generate system configuration updates and transmit them to the analysis unit 116. The service computer 112 can receive the analysis unit configuration, represented as "system configuration data" in Figure 1. The service computer 112 can receive stored system configuration data and libraries from the remote central database 118. The service computer 112 can send system configuration updates to the remote central database 118. The analysis unit 116 can send HL7 messages (including HL7 and Z-segment result messages) in response to commands from the LIMS 126. The LIMS 126 can provide the result messages to the remote central database 118.
[0122] Figure 3 illustrates a flowchart outlining a repair / maintenance workflow performed by an FSE or operator. For example, an FSE visits a customer to perform maintenance. First, the workflow may include step a) of a configuration management method, retrieving at least one information item regarding the configuration of at least one analysis unit 116 of the laboratory analysis system 114. The service computer 112 may receive a current operations library from a remote central database 118, which includes potential operations on the analysis unit 116. Additionally, a latest hash (hash 1) may be transmitted from the remote central database 118 to the service computer 112, and a latest hash may be transmitted from the analysis unit 116 to the service computer 112. This method may include an integrity test, where hash 1 from the remote central database 118 is compared with the latest hash from the analysis unit 116. If the two hashes are different, the FSE may be notified. If the two hashes are the same, the FSE may select the operation to be performed on the analysis unit 116, for example, via a user interface (e.g., a GUI and service software). For example, the operation performed on the analysis unit 116 is selected as the operation template. For example, operations on analysis unit 116 may include replacing old spare parts and installing new spare parts. Operations on analysis unit 116 may include updating the accumulated log with the new spare part, installation date, and serial number. A unique operation identifier (abbreviated as operation ID) can be created externally by the FSE, and this unique operation identifier can be an entry for information items related to the analysis unit configuration. An example of creating an operation ID is shown in Figure 4. The FSE can input additional information into service computer 112, such as additional metadata, such as timestamps, operator comments, and observations. Old spare parts can be replaced locally, and the fate of spare parts can be saved and / or updated externally. The installation of a new spare part may cause a counter reset.
[0123] Optionally, service computer 112 checks whether the defined operation affects the version (hardware or software). If not, the workflow can continue creating hash values, as described below. If so, the version may change. Service computer 112 can check whether the operation is related to the hardware or software version and can change it based on checking the hardware number or software number (or both), and increment it based on the version number. Additionally, service computer 112 can check whether the branch is related and can increment the branch number.
[0124] Next, the workflow may include step b) of a method for configuration management, which includes applying at least one cryptographic function to an information item (in this embodiment, an operation ID) related to the analysis unit configuration, thereby generating a security information item related to the analysis unit configuration. Specifically, for example, a hash value (hash2) may be created based on a unique operation ID and / or an encrypted operation ID.
[0125] Next, the workflow may include step c) of the configuration management method, which includes providing security information items related to the analysis unit configuration to database 122 and / or to remote central database 118. As shown in Figure 3, there may be three options to proceed.
[0126] For example, as indicated by the left arrow, the next activity could include 1) completing the file transfer to the remote central database 118, and 2) updating the analysis unit configuration in the form of hash 2. Next, verification and validation can be performed using metadata and include checking if the hash values match, for example, if they are as expected. If the updated configuration matches as expected, the FSE is notified.
[0127] For example, as indicated by the middle arrow, the next activity could include checking if the updated configuration is as expected. If the updated configuration is as expected, the FSE is notified.
[0128] For example, as indicated by the right arrow, the next activity could include updating the analysis unit configuration in database 122 as hash 2. Next, hash 2 can be resent to service computer 112, and the updated configuration can be checked to ensure it is as expected. If the updated configuration is as expected, the FSE is notified.
[0129] Figure 4 illustrates an example of creating an operation ID.
[0130] Potential operations that can be performed by the service client can be defined by basic definitions. Basic definitions may include information about one or more of the following: instrument type, manual or documentation record, operating version, procedure, impact on version control (Boolean value), location, and item. Basic definitions can be provided to the FSE in the form of operating templates from which the service client can select.
[0131] The service client can select one of the operation definitions via the service computer 116. Additionally, the service client can create a unique ID, make configuration changes, and optionally perform version changes. Furthermore, the service client can input additional information such as one or more of the following via the service computer 116: information about technicians, time periods, comments, and observations.
[0132] Analysis unit 116 may, for example, store a unique ID (such as one generated by the service client) in database 122. Analysis unit 116 may undergo configuration changes (such as those performed by the service client). Configuration changes may be defined by one or more of location, item or spare part, and installation date. Configuration changes may include resetting counters. Configuration changes may include version changes (such as those indicated by the service client).
[0133] Operation IDs can be created by two token gateways and / or blockchains, such as via service clients and tools.
[0134] Operation IDs can be transmitted to a remote central database 118 for central storage. Additional information from database 122 or service computer 112 can be transmitted to the remote central database 118 for central storage.
[0135] The remote central database 118 can provide information, for example, about the configuration of the analysis unit to other entities (such as warehouse server 132, which provides information to warehouse 130). Warehouse 130 can be, for example, a physical and / or digital warehouse that combines instruments and items and / or spare parts. Warehouse 130 can be configured to provide information related to one or more of the following: storage location, delivery date, and tags, to warehouse server 132. This information can be stored in a spare parts log.
[0136] Figure 5 illustrates an embodiment of a method for generating full-channel measurement results 134 for a laboratory analysis system 114. The method includes step i) 136, which includes providing at least one measurement result 138 generated by the analysis unit 116, for example, performing at least one measurement. The analysis unit 116 may provide channels referred to as measurement channels. The analysis unit 116 in Figure 5 may include at least one module 140 having at least one subunit 142. The database 122 may include one or more of the following: configuration information, such as location, spare parts, date, counters, and information items related to the configuration of the analysis unit (e.g., operation ID).
[0137] The method further includes step ii), which includes generating a full-channel measurement result 136 by associating the measurement result 138 with a security information item relating to the configuration of the analysis unit generated by performing a configuration management method according to the invention (e.g., as described with respect to Figures 1 to 4). The association may include combining, connecting, fusing, attaching, or aggregating one or more of the measurement result 138 and the security information item.
[0138] Information about the analysis unit configuration can be provided by at least one channel other than the measurement channel. For example, information about the analysis unit configuration can be retrieved from database 122.
[0139] The method may include associating the measurement result 138 with additional information obtained from at least one other internal sensor and / or at least one other external sensor. For example, the method may include associating the measurement result with at least one additional environmental readout. The additional environmental readout includes one or more of current, voltage, temperature, pressure, humidity, light conditions, etc. For example, additional information may be retrieved from a remote central database 118. For example, the additional information may include information about one or more of the following: components, various sensors, overall equipment efficiency, and information from a fault indication system.
[0140] The method may include correlating the measurement result 138 with additional information obtained through advanced analysis 144, such as using internal sensor storage and / or advanced sensor interpretation.
[0141] Figure 6 illustrates an embodiment of the analysis unit configuration 146. The analysis unit configuration 146 may contain information about location 148. This location may relate to a defined set of potential locations. This location may define a unique location with analysis unit 116. Some locations may even be restricted to certain items or spare parts. Each location is used only for a single item or spare part. Duplication is not allowed.
[0142] The analysis unit configuration 146 may include information about the item or spare part 150, such as item number, available location, available spare part, serial number or batch number, or additional information, or more.
[0143] Therefore, the resulting analysis unit configuration 146 may include information about location 148, information about item or spare part 150, operation ID, timestamp, and counters. The counters may be classic events, such as switching events, injections, etc., or computational events, such as the amount of organic solvent or cumulative acid content.
[0144] List of reference numerals .
Claims
1. A computer-implemented method for configuration management of at least one laboratory analysis system (114) including at least one analysis unit (116), wherein the method includes the following steps: a) Retrieve at least one information item relating to the configuration of at least one analysis unit (116) of the laboratory analysis system (114); b) Applying at least one cryptographic function to an information item relating to the configuration of the analysis unit to generate a security information item relating to the configuration of the analysis unit, wherein the cryptographic function includes at least one cryptographic hash function, wherein the method includes applying the cryptographic hash function to the information item relating to the configuration of the analysis unit to generate a hash value, wherein the method uses dynamic hashing, wherein additional information is added to the generated hash value, and subsequently encrypted by applying the cryptographic function or other cryptographic functions to generate the hash value; c) Providing the security information items related to the configuration of the analysis unit to at least one database (122) of the laboratory analysis system (114) and / or to at least one remote central database (118), wherein the remote central database (118) is located at the manufacturer's site and / or cloud database.
2. The method according to the preceding claims, wherein the information item relating to the configuration of the analysis unit includes information about at least one element selected from the group consisting of: software version; firmware version; hardware configuration; measurement batch, consumable batch; module information; unit information; sub-units of the analysis unit (116); sub-unit identifier; location information; location of at least one item or spare part; serial number of the item or spare part; batch number; installation date; unique operating identifier; type of analysis unit (116); operator or maintenance technician; defined maintenance or repair operation protocol; timestamp; location; or dynamic counter.
3. The method according to any one of the preceding claims, wherein the method further comprises generating a blockchain, wherein the method comprises generating a plurality of subsequently linked blocks of the blockchain, wherein each block includes a hash of a previous block and a timestamp.
4. The method according to any one of the preceding claims, wherein the security information item is provided in the z segment of the HL7 application layer or the z segment of the system status message.
5. The method according to any one of the preceding claims, wherein the method comprises at least one maintenance workflow and / or repair workflow, wherein the method includes - Perform at least one repair and / or maintenance operation on the at least one analysis unit (116); - Generate updated information items regarding the configuration of the analysis unit; - The cryptographic function is applied to the update information item of the relevant analysis unit configuration to generate an update security information item of the relevant analysis unit configuration; - Provide the updated security information items related to the configuration of the analysis unit to the database (122) of the laboratory analysis system (114) and to the remote central database (118).
6. The method according to any one of the preceding claims, wherein the method includes an integrity test, wherein the integrity test includes retrieving actual security information items related to the configuration of the analysis unit stored in the database (122) of the laboratory analysis system (114) and the actual security information items related to the configuration of the analysis unit stored in the remote central database (118), wherein the integrity test includes comparing the actual security information items related to the configuration of the analysis unit stored in the database (122) of the laboratory analysis system (114) and the actual security information items related to the configuration of the analysis unit stored in the remote central database (118), wherein if the actual security information items related to the configuration of the analysis unit stored in the database (122) of the laboratory analysis system (114) and the actual security information items related to the configuration of the analysis unit stored in the remote central database (118) are different, the integrity test fails; otherwise, the integrity test passes.
7. The method according to any one of the preceding claims, wherein the method is repeated upon subsequent changes and / or at other predefined times to generate an updated safety information item regarding the configuration of the analysis unit, wherein step c) includes replacing the safety information item regarding the configuration of the analysis unit in the database (122) of the laboratory analysis system (114) with the updated information item regarding the configuration of the analysis unit, and providing the updated information item regarding the configuration of the analysis unit to the remote central database (118).
8. A computer-implemented method for generating full-channel measurement results (134) of at least one laboratory analysis system (114), wherein the method comprises the following steps: i) Provide at least one measurement result (138) generated by at least one analysis unit (116) of the laboratory analysis system (114); ii) The full-channel measurement result (134) is generated by associating the measurement result (138) with a safety information item relating to the configuration of the analysis unit generated by performing the configuration management method according to any one of the preceding claims using at least one control unit (120) of the laboratory analysis system (114).
9. An infrastructure (110) comprising: - At least one service computer (112) configured to perform the method according to any one of claims 1 to 7; -At least one remote central database (118); - At least one laboratory analysis system (114) including at least one analysis unit (116), wherein the analysis unit (116) includes at least one analytical instrument, wherein the laboratory analysis system (114) includes at least one control unit (120) and at least one database (122), wherein the laboratory analysis system (114) includes at least one communication interface configured to communicate with the remote central database (118); The infrastructure (110) is configured to use the analysis unit (116) and the control unit (120) of the laboratory analysis system (114) to perform the method according to claim 8.
10. A computer program comprising instructions that, when executed by a processing unit such as a service computer, cause the processing unit to perform the method according to any one of claims 1 to 7 and / or the method according to any one of claims 8.
11. A computer-readable storage medium comprising instructions that, when executed by a processing unit such as a service computer, cause the processing unit to perform the method according to any one of claims 1 to 7 and / or the method according to any one of claims 8.
12. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of claims 1 to 7 and / or the method according to any one of claims 8.