Method, server, respiratory therapy system, respiratory therapy device, system, and apparatus
Secure wireless communication methods using shared secrets and authentication codes address unauthorized access and compliance issues in respiratory treatment systems, enhancing patient safety and treatment efficacy.
Patent Information
- Application Number
- JP2025128456
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2017-02-14
- Filing Date
- 2025-07-31
- Publication Date
- 2025-12-09
AI Technical Summary
Existing respiratory treatment systems face challenges in ensuring secure communication and compliance with therapy protocols, leading to potential unauthorized access and compromised data integrity, which affects patient safety and treatment efficacy.
Implementing a method for secure wireless communication between respiratory treatment devices and control devices using shared secrets and authentication codes, ensuring authorized access and secure data transmission to remote servers, thereby enhancing security and compliance verification.
Enhances the security and reliability of respiratory treatment systems by preventing unauthorized access and ensuring compliance with therapy protocols, thereby improving patient safety and treatment effectiveness.
Smart Images

Figure 2025179052000001_ABST
Abstract
Description
[Technical Field]
[0001] 1 Cross-reference to related applications This application is a joint venture of U.S. Provisional Patent Application No. 62 / 416,867 (filed November 3, 2016). and the benefit of U.S. Provisional Patent Application No. 62 / 458,658 (filed February 14, 2017). No. 6,299,333, filed Dec. 1, 2002, the entire contents of which are incorporated herein by reference.
[0002] 2. Technical Background 2.1 Technology field The technology relates to one or more of the detection, diagnosis, treatment, prevention, and amelioration of respiratory-related diseases. The present technology also relates to medical devices or apparatus and the use or operation thereof. [Background technology]
[0003] 2.2 Description of Related Art 2.2.1 The human respiratory system and its diseases The body's respiratory system facilitates gas exchange. The nose and mouth form the entrance to a patient's airways. Complete.
[0004] These airways contain a series of branching tubes that narrow as they go deeper into the lungs. The lungs' main function is gas exchange, taking oxygen from the air into the venous blood. The trachea divides into the right and left main bronchi, which The main bronchi further divide into terminal bronchioles. The airways are divided into respiratory tracts and do not participate in gas exchange. These become the bronchi and finally the alveoli. Gas exchange occurs in the alveolar region of the lungs, and this region This is called the breathing zone. See: "Respiratory Physiol John B. West, Lippincott Willia ms&Wilkins, ninth edition published 2012 .
[0005] A range of respiratory diseases exists. Certain diseases have specific manifestations (e.g., apnea, It may be characterized by hypopnea and hyperpnea.
[0006] Examples of respiratory disorders include obstructive sleep apnea (OSA), Cheyne-Stokes respiration (C SR), respiratory failure (RF), obesity hyperventilation syndrome (OHS), chronic obstructive pulmonary disease (COPD) ), neuromuscular diseases (NMD) and chest wall diseases.
[0007] Obstructive sleep apnea (OSA) is a form of sleep-disordered breathing (SDB) that affects It is characterized by respiratory episodes such as closure or obstruction of the upper airways during sleep. Abnormally small upper airway and normal deficits in muscle tone in the tongue region, soft palate, and posterior oropharyngeal wall These conditions cause respiratory arrest in affected patients, typically within 3 Breathing stops for 0-120 seconds, sometimes 200-300 times a night. It can lead to excessive daytime sleepiness and contribute to cardiovascular disease and brain damage. It is a common disease that is particularly prevalent in middle-aged, overweight men, but patients do not experience any symptoms. See, 944,310 (Sullivan).
[0008] Respiratory failure is a general term for respiratory disorders that can result in the inability to inhale enough oxygen to meet the patient's needs. Respiratory failure refers to the inability of the lungs to expel sufficient CO2. It may include some or all of the following conditions:
[0009] Obesity Hyperventilation Syndrome (OHS) is a severe form of hypoventilation in the absence of any other obvious cause. Defined as a combination of obesity and awake chronic hypercapnia. Symptoms include shortness of breath, , including morning headache and excessive daytime sleepiness.
[0010] Chronic obstructive pulmonary disease (COPD) is a group of lower respiratory tract diseases that share certain common characteristics. This includes any of the following: increased resistance to air movement, prolonged expiratory phase of breathing, The reduction in length and normal elasticity of the lungs is a common cause of COPD. The causes of COPD include chronic smoking (the primary risk factor), occupational exposure, and air pollution. Symptoms include shortness of breath on exertion, chronic cough and phlegm production. There is.
[0011] Neuromuscular diseases (NMDs) are disorders that affect muscles directly through intrinsic muscle pathology or indirectly through neuropathology. NMD is a broad term that encompasses a number of diseases and illnesses that impair muscle function. Some are characterized by progressive muscle damage, resulting in the inability to walk and the need for a wheelchair. This can lead to restriction, difficulty swallowing, and respiratory muscle weakness, ultimately resulting in death from respiratory failure. Muscle disorders can be divided into the following rapidly progressive and slowly progressive disorders: (i) rapidly progressive disorders: It is characterized by muscle damage that worsens over months and leads to death within a few years (e.g., Amyotrophic lateral sclerosis (ALS) and Duchenne muscular dystonia in teenagers (ii) variable or slowly progressive muscle disorder: muscle Characterized by disabilities (e.g., limb girdle, face-shoulder) and only a slight reduction in life expectancy. Symptoms of respiratory failure in NMD include: Increased general weakness, difficulty swallowing, dyspnea on exertion and at rest, fatigue, drowsiness, headache on waking pain, and difficulty concentrating and mood changes.
[0012] Chest wall disorders are a group of thoracic deformities that result from ineffective connections between the respiratory muscles and the rib cage. These disorders are primarily characterized by restrictive disorders and are caused by prolonged hypercapnia. Scoliosis and / or kyphoscoliosis can cause severe respiratory failure. Symptoms of respiratory failure include: dyspnea on exertion, peripheral floating swelling, orthopnea, recurrent chest infections, morning headache, fatigue, poor sleep quality, and loss of appetite Shake.
[0013] A range of respiratory therapies are used to treat such conditions.
[0014] 2.2.2 Respiratory therapy Various forms of respiratory therapy (e.g., continuous positive airway pressure (CPAP) therapy, non-invasive ventilation ( NIV and invasive ventilation (IV) are used to treat or improve one or more of the above respiratory conditions. Furthermore, otherwise healthy individuals may also benefit from the prevention and treatment of respiratory diseases. It can be used.
[0015] Continuous positive airway pressure (CPAP) therapy is used in the treatment of obstructive sleep apnea (OSA). Its mechanism of action is, for example, to push the soft palate and tongue forward toward the posterior oropharyngeal wall. By retracting or retracting the airway, the continuous positive airway pressure acts as a pneumatic splint, Treatment of OSA with CPAP therapy is voluntary and may prevent upper airway closure. To obtain this benefit, such patients must be able to use one or more of the following devices to deliver their treatment: Patients may choose not to adhere to treatment if they notice: discomfort, difficulty using Difficult, expensive, and lacking in aesthetic appeal.
[0016] Non-invasive ventilation (NIV) provides ventilatory support to patients through the upper airway, improving some of the respiratory functions. Partial or complete breathing support for the patient and / or maintaining adequate oxygen levels in the body Ventilatory support is provided via a non-invasive patient interface. NIV is a treatment for CSR and respiratory failure in forms such as OHS, COPD, MD, and chest wall disorders. It is used to treat
[0017] Invasive ventilation (IV) is the process of providing ventilation to patients who are no longer able to breathe effectively on their own. Assistance is provided and may be provided using a tracheostomy tube.
[0018] High-flow therapy is a type of respiratory therapy in which airflow is increased to a higher rate relative to typical respiratory flow. HFT is used in the treatment of OSA and COPD. It is used for this purpose.
[0019] Oxygen therapy is a type of respiratory therapy that involves the introduction of oxygen-enriched air into the airways at a prescribed flow rate. Oxygen therapy is used to treat COPD.
[0020] 2.2.3 Respiratory Treatment Systems Respiratory therapy is provided by a respiratory flow and / or pressure therapy system or device. The respiratory treatment system may include a respiratory treatment device (RT device) (e.g., a respiratory pressure therapy device). Regenerative Therapy (RPT) devices), air circuits, humidifiers, patient interfaces, external control devices , and a remote server.
[0021] 2.2.3.1 Patient Interface The patient interface may be configured to provide a respiratory device, for example, by providing airflow to the airway entrance. The airflow can be used to provide the wearer with an interface to the chair. and / or delivered via a mask into the mouth, a tube into the mouth, or a tracheostomy tube into the patient's trachea Depending on the therapy being applied, the patient interface may be configured to, for example, contact an area of the patient's face with This allows for sufficient pressure dispersion along with atmospheric pressure for therapy implementation. (e.g., at a positive pressure of about 10 cmH2O relative to atmospheric pressure) In other forms of treatment, such as oxygen therapy, the patient interface, e.g., nasal The cannula is designed to facilitate delivery of gas supply to the airways at a positive pressure of approximately 10 cmH2O. May not contain sufficient sealing.
[0022] 2.2.3.2 Respiratory Therapy (RT) Devices RT devices can, for example, generate a flow of air at positive pressure for delivery to the entrance of the airways. and can be used to deliver one or more of the therapies described above. These include CPAP devices, ventilators and portable oxygen concentrators.
[0023] 2.2.3.3 Humidifier Airflow delivery without humidification can lead to drying of the airways. When used with a chair and patient interface, humidified gas is generated, which may cause discomfort to the nasal mucosa. This minimizes drying of the airway and increases patient airway comfort. Generally, the application of warm air to the facial area around the patient interface is more comfortable than cool air. Increased aptitude.
[0024] 2.2.3.4 External Control Devices Due to cost and / or ease of manufacture, the user interface of an RT device The device may be quite limited, perhaps including one or two buttons and an LED. However, in this situation, the data sent through the RT device is It is necessary to ensure that the advances in treatment that can be achieved are not compromised. One way to achieve this is to allow an external control device to control the RT device. This external control device may, for example, control parameters (e.g., pressure and / or flow rate). The transmission of the settings allows the RT device to provide all the types of respiratory therapy it is capable of providing. The external control device is configured with its own pre-configured functions to control the RT device. by running a "remote control" or special purpose software application For convenience, the external control device may take the form of a portable general-purpose computing device. In some such cases, the external control device may be used as described in more detail herein. Special purpose software application(s) may be used to accomplish the functions described in number) from a remote server via a network (e.g., the Internet) It can be configured to load.
[0025] Typically, in such an external control configuration, the RT device communicates with the external control device. For convenience, especially if the external control device is portable, Communication between the RT device and an external control device can be wireless. An unauthorized person who also possesses an external control device configured to control this It is desirable to avoid a security breach of the deployment. Easy and unauthorized access to external control devices within the scope of the RT device is the rule. This is particularly challenging for wireless communication, which is practically impossible. Protocols for communication (e.g., Bluetooth) require a certain level of May have built-in security, but is determined by the specific wireless protocol being used Certain types of unauthorized external control devices within the scope of the RT Device, such as It remains vulnerable to attack.
[0026] 2.2.3.5 Remote Server Patients who are prescribed respiratory treatment for clinical reasons are "compliant" (For example, if a patient has their RT device in compliance with one or more "compliance rules" Compensation for CPAP treatment may be obtained to determine whether An example of a compliance rule is the requirement that a patient must meet in order to be considered compliant. The study found that patients received an RT device per night for at least 21 of 30 consecutive days. It should be used for at least 4 hours to determine patient compliance. the provider of the RT device (e.g., a healthcare provider or device manufacturer) ) is a remote device configured to communicate with the RT device over a network, e.g., periodically. The remote server may operate a remote server. The remote server may operate a remote server from one of the patient's treatment or RT devices. Data may be available that describes the results of the evaluation of these compliance regulations. The remote server and / or R The device will be evaluated along with the compliance rule(s). Providers can be assured that patients are using their RT devices in accordance with compliance rules. Once determined, the healthcare provider will certify that the patient is in compliance. May notify third parties.
[0027] Additionally, the "firmware" of RT devices needs to be upgraded from time to time. RT Devices may provide upgrade files for such purposes to the device manufacturer. The information may be available from a remote server operated over a network by a third party.
[0028] Patient care benefits from communication between the patient's RT device and a remote server. The following aspects are possible.
[0029] Securing such communications is essential for safety, compliance and / or privacy reasons. This can be important for privacy reasons, e.g., to ensure that only appropriate upgrades are sent to the recipient. If this is sent and applied securely to the RT device, it can prevent unauthorized operation of the RT device. Similarly, it will be possible to securely store data generated within the device. Reliable communication of this information helps ensure the integrity of the compliance verification process. The intended or authorized recipient of the data transfer of health-related information may Other benefits are provided by the following description of some aspects of the present technology. It can be revealed from Summary of the Invention
[0030] 3. Brief description of the technology This technology is intended to provide medical devices used in the diagnosis, improvement, treatment, or prevention of respiratory diseases. In relation to the supply of these medical devices, they offer improved comfort, cost, effectiveness, ease of use and manufacturing. It has one or more of the following manufacturing possibilities.
[0031] Aspects of the present technology relate to devices used in the diagnosis, amelioration, treatment, or prevention of respiratory disorders. do.
[0032] Some aspects of the present technology allow respiratory treatment devices to be associated with authorized users. It can securely connect to the controlled device.
[0033] In accordance with one form of the present technology, a control device controls a respiratory therapy (RT) device. via physical access to the RT device, and a first shared secret (e.g., The first shared secret is then communicated over an insecure communication line. The relatively strong and more secure second A shared secret (e.g., a second, more complex token) is established, thus providing a secure communication path. A line is established between the two parties. In secure communications, a second shared secret is used to secure the Used in.
[0034] Some versions of the present technology include a method for wireless communication with a respiratory treatment device. The method includes a control device establishing an unsecured wireless communication link with a respiratory treatment device. The method may further include: The method may include obtaining a first shared secret over the line. The first shared secret may be shared with the respiratory therapy device. The method may further comprise the step of: the control device transmitting the second shared secret to the first shared secret; Performing operations using data transmitted over unsecured and insecure wireless communication links The second shared secret may be known to the respiratory treatment device and may include the first shared secret. The method is more powerful than secret communication. This may involve doing so based on a shared secret between the two.
[0035] In some versions of the method, computing the second shared secret comprises: The method may include a Hellman key exchange, in which the control device derives the session key from a second shared secret. The method may include communicating with a respiratory treatment device via a wireless link. This includes the control device encrypting and decrypting the data being transmitted using a session key. In some versions, it is possible to establish an insecure wireless communication link. may involve the controlling device computing a symmetric key known to the respiratory treatment device. Obtaining the first shared secret over the different communication lines may be used to control respiratory therapy by the controlling device. Obtaining the first shared secret may depend on physical access to the device. a control device that includes a first shared secret in machine-readable form printed on a housing of the device; The machine readable form may include scanning the form with a bar code. The code may be a QR code.
[0036] In some versions, obtaining the first shared secret involves the user of the controlling device. receiving, by the control device, a first shared secret entered via the user interface; The method includes restricting the second shared secret from being known to the respiratory treatment device. In some versions, the verification may include verification by a control device. computing a first hash value using a second shared secret; and transmitting the second hash value from the respiratory treatment device. receiving a second hash value from the first hash value over an insecure wireless communication link; and comparing the first hash value to the second hash value. is not equal to the second hash value, via the user interface of the control device The second shared secret may include generating a user output. It can be used to establish a secure wireless communication link between some In this embodiment, the method may include computing a session key from the second shared secret. The method includes controlling a control parameter of a respiratory treatment device for controlling respiratory therapy operation of the respiratory treatment device. The control parameter may include transmitting the pressure control parameter over a secure wireless communication link. The method may include one of a force setting and a flow setting. The control device receives data relating to the operation via the secure wireless communication link. The data may include time of use of the respiratory treatment device and any of a plurality of respiratory events. It may include one or more of the following:
[0037] Some versions of the technology include a computer-readable data storage medium. The data storage medium may have program instructions encoded thereon, the program instructions comprising: A method for causing a processor to perform any of the method(s) described herein. Some versions of the technology are configured to The computer may include a server having access to the data storage medium. and transmitting the program instructions from the readable data storage medium to the control device via the network. The server may be configured to receive a request to download the program. The program instructions may be transmitted in response to a request to download RAM instructions.
[0038] Some versions of the present technology are configured to wirelessly communicate with respiratory treatment devices. The control device may include a memory for storing processing instructions. The device may include a processor, the processor being configured for secure communication with the respiratory treatment device. The processor may be configured to establish an unsecured wireless communication link. The first shared secret may be obtained via a communication line different from the communication line, The shared secret is known to the respiratory treatment device. The processor and the data communicated over the insecure wireless communication link to derive a second shared secret. The second shared secret may be known to the respiratory treatment device. , may be stronger than the first shared secret.
[0039] In some versions, the control device may include a barcode reader. The processor uses a barcode reader to read the barcode printed on the housing of the respiratory treatment device. The method may be further configured to obtain the first shared secret by scanning the code. The barcode may encode a first shared secret. In some versions, the control The device may include a user interface. The processor may and further configured to obtain a first shared secret via input entered through the access point. obtain.
[0040] Some versions of the technology provide wireless communication between respiratory treatment devices and a control device. The method may include providing an insecure wireless communication link with a respiratory therapy device. The method may include establishing, with the medical device, a first shared secret and a secure and transmitting a second shared secret to the respiratory treatment device using the data communicated via the wireless communication link. The first shared secret and the second shared secret may be computed by the control device. The second shared secret may be stronger than the first shared secret. The method further comprises the step of: causing the respiratory treatment device to wirelessly communicate with the control device based on a second shared secret. This may include:
[0041] Some versions of the present technology may include a respiratory The respiratory treatment device may include a memory for storing processing instructions. The respiratory treatment device is configured to establish an insecure wireless communication link with the controlling device. The controller may include a controller configured to receive a first shared secret and a secure and a second shared secret is calculated using the data communicated via the wireless communication line. The first shared secret and the second shared secret may be stored in the control device. The second shared secret may be stronger than the first shared secret. The respiratory treatment device may include a housing that includes a printed barcode. The code may encode a first shared secret.
[0042] Some versions of the present technology may include a respiratory treatment system. The system may include a respiratory treatment device. The system may be configured to communicate wirelessly with the respiratory treatment device. The control device may include a control device that is in an unsecured wireless connection with the respiratory treatment device. The processor may include a processor configured to establish a secure line communication link. and configured to obtain the first shared secret via a communication line different from the wireless communication line that is not the The first shared secret may be known to the respiratory treatment device. using the first shared secret and the data communicated over the unsecured wireless communication link. The respiratory treatment device may be configured to compute a second shared secret. The shared secret may be known to the processor and may be stronger than the first shared secret. The respiratory therapy device may be configured to communicate wirelessly with the respiratory therapy device based on a second shared secret. The device may include a housing having a printed barcode. The printed barcode may include a first The control device may further include a barcode reader. The processor obtains a first shared secret by scanning a barcode using a barcode reader. The control device may be further configured to obtain the user interface. The processor may further include: The method may be further configured to obtain the first shared secret by
[0043] Another aspect of the technology allows for the transmission of therapy data to respiratory therapy via an untrusted control device. When data is uploaded from a medical device to a remote server, the recipient has the right to Limitations can be imposed.
[0044] Another aspect of the technology is that both the RT device and the server (rather than the control device) The secret is known by the RT device and the server-supplied " This key derives an authentication code to authenticate the treatment data. It is used to get out.
[0045] Some versions of the technology communicate with respiratory treatment devices and with a remote server. generated by the respiratory treatment device via a control device configured to communicate The method may include a method for uploading the treatment data to a remote server. The method may include receiving by the controlling device from the respiratory treatment device. The method may include the control device receiving a nonce from the control device. The method may include transmitting the information to the respiratory treatment device. The signing key may include receiving a nonce and a signing key from the respiratory treatment device and The method may rely on the control device storing the treatment data and a secret known to the remote server. The authentication code may include generating an authentication code using the treatment data and the signing key. The method may be used for authentication of a control device, the control device receiving the treatment data and the authentication code. In some versions, the authentication code may include transmitting the authentication code to a remote server. may be a hashed message authentication code. The signing key is an offset into the shared secret The offset may be received from a remote server to the control device. In some versions, the control device The signing key is then revoked by decrypting it with a symmetric key known to the medical device. It may be securely received from the treatment device.
[0046] Some versions of the technology may include a control device. The control device may include a memory and a processor. The memory may include program instructions. The program instructions may include , when executed by the processor, to generate therapy data generated by the respiratory therapy device. Control the control device to upload the program instructions to the remote server. The instruction may control the control device to receive therapy data from the respiratory therapy device. The program instructions may control the control device to receive a nonce from a remote server. The program instructions control the controlling device to transmit the nonce to the respiratory treatment device. The program instructions configure the controlling device to receive a signing key from the respiratory treatment device. The signing key is a combination of a nonce and a signature known to the respiratory treatment device and the remote server. The program instructions may generate an authentication code using the treatment data and a signing key. The control device may be controlled to generate an authentication code. The authentication code is used to authenticate the treatment data. The program instructions are configured to transmit the treatment data and the authentication code to a remote server. The control device may be controlled.
[0047] Some versions of the present technology may include: The method may include an authentication method, the method including receiving treatment data and a first authentication code. The method derives a signing key from the nonce and a secret known to the respiratory treatment device. The method may include calculating a second authentication code from the received treatment data and the signing key. The method may include comparing the first authentication code with the second authentication code. The method may include authenticating the treatment data by verifying that the data is authentic.
[0048] In some versions, the method includes transmitting the offset to the respiratory treatment device. The signature key may depend on the offset. The authentication code may include the hashed message. The method may include transmitting a nonce to the respiratory treatment device. The nonce can be a pseudo-random number.
[0049] Some versions of the technology may include a server. The server may have memory and processor. The memory may include a processor. The memory may include program instructions. The program instructions may When executed by the device, the device authenticates the therapy data generated by the respiratory therapy device. The program instructions control the server to receive the treatment data and the first authentication code. The program instructions may include controlling the server to receive the nonce and the respiratory therapy information. The program instructions may include computing a signing key from a secret known to the medical device. The program may compute a second authentication code from the received treatment data and the signing key. The instructions authenticate the treatment data by comparing the first authentication code to the second authentication code. possible.
[0050] Some versions of the present technology may include a networked respiratory treatment system The system may include a respiratory treatment device configured to deliver respiratory treatment to the patient. The system may include a remote server. The system may be configured to communicate with and remotely control the respiratory treatment device. The control device may include a control device configured to communicate with the remote server. The control device may be configured to receive therapy data from the respiratory therapy device. The control device is configured to receive the nonce from the remote server by the control device. The control device may be configured to transmit a nonce to the respiratory treatment device. The control device may be configured to receive a signing key from the respiratory treatment device. The signing key is a combination of a nonce and a secret known to the respiratory therapy device and the remote server. The control device may generate an authentication code using the treatment data and a signing key. The authentication code can be used to authenticate the treatment data. The device may be configured to transmit the treatment data and the authentication code to a remote server. In some versions, the respiratory treatment device may be a respiratory pressure treatment device. The control device communicates with the respiratory treatment device securely using a shared symmetric key. The remote server may be configured to receive the treatment data and the first authentication code. The remote server can be configured to generate a nonce and a secret known to the respiratory treatment device. The remote server may be configured to compute a signature key for the received treatment data and the signature. The remote server may be configured to compute a second authentication code from the first authentication key. and configuring the device to authenticate the treatment data by comparing the code with a second authentication code. obtain.
[0051] Some versions of the present technology may include a networked respiratory treatment system The networked respiratory therapy system is configured to deliver respiratory therapy to a patient. The networked respiratory treatment system may include a respiratory treatment device. The networked respiratory therapy system may include a control device configured to communicate with the networked respiratory therapy system. The system may include a remote server configured to communicate with the control device. The server is configured to receive the treatment data and the first authentication code from the control device. The remote server can derive a signing key from the nonce and a secret known to the respiratory treatment device. The remote server may be configured to calculate from the received treatment data and the signing key: The remote server may be configured to compute a second authentication code from the first authentication code. The device may be configured to authenticate the treatment data by comparing the first authentication code with a second authentication code. The respiratory treatment device may be a respiratory pressure treatment device. The control device may be configured to communicate with the control device securely using a shared symmetric key. The control device may be configured to receive therapy data from the respiratory therapy device. The control device may be configured to receive a nonce from a remote server. The control device may be configured to transmit a signature from the respiratory treatment device to the treatment device. The signing key may be configured to receive a nonce and a signature key from the respiratory treatment device and remote device. The controlling device may rely on a secret known to the server, such as the treatment data and the signing key. The authentication code may be configured to generate an authentication code using the authentication code. The control device can be used to transmit treatment data and authentication codes to a remote server. The device may be configured to trust the
[0052] In some versions, the respiratory treatment device receives a nonce from the remote server. The respiratory treatment device may be configured to: The server may be configured to compute a signing key from a secret known to the server. The device can be configured to generate an authentication code using the treatment data and the signing key. The respiratory treatment device is configured to transmit the treatment data and the authentication code to a remote server. It can be done.
[0053] Some versions of the present technology may include: The method may include uploading the nonce to a remote server. The method may include receiving, by the respiratory treatment device, a signing key from the nonce and a remote server. This may include computing by the respiratory treatment device a secret known to the server. The law requires that respiratory treatment devices generate authentication codes using treatment data and a signing key. The authentication code is used to authenticate the treatment data. Transmitting an authentication code from the respiratory treatment device to a remote server may be included. may be a hashed message authentication code. The signing key is an offset into the shared secret The offset may further depend on the The nonce may be a pseudorandom number. The respiratory treatment device communicates with a remote server. The respiratory treatment device may receive the nonce via a control device configured to from the control device by decrypting the nonce with a symmetric key known to the device. The respiratory treatment device may be configured to communicate with a remote server. The treatment data and the authentication code may be transmitted via the control device. By encrypting the treatment data and authentication code with a symmetric key known to the device The treatment data and authentication code may then be transmitted to the control device.
[0054] Some versions of the present technology may include a respiratory treatment device. , a pressure generator. The pressure generator may be coupled to the patient interface and The patient interface is adapted to deliver a flow of air at pressure to the patient interface. The medical device may include a memory and a processor. The memory may include program instructions. The program instructions, when executed by the processor, control the respiratory treatment device. and controlling the respiratory therapy device to upload generated therapy data to a remote server. The program instructions may include: The program instructions may control a respiratory treatment device. The program instructions may include a signing key from a nonce and a remote server. The program may control the respiratory treatment device to compute a secret known to the program. The instructions configure the respiratory therapy device to generate an authentication code using the therapy data and a signing key. The authentication code may be used to authenticate the treatment data. Controlling a respiratory therapy device to transmit therapy data and an authentication code to a remote server possible.
[0055] Some versions of the present technology may include a networked respiratory treatment system The networked respiratory therapy system is a respiratory therapy system for administering respiratory therapy to patients. The networked respiratory treatment system may include a respiratory treatment device. The respiratory treatment device may include a remote server configured to receive the The respiratory treatment device may be configured to receive a nonce from the nonce. The respiratory treatment device may receive a signing key from the nonce and The respiratory treatment device may be configured to compute a secret known to the remote server. The authentication code may be configured to generate an authentication code using the treatment data and the signing key. The respiratory treatment device may store the treatment data and the authentication code. The respiratory treatment device may be configured to transmit the respiratory pressure therapy code to a remote server. In some versions, the networked respiratory therapy device The system securely communicates with a respiratory treatment device and with a remote server. The control device may include a control device configured to: configured to communicate securely with the respiratory treatment device using a symmetric key known to the The remote server may be configured to receive the treatment data and the first authentication code. The remote server derives a signing key from the nonce and a secret known to the respiratory treatment device. The remote server may be configured to calculate the first signature from the received treatment data and the signing key. The remote server may be configured to compute a second authentication code. The device may be configured to authenticate the treatment data by comparing it with the authentication code of the device.
[0056] Some versions of the present technology include a system for receiving therapy data from a respiratory therapy device. The apparatus may include an apparatus having means for receiving a nonce from a remote server, and means for transmitting the nonce. and means for transmitting the signal to the respiratory treatment device. The method may include means for receiving a signing key, the signing key being a nonce and a signature key for the respiratory treatment device and the remote server. The device relies on a secret known to the server. The device uses the treatment data and a signing key to The system may include means for generating an authentication code, which is used to authenticate the treatment data. The device may include means for transmitting the treatment data and the authentication code to a remote server.
[0057] Some versions of the present technology may include receiving therapy from a respiratory therapy device and a first authentication code. The device may include a device having device means for receiving data. The device may include a The apparatus may include means for computing a signing key from a secret known to the receiving device. The device may include means for computing a second authentication code from the acquired treatment data and the signing key. The device authenticates the treatment data by comparing the first authentication code with the second authentication code. The method may include means for:
[0058] Some versions of the present technology include a device having a means for delivering respiratory therapy to a patient. The apparatus may include means for receiving a nonce from a remote server. may include a means to compute a signing key from a nonce and a secret known to the remote server. The apparatus may include means for generating an authentication code using the treatment data and a signing key. The authentication code is used to authenticate the treatment data. This device The method may include means for transmitting the code to a remote server.
[0059] The methods, systems, devices and apparatus described herein allow a processor to functionality (e.g., special-purpose computer processors, respiratory monitors, and / or Further, the described methods, systems, devices, and methods may enable improved respiratory therapy device functionality. Devices and equipment for the automated management, monitoring and treatment of respiratory disorders (e.g., obstructive sleep apnea) and / or enable improvements in the fields of medical and / or therapeutic technology and device communication. do.
[0060] Of course, some of the above aspects may form sub-aspects of the present technology. and / or various combinations of the various aspects may be used to provide further aspects of the present technology. Or it may constitute a sub-embodiment.
[0061] Other features of the present technology are included in the following detailed description, abstract, drawings, and claims. This becomes clear in light of the information available. [Brief explanation of the drawings]
[0062] The present technology is illustrated by way of example and not by way of limitation in the accompanying drawings, in which like reference numerals refer to: contains the following similar elements:
[0063] [Figure 1] 1 shows a system including a patient 1000 wearing a patient interface 3000, which takes the form of nasal pillows and receives air at positive pressure supplied by an RT device 4000. The air from the RT device 4000 is humidified by a humidifier 5000 and travels along an air circuit 4170 to the patient 1000. A bed companion 1100 is also shown. [Figure 2] 4.2 Respiratory System and Facial Anatomy Figure 2 shows an overview of the human respiratory system, including the nose and oral cavity, larynx, vocal folds, esophagus, trachea, bronchi, lungs, alveolar sacs, heart, and diaphragm. [Figure 3] 4.3 Patient Interface FIG. 3 shows a patient interface in the form of a nasal mask in accordance with one form of the present technology. [Figure 4A]4.4 RT Device FIG. 4A illustrates an RT device in accordance with one aspect of the present technology. [Figure 4B] 4B is a schematic diagram of the air pressure paths of an RT device 4000 in accordance with one form of the present technology, with upstream and downstream directions indicated. [Figure 4C] FIG. 4C is a schematic diagram of the electrical components of an RT device 4000 in accordance with one aspect of the present technology. [Figure 5A] 4.5 Humidifier FIG. 5A is an isometric view of a humidifier in accordance with one form of the present technology. [Figure 5B] FIG. 5B is an isometric view of a humidifier in accordance with one form of the present technology, showing the humidifier reservoir 5110 removed from the humidifier reservoir dock 5130. [Figure 6] 4.6 Secure Networked Respiratory Treatment System FIG. 6 is a schematic diagram of a networked respiratory treatment system in accordance with one form of the present technology. [Figure 7] FIG. 7 is a flowchart illustrating a method by which a control device and an RT device may establish a secure communication link therebetween, in accordance with one aspect of the present technology. [Figure 8] FIG. 8 is a flowchart illustrating methods that the RT device and the control device may each perform (to perform their respective roles in the method of FIG. 7 in accordance with one aspect of the present technology). [Figure 9] FIG. 9 is a schematic diagram of a method that may be performed by the networked respiratory treatment system of FIG. 6 to secure firmware upgrades to RT devices in accordance with one form of the present technology. [Figure 10] FIG. 10 is a schematic diagram of a method that may be performed by the networked respiratory treatment system of FIG. 6 to authenticate treatment data upload to a server in accordance with one form of the present technology. [Figure 11] FIG. 11 is a schematic diagram of a method that may be performed by the networked respiratory treatment system of FIG. 6 to authenticate treatment data upload to a server in accordance with another form of the present technology. DETAILED DESCRIPTION OF THE INVENTION
[0064] 5 Detailed Description of the Embodiments of the Present Technology Before describing the present technology in more detail, it is important to note that the present technology is not limited to the different methods described herein. It should be understood that the present disclosure is not limited to the specific examples that may be used. The terminology used herein is for the purpose of describing the specific embodiments described herein. It should also be understood that this is not limiting.
[0065] The following description provides various embodiments that may share one or more common properties and / or characteristics. One or more features of any one embodiment may be used in conjunction with other embodiments or other embodiments. It should be understood that one or more features of the embodiments can be combined. In addition, any single feature or combination of features in any of these embodiments These may constitute further examples.
[0066] 5.1 Treatment In one form, the present technology includes a method of treating a respiratory disorder. It involves applying a positive pressure airflow to the entrance of the airway.
[0067] 5.2 Respiratory Treatment Systems In one form, the present technology includes a respiratory therapy system for the treatment of respiratory disorders. The therapy system directs air flow at positive pressure through air circuit 4000 to the patient interface 3000. 170 to the patient 1000.
[0068] 5.3 Patient Interface A non-invasive patient interface 3000 in accordance with one aspect of the present technology includes the following functional aspects: Including: seal-forming structure 3100, plenum chamber 3200, positioning and stabilizing structure 3 300, vent 3400, and one type of connection port 360 for connection to the air circuit 4170. 0, and forehead support 3700. In some embodiments, the functional modality may be one or more physical In some forms, it may be provided by a single physical component. In use, the seal-forming structure 310 0 surrounds the entrance to the patient's airway to promote positive air pressure delivery to the airway. To be placed.
[0069] 5.4 RT Devices The RT device 4000 according to one aspect of the present technology may be mechanical, pneumatic, and / or electrical. components, and one or more algorithms (e.g., as described in whole or in part herein) The RT device 4000 may be configured to perform, for example, For example, a device for injecting a substance into the airways of a patient for the treatment of one or more of the respiratory disorders described herein. It may be configured to provide a flow of air at positive pressure to the mouth.
[0070] The RT device may have an outer housing 4010. The outer housing 4010 may include an upper The outer housing is formed by two parts, a first part 4012 and a second part 4014. The group 4010 may include one or more panel(s) 4015. 4000 is a chassis that supports one or more internal components of the RT device 4000. 4016. The RT device 4000 may include a handle 4018.
[0071] The air pressure path of the pneumatic RT device 4000 may include one or more air circuit items (e.g., Inlet air filter 4112, inlet muffler 4122, and a device capable of supplying air at positive pressure. a pressure generator 4140 (e.g., blower 4142), an outlet muffler 4124, and one 4270 (e.g., pressure sensor 4272 and flow sensor 4274) obtain.
[0072] One or more of the air path items is a removable pneumatic block 4020. The pneumatic block 4020 may be disposed within an outer housing 4010. In one form, the pneumatic block 4020 may be located within the chassis 4016. Thus, it is supported by or forms part of the chassis 4016 .
[0073] The RT device 4000 includes a power supply 4210, one or more input devices 4220, a central computer a controller 4230, a therapy device controller 4240, a pressure generator 4140, and one or more protection circuit 4250, memory 4260, converter 4270, data communication interface 4 280, and one or more output devices 4290. The 4200 is mounted on a single printed circuit board assembly (PCBA) 4202. In one alternative, the RT device 4000 may include more than one PCBA. 4202.
[0074] 5.4.1 RT Devices Mechanical and Pneumatic Components An RT device may include one or more of the following components in an integral unit: In one alternative, one or more of the following components may be included in each separate unit: It can be arranged as a
[0075] 5.4.1.1 Air filter(s) An RT device in accordance with one form of the present technology may include an air filter 4110 or multiple air filters. It may include a data 4110.
[0076] In one form, the inlet air filter 4112 is located in the air pressure path upstream of the pressure generator 4140. is placed at the beginning of the
[0077] In one form, the outlet air filter 4114 (e.g., antibacterial factor) is It is positioned between the outlet of the valve 4020 and the patient interface 3000.
[0078] 5.4.1.2 Muffler(s) In accordance with one form of the present technology, an RT device may include a muffler 4120 or multiple mufflers 412 May contain 0.
[0079] In one form of the present technology, an inlet muffler 4122 is provided in the air pressure path to act as a pressure generator. It is located above 4140.
[0080] In one form of the present technology, an outlet muffler 4124 is provided in the air pressure path to 4140 and the patient interface 3000.
[0081] 5.4.1.3 Pressure generator In one form of the present technology, a pressure generator 4 is provided to generate a flow or supply of air at positive pressure. 140 is a controllable blower 4142. For example, the blower 4142 may be a The drive unit may include a brushless DC motor 4144 with one or more impellers housed in a The fan delivers an air supply of approximately 4 cmH2O to 120 liters per minute, for example. Positive pressure in the range of approximately 20 cmH2O, or in other forms up to approximately 30 cmH2O, may be used. The blower is described in one of the following patents or patent applications: U.S. Patent No. 7,866,944, the entire contents of which are incorporated herein by reference. No. 8,638,014, U.S. Pat. No. 8,636,479 and PCT Patent No. Patent application published as WO2013 / 020167.
[0082] The pressure generator 4140 is under the control of the therapy device controller 4240 .
[0083] In other embodiments, the pressure generator 4140 may be a piston-driven pump, a high pressure source (e.g., a pressure The pressure regulator may be a pressure regulator connected to a compressed air reservoir, or a bellows.
[0084] 5.4.1.4 Transducer(s) The converter may be internal to the RT device or external to the RT device. The external transducer may be located, for example, on the air circuit or part of the air circuit. The external transducer may form part of the non-contact sensor (e.g., a patient interface). This may take the form of a Doppler radar signal that transmits or moves a data RT device. movement sensor).
[0085] In one form of the present technology, one or more transducers 4270 are provided upstream and downstream of the pressure generator 4140. One or more transducers 4270 may be located adjacent to and / or downstream of the airflow. Generate a signal (e.g., flow rate, pressure, or temperature at that point in the pneumatic path) It can be constructed and arranged as follows:
[0086] In one form of the present technology, one or more transducers 4270 are connected to the patient interface 300. It can be placed near 0.
[0087] In one form, the signal from the converter 4270 is filtered (e.g., low-pass, high-pass, or It can be filtered (by bandpass filtering).
[0088] 5.4.1.4.1 Flow Sensor The flow sensor 4274 according to the present technology is a differential pressure transducer (e.g., from SENSIRION). SDP600 series differential pressure transducers).
[0089] In one embodiment, a signal indicative of flow rate from the flow sensor 4274 is transmitted to the central controller 42 Received by 30.
[0090] 5.4.1.4.2 Pressure Sensor A pressure sensor 4272 according to the present technology may be placed in fluid communication with the pneumatic path. An example of a pressure sensor is a transducer from the HONEYWELL ASDX series. Another suitable pressure sensor is the NPA series from GENERAL ELECTRIC. There are converters from the market.
[0091] In one form, the signal from the pressure sensor 4272 is transmitted to the central controller 4230. can be received.
[0092] 5.4.1.4.3 Motor Speed Converter In one form of the present technology, the rotational speed of the motor 4144 and / or the blower 4142 is To determine this, a motor speed converter 4276 can be used. The motor speed signal from the motor speed control unit 4240 may be provided to the therapy device controller 4240. The converter 4276 may be, for example, a speed sensor (eg, a Hall effect sensor).
[0093] 5.4.1.5 Anti-spillback valves In one form of the present technology, an anti-spillback valve 4160 is provided between the humidifier 5000 and the air The anti-spill valve may be disposed between the pressure block 4020 and the humidifier 500. 0 to reduce the risk of flow upstream (e.g., to the blower motor 4144). Constructed and placed.
[0094] 5.4.2 RT Device Electrical Components 5.4.2.1 Power supply The power supply 4210 may be located inside or outside the external housing 4010 of the RT device 4000. It can be arranged.
[0095] In one form of the present technology, the power supply 4210 provides power only to the RT device 4000. In another form of the present technology, power is supplied from a power source 4210 to the RT device 4000 and Humidifier 5000 is provided for both.
[0096] 5.4.2.2 Input Devices In one form of the present technology, the RT device 4000 allows the patient to interact with the device. In one such embodiment, the input device 4220 The switch 4220 includes one or more buttons, switches, or dials.
[0097] 5.4.2.3 Central Control Unit In one form of the present technology, the central controller 4230 controls the RT device 4000. One or more processors suitable for
[0098] A suitable processor is the ARM® Cortex-M3 processor from ARM Holdings. x86 INTEL processor, which is a processor based on the x®-M processor (e.g., S32 series microcontrollers from ST Macro Electronics) In certain alternatives of the present technology, a 32-bit RISC CPU (e.g. , STR9 series microcontroller from ST MICRO Electronics) or 16-bit Tri-RISC CPUs (e.g., manufactured by Texas Instruments) Processors from the MSP430 family of microcontrollers may also be suitable.
[0099] In one form of the present technology, the central controller 4230 is a dedicated electronic circuit.
[0100] In one form, the central controller 4230 is an application specific integrated circuit. In some embodiments, the central controller 4230 includes discrete electronic components.
[0101] The central controller 4230 may include one or more transducers 4270, one or more input devices 4280, 220 and the humidifier 5000.
[0102] The central controller 4230 transmits the output signals to the output device 4290, the therapy device controller 4292, and the Controller 4240, Data Communication Interface 4280 and Humidifier 5000 It may be configured to provide to one or more
[0103] In some forms of the present technology, the central controller 4230 may include one of the A program configured to embody the above method (e.g., a non-transitory computer-readable program) is provided. A computer program or one or more algorithms expressed as "firmware"). For example, The rhythm can detect patient respiratory events during respiratory therapy.
[0104] 5.4.2.4 Clock The RT device 4000 includes a clock 4232 connected to a central controller 4230. obtain.
[0105] 5.4.2.5 Therapy Device Controller In one form of the present technology, the therapy device controller 4240 is a therapy control module. and forms part of the algorithm executed by the central controller 4230.
[0106] In one form of the present technology, the therapy device controller 4240 includes a dedicated motor control integrated circuit For example, in one form, the MC33035 brand manufactured by ONSEMI A Siles DC motor controller is used.
[0107] 5.4.2.6 Protection circuit The one or more protection circuits 4250 according to the present technology may include electrical protection circuits, temperature and / or pressure protection circuits. A safety circuit may be included.
[0108] 5.4.2.7 Memory According to one aspect of the present technology, the RT device 4000 includes a memory 4260 (e.g., a non-volatile In some embodiments, the memory 4260 includes a battery-powered static R In some forms, the memory 4260 may include volatile RAM. .
[0109] The memory 4260 may be located on the PCBA 4202. The memory 4260 may include an EEPROM. It can take the form of OM or NAND flash.
[0110] Additionally or alternatively, the RT device 4000 may include removable memory 4260 ( For example, memory cards made according to the Secure Digital (SD) standard.
[0111] In one form of the present technology, the memory 4260 may be a non-transitory computer readable storage medium. The recording medium functions as a medium on which one or more of the methods described herein are represented. Computer program instructions (eg, one or more of the algorithms described above) are recorded.
[0112] 5.4.2.8 Communications In one form of the present technology, a data communication interface 4280 is provided, The data communication interface 4280 is connected to a remote external communication Connectable to network 4282 and / or local external communications network 4284 The remote external communication network 4282 can be connected to a remote external device 4286. The local external communication network 4284 may be capable of communicating with the local external device 428 8. The local external communication network 4284 may be wired. It may be wireless.
[0113] In one embodiment, the data communication interface 4280 is connected to the central controller 4230 In another embodiment, the data communication interface 4280 is part of a central control It may be separate from the roller 4230 and may include an integrated circuit or processor.
[0114] 5.4.2.9 Output Device The output device 4290 according to the present technology may be one or more of a visual, audio, and tactile unit. In one form, the output device 4290 includes an LED or obtain.
[0115] The output device 4290 and the input device 4220 are used by the user of the RT device 4000. These may be collectively referred to as interfaces.
[0116] 5.5 Air Circuit In use, the air circuit 4170 in accordance with one aspect of the present technology has two components: components (e.g., the RT device 4000 and the patient interface 3000) The conduit or tube is constructed and arranged to
[0117] 5.6 Humidifier In one form of the present technology, the absolute humidity of the air or gas to be delivered to the patient is adjusted to the ambient humidity. A humidifier 5000 is provided for varying the relative humidity (e.g., as shown in FIG. 5A). Typically, the humidifier 5000 humidifies the airflow (ambient air) before delivery to the patient's airway. It is used to increase the absolute humidity (relative to air) and to increase the temperature.
[0118] The humidifier 5000 includes a humidifier reservoir 5110 and a humidifier inlet 500 for receiving an air flow. 2 and a humidifier outlet 5004 for delivering the humidified air flow. and in some configurations, such as that shown in FIG. 5B, the inlet and The humidifier inlet 5002 and the humidifier outlet 5004 may be respectively. The humidifier may further include a humidifier base 5006. The humidifier base 5006 may include a humidifier ring. It may be adapted to receive the reservoir 5110 and may include a heating element 5240 .
[0119] 5.7 Secure Networked Respiratory Care FIG. 6 illustrates a network diagram with several external entities in accordance with one aspect of the present technology. 6 is a schematic diagram of a networked respiratory treatment system 6000. The system includes an RT device The RT device 4000 includes a positive pressure airflow as shown in FIG. The patient 1000 is supplied with air via an air circuit 4170 to the patient interface 3000. It is configured as follows.
[0120] The RT device 4000 communicates with the control device 6010 via a wireless connection 6015. The control device 6010 is associated with the patient 1000. The control device 6010 4C, and the wireless connection 6015 may correspond to the local external device 4288 of FIG. The control device 6010 may correspond to the communication network 4284. 0 (e.g., a special-purpose software application or A dedicated "remote control" or general-purpose computing device consisting of an "app" running on it Such software applications may be servered by the control device 6010. (e.g., a web server) to a network (e.g., an intranet or the Internet) The control device 6010 may be portable. In some embodiments, the wireless connection 6015 may be implemented using one or more wireless communication protocols, e.g. , Bluetooth or Bluetooth LE, NFC, or Consumer Infrared Pro Therefore, in the wireless connection 6015, Short-range or low-energy networking (which can be a direct link between obtain.
[0121] FIG. 6 illustrates a second control device communicating with the RT device 4000 via a wireless connection 6025. A second control device 6020 is also shown. However, the second control device 6020 is not part of the respiratory treatment system 6000. If wireless connection 6025 uses the same protocol as wireless connection 6015, In this case, a criminal 6030 who possesses a second control device 6020 may The security of the wireless connection 6015 between the RT device 4000 and the second control device For this reason, the second control device 6 020 may be referred to as an unauthorized control device 6020. Arrangements for securing wireless connections 6015 against various threats presented by The construction is described in more detail below.
[0122] The networked respiratory treatment system 6000 is connected to the control device via a wireless connection 6050. The remote server 6040 communicates with the control device 6010. one or more devices (e.g., control device 6010) via wireless connection 6050 accessible through a network (e.g., the Internet or Thus, the wireless connection 6050 may provide indirect networking to a remote server. Examples of such wireless networking include WIF I network, Bluetooth network, wireless cellular network (e.g. , Global System for Mobile Communication( GSM (registered trademark) network). Long-range wireless communication may be used compared to a wired connection 6015. The control device 6010 may be configured to act as an intermediary between the T device 4000 and the remote server 6040 The networked respiratory treatment system 6000 may communicate with other RT devices (as shown). Each of these other RT devices (not shown) may include a corresponding control device. The device (not shown) is controlled by a rotating sensor that includes a corresponding wireless connection (not shown). The server 6040 communicates with multiple RT devices 4000. The devices are configured to function as one and there is no confusion between them.
[0123] The RT device 4000 may collect data related to respiratory therapy (e.g., usage time, respiratory events, etc.). the number of devices, or compliance rule evaluation results) via the connection 6015 to the control device 60 10. Such treatment data can then be transmitted to the control device 6 6010 to the server 6040 via connection 6050. The 6010 is a device that connects and manages control parameters (e.g., compliance rules) for respiratory therapy. The RT device 4000 may be configured to transmit the RT signal to the RT device 4000 via the connection 6015. The control parameters are transmitted by the control device 6010 from the server 6040 through the connection 6050. The control device 6010 can download the upgraded RT device 40. 00 firmware via connection 6015. Such an upgrade is performed by the control device 6010 from the server 6040 to the connection 6050 It can be downloaded via.
[0124] FIG. 6 illustrates a computing device 6060 communicating with a server 6040 via a wireless connection 6070. However, the computing device 6060 is not a networked respiratory treatment system. In addition, the computing device 6060 does not form part of the system 6000. Since it is not connected to the network, it is called an unassociated (control) device. uses the same protocol as the wireless connection 6050 and (server 6040 is legitimate) Unassociated devices 6060 (to appear as a valid control device 6010) The "spoofed" version of the app running on the control device 6010 If the user is running a 6060, the criminal who owns the unassociated device The networked respiratory treatment system 6000 (particularly the server 6040) ) operation via an unassociated device 6060. Server against the diverse threats presented by unassociated devices 6060 Arrangements for securing the 6040 are described in more detail below.
[0125] The third category of threats to the Networked Respiratory Treatment System 6000 is R The control device 6010 in communication with the T-device 4000 is under the control of a criminal (not shown). This occurs when a criminal is running a "spyware" on a device they control and have privileges to access. Install a "spoofed" version of the app on the control device 6010. This spoofed version is being distributed to servers 6040 for illegal purposes. and / or act as if they were the authorized controlling device for the RT Device 4000. Therefore, such a control device 6010 is called a "spoof In other words, the server 6040 communicates with itself. be confident that any control device 6010 it is using is not being "spoofed" and therefore any control in the networked respiratory treatment system 6000. The control device 6010 should be treated as untrusted. The server 60 is configured to respond to various threats presented by the control device 6010. Arrangements for securing 40 are described in more detail below.
[0126] 5.7.1 RT Devices and Control Devices As described above, wireless communication 60 between the RT device 4000 and the control device 6010 15 security breaches prevented by unauthorized control devices 6020 It is desirable to securely connect the control device 6010 and the RT device 4000. It is further desirable to minimize the complexity of establishing such communication links. A secure communication line is established between the RT device and the device using a user interface. The input device 422 of the RT device 4000 must be able to establish a The RT device 4000 may consist of one button, and the output device 4290 of the RT device 4000 may consist of one However, this method of establishing a communication link may be implemented using a more sophisticated user interface. It should also be available on RT devices with a .NET 3.0 or .NET 4.0 interface.
[0127] A communication line between two devices is known to both devices and can be accessed by other devices. using a symmetric key unknown to both devices to encrypt and decrypt communications between them The security of the communication line can be achieved by the " Strength is directly related to the "strength" of a key. Strength is determined by the number of possible key values and the entropy or Generally, the probability of any value occurring is the same as the probability of all possible values. For a given key, the greater the number of possible values, the greater the entropy and strength of that key. One difficulty in establishing such a secure communication link is the When creating a symmetric key known to the device, unencrypted communication is This can be accessed from unauthorized control devices (e.g., 6020) that can sometimes eavesdrop. The symmetric key may be kept secret.
[0128] FIG. 7 is a flow chart illustrating a method 7000. The method 7000 is one aspect of the present technology. According to the configuration, the control device 6010 and the RT device 4000 communicate securely between each other. The control device 6010 can be used by both parties to establish a communication link. and / or the controller or processor of the RT device 4000, e.g., and performing (e.g., being programmed to perform) a method as described herein in connection with FIG. It can be configured as follows.
[0129] The method 7000 begins at step 7010. In step 7010, the control device The device 6010 and the RT device 4000 establish a communication link between them. The top is the result of some input activation on the user interface of the RT device 4000. For example, button 422 forms part of the user interface of the RT device 4000. The RT device 4000 may be initiated by the patient, clinician, or authorized This information is provided to any one or more of the designated technicians (e.g., technicians at the medical device provider). The LED 42 may be configured to limit or allow the availability of such activation inputs. 90 also forms part of the user interface of the RT device 4000. Turn on or off forced illumination to indicate the 4000 is ready to connect to a control device. Such an initiation action may result in the currently connected RT device 4000 Any control devices that are currently connected to the RT device 4000 are disconnected. Control-related communication lines are terminated by the RT device 4000.
[0130] The wireless protocol used is a standard communication protocol (e.g., Bluetooth) In an implementation of the method 7000, in response to a user-initiated action, the RT device The device 4000 enters "discoverable" mode, i.e., the protocol (e.g., Blue A device that supports the tooth function is connected to the RT device as part of step 7010. In one such implementation, the devices may be paired (e.g., For example, the Lisbon specification of the Bluetooth Core Specification[1] Just Works association model for Simple Pairing feature in release The system is designed to establish a symmetric key-encrypted communication channel between the two parties (using Each device can then encrypt and decrypt communications using the shared symmetric key. When using simple pairing, legacy Bluetooth 2.0+E Equal to the strength of protection against passive eavesdropping attacks on DR (and earlier) pairings The latter requires a 16-character case-sensitive alphanumeric PIN. (approximately 95 bits of entropy). In that case, it becomes much easier to use. The advantage of Simple Pairing is that it just works. Under the control model, the user can enter the following information on the user interface 6010 of the control device: Accept the pairing by selecting "Yes" for the "Yes / No" control in Just Works is a single button 4220 and LED 4 It is especially suited to RT devices with the simplest user interface available. Because for such devices, the Simple Pairing Number ric Comparison A non-fixed alphanumeric code as required for association models This is because it may become impossible to display the other execution modes of step 7010 (e.g., the wireless In the case where the protocol is Bluetooth, step 7010 The communication line established through this is unencrypted (i.e., a "clear" communication line). ).
[0131] As a result of step 7010, both devices are connected to a communication line for two-way communication between them. LED 4290 indicates completion of step 7010 by continuously illuminating. If the communication line is unencrypted, it is difficult to secure it due to the risk of passive eavesdropping. is not considered to be
[0132] Active unauthorized control devices (e.g., 6020) are in discoverable mode When the RT device 4000 is discovered, it can be used via the Just Works association model. to pair with the RT Device 4000, which then provides service to the Control Device 6010. The service may be refused.
[0133] To reduce this possibility, in some implementations, starting with step 7010 The effect of a user action on a page may be time-limited (e.g., within a "discoverability window"). In this implementation, the RT device 4000 is discoverable by the discoverable It can only be within a window (e.g., 62 seconds long). When removed from the window, the RT Device 4000 will communicate with all devices using the standard protocol. This will prevent the device from being discovered by other devices (e.g. Bluetooth devices). This can be indicated by the extinction of the LED 4290. For example, the RT device 4000 may attempt to deny service to the RT device 4000. The period during which the control device 6010 attempts to pair with the RT device 4000 is The active attempt is limited to a short interval.
[0134] If an unauthorized control device 6020 succeeds in pairing with an RT device 4000, If you do, you will not be able to complete that unique pairing by a certain predetermined deadline, and this situation The control device 6010 can detect this failure. The user may be notified of the initiation of an action (e.g., button 4220 on the RT device 4000). This initiation action may result in the user being prompted to repeat the above-described steps. All control devices paired with the RT Device 4000 will be disconnected. In the row mode, the discoverability window is longer than the first pairing attempt for the second and subsequent The pairing attempt may continue for a longer period of time.
[0135] A more serious threat than denial of service is the risk of unauthorized control devices during the discoverability window. The device 6020 (without being detected by either the device 6010 or the device 4000) There are situations where MITM (Minor Interference with Memory) attacks can occur. During Bluetooth pairing, each device acts like any other device. Then, the unauthorized control device 6020 attempts to relays information between the devices, making it appear as if the two devices are directly paired. This illusion is given to each device, and the symmetric key is calculated. An unauthorized control device 6020 can eavesdrop on the communication line between these two devices. It may be possible to insert and change information into the communication line (this is called "activity"). Therefore, the RT device 4000 and the control device 6010 When exchanging or sharing a symmetric key between The communication line is (Just Works Simple Pairing and / or even with the "discoverable window" option) at least active theft It is considered insecure for listening.
[0136] Referring to method 7000, the control device 6010 communicates with the RT device 4000 in a secure manner. After the establishment of a communication line that is not 0 prevents itself from being discovered by other devices communicating over standard protocols. Next, in order to reduce the risk of passive and active eavesdropping, step 70 Steps 7020 and 7030 may be performed. A shared secret (e.g., a token) is established and this first shared secret is used in insecure communication. A second shared secret (e.g., a second secret stronger than the first) is communicated over the wire. The first shared secret is then converted into a more complex token. 6020), so that the symmetric key established in step 7010 It cannot be derived from step 7010. The purpose of step 7020 is to connect the insecure communication line established in step 7010 to the The first shared secret is established using a different communication line.
[0137] Common significant differences between the control device 6010 and the unauthorized control device 6020 The former has physical access to the RT device 4000, while the latter does not. In step 7020, this difference is used to A first shared secret is established between the T device 4000 and the T device 4000. Such a first secret may be, for example, For example, the first secret may be predetermined by the manufacturer, thereby allowing the RT device 4000 to store the first secret. Therefore, the controller in the RT device 4000 can The controller may pre-program (e.g., along with the first secret) the first secret to distribute based on the first secret. Such a first secret may be programmed for / by the control device 6010. Once obtained by the control device 6010, the first secret becomes shared. The secure connection established in step 7010 between the RT device 4000 and the via a communication line or medium different from the communication line not in use (for example, communication line 6013 in FIG. 6) For example, in step 7020, The control device 6010 generates a token or a master key known to the RT device 4000. The token or master key is obtained through a different communication line 6013. The master key can be considered to be generated from a single manufacturer for each RT device 4000. The different communication lines 6013 are called "out-of-band" mechanisms. Some implementations of step 7020 may involve the control device 6010 sending the RT Physical access to the device 4000 may be utilized. Other such "different lines of communication" In step 7020, the transfer is made by (e.g., telephone, mail, user / instruction manual, Access to manufacturer website access and other distribution information specific to your particular RT Device 4000 Alternatively, the material may be obtained from a third party (e.g., via a third party supplier).
[0138] Next, in step 7030, the control device 6010 and the RT device 4000 is a method of exchanging information over an insecure communication line (e.g., a key) with a token or a master key. The second shared secret is then established using the second shared secret (exchange). The device (1) receives a first shared secret and and (2) a second claim from exchanged information that was not communicated over an insecure communication line. This second shared secret may be a more complex token than the preceding token. It may be a larger number (e.g., a larger number of bits, digits, and / or characters) and may be an "authentication key" A second shared secret is then used to create a pair known as a "session key." A shared secret or a session key can be derived and generated. There is no need to exchange data over an insecure communication line. The control device 6010 and the RT device 4000 that possess the application key use the Step 701 uses a session key for encryption and decryption. Establish a more secure communication link than the insecure one established in 0 Without knowledge of the master key, an unauthorized MITM-controlled device can obtain the second shared secret or The session key cannot be computed or derived during step 7030. Even if you knew all the data exchanged within the communication line, you could not It is not possible to eavesdrop on a communication line established at 030. Without knowing the session key, the M control device can decrypt information encrypted using the session key. They cannot decrypt the information or insert intelligible information into the communication lines. Therefore, the communication line established in step 7030 is may be considered more secure than the insecure communication lines established through
[0139] In one "physical access" implementation of step 7020, the master key is A token printed on a physical part of the device 4000 (e.g., housing 4010) or its user manual / instruction manual which may be distributed with the RT device 4000. A master key may be in human readable, machine readable form or In one implementation of machine-readable form, the token is printed in a format that is easy for humans to understand. For example, one such implementation Alternatively, the token may be encoded as a barcode 6017 (e.g., a QR code). or printed on the housing 4010 or other coded graphic symbol / indication. In such an implementation, the control device 6010 may receive a barcode reader (e.g., camera and associated barcode decoding image processing functions) and In step 7020, the control device 6010 reads the barcode using a barcode reader. In one implementation, the key is scanned and a master key is obtained. Therefore, the master key is printed in alphanumeric format on the housing 4010. In such an implementation, the control device 6010 may The user manually enters the key into the interface to obtain the key. In this state, the human-readable form of the key is a 5-decimal numeric code (1 00000 possibilities). Such a passkey would only have about 16 bits of entropy. In another implementation, the human-readable form of the key is A decimal number is a four-digit numeric code (e.g., "7409") and is considered weak as well. It is possible.
[0140] As mentioned above, the master key is available to the housing in both machine-readable and human-readable form. In this implementation, in step 7020 First, the control device 6010 transmits a machine-readable form of the master key to the control device 6010. If this fails, the control device 6010 will The master key in a form that can be deciphered by the user is obtained through the user interface of the control device 6010. Prompt the user for input.
[0141] In another "physical access" implementation of step 7020, the control device 6010 connects to RT devices via a short-range wireless protocol (e.g., Near Field Communication (NFC)) 4000. Another "physical access" implementation of step 7020. In this example, the control device 6010 reads the RFID tag embedded in the RT device 4000. The token is obtained from the RT device 4000 by scanning the RFID tag. encodes the token.
[0142] In step 7030, both devices use a security gateway to compute a shared (symmetric) authentication key. They communicate over an unsecured communication line to execute a key exchange protocol together. The duplicate key (first shared secret) obtained in step 7020 is used in step 7030. In some implementations of step 7030, A Diffie-Hellman based key exchange protocol may be used (e.g., secure Remote Password Protocol (SRP). In one implementation of step 7030 A Diffie-Hellman-based protocol known as SRP6a [2] SRP6a has the following properties: - Security against eavesdropping. The master key is secure even when the communication line is clear and the communication line is encrypted. It is not transmitted over an insecure communication line, even if it is a wire. Immunity to replay attacks. Captured information cannot be reused to gain access. This can be avoided. Resistance to offline dictionary attacks. Even if traffic is captured, offline computation attacks are not possible. No information is available for. Forward security. If a master key is known, the The encrypted traffic is safe from decryption. No back-end connection is required to pass the certificate and authentication.
[0143] As mentioned above, SRP6a secures the encryption through Diffie-Hellman-based iterations. Under SRP6a, one device (RT device in this technology) One (device 4000) is designated as the server and the other (control device 6010) is the client. The server (the authenticator) exchanges the shared secret with the verifier. The verifier then generates a public key that is combined with Diffie-Hellman exponentiation. As a result, security when used with a low-entropy passkey (e.g., a 5-digit passkey) The client (peer) also generates a Diffie-Hellman public key. The public keys are exchanged over insecure communication channels, and from this information the client Both the client and the server compute a shared secret (the authentication key) that is stronger than the passkey. Optionally, these two devices may authenticate themselves by verifying that their calculated authentication keys are identical. This allows for a complete message verification sequence to be performed to prove that the hash This is achieved through sequencing, the results of which are exchanged and compared between devices. If any comparison fails, step 7030 is aborted because The failure occurs when a MITM-controlled device attempts to participate in a key exchange using an incorrectly guessed master key. For added security, step 7030 In a preferred implementation, if step 7030 is repeated with the same duplicate key: The probability that the authentication keys are the same is statistically low.
[0144] Both devices store the authentication key in secure persistent storage (e.g., the RT device hash). As described above, step 7030 In the final substep, each device performs encryption / decryption in the current session. The session key is calculated from the hash of the authentication key for encryption. The "nonce" may be based on a single-use random number called a "nonce." In one implementation, the "nonce" is a random number. It is generated by the server and used by both devices in the session key calculation. It is sent to the client via an insecure communication line and then discarded. This substep is repeated for each subsequent re-pairing of the devices with a different nonce. By repeating this process, a different session key is calculated for each communication session, thereby This establishes the "forward security" mentioned above.
[0145] The master key itself does not need to be stored in the memory 4260 of the RT device 4000. Instead of The only thing required on the server side to perform step 7030 according to SRP6a is The secret key hash is not accessible from the RT device 4000. It is possible to make it local to the location in memory 4260 (where the hash is stored). Access to local or remote external computing devices can be provided via interface 4280. After step 7030 is completed, the duplicate key cannot be used in subsequent re-pairing operations. There is no need to store the master key in the control device 6010 since it will not be used.
[0146] FIG. 8 includes two flowcharts illustrating methods 8000 and 8050. 0 and 8050 are the server (RT Device 4000) and client (Control Device 6010) respectively, in a method 7000 according to one aspect of the present technology. Each of these can be executed to perform its respective role.
[0147] Method 8000 begins at step 8010, and method 8050 begins at step 8055. Here, the server and client each establish an unsecured communication channel. Take the necessary actions to establish a mutual Just Works Simple Pairing (Steps 7-10). In these steps, these two steps are performed as shown by the double dotted arrow 8001. This requires insecure two-way communication between the devices. This communication is indicated by the dashed arrow between method 8000 and method 8050 (step 80 60), conducted over unsecured communication lines.
[0148] Next, step 8060 of the method 8050 follows, where the client, e.g., With physical access to the bar, a master key can be obtained, as described above in connection with step 7020. (P) or obtain the first shared secret from the server. In the next step, step 7030 of method 7000 is performed. In step 8015, the server derives the server public key (B) using the salt (s). The salt(s) is a random number generated by the server. The cryptographic key exchange is based on a multiplicative group (known as the prime group) modulo a large prime number (N). To calculate the server public key (B), the server uses a small integer (e.g., 2) A group generator (g) and a prime number group (N) are used. First, the server generates a hash of the secret key (P). Calculate the exponent (x) as the hash of the salt (s) concatenated with the exponent:
number
number
[0149] The server then calculates the multiplication by hashing the prime group (N) and the group generator (g). Calculate the operator(k):
number
[0150] The server then computes the server public key (B) as follows:
number
[0151] The client receives the server public key (B) and The client receives the group generator (g) and the prime group (N). Therefore, in step 8070, the group generator (g) is set to the client random exponent. Calculate the client public key (A) by raising it modulo the prime number group (N) of (a) You can:
number
[0152] Also, in step 8070, the client transmits the client public key (A) to the server. This server receives the request in step 8020 of the method 8000. The client public key (A) is independent of the server public key (B) or salt(s). Note that steps 8065 and 8070 can be performed in any order. If step 8070 precedes step 8065, step 8020 May precede step 8015.
[0153] The client does not need a secret key (P) to calculate the client public key (A). It should also be noted that step 8060 may be followed by steps 8065 and 8070, so However, in some cases, step 8060 may precede step 8055. possible.
[0154] In step 8025, the server generates a hash of the client and server public keys. Calculate u (A and B):
number
number
[0155] In step 8075 of method 8050, the client uses the formula Calculate (u), multiplier (k) and exponent (x) (to calculate exponent (x), (Note that this requires the master key (P) obtained in the 8060.) The client computes the authentication key (S) as follows:
number
[0156] Using modulo N arithmetic, the client and server perform steps 8025 and It can be seen that the same authentication key (S) is calculated for each of the 8075. To protect the substrate from damage or destruction, subsequent steps of methods 8000 and 8050 The server and the client confirm that they share a common authentication key (S). In step 8080 of the method 8050, the client The client value (Mclient) is calculated as follows:
number
number
[0157] Server hash value and client hash value (Mserver and Mcree nt) are equal, method 8000 proceeds to step 8040, where the server , and calculate the second server hash value (HAMKserver) as follows:
number
[0158] Also in step 8040, the server generates a second server hash value (HAMKs server) and a nonce (randomly selected by the server) to the client. Meanwhile, in step 8085 of method 8050, the client The hash value (HAMKclient) is calculated as follows:
number
[0159] In step 8090, the client receives the second server hash value (HAMKs server) and nonce, and calculates the second server hash value and the client hash value. Compare the cache values (HAMKserver and HAMKclient). If not, the method 8050 aborts and the secure communication link establishment step 7030 fails. notify the user (e.g., via the user interface of the control device 6010 and / or or generating user output via the output device 4290 of the RT device 4000. ).
[0160] Second server hash value and client hash value (HAMKserver and Assuming that the HAMKclient and HAMKclient are equal, method 8050 proceeds to step 8095. The client then uses the hash of the authentication key (S) and the Calculate the session key (Ks) by hashing the nonce:
number
[0161] Meanwhile, in step 8045 of method 8000, the server generates a session key (Ks) is calculated in the same way.
[0162] With the above arrangement, an unauthorized control device 6020 can activate connection 6015. or passive eavesdropping is significantly reduced, so the control device 6010 and the RT device It may be possible to consider the connection between the device 4000 and the network device 4000 as secure.
[0163] However, the connection 6015 between the control device 6010 and the RT device 4000 The connection 6050 between the control device 6010 and the server 6040 is also secure. Even if it is nominally "secure" (for example, it adheres to the SSL connection protocol), The unassociated control device 6060 and the spoofed The control device 6010 controls the networked respiratory treatment system 6000. The threat remains.
[0164] 5.7.2 Control Devices and Servers Each RT device (e.g., 400 0) is a unique identifier known to the RT device itself and the server 6040. In addition, each RT device 4000 can be identified by other devices other than the server 6040. It knows a unique data block that is not known to all The unique identifier is then transmitted to the server 60 in a manner associated with the RT device 4000. 40. This data block is called the RT Device Secret. Even if the control device 6010 is a spoofed control device, this secret is unknown to the control device 6010 that mediates between the RT device and the server 6040. Therefore, this secret provides security between the RT device 4000 and the server 6040. This allows for a more flexible deployment configuration.
[0165] 5.7.2.1 Firmware Upgrade As mentioned above, you can upgrade the firmware on your RT Device 4000. In some cases, it may be necessary to It may be possible to tamper with the upgrade (without being detected by the Device 4000) In this case, the control device 6010 can change the operation of the RT device 4000. Therefore, the control device 6010 is ineffective in respiratory therapy. The source of the firmware upgrade is Server 6040, and the firmware upgrade The code is for the RT device 4000 and has not been tampered with by the control device 6010. It would be useful if the RT device 4000 could confirm that the
[0166] FIG. 9 is a schematic diagram of a method 9000. The method 9000 is a networked respiratory therapy system. The Medical System 6000 has approved a firmware upgrade for the RT Device 4000. The three entities involved in the method 9000 (RT device The device 4000, control device 6010 and server 6040 are shown as vertical lines. The diagram is shown from left to right, with communications and other actions between them in chronological order from top to bottom. This is illustrated as an arrow pointing downwards.
[0167] Method 9000 may begin at step 9005. In step 9005, the control The device 6010 checks the current firmware version number with the RT device 400. 0. In step 9010, the device 4000 Step 90: At 20, the control device 6010 sends a firmware upgrade to the server 6040. In step 9030, the firmware version number is sent. If this is required, the server 6040 will automatically update the firmware based on the firmware version number. Respond by sending a firmware upgrade file to the control device 6010 (If no upgrade is available, the server responds with the message "None" As a result, the control device 6010 ends the method 9000 after step 9030. ).
[0168] In some versions, the method may begin at step 9020. In a similar method 9000, steps 9005-9020 are omitted, and the method 9000 comprises: The process starts at step 9030. In step 9030, the server 6040 Firmware upgrades based on the device's own unique record of upgrade history. The upgrade file is sent to the control device 6010.
[0169] In a further type of method 9000, step 9005 includes: Requests the unique identifier of the RT device, not the software version number. In step 9010, the RT device 4000 sends a control device ID along with its unique identifier. In step 9020, the control device 6010 responds to the server 6 Step 903: Request a firmware upgrade from 040 and send a unique identifier. In 0, if one is needed, the server 6040 will create a farm based on the unique identifier. The firmware upgrade file is applied by sending it to the control device 6010. Due to the type of firmware upgrade available, the Server 6040 is A specific device (rather than all devices with a specific firmware version number) can be targeted.
[0170] In the next step 9035, the control device 6010 downloads the upgrade file In step 9040, the RT device 4000 sends the (In a further variant of the above, the control device 6010 may also send its own unique identifier to the control device 6010.) The unique identifier of the RT device 4000 is known to the control device 6010, Step 9040 is not necessary.) Next, in step 9045, the control device 601 0 requests an authorization code for the upgrade from the server 6040 and Next, in step 9050, the server 60 40 is a secret (i.e., The key is obtained from the RT device 4000 (i.e., a secret shared with the RT device 4000). In this case, the key is a subset of the data from the secret. The server 6040 then uses the key to In step 9030, the upgrade file sent to the control device 6010 In one implementation of step 9050, the authentication code is derived from the is a hashed message authentication code derived from the hash of the upgrade file In another implementation, the authentication code is a key encrypted access This is a hash of the upgrade file. It is not the upgrade file itself, but the hash. The upgrade file for the networked respiratory therapy system 60 The same operation can be performed multiple times on different RT devices in a This is advantageous for the server 6040 because it may be necessary to do this rather than automatically.
[0171] Next, in step 9055, the server 6040 transmits the authentication code to the control device 6 010. In step 9060, the control device 6010 sends the authentication code to RT In step 9065, the RT device 4000 sends the derives a key from its own secret in the same way as server 6040 in step 9050. Then, The RT device 4000 derives the same method as the server 6040 in step 9050. Using the key obtained in step 9065, the control The authentication code is calculated from the upgrade file received from the device 6010. In step 9065, the RT device 4000 calculates the authentication code. This mimics the operations performed by the server 6040 in step 9050. Next, the RT device 4000 receives the calculated authentication code and If these two codes match, the RT device The RT device 4000 authenticates the upgrade file. Safely apply the upgrade file to your own native firmware.
[0172] The authentication code is calculated as follows: (Calculate the authentication code from the upgrade file) Neither the secret nor the key is derived from the upgrade file and authentication code (even if it is known how to do so). Furthermore, there is a way to prevent a spoofed control device 6010 from being able to send out a spoofed control device 6010. If the upgrade file has been tampered with by The authentication code calculated by the RT device 4000 is transmitted to the server 6 in step 9055. 040 is different from the one received. Therefore, neither the key nor the secret is sent to the control device 6010. Without the key, the control device 6010 cannot compute the expected authentication code. Therefore, it is not possible to derive the key or secret from the control device 6010 and A spoofed control device 6010 can deliver fake or unauthorized upgrades to an RT device. It is also not possible to provide this to the 4000 firmware.
[0173] 5.7.2.2 Uploading Treatment Data As noted above, the RT devices ( For example, 4000) transmits the treatment data to the server 60 via its control device 6010. 40. Spoof under the control of criminal 6065 The associated control device 6010 or the unassociated control device 6060 , there is a possibility that an attempt may be made to upload false or fraudulent treatment data to server 6040. Isolated sources of false treatment data can arise from networks containing many RT devices. This is because there is only a minimal harm to the overall system of treatment. can be considered an acceptable risk. However, a spoofed control device6 010 or unassociated control device 6060 may be connected to other R These RT devices masquerade as control devices for T devices and send false treatment data to these RT devices. Uploading content that falsely claims to be from a different country is not acceptable because Such false treatment data may cause unauthorized access to the authorized control device 6010 and the server 6 This is because the genuine medical data uploaded to 040 may be overwhelmed. Therefore, at the time of uploading, the control device 6010 is the upload source of the treatment data. It is desirable to communicate with the RT device 4000 that claims to be such a device. By setting the conditions, you can connect to the RT Device 4000 at least once in the past. The unassociated control device 6060 that succeeded in associating the control device 6060 with the authority may later The device was connected to the 6010 and used for spoofing and uploading large amounts of fake medical data. This avoids such a situation.
[0174] 10 is a schematic diagram of method 10000. Method 10000 is implemented using the networked system of FIG. The respiratory treatment system 6000 may transmit treatment data to a server in accordance with one form of the present technology. It can be used to authenticate uploads.
[0175] Method 10000 begins at step 10005. In step 10005: The RT device 4000 sends the treatment data to the control device 6010. This step includes: This may be performed at other times relative to method 10000, but prior to the transfer of the treatment data to the server. In step 10010, the control device 6010 receives the "nonce" and The server 6040 requests the address and offset of the RT device 4000. A nonce is a (pseudo)random number with limited duration, time and / or number of uses. In this regard, a nonce may be used for a predetermined period of time and / or for a predetermined use. When the nonce expires, it is sent to server 6040. For example, the duration of a nonce can be exactly one use. In step 10015, the server 6040 sends the control device 6010 a nonce and The server 6040 provides the number of uses or step 1001 together with the offset. 5, the time elapsed since the nonce was first sent, the identifier of the RT device 4000, and To keep track of the nonce, the server 6040 can later determine if the nonce has expired. The offset is a pointer to the ID received in step 10010. A secret associated with the child (i.e., a secret known to the RT device 4000) is extracted as a key. For example, the pointer can be an identifier and can be used to derive data from a secret. Select a subset of the data to use as a key or generate a key from a subset of the data It is used to experience hashing.
[0176] Next, in step 10020, the control device 6010 , and the offset and the In step 10025, the RT device 4000 sends the offset, The nonce and its secret are used to derive a signing key. The RT device 4000 sends the signing key to the control device 6010. In this case, the control device 6010 uses the signing key to enter an authentication code for the treatment data. In one implementation, the authentication code is an HMAC. For example, the authentication code is , a hash computed with the treatment data and the signing key using a cryptographic hash function. In step 10040, the control device 6010 receives the treatment data, the authentication code, and the The ID of the RT device 4000 is sent to the server 6040. Finally, step 1 In step 10045, the server 6040 receives the received message sent in step 10015. Step 1: Check whether the nonce associated with the given identifier has expired. The received identifier and associated nonce sent in 0015 have expired. If so, the authentication fails. If the associated nonce has not expired, the server 6040 , the nonce sent in step 10015 and the secret associated with the identifier (i.e., The server derives a signing key using the secret (i.e., a secret known to the RT device 4000). 6040 uses the signing key to compute an authentication code for the treatment data. The method of calculating the authentication code is as follows: 4000 and the method used by the control device 6010. There is a match between the authentication code and the authentication code received in step 10040 In this case, the treatment data is authenticated.
[0177] Although not shown in FIG. 10, based on such authentication, the server 6040 then: The server 6040 may optionally perform actions using the treatment data. For example, the server 6040 may The data may be stored in a treatment-related database for later use. In this case, the server 6040 may perform a compliance process (e.g., Treatment subject to application of the Privacy Rule and / or compliance reporting as described above (including evaluation of data).
[0178] Upon subsequent upload of new treatment data received from the RT device 4000, The control device 6010 may omit step 10010 and use the The signing key received in step 10030 may be reused. However, if the nonce expires, If you lose upload privileges later, your treatment data may be lost. To upload, the control device 6010 performs step 1001 of the method 1000. In such a case, the server 6040 may optionally An error message may be sent prompting such a restart.
[0179] The connection between the control device 6010 and the server 6040 is not secure, so The unattached control device 6060 intercepts step 10015 and determines the offset. However, the RT device 4000 and the control device 6010 can obtain the The connection between them is secure, so that unassociated control devices 6060 can The control device 6060 cannot eavesdrop on the communication to obtain the signing key, and the control device 6060 cannot send false treatment data. Uploading to the server 6040 is also not permitted. Since the signing key was once obtained from the device 4000, The control device 6010 cannot continue to use this same signing key indefinitely because For example, the nonce used by server 6040 to derive the signing key will eventually expire. Furthermore, the spoofed control device 6010 can Method 1000, since the secret cannot be inferred from the signing key, nonce, and offset No matter how frequently you participate in 0, you cannot guess future signing keys yourself. Therefore, to be able to continuously authorize treatment data uploads, a control device There may be occasions when you need to connect a Device 6010 to an RT Device 4000. The shorter the duration of the treatment, the faster the timing of uploading the treatment data between the control device 6010 and the RT device. Since it is necessary to connect the device to the Vise 4000 in close proximity, security is high. However, the computational load on the system 6000 also increases, and the control device 6010 In this case, the convenience of the independent operation of the RT device 4000 is reduced. The dependency of the connection between the device 4000 and the control device 6010 is also increased, and the independence between them is increased. Therefore, it is desirable to adjust the expiry duration of the nonce to account for such concerns. You can choose to get the lance.
[0180] In one type of method 10000, no offset is used. In such a case, The RT device 4000 and the server 6040 derive the signing key only from the secret and the nonce. Put out.
[0181] In the case of method 10000, a spoofed control signal is connected to the RT device 4000. The device 6010 uses the treatment data (before signing (i.e., calculating the authentication code)). Please note that it is impossible to prevent fraud or falsification of treatment data. Therefore, the server 6040, when using the method 10000, detects such fraud or forgery. I can't put it out.
[0182] 11 is a schematic diagram of a further method 11000. The method 11000 is implemented using the network of FIG. A networked respiratory treatment system 6000 may be configured to access the treatment server in accordance with one form of the present technology. This may be used to authorize the upload of medical data. 5 to 11020 are steps 10005 to 11020 of the method 10000 that are given the corresponding reference numbers. Same as ~10020.
[0183] In step 11025, the RT device 4000 receives the offset, nonce, and The RT device 4000 then uses the signature key to obtain the signature key. , an authentication code (e.g., HMAC) from the treatment data sent in step 11005 In step 11030, the RT device 4000 controls the authentication code. Next, in step 11040, the control device 6010 , the treatment data, the authentication code, and the RT device identifier to the server 6040. In step 11045, the server 6040 receives the The nonce sent in step 11015 is checked to see if it has expired. If the received nonce has expired, authentication fails. If the sent nonce has not expired, the server 6040 returns to step 1101 The offset and nonce sent in 5 and the secret associated with the RT device identifier secret (i.e., a secret known to the RT device 4000) to derive a signing key. The server 6040 then uses the signing key to calculate an authentication code for the treatment data. The derivation of the signing key and the calculation of the authentication code are performed by the RT device in step 11025. The calculated authentication code is the same as that used by the service 4000. If the authentication code matches the authentication code received in the
[0184] When using method 11000, neither the secret nor the signing key is sent to the control device 6010. Furthermore, the method for deriving the signing key and authentication code is The offset, nonce, and authentication information are stored in the control device 6010 (even if the method of deriving them is known to the control device 6010). It is impossible to derive the signing key from the authentication code and treatment data. The spoofed control device 6010 may be configured to receive information about the fraudulent or forged data. does not have the key to generate an authentication code (detected by server 6040) Treatment data cannot be fraudulently or falsified (unless the data is provided).
[0185] A disadvantage of method 11000 is that it requires extra computational load and / or storage capacity on the RT device. This requires signing and transmitting many small chunks of treatment data on the 4000. After storing a large amount of treatment data in memory, the control device 601 signs this data. 0. In addition, the server 6040 and the RT device 40 This also creates an administrative burden on the control device 6010, which may not be simultaneously connected to the Therefore, the control device 6010 (the control device 6010 is the server 604 0) The treatment data is then sent to the server 6040 in association with the correct authentication code. Each sub-data item of treatment data is transferred while disconnected from the server 6040. Keep track of chunks and their associated authentication codes received from the RT device 4000. It is necessary to
[0186] In one type of method 11000, neither an offset nor a nonce is used. A signing key that can be derived from the secret without the need for information exchange is provided to the RT device 4000 and the server. In one such example, the signing key is a secret In this type, steps 11005 to 11020 are omitted. , starting from step 11025. In step 11025, the RT device 400 0 derives a signing key from the secret and uses the signing key to compute an authentication code from the treatment data. In step 11030, the RT device receives the therapy data. Then, in step 11040, both the data and the authentication code are sent to the control device 6010. The control device 6010 sends the treatment data and the authentication code to the server 6040. Finally, in step 11045, the server 6040 retrieves the ID associated with the Derive a signing key using a secret (i.e., a secret known to the RT device 4000); This signing key is used to compute an authentication code for the treatment data. The method of calculating the authentication code is performed by the RT device 4000 in step 11025. The calculated authentication code is the same as that used by If there is a match between the authentication code and the treatment data, the treatment data is authenticated. In this case, the authentication code is essentially derived from a fixed key, so the method using a random nonce Less desirable (i.e., less secure) than 10000.
[0187] This variant of Method 11000 is less secure than the original Method 11000. This is because the RT device 4000 may be a spoofed control device. Any difference between the associated control device 6010 and the unassociated control device 6060 If there is a counterfeit, any amount of counterfeit therapy data may be deemed to have come from the RT device 4000. This will lead to such devices claiming and uploading to server 6040. That's why.
[0188] 5.8 Glossary For purposes of this disclosure, in certain forms of this technology, one or more of the following definitions may be used: In other aspects of the technology, other definitions may also apply.
[0189] Air: In certain forms of the present technology, air may refer to the atmosphere, and in other forms of the present technology , air refers to a combination of other breathable gases (e.g., oxygen-rich atmosphere) obtain.
[0190] Automatic positive airway pressure (APAP) therapy: Depending on the presence or absence of signs of SDB onset, e.g. For example, a CP can automatically adjust the treatment pressure between minimum and maximum limits between breaths. AP therapy.
[0191] Continuous Positive Airway Pressure (CPAP) Therapy: A method of therapy in which the therapeutic pressure remains fairly constant throughout the patient's respiratory cycle. In some forms, the pressure at the entrance to the airways is increased during exhalation. In some configurations, the pressure increases slightly during breathing and decreases slightly during inspiration. Varies between different respiratory cycles (e.g., in response to detecting an onset of partial upper airway obstruction) (Increased in response to a pulmonary embolism and decreased in the absence of notification of partial upper airway obstruction).
[0192] Flow rate: The instantaneous volume (or mass) of air delivered per unit time. Flow rate is the instantaneous volume In some cases, when referring to flow rate, it is a scalar quantity (i.e., a large In other cases, when referring to flow rate, it refers to a vector quantity (i.e., a quantity that has both magnitude and direction). Flow rate may be given the symbol Q "Flow rate" can also be simply called "flow" or "airflow."
[0193] Humidifier: The word "humidifier" refers to the amount of air that is therapeutically beneficial to improve medical respiratory conditions in patients. constructed, arranged, or equipped with a physical structure capable of providing 1000 psi of water (H2O) vapor to an air stream. or a humidification device configured to
[0194] Patient: A person with or without a respiratory disease.
[0195] Respiratory therapy (RT) at therapeutic pressure, typically positive pressure relative to the atmosphere (pressure therapy) and / or air delivery at elevated flow rates relative to typical respiratory flow (flow therapy) Therapeutic addition to the airway entrance.
[0196] Ventilator: A mechanical device that provides pressure support to a patient while they perform some or all of the work of breathing. Chair.
[0197] 5.9 Other Notes A portion of the disclosure of this patent document contains material that is subject to copyright protection. The copyright owner reserves the right to modify, revise, or otherwise modify this patent document. If any person reproduces this patent document or this patent disclosure by facsimile, the Patent Office's patent file If it is something that is recorded in the mail or record, there is no objection if it is for a specific purpose, but if it is for any other purpose, All rights reserved.
[0198] Unless otherwise clearly indicated by the context and unless a range of values is provided, the lower limit 1 / 10 of a unit, between the upper and lower limits of the range, and any other stated value in the stated range It is understood that each intervention value for the intervention range is included in the present technology. The upper and lower limits of these intervention ranges specifically exceed the limits of the stated ranges. If the stated range includes one or both of these limits, In this case, ranges exceeding either or both of these stated limits are also encompassed by the present technology.
[0199] Furthermore, when a value or values are embodied herein as part of the technology, other Unless otherwise specified, such values may be approximated and may vary as practical engineering practice permits or requires. It is understood that such values may be used to any appropriate degree of significance.
[0200] Unless otherwise defined, all technical and scientific terms used herein belong to the art. It has the same meaning as commonly understood by those skilled in the art. and any methods and materials similar or equivalent to the materials used in the practice or testing of this technology. Although a limited number of exemplary methods and materials can be used in the It will be published.
[0201] Although certain materials are described as being suitable for use in the construction of components, their properties may vary. Similar and obvious alternative materials may be used as substitutes. Insofar as any and all components described herein are understood to be manufacturable. Therefore, they can be manufactured collectively or separately.
[0202] As used herein and in the appended claims, the singular form "a" "an" and "the" are used interchangeably unless the context clearly indicates otherwise. Please note that the term "includes multiple equivalents of" and "includes multiple equivalents of".
[0203] All publications mentioned herein are incorporated by reference in their entirety for all purposes, including, but not limited to, the methods and / or methods that are the subject of these publications. or disclosure and description of the materials, are incorporated by reference. , is provided solely for its disclosure prior to the filing date of the present application. Neither of these disclosures is an admission that the present technology did not antedate such publications by virtue of prior patents. Furthermore, the publication dates stated should not be construed as the actual publication dates. may differ and individual confirmation may be required.
[0204] The words "comprises" and "comprising" mean elements, constituent elements, The elements or steps described should be interpreted in a non-exclusive sense. An element, component, or step may be used in conjunction with other elements, components, or steps not specified. indicates that it can be present in, utilized in, or combined with
[0205] Headings used in the detailed description are for the convenience of the reader and are provided to assist in understanding the present disclosure or should not be used to limit what appears in the claims as a whole. These headings are provided for informational purposes only and should not be construed as limiting the scope of the claims or the limitations of the claims. should not be used in this way.
[0206] The technology herein has been described with reference to particular embodiments, but these embodiments It should be understood that these are merely illustrative of the principles and applications of the present technology. In some cases, terms and symbols may indicate specific details that are not necessary for the practice of the present technology. For example, the terms "first" and "second" (etc.) are used, but unless otherwise specified, these terms are not intended to denote any order. Furthermore, the process steps in the method Although the descriptions or examples of the groups may be presented in a sequential order, such order is not required. Those skilled in the art will recognize that such sequences can be changed and / or the manner in which they are performed simultaneously. It will be appreciated that this may be done synchronously or even more synchronously.
[0207] Thus, numerous exemplary embodiments may be implemented without departing from the spirit and scope of the present technology. It should be understood that variations of the above are possible and other arrangements may be devised. Various versions of such arrangements are shown in separate examples in the numbered paragraphs below. can be considered related.
[0208] 5.10 Example of a Patient Interface for the Technology 1. A method of wirelessly communicating with a respiratory treatment device, comprising: The controlling device establishes an insecure wireless communication link with the respiratory treatment device. And, The control device communicates with the first device via a communication line different from the insecure wireless communication line. obtaining a shared secret, the first shared secret being known to the respiratory treatment device; There is something, The control device then combines the second shared secret with the first shared secret and the unsecured wireless communication. and computing the second shared secret using data communicated over the communication line, a shared secret known to the respiratory therapy device and stronger than the first shared secret; The control device wirelessly communicates with the respiratory treatment device based on a second shared secret. And, A method comprising:
[0209] Example 2. Computing the second shared secret involves an implementation that includes a Diffie-Hellman key exchange. Method of Example 1.
[0210] Example 3. The control device further calculates a session key using a second shared secret. The method of Example 1, comprising:
[0211] Example 4. A control device secures data communicated with a respiratory treatment device via a wireless link. 4. The method of example 3, further comprising encrypting and decrypting using a session key.
[0212] Example 5. Establishing an insecure wireless communication link is a risk to respiratory therapy devices. 2. The method of embodiment 1, comprising the control device computing a known symmetric key using the
[0213] Example 6. Obtaining the first shared secret over a different communication line may be performed by the control device. The method of Example 1, wherein the method relies on physical access to the respiratory treatment device by
[0214] Example 7. Obtaining the first shared secret is performed by printing it on the housing of the respiratory treatment device. scanning, by the control device, the first shared secret in machine-readable form. y, the method of Example 6.
[0215] Example 8. The method of Example 7, wherein the machine-readable form is a bar code.
[0216] Example 9. The method of example 8, wherein the barcode is a QR code.
[0217] Example 10. Obtaining the first shared secret is performed via a user interface of the control device. receiving, by the control device, a first shared secret entered via the Method 6.
[0218] Example 11. The control device determines that the second shared secret is known to the respiratory treatment device. The method of Example 1, further comprising confirming by scanning.
[0219] Example 12. To confirm: computing a first hash value using a second shared secret; a second hash value transmitted from the respiratory treatment device over an insecure wireless communication link; receiving the Including, comparing the first hash value to the second hash value; The method of Example 11, comprising:
[0220] Example 13. If the first hash value is not equal to the second hash value, 13. The method of claim 12, further comprising generating a user output via a user interface. method.
[0221] Example 14. A second shared secret provides security between the control device and the respiratory treatment device. 14. The method of any one of embodiments 1 to 13, wherein a wireless communication link is established.
[0222] Example 15. The method of Example 1 further comprising computing a session key from a second shared secret. Method 4.
[0223] Example 16. Control parameter control device for controlling respiratory therapy operation of a respiratory treatment device. 15. The method of claim 14, further comprising: the device transmitting the secure wireless communication link. method.
[0224] Example 17. The control parameters include one of a pressure setting and a flow setting. Method 6.
[0225] Example 18. A control device stores data relating to respiratory therapy operation of a respiratory treatment device. 18. Any of Examples 14 to 17, further comprising receiving via a secure wireless communication link. Either one way.
[0226] Example 19. Data is collected from the respiratory therapy device and the duration of multiple respiratory events. The method of Example 18, including any one or more of:
[0227] Example 20. Computer-readable media having encoded program instructions thereon A data storage medium, wherein the program instructions are any one of the methods of embodiments 1 to 19. A data storage medium configured to cause a processor to perform a method including the method.
[0228] Example 21. Access to the computer-readable data storage medium described in Example 20 a server having access to a computer readable database; The program instructions on the data storage medium are downloaded to the control device via a network. a server configured to receive instructions from the
[0229] Example 22. A control device configured to wirelessly communicate with a respiratory treatment device, , a memory for storing processing instructions; And, establishing an unsecured wireless communication link with a respiratory treatment device; Obtaining a first shared secret via a communication line different from the insecure wireless communication line wherein the first shared secret is known to the respiratory treatment device; and a first shared secret and data communicated over an insecure wireless communication link; and computing a second shared secret using the second shared secret of the respiratory treatment device. and is stronger than the first shared secret; a processor configured to: a control device.
[0230] Example 23. The method further includes a barcode reader, wherein the processor reads the house number of the respiratory treatment device. The barcode printed on the packaging is scanned with a barcode reader. The barcode may be further configured to obtain a first shared secret, the barcode encoding the first shared secret. The control device of Example 22.
[0231] Example 24. The method further includes a user interface, wherein the processor and further configured to obtain a first shared secret via input entered through the interface. The control device of Example 22.
[0232] Example 25. A method for wireless communication between a respiratory treatment device and a control device, comprising: Establishing an insecure wireless communication link with the control device by the respiratory treatment device To do, a first shared secret and data communicated over an insecure wireless communication link; computing by the respiratory treatment device a second shared secret using the first shared secret The secret and the second shared secret are known to the control device, and the second shared secret is that the shared secret is stronger than the The respiratory treatment device wirelessly communicates with the control device based on a second shared secret. And, A method comprising:
[0233] Example 26. A respiratory treatment device configured for wireless communication with a control device. , the respiratory treatment device a memory for storing processing instructions; a controller, establishing an insecure wireless communication link with a control device; a first shared secret and data communicated over an insecure wireless communication link; where the first shared secret and the second shared secret are computed using is known to the control device, and the second shared secret is stronger than the first shared secret. a controller configured to: 1. A respiratory treatment device comprising:
[0234] Example 27. A housing including a printed bar code, a housing for encoding a first shared secret;
[0235] Example 28. A respiratory treatment system, comprising: Respiratory therapy devices; and a control device configured to wirelessly communicate with the respiratory treatment device; , The control device establishing an unsecured wireless communication link with a respiratory treatment device; Obtaining a first shared secret via a communication line different from the insecure wireless communication line wherein the first shared secret is known to the respiratory treatment device; and a first shared secret and data communicated over an insecure wireless communication link; and computing a second shared secret using the second shared secret of the respiratory treatment device. and is stronger than the first shared secret; and communicating wirelessly with the respiratory treatment device based on a second shared secret. a processor configured to: The respiratory treatment device of Example 26.
[0236] Example 29. A respiratory treatment device includes a housing containing a printed barcode, 29. The respiratory treatment system of Example 28, wherein the printed barcode encodes a first shared secret.
[0237] Example 30. The control device further includes a barcode reader, and the processor The first shared secret is obtained by scanning the barcode. The respiratory treatment system of Example 29, further comprising:
[0238] Example 31. The control device further includes a user interface, wherein the processor: to obtain a first shared secret via input entered through a user interface; The respiratory treatment system of Example 29, further comprising:
[0239] Example 32. Interacting with a respiratory treatment device to generate therapy data and a control device configured to communicate with the remote server. A method for uploading to a bar, receiving, by a controlling device, treatment data from a respiratory treatment device; receiving by the control device a nonce from a remote server; the controlling device transmitting the nonce to the respiratory treatment device; the controlling device receiving a signing key from the respiratory treatment device, the signing key comprising: This relies on a nonce and a secret known to the respiratory treatment device and the remote server. And, The control device generates an authentication code using the treatment data and a signing key. Therefore, the authentication code is used to authenticate the treatment data, the controlling device transmitting the treatment data and the authentication code to a remote server; A method comprising:
[0240] Example 33. The method of Example 32, wherein the authentication code is a hashed message authentication code. Law.
[0241] Example 34. The signing key further depends on an offset into the shared secret, and the offset is 34. Any one of embodiments 32-33, wherein the control device receives the information from the remote server. How to do it.
[0242] Example 35. The method of any one of Examples 32-34, wherein the nonce is a pseudorandom number.
[0243] Example 36. The control device generates a signing key using a symmetric key known to the respiratory treatment device. 32. Securely receiving a signing key from a respiratory treatment device by decrypting Any one of ~35 methods.
[0244] Example 37. A control device, comprising: Memory and a processor; Including, The memory contains program instructions, which are executed by the processor. Once connected, the therapy data generated by the respiratory therapy device is uploaded to a remote server. and the program instructions control the control device to: receiving treatment data from a respiratory treatment device; receiving a nonce from a remote server; sending a nonce to a respiratory treatment device; receiving a signing key from the respiratory treatment device, the signing key comprising a nonce and a call relying on a secret known to the respiratory treatment device and to the remote server; generating an authentication code using the treatment data and a signing key, The code is used to authenticate treatment data; sending the treatment data and the authentication code to a remote server; Controlling the control device to perform Control device.
[0245] Example 38. A method for authenticating therapy data generated by a respiratory therapy device, comprising: , receiving treatment data and a first authentication code; Computing a signing key from the nonce and a secret known to the respiratory treatment device. and, computing a second authentication code from the received treatment data and the signing key; Authenticating the treatment data by comparing the first authentication code with the second authentication code To do, A method comprising:
[0246] Example 39. Further comprising transmitting the offset to the respiratory treatment device, wherein the signing key is The method of Example 38, which relies on offset.
[0247] Example 40. The authentication code is a hashed message authentication code. Any one of the nine methods.
[0248] Example 41. The method of any of Examples 38-4, further comprising transmitting a nonce to a respiratory treatment device. One of the following methods:
[0249] Example 42. The method of any one of Examples 38-41, wherein the nonce is a pseudorandom number.
[0250] Example 43. A server, Memory and a processor; Including, The memory contains program instructions, which are executed by the processor. When activated, it controls the server to authenticate therapy data generated by the respiratory therapy device. Control, program instructions are receiving treatment data and a first authentication code; computing a signing key from the nonce and a secret known to the respiratory treatment device; , computing a second authentication code from the received treatment data and the signing key; Authenticating the treatment data by comparing the first authentication code with the second authentication code To do, Controlling the server to do server.
[0251] Example 44. A networked respiratory treatment system, comprising: a respiratory treatment device configured to deliver respiratory treatment to a patient; A remote server; configured to communicate with a respiratory treatment device and to communicate with a remote server A control device, the control device comprising: receiving, by a control device, therapy data from the respiratory therapy device; receiving, by the control device, a nonce from a remote server; sending a nonce to the respiratory treatment device by the control device; receiving, by the controlling device, a signing key from the respiratory treatment device; The authentication key relies on a nonce and a secret known to the respiratory therapy device and the remote server. And, The control device generates an authentication code using the treatment data and a signing key. The authentication code is used to authenticate the treatment data; the controlling device sending the treatment data and the authentication code to a remote server; a control device configured to:
[0252] Example 45. The system of Example 44, wherein the respiratory treatment device is a respiratory pressure treatment device. Hmm.
[0253] Example 46. A control device secures communications with respiratory treatment devices using a shared symmetric key. The system of any one of Examples 44 to 45, configured to perform the above.
[0254] Example 47. The remote server: receiving treatment data and a first authentication code; computing a signing key from the nonce and a secret known to the respiratory treatment device; , computing a second authentication code from the received treatment data and the signing key; Authenticating the treatment data by comparing the first authentication code with the second authentication code To do, The system of any one of Examples 44 to 46, configured to perform the following.
[0255] Example 48. A networked respiratory treatment system, comprising: a respiratory treatment device configured to deliver respiratory treatment to a patient; a control device configured to communicate with the respiratory treatment device; a remote server configured to communicate with the control device, receiving treatment data and a first authentication code from the controlling device; computing a signing key from the nonce and a secret known to the respiratory treatment device; , computing a second authentication code from the received treatment data and the signing key; Authenticating the treatment data by comparing the first authentication code with the second authentication code To do, a remote server configured to:
[0256] Example 49. The system of Example 48, wherein the respiratory treatment device is a respiratory pressure treatment device. Hmm.
[0257] Example 50. A control device secures communications with respiratory treatment devices using a shared symmetric key. The system of any one of Examples 48 to 49, configured to perform the above.
[0258] Example 51. The control device comprises: receiving treatment data from a respiratory treatment device; receiving a nonce from a remote server; sending a nonce to a respiratory treatment device; receiving a signing key from the respiratory treatment device, the signing key comprising a nonce and a call relying on a secret known to the respiratory treatment device and to the remote server; generating an authentication code using the treatment data and a signing key, The code is used to authenticate treatment data; sending the treatment data and the authentication code to a remote server; The system of any one of Examples 48 to 50, configured to perform the following.
[0259] Example 52. A respiratory treatment device comprises: receiving a nonce from a remote server; The signing key from the nonce and a secret known to the respiratory therapy device and the remote server and computing the density generating an authentication code using the treatment data and a signing key; sending the treatment data and the authentication code to a remote server; The system of any one of Examples 48 to 50, configured to perform the following.
[0260] Example 53. Uploading therapy data generated by a respiratory therapy device to a remote server 1. A method of loading, comprising: receiving, by the respiratory treatment device, a nonce from the remote server; The respiratory treatment device sends a signing key from the nonce and a secret known to the remote server. and The respiratory treatment device generates an authentication code using the treatment data and the signing key. wherein the authentication code is used to authenticate the treatment data; Transmitting therapy data and authentication codes from the respiratory therapy device to a remote server And, A method comprising:
[0261] Example 54. The method of Example 53, wherein the authentication code is a hashed message authentication code. Law.
[0262] Example 55. The signing key further depends on an offset into the shared secret, and the offset is 55. Any of embodiments 53-54, wherein the data is received by the respiratory treatment device from the remote server. One way.
[0263] Example 56. The method of any one of Examples 53-55, wherein the nonce is a pseudorandom number.
[0264] Example 57. A respiratory treatment device includes a control device configured to communicate with a remote server. 57. The method of any one of embodiments 53 to 56, wherein the nonce is received via the device.
[0265] Example 58. The respiratory treatment device uses a symmetric key known to the control device to generate a nonce. 58. The method of example 57, wherein the nonce is received from the control device by decrypting the nonce.
[0266] Example 59. A respiratory treatment device includes a control device configured to communicate with a remote server. Any one of Examples 53 to 58, wherein the treatment data and authentication code are transmitted via the device. How to do it.
[0267] Example 60. The control device encrypts the treatment data using a symmetric key known to the control device. and authentication code by encrypting the treatment data and authentication code to the control device The method of Example 59.
[0268] Example 61. A respiratory treatment device, comprising: Connecting to a patient interface and providing a positive pressure airflow to the patient interface. a pressure generator adapted to supply the source; Memory and a processor; Including, The memory contains program instructions, which are executed by the processor. Once connected, the therapy data generated by the respiratory therapy device is uploaded to a remote server. and controlling the respiratory therapy device to: receiving a nonce from a remote server; Computing a signing key from the nonce and a secret known to the remote server; generating an authentication code using the treatment data and a signing key, The code is used to authenticate treatment data; sending the treatment data and the authentication code to a remote server; controlling a respiratory therapy device to perform Respiratory therapy devices.
[0269] Example 62. A networked respiratory treatment system, comprising: a respiratory treatment device for administering respiratory treatment to a patient; a remote server configured to communicate with the respiratory treatment device; Including, Respiratory therapy devices include: receiving a nonce from a remote server; Computing a signing key from the nonce and a secret known to the remote server; generating an authentication code using the treatment data and a signing key, The code is used to authenticate treatment data; sending the treatment data and the authentication code to a remote server; configured to: Networked respiratory treatment systems.
[0270] Example 63. The system of Example 62, wherein the respiratory treatment device is a respiratory pressure treatment device. Hmm.
[0271] Example 64. Securely communicating with a respiratory treatment device and communicating with a remote server. 64. The method of any of Examples 62-63, further comprising a control device configured to: One system.
[0272] Example 65. The control device authenticates the respiratory treatment device using a symmetric key known to the respiratory treatment device. The system of Example 64, configured to securely communicate with a medical device.
[0273] Example 66. The remote server: receiving treatment data and a first authentication code; computing a signing key from the nonce and a secret known to the respiratory treatment device; , computing a second authentication code from the received treatment data and the signing key; Authenticating the treatment data by comparing the first authentication code with the second authentication code To do, The system of any one of Examples 62 to 65, configured to perform the following.
[0274] Example 67. A device comprising: means for receiving treatment data from a respiratory treatment device; means for receiving a nonce from a remote server; means for transmitting the nonce to the respiratory treatment device; means for receiving a signing key from the respiratory treatment device, the signing key comprising a nonce and a call a means for detecting a secret known to the respiratory treatment device and to a remote server; A means for generating an authentication code using the treatment data and a signing key, The code includes a means for authenticating the treatment data; means for transmitting the treatment data and the authentication code to a remote server; 1. An apparatus comprising:
[0275] Example 68. A device comprising: means for receiving treatment data from the respiratory treatment device and a first authentication code; means for computing a signing key from the nonce and a secret known to the respiratory treatment device; and, means for computing a second authentication code from the received treatment data and the signing key; Authenticating the treatment data by comparing the first authentication code with the second authentication code and 1. An apparatus comprising:
[0276] Example 69. An apparatus comprising: a means for delivering respiratory therapy to the patient; means for receiving a nonce from a remote server; means for computing a signing key from the nonce and a secret known to the remote server; A means for generating an authentication code using the treatment data and a signing key, The code includes a means for authenticating the treatment data; means for transmitting the treatment data and the authentication code to a remote server; 1. An apparatus comprising: [Explanation of symbols]
[0277] 5.11 List of Reference Symbols patient 1000 Bedmate: 1100 Patient Interface 3000 Seal forming structure 3100 Plenum Chamber 3200 Structure 3300 Ventilation 3400 Connection port 3600 Forehead support part 3700 RT Device 4000 Outer Housing 4010 Internal part 4012 Part 4014 Panel 4015 Chassis 4016 Handle 4018 Pneumatic Block 4020 Air Filter 4110 Inlet Air Filter 4112 Outlet Air Filter 4114 Muffler 4120 Inlet muffler 4122 Outlet muffler 4124 Pressure Generator 4140 Blower 4142 Motor 4144 Anti-spillback valve 4160 Air Circuit 4170 Electrical Components 4200 PCBA 4202 Electrical Power Supply 4210 Button 4220 Central control unit 4230 Clock 4232 Therapy Device Controller 4240 Protection circuit 4250 Memory 4260 Converter 4270 Pressure Sensor 4272 Flow Sensor 4274 Motor Speed Converter 4276 Interface 4280 Remote External Communications Network 4282 Local external communication network 4284 Remote External Device 4286 Local Foreign Device 4288 Output device 4290 Humidifier 5000 Humidifier inlet 5002 Humidifier outlet 5004 Humidifier Base 5006 Humidifier Reservoir 5110 Humidifier Reservoir Dock 5130 heating element 5240 Networked respiratory therapy system 6000 Control Device 6010 Channel 6013 Wireless connection 6015 Barcode 6017 Second Control Device 6020 Wireless connection 6025 criminal 6030 Server 6040 Wireless connection 6050 Unassociated Control Device 6060 criminal 6065 Wireless connection 6070 method 7000 Step 7010 Step 7020 Step 7030 method 8000 Arrow 8001 Step 8010 Step 8015 Step 8020 Step 8025 Step 8030 Step 8035 Step 8040 Step 8045 Method 8050 Step 8055 Step 8060 Step 8065 Step 8070 Step 8075 Step 8080 Step 8085 Step 8090 Step 8095 method 9000 Step 9005 Step 9010 Step 9020 Step 9030 Step 9035 Step 9040 Step 9045 Step 9050 Step 9055 Step 9060 Step 9065 method 10000 Step 10005 Step 10010 Step 10015 Step 10020 Step 10025 Step 10030 Step 10035 Step 10040 Step 10045 Method 11000 Step 11005 Step 11010 Step 11015 Step 11020 Step 11025 Step 11030 Step 11040 Step 10045
[0278] 6 References 1.Simple Pairing Whitepaper, version 10r 00.Bluetooth Core Specification Working Group, August 2006. 2.Using the Secure Remote Password (SRP) Protocol for TLS Authentication (RFC-50 54), Taylor et al., November 2007.
Claims
1. 1. A method for wireless communication with a respiratory treatment device, comprising: A controlling device establishing an unsecured wireless communication link with said respiratory treatment device. And, The control device transmits the first signal via a communication line different from the insecure wireless communication line. and obtaining a first shared secret for the respiratory treatment device. It is known that The control device combines a second shared secret with the first shared secret and the insecure A calculation is performed using data communicated via a wireless communication line, The secret is known to the respiratory treatment device and is stronger than the first shared secret. And, The control device communicates wirelessly with the respiratory treatment device based on the second shared secret. and A method comprising:
2. 10. The method of claim 1, wherein computing the second shared secret comprises a Diffie-Hellman key exchange. How to do it.
3. and further comprising the control device computing a session key using the second shared secret. The method of claim 1 , comprising:
4. The control device communicates data with the respiratory treatment device via the wireless link. The method of claim 3 further comprising encrypting and decrypting using the session key.
5. Establishing an insecure wireless communication link is known to the respiratory treatment device. The method of claim 1 , further comprising the control device computing a symmetric key of
6. Obtaining the first shared secret over a different line may be performed by the control device.
10. The method of claim 1, wherein the method relies on physical access to the respiratory treatment device.
7. Obtaining the first shared secret includes obtaining a first shared secret printed on a housing of the respiratory treatment device. scanning the first shared secret in machine-readable form by the control device; The method of claim 6, comprising:
8. The method of claim 7 , wherein the machine-readable form is a bar code.
9. The method of claim 8 , wherein the barcode is a QR code.
10. Obtaining the first shared secret may include using a user interface of the control device. receiving, by the control device, the first shared secret entered via The method of claim 6.
11. The control device may inform the respiratory treatment device that the second shared secret is known to the respiratory treatment device.
10. The method of claim 1, further comprising verifying by a
12. The confirmation is computing a first hash value using the second shared secret; a second hash value from the respiratory treatment device via the unsecured wireless communication link; receiving a value; comparing the first hash value to the second hash value; 12. The method of claim 11, comprising:
13. If the first hash value is not equal to the second hash value, 13. The method of claim 12, further comprising generating a user output via a user interface. method.
14. The second shared secret provides security between the control device and the respiratory treatment device. The method of claim 1 , wherein a wireless communication link is established.
15. 15. The method of claim 14, further comprising computing a session key from the second shared secret. 。
16. a control parameter for controlling the respiratory therapy operation of the respiratory treatment device; 15. The method of claim 14, further comprising: transmitting the secure wireless communication link. 。
17. 17. The method of claim 16, wherein the control parameters include one of a pressure setting and a flow setting. 。
18. The control device stores data related to the respiratory therapy operation of the respiratory treatment device in the security database.
15. The method of claim 14, further comprising receiving via a wireless communication link.
19. The data may include time of use of the respiratory treatment device and any of a plurality of respiratory events.
20. The method of claim 18, comprising one or more of:
20. A computer-readable data storage device having coded program instructions stored thereon.
10. A medium, the program instructions causing a processor to perform a method including the method of claim 1.
1. A data storage medium configured to:
21. A server having access to the computer readable data storage medium of claim 20. the server is connected to the computer-readable data storage medium; A request to download the program instructions to the control device via a network is received. A server configured to receive emails.
22. a control device configured to wirelessly communicate with a respiratory treatment device, a memory for storing processing instructions; 1. A processor, comprising: establishing an unsecured wireless communication link with the respiratory treatment device; obtaining a first shared secret via a line different from the insecure wireless communication line; the first shared secret is known to the respiratory treatment device; 、 the first shared secret and the data communicated over the insecure wireless communication link. and computing a second shared secret using the second shared secret, the shared secret is known to the medical device and is stronger than the first shared secret; a processor configured to: a control device.
23. a barcode reader for reading the respiratory treatment device housing; The barcode printed on the tag is scanned with the barcode reader. and obtaining the first shared secret, the barcode being the first shared secret.
23. The control device of claim 22, wherein the control device encodes the density.
24. The method further includes a user interface, and the processor and further configured to obtain the first shared secret via input entered through the 23. The control device of claim 22.
25. 1. A method for wireless communication between a respiratory treatment device and a control device, comprising: The respiratory treatment device establishes an unsecured wireless communication link with the control device. To stand and a first shared secret and data communicated over the insecure wireless communication link; computing by the respiratory treatment device a second shared secret using the first The shared secret and the second shared secret are known to the control device, and the second shared secret is the shared secret is stronger than the first shared secret; The respiratory treatment device communicates wirelessly with the control device based on the second shared secret. and A method comprising:
26. 1. A respiratory treatment device configured to wirelessly communicate with a control device, comprising: a memory for storing processing instructions; a controller, establishing an unsecured wireless communication link with the control device; a first shared secret and data communicated over the insecure wireless communication link; computing a second shared secret using the first shared secret and the second shared secret The shared secret is known to the control device and the second shared secret is known to the first shared secret. It is more powerful than secrets, a controller configured to:
1. A respiratory treatment device comprising:
27. and a housing including a printed bar code, the printed bar code comprising:
27. The respiratory treatment device of claim 26, wherein the first shared secret is encoded.
28. 1. A respiratory treatment system comprising: a respiratory treatment device; a control device configured to wirelessly communicate with the respiratory treatment device; Including, The control device includes a processor, the processor comprising: establishing an unsecured wireless communication link with the respiratory treatment device; obtaining a first shared secret via a line different from the insecure wireless communication line; the first shared secret is known to the respiratory treatment device; 、 the first shared secret and the data communicated over the insecure wireless communication link. and computing a second shared secret using the second shared secret, the shared secret is known to the medical device and is stronger than the first shared secret; wirelessly communicating with the respiratory treatment device based on the second shared secret; configured to: Respiratory treatment systems.
29. The respiratory treatment device includes a housing that includes a printed barcode, 30. The respiratory treatment system of claim 28, wherein the barcode encodes the first shared secret.
30. The control device further includes a barcode reader, and the processor The first shared secret is obtained by the barcode reader by scanning the barcode.
30. The respiratory treatment system of claim 29, further configured to:
31. The control device further includes a user interface, and the processor An input entered through a user interface is obtained via the first shared secret.
30. The respiratory treatment system of claim 29, further configured to:
32. and communicating therapy data generated by the respiratory treatment device to and from the respiratory treatment device. and a remote server via a control device configured to communicate with said remote server. A method of uploading to receiving the treatment data from the respiratory treatment device by the control device; receiving by the control device a nonce from the remote server; the control device transmitting the nonce to the respiratory treatment device; the controlling device receiving a signing key from the respiratory treatment device, The secret key is a combination of the nonce and a secret known to the respiratory treatment device and the remote server. Dependence on density, The controlling device generates an authentication code using the treatment data and the signing key. and the authentication code is used to authenticate the treatment data; The controlling device transmits the treatment data and the authentication code to the remote server. And, A method comprising:
33. 33. The method of claim 32, wherein the authentication code is a hashed message authentication code.
34. The signing key further depends on an offset into the shared secret, the offset being 33. The method of claim 32, wherein the information is received by the control device from the remote server.
35. 33. The method of claim 32, wherein the nonce is a pseudorandom number.
36. The control device generates the signing key using a symmetric key known to the respiratory treatment device. securely receiving the signing key from the respiratory treatment device by decrypting 33. The method of claim 32.
37. A control device comprising: Memory and a processor; Including, The memory includes program instructions that are executed by the processor. When executed, it uploads therapy data generated by the respiratory therapy device to a remote server. and controlling the control device to load the program instructions, receiving the treatment data from the respiratory treatment device; receiving a nonce from the remote server; sending the nonce to the respiratory treatment device; receiving a signing key from the respiratory treatment device, the signing key being a signature of the nonce; and a secret known to the respiratory treatment device and the remote server, And, generating an authentication code using the treatment data and the signing key, The authentication code is used to authenticate the medical data; sending the treatment data and the authentication code to the remote server; and controlling the control device to perform Control device.
38. 1. A method for authenticating treatment data generated by a respiratory treatment device, comprising: receiving the treatment data and a first authentication code; computing a signing key from the nonce and a secret known to said respiratory treatment device; 、 computing a second authentication code from the received treatment data and the signing key; comparing the first authentication code with the second authentication code to obtain the treatment data; and A method comprising:
39. and transmitting an offset to the respiratory treatment device, the signing key being the offset of the offset.
39. The method of claim 38, wherein the method is dependent on offset.
40. 39. The method of claim 38, wherein the authentication code is a hashed message authentication code.
41. 39. The method of claim 38, further comprising transmitting the nonce to the respiratory treatment device.
42. 39. The method of claim 38, wherein the nonce is a pseudorandom number.
43. a server, Memory and a processor; Including, The memory includes program instructions that are executed by the processor. When executed, the server is configured to authenticate therapy data generated by a respiratory therapy device. and said program instructions control a server, receiving the treatment data and a first authentication code; computing a signing key from a nonce and a secret known to the respiratory treatment device; computing a second authentication code from the received treatment data and the signing key; comparing the first authentication code with the second authentication code to obtain the treatment data; and controlling the server to perform server.
44. 1. A networked respiratory treatment system comprising: a respiratory treatment device configured to deliver respiratory treatment to a patient; A remote server; configured to communicate with the respiratory treatment device and to communicate with the remote server. A control device comprising: receiving, by the control device, treatment data from the respiratory treatment device; receiving by the control device a nonce from the remote server; sending the nonce to the respiratory treatment device by the control device; receiving, by the controlling device, a signing key from the respiratory treatment device; The signing key is a combination of the nonce and a signature already present on the respiratory treatment device and the remote server. Relying on the secrets of knowledge, The controlling device generates an authentication code using the treatment data and the signing key. and the authentication code is used to authenticate the treatment data; the controlling device sending the treatment data and the authentication code to the remote server; And, a control device configured to: Including, system.
45. 45. The system of claim 44, wherein the respiratory treatment device is a respiratory pressure treatment device.
46. The control device secures communication with the respiratory treatment device using a shared symmetric key.
45. The system of claim 44 configured to:
47. The remote server receiving the treatment data and a first authentication code; computing a signing key from a nonce and a secret known to the respiratory treatment device; computing a second authentication code from the received treatment data and the signing key; comparing the first authentication code with the second authentication code to obtain the treatment data; and configured to:
45. The system of claim 44.
48. 1. A networked respiratory treatment system comprising: a respiratory treatment device configured to deliver respiratory treatment to a patient; a control device configured to communicate with the respiratory treatment device; a remote server configured to communicate with the control device, the remote server - receiving treatment data and a first authentication code from the controlling device; computing a signing key from a nonce and a secret known to the respiratory treatment device; computing a second authentication code from the received treatment data and the signing key; comparing the first authentication code with the second authentication code to obtain the treatment data; and a remote server configured to: Including, the system.
49. 49. The system of claim 48, wherein the respiratory treatment device is a respiratory pressure treatment device.
50. The control device secures communication with the respiratory treatment device using a shared symmetric key.
49. The system of claim 48 configured to:
51. The control device receiving the treatment data from the respiratory treatment device; receiving a nonce from the remote server; sending the nonce to the respiratory treatment device; receiving a signing key from the respiratory treatment device, the signing key being a signature of the nonce; and a secret known to the respiratory treatment device and the remote server, And, generating an authentication code using the treatment data and the signing key, The authentication code is used to authenticate the medical data; sending the treatment data and the authentication code to the remote server; configured to:
49. The system of claim 48.
52. The respiratory treatment device comprises: receiving a nonce from the remote server; The signing key from the nonce and a signature key already known to the respiratory treatment device and the remote server. To calculate the secrets of knowledge, generating an authentication code using the treatment data and the signing key; sending the treatment data and the authentication code to the remote server; configured to:
49. The system of claim 48.
53. Method for uploading therapy data generated by a respiratory therapy device to a remote server It is a law, receiving by the respiratory treatment device a nonce from the remote server; A signing key from the nonce and a secret known to the remote server is sent to the respiratory treatment data and calculating by a vice; The respiratory treatment device generates an authentication code using the treatment data and the signing key. wherein the authentication code is used to authenticate the treatment data; the treatment data and the authentication code from the respiratory treatment device to the remote server Sending and A method comprising:
54. 54. The method of claim 53, wherein the authentication code is a hashed message authentication code.
55. The signing key further depends on an offset into the shared secret, the offset being 54. The method of claim 53, wherein the information is received by the respiratory treatment device from a remote server.
56. The method of claims 53 to 55, wherein the nonce is a pseudorandom number.
57. The respiratory treatment device includes a control device configured to communicate with the remote server.
54. The method of claim 53, wherein the nonce is received via
58. The respiratory treatment device uses a symmetric key known to the control device to generate the nonce.
58. The method of claim 57, wherein the nonce is received from the control device by decrypting Law.
59. The respiratory treatment device includes a control device configured to communicate with the remote server.
54. The method of claim 53, wherein the therapy data and the authentication code are transmitted via
60. The controlling device transmits the treatment data using a symmetric key known to the controlling device. and encrypting the authentication code to store the treatment data and the authentication code.
60. The method of claim 59, wherein the control device transmits the signal.
61. Respiratory therapy devices include: connecting to a patient interface and providing a positive pressure air flow through said patient interface; a pressure generator adapted to supply the pressure to the pressure source; Memory and a processor; Including, The memory includes program instructions that are executed by the processor. When executed, the therapy data generated by the respiratory therapy device is accessed by a remote server. and controlling the respiratory treatment device to upload a program instruction to the respiratory treatment device, the program instruction comprising: receiving a nonce from the remote server; Computing a signing key from the nonce and a secret known to the remote server; 、 generating an authentication code using the treatment data and the signing key, The authentication code is used to authenticate the medical data; transmitting the treatment data and the authentication code to the remote server. A respiratory treatment device that controls a respiratory treatment device.
62. 1. A networked respiratory treatment system comprising: a respiratory treatment device for administering respiratory treatment to a patient; a remote server configured to communicate with the respiratory treatment device; Including, The respiratory treatment device comprises: receiving a nonce from the remote server; Computing a signing key from the nonce and a secret known to the remote server; 、 generating an authentication code using the treatment data and the signing key, the code is used to authenticate the treatment data; sending the treatment data and the authentication code to the remote server; configured to: system.
63. 63. The system of claim 62, wherein the respiratory treatment device is a respiratory pressure treatment device.
64. Securely communicating with the respiratory treatment device and communicating with the remote server.
63. The system of claim 62, further comprising a control device configured to:
65. The control device communicates with the respiratory treatment device using a symmetric key known to the respiratory treatment device.
65. The system of claim 64, configured to securely communicate with a medical device.
66. The remote server receiving the treatment data and a first authentication code; computing a signing key from a nonce and a secret known to the respiratory treatment device; computing a second authentication code from the received treatment data and the signing key; comparing the first authentication code with the second authentication code to obtain the treatment data; and configured to:
63. The system of claim 62.
67. 1. An apparatus comprising: means for receiving treatment data from a respiratory treatment device; means for receiving a nonce from a remote server; means for transmitting the nonce to the respiratory treatment device; means for receiving a signing key from the respiratory treatment device, the signing key being a signature of the nonce; and a secret known to the respiratory treatment device and the remote server. Step by step, means for generating an authentication code using the treatment data and the signing key, The authentication code is used to authenticate the medical data; means for transmitting the treatment data and the authentication code to the remote server; 1. An apparatus comprising:
68. 1. An apparatus comprising: means for receiving treatment data from the respiratory treatment device and a first authentication code; means for computing a signing key from a nonce and a secret known to said respiratory treatment device; 、 means for computing a second authentication code from the received treatment data and the signing key; comparing the first authentication code with the second authentication code to obtain the treatment data; and a means for authenticating the 1. An apparatus comprising:
69. 1. An apparatus comprising: a means for delivering respiratory therapy to the patient; means for receiving a nonce from a remote server; means for computing a signing key from the nonce and a secret known to the remote server; 、 A means for generating an authentication code using the treatment data and the signing key, a means for authenticating said treatment data; means for transmitting the treatment data and the authentication code to the remote server; 1. An apparatus comprising: