SPATIAL AWARENESS OF SURGICAL DEVICES IN OPERATING ROOMS
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- ETHICON INC
- Filing Date
- 2018-09-11
- Publication Date
- 2026-07-15
AI Technical Summary
Existing surgical systems face challenges in managing the integration and communication of various surgical devices and systems within a sterile field, leading to inefficiencies and potential disruptions during procedures due to entanglement of power, data, and fluid lines, as well as limitations in real-time data processing and visualization across sterile and non-sterile fields.
A modular surgical hub system that integrates a unified environment for power, data, and fluid management, enabling seamless communication and interaction between different surgical devices, including a combo generator module, smoke evacuation, and suction/irrigation modules, while facilitating real-time data transfer and visualization across sterile and non-sterile fields through a cloud-based system.
Enhances surgical efficiency by reducing entanglement issues, allowing for quick module replacement and real-time data processing, and improving surgical outcomes through advanced visualization and cloud-based analytics.
Description
BACKGROUND
[0001] The present disclosure relates to various surgical systems. Surgical procedures are typically performed in surgical operating theaters or rooms in a healthcare facility such as, for example, a hospital. A sterile field is typically created around the patient. The sterile field may include the scrubbed team members, who are properly attired, and all furniture and fixtures in the area. Various surgical devices and systems are utilized in performance of a surgical procedure.
[0002] EP 3056923 A1 describes a scanning arrangement and a method for scanning an object, wherein a satellite computer located in the field is assigned to a laser scanner, via which the registration and / or evaluation of the scans in the field takes place. US 2017 / 347979 A1 describes a method and device for motion control of a mobile medical device. According to the document, collision-free movement of a mobile medical device, such as a mobile medical imaging device, in a room is controlled via a man-machine interface. A model of the room environment is created and displayed, together an actual position of the medical device. The room model and the actual position are based at least in part on real-time sensor data. A destination position for the medical device is entered, the entered destination position is displayed and a collision-free movement path is generated from the actual position to the destination position. The movement path is displayed in the room model. A movement command relating to the displayed movement path is entered and the medical device is driven along the entered movement path from the actual position to the destination position.
[0003] WO 2017 / 189317 A1 describes a telerobotic surgery system for remote surgeon training which may include a robotic surgery station at a first location in a first structure at a first geographic point. Harvested animated animal tissue is at the robotic surgery station and includes harvested animal tissue, and at least one animating device coupled thereto. A remote surgeon trainee station at a second location in a second structure at a second geographic point is remote from the first geographic point. A remote surgeon instructor station may also be included. A communications network couples the stations so that a trainee surgeon at the remote surgeon trainee station is able to remotely train by performing surgery on the harvested animated animal tissue at said robotic surgery station, and while an instructor surgeon at the remote surgeon instructor station is able to remotely instruct the trainee surgeon by also performing surgery. US 2015 / 163748 A1 describes a first Bluetooth-enabled device which includes an interface controller that determines proximity between a first Bluetooth module and a second Bluetooth module of a second Bluetooth-enabled device, and controls transitions, based on the proximity between the first Bluetooth module and the second Bluetooth module, between a first set of operating states of a classical Bluetooth interface of the first Bluetooth module that include an enabled state and a disabled state.
[0004] US 2017 / 172412 A1 describes a system which comprises a storage device, a piece of medical equipment, a portable computing device, and a hub portal. The piece of medical equipment has at least one electrically powered feature and comprises either a medical examination table or a storage cabinet. The storage device is operable to store data and is remotely located relative to the first piece of medical equipment and relative to the portable computing device. The hub portal is operable to provide communication of one or both of data or commands between the storage device, the piece of medical equipment, and the portable computing device. A method includes enablement or activation of an electrically powered feature of medical equipment upon entry of a portable computing device into a medical examination room. The method also includes disablement or further activation of the electrically powered feature upon exit of the portable computing device from the medical examination room.SUMMARY
[0005] In one general aspect, a surgical hub according to claim 1 is provided.
[0006] In another general aspect, a computer-readable medium according to claim 7 is provided.FIGURES
[0007] The features of various aspects are set forth with particularity in the appended claims. The various aspects, however, both as to organization and methods of operation, together with further objects and advantages thereof, may best be understood by reference to the following description, taken in conjunction with the accompanying drawings as follows. FIG. 1 is a block diagram of a computer-implemented interactive surgical system. FIG. 2 is a surgical system being used to perform a surgical procedure in an operating room. FIG. 3 is a surgical hub paired with a visualization system, a robotic system, and an intelligent instrument. FIG. 4 is a partial perspective view of a surgical hub enclosure, and of a combo generator module slidably receivable in a drawer of the surgical hub enclosure. FIG. 5 is a perspective view of a combo generator module with bipolar, ultrasonic, and monopolar contacts and a smoke evacuation component. FIG. 6 illustrates individual power bus attachments for a plurality of lateral docking ports of a lateral modular housing configured to receive a plurality of modules. FIG. 7 illustrates a vertical modular housing configured to receive a plurality of modules. FIG. 8 illustrates a surgical data network comprising a modular communication hub configured to connect modular devices located in one or more operating theaters of a healthcare facility, or any room in a healthcare facility specially equipped for surgical operations, to the cloud. FIG. 9 illustrates a computer-implemented interactive surgical system. FIG. 10 illustrates a surgical hub comprising a plurality of modules coupled to the modular control tower. FIG. 11 illustrates one aspect of a Universal Serial Bus (USB) network hub device. FIG. 12 illustrates a logic diagram of a control system of a surgical instrument or tool. FIG. 13 illustrates a control circuit configured to control aspects of the surgical instrument or tool. FIG. 14 illustrates a combinational logic circuit configured to control aspects of the surgical instrument or tool. FIG. 15 illustrates a sequential logic circuit configured to control aspects of the surgical instrument or tool. FIG. 16 illustrates a surgical instrument or tool comprising a plurality of motors which can be activated to perform various functions. FIG. 17 is a schematic diagram of a robotic surgical instrument configured to operate a surgical tool described herein. FIG. 18 illustrates a block diagram of a surgical instrument programmed to control the distal translation of a displacement member. FIG. 19 is a schematic diagram of a surgical instrument configured to control various functions. FIG. 20 is a simplified block diagram of a generator configured to provide inductorless tuning, among other benefits. FIG. 21 illustrates an example of a generator, which is one form of the generator of FIG. 20. FIG. 22 illustrates a combination generator. FIG. 23 illustrates a method of capturing data from a combination generator and communicating the captured generator data to a cloud-based system. FIG. 24 illustrates a data packet of combination generator data. FIG. 25 illustrates an encryption algorithm. FIG. 26 illustrates another encryption algorithm. FIG. 27 illustrates yet another encryption algorithm. FIG. 28 illustrates a high-level representation of a datagram. FIG. 29 illustrates a more detailed representation of the datagram of FIG. 28. FIG. 30 illustrates another representation of the datagram of FIG. 28. FIG. 31 illustrates a method of identifying surgical data associated with a failure event and communicating the identified surgical data to a cloud-based system on a prioritized basis. FIG. 32 illustrates yet another representation of the datagram of FIG. 28. FIG. 33 illustrates a partial artificial timeline of a surgical procedure performed in an operating room via a surgical system according to the invention. FIG. 34 illustrates ultrasonic pinging of an operating room wall to determine a distance between a surgical hub according to the invention and the operating room wall. FIG. 35 is a logic flow diagram of a process depicting a control program or a logic configuration for surgical hub of the invention pairing with surgical devices of a surgical system that are located within the bounds of an operating room. FIG. 36 is a logic flow diagram of a process, that may be performed by a surgical hub of the invention, depicting a control program or a logic configuration for selectively forming and severing connections between devices of a surgical system. FIG. 37 is a logic flow diagram of a process, that may be performed by a surgical hub of the invention, depicting a control program or a logic configuration for selectively reevaluating the bounds of an operating room after detecting a new device. FIG. 38 is a logic flow diagram of a process, that may be performed by a surgical hub of the invention, depicting a control program or a logic configuration for selectively reevaluating the bounds of an operating room after disconnection of a paired device. FIG. 39 is a logic flow diagram of a process, that may be performed by a surgical hub of the invention, depicting a control program or a logic configuration for reevaluating the bounds of an operating room by a surgical hub after detecting a change in the position of the surgical hub. FIG. 40 is a logic flow diagram of a process, that may be performed by a surgical hub of the invention, depicting a control program or a logic configuration for selectively forming connections between devices of a surgical system. FIG. 41 is a logic flow diagram of a process, that may be performed by a surgical hub of the invention, depicting a control program or a logic configuration for selectively forming and severing connections between devices of a surgical system. FIG. 42 illustrates a surgical hub of the invention pairing a first device and a second device of a surgical system in an operating room. FIG. 43 illustrates a surgical hub of the invention unpairing a first device and a second device of a surgical system in an operating room, and pairing the first device with a third device in the operating room. FIG. 44 is a logic flow diagram of a process, that may be performed by a surgical hub of the invention, depicting a control program or a logic configuration for forming an severing connections between devices of a surgical system in an operating room during a surgical procedure based on progression of the steps of the surgical procedure. FIG. 45 is a logic flow diagram of a process depicting a control program or a logic configuration for overlaying information derived from one or more still frames of a livestream of a remote surgical site onto the livestream. FIG. 46 is a logic flow diagram of a process depicting a control program or a logic configuration for differentiating among surgical steps of a surgical procedure. FIG. 47 is a logic flow diagram of a process 3230 depicting a control program or a logic configuration for differentiating among surgical steps of a surgical procedure. FIG. 48 is a logic flow diagram of a process 3240 depicting a control program or a logic configuration for identifying a staple cartridge from information derived from one or more still frames of staples deployed from the staple cartridge into tissue. FIG. 49 is a partial view of a surgical system in an operating room, the surgical system including a surgical hub that has an imaging module in communication with an imaging device at a remote surgical site. FIG. 50 illustrates a partial view of stapled tissue that received a first staple firing and a second staple firing arranged end-to-end. FIG. 51 illustrates three rows of staples deployed on one side of a tissue stapled and cut by a surgical stapler. FIG. 52 illustrates a non-anodized staple and an anodized staple. FIG. 53 is a logic flow diagram of a process depicting a control program or a logic configuration for coordinating a control arrangement between surgical hubs. FIG. 54 illustrates an interaction between two surgical hubs in an operating room. FIG. 55 is a logic flow diagram of a process depicting a control program or a logic configuration for coordinating a control arrangement between surgical hubs. FIG. 56 illustrates an interaction between two surgical hubs in different operating rooms ("OR1" and "OR3"). FIG. 57 illustrates a secondary display in an operating room ("OR3") showing a surgical site in a colorectal procedure. FIG. 58 illustrates a personal interface or tablet in OR1 displaying the surgical site of OR3. FIG. 59 illustrates an expanded view of the surgical site of OR3 displayed on a primary display of OR1. FIG. 60 illustrates a personal interface or tablet displaying a layout of OR1 that shows available displays. FIG. 61 illustrates a recommendation of a transection location of a surgical site of OR3 made by a surgical operator in OR1 via a personal interface or tablet in OR1. FIG. 62 illustrates a timeline depicting situational awareness of a surgical hub. DESCRIPTION
[0008] Before explaining various aspects of surgical devices and generators in detail, it should be noted that the illustrative examples are not limited in application or use to the details of construction and arrangement of parts illustrated in the accompanying drawings and description. The illustrative examples may be implemented or incorporated in other aspects, variations and modifications, and may be practiced or carried out in various ways. Further, unless otherwise indicated, the terms and expressions employed herein have been chosen for the purpose of describing the illustrative examples for the convenience of the reader and are not for the purpose of limitation thereof.
[0009] Referring to FIG. 1, a computer-implemented interactive surgical system 100 includes one or more surgical systems 102 and a cloud-based system (e.g., the cloud 104 that may include a remote server 113 coupled to a storage device 105). Each surgical system 102 includes at least one surgical hub 106 in communication with the cloud 104 that may include a remote server 113. As illustrated in FIG. 1, the surgical system 102 includes a visualization system 108, a robotic system 110, and a handheld intelligent surgical instrument 112, which are configured to communicate with one another and / or the hub 106. The surgical system 102 may include an M number of hubs 106, an N number of visualization systems 108, an O number of robotic systems 110, and a P number of handheld intelligent surgical instruments 112, where M, N, O, and P are integers greater than or equal to one.
[0010] FIG. 3 depicts an example of a surgical system 102 being used to perform a surgical procedure on a patient who is lying down on an operating table 114 in a surgical operating room 116. A robotic system 110 is used in the surgical procedure as a part of the surgical system 102. The robotic system 110 includes a surgeon's console 118, a patient side cart 120 (surgical robot), and a surgical robotic hub 122. The patient side cart 120 manipulates at least one removably coupled surgical tool 117 through a minimally invasive incision in the body of the patient while the surgeon views the surgical site through the surgeon's console 118. An image of the surgical site is obtained by a medical imaging device 124, which is manipulated by the patient side cart 120 to orient the imaging device 124. The robotic hub 122 is used to process the images of the surgical site for subsequent display to the surgeon through the surgeon's console 118.
[0011] Other types of robotic systems can be readily adapted for use with the surgical system 102. Various examples of robotic systems and surgical tools that are suitable for use with the present disclosure are described in U.S. Provisional Patent Application Serial No. 62 / 611,339, titled ROBOT ASSISTED SURGICAL PLATFORM, filed December 28, 2017.
[0012] Various examples of cloud-based analytics that are performed by the cloud 104, and are suitable for use with the present disclosure, are described in U.S. Provisional Patent Application Serial No. 62 / 611,340, titled CLOUD-BASED MEDICAL ANALYTICS, filed December 28, 2017.
[0013] The imaging device 124 includes at least one image sensor and one or more optical components. Suitable image sensors include, but are not limited to, Charge-Coupled Device (CCD) sensors and Complementary Metal-Oxide Semiconductor (CMOS) sensors.
[0014] The optical components of the imaging device 124 include one or more illumination sources and / or one or more lenses. The one or more illumination sources are directed to illuminate portions of the surgical field. The one or more image sensors receive light reflected or refracted from the surgical field, including light reflected or refracted from tissue and / or surgical instruments.
[0015] The one or more illumination sources are configured to radiate electromagnetic energy in the visible spectrum as well as the invisible spectrum. The visible spectrum, sometimes referred to as the optical spectrum or luminous spectrum, is that portion of the electromagnetic spectrum that is visible to (i.e., can be detected by) the human eye and may be referred to as visible light or simply light. A typical human eye will respond to wavelengths in air that are from about 380 nm to about 750 nm.
[0016] The invisible spectrum (i.e., the non-luminous spectrum) is that portion of the electromagnetic spectrum that lies below and above the visible spectrum (i.e., wavelengths below about 380 nm and above about 750 nm). The invisible spectrum is not detectable by the human eye. Wavelengths greater than about 750 nm are longer than the red visible spectrum, and they become invisible infrared (IR), microwave, and radio electromagnetic radiation. Wavelengths less than about 380 nm are shorter than the violet spectrum, and they become invisible ultraviolet, x-ray, and gamma ray electromagnetic radiation.
[0017] The imaging device 124 is configured for use in a minimally invasive procedure. Examples of imaging devices suitable for use with the present disclosure include, but not limited to, an arthroscope, angioscope, bronchoscope, choledochoscope, colonoscope, cytoscope, duodenoscope, enteroscope, esophagogastro-duodenoscope (gastroscope), endoscope, laryngoscope, nasopharyngo-neproscope, sigmoidoscope, thoracoscope, and ureteroscope.
[0018] The imaging device employs multi-spectrum monitoring to discriminate topography and underlying structures. A multi-spectral image is one that captures image data within specific wavelength ranges across the electromagnetic spectrum. The wavelengths are separated by filters or by the use of instruments that are sensitive to particular wavelengths, including light from frequencies beyond the visible light range, e.g., IR and ultraviolet. Spectral imaging can allow extraction of additional information the human eye fails to capture with its receptors for red, green, and blue. The use of multi-spectral imaging is described in greater detail under the heading "Advanced Imaging Acquisition Module" in U.S. Provisional Patent Application Serial No. 62 / 611,341, titled INTERACTIVE SURGICAL PLATFORM, filed December 28, 2017. Multi-spectrum monitoring can be a useful tool in relocating a surgical field after a surgical task is completed to perform one or more of the previously described tests on the treated tissue.
[0019] It is axiomatic that strict sterilization of the operating room and surgical equipment is required during any surgery. The strict hygiene and sterilization conditions required in a "surgical theater," i.e., an operating or treatment room, necessitate the highest possible sterility of all medical devices and equipment. Part of that sterilization process is the need to sterilize anything that comes in contact with the patient or penetrates the sterile field, including the imaging device 124 and its attachments and components. It will be appreciated that the sterile field may be considered a specified area, such as within a tray or on a sterile towel, that is considered free of microorganisms, or the sterile field may be considered an area, immediately around a patient, who has been prepared for a surgical procedure. The sterile field may include the scrubbed team members, who are properly attired, and all furniture and fixtures in the area.
[0020] The visualization system 108 includes one or more imaging sensors, one or more image processing units, one or more storage arrays, and one or more displays that are strategically arranged with respect to the sterile field, as illustrated in FIG. 2. The visualization system 108 includes an interface for HL7, PACS, and EMR. Various components of the visualization system 108 are described under the heading "Advanced Imaging Acquisition Module" in U.S. Provisional Patent Application Serial No. 62 / 611,341, titled INTERACTIVE SURGICAL PLATFORM, filed December 28, 2017.
[0021] As illustrated in FIG. 2, a primary display 119 is positioned in the sterile field to be visible to an operator at the operating table 114. In addition, a visualization tower 111 is positioned outside the sterile field. The visualization tower 111 includes a first non-sterile display 107 and a second non-sterile display 109, which face away from each other. The visualization system 108, guided by the hub 106, is configured to utilize the displays 107, 109, and 119 to coordinate information flow to operators inside and outside the sterile field. For example, the hub 106 may cause the visualization system 108 to display a snap-shot of a surgical site, as recorded by an imaging device 124, on a non-sterile display 107 or 109, while maintaining a live feed of the surgical site on the primary display 119. The snap-shot on the non-sterile display 107 or 109 can permit a non-sterile operator to perform a diagnostic step relevant to the surgical procedure, for example.
[0022] The hub 106 is also configured to route a diagnostic input or feedback entered by a non-sterile operator at the visualization tower 111 to the primary display 119 within the sterile field, where it can be viewed by a sterile operator at the operating table. The input is in the form of a modification to the snap-shot displayed on the non-sterile display 107 or 109, which can be routed to the primary display 119 by the hub 106.
[0023] Referring to FIG. 2, a surgical instrument 112 is being used in the surgical procedure as part of the surgical system 102. The hub 106 is also configured to coordinate information flow to a display of the surgical instrument 112. For example, in U.S. Provisional Patent Application Serial No. 62 / 611,341, titled INTERACTIVE SURGICAL PLATFORM, filed December 28, 2017. A diagnostic input or feedback entered by a non-sterile operator at the visualization tower 111 is routed by the hub 106 to the surgical instrument display 115 within the sterile field, where it is viewed by the operator of the surgical instrument 112. Example surgical instruments that are suitable for use with the surgical system 102 are described under the heading "Surgical Instrument Hardware" and in U.S. Provisional Patent Application Serial No. 62 / 611,341, titled INTERACTIVE SURGICAL PLATFORM, filed December 28, 2017.
[0024] Referring now to FIG. 3, a hub 106 is depicted in communication with a visualization system 108, a robotic system 110, and a handheld intelligent surgical instrument 112. The hub 106 includes a hub display 135, an imaging module 138, a generator module 140, a communication module 130, a processor module 132, and a storage array 134. As illustrated in FIG. 3, the hub 106 further includes a smoke evacuation module 126 and / or a suction / irrigation module 128.
[0025] During a surgical procedure, energy application to tissue, for sealing and / or cutting, is generally associated with smoke evacuation, suction of excess fluid, and / or irrigation of the tissue. Fluid, power, and / or data lines from different sources are often entangled during the surgical procedure. Valuable time can be lost addressing this issue during a surgical procedure. Detangling the lines may necessitate disconnecting the lines from their respective modules, which may require resetting the modules. The hub modular enclosure 136 offers a unified environment for managing the power, data, and fluid lines, which reduces the frequency of entanglement between such lines.
[0026] A surgical hub is used in a surgical procedure that involves energy application to tissue at a surgical site. The surgical hub includes a hub enclosure and a combo generator module slidably receivable in a docking station of the hub enclosure. The docking station includes data and power contacts. The combo generator module includes two or more of an ultrasonic energy generator component, a bipolar RF energy generator component, and a monopolar RF energy generator component that are housed in a single unit. The combo generator module also includes a smoke evacuation component, at least one energy delivery cable for connecting the combo generator module to a surgical instrument, at least one smoke evacuation component configured to evacuate smoke, fluid, and / or particulates generated by the application of therapeutic energy to the tissue, and a fluid line extending from the remote surgical site to the smoke evacuation component.
[0027] The fluid line is a first fluid line and a second fluid line extends from the remote surgical site to a suction and irrigation module slidably received in the hub enclosure. The hub enclosure comprises a fluid interface.
[0028] Certain surgical procedures may require the application of more than one energy type to the tissue. One energy type may be more beneficial for cutting the tissue, while another different energy type may be more beneficial for sealing the tissue. For example, a bipolar generator can be used to seal the tissue while an ultrasonic generator can be used to cut the sealed tissue. A hub modular enclosure 136 is configured to accommodate different generators, and facilitate an interactive communication therebetween. One of the advantages of the hub modular enclosure 136 is enabling the quick removal and / or replacement of various modules.
[0029] A modular surgical enclosure is used in a surgical procedure that involves energy application to tissue. The modular surgical enclosure includes a first energy-generator module, configured to generate a first energy for application to the tissue, and a first docking station comprising a first docking port that includes first data and power contacts, wherein the first energy-generator module is slidably movable into an electrical engagement with the power and data contacts and wherein the first energy-generator module is slidably movable out of the electrical engagement with the first power and data contacts.
[0030] The modular surgical enclosure also includes a second energy-generator module configured to generate a second energy, different than the first energy, for application to the tissue, and a second docking station comprising a second docking port that includes second data and power contacts, wherein the second energy-generator module is slidably movable into an electrical engagement with the power and data contacts, and wherein the second energy-generator module is slidably movable out of the electrical engagement with the second power and data contacts.
[0031] The modular surgical enclosure also includes a communication bus between the first docking port and the second docking port, configured to facilitate communication between the first energy-generator module and the second energy-generator module.
[0032] Referring to FIGS. 3-7, depicted is a hub modular enclosure 136 that allows the modular integration of a generator module 140, a smoke evacuation module 126, and a suction / irrigation module 128. The hub modular enclosure 136 further facilitates interactive communication between the modules 140, 126, 128. As illustrated in FIG. 5, the generator module 140 is a generator module with integrated monopolar, bipolar, and ultrasonic components supported in a single housing unit 139 slidably insertable into the hub modular enclosure 136. As illustrated in FIG. 5, the generator module 140 is configured to connect to a monopolar device 146, a bipolar device 147, and an ultrasonic device 148. Alternatively, the generator module 140 may comprise a series of monopolar, bipolar, and / or ultrasonic generator modules that interact through the hub modular enclosure 136. The hub modular enclosure 136 is configured to facilitate the insertion of multiple generators and interactive communication between the generators docked into the hub modular enclosure 136 so that the generators would act as a single generator.
[0033] The hub modular enclosure 136 comprises a modular power and communication backplane 149 with external and wireless communication headers to enable the removable attachment of the modules 140, 126, 128 and interactive communication therebetween.
[0034] The hub modular enclosure 136 includes docking stations, or drawers, 151, herein also referred to as drawers, which are configured to slidably receive the modules 140, 126, 128. FIG. 4 illustrates a partial perspective view of a surgical hub enclosure 136, and a combo generator module 145 slidably receivable in a docking station 151 of the surgical hub enclosure 136. A docking port 152 with power and data contacts on a rear side of the combo generator module 145 is configured to engage a corresponding docking port 150 with power and data contacts of a corresponding docking station 151 of the hub modular enclosure 136 as the combo generator module 145 is slid into position within the corresponding docking station 151 of the hub module enclosure 136. The combo generator module 145 includes a bipolar, ultrasonic, and monopolar module and a smoke evacuation module integrated together into a single housing unit 139, as illustrated in FIG. 5.
[0035] The smoke evacuation module 126 includes a fluid line 154 that conveys captured / collected smoke and / or fluid away from a surgical site and to, for example, the smoke evacuation module 126. Vacuum suction originating from the smoke evacuation module 126 can draw the smoke into an opening of a utility conduit at the surgical site. The utility conduit, coupled to the fluid line, is in the form of a flexible tube terminating at the smoke evacuation module 126. The utility conduit and the fluid line define a fluid path extending toward the smoke evacuation module 126 that is received in the hub enclosure 136.
[0036] The suction / irrigation module 128 is coupled to a surgical tool comprising an aspiration fluid line and a suction fluid line. The aspiration and suction fluid lines are in the form of flexible tubes extending from the surgical site toward the suction / irrigation module 128. One or more drive systems are configured to cause irrigation and aspiration of fluids to and from the surgical site.
[0037] The surgical tool includes a shaft having an end effector at a distal end thereof and at least one energy treatment associated with the end effector, an aspiration tube, and an irrigation tube. The aspiration tube has an inlet port at a distal end thereof and the aspiration tube extends through the shaft. Similarly, an irrigation tube extends through the shaft and has an inlet port in proximity to the energy deliver implement. The energy deliver implement is configured to deliver ultrasonic and / or RF energy to the surgical site and is coupled to the generator module 140 by a cable extending initially through the shaft.
[0038] The irrigation tube is in fluid communication with a fluid source, and the aspiration tube is in fluid communication with a vacuum source. The fluid source and / or the vacuum source is housed in the suction / irrigation module 128. In one example, the fluid source and / or the vacuum source is housed in the hub enclosure 136 separately from the suction / irrigation module 128. In such example, a fluid interface is configured to connect the suction / irrigation module 128 to the fluid source and / or the vacuum source.
[0039] The modules 140, 126, 128 and / or their corresponding docking stations on the hub modular enclosure 136 include alignment features that are configured to align the docking ports of the modules into engagement with their counterparts in the docking stations of the hub modular enclosure 136. For example, as illustrated in FIG. 4, the combo generator module 145 includes side brackets 155 that are configured to slidably engage with corresponding brackets 156 of the corresponding docking station 151 of the hub modular enclosure 136. The brackets cooperate to guide the docking port contacts of the combo generator module 145 into an electrical engagement with the docking port contacts of the hub modular enclosure 136.
[0040] The drawers 151 of the hub modular enclosure 136 are the same, or substantially the same size, and the modules are adjusted in size to be received in the drawers 151. The side brackets 155 and / or 156 are larger or smaller depending on the size of the module. Alternatively, the drawers 151 are different in size and are each designed to accommodate a particular module.
[0041] Furthermore, the contacts of a particular module can be keyed for engagement with the contacts of a particular drawer to avoid inserting a module into a drawer with mismatching contacts.
[0042] As illustrated in FIG. 4, the docking port 150 of one drawer 151 can be coupled to the docking port 150 of another drawer 151 through a communications link 157 to facilitate an interactive communication between the modules housed in the hub modular enclosure 136. The docking ports 150 of the hub modular enclosure 136 may alternatively, or additionally, facilitate a wireless interactive communication between the modules housed in the hub modular enclosure 136. Any suitable wireless communication can be employed, such as for example Air Titan-Bluetooth.
[0043] FIG. 6 illustrates individual power bus attachments for a plurality of lateral docking ports of a lateral modular housing 160 configured to receive a plurality of modules of a surgical hub 206. The lateral modular housing 160 is configured to laterally receive and interconnect the modules 161. The modules 161 are slidably inserted into docking stations 162 of lateral modular housing 160, which includes a backplane for interconnecting the modules 161. As illustrated in FIG. 6, the modules 161 are arranged laterally in the lateral modular housing 160. Alternatively, the modules 161 may be arranged vertically in a lateral modular housing.
[0044] FIG. 7 illustrates a vertical modular housing 164 configured to receive a plurality of modules 165 of the surgical hub 106. The modules 165 are slidably inserted into docking stations, or drawers, 167 of vertical modular housing 164, which includes a backplane for interconnecting the modules 165. Although the drawers 167 of the vertical modular housing 164 are arranged vertically, a vertical modular housing 164 may include drawers that are arranged laterally. Furthermore, the modules 165 interact with one another through the docking ports of the vertical modular housing 164. In the example of FIG. 7, a display 177 is provided for displaying data relevant to the operation of the modules 165. In addition, the vertical modular housing 164 includes a master module 178 housing a plurality of sub-modules that are slidably received in the master module 178.
[0045] The imaging module 138 comprises an integrated video processor and a modular light source and is adapted for use with various imaging devices. The imaging device is comprised of a modular housing that can be assembled with a light source module and a camera module. The housing is a disposable housing. The disposable housing is removably coupled to a reusable controller, a light source module, and a camera module. The light source module and / or the camera module are selectively chosen depending on the type of surgical procedure. The camera module comprises a CCD sensor. The camera module comprises a CMOS sensor. The camera module is configured for scanned beam imaging. Likewise, the light source module is configured to deliver a white light or a different light, depending on the surgical procedure.
[0046] During a surgical procedure, removing a surgical device from the surgical field and replacing it with another surgical device that includes a different camera or a different light source can be inefficient. Temporarily losing sight of the surgical field may lead to undesirable consequences. The module imaging device of the present disclosure is configured to permit the replacement of a light source module or a camera module midstream during a surgical procedure, without having to remove the imaging device from the surgical field.
[0047] The imaging device comprises a tubular housing that includes a plurality of channels. A first channel is configured to slidably receive the camera module, which can be configured for a snap-fit engagement with the first channel. A second channel is configured to slidably receive the light source module, which can be configured for a snap-fit engagement with the second channel. The camera module and / or the light source module can be rotated into a final position within their respective channels. A threaded engagement can be employed in lieu of the snap-fit engagement.
[0048] Multiple imaging devices are placed at different positions in the surgical field to provide multiple views. The imaging module 138 are configured to switch between the imaging devices to provide an optimal view. The imaging module 138 is configured to integrate the images from the different imaging device.
[0049] Various image processors and imaging devices suitable for use with the present disclosure are described in U.S. Patent No. 7,995,045, titled COMBINED SBI AND CONVENTIONAL IMAGE PROCESSOR, which issued on August 9, 2011. In addition, U.S. Patent No. 7,982,776, titled SBI MOTION ARTIFACT REMOVAL APPARATUS AND METHOD, which issued on July 19, 2011, describes various systems for removing motion artifacts from image data. Such systems can be integrated with the imaging module 138. Furthermore, U.S. Patent Application Publication No. 2011 / 0306840, titled CONTROLLABLE MAGNETIC SOURCE TO FIXTURE INTRACORPOREAL APPARATUS, which published on December 15, 2011, and U.S. Patent Application Publication No. 2014 / 0243597, titled SYSTEM FOR PERFORMING A MINIMALLY INVASIVE SURGICAL PROCEDURE, which published on August 28, 2014.
[0050] FIG. 8 illustrates a surgical data network 201 comprising a modular communication hub 203 configured to connect modular devices located in one or more operating theaters of a healthcare facility, or any room in a healthcare facility specially equipped for surgical operations, to a cloud-based system (e.g., the cloud 204 that includes a remote server 213 coupled to a storage device 205). The modular communication hub 203 comprises a network hub 207 and / or a network switch 209 in communication with a network router. The modular communication hub 203 also is coupled to a local computer system 210 to provide local computer processing and data manipulation. The surgical data network 201 may be configured as passive, intelligent, or switching. A passive surgical data network serves as a conduit for the data, enabling it to go from one device (or segment) to another and to the cloud computing resources. An intelligent surgical data network includes additional features to enable the traffic passing through the surgical data network to be monitored and to configure each port in the network hub 207 or network switch 209. An intelligent surgical data network is referred to as a manageable hub or switch. A switching hub reads the destination address of each packet and then forwards the packet to the correct port.
[0051] Modular devices 1a-1n located in the operating theater are coupled to the modular communication hub 203. The network hub 207 and / or the network switch 209 is / are coupled to a network router 211 to connect the devices 1a-1n to the cloud 204 or the local computer system 210. Data associated with the devices 1a-1n is transferred to cloud-based computers via the router for remote data processing and manipulation. Data associated with the devices 1a-1n is also be transferred to the local computer system 210 for local data processing and manipulation. Modular devices 2a-2m located in the same operating theater also are coupled to a network switch 209. The network switch 209 is coupled to the network hub 207 and / or the network router 211 to connect to the devices 2a-2m to the cloud 204. Data associated with the devices 2a-2n is transferred to the cloud 204 via the network router 211 for data processing and manipulation. Data associated with the devices 2a-2m is also be transferred to the local computer system 210 for local data processing and manipulation.
[0052] It will be appreciated that the surgical data network 201 can be expanded by interconnecting multiple network hubs 207 and / or multiple network switches 209 with multiple network routers 211. The modular communication hub 203 is contained in a modular control tower configured to receive multiple devices 1a-1n / 2a-2m. The local computer system 210 also is contained in a modular control tower. The modular communication hub 203 is connected to a display 212 to display images obtained by some of the devices 1a-1n / 2a-2m, for example during surgical procedures. The devices 1a-1n / 2a-2m include, for example, various modules such as an imaging module 138 coupled to an endoscope, a generator module 140 coupled to an energy-based surgical device, a smoke evacuation module 126, a suction / irrigation module 128, a communication module 130, a processor module 132, a storage array 134, a surgical device coupled to a display, and / or a non-contact sensor module, among other modular devices that are connected to the modular communication hub 203 of the surgical data network 201.
[0053] The surgical data network 201 comprises a combination of network hub(s), network switch(es), and network router(s) connecting the devices 1a-1n / 2a-2m to the cloud. Any one of or all of the devices 1a-1n / 2a-2m coupled to the network hub or network switch collects data in real time and transfers the data to cloud computers for data processing and manipulation. It will be appreciated that cloud computing relies on sharing computing resources rather than having local servers or personal devices to handle software applications. The word "cloud" is used as a metaphor for "the Internet," although the term is not limited as such. Accordingly, the term "cloud computing" is also used herein to refer to "a type of Internet-based computing," where different services-such as servers, storage, and applications-are delivered to the modular communication hub 203 and / or computer system 210 located in the surgical theater (e.g., a fixed, mobile, temporary, or field operating room or space) and to devices connected to the modular communication hub 203 and / or computer system 210 through the Internet. The cloud infrastructure may be maintained by a cloud service provider. In this context, the cloud service provider is the entity that coordinates the usage and control of the devices 1a-1n / 2a-2m located in one or more operating theaters. The cloud computing services can perform a large number of calculations based on the data gathered by smart surgical instruments, robots, and other computerized devices located in the operating theater. The hub hardware enables multiple devices or connections to be connected to a computer that communicates with the cloud computing resources and storage.
[0054] Applying cloud computer data processing techniques on the data collected by the devices 1a-1n / 2a-2m, the surgical data network provides improved surgical outcomes, reduced costs, and improved patient satisfaction. At least some of the devices 1a-1n / 2a-2m are employed to view tissue states to assess leaks or perfusion of sealed tissue after a tissue sealing and cutting procedure. At least some of the devices 1a-1n / 2a-2m are employed to identify pathology, such as the effects of diseases, using the cloud-based computing to examine data including images of samples of body tissue for diagnostic purposes. This includes localization and margin confirmation of tissue and phenotypes. At least some of the devices 1a-1n / 2a-2m are employed to identify anatomical structures of the body using a variety of sensors integrated with imaging devices and techniques such as overlaying images captured by multiple imaging devices. The data gathered by the devices 1a-1n / 2a-2m, including image data, is transferred to the cloud 204 or the local computer system 210 or both for data processing and manipulation including image processing and manipulation. The data is analyzed to improve surgical procedure outcomes by determining if further treatment, such as the application of endoscopic intervention, emerging technologies, a targeted radiation, targeted intervention, and precise robotics to tissue-specific sites and conditions, is pursued. Such data analysis employs outcome analytics processing, and using standardized approaches may provide beneficial feedback to either confirm surgical treatments and the behavior of the surgeon or suggest modifications to surgical treatments and the behavior of the surgeon.
[0055] The operating theater devices 1a-1n are connected to the modular communication hub 203 over a wired channel or a wireless channel depending on the configuration of the devices 1a-1n to a network hub. The network hub 207 is implemented as a local network broadcast device that works on the physical layer of the Open System Interconnection (OSI) model. The network hub provides connectivity to the devices 1a-1n located in the same operating theater network. The network hub 207 collects data in the form of packets and sends them to the router in half duplex mode. The network hub 207 does not store any media access control / internet protocol (MAC / IP) to transfer the device data. Only one of the devices 1a-1n can send data at a time through the network hub 207. The network hub 207 has no routing tables or intelligence regarding where to send information and broadcasts all network data across each connection and to a remote server 213 (FIG. 9) over the cloud 204. The network hub 207 can detect basic network errors such as collisions, but having all information broadcast to multiple ports can be a security risk and cause bottlenecks.
[0056] The operating theater devices 2a-2m are connected to a network switch 209 over a wired channel or a wireless channel. The network switch 209 works in the data link layer of the OSI model. The network switch 209 is a multicast device for connecting the devices 2a-2m located in the same operating theater to the network. The network switch 209 sends data in the form of frames to the network router 211 and works in full duplex mode. Multiple devices 2a-2m can send data at the same time through the network switch 209. The network switch 209 stores and uses MAC addresses of the devices 2a-2m to transfer data.
[0057] The network hub 207 and / or the network switch 209 are coupled to the network router 211 for connection to the cloud 204. The network router 211 works in the network layer of the OSI model. The network router 211 creates a route for transmitting data packets received from the network hub 207 and / or network switch 211 to cloud-based computer resources for further processing and manipulation of the data collected by any one of or all the devices 1a-1n / 2a-2m. The network router 211 is employed to connect two or more different networks located in different locations, such as, for example, different operating theaters of the same healthcare facility or different networks located in different operating theaters of different healthcare facilities. The network router 211 sends data in the form of packets to the cloud 204 and works in full duplex mode. Multiple devices can send data at the same time. The network router 211 uses IP addresses to transfer data.
[0058] The network hub 207 is implemented as a USB hub, which allows multiple USB devices to connect to a host computer. The USB hub expands a single USB port into several tiers so that there are more ports available to connect devices to the host system computer. The network hub 207 includes wired or wireless capabilities to receive information over a wired channel or a wireless channel. A wireless USB short-range, high-bandwidth wireless radio communication protocol is employed for communication between the devices 1a-1n and devices 2a-2m located in the operating theater.
[0059] The operating theater devices 1a-1n / 2a-2m communicate to the modular communication hub 203 via Bluetooth wireless technology standard for exchanging data over short distances (using short-wavelength UHF radio waves in the ISM band from 2.4 to 2.485 GHz) from fixed and mobile devices and building personal area networks (PANs). The operating theater devices 1a-1n / 2a-2m communicates to the modular communication hub 203 via a number of wireless or wired communication standards or protocols, including but not limited to Wi-Fi (IEEE 802.11 family), WiMAX (IEEE 802.16 family), IEEE 802.20, long-term evolution (LTE), and Ev-DO, HSPA+, HSDPA+, HSUPA+, EDGE, GSM, GPRS, CDMA, TDMA, DECT, and Ethernet derivatives thereof, as well as any other wireless and wired protocols that are designated as 3G, 4G, 5G, and beyond. The computing module includes a plurality of communication modules. For instance, a first communication module is dedicated to shorter-range wireless communications such as Wi-Fi and Bluetooth, and a second communication module is dedicated to longer-range wireless communications such as GPS, EDGE, GPRS, CDMA, WiMAX, LTE, Ev-DO, and others.
[0060] The modular communication hub 203 serves as a central connection for one or all of the operating theater devices 1a-1n / 2a-2m and handles a data type known as frames. Frames carry the data generated by the devices 1a-1n / 2a-2m. When a frame is received by the modular communication hub 203, it is amplified and transmitted to the network router 211, which transfers the data to the cloud computing resources by using a number of wireless or wired communication standards or protocols, as described herein.
[0061] The modular communication hub 203 can be used as a standalone device or be connected to compatible network hubs and network switches to form a larger network. The modular communication hub 203 is generally easy to install, configure, and maintain, making it a good option for networking the operating theater devices 1a-1n / 2a-2m.
[0062] FIG. 9 illustrates a computer-implemented interactive surgical system 200. The computer-implemented interactive surgical system 200 is similar in many respects to the computer-implemented interactive surgical system 100. For example, the computer-implemented interactive surgical system 200 includes one or more surgical systems 202, which are similar in many respects to the surgical systems 102. Each surgical system 202 includes at least one surgical hub 206 in communication with a cloud 204 that may include a remote server 213. In one aspect, the computer-implemented interactive surgical system 200 comprises a modular control tower 236 connected to multiple operating theater devices such as, for example, intelligent surgical instruments, robots, and other computerized devices located in the operating theater. As shown in FIG. 10, the modular control tower 236 comprises a modular communication hub 203 coupled to a computer system 210. As illustrated in the example of FIG. 9, the modular control tower 236 is coupled to an imaging module 238 that is coupled to an endoscope 239, a generator module 240 that is coupled to an energy device 241, a smoke evacuator module 226, a suction / irrigation module 228, a communication module 230, a processor module 232, a storage array 234, a smart device / instrument 235 optionally coupled to a display 237, and a non-contact sensor module 242. The operating theater devices are coupled to cloud computing resources and data storage via the modular control tower 236. A robot hub 222 also is connected to the modular control tower 236 and to the cloud computing resources. The devices / instruments 235, visualization systems 208, among others, is coupled to the modular control tower 236 via wired or wireless communication standards or protocols, as described herein. The modular control tower 236 is coupled to a hub display 215 (e.g., monitor, screen) to display and overlay images received from the imaging module, device / instrument display, and / or other visualization systems 208. The hub display also displays data received from devices connected to the modular control tower in conjunction with images and overlaid images.
[0063] FIG. 10 illustrates a surgical hub 206 comprising a plurality of modules coupled to the modular control tower 236. The modular control tower 236 comprises a modular communication hub 203, e.g., a network connectivity device, and a computer system 210 to provide local processing, visualization, and imaging, for example. As shown in FIG. 10, the modular communication hub 203 is connected in a tiered configuration to expand the number of modules (e.g., devices) that may be connected to the modular communication hub 203 and transfer data associated with the modules to the computer system 210, cloud computing resources, or both. As shown in FIG. 10, each of the network hubs / switches in the modular communication hub 203 includes three downstream ports and one upstream port. The upstream network hub / switch is connected to a processor to provide a communication connection to the cloud computing resources and a local display 217. Communication to the cloud 204 is made either through a wired or a wireless communication channel.
[0064] The surgical hub 206 employs a non-contact sensor module 242 to measure the dimensions of the operating theater and generate a map of the surgical theater using either ultrasonic or laser-type non-contact measurement devices. An ultrasound-based non-contact sensor module scans the operating theater by transmitting a burst of ultrasound and receiving the echo when it bounces off the perimeter walls of an operating theater as described under the heading "Surgical Hub Spatial Awareness Within an Operating Room" in U.S. Provisional Patent Application Serial No. 62 / 611,341, titled INTERACTIVE SURGICAL PLATFORM, filed December 28, 2017, in which the sensor module is configured to determine the size of the operating theater and to adjust Bluetooth-pairing distance limits. A laser-based non-contact sensor module scans the operating theater by transmitting laser light pulses, receiving laser light pulses that bounce off the perimeter walls of the operating theater, and comparing the phase of the transmitted pulse to the received pulse to determine the size of the operating theater and to adjust Bluetooth pairing distance limits, for example.
[0065] The computer system 210 comprises a processor 244 and a network interface 245. The processor 244 is coupled to a communication module 247, storage 248, memory 249, non-volatile memory 250, and input / output interface 251 via a system bus. The system bus is any of several types of bus structure(s) including the memory bus or memory controller, a peripheral bus or external bus, and / or a local bus using any variety of available bus architectures including, but not limited to, 9-bit bus, Industrial Standard Architecture (ISA), Micro-Charmel Architecture (MSA), Extended ISA (EISA), Intelligent Drive Electronics (IDE), VESA Local Bus (VLB), Peripheral Component Interconnect (PCI), USB, Advanced Graphics Port (AGP), Personal Computer Memory Card International Association bus (PCMCIA), Small Computer Systems Interface (SCSI), or any other proprietary bus.
[0066] The processor 244 is any single-core or multicore processor such as those known under the trade name ARM Cortex by Texas Instruments. In one aspect, the processor may be an LM4F230H5QR ARM Cortex-M4F Processor Core, available from Texas Instruments, for example, comprising an on-chip memory of 256 KB single-cycle flash memory, or other non-volatile memory, up to 40 MHz, a prefetch buffer to improve performance above 40 MHz, a 32 KB single-cycle serial random access memory (SRAM), an internal read-only memory (ROM) loaded with StellarisWare ®< software, a 2 KB electrically erasable programmable read-only memory (EEPROM), and / or one or more pulse width modulation (PWM) modules, one or more quadrature encoder inputs (QEI) analogs, one or more 12-bit analog-to-digital converters (ADCs) with 12 analog input channels, details of which are available for the product datasheet.
[0067] In one aspect, the processor 244 comprises a safety controller comprising two controller-based families such as TMS570 and RM4x, known under the trade name Hercules ARM Cortex R4, also by Texas Instruments. The safety controller is configured specifically for IEC 61508 and ISO 26262 safety critical applications, among others, to provide advanced integrated safety features while delivering scalable performance, connectivity, and memory options.
[0068] The system memory includes volatile memory and non-volatile memory. The basic input / output system (BIOS), containing the basic routines to transfer information between elements within the computer system, such as during start-up, is stored in non-volatile memory. For example, the non-volatile memory can include ROM, programmable ROM (PROM), electrically programmable ROM (EPROM), EEPROM, or flash memory. Volatile memory includes random-access memory (RAM), which acts as external cache memory. Moreover, RAM is available in many forms such as SRAM, dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and direct Rambus RAM (DRRAM).
[0069] The computer system 210 also includes removable / non-removable, volatile / non-volatile computer storage media, such as for example disk storage. The disk storage includes, but is not limited to, devices like a magnetic disk drive, floppy disk drive, tape drive, Jaz drive, Zip drive, LS-60 drive, flash memory card, or memory stick. In addition, the disk storage can include storage media separately or in combination with other storage media including, but not limited to, an optical disc drive such as a compact disc ROM device (CD-ROM), compact disc recordable drive (CD-R Drive), compact disc rewritable drive (CD-RW Drive), or a digital versatile disc ROM drive (DVD-ROM). To facilitate the connection of the disk storage devices to the system bus, a removable or non-removable interface may be employed.
[0070] It is to be appreciated that the computer system 210 includes software that acts as an intermediary between users and the basic computer resources described in a suitable operating environment. Such software includes an operating system. The operating system, which can be stored on the disk storage, acts to control and allocate resources of the computer system. System applications take advantage of the management of resources by the operating system through program modules and program data stored either in the system memory or on the disk storage. It is to be appreciated that various components described herein can be implemented with various operating systems or combinations of operating systems.
[0071] A user enters commands or information into the computer system 210 through input device(s) coupled to the I / O interface 251. The input devices include, but are not limited to, a pointing device such as a mouse, trackball, stylus, touch pad, keyboard, microphone, joystick, game pad, satellite dish, scanner, TV tuner card, digital camera, digital video camera, web camera, and the like. These and other input devices connect to the processor through the system bus via interface port(s). The interface port(s) include, for example, a serial port, a parallel port, a game port, and a USB. The output device(s) use some of the same types of ports as input device(s). Thus, for example, a USB port is used to provide input to the computer system and to output information from the computer system to an output device. An output adapter is provided to illustrate that there are some output devices like monitors, displays, speakers, and printers, among other output devices that require special adapters. The output adapters include, by way of illustration and not limitation, video and sound cards that provide a means of connection between the output device and the system bus. It should be noted that other devices and / or systems of devices, such as remote computer(s), provide both input and output capabilities.
[0072] The computer system 210 operates in a networked environment using logical connections to one or more remote computers, such as cloud computer(s), or local computers. The remote cloud computer(s) can be a personal computer, server, router, network PC, workstation, microprocessor-based appliance, peer device, or other common network node, and the like, and typically includes many or all of the elements described relative to the computer system. For purposes of brevity, only a memory storage device is illustrated with the remote computer(s). The remote computer(s) is logically connected to the computer system through a network interface and then physically connected via a communication connection. The network interface encompasses communication networks such as local area networks (LANs) and wide area networks (WANs). LAN technologies include Fiber Distributed Data Interface (FDDI), Copper Distributed Data Interface (CDDI), Ethernet / IEEE 802.3, Token Ring / IEEE 802.5 and the like. WAN technologies include, but are not limited to, point-to-point links, circuit-switching networks like Integrated Services Digital Networks (ISDN) and variations thereon, packet-switching networks, and Digital Subscriber Lines (DSL).
[0073] The computer system 210 of FIG. 10, the imaging module 238 and / or visualization system 208, and / or the processor module 232 of FIGS. 9-10, comprises an image processor, image processing engine, media processor, or any specialized digital signal processor (DSP) used for the processing of digital images. The image processor employs parallel computing with single instruction, multiple data (SIMD) or multiple instruction, multiple data (MIMD) technologies to increase speed and efficiency. The digital image processing engine can perform a range of tasks. The image processor may be a system on a chip with multicore processor architecture.
[0074] The communication connection(s) refers to the hardware / software employed to connect the network interface to the bus. While the communication connection is shown for illustrative clarity inside the computer system, it can also be external to the computer system 210. The hardware / software necessary for connection to the network interface includes, for illustrative purposes only, internal and external technologies such as modems, including regular telephone-grade modems, cable modems, and DSL modems, ISDN adapters, and Ethernet cards.
[0075] FIG. 11 illustrates a functional block diagram of a USB network hub 300 device. The USB network hub device 300 employs a TUSB2036 integrated circuit hub by Texas Instruments. The USB network hub 300 is a CMOS device that provides an upstream USB transceiver port 302 and up to three downstream USB transceiver ports 304, 306, 308 in compliance with the USB 2.0 specification. The upstream USB transceiver port 302 is a differential root data port comprising a differential data minus (DM0) input paired with a differential data plus (DP0) input. The three downstream USB transceiver ports 304, 306, 308 are differential data ports where each port includes differential data plus (DP1-DP3) outputs paired with differential data minus (DM1-DM3) outputs.
[0076] The USB network hub 300 device is implemented with a digital state machine instead of a microcontroller, and no firmware programming is required. Fully compliant USB transceivers are integrated into the circuit for the upstream USB transceiver port 302 and all downstream USB transceiver ports 304, 306, 308. The downstream USB transceiver ports 304, 306, 308 support both full-speed and low-speed devices by automatically setting the slew rate according to the speed of the device attached to the ports. The USB network hub 300 device may be configured either in bus-powered or self-powered mode and includes a hub power logic 312 to manage power.
[0077] The USB network hub 300 device includes a serial interface engine 310 (SIE). The SIE 310 is the front end of the USB network hub 300 hardware and handles most of the protocol described in chapter 8 of the USB specification. The SIE 310 typically comprehends signaling up to the transaction level. The functions that it handles include: packet recognition, transaction sequencing, SOP, EOP, RESET, and RESUME signal detection / generation, clock / data separation, non-return-to-zero invert (NRZI) data encoding / decoding and bit-stuffing, CRC generation and checking (token and data), packet ID (PID) generation and checking / decoding, and / or serial-parallel / parallel-serial conversion. The 310 receives a clock input 314 and is coupled to a suspend / resume logic and frame timer 316 circuit and a hub repeater circuit 318 to control communication between the upstream USB transceiver port 302 and the downstream USB transceiver ports 304, 306, 308 through port logic circuits 320, 322, 324. The SIE 310 is coupled to a command decoder 326 via interface logic to control commands from a serial EEPROM via a serial EEPROM interface 330.
[0078] The USB network hub 300 connects 127 functions configured in up to six logical layers (tiers) to a single computer. Further, the USB network hub 300 connects to all peripherals using a standardized four-wire cable that provides both communication and power distribution. The power configurations are bus-powered and self-powered modes. The USB network hub 300 is configured to support four modes of power management: a bus-powered hub, with either individual-port power management or ganged-port power management, and the self-powered hub, with either individual-port power management or ganged-port power management. Using a USB cable, the USB network hub 300, the upstream USB transceiver port 302 is plugged into a USB host controller, and the downstream USB transceiver ports 304, 306, 308 are exposed for connecting USB compatible devices, and so forth.Surgical Instrument Hardware
[0079] FIG. 12 illustrates a logic diagram of a control system 470 of a surgical instrument or tool. The system 470 comprises a control circuit. The control circuit includes a microcontroller 461 comprising a processor 462 and a memory 468. One or more of sensors 472, 474, 476, for example, provide real-time feedback to the processor 462. A motor 482, driven by a motor driver 492, operably couples a longitudinally movable displacement member to drive the I-beam knife element. A tracking system 480 is configured to determine the position of the longitudinally movable displacement member. The position information is provided to the processor 462, which is programmed or configured to determine the position of the longitudinally movable drive member as well as the position of a firing member, firing bar, and I-beam knife element. Additional motors are provided at the tool driver interface to control I-beam firing, closure tube travel, shaft rotation, and articulation. A display 473 displays a variety of operating conditions of the instruments and includes touch screen functionality for data input. Information displayed on the display 473 is overlaid with images acquired via endoscopic imaging modules.
[0080] The microcontroller 461 may be any single-core or multicore processor such as those known under the trade name ARM Cortex by Texas Instruments. The main microcontroller 461 may be an LM4F230H5QR ARM Cortex-M4F Processor Core, available from Texas Instruments, for example, comprising an on-chip memory of 256 KB single-cycle flash memory, or other non-volatile memory, up to 40 MHz, a prefetch buffer to improve performance above 40 MHz, a 32 KB single-cycle SRAM, and internal ROM loaded with StellarisWare ®< software, a 2 KB EEPROM, one or more PWM modules, one or more QEI analogs, and / or one or more 12-bit ADCs with 12 analog input channels, details of which are available for the product datasheet.
[0081] The microcontroller 461 comprises a safety controller comprising two controller-based families such as TMS570 and RM4x, known under the trade name Hercules ARM Cortex R4, also by Texas Instruments. The safety controller is configured specifically for IEC 61508 and ISO 26262 safety critical applications, among others, to provide advanced integrated safety features while delivering scalable performance, connectivity, and memory options.
[0082] The microcontroller 461 is programmed to perform various functions such as precise control over the speed and position of the knife and articulation systems. The microcontroller 461 includes a processor 462 and a memory 468. The electric motor 482 may be a brushed direct current (DC) motor with a gearbox and mechanical links to an articulation or knife system. A motor driver 492 is an A3941 available from Allegro Microsystems, Inc. Other motor drivers may be readily substituted for use in the tracking system 480 comprising an absolute positioning system. A detailed description of an absolute positioning system is described in U.S. Patent Application Publication No. 2017 / 0296213, titled SYSTEMS AND METHODS FOR CONTROLLING A SURGICAL STAPLING AND CUTTING INSTRUMENT, which published on October 19, 2017.
[0083] The microcontroller 461 is programmed to provide precise control over the speed and position of displacement members and articulation systems. The microcontroller 461 is configured to compute a response in the software of the microcontroller 461. The computed response is compared to a measured response of the actual system to obtain an "observed" response, which is used for actual feedback decisions. The observed response is a favorable, tuned value that balances the smooth, continuous nature of the simulated response with the measured response, which detects outside influences on the system.
[0084] The motor 482 is controlled by the motor driver 492 and is employed by the firing system of the surgical instrument or tool. The motor 482 is a brushed DC driving motor having a maximum rotational speed of approximately 25,000 RPM. Alernatively, the motor 482 includes a brushless motor, a cordless motor, a synchronous motor, a stepper motor, or any other suitable electric motor. The motor driver 492 comprises an H-bridge driver comprising field-effect transistors (FETs), for example. The motor 482 is powered by a power assembly releasably mounted to the handle assembly or tool housing for supplying control power to the surgical instrument or tool. The power assembly comprises a battery which includes a number of battery cells connected in series that can be used as the power source to power the surgical instrument or tool. In certain circumstances, the battery cells of the power assembly are replaceable and / or rechargeable. In at least one example, the battery cells can be lithium-ion batteries which are couplable to and separable from the power assembly.
[0085] The motor driver 492 may be an A3941 available from Allegro Microsystems, Inc. The A3941 492 is a full-bridge controller for use with external N-channel power metal-oxide semiconductor field-effect transistors (MOSFETs) specifically designed for inductive loads, such as brush DC motors. The driver 492 comprises a unique charge pump regulator that provides full (>10 V) gate drive for battery voltages down to 7 V and allows the A3941 to operate with a reduced gate drive, down to 5.5 V. A bootstrap capacitor is employed to provide the above battery supply voltage required for N-channel MOSFETs. An internal charge pump for the high-side drive allows DC (100% duty cycle) operation. The full bridge is driven in fast or slow decay modes using diode or synchronous rectification. In the slow decay mode, current recirculation can be through the high-side or the lowside FETs. The power FETs are protected from shoot-through by resistor-adjustable dead time. Integrated diagnostics provide indications of undervoltage, overtemperature, and power bridge faults and are configured to protect the power MOSFETs under most short circuit conditions. Other motor drivers are readily substituted for use in the tracking system 480 comprising an absolute positioning system.
[0086] The tracking system 480 comprises a controlled motor drive circuit arrangement comprising a position sensor 472. The position sensor 472 for an absolute positioning system provides a unique position signal corresponding to the location of a displacement member. The displacement member represents a longitudinally movable drive member comprising a rack of drive teeth for meshing engagement with a corresponding drive gear of a gear reducer assembly. The displacement member represents the firing member, which could be adapted and configured to include a rack of drive teeth. The displacement member represents a firing bar or the I-beam, each of which can be adapted and configured to include a rack of drive teeth. Accordingly, as used herein, the term displacement member is used generically to refer to any movable member of the surgical instrument or tool such as the drive member, the firing member, the firing bar, the I-beam, or any element that can be displaced. The longitudinally movable drive member is coupled to the firing member, the firing bar, and the I-beam. Accordingly, the absolute positioning system can, in effect, track the linear displacement of the I-beam by tracking the linear displacement of the longitudinally movable drive member. The displacement member is coupled to any position sensor 472 suitable for measuring linear displacement. Thus, the longitudinally movable drive member, the firing member, the firing bar, or the I-beam, or combinations thereof, are coupled to any suitable linear displacement sensor. Linear displacement sensors include contact or non-contact displacement sensors. Linear displacement sensors comprise linear variable differential transformers (LVDT), differential variable reluctance transducers (DVRT), a slide potentiometer, a magnetic sensing system comprising a movable magnet and a series of linearly arranged Hall effect sensors, a magnetic sensing system comprising a fixed magnet and a series of movable, linearly arranged Hall effect sensors, an optical sensing system comprising a movable light source and a series of linearly arranged photo diodes or photo detectors, an optical sensing system comprising a fixed light source and a series of movable linearly, arranged photo diodes or photo detectors, or any combination thereof.
[0087] The electric motor 482 can include a rotatable shaft that operably interfaces with a gear assembly that is mounted in meshing engagement with a set, or rack, of drive teeth on the displacement member. A sensor element is operably coupled to a gear assembly such that a single revolution of the position sensor 472 element corresponds to some linear longitudinal translation of the displacement member. An arrangement of gearing and sensors is connected to the linear actuator, via a rack and pinion arrangement, or a rotary actuator, via a spur gear or other connection. A power source supplies power to the absolute positioning system and an output indicator may display the output of the absolute positioning system. The displacement member represents the longitudinally movable drive member comprising a rack of drive teeth formed thereon for meshing engagement with a corresponding drive gear of the gear reducer assembly. The displacement member represents the longitudinally movable firing member, firing bar, I-beam, or combinations thereof.
[0088] A single revolution of the sensor element associated with the position sensor 472 is equivalent to a longitudinal linear displacement d1 of the of the displacement member, where d1 is the longitudinal linear distance that the displacement member moves from point "a" to point "b" after a single revolution of the sensor element coupled to the displacement member. The sensor arrangement may be connected via a gear reduction that results in the position sensor 472 completing one or more revolutions for the full stroke of the displacement member. The position sensor 472 may complete multiple revolutions for the full stroke of the displacement member.
[0089] A series of switches, where n is an integer greater than one, is employed alone or in combination with a gear reduction to provide a unique position signal for more than one revolution of the position sensor 472. The state of the switches are fed back to the microcontroller 461 that applies logic to determine a unique position signal corresponding to the longitudinal linear displacement d1 + d2 + ... dn of the displacement member. The output of the position sensor 472 is provided to the microcontroller 461. The position sensor 472 of the sensor arrangement comprises a magnetic sensor, an analog rotary sensor like a potentiometer, or an array of analog Hall-effect elements, which output a unique combination of position signals or values.
[0090] The position sensor 472 comprisea any number of magnetic sensing elements, such as, for example, magnetic sensors classified according to whether they measure the total magnetic field or the vector components of the magnetic field. The techniques used to produce both types of magnetic sensors encompass many aspects of physics and electronics. The technologies used for magnetic field sensing include search coil, fluxgate, optically pumped, nuclear precession, SQUID, Hall-effect, anisotropic magnetoresistance, giant magnetoresistance, magnetic tunnel junctions, giant magnetoimpedance, magnetostrictive / piezoelectric composites, magnetodiode, magnetotransistor, fiber-optic, magneto-optic, and microelectromechanical systems-based magnetic sensors, among others.
[0091] The position sensor 472 for the tracking system 480 comprising an absolute positioning system comprises a magnetic rotary absolute positioning system. The position sensor 472 may be implemented as an AS5055EQFT single-chip magnetic rotary position sensor available from Austria Microsystems, AG. The position sensor 472 is interfaced with the microcontroller 461 to provide an absolute positioning system. The position sensor 472 is a low-voltage and low-power component and includes four Hall-effect elements in an area of the position sensor 472 that is located above a magnet. A high-resolution ADC and a smart power management controller are also provided on the chip. A coordinate rotation digital computer (CORDIC) processor, also known as the digit-by-digit method and Volder's algorithm, is provided to implement a simple and efficient algorithm to calculate hyperbolic and trigonometric functions that require only addition, subtraction, bitshift, and table lookup operations. The angle position, alarm bits, and magnetic field information are transmitted over a standard serial communication interface, such as a serial peripheral interface (SPI) interface, to the microcontroller 461. The position sensor 472 provides 12 or 14 bits of resolution. The position sensor 472 may be an AS5055 chip provided in a small QFN 16-pin 4x4x0.85mm package.
[0092] The tracking system 480 comprising an absolute positioning system comprises and / or is programmed to implement a feedback controller, such as a PID, state feedback, and adaptive controller. A power source converts the signal from the feedback controller into a physical input to the system: in this case the voltage. Other examples include a PWM of the voltage, current, and force. Other sensor(s) may be provided to measure physical parameters of the physical system in addition to the position measured by the position sensor 472. The other sensor(s) can include sensor arrangements such as those described in U.S. Patent No. 9,345,481, titled STAPLE CARTRIDGE TISSUE THICKNESS SENSOR SYSTEM, which issued on May 24, 2016; U.S. Patent Application Publication No. 2014 / 0263552, titled STAPLE CARTRIDGE TISSUE THICKNESS SENSOR SYSTEM, which published on September 18, 2014; and U.S. Patent Application Serial No. 15 / 628,175, titled TECHNIQUES FOR ADAPTIVE CONTROL OF MOTOR VELOCITY OF A SURGICAL STAPLING AND CUTTING INSTRUMENT, filed June 20, 2017. In a digital signal processing system, an absolute positioning system is coupled to a digital data acquisition system where the output of the absolute positioning system will have a finite resolution and sampling frequency. The absolute positioning system comprises a compare-and-combine circuit to combine a computed response with a measured response using algorithms, such as a weighted average and a theoretical control loop, that drive the computed response towards the measured response. The computed response of the physical system takes into account properties like mass, inertial, viscous friction, inductance resistance, etc., to predict what the states and outputs of the physical system will be by knowing the input.
[0093] The absolute positioning system provides an absolute position of the displacement member upon power-up of the instrument, without retracting or advancing the displacement member to a reset (zero or home) position as may be required with conventional rotary encoders that merely count the number of steps forwards or backwards that the motor 482 has taken to infer the position of a device actuator, drive bar, knife, or the like.
[0094] A sensor 474, such as, for example, a strain gauge or a micro-strain gauge, is configured to measure one or more parameters of the end effector, such as, for example, the amplitude of the strain exerted on the anvil during a clamping operation, which is indicative of the closure forces applied to the anvil. The measured strain is converted to a digital signal and provided to the processor 462. Alternatively, or in addition to the sensor 474, a sensor 476, such as, for example, a load sensor, measures the closure force applied by the closure drive system to the anvil. The sensor 476, such as, for example, a load sensor, can measure the firing force applied to an I-beam in a firing stroke of the surgical instrument or tool. The I-beam is configured to engage a wedge sled, which is configured to upwardly cam staple drivers to force out staples into deforming contact with an anvil. The I-beam also includes a sharpened cutting edge that is used to sever tissue as the I-beam is advanced distally by the firing bar. Alternatively, a current sensor 478 is employed to measure the current drawn by the motor 482. The force required to advance the firing member corresponds to the current drawn by the motor 482, for example. The measured force is converted to a digital signal and provided to the processor 462.
[0095] The strain gauge sensor 474 is used to measure the force applied to the tissue by the end effector. A strain gauge is coupled to the end effector to measure the force on the tissue being treated by the end effector. A system for measuring forces applied to the tissue grasped by the end effector comprises a strain gauge sensor 474, such as, for example, a micro-strain gauge, that is configured to measure one or more parameters of the end effector, for example. The strain gauge sensor 474 measures the amplitude or magnitude of the strain exerted on a jaw member of an end effector during a clamping operation, which is indicative of the tissue compression. The measured strain is converted to a digital signal and provided to a processor 462 of the microcontroller 461. A load sensor 476 measures the force used to operate the knife element, for example, to cut the tissue captured between the anvil and the staple cartridge. A magnetic field sensor is employed to measure the thickness of the captured tissue. The measurement of the magnetic field sensor also may be converted to a digital signal and provided to the processor 462.
[0096] The measurements of the tissue compression, the tissue thickness, and / or the force required to close the end effector on the tissue, as respectively measured by the sensors 474, 476, is used by the microcontroller 461 to characterize the selected position of the firing member and / or the corresponding value of the speed of the firing member. A memory 468 stores a technique, an equation, and / or a lookup table which is employed by the microcontroller 461 in the assessment.
[0097] The control system 470 of the surgical instrument or tool also comprises wired or wireless communication circuits to communicate with the modular communication hub as shown in FIGS. 8-11.
[0098] FIG. 13 illustrates a control circuit 500 configured to control aspects of the surgical instrument or tool. The control circuit 500 is configured to implement various processes described herein. The control circuit 500 comprises a microcontroller comprising one or more processors 502 (e.g., microprocessor, microcontroller) coupled to at least one memory circuit 504. The memory circuit 504 stores machine-executable instructions that, when executed by the processor 502, cause the processor 502 to execute machine instructions to implement various processes described herein. The processor 502 is any one of a number of single-core or multicore processors known in the art. The memory circuit 504 comprises volatile and non-volatile storage media. The processor 502 includes an instruction processing unit 506 and an arithmetic unit 508. The instruction processing unit is configured to receive instructions from the memory circuit 504 of this disclosure.
[0099] FIG. 14 illustrates a combinational logic circuit 510 configured to control aspects of the surgical instrument or tool. The combinational logic circuit 510 can be configured to implement various processes described herein. The combinational logic circuit 510 comprises a finite state machine comprising a combinational logic 512 configured to receive data associated with the surgical instrument or tool at an input 514, process the data by the combinational logic 512, and provide an output 516.
[0100] FIG. 15 illustrates a sequential logic circuit 520 configured to control aspects of the surgical instrument or tool. The sequential logic circuit 520 or the combinational logic 522 is configured to implement various processes described herein. The sequential logic circuit 520 comprises a finite state machine. The sequential logic circuit 520 comprises a combinational logic 522, at least one memory circuit 524, and a clock 529, for example. The at least one memory circuit 524 stores a current state of the finite state machine. The sequential logic circuit 520 is synchronous or asynchronous. The combinational logic 522 is configured to receive data associated with the surgical instrument or tool from an input 526, process the data by the combinational logic 522, and provide an output 528. The circuit comprises a combination of a processor (e.g., processor 502, FIG. 13) and a finite state machine to implement various processes herein. The finite state machine comprises a combination of a combinational logic circuit (e.g., combinational logic circuit 510, FIG. 14) and the sequential logic circuit 520.
[0101] FIG. 16 illustrates a surgical instrument or tool comprising a plurality of motors which are activated to perform various functions. A first motor is activated to perform a first function, a second motor is activated to perform a second function, a third motor is activated to perform a third function, a fourth motor is activated to perform a fourth function, and so on. The plurality of motors of robotic surgical instrument 600 are individually activated to cause firing, closure, and / or articulation motions in the end effector. The firing, closure, and / or articulation motions are transmitted to the end effector through a shaft assembly, for example.
[0102] The surgical instrument system or tool includes a firing motor 602. The firing motor 602 is operably coupled to a firing motor drive assembly 604 which is configured to transmit firing motions, generated by the motor 602 to the end effector, in particular to displace the I-beam element. The firing motions generated by the motor 602 cause the staples to be deployed from the staple cartridge into tissue captured by the end effector and / or the cutting edge of the I-beam element to be advanced to cut the captured tissue, for example. The I-beam element is retracted by reversing the direction of the motor 602.
[0103] The surgical instrument or tool includes a closure motor 603. The closure motor 603 is operably coupled to a closure motor drive assembly 605 which is configured to transmit closure motions, generated by the motor 603 to the end effector, in particular to displace a closure tube to close the anvil and compress tissue between the anvil and the staple cartridge. The closure motions cause the end effector to transition from an open configuration to an approximated configuration to capture tissue, for example. The end effector is transitioned to an open position by reversing the direction of the motor 603.
[0104] The surgical instrument or tool includes one or more articulation motors 606a, 606b, for example. The motors 606a, 606b are operably coupled to respective articulation motor drive assemblies 608a, 608b, which are configured to transmit articulation motions generated by the motors 606a, 606b to the end effector. The articulation motions causes the end effector to articulate relative to the shaft, for example.
[0105] As described above, the surgical instrument or tool includes a plurality of motors which are configured to perform various independent functions. The plurality of motors of the surgical instrument or tool are individually or separately activated to perform one or more functions while the other motors remain inactive. For example, the articulation motors 606a, 606b are activated to cause the end effector to be articulated while the firing motor 602 remains inactive. Alternatively, the firing motor 602 is activated to fire the plurality of staples, and / or to advance the cutting edge, while the articulation motor 606 remains inactive. Furthermore the closure motor 603 is activated simultaneously with the firing motor 602 to cause the closure tube and the I-beam element to advance distally as described in more detail hereinbelow.
[0106] The surgical instrument or tool includes a common control module 610 which is employed with a plurality of motors of the surgical instrument or tool. The common control module 610 accommodates one of the plurality of motors at a time. For example, the common control module 610 is couplable to and separable from the plurality of motors of the robotic surgical instrument individually. A plurality of the motors of the surgical instrument or tool shares one or more common control modules such as the common control module 610. A plurality of motors of the surgical instrument or tool are individually and selectively engaged with the common control module 610. The common control module 610 is selectively switched from interfacing with one of a plurality of motors of the surgical instrument or tool to interfacing with another one of the plurality of motors of the surgical instrument or tool.
[0107] The common control module 610 is selectively switched between operable engagement with the articulation motors 606a, 606b and operable engagement with either the firing motor 602 or the closure motor 603. As illustrated in FIG. 16, a switch 614 is moved or transitioned between a plurality of positions and / or states. In a first position 616, the switch 614 electrically couples the common control module 610 to the firing motor 602; in a second position 617, the switch 614 electrically couples the common control module 610 to the closure motor 603; in a third position 618a, the switch 614 electrically couples the common control module 610 to the first articulation motor 606a; and in a fourth position 618b, the switch 614 electrically couples the common control module 610 to the second articulation motor 606b, for example. In certain instances, separate common control modules 610 are electrically coupled to the firing motor 602, the closure motor 603, and the articulations motor 606a, 606b at the same time. The switch 614 may be a mechanical switch, an electromechanical switch, a solid-state switch, or any suitable switching mechanism.
[0108] Each of the motors 602, 603, 606a, 606b comprises a torque sensor to measure the output torque on the shaft of the motor. The force on an end effector is sensed in any conventional manner, such as by force sensors on the outer sides of the jaws or by a torque sensor for the motor actuating the jaws.
[0109] As illustrated in FIG. 16, the common control module 610 comprises a motor driver 626 which comprises one or more H-Bridge FETs. The motor driver 626 modulates the power transmitted from a power source 628 to a motor coupled to the common control module 610 based on input from a microcontroller 620 (the "controller"), for example. The microcontroller 620 is employed to determine the current drawn by the motor while the motor is coupled to the common control module 610, as described above.
[0110] The microcontroller 620 includes a microprocessor 622 (the "processor") and one or more non-transitory computer-readable mediums or memory units 624 (the "memory"). The memory 624 stores various program instructions, which when executed cause the processor 622 to perform a plurality of functions and / or calculations described herein. One or more of the memory units 624 is coupled to the processor 622.
[0111] The power source 628 is employed to supply power to the microcontroller 620. The power source 628 may comprise a battery (or "battery pack" or "power pack"), such as a lithium-ion battery, for example. The battery pack is configured to be releasably mounted to a handle for supplying power to the surgical instrument 600. A number of battery cells connected in series is used as the power source 628. The power source 628 may be replaceable and / or rechargeable.
[0112] The processor 622 controls the motor driver 626 to control the position, direction of rotation, and / or velocity of a motor that is coupled to the common control module 610. The processor 622 signals the motor driver 626 to stop and / or disable a motor that is coupled to the common control module 610. It should be understood that the term "processor" as used herein includes any suitable microprocessor, microcontroller, or other basic computing device that incorporates the functions of a computer's central processing unit (CPU) on an integrated circuit or, at most, a few integrated circuits. The processor is a multipurpose, programmable device that accepts digital data as input, processes it according to instructions stored in its memory, and provides results as output. It is an example of sequential digital logic, as it has internal memory. Processors operate on numbers and symbols represented in the binary numeral system.
[0113] The processor 622 may be any single-core or multicore processor such as those known under the trade name ARM Cortex by Texas Instruments. The microcontroller 620 may be an LM 4F230H5QR, available from Texas Instruments. the Texas Instruments LM4F230H5QR is an ARM Cortex-M4F Processor Core comprising an on-chip memory of 256 KB single-cycle flash memory, or other non-volatile memory, up to 40 MHz, a prefetch buffer to improve performance above 40 MHz, a 32 KB single-cycle SRAM, an internal ROM loaded with StellarisWare ®< software, a 2 KB EEPROM, one or more PWM modules, one or more QEI analogs, one or more 12-bit ADCs with 12 analog input channels, among other features that are readily available for the product datasheet. Other microcontrollers may be readily substituted for use with the module 4410. Accordingly, the present disclosure should not be limited in this context.
[0114] The memory 624 includes program instructions for controlling each of the motors of the surgical instrument 600 that are couplable to the common control module 610. The memory 624 includes program instructions for controlling the firing motor 602, the closure motor 603, and the articulation motors 606a, 606b. Such program instructions cause the processor 622 to control the firing, closure, and articulation functions in accordance with inputs from algorithms or control programs of the surgical instrument or tool.
[0115] One or more mechanisms and / or sensors such as sensors 630 are employed to alert the processor 622 to the program instructions that should be used in a particular setting. The sensors 630 alert the processor 622 to use the program instructions associated with firing, closing, and articulating the end effector. The sensors 630 comprise position sensors which are be employed to sense the position of the switch 614. Accordingly, the processor 622 uses the program instructions associated with firing the I-beam of the end effector upon detecting, through the sensors 630 , that the switch 614 is in the first position 616; the processor 622 uses the program instructions associated with closing the anvil upon detecting, through the sensors 630 , that the switch 614 is in the second position 617; and the processor 622 uses the program instructions associated with articulating the end effector upon detecting, through the sensors 630 , that the switch 614 is in the third or fourth position 618a, 618b.
[0116] FIG. 17 is a schematic diagram of a robotic surgical instrument 700 configured to operate a surgical tool described herein . The robotic surgical instrument 700 is programmed or configured to control distal / proximal translation of a displacement member, distal / proximal displacement of a closure tube, shaft rotation, and articulation, either with single or multiple articulation drive links. The surgical instrument 700 is programmed or configured to individually control a firing member, a closure member, a shaft member, and / or one or more articulation members. The surgical instrument 700 comprises a control circuit 710 configured to control motor-driven firing members, closure members, shaft members, and / or one or more articulation members.
[0117] The robotic surgical instrument 700 comprises a control circuit 710 configured to control an anvil 716 and an I-beam 714 (including a sharp cutting edge) portion of an end effector 702, a removable staple cartridge 718, a shaft 740, and one or more articulation members 742a, 742b via a plurality of motors 704a-704e. A position sensor 734 is configured to provide position feedback of the I-beam 714 to the control circuit 710. Other sensors 738 are configured to provide feedback to the control circuit 710. A timer / counter 731 provides timing and counting information to the control circuit 710. An energy source 712 is provided to operate the motors 704a-704e, and a current sensor 736 provides motor current feedback to the control circuit 710. The motors 704a-704e are operated individually by the control circuit 710 in a open-loop or closed-loop feedback control.
[0118] The control circuit 710 comprises one or more microcontrollers, microprocessors, or other suitable processors for executing instructions that cause the processor or processors to perform one or more tasks. A timer / counter 731 provides an output signal, such as the elapsed time or a digital count, to the control circuit 710 to correlate the position of the I-beam 714 as determined by the position sensor 734 with the output of the timer / counter 731 such that the control circuit 710 can determine the position of the I-beam 714 at a specific time (t) relative to a starting position or the time (t) when the I-beam 714 is at a specific position relative to a starting position. The timer / counter 731 is configured to measure elapsed time, count external events, or time external events.
[0119] The control circuit 710 is programmed to control functions of the end effector 702 based on one or more tissue conditions. The control circuit 710 is programmed to sense tissue conditions, such as thickness, either directly or indirectly, as described herein. The control circuit 710 is programmed to select a firing control program or closure control program based on tissue conditions. A firing control program describes the distal motion of the displacement member. Different firing control programs are selected to better treat different tissue conditions. For example, when thicker tissue is present, the control circuit 710 is programmed to translate the displacement member at a lower velocity and / or with lower power. When thinner tissue is present, the control circuit 710 is programmed to translate the displacement member at a higher velocity and / or with higher power. A closure control program controls the closure force applied to the tissue by the anvil 716. Other control programs control the rotation of the shaft 740 and the articulation members 742a, 742b.
[0120] The control circuit 710 generates motor set point signals. The motor set point signals are provided to various motor controllers 708a-708e. The motor controllers 708a-708e comprise one or more circuits configured to provide motor drive signals to the motors 704a-704e to drive the motors 704a-704e as described herein. The motors 704a-704e may be brushed DC electric motors. The velocity of the motors 704a-704e are proportional to the respective motor drive signals. In some examples, the motors 704a-704e may be brushless DC electric motors, and the respective motor drive signals may comprise a PWM signal provided to one or more stator windings of the motors 704a-704e. Also, in some examples, the motor controllers 708a-708e may be omitted and the control circuit 710 may generate the motor drive signals directly.
[0121] The control circuit 710 initially operates each of the motors 704a-704e in an open-loop configuration for a first open-loop portion of a stroke of the displacement member. Based on the response of the robotic surgical instrument 700 during the open-loop portion of the stroke, the control circuit 710 selects a firing control program in a closed-loop configuration. The response of the instrument includes a translation distance of the displacement member during the open-loop portion, a time elapsed during the open-loop portion, the energy provided to one of the motors 704a-704e during the open-loop portion, a sum of pulse widths of a motor drive signal, etc. After the open-loop portion, the control circuit 710 implements the selected firing control program for a second portion of the displacement member stroke. For example, during a closed-loop portion of the stroke, the control circuit 710 modulates one of the motors 704a-704e based on translation data describing a position of the displacement member in a closed-loop manner to translate the displacement member at a constant velocity.
[0122] The motors 704a-704e receive power from an energy source 712. The energy source 712 is a DC power supply driven by a main alternating current power source, a battery, a super capacitor, or any other suitable energy source. The motors 704a-704e are mechanically coupled to individual movable mechanical elements such as the I-beam 714, anvil 716, shaft 740, articulation 742a, and articulation 742b via respective transmissions 706a-706e. The transmissions 706a-706e include one or more gears or other linkage components to couple the motors 704a-704e to movable mechanical elements. A position sensor 734 senses a position of the I-beam 714. The position sensor 734 includes any type of sensor that is capable of generating position data that indicate a position of the I-beam 714. The position sensor 734 includes an encoder configured to provide a series of pulses to the control circuit 710 as the I-beam 714 translates distally and proximally. The control circuit 710 tracks the pulses to determine the position of the I-beam 714. Other suitable position sensors may be used, including, for example, a proximity sensor. Other types of position sensors provide other signals indicating motion of the I-beam 714. Also, in some examples, the position sensor 734 may be omitted. Where any of the motors 704a-704e is a stepper motor, the control circuit 710 tracks the position of the I-beam 714 by aggregating the number and direction of steps that the motor 704 has been instructed to execute. The position sensor 734 is located in the end effector 702 or at any other portion of the instrument. The outputs of each of the motors 704a-704e include a torque sensor 744a-744e to sense force and have an encoder to sense rotation of the drive shaft.
[0123] The control circuit 710 is configured to drive a firing member such as the I-beam 714 portion of the end effector 702. The control circuit 710 provides a motor set point to a motor control 708a, which provides a drive signal to the motor 704a. The output shaft of the motor 704a is coupled to a torque sensor 744a. The torque sensor 744a is coupled to a transmission 706a which is coupled to the I-beam 714. The transmission 706a comprises movable mechanical elements such as rotating elements and a firing member to control the movement of the I-beam 714 distally and proximally along a longitudinal axis of the end effector 702. The motor 704a is coupled to the knife gear assembly, which includes a knife gear reduction set that includes a first knife drive gear and a second knife drive gear. A torque sensor 744a provides a firing force feedback signal to the control circuit 710. The firing force signal represents the force required to fire or displace the I-beam 714. A position sensor 734 is configured to provide the position of the I-beam 714 along the firing stroke or the position of the firing member as a feedback signal to the control circuit 710. The end effector 702 includes additional sensors 738 configured to provide feedback signals to the control circuit 710. When ready to use, the control circuit 710 provides a firing signal to the motor control 708a. In response to the firing signal, the motor 704a drives the firing member distally along the longitudinal axis of the end effector 702 from a proximal stroke start position to a stroke end position distal to the stroke start position. As the firing member translates distally, an I-beam 714, with a cutting element positioned at a distal end, advances distally to cut tissue located between the staple cartridge 718 and the anvil 716.
[0124] The control circuit 710 is configured to drive a closure member such as the anvil 716 portion of the end effector 702. The control circuit 710 provides a motor set point to a motor control 708b, which provides a drive signal to the motor 704b. The output shaft of the motor 704b is coupled to a torque sensor 744b. The torque sensor 744b is coupled to a transmission 706b which is coupled to the anvil 716. The transmission 706b comprises movable mechanical elements such as rotating elements and a closure member to control the movement of the anvil 716 from the open and closed positions. The motor 704b is coupled to a closure gear assembly, which includes a closure reduction gear set that is supported in meshing engagement with the closure spur gear. The torque sensor 744b provides a closure force feedback signal to the control circuit 710. The closure force feedback signal represents the closure force applied to the anvil 716. The position sensor 734 is configured to provide the position of the closure member as a feedback signal to the control circuit 710. Additional sensors 738 in the end effector 702 provide the closure force feedback signal to the control circuit 710. The pivotable anvil 716 is positioned opposite the staple cartridge 718. When ready to use, the control circuit 710 provides a closure signal to the motor control 708b. In response to the closure signal, the motor 704b advances a closure member to grasp tissue between the anvil 716 and the staple cartridge 718.
[0125] The control circuit 710 is configured to rotate a shaft member such as the shaft 740 to rotate the end effector 702. The control circuit 710 provides a motor set point to a motor control 708c, which provides a drive signal to the motor 704c. The output shaft of the motor 704c is coupled to a torque sensor 744c. The torque sensor 744c is coupled to a transmission 706c which is coupled to the shaft 740. The transmission 706c comprises movable mechanical elements such as rotating elements to control the rotation of the shaft 740 clockwise or counterclockwise up to and over 360°. The motor 704c is coupled to the rotational transmission assembly, which includes a tube gear segment that is formed on (or attached to) the proximal end of the proximal closure tube for operable engagement by a rotational gear assembly that is operably supported on the tool mounting plate. The torque sensor 744c provides a rotation force feedback signal to the control circuit 710. The rotation force feedback signal represents the rotation force applied to the shaft 740. The position sensor 734 is configured to provide the position of the closure member as a feedback signal to the control circuit 710. Additional sensors 738 such as a shaft encoder may provide the rotational position of the shaft 740 to the control circuit 710.
[0126] The control circuit 710 is configured to articulate the end effector 702. The control circuit 710 provides a motor set point to a motor control 708d, which provides a drive signal to the motor 704d. The output shaft of the motor 704d is coupled to a torque sensor 744d. The torque sensor 744d is coupled to a transmission 706d which is coupled to an articulation member 742a. The transmission 706d comprises movable mechanical elements such as articulation elements to control the articulation of the end effector 702 ±65°. The motor 704d is coupled to an articulation nut, which is rotatably journaled on the proximal end portion of the distal spine portion and is rotatably driven thereon by an articulation gear assembly. The torque sensor 744d provides an articulation force feedback signal to the control circuit 710. The articulation force feedback signal represents the articulation force applied to the end effector 702. Sensors 738, such as an articulation encoder, may provide the articulation position of the end effector 702 to the control circuit 710.
[0127] The articulation function of the robotic surgical system 700 comprises two articulation members, or links, 742a, 742b. These articulation members 742a, 742b are driven by separate disks on the robot interface (the rack) which are driven by the two motors 708d, 708e. When the separate firing motor 704a is provided, each of articulation links 742a, 742b can be antagonistically driven with respect to the other link in order to provide a resistive holding motion and a load to the head when it is not moving and to provide an articulation motion as the head is articulated. The articulation members 742a, 742b attach to the head at a fixed radius as the head is rotated. Accordingly, the mechanical advantage of the push-and-pull link changes as the head is rotated. This change in the mechanical advantage may be more pronounced with other articulation link drive systems.
[0128] The one or more motors 704a-704e comprises a brushed DC motor with a gearbox and mechanical links to a firing member, closure member, or articulation member. Another example includes electric motors 704a-704e that operate the movable mechanical elements such as the displacement member, articulation links, closure tube, and shaft. An outside influence is an unmeasured, unpredictable influence of things like tissue, surrounding bodies, and friction on the physical system. Such outside influence can be referred to as drag, which acts in opposition to one of electric motors 704a-704e. The outside influence, such as drag, may cause the operation of the physical system to deviate from a desired operation of the physical system.
[0129] The position sensor 734 is implemented as an absolute positioning system. The position sensor 734 comprises a magnetic rotary absolute positioning system implemented as an AS5055EQFT single-chip magnetic rotary position sensor available from Austria Microsystems, AG. The position sensor 734 interfaces with the control circuit 710 to provide an absolute positioning system. The position includes multiple Hall-effect elements located above a magnet and coupled to a CORDIC processor, also known as the digit-by-digit method and Volder's algorithm, that is provided to implement a simple and efficient algorithm to calculate hyperbolic and trigonometric functions that require only addition, subtraction, bitshift, and table lookup operations.
[0130] The control circuit 710 is in communication with one or more sensors 738. The sensors 738 are positioned on the end effector 702 and adapted to operate with the robotic surgical instrument 700 to measure the various derived parameters such as the gap distance versus time, tissue compression versus time, and anvil strain versus time. The sensors 738 comprise a magnetic sensor, a magnetic field sensor, a strain gauge, a load cell, a pressure sensor, a force sensor, a torque sensor, an inductive sensor such as an eddy current sensor, a resistive sensor, a capacitive sensor, an optical sensor, and / or any other suitable sensor for measuring one or more parameters of the end effector 702. The sensors 738 include one or more sensors. The sensors 738 are be located on the staple cartridge 718 deck to determine tissue location using segmented electrodes. The torque sensors 744a-744e are configured to sense force such as firing force, closure force, and / or articulation force, among others. Accordingly, the control circuit 710 can sense (1) the closure load experienced by the distal closure tube and its position, (2) the firing member at the rack and its position, (3) what portion of the staple cartridge 718 has tissue on it, and (4) the load and position on both articulation rods.
[0131] The one or more sensors 738 comprise a strain gauge, such as a micro-strain gauge, configured to measure the magnitude of the strain in the anvil 716 during a clamped condition. The strain gauge provides an electrical signal whose amplitude varies with the magnitude of the strain. The sensors 738 comprise a pressure sensor configured to detect a pressure generated by the presence of compressed tissue between the anvil 716 and the staple cartridge 718. The sensors 738 are configured to detect impedance of a tissue section located between the anvil 716 and the staple cartridge 718 that is indicative of the thickness and / or fullness of tissue located therebetween.
[0132] The sensors 738 are implemented as one or more limit switches, electromechanical devices, solid-state switches, Hall-effect devices, magneto-resistive (MR) devices, giant magneto-resistive (GMR) devices, magnetometers, among others. The sensors 738 may be implemented as solid-state switches that operate under the influence of light, such as optical sensors, IR sensors, ultraviolet sensors, among others. Still, the switches may be solid-state devices such as transistors (e.g., FET, junction FET, MOSFET, bipolar, and the like). The sensors 738 may include electrical conductorless switches, ultrasonic switches, accelerometers, and inertial sensors, among others.
[0133] The sensors 738 are configured to measure forces exerted on the anvil 716 by the closure drive system. For example, one or more sensors 738 are at an interaction point between the closure tube and the anvil 716 to detect the closure forces applied by the closure tube to the anvil 716. The forces exerted on the anvil 716 can be representative of the tissue compression experienced by the tissue section captured between the anvil 716 and the staple cartridge 718. The one or more sensors 738 are positioned at various interaction points along the closure drive system to detect the closure forces applied to the anvil 716 by the closure drive system. The one or more sensors 738 are sampled in real time during a clamping operation by the processor of the control circuit 710. The control circuit 710 receives real-time sample measurements to provide and analyze time-based information and assess, in real time, closure forces applied to the anvil 716.
[0134] A current sensor 736 is employed to measure the current drawn by each of the motors 704a-704e. The force required to advance any of the movable mechanical elements such as the I-beam 714 corresponds to the current drawn by one of the motors 704a-704e. The force is converted to a digital signal and provided to the control circuit 710. The control circuit 710 is configured to simulate the response of the actual system of the instrument in the software of the controller. A displacement member is actuated to move an I-beam 714 in the end effector 702 at or near a target velocity. The robotic surgical instrument 700 includes a feedback controller, which can be one of any feedback controllers, including, but not limited to a PID, a state feedback, a linear-quadratic (LQR), and / or an adaptive controller, for example. The robotic surgical instrument 700 includes a power source to convert the signal from the feedback controller into a physical input such as case voltage, PWM voltage, frequency modulated voltage, current, torque, and / or force, for example. Additional details are disclosed in U.S. Patent Application Serial No. 15 / 636,829, titled CLOSED LOOP VELOCITY CONTROL TECHNIQUES FOR ROBOTIC SURGICAL INSTRUMENT, filed June 29, 2017.
[0135] FIG. 18 illustrates a block diagram of a surgical instrument 750 programmed to control the distal translation of a displacement member. The surgical instrument 750 is programmed to control the distal translation of a displacement member such as the I-beam 764. The surgical instrument 750 comprises an end effector 752 that comprises an anvil 766, an I-beam 764 (including a sharp cutting edge), and a removable staple cartridge 768.
[0136] The position, movement, displacement, and / or translation of a linear displacement member, such as the I-beam 764, is measured by an absolute positioning system, sensor arrangement, and position sensor 784. Because the I-beam 764 is coupled to a longitudinally movable drive member, the position of the I-beam 764 is determined by measuring the position of the longitudinally movable drive member employing the position sensor 784. Accordingly, in the following description, the position, displacement, and / or translation of the I-beam 764 is achieved by the position sensor 784 as described herein. A control circuit 760 is programmed to control the translation of the displacement member, such as the I-beam 764. The control circuit 760, in some examples, comprises one or more microcontrollers, microprocessors, or other suitable processors for executing instructions that cause the processor or processors to control the displacement member, e.g., the I-beam 764, in the manner described. A timer / counter 781 provides an output signal, such as the elapsed time or a digital count, to the control circuit 760 to correlate the position of the I-beam 764 as determined by the position sensor 784 with the output of the timer / counter 781 such that the control circuit 760 can determine the position of the I-beam 764 at a specific time (t) relative to a starting position. The timer / counter 781 is configured to measure elapsed time, count external events, or time external events.
[0137] The control circuit 760 generates a motor set point signal 772. The motor set point signal 772 is provided to a motor controller 758. The motor controller 758 comprises one or more circuits configured to provide a motor drive signal 774 to the motor 754 to drive the motor 754 as described herein. In some examples, the motor 754 is a brushed DC electric motor. The velocity of the motor 754 is proportional to the motor drive signal 774. The motor 754 is a brushless DC electric motor and the motor drive signal 774 comprises a PWM signal provided to one or more stator windings of the motor 754. The motor controller 758 may be omitted, and the control circuit 760 generates the motor drive signal 774 directly.
[0138] The motor 754 receives power from an energy source 762. The energy source 762 may be or include a battery, a super capacitor, or any other suitable energy source. The motor 754 is mechanically coupled to the I-beam 764 via a transmission 756. The transmission 756 includes one or more gears or other linkage components to couple the motor 754 to the I-beam 764. A position sensor 784 senses a position of the I-beam 764. The position sensor 784 includes any type of sensor that is capable of generating position data that indicate a position of the I-beam 764. The position sensor 784 includes an encoder configured to provide a series of pulses to the control circuit 760 as the I-beam 764 translates distally and proximally. The control circuit 760 may track the pulses to determine the position of the I-beam 764. Other suitable position sensors are used, including, for example, a proximity sensor. Other types of position sensors provide other signals indicating motion of the I-beam 764.The position sensor 784 may be omitted. Where the motor 754 is a stepper motor, the control circuit 760 tracks the position of the I-beam 764 by aggregating the number and direction of steps that the motor 754 has been instructed to execute. The position sensor 784 is located in the end effector 752 or at any other portion of the instrument.
[0139] The control circuit 760 is in communication with one or more sensors 788. The sensors 788 are positioned on the end effector 752 and adapted to operate with the surgical instrument 750 to measure the various derived parameters such as gap distance versus time, tissue compression versus time, and anvil strain versus time. The sensors 788 comprise a magnetic sensor, a magnetic field sensor, a strain gauge, a pressure sensor, a force sensor, an inductive sensor such as an eddy current sensor, a resistive sensor, a capacitive sensor, an optical sensor, and / or any other suitable sensor for measuring one or more parameters of the end effector 752. The sensors 788 include one or more sensors.
[0140] The one or more sensors 788 comprise a strain gauge, such as a micro-strain gauge, configured to measure the magnitude of the strain in the anvil 766 during a clamped condition. The strain gauge provides an electrical signal whose amplitude varies with the magnitude of the strain. The sensors 788 comprise a pressure sensor configured to detect a pressure generated by the presence of compressed tissue between the anvil 766 and the staple cartridge 768. The sensors 788 are configured to detect impedance of a tissue section located between the anvil 766 and the staple cartridge 768 that is indicative of the thickness and / or fullness of tissue located therebetween.
[0141] The sensors 788 are configured to measure forces exerted on the anvil 766 by a closure drive system. For example, one or more sensors 788 can be at an interaction point between a closure tube and the anvil 766 to detect the closure forces applied by a closure tube to the anvil 766. The forces exerted on the anvil 766 can be representative of the tissue compression experienced by the tissue section captured between the anvil 766 and the staple cartridge 768. The one or more sensors 788 are positioned at various interaction points along the closure drive system to detect the closure forces applied to the anvil 766 by the closure drive system. The one or more sensors 788 are sampled in real time during a clamping operation by a processor of the control circuit 760. The control circuit 760 receives real-time sample measurements to provide and analyze time-based information and assess, in real time, closure forces applied to the anvil 766.
[0142] A current sensor 786 is employed to measure the current drawn by the motor 754. The force required to advance the I-beam 764 corresponds to the current drawn by the motor 754. The force is converted to a digital signal and provided to the control circuit 760.
[0143] The control circuit 760 is configured to simulate the response of the actual system of the instrument in the software of the controller. A displacement member is actuated to move an I-beam 764 in the end effector 752 at or near a target velocity. The surgical instrument 750 includes a feedback controller, which can be one of any feedback controllers, including, but not limited to a PID, a state feedback, LQR, and / or an adaptive controller, for example. The surgical instrument 750 includes a power source to convert the signal from the feedback controller into a physical input such as case voltage, PWM voltage, frequency modulated voltage, current, torque, and / or force, for example.
[0144] The actual drive system of the surgical instrument 750 is configured to drive the displacement member, cutting member, or I-beam 764, by a brushed DC motor with gearbox and mechanical links to an articulation and / or knife system. Another example is the electric motor 754 that operates the displacement member and the articulation driver, for example, of an interchangeable shaft assembly. An outside influence is an unmeasured, unpredictable influence of things like tissue, surrounding bodies and friction on the physical system. Such outside influence can be referred to as drag which acts in opposition to the electric motor 754. The outside influence, such as drag, causes the operation of the physical system to deviate from a desired operation of the physical system.
[0145] A surgical instrument 750 comprises an end effector 752 with motor-driven surgical stapling and cutting implements. A motor 754 drives a displacement member distally and proximally along a longitudinal axis of the end effector 752. The end effector 752 comprises a pivotable anvil 766 and, when configured for use, a staple cartridge 768 positioned opposite the anvil 766. A clinician grasps tissue between the anvil 766 and the staple cartridge 768, as described herein. When ready to use the instrument 750, the clinician provides a firing signal, for example by depressing a trigger of the instrument 750. In response to the firing signal, the motor 754 drives the displacement member distally along the longitudinal axis of the end effector 752 from a proximal stroke begin position to a stroke end position distal of the stroke begin position. As the displacement member translates distally, an I-beam 764 with a cutting element positioned at a distal end, cuts the tissue between the staple cartridge 768 and the anvil 766.
[0146] The surgical instrument 750 comprises a control circuit 760 programmed to control the distal translation of the displacement member, such as the I-beam 764, for example, based on one or more tissue conditions. The control circuit 760 is programmed to sense tissue conditions, such as thickness, either directly or indirectly, as described herein. The control circuit 760 is programmed to select a firing control program based on tissue conditions. A firing control program may describe the distal motion of the displacement member. Different firing control programs are selected to better treat different tissue conditions. For example, when thicker tissue is present, the control circuit 760 is programmed to translate the displacement member at a lower velocity and / or with lower power. When thinner tissue is present, the control circuit 760 is programmed to translate the displacement member at a higher velocity and / or with higher power.
[0147] The control circuit 760 initially operates the motor 754 in an open loop configuration for a first open loop portion of a stroke of the displacement member. Based on a response of the instrument 750 during the open loop portion of the stroke, the control circuit 760 selects a firing control program. The response of the instrument includes, a translation distance of the displacement member during the open loop portion, a time elapsed during the open loop portion, energy provided to the motor 754 during the open loop portion, a sum of pulse widths of a motor drive signal, etc. After the open loop portion, the control circuit 760 implements the selected firing control program for a second portion of the displacement member stroke. For example, during the closed loop portion of the stroke, the control circuit 760 modulates the motor 754 based on translation data describing a position of the displacement member in a closed loop manner to translate the displacement member at a constant velocity. Additional details are disclosed in U.S. Patent Application Serial No. 15 / 720,852, titled SYSTEM AND METHODS FOR CONTROLLING A DISPLAY OF A SURGICAL INSTRUMENT, filed September 29, 2017, .
[0148] FIG. 19 is a schematic diagram of a surgical instrument 790 configured to control various functions . The surgical instrument 790 is programmed to control distal translation of a displacement member such as the I-beam 764. The surgical instrument 790 comprises an end effector 792 that comprises an anvil 766, an I-beam 764, and a removable staple cartridge 768 which may be interchanged with an RF cartridge 796 (shown in dashed line).
[0149] Sensors 788 are implemented as a limit switch, electromechanical device, solid-state switches, Hall-effect devices, MR devices, GMR devices, magnetometers, among others. The sensors 638 are solid-state switches that operate under the influence of light, such as optical sensors, IR sensors, ultraviolet sensors, among others. Still, the switches are solid-state devices such as transistors (e.g., FET, junction FET, MOSFET, bipolar, and the like). The sensors 788 include electrical conductorless switches, ultrasonic switches, accelerometers, and inertial sensors, among others.
[0150] The position sensor 784 is implemented as an absolute positioning system comprising a magnetic rotary absolute positioning system implemented as an AS5055EQFT single-chip magnetic rotary position sensor available from Austria Microsystems, AG. The position sensor 784 interfaces with the control circuit 760 to provide an absolute positioning system. The position includes multiple Hall-effect elements located above a magnet and coupled to a CORDIC processor, also known as the digit-by-digit method and Volder's algorithm, that is provided to implement a simple and efficient algorithm to calculate hyperbolic and trigonometric functions that require only addition, subtraction, bitshift, and table lookup operations.
[0151] The I-beam 764 is implemented as a knife member comprising a knife body that operably supports a tissue cutting blade thereon and further includes anvil engagement tabs or features and channel engagement features or a foot. The staple cartridge 768 is implemented as a standard (mechanical) surgical fastener cartridge. The RF cartridge 796 is implemented as an RF cartridge. These and other sensors arrangements are described in commonly-owned U.S. Patent Application Serial No. 15 / 628,175, titled TECHNIQUES FOR ADAPTIVE CONTROL OF MOTOR VELOCITY OF A SURGICAL STAPLING AND CUTTING INSTRUMENT, filed June 20, 2017.
[0152] The position, movement, displacement, and / or translation of a linear displacement member, such as the I-beam 764, is measured by an absolute positioning system, sensor arrangement, and position sensor represented as position sensor 784. Because the I-beam 764 is coupled to the longitudinally movable drive member, the position of the I-beam 764 is determined by measuring the position of the longitudinally movable drive member employing the position sensor 784. Accordingly, in the following description, the position, displacement, and / or translation of the I-beam 764 is achieved by the position sensor 784 as described herein. A control circuit 760 is programmed to control the translation of the displacement member, such as the I-beam 764, as described herein. The control circuit 760, in some examples, comprises one or more microcontrollers, microprocessors, or other suitable processors for executing instructions that cause the processor or processors to control the displacement member, e.g., the I-beam 764, in the manner described. A timer / counter 781 provides an output signal, such as the elapsed time or a digital count, to the control circuit 760 to correlate the position of the I-beam 764 as determined by the position sensor 784 with the output of the timer / counter 781 such that the control circuit 760 can determine the position of the I-beam 764 at a specific time (t) relative to a starting position. The timer / counter 781 is configured to measure elapsed time, count external events, or time external events.
[0153] The control circuit 760 generates a motor set point signal 772. The motor set point signal 772 is provided to a motor controller 758. The motor controller 758 comprises one or more circuits configured to provide a motor drive signal 774 to the motor 754 to drive the motor 754 as described herein. The motor 754 is a brushed DC electric motor. The velocity of the motor 754 is proportional to the motor drive signal 774. In some examples, the motor 754 is a brushless DC electric motor and the motor drive signal 774 may comprise a PWM signal provided to one or more stator windings of the motor 754. Also, in some examples, the motor controller 758 is omitted, and the control circuit 760 generates the motor drive signal 774 directly.
[0154] The motor 754 receives power from an energy source 762. The energy source 762 may be or include a battery, a super capacitor, or any other suitable energy source. The motor 754 is mechanically coupled to the I-beam 764 via a transmission 756. The transmission 756 includes one or more gears or other linkage components to couple the motor 754 to the I-beam 764. A position sensor 784 senses a position of the I-beam 764. The position sensor 784 includes any type of sensor that is capable of generating position data that indicate a position of the I-beam 764. The position sensor 784 includes an encoder configured to provide a series of pulses to the control circuit 760 as the I-beam 764 translates distally and proximally. The control circuit 760 tracks the pulses to determine the position of the I-beam 764. Other suitable position sensors are used, including, for example, a proximity sensor. Other types of position sensors provide other signals indicating motion of the I-beam 764. Also, in some examples, the position sensor 784 is omitted. Where the motor 754 is a stepper motor, the control circuit 760 tracks the position of the I-beam 764 by aggregating the number and direction of steps that the motor has been instructed to execute. The position sensor 784 is located in the end effector 792 or at any other portion of the instrument.
[0155] The control circuit 760 is in communication with one or more sensors 788. The sensors 788 are positioned on the end effector 792 and adapted to operate with the surgical instrument 790 to measure the various derived parameters such as gap distance versus time, tissue compression versus time, and anvil strain versus time. The sensors 788 comprise a magnetic sensor, a magnetic field sensor, a strain gauge, a pressure sensor, a force sensor, an inductive sensor such as an eddy current sensor, a resistive sensor, a capacitive sensor, an optical sensor, and / or any other suitable sensor for measuring one or more parameters of the end effector 792. The sensors 788 include one or more sensors.
[0156] The one or more sensors 788 comprise a strain gauge, such as a micro-strain gauge, configured to measure the magnitude of the strain in the anvil 766 during a clamped condition. The strain gauge provides an electrical signal whose amplitude varies with the magnitude of the strain. The sensors 788 comprise a pressure sensor configured to detect a pressure generated by the presence of compressed tissue between the anvil 766 and the staple cartridge 768. The sensors 788 are configured to detect impedance of a tissue section located between the anvil 766 and the staple cartridge 768 that is indicative of the thickness and / or fullness of tissue located therebetween.
[0157] The sensors 788 are configured to measure forces exerted on the anvil 766 by the closure drive system. For example, one or more sensors 788 is at an interaction point between a closure tube and the anvil 766 to detect the closure forces applied by a closure tube to the anvil 766. The forces exerted on the anvil 766 are representative of the tissue compression experienced by the tissue section captured between the anvil 766 and the staple cartridge 768. The one or more sensors 788 are positioned at various interaction points along the closure drive system to detect the closure forces applied to the anvil 766 by the closure drive system. The one or more sensors 788 are sampled in real time during a clamping operation by a processor portion of the control circuit 760. The control circuit 760 receives real-time sample measurements to provide and analyze time-based information and assess, in real time, closure forces applied to the anvil 766.
[0158] A current sensor 786 is employed to measure the current drawn by the motor 754. The force required to advance the I-beam 764 corresponds to the current drawn by the motor 754. The force is converted to a digital signal and provided to the control circuit 760.
[0159] An RF energy source 794 is coupled to the end effector 792 and is applied to the RF cartridge 796 when the RF cartridge 796 is loaded in the end effector 792 in place of the staple cartridge 768. The control circuit 760 controls the delivery of the RF energy to the RF cartridge 796.
[0160] Additional details are disclosed in U.S. Patent Application Serial No. 15 / 636,096, titled SURGICAL SYSTEM COUPLABLE WITH STAPLE CARTRIDGE AND RADIO FREQUENCY CARTRIDGE, AND METHOD OF USING SAME, filed June 28, 2017.Generator Hardware
[0161] FIG. 20 is a simplified block diagram of a generator 800 configured to provide inductorless tuning, among other benefits. Additional details of the generator 800 are described in U.S. Patent No. 9,060,775, titled SURGICAL GENERATOR FOR ULTRASONIC AND ELECTROSURGICAL DEVICES, which issued on June 23, 2015, . The generator 800 comprises a patient isolated stage 802 in communication with a non-isolated stage 804 via a power transformer 806. A secondary winding 808 of the power transformer 806 is contained in the isolated stage 802 and comprises a tapped configuration (e.g., a center-tapped or a non-center-tapped configuration) to define drive signal outputs 810a, 810b, 810c for delivering drive signals to different surgical instruments, such as, for example, an ultrasonic surgical instrument, an RF electrosurgical instrument, and a multifunction surgical instrument which includes ultrasonic and RF energy modes that can be delivered alone or simultaneously. In particular, drive signal outputs 810a, 810c output an ultrasonic drive signal (e.g., a 420V root-mean-square (RMS) drive signal) to an ultrasonic surgical instrument, and drive signal outputs 810b, 810c output an RF electrosurgical drive signal (e.g., a 100V RMS drive signal) to an RF electrosurgical instrument, with the drive signal output 810b corresponding to the center tap of the power transformer 806.
[0162] The ultrasonic and electrosurgical drive signals are provided simultaneously to distinct surgical instruments and / or to a single surgical instrument, such as the multifunction surgical instrument, having the capability to deliver both ultrasonic and electrosurgical energy to tissue. It will be appreciated that the electrosurgical signal, provided either to a dedicated electrosurgical instrument and / or to a combined multifunction ultrasonic / electrosurgical instrument is either a therapeutic or sub-therapeutic level signal where the sub-therapeutic signal is used, for example, to monitor tissue or instrument conditions and provide feedback to the generator. For example, the ultrasonic and RF signals are delivered separately or simultaneously from a generator with a single output port in order to provide the desired output signal to the surgical instrument, as will be discussed in more detail below. Accordingly, the generator combines the ultrasonic and electrosurgical RF energies and deliver the combined energies to the multifunction ultrasonic / electrosurgical instrument. Bipolar electrodes are placed on one or both jaws of the end effector. One jaw may be driven by ultrasonic energy in addition to electrosurgical RF energy, working simultaneously. The ultrasonic energy is employed to dissect tissue, while the electrosurgical RF energy is employed for vessel sealing.
[0163] The non-isolated stage 804 comprises a power amplifier 812 having an output connected to a primary winding 814 of the power transformer 806. The power amplifier 812 comprises a push-pull amplifier. The non-isolated stage 804 further comprises a logic device 816 for supplying a digital output to a digital-to-analog converter (DAC) circuit 818, which in turn supplies a corresponding analog signal to an input of the power amplifier 812. In certain forms, the logic device 816 comprises a programmable gate array (PGA), a FPGA, programmable logic device (PLD), among other logic circuits, for example. The logic device 816, by virtue of controlling the input of the power amplifier 812 via the DAC circuit 818, therefore controls any of a number of parameters (e.g., frequency, waveform shape, waveform amplitude) of drive signals appearing at the drive signal outputs 810a, 810b, 810c. As discussed below, the logic device 816, in conjunction with a processor (e.g., a DSP discussed below), implements a number of DSP-based and / or other control algorithms to control parameters of the drive signals output by the generator 800.
[0164] Power is supplied to a power rail of the power amplifier 812 by a switch-mode regulator 820, e.g., a power converter. The switch-mode regulator 820 comprises an adjustable buck regulator. The non-isolated stage 804 further comprises a first processor 822, which in one form comprises a DSP processor such as an Analog Devices ADSP-21469 SHARC DSP, available from Analog Devices, Norwood, MA, for example, although in various forms any suitable processor is employed. The DSP processor 822 controls the operation of the switch-mode regulator 820 responsive to voltage feedback data received from the power amplifier 812 by the DSP processor 822 via an ADC circuit 824. The DSP processor 822 receives as input, via the ADC circuit 824, the waveform envelope of a signal (e.g., an RF signal) being amplified by the power amplifier 812. The DSP processor 822 then controls the switch-mode regulator 820 (e.g., via a PWM output) such that the rail voltage supplied to the power amplifier 812 tracks the waveform envelope of the amplified signal. By dynamically modulating the rail voltage of the power amplifier 812 based on the waveform envelope, the efficiency of the power amplifier 812 is significantly improved relative to a fixed rail voltage amplifier schemes.
[0165] The logic device 816, in conjunction with the DSP processor 822, implements a digital synthesis circuit such as a direct digital synthesizer control scheme to control the waveform shape, frequency, and / or amplitude of drive signals output by the generator 800. The logic device 816 implements a DDS control algorithm by recalling waveform samples stored in a dynamically updated lookup table (LUT), such as a RAM LUT, which are embedded in an FPGA. This control algorithm is particularly useful for ultrasonic applications in which an ultrasonic transducer, such as an ultrasonic transducer, is driven by a clean sinusoidal current at its resonant frequency. Because other frequencies may excite parasitic resonances, minimizing or reducing the total distortion of the motional branch current may correspondingly minimize or reduce undesirable resonance effects. Because the waveform shape of a drive signal output by the generator 800 is impacted by various sources of distortion present in the output drive circuit (e.g., the power transformer 806, the power amplifier 812), voltage and current feedback data based on the drive signal is input into an algorithm, such as an error control algorithm implemented by the DSP processor 822, which compensates for distortion by suitably pre-distorting or modifying the waveform samples stored in the LUT on a dynamic, ongoing basis (e.g., in real time). In one form, the amount or degree of pre-distortion applied to the LUT samples is based on the error between a computed motional branch current and a desired current waveform shape, with the error being determined on a sample-by-sample basis. In this way, the pre-distorted LUT samples, when processed through the drive circuit, results in a motional branch drive signal having the desired waveform shape (e.g., sinusoidal) for optimally driving the ultrasonic transducer. In such forms, the LUT waveform samples will therefore not represent the desired waveform shape of the drive signal, but rather the waveform shape that is required to ultimately produce the desired waveform shape of the motional branch drive signal when distortion effects are taken into account.
[0166] The non-isolated stage 804 further comprises a first ADC circuit 826 and a second ADC circuit 828 coupled to the output of the power transformer 806 via respective isolation transformers 830, 832 for respectively sampling the voltage and current of drive signals output by the generator 800. In certain forms, the ADC circuits 826, 828 are configured to sample at high speeds (e.g., 80 mega samples per second (MSPS)) to enable oversampling of the drive signals. In one form, for example, the sampling speed of the ADC circuits 826, 828 enable approximately 200x (depending on frequency) oversampling of the drive signals. In certain forms, the sampling operations of the ADC circuit 826, 828 are performed by a single ADC circuit receiving input voltage and current signals via a two-way multiplexer. The use of highspeed sampling in forms of the generator 800 enable, among other things, calculation of the complex current flowing through the motional branch (which is used in certain forms to implement DDS-based waveform shape control described above), accurate digital filtering of the sampled signals, and calculation of real power consumption with a high degree of precision. Voltage and current feedback data output by the ADC circuits 826, 828 is received and processed (e.g., first-in-first-out (FIFO) buffer, multiplexer) by the logic device 816 and stored in data memory for subsequent retrieval by, for example, the DSP processor 822. As noted above, voltage and current feedback data is used as input to an algorithm for pre-distorting or modifying LUT waveform samples on a dynamic and ongoing basis. This requires each stored voltage and current feedback data pair to be indexed based on, or otherwise associated with, a corresponding LUT sample that was output by the logic device 816 when the voltage and current feedback data pair was acquired. Synchronization of the LUT samples and the voltage and current feedback data in this manner contributes to the correct timing and stability of the pre-distortion algorithm.
[0167] The voltage and current feedback data is used to control the frequency and / or amplitude (e.g., current amplitude) of the drive signals. In one form, for example, voltage and current feedback data is used to determine impedance phase. The frequency of the drive signal may then be controlled to minimize or reduce the difference between the determined impedance phase and an impedance phase setpoint (e.g., 0°), thereby minimizing or reducing the effects of harmonic distortion and correspondingly enhancing impedance phase measurement accuracy. The determination of phase impedance and a frequency control signal is implemented in the DSP processor 822, for example, with the frequency control signal being supplied as input to a DDS control algorithm implemented by the logic device 816.
[0168] The current feedback data is monitored in order to maintain the current amplitude of the drive signal at a current amplitude setpoint. The current amplitude setpoint is specified directly or determined indirectly based on specified voltage amplitude and power setpoints. Control of the current amplitude is implemented by control algorithm, such as, for example, a proportional-integral-derivative (PID) control algorithm, in the DSP processor 822. Variables controlled by the control algorithm to suitably control the current amplitude of the drive signal include, for example, the scaling of the LUT waveform samples stored in the logic device 816 and / or the full-scale output voltage of the DAC circuit 818 (which supplies the input to the power amplifier 812) via a DAC circuit 834.
[0169] The non-isolated stage 804 further comprises a second processor 836 for providing, among other things user interface (UI) functionality. The UI processor 836 may comprise an Atmel AT91SAM9263 processor having an ARM 926EJ-S core, available from Atmel Corporation, San Jose, California, for example. Examples of UI functionality supported by the UI processor 836 include audible and visual user feedback, communication with peripheral devices (e.g., via a USB interface), communication with a foot switch, communication with an input device (e.g., a touch screen display) and communication with an output device (e.g., a speaker). The UI processor 836 communicates with the DSP processor 822 and the logic device 816 (e.g., via SPI buses). Although the UI processor 836 may primarily support UI functionality, it also coordinates with the DSP processor 822 to implement hazard mitigation in certain forms. For example, the UI processor 836 may be programmed to monitor various aspects of user input and / or other inputs (e.g., touch screen inputs, foot switch inputs, temperature sensor inputs) and disables the drive output of the generator 800 when an erroneous condition is detected.
[0170] Both the DSP processor 822 and the UI processor 836determine and monitor the operating state of the generator 800. For the DSP processor 822, the operating state of the generator 800 dictates, for example, which control and / or diagnostic processes are implemented by the DSP processor 822. For the UI processor 836, the operating state of the generator 800 dictates, for example, which elements of a UI (e.g., display screens, sounds) are presented to a user. The respective DSP and UI processors 822, 836 independently maintain the current operating state of the generator 800 and recognize and evaluate possible transitions out of the current operating state. The DSP processor 822 functions as the master in this relationship and determine when transitions between operating states are to occur. The UI processor 836 is aware of valid transitions between operating states and confirms if a particular transition is appropriate. For example, when the DSP processor 822 instructs the UI processor 836 to transition to a specific state, the UI processor 836 verifies that requested transition is valid. In the event that a requested transition between states is determined to be invalid by the UI processor 836, the UI processor 836 causes the generator 800 to enter a failure mode.
[0171] The non-isolated stage 804 further comprises a controller 838 for monitoring input devices (e.g., a capacitive touch sensor used for turning the generator 800 on and off, a capacitive touch screen). The controller 838 comprises at least one processor and / or other controller device in communication with the UI processor 836. In one form, for example, the controller 838 comprises a processor (e.g., a Meg168 8-bit controller available from Atmel) configured to monitor user input provided via one or more capacitive touch sensors. The controller 838 comprises a touch screen controller (e.g., a QT5480 touch screen controller available from Atmel) to control and manage the acquisition of touch data from a capacitive touch screen.
[0172] When the generator 800 is in a "power off" state, the controller 838 continues to receive operating power (e.g., via a line from a power supply of the generator 800, such as the power supply 854 discussed below). In this way, the controller 838 continues to monitor an input device (e.g., a capacitive touch sensor located on a front panel of the generator 800) for turning the generator 800 on and off. When the generator 800 is in the power off state, the controller 838 wakes the power supply (e.g., enable operation of one or more DC / DC voltage converters 856 of the power supply 854) if activation of the "on / off" input device by a user is detected. The controller 838 therefore initiates a sequence for transitioning the generator 800 to a "power on" state. Conversely, the controller 838 may initiate a sequence for transitioning the generator 800 to the power off state if activation of the "on / off" input device is detected when the generator 800 is in the power on state. The controller 838 reports activation of the "on / off" input device to the UI processor 836, which in turn implements the necessary process sequence for transitioning the generator 800 to the power off state. The controller 838 has no independent ability for causing the removal of power from the generator 800 after its power on state has been established.
[0173] The controller 838 causes the generator 800 to provide audible or other sensory feedback for alerting the user that a power on or power off sequence has been initiated. Such an alert is provided at the beginning of a power on or power off sequence and prior to the commencement of other processes associated with the sequence.
[0174] The isolated stage 802 comprises an instrument interface circuit 840 to, for example, provide a communication interface between a control circuit of a surgical instrument (e.g., a control circuit comprising handpiece switches) and components of the non-isolated stage 804, such as, for example, the logic device 816, the DSP processor 822, and / or the UI processor 836. The instrument interface circuit 840 exchanges information with components of the non-isolated stage 804 via a communication link that maintains a suitable degree of electrical isolation between the isolated and non-isolated stages 802, 804, such as, for example, an IR-based communication link. Power is supplied to the instrument interface circuit 840 using, for example, a low-dropout voltage regulator powered by an isolation transformer driven from the non-isolated stage 804.
[0175] The instrument interface circuit 840 comprises a logic circuit 842 (e.g., logic circuit, programmable logic circuit, PGA, FPGA, PLD) in communication with a signal conditioning circuit 844. The signal conditioning circuit 844 is configured to receive a periodic signal from the logic circuit 842 (e.g., a 2 kHz square wave) to generate a bipolar interrogation signal having an identical frequency. The interrogation signal is generated, for example, using a bipolar current source fed by a differential amplifier. The interrogation signal is communicated to a surgical instrument control circuit (e.g., by using a conductive pair in a cable that connects the generator 800 to the surgical instrument) and monitored to determine a state or configuration of the control circuit. The control circuit comprises a number of switches, resistors, and / or diodes to modify one or more characteristics (e.g., amplitude, rectification) of the interrogation signal such that a state or configuration of the control circuit is uniquely discernable based on the one or more characteristics. In one form, for example, the signal conditioning circuit 844 comprises an ADC circuit for generating samples of a voltage signal appearing across inputs of the control circuit resulting from passage of interrogation signal therethrough. The logic circuit 842 (or a component of the non-isolated stage 804) then determines the state or configuration of the control circuit based on the ADC circuit samples.
[0176] The instrument interface circuit 840 comprises a first data circuit interface 846 to enable information exchange between the logic circuit 842 (or other element of the instrument interface circuit 840) and a first data circuit disposed in or otherwise associated with a surgical instrument. A first data circuit is disposed in a cable integrally attached to a surgical instrument handpiece or in an adaptor for interfacing a specific surgical instrument type or model with the generator 800. The first data circuit is implemented in any suitable manner and communicates with the generator according to any suitable protocol, including, for example, as described herein with respect to the first data circuit. The first data circuit comprise a non-volatile storage device, such as an EEPROM device. The first data circuit interface 846 is implemented separately from the logic circuit 842 and comprise suitable circuitry (e.g., discrete logic devices, a processor) to enable communication between the logic circuit 842 and the first data circuit. The first data circuit interface 846 is integral with the logic circuit 842.
[0177] The first data circuit stores information pertaining to the particular surgical instrument with which it is associated. Such information includes, for example, a model number, a serial number, a number of operations in which the surgical instrument has been used, and / or any other type of information. This information is read by the instrument interface circuit 840 (e.g., by the logic circuit 842), transferred to a component of the non-isolated stage 804 (e.g., to logic device 816, DSP processor 822, and / or UI processor 836) for presentation to a user via an output device and / or for controlling a function or operation of the generator 800. Additionally, any type of information is communicated to the first data circuit for storage therein via the first data circuit interface 846 (e.g., using the logic circuit 842). Such information comprises, for example, an updated number of operations in which the surgical instrument has been used and / or dates and / or times of its usage.
[0178] As discussed previously, a surgical instrument is detachable from a handpiece (e.g., the multifunction surgical instrument may be detachable from the handpiece) to promote instrument interchangeability and / or disposability. In such cases, conventional generators are limited in their ability to recognize particular instrument configurations being used and to optimize control and diagnostic processes accordingly. The addition of readable data circuits to surgical instruments to address this issue is problematic from a compatibility standpoint, however. For example, designing a surgical instrument to remain backwardly compatible with generators that lack the requisite data reading functionality may be impractical due to, for example, differing signal schemes, design complexity, and cost. Forms of instruments discussed herein address these concerns by using data circuits that are implemented in existing surgical instruments economically and with minimal design changes to preserve compatibility of the surgical instruments with current generator platforms.
[0179] Additionally, forms of the generator 800 enable communication with instrument-based data circuits. For example, the generator 800 is configured to communicate with a second data circuit contained in an instrument (e.g., the multifunction surgical instrument). In some forms, the second data circuit is implemented in a many similar to that of the first data circuit described herein. The instrument interface circuit 840 comprises a second data circuit interface 848 to enable this communication. The second data circuit interface 848 comprises a tri-state digital interface, although other interfaces may also be used. In certain forms, the second data circuit is generally any circuit for transmitting and / or receiving data. The second data circuit stores information pertaining to the particular surgical instrument with which it is associated. Such information includes, for example, a model number, a serial number, a number of operations in which the surgical instrument has been used, and / or any other type of information.
[0180] The second data circuit stores information about the electrical and / or ultrasonic properties of an associated ultrasonic transducer, end effector, or ultrasonic drive system. For example, the first data circuit indicates a burn-in frequency slope, as described herein. Additionally or alternatively, any type of information is communicated to second data circuit for storage therein via the second data circuit interface 848 (e.g., using the logic circuit 842). Such information comprises, for example, an updated number of operations in which the instrument has been used and / or dates and / or times of its usage. In certain forms, the second data circuit may transmit data acquired by one or more sensors (e.g., an instrument-based temperature sensor). In certain forms, the second data circuit receives data from the generator 800 and provide an indication to a user (e.g., a light emitting diode indication or other visible indication) based on the received data.
[0181] The second data circuit and the second data circuit interface 848 is configured such that communication between the logic circuit 842 and the second data circuit can be effected without the need to provide additional conductors for this purpose (e.g., dedicated conductors of a cable connecting a handpiece to the generator 800). Information is communicated to and from the second data circuit using a one-wire bus communication scheme implemented on existing cabling, such as one of the conductors used transmit interrogation signals from the signal conditioning circuit 844 to a control circuit in a handpiece. In this way, design changes or modifications to the surgical instrument that might otherwise be necessary are minimized or reduced. Moreover, because different types of communications implemented over a common physical channel can be frequency-band separated, the presence of a second data circuit is "invisible" to generators that do not have the requisite data reading functionality, thus enabling backward compatibility of the surgical instrument.
[0182] The isolated stage 802 comprises at least one blocking capacitor 850-1 connected to the drive signal output 810b to prevent passage of DC current to a patient. A single blocking capacitor is required to comply with medical regulations or standards, for example. While failure in single-capacitor designs is relatively uncommon, such failure nonetheless has negative consequences. A second blocking capacitor 850-2 is provided in series with the blocking capacitor 850-1, with current leakage from a point between the blocking capacitors 850-1, 850-2 being monitored by an ADC circuit 852 for sampling a voltage induced by leakage current. The samples are received by the logic circuit 842, for example. Based changes in the leakage current (as indicated by the voltage samples), the generator 800 determines when at least one of the blocking capacitors 850-1, 850-2 has failed, thus providing a benefit over single-capacitor designs having a single point of failure.
[0183] In certain forms, the non-isolated stage 804 comprises a power supply 854 for delivering DC power at a suitable voltage and current. The power supply comprises, for example, a 400 W power supply for delivering a 48 VDC system voltage. The power supply 854 further comprises one or more DC / DC voltage converters 856 for receiving the output of the power supply to generate DC outputs at the voltages and currents required by the various components of the generator 800. As discussed above in connection with the controller 838, one or more of the DC / DC voltage converters 856 may receive an input from the controller 838 when activation of the "on / off" input device by a user is detected by the controller 838 to enable operation of, or wake, the DC / DC voltage converters 856.
[0184] FIG. 21 illustrates an example of a generator 900, which is one form of the generator 800 (FIG. 20). The generator 900 is configured to deliver multiple energy modalities to a surgical instrument. The generator 900 provides RF and ultrasonic signals for delivering energy to a surgical instrument either independently or simultaneously. The RF and ultrasonic signals are provided alone or in combination and are provided simultaneously. As noted above, at least one generator output can deliver multiple energy modalities (e.g., ultrasonic, bipolar or monopolar RF, irreversible and / or reversible electroporation, and / or microwave energy, among others) through a single port, and these signals can be delivered separately or simultaneously to the end effector to treat tissue.
[0185] The generator 900 comprises a processor 902 coupled to a waveform generator 904. The processor 902 and waveform generator 904 are configured to generate a variety of signal waveforms based on information stored in a memory coupled to the processor 902, not shown for clarity of disclosure. The digital information associated with a waveform is provided to the waveform generator 904 which includes one or more DAC circuits to convert the digital input into an analog output. The analog output is fed to an amplifier 1106 for signal conditioning and amplification. The conditioned and amplified output of the amplifier 906 is coupled to a power transformer 908. The signals are coupled across the power transformer 908 to the secondary side, which is in the patient isolation side. A first signal of a first energy modality is provided to the surgical instrument between the terminals labeled ENERGY1 and RETURN. A second signal of a second energy modality is coupled across a capacitor 910 and is provided to the surgical instrument between the terminals labeled ENERGY2 and RETURN. It will be appreciated that more than two energy modalities may be output and thus the subscript "n" may be used to designate that up to n ENERGYn terminals may be provided, where n is a positive integer greater than 1. It also will be appreciated that up to "n" return paths RETURNn may be provided without departing from the scope of the present disclosure.
[0186] A first voltage sensing circuit 912 is coupled across the terminals labeled ENERGY1 and the RETURN path to measure the output voltage therebetween. A second voltage sensing circuit 924 is coupled across the terminals labeled ENERGY2 and the RETURN path to measure the output voltage therebetween. A current sensing circuit 914 is disposed in series with the RETURN leg of the secondary side of the power transformer 908 as shown to measure the output current for either energy modality. If different return paths are provided for each energy modality, then a separate current sensing circuit should be provided in each return leg. The outputs of the first and second voltage sensing circuits 912, 924 are provided to respective isolation transformers 916, 922 and the output of the current sensing circuit 914 is provided to another isolation transformer 918. The outputs of the isolation transformers 916, 928, 922 in the on the primary side of the power transformer 908 (non-patient isolated side) are provided to a one or more ADC circuit 926. The digitized output of the ADC circuit 926 is provided to the processor 902 for further processing and computation. The output voltages and output current feedback information can be employed to adjust the output voltage and current provided to the surgical instrument and to compute output impedance, among other parameters. Input / output communications between the processor 902 and patient isolated circuits is provided through an interface circuit 920. Sensors also may be in electrical communication with the processor 902 by way of the interface circuit 920.
[0187] The impedance is determined by the processor 902 by dividing the output of either the first voltage sensing circuit 912 coupled across the terminals labeled ENERGY1 / RETURN or the second voltage sensing circuit 924 coupled across the terminals labeled ENERGY2 / RETURN by the output of the current sensing circuit 914 disposed in series with the RETURN leg of the secondary side of the power transformer 908. The outputs of the first and second voltage sensing circuits 912, 924 are provided to separate isolations transformers 916, 922 and the output of the current sensing circuit 914 is provided to another isolation transformer 916. The digitized voltage and current sensing measurements from the ADC circuit 926 are provided the processor 902 for computing impedance. As an example, the first energy modality ENERGY1 is ultrasonic energy and the second energy modality ENERGY2 is RF energy. Nevertheless, in addition to ultrasonic and bipolar or monopolar RF energy modalities, other energy modalities include irreversible and / or reversible electroporation and / or microwave energy, among others. Also, although the example illustrated in FIG. 21 shows a single return path RETURN is provided for two or more energy modalities, multiple return paths RETURNn may be provided for each energy modality ENERGYn. Thus, as described herein, the ultrasonic transducer impedance is measured by dividing the output of the first voltage sensing circuit 912 by the current sensing circuit 914 and the tissue impedance is measured by dividing the output of the second voltage sensing circuit 924 by the current sensing circuit 914.
[0188] As shown in FIG. 21, the generator 900 comprising at least one output port can include a power transformer 908 with a single output and with multiple taps to provide power in the form of one or more energy modalities, such as ultrasonic, bipolar or monopolar RF, irreversible and / or reversible electroporation, and / or microwave energy, among others, for example, to the end effector depending on the type of treatment of tissue being performed. For example, the generator 900 can deliver energy with higher voltage and lower current to drive an ultrasonic transducer, with lower voltage and higher current to drive RF electrodes for sealing tissue, or with a coagulation waveform for spot coagulation using either monopolar or bipolar RF electrosurgical electrodes. The output waveform from the generator 900 can be steered, switched, or filtered to provide the frequency to the end effector of the surgical instrument. The connection of an ultrasonic transducer to the generator 900 output would be preferably located between the output labeled ENERGY1 and RETURN as shown in FIG. 21. In one example, a connection of RF bipolar electrodes to the generator 900 output would be preferably located between the output labeled ENERGY2 and RETURN. In the case of monopolar output, the preferred connections would be active electrode (e.g., pencil or other probe) to the ENERGY2 output and a suitable return pad connected to the RETURN output.
[0189] Additional details are disclosed in U.S. Patent Application Publication No. 2017 / 0086914, titled TECHNIQUES FOR OPERATING GENERATOR FOR DIGITALLY GENERATING ELECTRICAL SIGNAL WAVEFORMS AND SURGICAL INSTRUMENTS, which published on March 30, 2017.
[0190] As used throughout this description, the term "wireless" and its derivatives is used to describe circuits, devices, systems, methods, techniques, communications channels, etc., that communicate data through the use of modulated electromagnetic radiation through a non-solid medium. The term does not imply that the associated devices do not contain any wires, although in some aspects they might not. The communication module implements any of a number of wireless or wired communication standards or protocols, including but not limited to Wi-Fi (IEEE 802.11 family), WiMAX (IEEE 802.16 family), IEEE 802.20, long term evolution (LTE), Ev-DO, HSPA+, HSDPA+, HSUPA+, EDGE, GSM, GPRS, CDMA, TDMA, DECT, Bluetooth, Ethernet derivatives thereof, as well as any other wireless and wired protocols that are designated as 3G, 4G, 5G, and beyond. The computing module includes a plurality of communication modules. A first communication module is dedicated to shorter range wireless communications such as Wi-Fi and Bluetooth and a second communication module is dedicated to longer range wireless communications such as GPS, EDGE, GPRS, CDMA, WiMAX, LTE, Ev-DO, and others.
[0191] As used herein a processor or processing unit is an electronic circuit which performs operations on some external data source, usually memory or some other data stream. The term is used herein to refer to the central processor (central processing unit) in a system or computer systems (especially systems on a chip (SoCs)) that combine a number of specialized "processors."
[0192] As used herein, a system on a chip or system on chip (SoC or SOC) is an integrated circuit (also known as an "IC" or "chip") that integrates all components of a computer or other electronic systems. It contains digital, analog, mixed-signal, and often radio-frequency functions-all on a single substrate. A SoC integrates a microcontroller (or microprocessor) with advanced peripherals like graphics processing unit (GPU), Wi-Fi module, or coprocessor. A SoC may contain built-in memory.
[0193] As used herein, a microcontroller or controller is a system that integrates a microprocessor with peripheral circuits and memory. A microcontroller (or MCU for microcontroller unit) is implemented as a small computer on a single integrated circuit. It is similar to a SoC; an SoC includes a microcontroller as one of its components. A microcontroller contains one or more core processing units (CPUs) along with memory and programmable input / output peripherals. Program memory in the form of Ferroelectric RAM, NOR flash or OTP ROM is also often included on chip, as well as a small amount of RAM. Microcontrollers are employed for embedded applications, in contrast to the microprocessors used in personal computers or other general purpose applications consisting of various discrete chips.
[0194] As used herein, the term controller or microcontroller is a stand-alone IC or chip device that interfaces with a peripheral device. This is a link between two parts of a computer or a controller on an external device that manages the operation of (and connection with) that device.
[0195] Any of the processors or microcontrollers described herein, are implemented by any single core or multicore processor such as those known under the trade name ARM Cortex by Texas Instruments. The processor may be an LM4F230H5QR ARM Cortex-M4F Processor Core, available from Texas Instruments comprising on-chip memory of 256 KB single-cycle flash memory, or other non-volatile memory, up to 40 MHz, a prefetch buffer to improve performance above 40 MHz, a 32 KB single-cycle serial random access memory (SRAM), internal read-only memory (ROM) loaded with StellarisWare ®< software, 2 KB electrically erasable programmable read-only memory (EEPROM), one or more pulse width modulation (PWM) modules, one or more quadrature encoder inputs (QEI) analog, one or more 12-bit Analog-to-Digital Converters (ADC) with 12 analog input channels, details of which are available for the product datasheet.
[0196] The processor comprises a safety controller comprising two controller-based families such as TMS570 and RM4x known under the trade name Hercules ARM Cortex R4, also by Texas Instruments. The safety controller is configured specifically for IEC 61508 and ISO 26262 safety critical applications, among others, to provide advanced integrated safety features while delivering scalable performance, connectivity, and memory options.
[0197] Modular devices include the modules (as described in connection with FIGS. 3 and 9, for example) that are receivable within a surgical hub and the surgical devices or instruments that can be connected to the various modules in order to connect or pair with the corresponding surgical hub. The modular devices include, for example, intelligent surgical instruments, medical imaging devices, suction / irrigation devices, smoke evacuators, energy generators, ventilators, insufflators, and displays. The modular devices described herein are controlled by control algorithms. The control algorithms can be executed on the modular device itself, on the surgical hub to which the particular modular device is paired, or on both the modular device and the surgical hub (e.g., via a distributed computing architecture). In some exemplifications, the modular devices' control algorithms control the devices based on data sensed by the modular device itself (i.e., by sensors in, on, or connected to the modular device). This data is related to the patient being operated on (e.g., tissue properties or insufflation pressure) or the modular device itself (e.g., the rate at which a knife is being advanced, motor current, or energy levels). For example, a control algorithm for a surgical stapling and cutting instrument can control the rate at which the instrument's motor drives its knife through tissue according to resistance encountered by the knife as it advances.Long Distance Communication and Condition Handling of Devices and Data
[0198] Surgical procedures are performed by different surgeons at different locations, some with much less experience than others. For a given surgical procedure, there are many parameters that can be varied to attempt to realize a desired outcome. For example, for a given surgical procedure which utilizes energy supplied by a generator, the surgeon often relies on experience alone for determining which mode of energy to utilize, which level of output power to utilize, the duration of the application of the energy, etc., in order to attempt to realize the desired outcome. To increase the likelihood of realizing desired outcomes for a plurality of different surgical procedures, each surgeon should be provided with best practice recommendations which are based on important relationships identified within large, accurate data sets of information associated with multiple surgical procedures performed in multiple locations over time. However, there are many ways that such data sets can be rendered compromised, inaccurate, and / or unsecure, thereby calling into question the applicability of the best practice recommendations derived therefrom. For example, for data sent from a source to a cloud-based system, the data can be lost while in transit to the cloud-based system, the data can be corrupted while in transit to the cloud-based system, the confidentiality of the data can be comprised while in transit to the cloud-based system, and / or the content of the data can be altered while in transit to the cloud-based system.
[0199] A plurality of operating rooms located in multiple locations can each be equipped with a surgical hub. When a given surgical procedure is performed in a given operating room, the surgical hub can receive data associated with the surgical procedure and communicate the data to a cloud-based system. Over time, the cloud-based system will receive large data sets of information associated with the surgeries. The data can be communicated from the surgical hubs to the cloud-based system in a manner which allows for the cloud-based system to (1) verify the authenticity of the communicated data, (2) authenticate each of the respective surgical hubs which communicated the data, and (3) trace the paths the data followed from the respective surgical hubs to the cloud-based system.
[0200] Accordingly, in one aspect, the present disclosure provides a surgical hub for transmitting generator data associated with a surgical procedure to a cloud-based system communicatively coupled to a plurality of surgical hubs. The surgical hub comprises a processor and a memory coupled to the processor. The memory stores instructions executable by the processor to receive data from a generator, encrypt the data, generate a message authentication code (MAC) based on the data, generate a datagram comprising the encrypted data, the generated MAC, a source identifier, and a destination identifier, and transmit the datagram to a cloud-based system. The data is structured into a data packet comprising at least two of the following fields: a field that indicates the source of the data, a unique time stamp, a field indicating an energy mode of the generator, a field indicating the power output of the generator, and a field indicating a duration of the power output of the generator. The datagram allows for the cloud-based system to decrypt the encrypted data of the transmitted datagram, verify integrity of the data based on the MAC, authenticate the surgical hub as the source of the datagram, and validate a transmission path followed by the datagram between the surgical hub and the cloud-based system. In various aspects, the present disclosure provides a control circuit to transmit generator data associated with a surgical procedure to a cloud-based system communicatively coupled to a plurality of surgical hubs, as described above. In various aspects, the present disclosure provides a non-transitory computer-readable medium storing computer-readable instructions which, when executed, causes a machine to transmit generator data associated with a surgical procedure to a cloud-based system communicatively coupled to a plurality of surgical hubs, as described above.
[0201] In another aspect, the present disclosure provides a cloud-based system communicatively coupled to a plurality of surgical hubs. Each surgical hub is configured to transmit generator data associated with a surgical procedure to the cloud-based system. The cloud-based system comprises a processor and a memory coupled to the processor. The memory stores instructions executable by the processor to receive a datagram generated by a surgical hub, decrypt the encrypted generator data of the received datagram, verify integrity of the generator data based on the MAC, authenticate the surgical hub as the source of the datagram, and validate a transmission path followed by the datagram between the surgical hub and the cloud-based system. The datagram comprises generator data captured from a generator associated with the surgical hub, a MAC generated by the surgical hub based on the generator data, a source identifier, and a destination identifier. The generator data has been encrypted by the surgical hub. The encrypted generator data has been structured into a data packet comprising at least two of the following fields: a field that indicates the source of the data, a unique time stamp, a field indicating an energy mode, a field indicating power output, and a field indicating a duration of applied power.
[0202] In various aspects, the present disclosure provides a control circuit to transmit generator data associated with a surgical procedure to the cloud-based system. In various aspects, the present disclosure provides a non-transitory computer-readable medium storing computer-readable instructions which, when executed, causes a machine to transmit generator data associated with a surgical procedure to the cloud-based system.
[0203] In another aspect, the present disclosure provides a method, comprising capturing data from a combination generator of a surgical hub during a surgical procedure, wherein the combination generator is configured to supply two or more different modes of energy. Encrypting the captured generator data, generating a MAC based on the captured generator data, generating a datagram comprising the encrypted generator data, the MAC, a source identifier, and a destination identifier, and communicating the datagram from the surgical hub to a cloud-based system. The datagram allows for the cloud-based system to authenticate integrity of the communicated generator data, authenticate the surgical hub as a source of the datagram, and determine a communication path followed by the datagram between the surgical hub and the cloud-based system.
[0204] By sending captured generator data from a plurality of different surgical hubs to a cloud-based system, the cloud-based system is able to quickly build large data sets of information associated with multiple surgical procedures performed in multiple locations over time. Furthermore, due to the composition of the respective datagrams, for a given datagram, the cloud-based system is able to determine whether the datagram was originally sent by one of the surgical hubs (source validation), thereby providing an indication that the generator data received at the cloud-based system is legitimate data. For the given datagram, the cloud-based system is also able to determine whether the generator data received at the cloud-based system is identical to the generator data sent by the given surgical hub (data integrity), thereby allowing for the authenticity of the received generator data to be verified. Additionally, for the given datagram, the cloud-based system is also able to re-trace the communication path followed by the datagram, thereby allowing for enhanced troubleshooting if a datagram received by the cloud-based system was originally sent from a device other than the surgical hubs and / or if the content of the datagram was altered while in transit to the cloud-based system. Notably, the present disclosure references generator data in particular. Here, the present disclosure should not be limited as being able to process only generator data. For example, the surgical hub 206 and / or the cloud-based system 205 may process data received from any component (e.g., imaging module 238, generator module 240, smoke evacuator module 226, suction / irrigation module 228, communication module 230, processor module 232, storage array 234, smart device / instrument 235, non-contact sensor module 242, robot hub 222, a non-robotic surgical hub 206, wireless smart device / instrument 235, visualization system 208) of the surgical system 202 that is coupled to the surgical hub 206 and / or data from any devices (e.g., endoscope 239, energy device 241) coupled to / through such components (e.g., see FIGS. 9-10), in a similar manner as discussed herein.
[0205] Unfortunately, the outcome of a surgical procedure is not always optimal. For example, a failure event such as a surgical device failure, an unwanted tissue perforation, an unwanted post-operative bleeding, or the like can occur. The occurrence of a failure event can be attributed to any of a variety of different people and devices, including one or more surgeons, one or more devices associated with the surgery, a condition of the patient, and combinations thereof. When a given failure event occurs, it is not always clear regarding who or what caused the failure event or how the occurrence of the failure event can be mitigated in connection with a future surgery.
[0206] During a given surgical procedure, a large amount of data associated with the surgical procedure can be generated and captured. All of the captured data can be communicated to a surgical hub, and the captured data can be time-stamped either before or after being received at the surgical hub. When a failure event associated with the surgical procedure is detected and / or identified, it can be determined which of the captured data is associated with the failure event and / or which of the captured data is not associated with the failure event. In making this determination, the failure event can be defined to include a period of time prior to the detection / identification of the failure event. Once the determination is made regarding the captured data associated with the failure event, the surgical hub can separate the captured data associated with the failure event from all other captured data, and the captured data can be separated based on tagging, flagging, or the like. The captured data associated with the failure event can then be chronologized based on the time-stamping and the defined time period applicable to the failure event. The chronologized captured data can then be communicated to a cloud-based system on a prioritized basis for analysis, where the prioritized basis is relative to the captured data which is not associated with the failure event. Whether or not the analysis identifies a device associated with the surgical procedure as the causation of the failure event, the surgical hub can tag the device for removal of the device from future use, further analysis of the device, and / or to return the device to the manufacturer.
[0207] When a given surgical procedure is performed, a large amount of data associated with the surgical procedure can be generated and captured. All of the captured data can be communicated to a surgical hub, where the information can be stripped of all "personal" associations. The captured data can be time-stamped before being received at the surgical hub, after being received at the surgical hub, before being stripped of the "personal" associations, or after being stripped of the "personal" associations. The surgical hub can communicate the stripped data to the cloud-based system for subsequent analysis. Over time, the cloud-based system will receive large data sets of information associated with the surgeries. Accordingly, in one aspect, the present disclosure provides a surgical hub for prioritizing surgical data associated with a surgical procedure to a cloud-based system communicatively coupled to a plurality of surgical hubs. The surgical hub comprises a processor and a memory coupled to the processor. The memory stores instructions executable by the processor to capture surgical data, wherein the surgical data comprises data associated with a surgical device, time-stamp the captured surgical data, identify a failure event, identify a time period associated with the failure event, isolate failure event surgical data from surgical data not associated with the failure event based on the identified time period, chronologize the failure event surgical data by time-stamp, encrypt the chronologized failure event surgical data, generate a datagram comprising the encrypted failure event surgical data, and transmit the datagram to a cloud-based system. The datagram is structured to include a field which includes a flag that prioritizes the encrypted failure event surgical data over other encrypted data of the datagram. The datagram allows for the cloud-based system to decrypt the encrypted failure event surgical data, focus analysis on the failure event surgical data rather than surgical data not associated with the failure event, and flag the surgical device associated with the failure event for at least one of the following: removal from an operating room, return to a manufacturer, or future inoperability in the cloud-based system.
[0208] In various aspects, the present disclosure provides a control circuit to prioritize surgical data associated with a surgical procedure to a cloud-based system communicatively coupled to a plurality of surgical hubs. In various aspects, the present disclosure provides a non-transitory computer-readable medium storing computer-readable instructions which, when executed, causes a machine to prioritize surgical data associated with a surgical procedure to a cloud-based system communicatively coupled to a plurality of surgical hubs.
[0209] In another aspect, the present disclosure provides a method, comprising capturing data during a surgical procedure, communicating the captured data to a surgical hub, time-stamping the captured data, identifying a failure event associated with the surgical procedure, determining which of the captured data is associated with the failure event, separating the captured data associated with the failure event from all other captured data, chronologizing the captured data associated with the failure event, and communicating the chronologized captured data to a cloud-based system on a prioritized basis.
[0210] By capturing the large amount of data associated with the surgical procedure, and with having the captured data time-stamped, the portion of the captured data which is relevant to the detected / identified failure event can be more easily isolated from all of the other captured data, thereby allowing for a more focused subsequent analysis on just the relevant captured data. The data associated with the failure event can then be chronologized (this requires less processing power than chronologizing all of the captured data), thereby allowing for the events leading up to the detection / identification of the failure event to be more easily considered during the subsequent analysis of the failure event. The chronologized data can then be communicated to the cloud-based system (this requires less communication resources than communicating all of the captured data at the same time) on a prioritized basis, thereby allowing for the focused subsequent analysis of the fault event to be performed by the cloud-based system in a more time-sensitive manner.
[0211] To help ensure that the best practice recommendations are developed based on accurate data, it would be desirable to ensure that the generator data received at the cloud-based system is the same as the generator data communicated to the cloud-based system. Also, to help to be able to determine the cause of a failure event as quickly as possible, it would be desirable to ensure that surgical data associated with the failure event is communicated to the cloud-based system in a prioritized manner (relative to surgical data not associated with the failure event) so that analysis of the surgical data can be performed in an expedited manner.
[0212] Aspects of a system and method for communicating data associated with a surgical procedure are described herein. As shown in FIG. 9, various aspects of the computer implemented interactive surgical system 200 includes a device / instrument 235, a generator module 240, a modular control tower 236, and a cloud-based system 205. As shown in FIG. 10, the device / instrument 235, the generator module 240, and the modular control tower 236 are components / portions of a surgical hub 206.
[0213] In various aspects, the generator module 240 of the surgical hub 206 can supply radio-frequency energy such as monopolar radio-frequency energy, bipolar radio-frequency energy, and advanced bipolar energy and / or ultrasonic energy to a device / instrument 235 for use in a surgical procedure. Thus, the generator module 240 may be referred to as a combination generator. An example of such a combination generator is shown in FIG. 22, where the combination generator 3700 is shown as including a monopolar module 3702, a bipolar module 3704, an advanced bipolar module 3706, and an ultrasound module 3708. When utilized during a surgical procedure, the respective energy modules (e.g., 3702, 3704, 3706, and / or 3708) of the combination generator 3700 can provide generator data such as type of energy supplied to the device instrument (e.g., radio-frequency energy, ultrasound energy, radio-frequency energy and ultrasound energy), type of radio-frequency energy (e.g., monoplar, bipolar, advanced bipolar), frequency, power output, duration, etc., to the data communication module 3710 of the combination generator 3700.
[0214] FIG. 23 illustrates various aspects of a method of capturing data from a combination generator 3700 and communicating the captured generator data to a cloud-based system 205. Notably, as discussed herein, the present disclosure should not be limited to processing generator data. As such, the method of FIG. 23 similarly extends to other types of data received from other components coupled to the surgical hub 206 (e.g., imaging module data, smoke evacuator data, suction / irrigation data, device / instrument data). The method comprises (1) capturing 3712 data from a combination generator 3700 of a surgical hub 206 during a surgical procedure, wherein the combination generator 3700 is configured to supply two or more different modes of energy; (2) encrypting 3714 the captured generator data; (3) generating 3716 a MAC based on the captured generator data; (4) generating 3718 a datagram comprising the encrypted generator data, the MAC, a source identifier, and a destination identifier; and (5) communicating 3720 the datagram from the surgical hub 206 to a cloud-based system 205, wherein the datagram allows for the cloud-based system 205 to (i) authenticate integrity of the communicated generator data, (ii) authenticate the surgical hub as a source of the datagram, and (iii) determine a communication path followed by the datagram between the surgical hub 206 and the cloud-based system 205.
[0215] More specifically, once the generator data is received at the data communication module 3710 of the combination generator 3700, the generator data can be communicated to the modular communication hub 203 of the surgical hub 206 for subsequent communication to the cloud-based system 205. The data communication module 3710 can communicate the generator data to the modular communication hub 203 serially over a single communication line or in parallel over a plurality of communication lines, and such communication can be performed in real time or near real time. Alternatively, such communication can be performed in batches.
[0216] According to various aspects, prior to communicating the generator data to the modular communication hub 203, a component of the combination generator 3700 (e.g., the data communication module 3710) can organize the generator data into data packets. An example of such a data packet is shown in FIG. 24, where the data packet 3722 includes a preamble 3724 or self-describing data header which defines what the data is (e.g., combination generator data - CGD) and fields which indicate where the generator data came from [e.g., combination generator ID number 3726 - (e.g., 017), a unique time stamp 3728 (e.g., 08:27:16), the energy mode utilized 3730 (e.g., RF, U, RF+U), the type of radio-frequency energy or radio frequency mode 3732 (e.g., MP, BP, ABP), the frequency 3734 (e.g., 500Khz), the power output 3736 (e.g., 30 watts), the duration of applied power 3738 (e.g., 45 milliseconds), and an authentication / identification certificate of the data point 3740 (e.g., 01101011001011)]. The example data packet 3722 may be considered a self-describing data packet, and the combination generator 3700 and other intelligent devices (e.g., the surgical hub 206) can use the self-describing data packets to minimize data size and data-handling resources. Again, as discussed herein, the present disclosure should not be limited to processing generator data received from a combination generator 3700. As such, the data packet 3722 of FIG. 24 similarly extends to other types of data received from other components coupled to the surgical hub 206. In one aspect, the data packet 3722 may comprise data associated with endoscope 239 (e.g., image data) received from a component of the imaging module 238. In another aspect, the data packet 3722 may comprises data associated with an evacuation system (e.g., pressures, particle counts, flow rates, motor speeds) received from a component of the smoke evacuator module 226. In yet another aspect, the data packet 3722 may comprise data associated with a device / instrument (e.g., temperature sensor data, firing data, sealing data) received from a component of the device / instrument 235. In various other aspects, the data packet 3722 may similarly comprise data received from other components coupled to the surgical hub 206 (e.g., suction / irrigation module 228, non-contact sensor module 242)
[0217] Additionally, the data communication module 3710 can compress the generator data and / or encrypt the generator data prior to communicating the generator data to the modular communication hub 203. The specific method of compressing and / or encrypting can be the same as or different from the compressing and / or encrypting which may be performed by the surgical hub 206 as described in more detail below.
[0218] The modular communication hub 203 can receive the generator data communicated from the combination generator 3700 (e.g., via the data communication module 3710), and the generator data can be subsequently communicated to the cloud-based system 205 (e.g., through the Internet). According to various aspects, the modular communication hub 203 can receive the generator data through a hub / switch 207 / 209 of the modular communication hub 203 (See FIG. 10), and the generator data can be communicated to the cloud-based system 205 by a router 211 of the modular communication hub 203 (See FIG. 10). The generator data may be communicated in real time, near real time, or in batches to the cloud-based system 205 or may be stored at the surgical hub 206 prior to being communicated to the cloud-based system 205. The generator data can be stored, for example, at the storage array 234 or at the memory 249 of the computer system 210 of the surgical hub 206.
[0219] In various aspects, for instances where the generator data received at the modular communication hub 203 is not encrypted, prior to the received generator data being communicated to the cloud-based system 205, the generator data is encrypted to help ensure the confidentiality of the generator data, either while it is being stored at the surgical hub 206 or while it is being transmitted to the cloud 204 using the Internet or other computer networks. According to various aspects, a component of the surgical hub 206 utilizes an encryption algorithm to convert the generator data from a readable version to an encoded version, thereby forming the encrypted generator data. The component of the surgical hub 206 which utilizes / executes the encryption algorithm can be, for example, the processor module 232, the processor 244 of the computer system 210, and / or combinations thereof. The utilized / executed encryption algorithm can be a symmetric encryption algorithm and / or an asymmetric encryption algorithm.
[0220] Using a symmetric encryption algorithm, the surgical hub 206 would encrypt the generator data using a shared secret (e.g., private key, passphrase, password). In such an aspect, a recipient of the encrypted generator data (e.g., cloud-based system 205) would then decrypt the encrypted generator data using the same shared secret. In such an aspect, the surgical hub 206 and the recipient would need access to and / or knowledge of the same shared secret. In one aspect, a shared secret can be generated / chosen by the surgical hub 206 and securely delivered (e.g., physically) to the recipient before encrypted communications to the recipient.
[0221] Alternatively, using an asymmetric encryption algorithm, the surgical hub 206 would encrypt the generator data using a public key associated with a recipient (e.g., cloud-based system 205). This public key could be received by the surgical hub 206 from a certificate authority that issues a digital certificate certifying the public key as owned by the recipient. The certificate authority can be any entity trusted by the surgical hub 206 and the recipient. In such an aspect, the recipient of the encrypted generator data would then decrypt the encrypted generator data using a private key (i.e., known only by the recipient) paired to the public key used by the surgical hub 206 to encrypt the generator data. Notably, in such an aspect, the encrypted generator data can only be decrypted using the recipient's private key.
[0222] According to aspects of the present disclosure, components (e.g., surgical device / instrument 235, energy device 241, endoscope 239) of the surgical system 202 are associated with unique identifiers, which can be in the form of serial numbers. As such, according to various aspects of the present disclosure, when a component is coupled to a surgical hub 206, the component may establish a shared secret with the surgical hub 206 using the unique identifier of the coupled component as the shared secret. Further, in such an aspect, the component may derive a checksum value by applying a checksum function / algorithm to the unique identifier and / or other data being communicated to the surgical hub 206. Here, the checksum function / algorithm is configured to output a significantly different checksum value if there is a modification to the underlying data.
[0223] In one aspect, the component may initially encrypt the unique identifier of a coupled component using a public key associated with the surgical hub (e.g., received by the component from the surgical hub 206 upon / after connection) and communicate the encrypted unique identifier to the surgical hub 206. In other aspects, the component may encrypt the unique identifier and the derived checksum value of a coupled component using a public key associated with the surgical hub 206 and communicate the encrypted unique identifier and linked / associated checksum value to the surgical hub 206.
[0224] In yet other aspects, the component may encrypt the unique identifier and a checksum function / algorithm using a public key associated with the surgical hub 206 and communicate the encrypted unique identifier and the checksum function / algorithm to the surgical hub 206. In such aspects, the surgical hub 206 would then decrypt the encrypted unique identifier or the encrypted unique identifier and the linked / associated checksum value or the encrypted unique identifier and the checksum function / algorithm using a private key (i.e., known only by the surgical hub 206) paired to the public key used by the component to encrypt the unique identifier.
[0225] Since the encrypted unique identifier can only be decrypted using the surgical hub's 206 private key and the private key is only known by the surgical hub, this is a secure way to communicate a shared secret (e.g., the unique identifier of the coupled component) to the surgical hub 206. Further, in aspects where a checksum value is linked to / associated with the unique identifier, the surgical hub 206 may apply the same checksum function / algorithm to the decrypted unique identifier to generate a validating checksum value. If the validating checksum value matches the decrypted checksum value, the integrity of the decrypted unique identifier is further verified. Further, in such aspects, with a shared secret established, the component can encrypt future communications to the surgical hub 206, and the surgical hub 206 can decrypt the future communications from the component using the shared secret (e.g., the unique identifier of the coupled component). Here, according to various aspects, a checksum value may be derived for and communicated with each communication between the component and the surgical hub 206 (e.g., the checksum value based on the communicated data or at least a designated portion thereof). Here, a checksum function / algorithm (e.g., known by the surgical hub 206 and / or component or communicated when establishing the shared secret between the surgical hub 206 and the component as described above) may be used to generate validating checksum values for comparison with communicated checksum values to further verify the integrity of communicated data in each communication.
[0226] Notably, asymmetric encryption algorithms may be complex and may require significant computational resources to execute each communication. As such, establishing the unique identifier of the coupled component as the shared secret is not only quicker (e.g., no need to generate a shared secret using a pseudorandom key generator) but also increases computational efficiency (e.g., enables the execution of faster, less complex symmetric encryption algorithms) for all subsequent communications. In various aspects, this established shared secret may be utilized by the component and surgical hub 206 until the component is decoupled from the surgical hub (e.g., surgical procedure ended).
[0227] According to other aspects of the present disclosure, components (e.g., surgical device / instrument 235, energy device 241, endoscope 239) of the surgical system 202 may comprise sub-components (e.g., handle, shaft, end effector, cartridge) each associated with its own unique identifier. As such, according to various aspects of the present disclosure, when a component is coupled to the surgical hub 206, the component may establish a shared secret with the surgical hub 206 using a unique compilation / string (e.g., ordered or random) of the unique identifiers associated with the sub-components that combine to form the coupled component. In one aspect, the component may initially encrypt the unique compilation / string of the coupled component using a public key associated with the surgical hub 206 and communicate the encrypted unique compilation / string to the surgical hub 206. In such an aspect, the surgical hub 206 would then decrypt the encrypted unique compilation / string using a private key (i.e., known only by the surgical hub 206) paired to the public key used by the component to encrypt the unique compilation / string. Since the encrypted unique compilation / string can only be decrypted using the surgical hub's 206 private key and the private key is only known by the surgical hub 206, this is a secure way to communicate a shared secret (e.g., the unique compilation / string of the coupled component) to the surgical hub 206. Further, in such an aspect, with a shared secret established, the component can encrypt future communications to the surgical hub 206, and the surgical hub 206 can decrypt the future communications from the component using the shared secret (e.g., the unique compilation / string of the coupled component).
[0228] Again, asymmetric encryption algorithms may be complex and may require significant computational resources to execute each communication. As such, establishing the unique compilation / string of the coupled component (i.e., readily combinable by the component) as the shared secret is not only quicker (e.g., no need to generate a shared secret using a pseudorandom key generator) but also increases computational efficiency (e.g., enables the execution of faster, less complex symmetric encryption algorithms) for all subsequent communications. In various aspects, this established shared secret may be utilized by the component and surgical hub 206 until the component is decoupled from the surgical hub 206 (e.g., surgical procedure ended). Furthermore, in such an aspect, since various sub-components may be reusable (e.g., handle, shaft, end effector) while other sub-components may not be reusable (e.g., end effector, cartridge) each new combination of sub-components that combine to form the coupled component provide a unique compilation / string usable as a shared secret for component communications to the surgical hub 206.
[0229] According to further aspects of the present disclosure, components (e.g., surgical device / instrument 235, energy device 241, endoscope 239) of the surgical system 202 are associated with unique identifiers. As such, according to various aspects of the present disclosure, when a component is coupled to the surgical hub 206, the surgical hub 206 may establish a shared secret with a recipient (e.g., cloud-based system 205) using the unique identifier of the coupled component. In one aspect, the surgical hub 206 may initially encrypt the unique identifier of a coupled component using a public key associated with the recipient and communicate the encrypted unique identifier to the recipient. In such an aspect, the recipient would then decrypt the encrypted unique identifier using a private key (i.e., known only by the recipient) paired to the public key used by the surgical hub 206 to encrypt the unique identifier. Since the encrypted unique identifier can only be decrypted using the recipient's private key and the private key is only known by the recipient, this is a secure way to communicate a shared secret (e.g., the unique identifier of the coupled component) to the recipient (e.g., cloud-based system). Further in such an aspect, with a shared secret established, the surgical hub 206 can encrypt future communications to the recipient (e.g., cloud-based system 205), and the recipient can decrypt the future communications from the surgical hub 206 using the shared secret (e.g., the unique identifier of the coupled component).
[0230] Notably, asymmetric encryption algorithms may be complex and may require significant computational resources to execute each communication. As such, establishing the unique identifier of the coupled component (i.e., already available to the surgical hub 206) as the shared secret is not only quicker (e.g., no need to generate a shared secret using a pseudorandom key generator) but also increases computational efficiency by, for example, enabling the execution of faster, less complex symmetric encryption algorithms for all subsequent communications. In various aspects, this established shared secret may be utilized by the surgical hub 206 until the component is decoupled from the surgical hub (e.g., surgical procedure ended).
[0231] According to yet further aspects of the present disclosure, components (e.g., surgical device / instrument 235, energy device 241, endoscope 239) of the surgical system 202 may comprise sub-components (e.g., handle, shaft, end effector, cartridge) each associated with its own unique identifier. As such, according to various aspects of the present disclosure, when a component is coupled to the surgical hub 206, the surgical hub 206 may establish a shared secret with a recipient (e.g., cloud-based system 205) using a unique compilation / string (e.g., ordered or random) of the unique identifiers associated with the sub-components that combine to form the coupled component.
[0232] In one aspect, the surgical hub 206 may initially encrypt the unique compilation / string of the coupled component using a public key associated with the recipient and communicate the encrypted unique compilation / string to the recipient. In such an aspect, the recipient would then decrypt the encrypted unique compilation / string using a private key (i.e., known only by the recipient) paired to the public key used by the surgical hub 206 to encrypt the unique compilation / string. Since the encrypted unique compilation / string can only be decrypted using the recipient's private key and the private key is only known by the recipient, this is a secure way to communicate a shared secret (e.g., the unique compilation / string of the coupled component) to the recipient. With a shared secret established, the surgical hub 206 can encrypt future communications to the recipient (e.g., cloud-based system 205), and the recipient can decrypt the future communications from the surgical hub 206 using the shared secret (e.g., the unique compilation / string of the coupled component). Again, asymmetric encryption algorithms may be complex and may require significant computational resources to execute each communication. As such, establishing the unique compilation / string of the coupled component (i.e., readily combinable by the surgical hub 206) as the shared secret is not only quicker (e.g., no need to generate a shared secret using a pseudorandom key generator) but also increases computational efficiency (e.g., enables the execution of faster, less complex symmetric encryption algorithms) for all subsequent communications.
[0233] In various aspects, this established shared secret may be utilized by the surgical hub 206 until the component is decoupled from the surgical hub (e.g., surgical procedure ended). Furthermore, in such an aspect, since various sub-components may be reusable (e.g., handle, shaft, end effector) while other sub-components may not be reusable (e.g., end effector, cartridge) each new combination of sub-components that combine to form the coupled component provide a unique compilation / string usable as a shared secret for surgical hub 206 communications to the recipient.
[0234] In some aspects, an encrypt-then-MAC (EtM) approach may be utilized to produce the encrypted generator data. An example of this approach is shown in FIG. 25, where the non-encrypted generator data (i.e., the plaintext 3742, e.g., data packet 3722) is first encrypted 3743 (e.g., via key 3746) to produce a ciphertext 3744 (i.e., the encrypted generator data), then a MAC 3745 is produced based on the resulting ciphertext 3744, the key 3746, and a MAC algorithm (e.g., a hash function 3747). More specifically, the ciphertext 3744 is processed through the MAC algorithm using the key 3746. In one aspect similar to symmetric encryption discussed herein, the key 3746 is a secret key accessible / known by the surgical hub 206 and the recipient (e.g., cloud-based system 205). In such an aspect, the secret key is a shared secret associated with / chosen by the surgical hub 206, a shared secret associated with / chosen by the recipient, or a key selected via a pseudorandom key generator. For this approach, as shown generally at 3748, the encrypted generator data (i.e., the ciphertext 3744) and the MAC 3745 would be communicated together to the cloud-based system 205.
[0235] In other aspects, an encrypt-and-MAC (E&M) approach may be utilized to produce the encrypted generator data. An example of this approach is shown in FIG. 26, where the MAC 3755 is produced based on the non-encrypted generator data (i.e., the plaintext 3752, e.g., data packet 3722), a key 3756, and a MAC algorithm (e.g., a hash function 3757). More specifically, the plaintext 3752 is processed through the MAC algorithm using the key 3756. In one aspect similar to symmetric encryption discussed herein, the key 3756 is a secret key accessible / known by the surgical hub 206 and the recipient (e.g., cloud-based system 205). In such an aspect, the secret key is a shared secret associated with / chosen by the surgical hub 206, a shared secret associated with / chosen by the recipient, or a key selected via a pseudorandom key generator. Further, in such an aspect, the non-encrypted generator data (i.e., the plaintext 3752, e.g., data packet 3722) is encrypted 3753 (e.g., via key 3756) to produce a ciphertext 3754. For this approach, as shown generally at 3758, the MAC 3755 (i.e., produced based on the non-encrypted generator data) and the encrypted generator data (i.e., the ciphertext 3754) would be communicated together to the cloud-based system 205.
[0236] In yet other aspects, a MAC-then-encrypt (MtE) approach may be utilized to produce the encrypted generator data. An example of this approach is shown in FIG. 27, where the MAC 3765 is produced based on the non-encrypted generator data (i.e., the plaintext 3762), a key 3766, and a MAC algorithm (e.g., a hash function 3767). More specifically, the plaintext 3762 is processed through the MAC algorithm using the key 3766. In one aspect similar to symmetric encryption discussed herein, the key 3766 is a secret key accessible / known by the surgical hub 206 and the recipient (e.g., cloud-based system 205). In such an aspect, the secret key is a shared secret associated with / chosen by the surgical hub 206, a shared secret associated with / chosen by the recipient, or a key selected via a pseudorandom key generator. Next, the non-encrypted generator data (i.e., the plaintext 3762) and the MAC 3765 are together encrypted 3763 (e.g., via key 3766) to produce a ciphertext 3764 based on both. For this approach, as shown generally at 3768, the ciphertext 3764 (i.e., which includes the encrypted generator data and the encrypted MAC 3765) would be communicated to the cloud-based system 205.
[0237] In alternative aspects, the key used to encrypt the non-encrypted generator data (e.g., FIG. 25 and FIG. 26) or the non-encrypted generator data and the MAC (e.g., FIG. 27) may be different from the key (e.g., keys 3746, 3756, 3766) used to produce the MAC. For example, the key used to encrypt the non-encrypted generator data (e.g., FIG. 25 and FIG. 26) or the non-encrypted generator data and the MAC (e.g., FIG. 27) may be a different shared secret or a public key associated with the recipient.
[0238] In lieu of utilizing the MAC to provide for a subsequent assurance of data integrity to the cloud-based system 205, according to other aspects, the surgical hub 206 can utilize a digital signature to allow the cloud-based system 205 to subsequently authenticate integrity of the communicated generator data. For example, the processor module 232 and / or the processor 244 of the computer system 210 can utilize one or more algorithms to generate a digital signature associated with the generator data, and the cloud-based system 205 can utilize an algorithm to determine the authenticity of the received generator data. The algorithms utilized by the processor module 232 and / or the processor 244 of the computer system 210 can include: (1) a key generation algorithm that selects a private key uniformly at random from a set of possible private keys, where the key generation algorithm outputs the private key and a corresponding public key; and (2) a signing algorithm that, given the generator data and a private key, produces a digital signature associated with the generator data. The cloud-based system 205 can utilize a signature verifying algorithm that, given the received generator data, public key, and digital signature, can accept the received generator data as authentic if the digital signature is determined to be authentic or consider the generator data to be compromised or altered if the digital signature is not determined to be authentic.
[0239] According to other aspects of the present disclosure, the surgical hub 206 can utilize a commercial authentication program (e.g., Secure Hash Algorithm, SHA-2 comprising SHA-256) to provide for a subsequent assurance of data integrity of the communicated generator data to the cloud-based system 205.
[0240] After the generator data has been encrypted (e.g., via EtM, E&M, MtE), a component of the surgical hub 206 can communicate the encrypted generator data to the cloud-based system 205. The component of the surgical hub 206 which communicates the encrypted generator data to the cloud-based system 205 can be, for example, the processor module 232, a hub / switch 207 / 209 of the modular communication hub 203, the router 211 of the modular communication hub 203, the communication module 247 of the computer system 210, etc.
[0241] According to various aspects, the communication of the encrypted generator data through the Internet can follow an IP which: (1) defines datagrams that encapsulate the encrypted generator data to be delivered and / or (2) defines addressing methods that are used to label the datagram with source and destination information. A high-level representation of an example datagram 3770 is shown in FIG. 28, where the datagram 3770 includes a header 3772 and a payload 3774, and in other aspects also may include a trailer (not shown). A more detailed representation of an example datagram 3780 is shown in FIG. 29, where the header 3782 can include fields for information such as, for example, the IP address of the source 3786 which is sending the datagram (e.g., the router 211 of the modular communication hub 203), the IP address of the destination 3788 which is to receive the datagram (e.g., the cloud 204 and / or the remote server 213 associated with the cloud-based system 205), a type of service designation (not shown), a header length 3790, a payload length 3792, and a checksum value 3794. In such an aspect, the surgical hub 206 may further apply a checksum function / algorithm to the non-encrypted generator data (i.e., the plaintext 3742, e.g., data packet 3722) or at least a portion of the non-encrypted generator data (e.g., combination generator ID 3726) to derive the checksum value 3794. Here, the checksum function / algorithm is configured to output a significantly different checksum value if there is any modification (e.g., even a slight change) to the underlying data (e.g., generator data). After decryption of the encrypted generator data by its recipient (e.g., cloud-based system 205), the recipient may apply the same checksum function / algorithm to the decrypted generator data to generate a validating checksum value. If the validating checksum value matches the checksum value 3794 (i.e., stored in the header 3782 of the received datagram 3780), the integrity of the received generator data is further verified. The payload 3784 may include the encrypted generator data 3796 and can also include padding 3798 if the encrypted generator data 3796 is less than a specified payload length. Notably, the communicated encrypted generator data 3796 may comprise a MAC as discussed in FIGS. 25, 26, and 27 above (e.g., references 3748, 3758, and 3768, respectively). In some aspects, the header 3782 can further include a specific path the datagram is to follow when the datagram is communicated from the surgical hub 206 to the cloud-based system 205 (e.g., from IP address of the source, to IP address of at least one intermediate network component (e.g., specified routers, specified servers), to IP address of the destination).
[0242] According to various aspects, prior to the generator data being encrypted, the generator data can be time-stamped (if not already time-stamped by the combination generator 3700) and / or the generator data can be compressed (if not already compressed by the combination generator 3700). Time-stamping allows for the cloud-based system 205 to correlate the generator data with other data (e.g., stripped patient data) which may be communicated to the cloud-based system 205. The compression allows for a smaller representation of the generator data to be subsequently encrypted and communicated to the cloud-based system 205. For the compression, a component of the surgical hub 206 can utilize a compression algorithm to convert a representation of the generator data to a smaller representation of the generator data, thereby allowing for a more efficient and economical encryption of the generator data (e.g., less data to encrypt utilizes less processing resources) and a more efficient and economical communication of the encrypted generator data (e.g., smaller representations of the generator data within the payload of the datagrams (e.g., FIGS. 28 and 29) allow for more generator data to be included in a given datagram, for more generator data to be communicated within a given time period, and / or for generator data to be communicated with fewer communication resources). The component of the surgical hub 206 which utilizes / executes the compression algorithm can be, for example, the processor module 232, the processor 244 of the computer system, and / or combinations thereof. The utilized / executed compression algorithm can be a lossless compression algorithm or a lossy compression algorithm.
[0243] Once the generator data and the MAC for a given datagram has been received at the cloud-based system 205 (e.g., FIG. 25, reference 3748; FIG. 26, reference 3758; and FIG. 27, reference 3768), the cloud-based system 205 can decrypt the encrypted generator data from the payload of the communicated datagram to realize the communicated generator data.
[0244] In one aspect, referring back to FIG. 25, the recipient (e.g., cloud-based system 205) may, similar to the surgical hub 206, process the ciphertext 3744 through the same MAC algorithm using the same known / accessible secret key to produce an authenticating MAC. If the received MAC 3745 matches this authenticating MAC, the recipient (e.g., cloud-based system 205) may safely assume that the ciphertext 3744 has not been altered and is from the surgical hub 206. The recipient (e.g., cloud-based system 205) may then decrypt the ciphertext 3744 (e.g., via key 3746) to realize the plaintext 3742 (e.g., data packet comprising generator data).
[0245] In another aspect, referring back to FIG. 26, the recipient (e.g., cloud-based system 205) may decrypt the ciphertext 3754 (e.g., via key 3756) to realize the plaintext 3752 (e.g., data packet comprising generator data). Next, similar to the surgical hub 206, the recipient (e.g., cloud-based system 205) may process the plaintext 3752 through the same MAC algorithm using the same known / accessible secret key to produce an authenticating MAC. If the received MAC 3755 matches this authenticating MAC, the recipient (e.g., cloud-based system 205) may safely assume that the plaintext 3752 has not been altered and is from the surgical hub 206.
[0246] In yet another aspect, referring back to FIG. 27, the recipient (e.g., cloud-based system 205) may decrypt the ciphertext 3764 (e.g., via key 3766) to realize the plaintext 3762 (e.g., data packet comprising generator data) and the MAC 3765. Next, similar to the surgical hub 206, the recipient (e.g., cloud-based system 205) may process the plaintext 3762 through the same MAC algorithm using the same known / accessible secret key to produce an authenticating MAC. If the received MAC 3765 matches this authenticating MAC, the recipient (e.g., cloud-based system 205) may safely assume that the plaintext 3762 has not been altered and is from the surgical hub 206.
[0247] In alternative aspects, the key used to encrypt the non-encrypted generator data (e.g., FIG. 25 and FIG. 26) or the non-encrypted generator data and the MAC (e.g., FIG. 27) may be different from the key (e.g., keys 3746, 3756, 3766) used to produce the MAC. For example, the key used to encrypt the non-encrypted generator data (e.g., FIG. 25 and FIG. 26) or the non-encrypted generator data and the MAC (e.g., FIG. 27) may be a different shared secret or a public key associated with the recipient. In such aspects, referring to FIG. 25, the recipient (e.g., cloud-based system 205) may, after verifying the authenticating MAC via key 3746 (described above), then decrypt the ciphertext 3744 (e.g., via the different shared secret or private key associated with the recipient) to realize the plaintext 3742 (e.g., data packet comprising generator data). In such aspects, referring to FIG. 26, the recipient may decrypt the ciphertext 3754 (e.g., via the different shared secret or private key associated with the recipient) to realize the plaintext 3752 (e.g., data packet comprising generator data), then verify the authenticating MAC via key 3756 (described above). In such aspects, referring to FIG. 27, the recipient may decrypt the ciphertext 3764 (e.g., via the different shared secret or private key associated with the recipient) to realize the plaintext 3762 (e.g., data packet comprising generator data) and the MAC 3765, then verify the authenticating MAC via key 3766 (described above).
[0248] In sum, referring to FIGS. 25-27, if an authenticating MAC, as determined / calculated by the cloud-based system 205, is the same as the MAC which was received with the datagram, the cloud-based system 205 can have confidence that the received generator data is authentic (i.e., it is the same as the generator data which was communicated by the surgical hub 206) and that the data integrity of the communicated generator data has not been compromised or altered. As described above, the recipient may further apply the plaintext 3742, 3752, 3762, or at least a portion thereof to the same checksum function / algorithm (i.e., used by the surgical hub 206) to generate a validating checksum value to further verify the integrity of the generator data based on the checksum value stored in the header of the communicated datagram.
[0249] Additionally, based on the decrypted datagram, the IP address of the source (e.g., FIG. 29, reference 3786) which originally communicated the datagram to the cloud-based system 205 can be determined from the header of the communicated datagram. If the determined source is a recognized source, the cloud-based system 205 can have confidence that the generator data originated from a trusted source, thereby providing source authentication and even more assurance of the data integrity of the generator data. Furthermore, since each router the datagram passed through in route to the cloud-based system 205 includes its IP address with its forwarded communication, the cloud-based system 205 is able to trace back the path followed by the datagram and identify each router which handled the datagram. The ability to identify the respective routers can be helpful in instances where the content of the datagram received at the cloud-based system 205 is not the same as the content of the datagram as originally communicated by the surgical hub 206. For aspects where the communication path was pre-specified and included in the header of the communicated datagram, the ability to identify the respective routers can allow for path validation and provide additional confidence of the authenticity of the received generator data.
[0250] Furthermore, according to various aspects, after authenticating the received generator data, the cloud-based system 205 can communicate a message (e.g., a handshake or similar message) to the surgical hub 206 via the Internet or another communication network, confirming / guaranteeing that the datagram communicated from the surgical hub 206 was received intact by the cloud-based system 205, thereby effectively closing the loop for that particular datagram.
[0251] Aspects of the above-described communication method, and / or variations thereof, can also be employed to communicate data other than generator data to the cloud-based system 205 and / or to communicate generator data and / or other data from the surgical hub 206 to systems and / or devices other than the cloud-based system 205. For example, according to various aspects, the generator data and / or other data can be communicated from the surgical hub 206 to a hand-held surgical device / instrument (e.g., wireless device / instrument 235), to a robotic interface of a surgical device / instrument (e.g., robot hub 222) and / or to other servers, including servers (e.g., similar to server 213) associated with other cloud-based systems (e.g., similar to cloud-based system 205) in accordance with the above-described communication method. For example, in certain instances, an EEPROM chip of a given surgical instrument can initially be provided with merely an electronic chip device ID. Upon connection of the given surgical instrument to the combination generator 3700, data can be downloaded from the cloud-based system 205 to the surgical hub 206 and subsequently to the EEPROM of the surgical instrument in accordance with the above-described communication method.
[0252] In addition to communicating generator data to the cloud-based system 205, the surgical hub 206 can also utilize the above-described method of communication, and / or variations thereof, to communicate data other than generator data to the cloud-based system 205. For example, the surgical hub 206 can also communicate other information associated with the surgical procedure to the cloud-based system 205. Such other information can include, for example, the type of surgical procedure being performed, the name of the facility where the surgical procedure is being performed, the location of the facility where the surgical procedure is being performed, an identification of the operating room within the facility where the surgical procedure is being performed, the name of the surgeon performing the surgical procedure, the age of the patient, and data associated with the condition of the patient (e.g., blood pressure, heart rate, current medications). According to various aspects, such other information may be stripped of all information which could identify the specific surgery, the patient, or the surgeon, so that the information is essentially anonymized for further processing and analysis by the cloud-based system 205. In other words, the stripped data is not correlated to a specific surgery, patient, or surgeon. The stripped information can be communicated to the cloud-based system 205 either together with or distinct from the communicated generator data.
[0253] For instances where the stripped / other data is to be communicated apart from the generator data, the stripped / other data can be time-stamped, compressed, and / or encrypted in a manner identical to or different from that described above regarding the generator data, and the surgical hub 206 may be programmed / configured to generate a datagram which includes the encrypted stripped / other information in lieu of the encrypted generator data. The datagram can then be communicated from the surgical hub 206 through the Internet to the cloud-based system 205 following an IP which: (1) defines datagrams that encapsulate the encrypted stripped / other data to be delivered, and (2) defines addressing methods that are used to label the datagram with source and destination information.
[0254] For instances where the stripped / other information is to be communicated with the generator data, the stripped / other data can be time-stamped, compressed, and / or encrypted in a manner identical to or different from that described above regarding the generator data, and the surgical hub 206 may be programmed / configured to generate a datagram which includes both the encrypted generator data and the encrypted stripped / other information. An example of such a datagram in shown in FIG. 30, where the payload 3804 of the datagram 3800 is divided into two or more distinct payload data portions (e.g., one for the encrypted generator data 3834, one for the encrypted stripped / other information 3836), with each portion having an identifying bit (e.g., generator data (GD) 3806, other data (OD) 3812), the associated encrypted data 3808, 3814, and the associated padding 3810, 3816, if needed, respectively. Further, as shown in FIG. 30, the header 3802 may be the same as (e.g., IP address source 3818, IP address destination 3820, header length 3822) or different from the header 3782 described with reference to the datagram 3780 shown in FIG. 29. For example, the header 3802 may be different in that the header 3802 further includes a field designating the number of payload data portions 3824 (e.g., 2) included in the payload 3804 of the datagram 3800. The header 3802 can also be different in that it can include fields designating the payload length 3826, 3830 and the checksum value 3828, 2832 for each payload data portion 3834, 3836, respectively. Although only two payload data portions are shown in FIG. 30, it will be appreciated that the payload 3804 of the datagram 3800 may include any quantity / number of payload data portions (e.g., 1, 2, 3, 4, 5), where each payload data portion includes data associated with a different aspect of the surgical procedure. The datagram 3800 can then be communicated from the surgical hub 206 through the Internet to the cloud-based system 205 following an IP which: (1) defines datagrams that encapsulate the encrypted generator data and the encrypted stripped / other data to be delivered, and (2) defines addressing methods that are used to label the datagram with source and destination information.
[0255] As set forth above, it is an unfortunate reality that the outcomes of all surgical procedures are not always optimal and / or successful. For instances where a failure event is detected and / or identified, a variation of the above-described communication methods can be utilized to isolate surgical data which is associated with the failure event (e.g., failure event surgical data) from surgical data which is not associated with the failure event (e.g., non-failure event surgical data) and communicate the surgical data which is associated with the failure event (e.g., failure event data) from the surgical hub 206 to the cloud-based system 205 on a prioritized basis for analysis. According to one aspect of the present disclosure, failure event surgical data is communicated from the surgical hub 206 to the cloud-based system 205 on a prioritized basis relative to non-failure event surgical data.
[0256] FIG. 31 illustrates various aspects of a system-implemented method of identifying surgical data associated with a failure event (e.g., failure event surgical data) and communicating the identified surgical data to a cloud-based system 205 on a prioritized basis. The method comprises (1) receiving 3838 surgical data at a surgical hub 206, wherein the surgical data is associated with a surgical procedure; (2) time-stamping 3840 the surgical data; (3) identifying 3842 a failure event associated with the surgical procedure; (4) determining 3844 which of the surgical data is associated with the failure event (e.g., failure event surgical data); (5) separating 3846 the surgical data associated with the failure event from all other surgical data (e.g., non-failure event surgical data) received at the surgical hub 206; (6) chronologizing 3848 the surgical data associated with the failure event; (7) encrypting 3850 the surgical data associated with the failure event; and (8) communicating 3852 the encrypted surgical data to a cloud-based system 205 on a prioritized basis.
[0257] More specifically, various surgical data can be captured during a surgical procedure and the captured surgical data, as well as other surgical data associated with the surgical procedure, can be communicated to the surgical hub 206. The surgical data can include, for example, data associated with a surgical device / instrument (e.g., FIG. 9, surgical device / instrument 235) utilized during the surgery, data associated with the patient, data associated with the facility where the surgical procedure was performed, and data associated with the surgeon. Either prior to or subsequent to the surgical data being communicated to and received by the surgical hub 206, the surgical data can be time-stamped and / or stripped of all information which could identify the specific surgery, the patient, or the surgeon, so that the information is essentially anonymized for further processing and analysis by the cloud-based system 205.
[0258] Once a failure event has been detected and / or identified (e.g., which can be either during or after the surgical procedure), the surgical hub 206 can determine which of the surgical data is associated with the failure event (e.g., failure event surgical data) and which of the surgical data is not associated with the surgical event (e.g., non-failure event surgical data). According to one aspect of the present disclosure, a failure event can include, for example, a detection of one or more misfired staples during a stapling portion of a surgical procedure. For example, in one aspect, referring to FIG. 9, an endoscope 239 may take snapshots while a surgical device / instrument 235 comprising an end effector including a staple cartridge performs a stapling portion of a surgical procedure. In such an aspect, an imaging module 238 may compare the snapshots to stored images and / or images downloaded from the cloud-based system 205 that convey correctly fired staples to detect a misfired staple and / or evidence of a misfired staple (e.g., a leak). In another aspect, the imaging module 238 may analyze the snapshots themselves to detect a misfired staple and / or evidence of a misfired staple. In one alternative aspect, the surgical hub 206 may communicate the snapshots to the cloud-based system 205, and a component of the cloud-based system 205 may perform the various imaging module functions described above to detect a misfired staple and / or evidence of a misfired staple and to report the detection to the surgical hub 206. According to another aspect of the present disclosure, a failure event can include a detection of a tissue temperature which is below the expected temperature during a tissue-sealing portion of a surgical procedure and / or a visual indication of excessive bleeding or oozing following a surgical procedure (e.g., FIG. 9, via endoscope 239). For example, in one aspect, referring to FIG. 9, the surgical device / instrument 235 may comprise an end effector, including a temperature sensor and the surgical hub 206, and / or the cloud-based system may compare at least one temperature detected by the temperature sensor (e.g., during a tissue-sealing portion of a surgical procedure) to a stored temperature and / or a range of temperatures expected and / or associated with that surgical procedure to detect an inadequate / low sealing temperature. In another aspect, an endoscope 239 may take snapshots during a surgical procedure. In such an aspect, an imaging module 238 may compare the snapshots to stored images and / or images downloaded from the cloud-based system 205 that convey tissue correctly sealed at expected temperatures to detect evidence of an improper / insufficient sealing temperature (e.g., charring, oozing / bleeding). Further, in such an aspect, the imaging module 238 may analyze the snapshots themselves to detect evidence of an improper / insufficient sealing temperature (e.g., charring, oozing / bleeding). In one alternative aspect, the surgical hub 206 may communicate the snapshots to the cloud-based system 205, and a component of the cloud-based system 205 may perform the various imaging module functions described above to detect evidence of an improper / insufficient sealing temperature and to report the detection to the surgical hub 206. According to the various aspects described above, in response to the detected and / or identified failure event, the surgical hub 206 may download a program from the cloud-based system 205 for execution by the surgical device / instrument 235 that corrects the detected issue (i.e., program that alters surgical device / instrument parameters to prevent misfired staples, program that alters surgical device / instrument parameters to ensure correct sealing temperature).
[0259] In some aspects, a failure event is deemed to cover a certain time period, and all surgical data associated with that certain time period can be deemed to be associated with the failure event.
[0260] After the surgical data associated with the failure event has been identified, the identified surgical data (e.g., failure event surgical data) can be separated or isolated from all of the other surgical data associated with the surgical procedure (e.g., non-failure event surgical data). The separation can be realized, for example, by tagging or flagging the identified surgical data, by storing the identified surgical data apart from all of the other surgical data associated with the surgical procedure, or by storing only the other surgical data while continuing to process the identified surgical data for subsequent prioritized communication to the cloud-based system 205. According to various aspects, the tagging or flagging of the identified surgical data can occur during the communication process when the datagram is generated as described in more detail below.
[0261] The time-stamping of all of the surgical data (e.g., either before or after the surgical data is received at the surgical hub) can be utilized by a component of the surgical hub 206 to chronologize the identified surgical data associated with the failure event. The component of the surgical hub 206 which utilizes the time-stamping to chronologize the identified surgical data can be, for example, the processor module 232, the processor 244 of the computer system 210, and / or combinations thereof. By chronologizing the identified surgical data, the cloud-based system 205 and / or other interested parties can subsequently better understand the conditions which were present leading up to the occurrence of the failure event and possibly pinpoint the exact cause of the failure event, thereby providing the knowledge to potentially mitigate a similar failure event from occurring during a similar surgical procedure performed at a future date.
[0262] Once the identified surgical data has been chronologized, the chronologized surgical data may be encrypted in a manner similar to that described above with respect to the encryption of the generator data. Thus, the identified surgical data can be encrypted to help ensure the confidentiality of the identified surgical data, either while it is being stored at the surgical hub 206 or while it is being transmitted to the cloud-based system 205 using the Internet or other computer networks. According to various aspects, a component of the surgical hub 206 utilizes an encryption algorithm to convert the identified surgical data from a readable version to an encoded version, thereby forming the encrypted surgical data associated with the failure event (e.g., FIGS. 25-27). The component of the surgical hub which utilizes the encryption algorithm can be, for example, the processor module 232, the processor 244 of the computer system 210, and / or combinations thereof. The utilized encryption algorithm can be a symmetric encryption algorithm or an asymmetric encryption algorithm.
[0263] After the identified surgical data has been encrypted, a component of the surgical hub can communicate the encrypted surgical data associated with the failure event (e.g., encrypted failure event surgical data) to the cloud-based system 205. The component of the surgical hub which communicates the encrypted surgical data to the cloud-based system 205 can be, for example, the processor module 232, a hub / switch 207 / 209 of the modular communication hub 203, the router 211 of the modular communication hub 203, or the communication module 247 of the computer system 210. According to various aspects, the communication of the encrypted surgical data (e.g., encrypted failure event surgical data) through the Internet can follow an IP which: (1) defines datagrams that encapsulate the encrypted surgical data to be delivered, and (2) defines addressing methods that are used to label the datagram with source and destination information. The datagram can be similar to the datagram shown in FIG. 29 or the datagram shown in FIG. 30, but can be different in that either the header or the payload of the datagram can include a field which includes a flag or a tag which identifies the encrypted surgical data (e.g., encrypted failure event surgical data) as being prioritized relative to other non-prioritized surgical data (e.g., encrypted non-failure event surgical data). An example of such a datagram is shown in FIG. 32, where the payload 3864 of the datagram 3860 includes a field which indicates (e.g., a prioritized designation 3834) that the payload 3864 includes prioritized surgical data (e.g., combination generator data 3868). According to various aspects, the payload 3864 of the datagram 3860 can also include non-flagged / non-tagged / non-prioritized surgical data 3836 (e.g., other surgical data 3874) as shown in FIG. 32.
[0264] According to various aspects, prior to the identified surgical data (e.g., failure event surgical data) being encrypted, the identified surgical data can be compressed (if not already compressed by the source(s) of the relevant surgical data). The compression allows for a smaller representation of the surgical data associated with the failure event to be subsequently encrypted and communicated to the cloud-based system 205. For the compression, a component of the surgical hub 206 can utilize a compression algorithm to convert a representation of the identified surgical data to a smaller representation of the identified surgical data, thereby allowing for a more efficient and economical encryption of the identified surgical data (less data to encrypt utilizes less processing resources) and a more efficient and economical communication of the encrypted surgical data (smaller representations of the surgical data within the payload of the datagrams allow for more identified surgical data to be included in a given datagram, for more identified surgical data to be communicated within a given time period, and / or for identified surgical data to be communicated with fewer communication resources). The component of the surgical hub 206 which utilizes the compression algorithm can be, for example, the processor module 232, the processor 244 of the computer system 210, and / or combinations thereof. The utilized compression algorithm can be a lossless compression algorithm or a lossy compression algorithm.
[0265] In instances where other non-prioritized surgical data (e.g., non-failure event surgical data) is to be communicated with prioritized surgical data (e.g., failure event surgical data), the other non-prioritized surgical data can be time-stamped, compressed, and / or encrypted in a manner identical to or different from that described above regarding the surgical data identified as associated with a failure event (e.g., failure event surgical data), and the surgical hub 206 may be programmed / configured to generate a datagram which includes both the encrypted prioritized surgical data (e.g., encrypted failure event surgical data) and the encrypted other non-prioritized surgical data (e.g., encrypted non-failure event surgical data). For example, in light of FIG. 32, the payload 3864 of the datagram 3860 may be divided into two or more distinct payload data portions (e.g., one for the prioritized surgical data 3834, one for the non-prioritized surgical data 3836), with each portion having an identifying bit (e.g., generator data (GD) 3866, other data (OD) 3872), the associated encrypted data (e.g., encrypted prioritized surgical data 3868, encrypted non-prioritized surgical data 3874), and the associated padding 3870, 3876, if needed, respectively. Further, similar to FIG. 30, the header 3862 may be the same as (e.g., IP address source 3878, IP address destination 3880, header length 3882) or different from the header 3782 described with reference to the datagram 3780 shown in FIG. 29. For example, the header 3862 may be different in that the header 3862 further includes a field designating the number of payload data portions 3884 (e.g., 2) included in the payload 3864 of the datagram 3860. The header 3862 can also be different in that it can include fields designating the payload length 3886, 3890 and the checksum value 3888, 2892 for each payload data portion 3834, 3836, respectively. Although only two payload data portions are shown in FIG. 32, it will be appreciated that the payload 3864 of the datagram 3860 may include any quantity / number of payload data portions (e.g., 1, 2, 3, 4, 5), where each payload data portion includes data associated with a different aspect of the surgical procedure. The datagram 3860 can then be communicated from the surgical hub 206 through the Internet to the cloud-based system 205 following an IP which: (1) defines datagrams that encapsulate the encrypted generator data and the encrypted stripped / other data to be delivered, and (2) defines addressing methods that are used to label the datagram with source and destination information.
[0266] In some aspects, once a failure event associated with a surgical procedure has been identified, the surgical hub 206 and / or the cloud-based system 205 can subsequently flag or tag a surgical device / instrument 235 which was utilized during the surgical procedure for inoperability and / or removal. For example, in one aspect, information (e.g., serial number, ID) associated with the surgical device / instrument 235 and stored at the surgical hub 206 and / or the cloud-based system 205 can be utilized to effectively block the surgical device / instrument 235 from being used again (e.g., blacklisted). In another aspect, information (e.g., serial number, ID) associated with the surgical device / instrument can initiate the printing of a shipping slip and shipping instructions for returning the surgical device / instrument 235 back to a manufacturer or other designated party so that a thorough analysis / inspection of the surgical device / instrument 235 can be performed (e.g., to determine the cause of the failure). According to various aspects described herein, once the cause of a failure is determined (e.g., via the surgical hub 206 and / or the cloud-based system 205), the surgical hub 206 may download a program from the cloud-based system 205 for execution by the surgical device / instrument 235 that corrects the determined cause of the failure (i.e., program that alters surgical device / instrument parameters to prevent the failure from occurring again).
[0267] According to some aspects, the surgical hub 206 and / or the cloud-based system 205 can also provide / display a reminder (e.g., via hub display 215 and / or surgical device / instrument display 237) to administrators, staff, and / or other personnel to physically remove the surgical device / instrument 235 from the operating room (e.g., if detected as still present in the operating room) and / or to send the surgical device / instrument 235 to the manufacturer or the other designated party. In one aspect, the reminder may be set up to be provided / displayed periodically until an administrator can remove the flag or tag of the surgical device / instrument 235 from the surgical hub 206 and / or the cloud-based system 205. According to various aspects, an administrator may remove the flag or tag once the administrator can confirm (e.g., system tracking of the surgical device / instrument 235 via its serial number / ID) that the surgical device / instrument 235 has been received by the manufacturer or the other designated party. By using the above-described method to flag and / or track surgical data associated with a failure event, a closed loop control of the surgical data associated with the failure event and / or with a surgical device / instrument 235 can be realized. Additionally, in view of the above, it will be appreciated that the surgical hub 206 can be utilized to effectively manage the utilization (or non-utilization) of surgical devices / instruments 235 which have or potentially could be utilized during a surgical procedure.
[0268] In various aspects of the present disclosure, the surgical hub 206 and / or cloud-based system 205 may want to control which components (e.g., surgical device / instrument 235, energy device 241) are being utilized in its interactive surgical system 100 / 200 to perform surgical procedures (e.g., to minimize future failure events, to avoid the use of unauthorized or knock-off components).
[0269] As such, in various aspects of the present disclosure, since an interactive surgical system 100 may comprise a plurality of surgical hubs 106, a cloud-based system 105 and / or each surgical hub 106 of the interactive surgical system 100 may want to track component-surgical hub combinations utilized over time. In one aspect, upon / after a component (See FIG. 9, e.g., surgical device / instrument 235, energy device 241) is connected to / used with a particular surgical hub 106 (e.g., surgical device / instrument 235 wired / wirelessly connected to the particular surgical hub 106, energy device 241 connected to the particular surgical hub 106 via generator module 240), the particular surgical hub 106 may communicate a record / block of that connection / use (e.g., linking respective unique identifiers of the connected devices) to the cloud-based system 105 and / or to the other surgical hubs 106 in the interactive surgical system 100. For example, upon / after the connection / use of an energy device 241, a particular surgical hub 106 may communicate a record / block (e.g., linking a unique identifier of the energy device 241 to a unique identifier of a generator module 240 to a unique identifier of the particular surgical hub 106) to the cloud-based system 105 and / or other surgical hubs 106 in the interactive surgical system 100. In such an aspect, if this is the first time the component (e.g., energy device) is connected to / used with a surgical hub 106 in the interactive surgical system 100, the cloud-based system 105 and / or each surgical hub 106 of the interactive surgical system 100 may store the record / block as a genesis record / block. In such an aspect, the genesis record / block stored at the cloud-based system 105 and / or each surgical hub 106 may comprise a time stamp. However, in such an aspect, if this is not the first time the component (e.g., energy device 241) has been connected to / used with a surgical hub 106 in the interactive surgical system 100, the cloud-based system 105 and / or each surgical hub 106 of the interactive surgical system may store the record / block as a new record / block in a chain of record / blocks associated with the component. In such an aspect, the new record / block may comprise a cryptographic hash of the most recently communicated record / block stored at the cloud-based system 105 and / or each surgical hub 106, the communicated linkage data, and a time stamp. In such an aspect, each cryptographic hash links each new record / block (e.g., each use of the component) to its prior record / block to form a chain confirming the integrity of each prior record / block(s) back to an original genesis record / block (e.g., first use of the component). According to such an aspect, this blockchain of records / blocks may be developed at the cloud-based system 105 and / or each surgical hub 106 of the interactive surgical system 100 to permanently and verifiably tie usage of a particular component to one or more than one surgical hub 106 in the interactive surgical system 100 over time. Here, according to another aspect, this approach may be similarly applied to sub-components (e.g., handle, shaft, end effector, cartridge) of a component when / after the component is connected to / used with a particular surgical hub 106 of an interactive surgical system 100.
[0270] According to various aspects of the present disclosure, the cloud-based system 105 and / or each surgical hub 106 may utilize such records / blocks to trace usage of a particular component and / or a sub-component back to its initial usage in the interactive surgical system 100. For example, if a particular component (e.g., surgical device / instrument 235) is flagged / tagged as related to a failure event, the cloud-based system 105 and / or a surgical hub 106 may analyze such records / blocks to determine whether past usage of that component and / or a sub-component of that component contributed to or caused the failure event (e.g., overused). In one example, the cloud-based system 105 may determine that a sub-component (e.g., end effector) of that component may actually be contributing / causing the failure event and then tag / flag that component for inoperability and / or removal based on the determination.
[0271] According to another aspect, the cloud-based system 205 and / or surgical hub 206 may control which components (e.g., surgical device / instrument 235, energy device 241) are being utilized in an interactive surgical system 200 to perform surgical procedures by authenticating the component and / or its supplier / manufacturer. In one aspect, the supplier / manufacturer of a component may associate a serial number and a source ID with the component. In such an aspect, the supplier / manufacturer may create / generate a private key for the serial number, encrypt the serial number with the private key, and store the encrypted serial number and the source ID on an electronic chip (e.g., memory) in the component prior to shipment to a surgical site. Here, upon / after connection of the component to a surgical hub 206, the surgical hub 206 may read the encrypted serial number and the source ID from the electronic chip. In response, the surgical hub 206 may send a message (i.e., comprising the encrypted serial number) to a server of the supplier / manufacturer associated with the source ID (e.g., directly or via the cloud-based system 205). In such an aspect, the surgical hub 206 may encrypt the message using a public key associated with that supplier / manufacturer. In response, the surgical hub 206 may receive a message (i.e., comprising the private key the supplier / manufacturer generated for / associated with that encrypted serial number) from the supplier / manufacturer server (e.g., directly or via the cloud-based system 205). In such an aspect, the supplier / manufacturer server may encrypt the message using a public key associated with the surgical hub 206. Further, in such an aspect, the surgical hub 206 may then decrypt the message (e.g., using a private key paired to the public key used to encrypt the message) to reveal the private key associated with the encrypted serial number. The surgical hub 206 may then decrypt the encrypted serial number, using that private key, to reveal the serial number. Further, in such an aspect, the surgical hub 206 may then compare the decrypted serial number to a comprehensive list of authorized serial numbers (e.g., stored at the surgical hub 206 and / or the cloud-based system and / or downloaded from the cloud-based system, e.g., received separately from the supplier / manufacturer) and permit use of the connected component if the decrypted serial number matches an authorized serial number. Initially, such a process permits the surgical hub 206 to authenticate the supplier / manufacturer. In particular, the surgical hub 206 encrypted the message comprising the encrypted serial number using a public key associated with the supplier / manufacturer. As such, receiving a response message (i.e., comprising the private key) authenticates the supplier / manufacturer to the surgical hub 206 (i.e., otherwise the supplier / manufacturer would not have access to the private key paired to the public key used by the surgical hub 206 to encrypt the message, and the supplier / manufacturer would not have been able to associate the encrypted serial number received in the message to its already generated private key). Furthermore, such a process permits the surgical hub 206 to authenticate the connected component / device itself. In particular, the supplier / manufacturer (e.g., just authenticated) encrypted the serial number of the component using the delivered private key. Upon secure receipt of the private key, the surgical hub 206 is able to decrypt the encrypted serial number (i.e., read from the connected component), which authenticates the component and / or its association with the supplier / manufacturer (i.e., only that private key as received from that supplier / manufacturer would decrypt the encrypted serial number). Nonetheless, the surgical hub 206 further verifies the component as authentic (e.g., compares the decrypted serial number to a comprehensive list of authorized serial numbers received separately from the supplier / manufacturer). Notably, such aspects as described above can alternatively be performed by the cloud-based system 205 and / or a combination of the cloud-based system 205 and the surgical hub 206 to control which components (e.g., surgical device / instrument 235, energy device 241) are being utilized in an interactive surgical system 200 (e.g., to perform surgical procedures) by authenticating the component and / or its supplier / manufacturer. In one aspect, such described approaches may prevent the use of knock-off component(s) within the interactive surgical system 200 and ensure the safety and well-being of surgical patients.
[0272] According to another aspect, the electronic chip of a component (e.g., surgical device / instrument 235, energy device 241) may store (e.g., in memory) data associated with usage of that component (i.e., usage data, e.g., number of uses with a limited use device, number of uses remaining, firing algorithms executed, designation as a single-use component). In such an aspect, the surgical hub 206 and / or the cloud-based system 205, upon / after connection of the component to the interactive surgical system, may read such usage data from the memory of a component and write back at least a portion of that usage data for storage (e.g., in memory 249) at the surgical hub 206 and / or for storage at the cloud-based system 205 (e.g., individually and / or under a blockchain approach discussed herein). According to such an aspect, the surgical hub 206 and / or the cloud-based system 205, upon / after a subsequent connection of that component to the interactive surgical system, may again read such usage data and compare that usage to previously stored usage data. Here, if a discrepancy exists or if a predetermined / authorized usage has been met, the surgical hub 206 and / or the cloud-based system 205 may prevent use of that component (e.g., blacklisted, rendered inoperable, flagged for removal) on the interactive surgical system 200. In various aspects, such an approach prevents bypass of the encryption chip systems. If the component's electronic chip / memory has been tampered with (e.g., memory reset, number of uses altered, firing algorithms altered, single-use device designated as a multi-use device), a discrepancy will exist, and the component's use will be controlled / prevented.
[0273] Additional details are disclosed in U.S. Patent Application Publication No. 2017 / 0086914, entitled TECHNIQUES FOR OPERATING GENERATOR FOR DIGITALLY GENERATING ELECTRICAL SIGNAL WAVEFORMS AND SURGICAL INSTRUMENTS.Surgical Hub Coordination of Device Pairing in an Operating Room
[0274] One of the functions of the surgical hub 106 is to pair (also referred to herein as "connect" or "couple") with other components of the surgical system 102 to control, gather information from, or coordinate interactions between the components of the surgical system 102. Since the operating rooms of a hospital are likely in close physical proximity to one another, a surgical hub 106 of a surgical system 102 may unknowingly pair with components of a surgical system 102 in a neighboring operating room, which would significantly interfere with the functions of the surgical hub 106. For example, the surgical hub 106 may unintentionally activate a surgical instrument in a different operating room or record information from a different ongoing surgical procedure in a neighboring operating room.
[0275] A surgical hub 106 according to the present invention only pairs with detected devices of the surgical system 102 that are located within the bounds of its operating room.
[0276] Furthermore, the surgical hub 106 may rely on its knowledge of the location of other components of the surgical system 102 within its operating room in making decisions about, for example, which surgical instruments should be paired with one another or activated. A change in the position of the surgical hub 106 or another component of the surgical system 102 can be problematic.
[0277] Furthermore, the surgical hub 106 of the present invention may be configured to reevaluate or redetermine the bounds of its operating room upon detecting that the surgical hub 106 has been moved. The surgical hub 106 may be configured to redetermine the bounds of its operating room upon detection of a potential device of the surgical system 102, which can be an indication that the surgical hub 106 has been moved.
[0278] In various aspects, a surgical hub 106 is used with a surgical system 102 in a surgical procedure performed in an operating room. The surgical hub 106 comprises a control circuit configured to determine the bounds of the operating room, determine devices of the surgical system 102 located within the bounds of the operating room, and pair the surgical hub 106 with the devices of the surgical system 102 located within the bounds of the operating room.
[0279] In one aspect, the control circuit is configured to determine the bounds of the operating room after activation of the surgical hub 106. In one aspect, the surgical hub 106 includes a communication circuit configured to detect and pair with the devices of the surgical system located within the bounds of the operating room. In one aspect, the control circuit is configured to redetermine the bounds of the operating room after a potential device of the surgical system 102 is detected. In one aspect, the control circuit is configured to periodically determine the bounds of the operating room.
[0280] In one aspect, the surgical hub 106 comprises an operating room mapping circuit that includes a plurality of non-contact sensors configured to measure the bounds of the operating room.
[0281] In various aspects, the surgical hub 106 includes a processor and a memory coupled to the processor. The memory stores instructions executable by the processor to pair the surgical hub with devices of the surgical system 102 located within the bounds of the operating room, as described above. In various aspects, the present disclosure provides a non-transitory computer-readable medium storing computer-readable instructions which, when executed, cause a machine to pair the surgical hub 106 with devices of the surgical system 102 located within the bounds of the operating room, as described above.
[0282] FIGS. 35 and 36 are logic flow diagrams of processes depicting control programs or logic configurations for pairing the surgical hub 106 with devices of the surgical system 102 located within the bounds of the operating room, as described above.
[0283] The surgical hub106 performs a wide range of functions that requires short- and long-range communication, such as assisting in a surgical procedure, coordinating between devices of the surgical system 102, and gathering and transmitting data to the cloud 104. To properly perform its functions, the surgical hub 106 is equipped with a communication module 130 capable of short-range communication with other devices of the surgical system 102. The communication module 130 is also capable of long-range communication with the cloud 104.
[0284] The surgical hub 106 is also equipped with an operating-room mapping module 133 which is capable of identifying the bounds of an operating room, and identifying devices of the surgical system 102 within the operating room. The surgical hub 106 is configured to identify the bounds of an operating room, and only pair with or connect to potential devices of the surgical system 102 that are detected within the operating room.
[0285] In one aspect, the pairing comprises establishing a communication link or pathway. In another aspect, the pairing comprises establishing a control link or pathway.
[0286] An initial mapping or evaluation of the bounds of the operating room takes place during an initial activation of the surgical hub 106. Furthermore, the surgical hub 106 is configured to maintain spatial awareness during operation by periodically mapping its operating room, which can be helpful in determining if the surgical hub 106 has been moved. The reevaluation 3017 can be performed periodically or it can be triggered by an event such as observing a change in the devices of the surgical system 102 that are deemed within the operating room. In one aspect, the change is detection 3010 of a new device that was not previously deemed as within the bounds of the operating room, as illustrated in FIG. 37. In another aspect, the change is a disappearance, disconnection, or un-pairing of a paired device that was previously deemed as residing within the operating room, as illustrated in FIG. 38. The surgical hub 106 may continuously monitor 3035 the connection with paired devices to detect 3034 the disappearance, disconnection, or un-pairing of a paired device.
[0287] In other aspects, reevaluation triggering events can be, for example, changes in surgeons' positions, instrument exchanges, or sensing of a new set of tasks being performed by the surgical hub 106.
[0288] In one aspect, the evaluation of the bounds of the room by the surgical hub 106 is accomplished by activation of a sensor array of the operating-room mapping module 133 within the surgical hub 106 which enables it to detect the walls of the operating room.
[0289] Other components of the surgical system 102 can be made to be spatially aware in the same, or a similar, manner as the surgical hub 106. For example, a robotic hub 122 may also be equipped with an operating-room mapping module 133.
[0290] The spatial awareness of the surgical hub 106 and its ability to map an operating room for potential components of the surgical system 102 allows the surgical hub 106 to make autonomous decisions about whether to include or exclude such potential components as part of the surgical system 102, which relieves the surgical staff from dealing with such tasks. Furthermore, the surgical hub 106 is configured to make inferences about, for example, the type of surgical procedure to be performed in the operating room based on information gathered prior to, during, and / or after the performance of the surgical procedure. Examples of gathered information include the types of devices that are brought into the operating room, time of introduction of such devices into the operating room, and / or the devices sequence of activation.
[0291] In one aspect, and in accordance with the invention, the surgical hub 106 employs the operating-room mapping module 133 to determine the bounds of the surgical theater (e.g., a fixed, mobile, or temporary operating room or space) using either ultrasonic or laser non-contact measurement devices.
[0292] Referring to FIG. 34, ultrasound based non-contact sensors 3002 can be employed to scan the operating theater by transmitting a burst of ultrasound and receiving the echo when it bounces off a perimeter wall 3006 of an operating theater to determine the size of the operating theater and to adjust Bluetooth pairing distance limits. In one example, the non-contact sensors 3002 can be Ping ultrasonic distance sensors, as illustrated in FIG. 34.
[0293] FIG. 34 shows how an ultrasonic sensor 3002 sends a brief chirp with its ultrasonic speaker 3003 and makes it possible for a micro-controller 3004 of the operating-room mapping module 133 to measure how long the echo takes to return to the ultrasonic sensor's ultrasonic microphone 3005. The micro-controller 3004 has to send the ultrasonic sensor 3002 a pulse to begin the measurement. The ultrasonic sensor 3002 then waits long enough for the micro-controller program to start a pulse input command. Then, at about the same time the ultrasonic sensor 3002 chirps a 40 kHz tone, it sends a high signal to the micro-controller 3004. When the ultrasonic sensor 3002 detects the echo with its ultrasonic microphone 3005, it changes that high signal back to low. The micro-controller's pulse input command measures the time between the high and low changes and stores its measurement in a variable. This value can be used along with the speed of sound in air to calculate the distance between the surgical hub 106 and the operating-room wall 3006.
[0294] In one example, as illustrated in FIG. 33, a surgical hub 106 can be equipped with four ultrasonic sensors 3002, wherein each of the four ultrasonic sensors is configured to assess the distance between the surgical hub 106 and a wall of the operating room 3000. A surgical hub 106 can be equipped with more or less than four ultrasonic sensors 3002 to determine the bounds of an operating room.
[0295] Other distance sensors can be employed by the operating-room mapping module 133 to determine the bounds of an operating room. In one example, the operating-room mapping module 133 can be equipped with one or more photoelectric sensors that can be employed to assess the bounds of an operating room. In one example, suitable laser distance sensors can also be employed to assess the bounds of an operating room. Laser-based non-contact sensors may scan the operating theater by transmitting laser light pulses, receiving laser light pulses that bounce off the perimeter walls of the operating theater, and comparing the phase of the transmitted pulse to the received pulse to determine the size of the operating theater and to adjust Bluetooth pairing distance limits.
[0296] Referring to the top left corner of FIG. 33, a surgical hub 106 is brought into an operating room 3000. The surgical hub 106 is activated at the beginning of the set-up that occurs prior to the surgical procedure. In the example of FIG. 33, the set-up starts at an actual time of 11:31:14 (EST) based on a real-time clock. However, at the stated procedure set-up start time, the surgical hub 106 starts 3001 an artificial randomized real-time clock timing scheme at artificial real time 07:36:00 to protect private patient information.
[0297] At artificial real time 07:36:01, the operating-room mapping module 133 employs the ultrasonic distance sensors to ultrasonically ping the room (e.g., sends out a burst of ultrasound and listens for the echo when it bounces off the perimeter walls of the operating room as described above) to verify the size of the operating room and to adjust pairing distance limits.
[0298] At artificial real time 07:36:03, the data is stripped and time-stamped. At artificial real time 07:36:05, the surgical hub 106 begins pairing devices located only within the operating room 3000 as verified using ultrasonic distance sensors 3002 of the operating-room mapping module 133. The top right corner of FIG. 33 illustrates several example devices that are within the bounds of the operating room 3000 and are paired with the surgical hub 106, including a secondary display device 3020, a secondary hub 3021, a common interface device 3022, a powered stapler 3023, a video tower module 3024, and a powered handheld dissector 3025. On the other hand, secondary hub 3021', secondary display device 3020', and powered stapler 3026 are all outside the bounds of the operating room 3000 and, accordingly, are not paired with the surgical hub 106.
[0299] In addition to establishing a communication link with the devices of the surgical system 102 that are within the operating room, the surgical hub 106 also assigns a unique identification and communication sequence or number to each of the devices. The unique sequence may include the device's name and a time stamp of when the communication was first established. Other suitable device information may also be incorporated into the unique sequence of the device.
[0300] As illustrated in the top left corner of FIG. 33, the surgical hub 106 has determined that the operating room 3000 bounds are at distances a, -a, b, and -b from the surgical hub 106. Since Device "D" is outside the determined bounds of its operating room 3000, the surgical hub 106 will not pair with the Device "D." FIG. 35 is an example algorithm illustrating how the surgical hub 106 only pairs with devices within the bounds of its operating room. After activation, the surgical hub 106 determines 3007 bounds of the operating room using the operating-room mapping module 133, as described above. After the initial determination, the surgical hub 106 continuously searches for or detects 3008 devices within a pairing range. If a device is detected 3010, the surgical hub 106 then determines 3011 whether the detected device is within the bounds of the operating room. The surgical hub 106 pairs 3012 with the device if it is determined that the device is within the bounds of the operating room. In certain instances, the surgical hub 106 will also assign 3013 an identifier to the device. If, however, the surgical hub 106 determines that the detected device is outside the bounds of the operating room, the surgical hub 106 will ignore 3014 the device.
[0301] Referring to FIG. 36, after an initial determination of the bounds of the room, and after an initial pairing of devices located within such bounds, the surgical hub 106 continues to detect 3015 new devices that become available for pairing. If a new device is detected 3016, the surgical hub 106 is configured to reevaluate 3017 the bounds of the operating room prior to pairing with the new device. If the new device is determined 3018 to be within the newly determined bounds of the operating room, then the surgical hub 106 pairs with the device 3019 and assigns 3030 a unique identifier to the new device. If, however, the surgical hub 106 determines that the new device is outside the newly determined bounds of the operating room, the surgical hub 106 will ignore 3031 the device.
[0302] For pairing, the operating-room mapping module 133 contains a compass and integrated Bluetooth transceiver. Other communication mechanisms, which are not significantly affected by the hospital environment or geographical location, can be employed. Bluetooth Low Energy (BLE) beacon technology can currently achieve indoor distance measurements with accuracy of about 1-2 meters, with improved accuracy in closer proximities (within 0-6 meters). To improve the accuracy of the distance measurements, a compass is used with the BLE. The operating-room mapping module 133 utilizes the BLE and the compass to determine where modules are located in relation to the patient. For example, two modules facing each other (detected by compass) with greater than one meter distance between them may clearly indicate that the modules are on opposite sides of the patient. The more "Hub"-enabled modules that reside in the operating room, the greater the achievable accuracy becomes due to triangulation techniques.
[0303] In the situations where multiple surgical hubs 106, modules, and / or other peripherals are present in the same operating room, as illustrated in the top right corner of FIG. 33, the operating-room mapping module 133 is configured to map the physical location of each module that resides within the operating room. This information could be used by the user interface to display a virtual map of the room, enabling the user to more easily identify which modules are present and enabled, as well as their current status. In one aspect, the mapping data collected by surgical hubs 106 are uploaded to the cloud 104, where the data are analyzed for identifying how an operating room is physically setup, for example.
[0304] The surgical hub 106 is configured to determine a device's location by assessing transmission radio signal strength and direction. For Bluetooth protocols, the Received Signal Strength Indication (RSSI) is a measurement of the received radio signal strength. In one aspect, the devices of the surgical system 102 can be equipped with USB Bluetooth dongles. The surgical hub 106 may scan the USB Bluetooth beacons to get distance information. In another aspect, multiple high-gain antennas on a Bluetooth access point with variable attenuators can produce more accurate results than RSSI measurements. In one aspect, the hub is configured to determine the location of a device by measuring the signal strength from multiple antennas. Alternatively, in some examples, the surgical hub 106 can be equipped with one or more motion sensor devices configured to detect a change in the position of the surgical hub 106.
[0305] Referring to the bottom left corner of FIG. 33, the surgical hub 106 has been moved from its original position, which is depicted in dashed lines, to a new position closer to the device "D," which is still outside the bounds of the operating room 3000. The surgical hub 106 in its new position, and based on the previously determined bounds of the operating room, would naturally conclude that the device "D" is a potential component of the surgical system 102. However, the introduction of a new device is a triggering event for reevaluation 3017 of the bounds of the operating room, as illustrated in the example algorithm of FIGS. 35, 37. After performing the reevaluation, the surgical hub 106 determines that the operating room bounds have changed. Based on the new bounds, at distances a new , -a new , b new , and -b new , the surgical hub 106 concludes that it has been moved and that the Device "D" is outside the newly determined bounds of its operating room. Accordingly, the surgical hub 106 will still not pair with the Device "D."
[0306] In one aspect, one or more of the processes depicted in FIGS. 35-39 can be executed by a control circuit of a surgical hub 106, as depicted in FIG. 10 (processor 244). In another aspect, one or more of the processes depicted in FIGS. 35-39 can be executed by a cloud computing system 104, as depicted in FIG. 1. In yet another aspect, one or more of the processes depicted in FIGS. 35-39 can be executed by at least one of the aforementioned cloud computing systems 104 and / or a control circuit of a surgical hub 106 in combination with a control circuit of a modular device, such as the microcontroller 461 of the surgical instrument depicted in FIG. 12, the microcontroller 620 of the surgical instrument depicted in FIG. 16, the control circuit 710 of the robotic surgical instrument 700 depicted in FIG. 17, the control circuit 760 of the surgical instruments 750, 790 depicted in FIGS. 18-19, or the controller 838 of the generator 800 depicted in FIG. 20.Spatial Awareness of Surgical Hubs in Operating Rooms
[0307] During a surgical procedure, a surgical instrument such as an ultrasonic or an RF surgical instrument can be coupled to a generator module 140 of the surgical hub 106 according to the invention. In addition, a separate surgical instrument controller such as a foot, or hand, switch or activation device can be used by an operator of the surgical instrument to activate the energy flow from the generator to the surgical instrument. Multiple surgical instrument controllers and multiple surgical instruments can be used concurrently in an operating room. Pressing or activating the wrong surgical instrument controller can lead to undesirable consequences. A surgical hub 106 of the invention coordinates the pairing of surgical instrument controllers and surgical instruments to ensure patient and operator safety.
[0308] A surgical hub 106 according to the invention may be configured to establish and sever pairings between components of the surgical system 102 within the bounds of the operating room to coordinate flow of information and control actions between such components. The surgical hub 106 can be configured to establish a pairing between a surgical instrument controller and a surgical instrument that reside within the bounds of an operating room of surgical hub 106.
[0309] The surgical hub 106 of the invention can be configured to establish and sever pairings between components of the surgical system 102 based on operator request or situational and / or spatial awareness. The hub situational awareness is described in greater detail below in connection with FIG. 62.
[0310] A surgical hub of the invention is for use with a surgical system in a surgical procedure performed in an operating room. The surgical hub includes a control circuit that selectively forms and severs pairings between devices of the surgical system. In one aspect, the hub includes a control circuit is configured to pair the hub with a first device of the surgical system, assign a first identifier to the first device, pair the hub with a second device of the surgical system, assign a second identifier to the second device, and selectively pair the first device with the second device. In one aspect, the surgical hub includes a storage medium, wherein the control circuit is configured to store a record indicative of the pairing between the first device and the second device in the storage medium. In one aspect, the pairing between the first device and the second device defines a communication pathway therebetween. In one aspect, the pairing between the first device and the second device defines a control pathway for transmitting control actions from the second device to the first device.
[0311] Further to the above, in one aspect, the control circuit is further configured to pair the hub with a third device of the surgical system, assign a third identifier to the third device, sever the pairing between the first device and the second device, and selectively pair the first device with the third device. In one aspect, the control circuit is further configured to store a record indicative of the pairing between the first device and the third device in the storage medium. In one aspect, the pairing between the first device and the third device defines a communication pathway therebetween. In one aspect, the pairing between the first device and the third device defines a control pathway for transmitting control actions from the third device to the first device.
[0312] In various aspects, the surgical hub includes a processor and a memory coupled to the processor. The memory stores instructions executable by the processor to selectively form and sever pairings between the devices of the surgical system, as described above. In various aspects, the present disclosure provides a non-transitory computer-readable medium storing computer-readable instructions which, when executed, cause a machine to selectively form and sever pairings between the devices of the surgical system, as described above. FIGS. 40 and 41 are logic flow diagrams of processes depicting control programs or logic configurations for selectively forming and severing pairings between the devices of the surgical system, as described above.
[0313] In one aspect, the surgical hub 106 establishes a first pairing with a surgical instrument and a second pairing with the surgical instrument controller. The surgical hub 106 then links the pairings together allowing the surgical instrument and the surgical instrument controller to operate with one another. In another aspect, the surgical hub 106 may sever an existing communication link between a surgical instrument and a surgical instrument controller, then link the surgical instrument to another surgical instrument controller that is linked to the surgical hub 106.
[0314] In one aspect, the surgical instrument controller is paired to two sources. First, the surgical instrument controller is paired to the surgical hub 106, which includes the generator module 140, for control of its activation. Second, the surgical instrument controller is also paired to a specific surgical instrument to prevent inadvertent activation of the wrong surgical instrument.
[0315] Referring to FIGS. 40 and 42, the surgical hub 106 may cause the communication module 130 to pair 3100 or establish a first communication link 3101 with a first device 3102 of the surgical system 102, which can be a first surgical instrument. Then, the hub may assign 3104 a first identification number to the first device 3102. This is a unique identification and communication sequence or number that may include the device's name and a time stamp of when the communication was first established.
[0316] In addition, the surgical hub 106 may then cause the communication module 130 to pair 3106 or establish a second communication link 3107 with a second device 3108 of the surgical system 102, which can be a surgical instrument controller. The surgical hub 106 then assigns 3110 a second identification number to the second device 3108.
[0317] In various aspects, the steps of pairing a surgical hub 106 with a device may include detecting the presence of a new device, determining that the new device is within bounds of the operating room, as described above in greater detail, and only pairing with the new device if the new device is located within the bounds of the operating room.
[0318] The surgical hub 106 may then pair 3112 or authorize a communication link 3114 to be established between the first device 3102 and the second device 3108, as illustrated in FIG. 42. A record indicative of the communication link 3114 is stored by the surgical hub 106 in the storage array 134. In one aspect, the communication link 3114 is established through the surgical hub 106. In another aspect, as illustrated in FIG. 42, the communication link 3114 is a direct link between the first device 3102 and the second device 3108.
[0319] Referring to FIGS. 41 and 43, the surgical hub 106 may then detect and pair 3120 or establish a third communication link 3124 with a third device 3116 of the surgical system 102, which can be another surgical instrument controller, for example. The surgical hub 106 may then assign 3126 a third identification number to the third device 3116.
[0320] In certain aspects, as illustrated in FIG. 43, the surgical hub 106 may then pair 3130 or authorize a communication link 3118 to be established between the first device 3102 and the third device 3116, while causing the communication link 3114 to be severed 3128, as illustrated in FIG. 43. A record indicative of the formation of the communication link 3118 and severing of the communication link 3114 is stored by the surgical hub 106 in the storage array 134. In one aspect, the communication link 3118 is established through the surgical hub 106. In another aspect, as illustrated in FIG. 43, the communication link 3118 is a direct link between the first device 3102 and the third device 3116.
[0321] As described above, the surgical hub 106 can manage an indirect communication between devices of the surgical system 102. For example, in situations where the first device 3102 is a surgical instrument and the second device 3108 is a surgical instrument controller, an output of the surgical instrument controller can be transmitted through the communication link 3107 to the surgical hub 106, which may then transmit the output to the surgical instrument through the communication link 3101.
[0322] In making a decision to connect or sever a connection between devices of the surgical system 102, the surgical hub 106 may rely on perioperative data received or generated by the surgical hub 106. Perioperative data includes operator input, hub-situational awareness, hub-spatial awareness, and / or cloud data. For example, a request can be transmitted to the surgical hub 106 from an operator user-interface to assign a surgical instrument controller to a surgical instrument. If the surgical hub 106 determines that the surgical instrument controller is already connected to another surgical instrument, the surgical hub 106 may sever the connection and establish a new connection per the operator's request.
[0323] In certain examples, the surgical hub 106 may establish a first communication link between the visualization system 108 and the primary display 119 to transmit an image, or other information, from the visualization system 108, which resides outside the sterile field, to the primary display 119, which is located within the sterile field. The surgical hub 106 may then sever the first communication link and establish a second communication link between a robotic hub 122 and the primary display 119 to transmit another image, or other information, from the robotic hub 122 to the primary display 119, for example. The ability of the surgical hub 106 to assign and reassign the primary display 119 to different components of the surgical system 102 allows the surgical hub 106 to manage the information flow within the operating room, particularly between components inside the sterile field and outside the sterile field, without physically moving these components.
[0324] In another example that involves the hub-situational awareness, t...
Claims
1. A surgical hub (106) for use with a surgical system (102) in a surgical procedure performed in an operating room, wherein the surgical hub comprises: an operating-room mapping module (133) comprising at least one non-contact distance sensor; means for determining the locations of devices of the surgical system located within a pairing range of the surgical hub by assessing transmission radio signal strength and direction; and a control circuit configured to: determine bounds of the operating room using the at least one non-contact distance sensor of the operating-room mapping module; detect devices of the surgical system within the pairing range of the surgical hub; determine the locations of detected devices using the means for determining the locations of devices; determine whether the detected devices of the surgical system are located within the determined bounds of the operating room; and pair the surgical hub with the devices of the surgical system that are located within the bounds of the operating room.
2. The surgical hub of Claim 1, wherein the control circuit is configured to determine the bounds of the operating room after activation of the surgical hub.
3. The surgical hub of any preceding Claim, wherein the control circuit is configured to redetermine the bounds of the operating room after determining that the surgical hub has been moved.
4. The surgical hub of any preceding Claim, wherein the control circuit is configured to redetermine the bounds of the operating room after a potential device of the surgical system is detected.
5. The surgical hub of any preceding Claim, wherein the control circuit is configured to periodically determine the bounds of the operating room.
6. The surgical hub of any preceding Claim, wherein the control circuit comprises: a processor; and a memory coupled to the processor, the memory storing instructions executable by the processor to: determine bounds of the operating room using the at least one non-contact distance sensor of the operating-room mapping module; detect devices of the surgical system within the pairing range of the surgical hub; determine the locations of detected devices using the means for determining the locations of devices; determine whether the detected devices of the surgical system are located within the bounds of the operating room; and pair the surgical hub with the devices of the surgical system that are located within the bounds of the operating room.
7. A non-transitory computer readable medium storing computer readable instructions which, when executed by a processor of a surgical hub, cause the surgical hub (106) to: determine bounds of an operating room using an operating-room mapping module (133) of the surgical hub, the operating-room mapping module comprising at least one non-contact distance sensor; detect devices of the surgical system within a pairing range of the surgical hub; determine the locations of detected devices using means of the surgical hub for determining the locations of devices of the surgical system located within the pairing range of the surgical hub by assessing transmission radio signal strength and direction; determine whether the detected devices of the surgical system are located within the determined bounds of the operating room; and pair the surgical hub with the devices of the surgical system located within the bounds of the operating room.
8. The non-transitory computer readable medium of Claim 7, wherein the computer readable instructions, when executed, further cause the surgical hub to determine the bounds of the operating room after activation of the surgical hub.
9. The non-transitory computer readable medium of Claim 7 or Claim 8, wherein the computer readable instructions, when executed, further cause the surgical hub to redetermine the bounds of the operating room after determining that the surgical hub has been moved.
10. The non-transitory computer readable medium of any one of Claims 7 to 9, wherein the computer readable instructions, when executed, further cause the surgical hub to redetermine the bounds of the operating room after a potential device of the surgical system is detected.
11. The non-transitory computer readable medium of any one of Claims 7 to 10, wherein the computer readable instructions, when executed, further cause the surgical hub to periodically determine the bounds of the operating room.