Facilitating persistent connectivity to remote specimen monitoring systems
The analyte monitoring system addresses communication gaps by detecting unresponsive channels and providing alerts, ensuring continuous data availability and user awareness, thus improving system responsiveness.
Patent Information
- Application Number
- JP2025522118
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-10-24
- Filing Date
- 2023-10-18
- Publication Date
- 2025-11-12
AI Technical Summary
Users of analyte monitoring systems experience gaps in data communication with central application servers, making it difficult to determine the cause of communication problems and leading to pauses in data reception.
An analyte monitoring system that includes mechanisms to detect unresponsive communication channels and provides alerts and notifications to users, allowing for timely response to communication issues.
Facilitates prompt identification and resolution of communication problems, ensuring continuous data availability and user awareness of connectivity status.
Smart Images

Figure 2025536929000001_ABST
Abstract
Description
[Technical Field]
[0001] Priority This application claims the benefit under 35 USC § 119(e) of U.S. Provisional Patent Application No. 63 / 380,609, filed October 24, 2022, which is incorporated herein by reference.
[0002] The subject matter described herein relates to systems and methods that facilitate communication between devices and facilitate maintaining a communication session between devices, for example, with respect to operation of a handheld device and a remote server that form part of an in-vivo analyte monitor system. [Background technology]
[0003] Detection of glucose or other analyte concentration levels in certain individuals using medical sensors is believed to be beneficial to their health. For example, monitoring glucose levels is important for individuals with diabetes or pre-diabetes. People with diabetes may need to monitor their glucose levels to determine when they need medication (e.g., insulin) to reduce their glucose levels or when they need additional glucose.
[0004] Devices and systems have been developed for automatic in-vivo monitoring of analyte concentrations, such as glucose levels, in bodily fluids, such as the bloodstream or interstitial fluid. Some of these analyte level measurement devices are configured so that at least a portion of the device is positioned below the surface of the user's skin, for example, in the user's blood vessels or subcutaneous tissue. As used herein, the term analyte monitoring system refers to any type of in-vivo monitoring system that uses a sensor that is at least partially placed subcutaneously to automatically measure and store sensor data representative of analyte concentration levels over time. The analyte monitoring system may include transmitting sensor data to a processor / display unit for further processing and / or display to a user.
[0005] Frequent monitoring and management of analyte levels, such as glucose, ketones, lactate, oxygen, or hemoglobin A1C, can improve the overall health of people, and particularly those with diabetes. As an example, diabetic patients generally need to monitor their glucose levels to ensure they are maintained within a clinically safe range and can also use that information to determine when they need insulin to manage their glucose levels or when they need glucose to raise their glucose levels. Clinical data has revealed a strong correlation between the frequency of glucose monitoring and glycemic control. However, despite this correlation, many individuals diagnosed with diabetes do not monitor their glucose levels as frequently as they should due to a combination of factors, including convenience, testing discretion, pain associated with glucose testing, and cost.
[0006] To increase patient adherence to frequent glucose monitoring regimens, in-vivo analyte monitoring systems can be utilized in which a sensor-controlling device can be worn on the body of an individual requiring analyte monitoring. The sensor-controlling device can also be configured to transmit analyte data to one or more data-receiving devices, from which the individual, their healthcare provider (“HCP”), or others can review the data and make therapeutic decisions. The data-receiving device can include various hardware components to enable processing of the analyte data received from the sensor-controlling device and must include long-range communication components to enable communication with the sensor-controlling device. The data-receiving device can further include additional testing or transmission hardware to assist the individual or their HCP in making therapeutic decisions.
[0007] The data received from the sensor-controlled device may be further relayed by one or more other devices to a central application server associated with the analyte monitoring system. The central application server may perform additional analysis of the data and provide the analysis to a user of the sensor-controlled device. In some cases, the central application server may further provide some information based on the data and analysis to other users of the analyte monitoring system. However, users who rely on receiving this data from a remote application server that monitors the health and well-being of users wearing the sensor-controlled device may experience pauses or other gaps in the data they receive. It may be difficult for a user to determine whether the pauses are due to a problem with the sensor-controlled device, the analyte monitoring system, or the user wearing the sensor-controlled device. In most cases, the user is simply left in the dark without any additional information until current sensor data is provided again. [Prior art documents] [Patent documents]
[0008] [Patent Document 1] US Patent Application Publication No. 2013 / 0150691 [Patent Document 2] U.S. Patent Application Publication No. 2021 / 0204841 [Patent Document 3] International Publication No. 2018 / 136898 [Patent Document 4] International Publication No. 2019 / 236850 [Patent Document 5] International Publication No. 2019 / 236859 [Patent Document 6] International Publication No. 2019 / 236876 [Patent Document 7] US Patent Application Publication No. 2020 / 0196919 [Patent Document 8] US Patent Application Publication No. 2016 / 0331283 [Patent Document 9] US Patent Application Publication No. 2018 / 0235520 [Patent Document 10] US Patent Application Publication No. 2014 / 0171771 [Patent Document 11] US Patent Application Publication No. 2010 / 0230285 [Patent Document 12] US Patent Application Publication No. 2019 / 0274598 Summary of the Invention [Problem to be solved by the invention]
[0009] Therefore, it would be beneficial to incorporate an alternative mechanism for a user of a monitoring application associated with an analyte monitoring system to determine when a communication problem with a central application server exists. Additionally, it would be further beneficial to provide a system and method that expedites response to these communication problems. [Means for solving the problem]
[0010] The objects and advantages of the presently disclosed subject matter will be set forth in and obvious from the description which follows, as well as be learned by practice of the presently disclosed subject matter. Additional advantages of the presently disclosed subject matter will be realized and attained by the methods and systems particularly pointed out in the description and claims hereof, as well as from the drawings.
[0011] Embodiments described herein include analyte monitoring systems configured to use various systems and methods to facilitate the communication of analyte data and derived data therefrom to a data monitoring device. Certain embodiments include mechanisms for detecting whether a communication channel between the data monitoring device and one or more remote servers associated with or used by the analyte monitoring system is available. In particular, certain embodiments include techniques for detecting that a communication channel between an application executing on a mobile device and associated with the analyte monitoring system and the analyte monitoring system server is not responding. Certain embodiments further include providing a response to detecting that the communication channel is not responding.
[0012] To achieve these and other advantages and in accordance with the objectives of the presently disclosed subject matter, as embodied and broadly described, the presently disclosed subject matter includes an analyte monitoring device and a computer program product stored on a computer-readable medium for monitoring an analyte to detect when a communication channel between an application and an analyte monitoring system server is unresponsive. Exemplary systems and methods may include an analyte monitoring system. The analyte monitoring system may include a mobile device having one or more processors and memory communicatively coupled thereto. The memory may include instructions configured, when executed by the one or more processors, to cause the one or more processors to execute an application associated with the analyte monitoring system. The analyte monitoring system may include an analyte monitoring system server configured to be communicatively coupled with the application. The application associated with the analyte monitoring system, when executing the instructions, is configured to detect when a communication channel between the application and the analyte monitoring system server is unresponsive by performing certain operations. The application may receive notifications from the analyte monitoring system server through a notification service server. The notification service server may be configured to be communicatively coupled with the application and the analyte monitoring system server. In response to receiving the notification, the application can cancel output of a first connectivity alert that was scheduled before receiving the notification. In response to receiving the notification, the application can schedule output of a second connectivity alert. The second connectivity alert can be scheduled to be output upon expiration of a timer unless the mobile device receives a second notification from the analyte monitor system server. The application can determine that the timer has expired. The application can output a second connectivity alert indicating that the application has not established connectivity with the analyte monitor system server for a predetermined period of time.
[0013] In some embodiments, the application may receive a request to establish a schedule for monitoring a communication channel between the application and the analyte monitor system server prior to receiving a notification from the analyte monitor system server. In response to receiving the request, the application may schedule output of a first connectivity alert. In some embodiments, the amount of time associated with the timer is based on user input to an application associated with the analyte monitor system. In some embodiments, the application is a monitor application of the analyte monitor system. Through the application, a first user receives information related to an analyte level of a second user.
[0014] In some embodiments, the application is further configured to attempt to initiate a communication session with the analyte monitor system server using the above-mentioned communication channel or an alternate communication channel before outputting the second connectivity alert. In some embodiments, the application is further configured to receive a second notification from the analyte monitor system server before determining that the timer has expired, discontinue outputting the second connectivity alert, and schedule outputting a third connectivity alert. The third connectivity alert can be scheduled to be output upon expiration of the second timer unless the mobile device receives a third notification from the analyte monitor system server. In some embodiments, the application is further configured to receive other data from the analyte monitor system server before determining that the timer has expired, discontinue outputting the second connectivity alert, and schedule outputting a third connectivity alert. The third connectivity alert can be scheduled to be output upon expiration of the second timer unless the mobile device receives a third notification from the analyte monitor system server.
[0015] According to another aspect of the presently disclosed subject matter, systems and methods may include systems and methods for responding to detecting that a communication channel between an application and an analyte monitoring system is unresponsive. Exemplary systems and methods may include an analyte monitoring system. The analyte monitoring system may include a mobile device having one or more processors and a memory communicatively coupled thereto. The memory includes instructions configured, when executed by the one or more processors, to cause the one or more processors to execute an application associated with the analyte monitoring system. The analyte monitoring system may further include an analyte monitoring system server configured to be communicatively coupled to the application. The application associated with the analyte monitoring system may be configured, upon executing the instructions, to receive one or more current values associated with an analyte level and one or more past values associated with the analyte level through the communication channel between the application and the analyte monitoring system server. The application may detect that the communication channel between itself and the analyte monitoring system server is unresponsive. The application may determine one or more possible causes for the communication channel being unresponsive. The application may modify an output of the application based on the communication channel being unresponsive. The application may display a notification based on the one or more possible causes for the communication channel being unresponsive. The notification may include additional information to resolve the non-responsive communication channel. In some embodiments, the application is a monitor application of an analyte monitoring system. Through the application, a first user receives information related to the analyte level of a second user.
[0016] In some embodiments, modifying the output of the application includes restricting functionality of the application while the communication channel is unresponsive. In some embodiments, the application is capable of storing past values. Modifying the output of the application includes displaying the past values until the application detects that the communication channel is unresponsive. In some embodiments, the application is further configured to encrypt the past values before storing. In some embodiments, the application is further configured to anonymize the past values before storing. In some embodiments, the application is further configured to erase the past values after a predetermined period of time has elapsed.
[0017] In some embodiments, modifying the output of the application includes displaying a last known status of the analyte level. In some embodiments, the application is further configured to determine the last known status of the analyte level by comparing one or more current values to one or more thresholds, each corresponding to a respective last known status. In some embodiments, the notification is persistently displayed by the application while the communication channel is unresponsive. In some embodiments, the notification identifies an error within the application or a system status of the mobile device. In some embodiments, the notification identifies an error within the analyte monitoring system server. In some embodiments, the notification includes a recommendation to use a second communication channel between the application and the analyte monitoring system server.
[0018] In some embodiments, the application is further configured to, after displaying the notification, detect that the communication channel between the application and the analyte monitor system server is responsive, and receive additional historical values associated with the analyte corresponding to a period during which the communication channel was unresponsive. In some embodiments, the application is further configured to determine a geolocation of the mobile device upon detecting that the communication channel is unresponsive. After displaying the notification, the application may detect that the communication channel between the application and the analyte monitor system server is responsive, and provide the geolocation of the mobile device to the analyte monitor system server upon detecting that the communication channel is unresponsive.
[0019] Embodiments described herein include an analyte monitor system including an application executing on a mobile device and an analyte monitor system server. The application is configured to detect when a communication channel between the application and the analyte monitor system server is unresponsive and take appropriate action or recommend options for remediating the unresponsive communication channel. The technique includes receiving a notification from the analyte monitor system server through a notification service server. In response to receiving the notification, outputting of a first connectivity alert is discontinued. Also in response to receiving the notification, outputting of a second connectivity alert is scheduled to be output upon expiration of a timer unless the mobile device receives a second notification from the analyte monitor system server. When output, the second connectivity alert indicates that the application has not established connectivity with the analyte monitor system server for a period of time.
[0020] Other systems, methods, features, and advantages of the subject matter described herein will be apparent to one of ordinary skill in the art upon examination of the following figures and detailed description. All such additional systems, methods, features, and advantages are intended to be included within this description, be within the subject matter described herein, and be protected by the accompanying claims. These features of the example embodiments should not be construed in any way as limiting the scope of the claims, even if the claims do not explicitly recite these features.
[0021] It is to be understood that both the foregoing general description and the following detailed description are exemplary and are intended to provide further explanation of the presently disclosed subject matter. The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate and are included to provide a further understanding of the methods and systems of the presently disclosed subject matter. Together with the description, the drawings serve to explain the principles of the presently disclosed subject matter.
[0022] Details of the subject matter presented herein, both as to structure and operation, will be apparent from consideration of the accompanying drawings, in which like reference numerals indicate like parts. The components in these figures are not necessarily to scale, emphasis instead being placed upon illustrating the principles of the inventive subject matter. Moreover, all illustrative examples are intended to convey design concepts, and relative sizes, shapes, and other detailed attributes may be illustrated schematically, rather than precisely or precisely. [Brief explanation of the drawings]
[0023] [Figure 1A] 1 is a system schematic diagram of a sensor applicator, a reader device, a monitor system, a network, and a remote system. [Figure 1B] FIG. 1 illustrates the operating environment of an exemplary analyte monitor system suitable for use with the technology described herein. [Figure 2A] FIG. 2 is a block diagram illustrating an exemplary embodiment of a reader device. [Figure 2B]FIG. 2 is a block diagram illustrating an exemplary data receiving device for communicating with a sensor in accordance with an illustrative embodiment of the presently disclosed subject matter. [Figure 2C] FIG. 1 is a block diagram illustrating an exemplary embodiment of a sensor control device. [Figure 2D] FIG. 1 is a block diagram illustrating an exemplary embodiment of a sensor control device. [Figure 2E] FIG. 1 is a block diagram illustrating an exemplary analyte sensor according to an illustrative embodiment of the presently disclosed subject matter. [Figure 3A] FIG. 10 is a close-up perspective view depicting an exemplary embodiment of a user preparing a tray for assembly. [Figure 3B] 10A-10C are side views depicting an exemplary embodiment of a user preparing the applicator device for assembly. [Figure 3C] FIG. 10 is a close-up perspective view depicting an exemplary embodiment in which a user inserts an applicator device into a tray during assembly. [Figure 3D] FIG. 10 is a close-up perspective view depicting an exemplary embodiment in which a user removes the applicator device from a tray during assembly. [Figure 3E] FIG. 10 is a close-up perspective view depicting an exemplary embodiment in which a patient applies a sensor using an applicator device. [Figure 3F] FIG. 1 is a close-up perspective view depicting an exemplary embodiment of a patient with an applied sensor and a used applicator device. [Figure 4A] 1 is a side view depicting an exemplary embodiment of an applicator device coupled to a cap. [Figure 4B] FIG. 10 is a side perspective view depicting an exemplary embodiment of an applicator device and cap separated. [Figure 4C] FIG. 1 is a perspective view depicting an exemplary embodiment of the distal end of the applicator device and electronics housing. [Figure 4D] FIG. 1 is a top perspective view of an illustrative applicator device in accordance with the presently disclosed subject matter. [Figure 4E] FIG. 4E is a bottom perspective view of the applicator device of FIG. 4D. [Figure 4F]FIG. 4E is an exploded view of the applicator device of FIG. 4D. [Figure 4G] FIG. 4E is a side cutaway view of the applicator device of FIG. 4D. [Figure 5] FIG. 1 is a close-up perspective view depicting an exemplary embodiment of a tray with a sterilization lid attached thereto. [Figure 6A] FIG. 1 is a close-up perspective cutaway view depicting an exemplary embodiment of a tray having a sensor delivery component. [Figure 6B] FIG. 1 is a close-up perspective view depicting a sensor delivery component. [Figure 7A] FIG. 1 is an isometric exploded top view of an illustrative sensor control device. [Figure 7B] FIG. 1 is an isometric exploded bottom view of an illustrative sensor control device. [Figure 8A] FIG. 12 is an assembly view of an on-body device including an integrated connector for a sensor assembly. [Figure 8B] FIG. 10 is a cross-sectional view of an on-body device including an integrated connector for a sensor assembly. [Figure 8C] FIG. 10 is a cross-sectional view of an on-body device including an integrated connector for a sensor assembly. [Figure 9A] 2D is a side view of the exemplary embodiment of the sensor applicator of FIG. 1A coupled with the cap of FIG. 2C. [Figure 9B] 2D is a cross-sectional side view of an exemplary embodiment of the sensor applicator of FIG. 1A coupled with the cap of FIG. 2C. [Figure 10A] FIG. 10 is an isometric view of another exemplary sensor control device. [Figure 10B] FIG. 10 is a side view of another exemplary sensor control device. [Figure 11A] 10A-10B are cross-sectional side views illustrating the assembly of a sensor applicator with the sensor control device of FIGS. 10A-10B. [Figure 11B] 10A-10B are cross-sectional side views illustrating the assembly of a sensor applicator with the sensor control device of FIGS. 10A-10B. [Figure 11C] 10A-10B are cross-sectional side views illustrating the assembly of a sensor applicator with the sensor control device of FIGS. 10A-10B. [Figure 12A] 10A-10B are cross-sectional side views illustrating the assembly and disassembly of an exemplary embodiment of a sensor applicator and sensor control device of FIGS. 10A-10B. [Figure 12B] 10A-10B are cross-sectional side views illustrating the assembly and disassembly of an exemplary embodiment of a sensor applicator and sensor control device of FIGS. 10A-10B. [Figure 12C] 10A-10B are cross-sectional side views illustrating the assembly and disassembly of an exemplary embodiment of a sensor applicator and sensor control device of FIGS. 10A-10B. [Figure 13A] 1 is a cross-sectional view depicting an exemplary embodiment of an applicator during a deployment stage. [Figure 13B] 1 is a cross-sectional view depicting an exemplary embodiment of an applicator during a deployment stage. [Figure 13C] 1 is a cross-sectional view depicting an exemplary embodiment of an applicator during a deployment stage. [Figure 13D] 1 is a cross-sectional view depicting an exemplary embodiment of an applicator during a deployment stage. [Figure 13E] 1 is a cross-sectional view depicting an exemplary embodiment of an applicator during a deployment stage. [Figure 13F] 1 is a cross-sectional view depicting an exemplary embodiment of an applicator during a deployment stage. [Figure 14] 1 is a graph depicting an example of in vitro sensitivity of an analyte sensor. [Figure 15] 1A-1C illustrate exemplary operational states of a sensor according to an illustrative embodiment of the presently disclosed subject matter. [Figure 16] 10A-10D illustrate exemplary operational and data flows for wireless programming of a sensor in accordance with the subject matter of the present disclosure. [Figure 17] FIG. 2 illustrates an exemplary data flow for secure data exchange between two devices in accordance with the subject matter of the present disclosure. [Figure 18] FIG. 1 illustrates the data flow between various components of an exemplary analyte monitor system in accordance with the technology described herein. [Figure 19]FIG. 1 illustrates an exemplary method for providing notification of no available communication channel between devices in an analyte monitoring system in accordance with certain embodiments. [Figure 20A] FIG. 1 illustrates an exemplary method for determining the availability of a communication channel between devices in an analyte monitoring system in accordance with certain embodiments. [Figure 20B] FIG. 1 illustrates an exemplary method for determining the availability of a communication channel between devices in an analyte monitoring system in accordance with certain embodiments. [Figure 21] FIG. 1 illustrates an exemplary method for providing notification of no available communication channel between devices in an analyte monitoring system in accordance with certain embodiments. [Figure 22] FIG. 1 illustrates an exemplary method for providing notification of no available communication channel between devices in an analyte monitoring system in accordance with certain embodiments. [Figure 23] FIG. 2 illustrates an exemplary user interface of an application executed in accordance with certain embodiments. [Figure 24] FIG. 2 illustrates an exemplary user interface of an application executed in accordance with certain embodiments. [Figure 25] FIG. 2 illustrates an exemplary user interface of an application executed in accordance with certain embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0024] Reference will now be made in detail to various illustrative embodiments of the presently disclosed subject matter, which are illustrated in the accompanying drawings.
[0025] Before describing the present subject matter in detail, it is to be understood that the present disclosure is not limited to particular embodiments described, as such can, of course, vary. It is also to be understood that the terminology used herein is for the purpose of describing particular embodiments only, since the scope of the present disclosure is not to be limited except as by the appended claims.
[0026] As used in this specification and claims, the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise.
[0027] The documents discussed herein are provided solely for their disclosure prior to the filing date of the present application. Nothing herein should be construed as an admission that the present disclosure is not entitled to antedate such document by virtue of prior disclosure. Further, the dates of the documents provided may be different from the actual publication dates, which may need to be independently confirmed.
[0028] Generally, embodiments of the present disclosure include systems, devices, and methods for the use of analyte sensors for use in in-vivo analyte monitoring systems. Many embodiments include an in-vivo analyte sensor that is structurally configured such that at least a portion of the sensor is or can be positioned on a user's body to obtain information related to at least one analyte in the body. However, it should be noted that the embodiments disclosed herein can be used with in-vivo analyte monitoring systems that incorporate extracorporeal functionality, as well as purely extracorporeal or ex vivo analyte monitoring systems, including completely non-invasive systems.
[0029] The applicator can be provided to the user in a sterile package with at least the electronics housing of the sensor control device enclosed therein. According to some embodiments, a structure such as a container separate from the applicator can also be provided to the user as a sterile package with the sensor module and sharps module enclosed therein. To add a sensor, the user can couple the sensor module to the electronics housing and couple the sharps to the applicator through an assembly process that includes inserting the applicator into the container in a specified manner. In other embodiments, the applicator, sensor control device, sensor module, and sharps module can be provided in a single package. The applicator can be used to position the sensor control device on the human body with the sensor in contact with the wearer's bodily fluids.
[0030] Additionally, many embodiments include in-vivo analyte sensors that are structurally configured such that at least a portion of the sensor is or can be positioned on the body of a user to obtain information related to at least one analyte in the body. However, it should be noted that the embodiments disclosed herein can be used with in-vivo analyte monitoring systems that incorporate extracorporeal functionality, as well as purely extracorporeal or ex vivo analyte monitoring systems, including completely non-invasive systems.
[0031] For each and every embodiment of the methods disclosed herein, systems and devices capable of performing each of these embodiments are encompassed within the scope of the present disclosure. For example, sensor control device embodiments are disclosed, and these devices can include one or more sensors, analyte monitor circuitry (e.g., analog circuitry), memory (e.g., for storing instructions), power sources, communication circuitry, transmitters, receivers, processors, and / or controllers (e.g., for executing instructions) that can perform or facilitate the performance of any and all method steps. These sensor control device embodiments can be used to, and can be capable of, performing steps performed by the sensor control device from any and all of the methods described herein.
[0032] Additionally, the systems and methods presented herein can be used in conjunction with the operation of sensors used in analyte monitoring systems, such as, but not limited to, for purposes related to fitness, diet, research, information, or any purpose related to analyte sensing over time. As used herein, "sensor" can refer to any device capable of accepting sensor information from a user, including, by way of example only, a temperature sensor, a blood pressure sensor, a pulse or heart rate sensor, a glucose level sensor, an analyte sensor, a physical activity sensor, a body movement sensor, or any other sensor for collecting physical or biometric information. Analytes measured by an analyte sensor can include, by way of example only, glucose, ketones, lactate, oxygen, hemoglobin A1C, albumin, alcohol, alkaline phosphatase, alanine transaminase, aspartate aminotransferase, bilirubin, blood urea nitrogen, calcium, carbon dioxide, chloride, creatinine, hematocrit, lactate, magnesium, oxygen, pH, phosphorus, potassium, sodium, total protein, uric acid, etc.
[0033] However, before describing the above aspects of the embodiments in detail, it is desirable to first describe examples of devices and their operation that may be present, for example, in an in vivo analyte monitor system, all of which may be used in conjunction with the embodiments described herein.
[0034] Various types of in-vivo analyte monitor systems exist. A "continuous analyte monitor" system (or "continuous glucose monitor" system), for example, can transmit data continuously, e.g., automatically according to a schedule, from the sensor control device to the reader device without requiring acknowledgment. As another example, an "intermittent analyte monitor" system (or "intermittent glucose monitor" system or simply "intermittent" system) can relay data from the sensor control device using a near-field communication (NFC) protocol or a radio frequency identification (RFID) protocol, etc., upon scanning by the reader device or data as needed. An in-vivo analyte monitor system can operate without the need for fingerstick calibration.
[0035] In vivo analyte monitor systems can be distinguished from "ex vivo" systems, which generally include a measurement device that contacts a biological sample outside the body (or "ex vivo") and has a port for accepting an analyte test strip that carries a user's bodily fluid and can be analyzed to determine the user's blood glucose level.
[0036] An in-vivo monitoring system may include a sensor that contacts a user's bodily fluid while placed in vivo and senses the analyte level contained therein. The sensor may be part of a sensor control device that resides on the user's body, the sensor control device including the electronics and power source that enable and control the analyte sensing. Sensor control devices and variations thereof may be referred to as "sensor control units," "on-body electronics" devices or units, "on-body" devices or units, or "sensor data communication" devices or units, to name a few.
[0037] The in-vivo monitoring system may also include a data receiving device that accepts sensed analyte data from the sensor controlling device and processes and / or displays it to a user in any number of forms. This device and variations thereof may be referred to as a "handheld reader device," "reader device," (or simply "reader"), "handheld electronic device" (or simply "handheld"), "portable data processing" device or "portable data processing" unit, "data receiver," "receiver" device or "receiver" unit (or simply "receiver"), or "remote" device or "remote" unit, to name a few. Other devices, such as personal computers, have also been used in or incorporated into in-vivo or ex-vivo monitoring systems. The data receiving device may be further configured to provide the sensed analyte data received from the sensor controlling device to a remote application server associated with the analyte monitoring system. The remote application server(s) may perform further analysis of the data. Additionally, with user permission, the remote application server may be configured to distribute the analyte data or other information derived therefrom to one or more other devices, which may be referred to as "data monitoring devices."
[0038] FIG. 1A is a conceptual diagram illustrating an exemplary embodiment of an analyte monitoring system 100 including a sensor applicator 150, a sensor control device 102, and a data receiving device 120. Here, the sensor applicator 150 can be used to deliver the sensor control device 102 to a monitoring location on a user's skin, where the sensor 104 is held stationary for a period of time by an adhesive patch 105. The sensor control device 102, described in more detail in FIGS. 2B and 2C, can communicate with the data receiving device 120 through a communication path 140 using wired or wireless technology. Exemplary wireless protocols include Bluetooth, Bluetooth Low Energy (such as BLE, BTLE, or Bluetooth Smart), Near Field Communication (NFC), and others. A user can monitor applications installed in memory on the data receiving device 120 using a screen 122 and input 121, and can recharge the device's battery using a power port 123. Further details regarding the data receiving device 120 are revealed below in FIG. 2A. Data receiving device 120 can communicate with local computer system 170 over communication path 141 using wired or wireless technologies. Local computer system 170 can include one or more of a laptop, desktop, tablet, phablet, smart phone, set-top box, video game console, or other computing device, and the wireless communication can include any of several applicable wireless network connection protocols, including Bluetooth, Bluetooth Low Energy (BTLE), Wi-Fi, or others. Local computer system 170 can communicate with network 190 over communication path 143 using wired or wireless technologies as described above in a manner similar to the manner in which data receiving device 120 can communicate with network 190 over communication path 142.Network 190 can be any of several networks, such as private and public networks, local area networks or wide area networks, etc. Trusted computer system 180 can include a server, can provide authentication services and secure data storage, and can communicate with network 190 through communication path 144 using wired or wireless technologies.
[0039] FIG. 1B illustrates another exemplary embodiment of an operating environment for an analyte monitoring system 100 capable of embodying the techniques described herein. As shown, the analyte monitoring system 100 can include a system of components designed to provide monitoring of a parameter, such as an analyte level, in a human or animal body, or can enable other operations based on the configuration of the various components. As embodied herein, the system can include a low-power sensor control device 102 worn by a user or attached to the body from which information is being collected. As embodied herein, the sensor control device 102 can be a sealed, disposable device having a predetermined useful lifespan (e.g., about 1 day, about 14 days, about 30 days, etc.). The sensor control device 102 can be applied to the skin of a user's body and can remain adhered for the duration of the sensor lifespan, or can be designed to remain functional when selectively detached and reapplied. The sample monitor system 100 may further include a data reading device 120 or a general-purpose hardware device 130 configured as described herein to facilitate the retrieval and transmission of data, including sample data, from the sensor control device 102.
[0040] The sensor control device 102 can communicate with the data receiving device 120 or the multipurpose hardware device 130 using wired or wireless technology. Exemplary wireless protocols include Bluetooth, Bluetooth Low Energy (such as BLE, BTLE, or Bluetooth Smart), Near Field Communication (NFC), and others. The data receiving device 120 can communicate with the multipurpose hardware device 130 or another user device 140 using wired or wireless technology. The user device 140 can include one or more of a laptop, desktop, tablet, phablet, smart phone, set-top box, video game console, or other computing device, and the wireless communication can include any of several applicable wireless network connection protocols, including Bluetooth, Bluetooth Low Energy (BTLE), Wi-Fi, or others. The user computing device 140 can communicate with a network in the same manner as the data receiving device 120 can communicate via wired or wireless technology, as described above. The general-purpose hardware device 130 and the user device 140 can communicate with a remote application server 155 to provide data such as analyte data from the sensor control device 102, identification data from the sensor control device 102 or the transmitting device, and derived data based on the analyte data. Conversely, as described herein, the remote application server 155 can communicate certain data with the data monitor device 135 according to permissions and instructions set by or on behalf of a user. The data monitor device 135 is described in detail herein.
[0041] As embodied herein, the analyte monitoring system 100 may include software or firmware libraries or applications provided by a third party, for example, through a remote application server 155, and embedded into a multipurpose hardware device 130, such as a mobile phone, tablet, personal computing device, or other similar computing device capable of communicating with the sensor control device 102 through a communications link. The multipurpose hardware may further include embedded devices, including, but not limited to, an insulin pump or insulin pen, having an embedded library configured to communicate with the sensor control device 102. While the illustrated embodiment of the analyte monitoring system 100 includes only one of each of the illustrated devices, the present disclosure contemplates that the analyte monitoring system 100 may incorporate multiple respective components through which it interacts. For example, and without limitation, as embodied herein, the data receiving device 120 and / or the multipurpose hardware device 130 may include multiple of each. As embodied herein, the multipurpose hardware device 130 may communicate directly with the sensor control device 102 as described herein. Additionally or alternatively, the data receiving device 120 may communicate with an auxiliary data receiving device 130 to provide the specimen data or a visual representation or analytical results thereof for auxiliary display to the user or other authorized party.
[0042] The analyte monitor system 100 may further include software or firmware libraries or applications provided through a remote application server 155 to other general-purpose hardware devices that do not receive data directly from the sensor control device 102, for example. These data monitor devices 135 instead receive data originating from the sensor control device 102 through the remote application service 155 or other related services. In certain embodiments, the software libraries or applications provided for the data monitor devices 135 are the same applications as those provided for the general-purpose device 130, but used in different contexts. In certain embodiments, these applications are separate applications used only for their intended purpose.
[0043] 2A is a block diagram illustrating an exemplary embodiment of a data receiving device 120 configured as a smart phone. In this case, the data receiving device 120 may include a display 122, input components 121, a processing core 206 including a communication processor 222 coupled to memory 223, and an application processor 224 coupled to memory 225. Also included may be a separate memory 230, an RF transceiver 228 having an antenna 229, and a power supply 226 having a power management module 238. Additionally, a multi-function transceiver 232 capable of communicating via Wi-Fi, NFC, Bluetooth, BTLE, and GPS using an antenna 234 may be included. As will be appreciated by those skilled in the art, these components are electrically and communicatively coupled to create a functional device.
[0044] The data receiving device 120 may be, for example, a mobile communication device such as a Wi-Fi or Internet-enabled smart phone, tablet, or personal digital assistant (PDA). Examples of smart phones may include, but are not limited to, phones based on various commercially available operating systems that have data network connectivity for data communication over an Internet connection and / or a local area network (LAN).
[0045] The data receiving device 120 can be configured as a mobile smart wearable electronics assembly, such as an optical assembly (e.g., a smart monocular or smart glasses) worn on or adjacent to a user's eyes. The optical assembly can have a transparent display that displays information related to the user's analyte level (as described herein) to the user while allowing the user to see through the display with minimal obstruction to the user's overall vision. The optical assembly can have wireless communication capabilities akin to a smart phone. Other examples of wearable electronics include devices worn on or around a user's wrist (e.g., like a smart watch), devices worn on or around the neck (e.g., like a necklace), devices worn on or around the head (e.g., like a headband, hat), devices worn on or around the chest, etc.
[0046] For purposes of illustration and not limitation, see another exemplary embodiment 120 of a data receiving device for use with the subject matter of the present disclosure, shown in FIG. 2B . The data receiving device 120 and associated general-purpose data receiving device 130 include components germane to the discussion of the sensor control device 102 and its operation, and may include additional components. In certain embodiments, the data receiving device 120 and general-purpose data receiving device 130 may be or include components provided by third parties, and are not necessarily limited to including devices manufactured by the same manufacturer as the sensor control device 102.
[0047] 2B , the data receiving device 120 includes an ASIC 4000 that includes a microcontroller 4010 communicatively coupled to a communication module 4040, a memory 4020, and storage 4030. Power for the components of the data receiving device 120 can be delivered by a power module 4050, which can include a rechargeable battery as specifically shown herein. The data receiving device 120 can further include a display 4070 to facilitate review of analyte data received from the sensor control device 102 or other devices (e.g., a user device 145 or a remote application server 155). The data receiving device 120 can include separate user interface components (e.g., physical keys, a light sensor, a microphone, etc.).
[0048] The communication module 4040 may include a BLE module 4041 and an NFC module 4042. The data receiving device 120 may be configured to wirelessly couple with the sensor control device 102 and to send commands to and receive data from the sensor control device 102. As embodied herein, the data receiving device 120 may be configured to operate as an NFC scanner and a BLE endpoint through a particular module of the communication module 4040 (e.g., the BLE module 4042 or the NFC module 4043) with respect to the sensor control device 102 described herein. For example, the data receiving device 120 may use a first module of the communication module 4040 to issue commands to the sensor control device 102 (e.g., an activation command for a data broadcast mode of the sensor, a pairing command for identifying the data receiving device 120), and may use a second module of the communication module 4040 to send and receive data to and from the sensor control device 102. The data receiving device 120 may be configured for communication with the user device 145 through a universal serial bus (USB) module 4045 of the communication module 4040 .
[0049] As another example, the communications module 4040 may include, for example, a cellular radio module 4044. The cellular radio module 4044 may include one or more radio transceivers for communicating using wideband cellular networks, including, but not limited to, third-generation (3G), fourth-generation (4G), and fifth-generation (5G) networks. Additionally, the communications module 4040 of the data receiving device 120 may include a Wi-Fi radio module 4043 for communicating using wireless local area networks according to one or more of the “IEEE 802.11” standards (e.g., 802.11a, 802.11b, 802.11g, 802.11n (aka Wi-Fi 4), 802.11ac (aka Wi-Fi 5), and 802.11ax (aka Wi-Fi 6)). Using the cellular wireless module 4044 or the Wi-Fi wireless module 4043, the data receiving device 120 can communicate with a remote application server 155 to receive analyte data or provide updates or input received from a user. Although not illustrated, the communication module 5040 of the analyte sensor 120 can also include a cellular wireless module or a Wi-Fi wireless module.
[0050] As embodied herein, the on-board storage 4030 of the data receiving device 120 can store analyte data received from the sensor control device 102. Furthermore, the data receiving device 120, the general-purpose data receiving device 130, or the user device 145 can be configured to communicate with a remote application server 155 over a wide area network. As embodied herein, the sensor control device 102 can provide data to the data receiving device 120 or the general-purpose data receiving device 130. The data receiving device 120 can transmit these data to the user computing device 145. Furthermore, the user computing device 145 (or the general-purpose data receiving device 130) can transmit these data to the remote application server 155 for processing and analysis.
[0051] As embodied herein, the data receiving device 120 may further include sensing hardware 4060 similar to or enhanced from the sensing hardware 5060 of the sensor control device 102. In particular embodiments, the data receiving device 120 may be configured to interface with the sensor control device 102 and act based on analyte data received therefrom. As an example, if the sensor control device 102 is a glucose sensor, the data receiving device 120 may be or include an insulin pump or an insulin injection pen. In cooperation, the compatible device 130 may adjust insulin dosages for the user based on glucose values received from the analyte sensor.
[0052] 2C and 2D are block diagrams illustrating an exemplary embodiment of a sensor control device 102 having an analyte sensor 104 and sensor electronics 160, which may contain most of the processing functionality for rendering final result data suitable for display to a user. FIG. 2C shows a single semiconductor chip 161, which may be a custom application-specific integrated circuit (ASIC). Within the ASIC 161, certain high-level functional units are shown, including an analog front-end (AFE) 162, a power management (or control) circuit 164, a processor 166, and a communications circuit 168 (which may be implemented as a transmitter, receiver, transceiver, passive circuitry, or other communications protocol). In this embodiment, both the AFE 162 and the processor 166 are used as analyte monitoring circuitry, although in other embodiments, either circuitry may perform the analyte monitoring function. The processor 166 may include one or more processors, microprocessors, controllers, and / or microcontrollers, each of which may be a separate chip or distributed among (and be part of) several different chips.
[0053] Also included within the ASIC 161 is memory 163, which may be shared by the various functional units present within the ASIC 161 or distributed among two or more of these functional units. The memory 163 may be a separate chip. The memory 163 may be volatile and / or non-volatile memory. In this embodiment, the ASIC 161 is coupled to a power source 172, which may be a coin cell battery or the like. The AFE 162 interconnects with the in-vivo analyte sensor 104 to accept measurement data therefrom and output these data in digital form to the processor 166, which further processes these data to provide final resultant glucose individual values and glucose trend values, etc. These data may then be provided to the communications circuitry 168 via the antenna 171 for transmission to, for example, the data receiving device 120 (not shown), where little further processing by a resident software application is required to display the data.
[0054] FIG. 2D is similar to FIG. 2C but includes two separate semiconductor chips 162 and 174, which can be packaged together or separately. In this case, AFE 162 resides on ASIC 161. Processor 166 is integrated with power management circuitry 164 and communications circuitry 168 on chip 174. AFE 162 includes memory 163, and chip 174 includes memory 165, which can be isolated or distributed within it. In one exemplary embodiment, AFE 162 is combined with power management circuitry 164 and processor 166 on one chip, while communications circuitry 168 is on a separate chip. In another exemplary embodiment, both AFE 162 and communications circuitry 168 are on one chip, and processor 166 and power management circuitry 164 are on another chip. It should be noted that other chip combinations are possible, including three or more chips, each performing a separate function as described, or sharing one or more functions to achieve fail-safe redundancy.
[0055] For purposes of illustration and not limitation, FIG. 2E depicts another exemplary embodiment of a sensor control device 102 that supports the security architecture and communication schemes described herein.
[0056] As embodied herein, the sensor control device 102 may include an application specific integrated circuit ("ASIC") 5000 communicatively coupled to a communications module 5040. The ASIC 5000 may include a microcontroller core 5010, an on-board memory 5020, and a storage memory 5030. The storage memory 5030 may store data used for authentication and encryption security architectures. The storage memory 5030 may store programming instructions for the sensor control device 102. As embodied herein, a communications chipset (e.g., an NFC transceiver 5025) may be embedded within the ASIC 5000. The ASIC 5000 may receive power from a power module 5050, such as an on-board battery, or from an NFC pulse. The storage memory 5030 of the ASIC 5000 may be programmed to include information such as an identifier for the sensor control device 102 for identification and tracking purposes. The storage memory 5030 can be programmed with configuration or calibration parameters used by the sensor control device 102 and its various components. The storage memory 5030 can include rewritable memory or one-time programming (OTP) memory. The storage memory 5030 can be updated using techniques described herein to extend the usefulness of the sensor control device 102.
[0057] As embodied herein, the communication module 5040 of the sensor control device 102 may be or include one or more modules for supporting communication with other devices in the analyte monitoring system 100. By way of example only and not limitation, the exemplary communication module 5040 may include a Bluetooth Low Energy (“BLE”) module 5041, which is used throughout this disclosure to refer to a short-range communication protocol optimized for easy Bluetooth device pairing for end users. The communication module 5040 may transmit and receive data and instructions by interacting with a similarly capable communication module in the data receiving device 120 or user device 145. The communication module 5040 may include additional or alternative chipsets suitable for use with similar short-range communication techniques, such as, for example, the “IEEE 802.”15 protocol, personal area networks according to the “IEEE 802.”11 protocol, or infrared communication according to the Infrared Data Association (IrDA) standard.
[0058] To perform its functions, the sensor control device 102 may further include sensing hardware 5060 appropriate for those functions. As embodied herein, the sensing hardware 5060 may include an analyte sensor placed transcutaneously or subcutaneously in contact with the subject's bodily fluid. The analyte sensor may generate sensor data containing values corresponding to one or more analyte levels in the bodily fluid.
[0059] The components of the sensor control device 102 may be acquired by the user in multiple packages that require final assembly by the user before delivery to the appropriate user location. Figures 3A-3D depict an example embodiment of a user assembly process for the sensor control device 102, including preparation of the separate components before combining them to provide the sensor for delivery. Figures 3E-3F depict an example embodiment of delivery of the device 102 to the appropriate user location by selecting an appropriate delivery location and applying the sensor control device 102 to this location.
[0060] 3A is a close-up perspective view depicting an exemplary embodiment in which a user provides a container 810, in this case configured as a tray for the assembly process (although other packaging can be used). The user can accomplish this preparation by removing the lid 812 from the tray 810 to expose the platform 808, for example, by peeling the non-adhered portion of the lid 812 from the tray 810 so that the adhered portion of the lid 812 is removed. Removal of the lid 812 can be suitable in various embodiments as long as the platform 808 is sufficiently exposed within the tray 810. The lid 812 can then be set aside.
[0061] 3B is a side view depicting an exemplary embodiment in which a user prepares applicator device 150 for assembly. Applicator device 150 may be provided in a sterile package sealed by applicator cap 708. Preparing applicator device 150 may include disconnecting housing 702 from applicator cap 708 to expose sheath 704 (FIG. 3C). This disconnection may be accomplished by twisting (or otherwise detaching) applicator cap 708 from housing 702. Applicator cap 708 may be set aside.
[0062] 3C is a close-up perspective view depicting an exemplary embodiment in which a user inserts applicator device 150 into tray 810 during assembly. First, a user can insert sheath 704 into platform 808 inside tray 810 after aligning housing orientation feature 1302 (or slot or recess) with tray orientation feature 924 (abutment or detent). Inserting sheath 704 into platform 808 temporarily unlocks sheath 704 from housing 702, which also temporarily unlocks platform 808 from tray 810. At this stage, removal of applicator device 150 from tray 810 will result in the same condition as before the initial insertion of applicator device 150 into tray 810 (i.e., the process can be reversed or interrupted at this point and repeated without further ramifications).
[0063] During distal advancement of housing 702, sheath 704 maintains its position relative to housing 702 within platform 808 and can couple with platform 808 to advance platform 808 distally relative to tray 810. This step unlocks and collapses platform 808 within tray 810. Sheath 704 contacts and disengages a locking mechanism (not shown) within tray 810, thereby unlocking sheath 704 from housing 702 and preventing it from moving (relatively) while housing 702 distally advances platform 808. At the end of advancement of housing 702 and platform 808, sheath 704 is permanently unlocked from housing 702. At the end of distal advancement of housing 702, a sharp and sensor (not shown) within tray 810 can couple with an electronics housing (not shown) within housing 702. The operation and interaction of applicator device 150 and tray 810 is described in further detail below.
[0064] 3D is a close-up perspective view depicting an exemplary embodiment in which a user removes applicator device 150 from tray 810 during assembly. A user can remove applicator 150 from tray 810 by advancing housing 702 proximally relative to tray 810 or other movement that has the same end effect as decoupling applicator 150 and tray 810. Applicator device 150 is removed with sensor control device 102 (sharp, sensor, electronics) (not shown) fully assembled therein and positioned for delivery.
[0065] 3E is a close-up perspective view depicting an exemplary embodiment in which a patient uses applicator device 150 to apply sensor control device 102 to a target area of skin, for example, on the abdomen or other suitable location. Advancing housing 702 collapses sheath 704 distally therein, applying the sensor to the target location such that the adhesive layer on the bottom surface of sensor control device 102 adheres to the skin. The sharps automatically retract when housing 702 is fully advanced, while the sensor (not shown) is left in place to measure the analyte level.
[0066] 3F is a close-up perspective view depicting an exemplary embodiment of a patient with the sensor control device 102 in application position. The user can then remove the applicator 150 from the application site.
[0067] 3A-3F and described elsewhere herein can reduce or eliminate the possibility of accidental damage, permanent deformation, or incorrect assembly of applicator components compared to prior art systems. Because the applicator housing 702 directly engages the platform 808 rather than indirectly engaging through the sheath 704 while the sheath 704 is unlocked, the relative angle between the sheath 704 and the housing 702 does not result in damage or permanent deformation of the arms or other components. The potential for relatively high forces during assembly (as in conventional devices) is reduced, thereby reducing the likelihood of user assembly failure.
[0068] Figure 4A is a side view depicting an exemplary embodiment of applicator device 150 coupled to a screw applicator cap 708. This view is an example of how applicator 150 may be shipped and received by a user prior to assembly with a sensor by the user. Figure 4B is a side perspective view depicting applicator 150 and applicator cap 708 after they have been separated. Figure 4C is a perspective view depicting an exemplary embodiment of the distal end of applicator device 150 with electronics housing 706 and adhesive patch 105 removed from the positions they would have maintained within sensor carrier 710 of sheath 704 when applicator cap 708 was in place.
[0069] 4D-4G, for purposes of illustration and not limitation, another exemplary embodiment of an applicator device 20150 can be provided to a user as a single integrated assembly. FIGS. 4D and 4E provide perspective top and bottom views, respectively, of the applicator device 20150, FIG. 4F provides an exploded view of the applicator device 20150, and FIG. 4G provides a side cutaway view. These perspective views illustrate how the applicator 20150 is shipped and received by a user. The exploded and cutaway views illustrate the components of the applicator device 20150. The applicator device 20150 can include a housing 20702, a gasket 20701, a sheath 20704, a sharps carrier 201102, a spring 205612, a sensor carrier 20710 (also referred to as a "puck carrier"), a sharps hub 205014, a sensor control device (also referred to as a "puck") 20102, an adhesive patch 20105, a desiccant 20502, an applicator cap 20708, a serial label 20709, and an untampering feature 20712. In some embodiments, only the housing 20702, the applicator cap 20708, the untampering feature 20712, and the label 20709 are visible to a user upon receipt. The tamper-evident feature 20712 may be, for example, a sticker coupled to each of the housing 20702 and the applicator cap 20708, and may be, for example, irreparably damaged by separating the housing 20702 and the applicator cap 20708, thereby indicating to the user that the housing 20702 and the applicator cap 20708 have previously been separated. These features are described in more detail below.
[0070] FIG. 5 shows an exemplary embodiment of a tray 810 with a sterilization lid 812 removably coupled thereto, in a close-up perspective view that may represent how the package is shipped to a user and how it is received by the user prior to assembly.
[0071] 6A is a close-up perspective cutaway view depicting the sensor delivery components within a tray 810. A platform 808 is slidably coupled within the tray 810. A desiccant 502 is fixed relative to the tray 810. A sensor module 504 is mounted within the tray 810.
[0072] 6B is a close-up perspective view depicting the sensor module 504 in greater detail, where the retention arm extensions 1834 of the platform 808 releasably secure the sensor module 504 in place. The module 2200 is coupled with the connector 2300, the sharp module 2500, and the sensor (not shown), allowing them to be detached from one another as the sensor module 504 during assembly.
[0073] 1A and 3A-3G , in a two-piece architecture system, the sensor tray 810 and the sensor applicator 150 are provided to the user in separate packages, thus requiring the user to unpack each package and ultimately assemble the system. In some applications, these separate, sealed packages allow the sensor tray 810 and the sensor applicator 150 to be sterilized in separate sterilization processes that are unique to the contents of each package and incompatible with the contents of the other. More specifically, the sensor tray 810, including the plug assembly 207, including the sensors 104 and the sharps 220, can be sterilized using radiation sterilization, such as electron beam (or “e-beam”) illumination. Suitable radiation sterilization processes include, but are not limited to, electron beam (e-beam) illumination, gamma ray illumination, x-ray illumination, or any combination thereof. However, radiation sterilization may damage electrical components located within the electronics housing of the sensor control device 102. As a result, if the sensor applicator 150, including the electronics housing of the sensor control device 102, needs to be sterilized, it can be sterilized by another method, such as gas chemical sterilization using, for example, ethylene oxide. However, gas chemical sterilization may destroy enzymes or other chemical and biological agents contained on the sensors 104. Due to this sterilization incompatibility, the sensor tray 810 and the sensor applicator 150 are typically sterilized in separate sterilization processes and then packaged separately, thereby requiring the user to ultimately assemble the components for use.
[0074] 7A and 7B are exploded top and bottom views, respectively, of a sensor control device 3702 in accordance with one or more embodiments. The shell 5006 and mount 5008 act as opposing clamshell halves that enclose or otherwise substantially encapsulate the various electronic components of the sensor control device 3702. As shown, the sensor control device 3702 may include a printed circuit board assembly (PCBA) 3802 that includes a printed circuit board (PCB) 3804 having a plurality of electronic modules 3806 coupled thereto. Exemplary electronic modules 3806 include, but are not limited to, resistors, transistors, capacitors, inductors, diodes, and switches. Conventional sensor control devices typically stack PCB components on only one side of the PCB. In contrast, the PCB components 3806 in the sensor control device 3702 may be distributed around the surface area of both sides (i.e., the top and bottom) of the PCB 3804.
[0075] In addition to the electronics module 3806, the PCBA 3802 may further include a data processing unit 3808 mounted on the PCB 3804. The data processing unit 3808 may include, for example, an application specific integrated circuit (ASIC) configured to perform one or more functions or routines related to the operation of the sensor control device 3702. More specifically, the data processing unit 3808 may be configured to perform data processing functions, where such functions may include, but are not limited to, filtering and encoding multiple data signals each corresponding to a sampled analyte level of a user. The data processing unit 3808 may further include or otherwise be in communication with an antenna for communicating with the reader device 106.
[0076] A battery opening 3810 can be defined within the PCB 3804 and sized to receive and seat a battery 3812 configured to power the sensor control device 3702. An axial battery contact 3814a and a radial battery contact 3814b can be coupled to the PCB 3804 and can extend into the battery opening 3810 to facilitate the transfer of power from the battery 3812 to the PCB 3804. As the names suggest, the axial battery contact 3814a can be configured to provide axial contact to the battery 3812, while the radial battery contact 3814b can provide radial contact to the battery 3812. Positioning the battery 3812 within the battery opening 3810 with the battery contacts 3814a, 3814b helps reduce the height H of the sensor control device 3702, thereby allowing the PCB 3804 to be centered and its components to be distributed on both sides (i.e., the top and bottom). This also helps facilitate providing a chamfer 3718 on the electronics housing 3704 .
[0077] The sensor 3716 may be centrally positioned with respect to the PCB 3804 and may include a tail 3816, a flag 3818, and a neck 3820 interconnecting the tail 3816 and the flag 3818. The tail 3816 may extend through a central opening 3720 in the mount 3708 and be configured to be transcutaneously received under the skin of a user. Additionally, the tail 3816 may have an enzyme or other chemical agent included thereon to help facilitate the analyte monitor.
[0078] The flag 3818 may include a generally flat surface having one or more sensor contacts 3822 (three shown in FIG. 7B ) disposed thereon. The sensor contacts 3822 may be configured to align with and engage one or more corresponding circuit contacts 3824 (three shown in FIG. 7A ) provided on the PCB 3804. In some embodiments, the sensor contacts 3822 may include a carbon-impregnated polymer printed or otherwise digitally applied to the flag 3818. Conventional sensor control devices typically include a connector fabricated from silicone rubber encapsulating one or more flexible carbon-impregnated polymer modules that serve as conductive contacts between the sensor and the PCB. In contrast, the sensor contacts 3822 of the present disclosure provide a direct connection between the sensor 3716 and the PCB 3804, thereby eliminating the need for prior art connectors and advantageously reducing the height H. Furthermore, the elimination of the flexible carbon-impregnated polymer modules eliminates significant circuit resistance, thus improving circuit conductivity.
[0079] The sensor control device 3702 may further include a flexible member 3826 that may be positioned to be sandwiched between the flag 3818 and the inner surface of the shell 3706. More specifically, when the shell 3706 and the mount 3708 are assembled together, the flexible member 3826 may be configured to provide a passive biasing load against the flag 3818 that urges the sensor contacts 3822 into continuous engagement with the corresponding circuit contacts 3824. In the illustrated embodiment, the flexible member 3826 is a resilient O-ring, but it is contemplated that the flexible member 3826 may alternatively include any other type of biasing device or feature, such as a compression spring, without departing from the scope of the present disclosure.
[0080] The sensor control device 3702 may further include one or more electromagnetic shields, shown as a first shield 3828a and a second shield. The shell 3706 may provide or otherwise define a first orientation determining receptacle 3830a (FIG. 7B) and a second orientation determining receptacle 3830b (FIG. 7B), and the mount 3708 may provide or otherwise define a first orientation determining post 3832a (FIG. 7A) and a second orientation determining post 3832b (FIG. 7A). The shell 3706 is properly aligned with the mount 3708 by mating the first and second orientation determining receptacles 3830a, 3830b with the first orientation determining posts 3832a, 3832b, respectively.
[0081] 7A , the inner surface of the mount 3708 can provide or otherwise define a plurality of pockets or recesses configured to receive various subcomponents of the sensor control device 3702 when the shell 3706 is mated to the mount 3708. For example, the inner surface of the mount 3708 can define a battery locator 3834 configured to receive a portion of the battery 3812 when the sensor control device 3702 is assembled. An adjacent contact pocket 3836 can be configured to receive a portion of the axial contact 3814a.
[0082] Additionally, a plurality of module pockets 3838 may be defined within the inner surface of the mount 3708 for receiving various electronic modules 3806 disposed on the bottom of the PCB 3804. Additionally, a shield locator 3840 may be defined within the inner surface of the mount 3708 for receiving at least a portion of the second shield 3828b when the sensor control device 3702 is assembled. The battery locator 3834, contact pocket 3836, module pocket 3838, and shield locator 3840 all extend a short distance into the inner surface of the mount 3708, thereby reducing the overall height H of the sensor control device 3702 as compared to conventional sensor control devices. The module pockets 3838 may help minimize the diameter of the PCB 3804 by allowing PCB components to be disposed on both sides (i.e., the top and bottom).
[0083] Continuing with reference to FIG. 7A , the mount 3708 can further include a plurality of carrier gripping features 3842 (two shown) defined interspersed about its periphery. The carrier gripping features 3842 are axially offset from a bottom 3844 of the mount 3708, at which a transfer adhesive (not shown) can be applied during assembly. In contrast to conventional sensor control devices that typically include conical carrier gripping features that intersect with the bottom of the mount, the carrier gripping features 3842 of the present disclosure are offset from this plane (i.e., bottom 3844), at which the transfer adhesive is applied. This can prove advantageous as it helps ensure that the delivery system does not inadvertently attach to the transfer adhesive during assembly. Furthermore, the carrier gripping features 3842 of the present disclosure eliminate the need for a scalloped transfer adhesive, thereby facilitating the manufacture of the transfer adhesive and eliminating the need to precisely orient the transfer adhesive relative to the mount 3708. This, in turn, increases the bonding area and, therefore, the bond strength.
[0084] 7B , the bottom 3844 of the mount 3708 may provide or otherwise define a plurality of grooves 3846 that may be defined at or near the periphery of the mount 3708 and spaced equidistant from one another. A transfer adhesive (not shown) may be bonded to the bottom 3844, and the grooves 3846 may be configured to aid in transporting moisture from the sensor control device 3702 around the mount 3708 during use. In some embodiments, the spacing of the grooves 3846 may be sandwiched between module pockets 3838 ( FIG. 7A ) defined on the opposite (inner) side of the mount 3708. As will be appreciated, alternating the locations of the grooves 3846 and the module pockets 3838 ensures that opposing features on opposite sides of the mount 3708 do not extend into one another. This may help maximize material utilization for the mount 3708, thereby helping to maintain a minimum height H of the sensor control device 3702. The module pocket 3838 can significantly reduce mold collapse and improve the flatness of the bottom 3844 to which the transfer adhesive adheres.
[0085] 7B , the inner surface of the shell 3706 can also provide or otherwise define a plurality of pockets or recesses configured to receive various subcomponents of the sensor control device 3702 when the shell 3706 is mated to the mount 3708. For example, the inner surface of the shell 3706 can define an opposing battery locator 3848 positionable opposite the battery locator 3834 ( FIG. 7A ) of the mount 3708 and configured to receive a portion of the battery 3812 when the sensor control device 3702 is assembled. The opposing battery locator 3848 extends a short distance into the inner surface of the shell 3706, which helps to reduce the overall height H of the sensor control device 3702.
[0086] A sharp and sensor locator 3852 may be provided by or otherwise defined on the inner surface of the shell 3706. The sharp and sensor locator 3852 may be configured to receive both a sharp (not shown) and a portion of the sensor 3716. Furthermore, the sharp and sensor locator 3852 may be configured to align and / or mate with a corresponding sharp and sensor locator 2054 ( FIG. 7A ) provided on the inner surface of the mount 3708.
[0087] 8A-8C illustrate alternative sensor assembly / electronics assembly connection techniques in accordance with embodiments of the present disclosure. As shown, the sensor assembly 14702 includes a sensor 14704, a connector support 14706, and a connector 14708. Among other things, a recess or receptacle 14710 can be defined within the bottom of the mount of the electronics assembly 14712, which can provide a location for receiving the sensor assembly 14702 and coupling it to the electronics assembly 14712, thereby fully assembling the sensor control device. The contours of the sensor assembly 14702 can be shaped in a manner that matches or is complementary to the receptacle 14710, which includes a resilient sealing member 14714 (including a conductive material that is coupled to a circuit board and aligns with the electrical contacts of the sensor 14704). 8C is formed when the sensor assembly 14702 is snapped or otherwise attached to the electronics assembly 14712 by pressing the sensor assembly 14702 into the recess 14710 integrally formed in the electronics assembly 14712. This embodiment provides an integrated connector for the sensor assembly 14702 within the electronics assembly 14712.
[0088] Additional information regarding sensor assemblies is provided in U.S. Patent Application Publication Nos. 2013 / 0150691 and 2021 / 0204841, the entire contents of each of which are incorporated herein by reference.
[0089] In accordance with embodiments of the present disclosure, the sensor control device 102 can be modified to provide a one-piece architecture that allows for the application of sterilization techniques specifically designed for the one-piece architecture sensor control device. The one-piece architecture allows the sensor applicator 150 and sensor control device 102 to be shipped to a user in a single, sealed package that does not require any final user assembly steps. In other words, the user need only unpack one package and then deliver the sensor control device 102 to the target monitoring location. The one-piece system architecture described herein can prove advantageous because it eliminates subcomponents, various fabrication process steps, and user assembly steps. This results in reduced packaging and waste, and mitigates user error or system contamination.
[0090] 9A and 9B are a side view and a cross-sectional side view, respectively, of an exemplary embodiment of sensor applicator 150 coupled with applicator cap 708. More specifically, FIG. 9A illustrates how sensor applicator 150 may be shipped to and received by a user, and FIG. 9B depicts sensor control device 4402 disposed within sensor applicator 150. These figures show that a fully assembled sensor control device 4402 is installed within already assembled sensor applicator 150 prior to delivery to the user, thus eliminating any additional assembly steps that the user may otherwise have to implement.
[0091] The fully assembled sensor control device 4402 can be loaded into the sensor applicator 150, and then the applicator cap 708 can be coupled to the sensor applicator 150. In some embodiments, the applicator cap 708 can be threaded onto the housing 702 and can include an unsealing ring 4702. When the applicator cap 708 is rotated (e.g., twisted off) relative to the housing 702, the unsealing ring 4702 is threaded off, thereby allowing the applicator cap 708 to be released from the sensor applicator 150.
[0092] In accordance with the present disclosure, the sensor control device 4402, while loaded into the sensor applicator 150, can be subjected to a gaseous chemical sterilization 4704 configured to sterilize its electronics housing 4404 and any other exposed portions. To effect this sterilization, chemicals can be injected into a sterilization chamber 4706 cooperatively defined by the sensor applicator 150 and the interconnected cap 210. In some applications, chemicals can be injected into the sterilization chamber 4706 through one or more vent ports 4708 defined in the applicator cap 708 at its proximal end 610. Exemplary chemicals that can be used for the gaseous chemical sterilization 4704 include, but are not limited to, ethylene oxide, hydrogen peroxide vapor, nitrogen oxides (such as, for example, nitrous oxide, nitrogen dioxide), and steam.
[0093] The distal portion of the sensor 4410 and the sharp 4412 are sealed within the sensor cap 4416 so that the chemicals used during the gas chemical sterilization process do not interact with the enzymes, chemical agents, or biological agents disposed on the tail 4524 and other sensor components, such as the membrane coating that regulates analyte inflow.
[0094] Once the desired level of sterility has been reached within the sterilization chamber 4706, the gas solution can be removed and the sterilization chamber 4706 can be aerated. Aeration can be achieved by a series of vacuums followed by circulating a gas (e.g., nitrogen) or sterile air through the gas sterilization chamber 4706. Once the sterilization chamber 4706 is properly aerated, the vent port 4708 can be blocked with a seal 4712 (shown in dashed lines).
[0095] In some embodiments, the seal 4712 may include two or more layers composed of different materials. The first layer may be made of a synthetic material (e.g., flash-spun high-density polyethylene fiber) such as Tyvek® available from DuPont®. Tyvek® is durable, puncture-resistant, and allows vapor transmission. The Tyvek® layer may be applied prior to the gas-chemical sterilization process, and following the gas-chemical sterilization process, a foil or other steam- and moisture-resistant material layer may be sealed (e.g., heat-fused) over the Tyvek® layer to prevent the ingress of contaminants and moisture into the sterilization chamber 4706. In other embodiments, the seal 4712 may include only a single protective layer applied to the applicator cap 708. In such embodiments, this single layer may be gas-permeable for the sterilization process but may provide protection against moisture and other harmful elements after the sterilization process is complete.
[0096] With the seal 4712 in place, the applicator cap 708 provides a barrier to external contamination, thereby maintaining a sterile environment for the assembled sensor control device 4402 until the user removes (unscrews) the applicator cap 708. The applicator cap 708 can create a dust-free environment that prevents the adhesive patch 4714 from becoming soiled during shipping and storage.
[0097] 10A and 10B are isometric and side views, respectively, of another exemplary sensor control device 5002 in accordance with one or more embodiments of the present disclosure. The sensor control device 5002 may be similar in some respects to the sensor control device 102 of FIG. 1A and may therefore be most clearly understood with reference thereto. Furthermore, the sensor control device 5002 may replace the sensor control device 102 of FIG. 1A and thus may be used in conjunction with the sensor applicator 150 of FIG. 1A, which may deliver the sensor control device 5002 to a target monitoring location on a user's skin.
[0098] 1A, the sensor control device 5002 may include a one-piece system architecture that does not require a user to unpack multiple packages and final assemble the sensor control device 5002 before application. In other words, upon receipt by the user, the sensor control device 5002 is already fully assembled and properly positioned within the sensor applicator 150 (FIG. 1A). To use the sensor control device 5002, the user need only open a single barrier (e.g., applicator cap 708 of FIG. 3B) for use, and then immediately deliver the sensor control device 5002 to the target monitoring location.
[0099] As shown, the sensor control device 5002 includes an electronics housing 5004 that is generally disc-shaped and may have a circular cross-section. However, in other embodiments, the electronics housing 5004 may exhibit other cross-sectional shapes, such as oval or polygonal, without departing from the scope of this disclosure. The electronics housing 5004 may be configured to house or otherwise contain various electrical components used to operate the sensor control device 5002. In at least one embodiment, an adhesive patch (not shown) may be disposed on the bottom of the electronics housing 5004. The adhesive patch may be similar to adhesive patch 105 of FIG. 1A and, therefore, may aid in adhering the sensor control device 5002 to a user's skin for use.
[0100] As shown, the sensor control device 5002 includes an electronics housing 5004 that includes a shell 5006 and a mateable mount 5008. The shell 5006 may be secured to the mount 5008 by a variety of techniques, such as a snap fit, an interference fit, sonic welding, one or more mechanical fasteners (e.g., screws), a gasket, an adhesive, or any combination thereof. In some cases, the shell 5006 may be secured to the mount 5008 such that a sealed interface is created between the shell 5006 and the mount 5008.
[0101] The sensor control device 5002 may further include a sensor 5010 (partially visible) and a sharp 5012 (partially visible) that is used to aid in transcutaneous delivery of the sensor 5010 beneath a user's skin during application of the sensor control device 5002. As shown, corresponding portions of the sensor 5010 and sharp 5012 extend distally from the bottom of the electronics housing 5004 (e.g., mount 5008). The sharp 5012 may include a sharp hub 5014 configured to securely support the sharp 5012. As seen most clearly in FIG. 10B , the sharp hub 5014 may include or otherwise define an engaging member 5016. To couple the sharp 5012 to the sensor control device 5002, the sharp 5012 may be advanced axially through the electronics housing 5004 until the sharp hub 5014 engages the top surface of the shell 5006 and the engaging member 5016 extends distally from the bottom of the mount 5008. When the sharp 5012 penetrates the electronics housing 5004, the exposed portion of the sensor 5010 can be received within the hollow or recessed (arcuate) portion of the sharp 5012. The remainder of the sensor 5010 is disposed within the electronics housing 5004.
[0102] The sensor control device 5002 may further include a sensor cap 5018, which is shown in FIGS. 10A-10B disassembled or detached from the electronics housing 5004. The sensor cap 5018 may be removably coupled to the sensor control device 5002 (e.g., the electronics housing 5004) at or near the bottom of the mount 5008. The sensor cap 5018 may help provide a hermetic barrier surrounding the exposed portions of the sensor 5010 and the sharps 5012 to protect them from gaseous chemical sterilization. As shown, the sensor cap 5018 may include a generally cylindrical body having a first end 5020a and an opposing second end 5020b. The first end 5020a may be open to provide access to an interior chamber 5022 defined within the body. In contrast, the second end 5020b may be closed and may provide or otherwise define an engagement feature 5024. As described herein, the engagement feature 5024 can assist in fitting the sensor cap 5018 to a cap (e.g., applicator cap 708 of FIG. 3B) of a sensor applicator (e.g., sensor applicator 150 of FIGS. 1 and 3A-3G) and can assist in removing the sensor cap 5018 from the sensor control device 5002 when the cap is removed from the sensor applicator 150.
[0103] The sensor cap 5018 can be removably coupled to the electronics housing 5004 at or near the bottom of the mount 5008. More specifically, the sensor cap 5018 can be removably coupled to a mating member 5016 that extends distally from the bottom of the mount 5008. In at least one embodiment, for example, the mating member 5016 can define a set of external threads 5026a ( FIG. 10B ) that can mate with a set of internal threads 5026b ( FIG. 10A ) defined by the sensor cap 5018. In some embodiments, the external and internal threads 5026a, 5026b can include a square thread design (e.g., lacking a helical curvature), which can prove advantageous for molding these parts. Alternatively, the external and internal threads 5026a, 5026b can include a helical threaded engagement. Thus, the sensor cap 5018 can be threadably coupled to the sensor control device 5002 at the mating member 5016 of the sharp hub 5014. In other embodiments, the sensor cap 5018 can be removably coupled to the mating member 5016 by other types of engagement, including, but not limited to, an interference fit or a friction fit or a frangible member or material that can be broken with a small separation force (e.g., axial or rotational force).
[0104] In some embodiments, the sensor cap 5018 may include a monolithic (single) structure extending between the first end 5020a and the second end 5020b. However, in other embodiments, the sensor cap 5018 may include two or more subcomponents. In the illustrated embodiment, for example, the sensor cap 5018 may include a sealing ring 5028 disposed at the first end 5020a and a desiccant cap 5030 disposed at the second end 5020b. The sealing ring 5028 may help seal the inner chamber 5022, as described in more detail below. In at least one embodiment, the sealing ring 5028 may include an elastomeric O-ring. The desiccant cap 5030 may store or include a desiccant that helps maintain a preferred humidity level within the inner chamber 5022. Additionally, the desiccant cap 5030 may define or otherwise provide an engagement feature 5024 for the sensor cap 5018.
[0105] 11A-11C are staged cross-sectional side views illustrating the assembly of a sensor applicator 150 and a sensor control device 5002 according to one or more embodiments. Once the sensor control device 5002 is fully assembled, it can be loaded into the sensor applicator 150. Referring to FIG. 11A, the sharps hub 5014 can include or otherwise define hub snap tabs 5302 configured to assist in coupling the sensor control device 5002 to the sensor applicator 150. More specifically, the sensor control device 5002 can be advanced into the sensor applicator 150, and the hub snap tabs 5302 can be received by corresponding arms 5304 of a sharps carrier 5306 disposed within the sensor applicator 150.
[0106] 11B shows the sensor control device 5002 received by the sharps carrier 5306 and thus secured within the sensor applicator 150. Once the sensor control device 5002 is loaded into the sensor applicator 150, the applicator cap 708 can be coupled to the sensor applicator 150. In some embodiments, the applicator cap 708 and housing 702 can have a set of intermateable threads 5308 that allow the applicator cap 708 to be twisted onto the housing 702 in a clockwise (or counterclockwise) direction, thereby securing the applicator cap 708 to the sensor applicator 150.
[0107] As shown, a sheath 704 is further disposed within the sensor applicator 150, and the sensor applicator 150 can include a sheath locking mechanism 5310 configured to ensure that the sheath 704 does not prematurely collapse during an impact event. In the illustrated embodiment, the sheath locking mechanism 5310 can include a threaded engagement between the applicator cap 708 and the sheath 704. More specifically, one or more internal threads 5312a can be defined or otherwise provided on an inner surface of the applicator cap 708, and one or more external threads 5312b can be defined or otherwise provided on the sheath 704. The internal threads 5312a and external threads 5312b can be configured to threadably mate when the applicator cap 708 is threaded onto the sensor applicator 150 via the threads 5308. The female and male threads 5312 a , 5312 b can have the same thread pitch as the threads 5308 that allow the applicator cap 708 to be twisted onto the housing 702 .
[0108] 11C shows the applicator cap 708 fully threaded (coupled) to the housing 702. As shown, the applicator cap 708 may further include or otherwise define a cap post 5314 centrally positioned therein and extending proximally from the bottom of the applicator cap 708. The cap post 5314 may be configured to receive at least a portion of the sensor cap 5018 when the applicator cap 708 is twisted onto the housing 702.
[0109] With the sensor control device 5002 loaded into the sensor applicator 150 and the applicator cap 708 properly secured, the sensor control device 5002 can then be subjected to a gas chemical sterilization configured to sterilize its electronics housing 5004 and any other exposed portions. Because the distal portion of the sensor 5010 and sharps 5012 are sealed within the sensor cap 5018, the chemicals used during the gas chemical sterilization process cannot interact with the enzymes, chemical and biological agents provided on the tail 5104, as well as other sensor components, such as the membrane coating that regulates analyte inflow.
[0110] 12A-12C are step-by-step cross-sectional side views illustrating assembly and disassembly of an alternative embodiment of a sensor applicator 150 and a sensor control device 5002 according to one or more additional embodiments. As generally described above, the fully assembled sensor control device 5002 can be loaded into the sensor applicator 150 by coupling the hub snap pawls 5302 into the arms 5304 of a sharps carrier 5306 disposed within the sensor applicator 150.
[0111] In the illustrated embodiment, the sheath arm 5604 of the sheath 704 can be configured to interact with a first detent 5702a and a second detent 5702b defined within the housing 702. The first detent 5702a may alternatively be referred to as a “locking” detent, and the second detent 5702b may alternatively be referred to as a “release” detent. When the sensor control device 5002 is initially installed within the sensor applicator 150, the sheath arm 5604 can be received within the first detent 5702a. As described below, the sheath 704 can be actuated to move the sheath arm 5604 to the second detent 5702b, thereby placing the sensor applicator 150 in the release position.
[0112] 12B , applicator cap 708 is aligned with and advanced relative to housing 702 so that sheath 704 is received within applicator cap 708. Instead of rotating applicator cap 708 relative to housing 702 to couple applicator cap 708 to housing 702, the threads of applicator cap 708 can snap onto corresponding threads of housing 702. Axial cuts or slots 5703 (one shown) defined in applicator cap 708 can allow a portion of applicator cap 708 proximal to its threads to bend outward and snap into engagement with the threads of housing 702. When applicator cap 708 is snapped onto housing 702, sensor cap 5018 can snap into cap post 5314 accordingly.
[0113] 11A-11C , the sensor applicator 150 can include a sheath locking mechanism configured to ensure that the sheath 704 does not prematurely collapse during an impact event. In the illustrated embodiment, the sheath locking mechanism includes one or more ribs 5704 (one shown) defined near the base of the sheath 704 and configured to interact with one or more ribs 5706 (two shown) and a shoulder 5708 defined near the base of the applicator cap 708. The rib 5704 can be configured to engage between the rib 5706 and the shoulder 5708 while attaching the applicator cap 708 to the housing 702. More specifically, once the applicator cap 708 is snapped onto the housing 702, the applicator cap 708 can be rotated (e.g., clockwise) such that the rib 5704 of the sheath 704 is positioned between the rib 5706 and the shoulder 5708 of the applicator cap 708, which "locks" the applicator cap 708 in place until a user counter-rotates the applicator cap 708 to remove it for use. The engagement of the rib 5704 between the rib 5706 and the shoulder 5708 of the applicator cap 708 can also prevent the sheath 704 from prematurely collapsing.
[0114] 12C, the applicator cap 708 has been removed from the housing 702. As with the embodiment of FIGS. 12A-12C, the applicator cap 708 can be removed by counter-rotating it, which correspondingly rotates the cap post 5314 in the same direction, unscrewing the sensor cap 5018 from the fitting 5016, as generally described above. Furthermore, disconnecting the sensor cap 5018 from the sensor control device 5002 exposes the sensor 5010 and distal portions of the sharps 5012.
[0115] When the applicator cap 708 is twisted off the housing 702, the rib 5704 defined on the sheath 704 can slidingly engage the top of the rib 5706 defined on the applicator cap 708. The top of the rib 5706 can provide a corresponding raised surface that causes upward displacement of the sheath 704 when the applicator cap 708 is rotated, and the upward movement of the sheath 704 results in the sheath arm 5604 bending out of engagement with the first detent 5702a and being received into the second detent 5702b. As the sheath 704 moves to the second detent 5702b, the radial shoulder 5614 disengages from radial engagement with the carrier arm 5608, thereby allowing the passive spring force of the spring 5612 to push the sharp carrier 5306 upward, forcing the carrier arm 5608 out of engagement with the groove 5610. As the sharps carrier 5306 moves upward within the housing 702, the engaging member 5016 can be retracted accordingly until it is flush, substantially flush, or near-flush with the bottom of the sensor control device 5002. At this point, the sensor applicator 150 is in the ejection position. Thus, in this embodiment, removing the applicator cap 708 correspondingly retracts the engaging member 5016.
[0116] 13A-13F illustrate exemplary details of an embodiment of the internal device configuration for applying the sensor control device 102 to a user and "firing" the applicator 150, including safely retracting the sharpener 1030 back into the used applicator 150. Together, these figures depict an exemplary sequence of driving the sharpener 1030 (carrying a sensor coupled to the sensor control device 102) into the user's skin, withdrawing the sharpener while leaving the sensor in operable contact with the user's interstitial fluid, and adhesively adhering the sensor control device to the user's skin. With reference to these figures, one skilled in the art can recognize modifications of such actions for use with alternative applicator assembly embodiments and components. Furthermore, the applicator 150 can be a sensor applicator having a one-piece or two-piece architecture as disclosed herein.
[0117] 13A , the sensor 1102 is supported within the sharp 1030 slightly above the user's skin 1104. Rails 1106 (optionally three rails 1106) on the upper guide section 1108 can be provided to control movement of the applicator 150 relative to the sheath 704. The sheath 704 is secured within the applicator 150 by detent features 1110 such that an appropriate downward force along the longitudinal axis of the applicator 150 will overcome the resistance provided by the detent features 1110 so that the sharp 1030 and sensor control device 102 can be translated along the longitudinal axis into (and onto) the user's skin 1104. Additionally, a catch arm 1112 on the sensor carrier 1022 engages the sharp retraction assembly 1024 to maintain the sharp 1030 in position relative to the sensor control device 102.
[0118] 13B , a user force is applied to overcome and disable the detent feature 1110, causing the sheath 704 to collapse into the housing 702 and drive the sensor control device 102 (together with the attached portions) to translate downward along the longitudinal axis as shown by arrow L. The inner diameter of the upper guide section 1108 of the sheath 704 constrains the position of the carrier arm 1112 throughout the entire stroke of the sensor / sharps insertion process. The retention of the stop surface 1114 of the carrier arm 1112 against the complementary surface 1116 of the sharps retraction assembly 1024 maintains the position of these members with the return spring 1118 fully biased. According to an embodiment, instead of using user force to drive the sensor control device 102 to translate downward along the longitudinal axis as shown by arrow L, the housing 702 can include a button (by way of example and not limitation, a push button) that activates a drive spring (by way of example and not limitation, a coil spring) to drive the sensor control device 102.
[0119] 13C, the sensor 1102 and sharp 1030 reach maximum insertion depth. In doing so, the carrier arm 1112 passes through the inner diameter of the upper guide section 1108. The compressive force of the coil return spring 1118 then drives the bent stop surface 1114 radially outward, releasing a force that drives the sharp carrier 1102 of the sharp retraction assembly 1024 to pull the (slotted or otherwise configured) sharp 1030 out of the user and away from the sensor 1102, as shown by arrow R in FIG. 13D.
[0120] With the sharp 1030 fully retracted, as shown in Figure 13E, the final locking mechanism 1120 is engaged with the upper guide section 1108 of the sheath 704. As shown in Figure 13F, the used applicator assembly 150 is removed from the insertion site, leaving the sensor control device 102 behind and with the sharp 1030 safely secured inside the applicator assembly 150. At this point, the used applicator assembly 150 is ready to be discarded.
[0121] Actuation of the applicator 150 when applying the sensor control device 102 is designed to give the user the sensation that both insertion and retraction of the sharpener 1030 are automatically performed by the applicator's 150 internal features. In other words, the present invention avoids the user experiencing the sensation of forcing the sharpener 1030 into their skin. Thus, after the user applies sufficient force to overcome the resistance from the applicator's 150 detent features, the resulting movement of the applicator 150 is perceived as an automatic response to the applicator being "triggered." Even though all of the driving force to insert the sharpener 1030 is provided by the user and no additional biasing / driving means are used, the user does not perceive that they are providing additional force to drive the sharpener 1030 to penetrate the skin. As detailed above in FIG. 13C , retraction of the sharpener 1030 is automated by the applicator's 150 coil return spring 1118.
[0122] With respect to any of the applicator embodiments described herein, and any of the components of the applicator embodiments, including but not limited to, the sharp, sharp module, and sensor module embodiments, those skilled in the art will understand that these embodiments can be sized and configured to be suitable for use with a sensor configured to sense an analyte level in a bodily fluid within the epidermis, dermis, or subcutaneous tissue of a subject. In some embodiments, for example, the sharp and distal portion of the analyte sensor disclosed herein can be sized and configured to be positioned at a particular distal depth (i.e., the deepest penetration point into a tissue or layer of a subject's body, e.g., the epidermis, dermis, or subcutaneous tissue). With respect to some applicator embodiments, those skilled in the art will recognize that certain embodiments of the sharp can be sized and configured to be positioned at a different distal depth within the subject's body compared to the final distal depth of the analyte sensor. In some embodiments, for example, the sharp can be positioned at a first distal depth within the subject's epidermis prior to retraction, while the distal portion of the analyte sensor can be positioned at a second distal depth within the subject's dermis. In other embodiments, the sharp may be positioned at a first distal depth within the subject's dermis prior to retraction, while the distal portion of the analyte sensor may be positioned at a second distal depth within the subcutaneous tissue of the subject. In yet other embodiments, the sharp may be positioned at a first distal depth and the analyte sensor may be positioned at a second distal depth prior to retraction, both within the same layer or tissue of the subject's body.
[0123] Additionally, with respect to any of the applicators described herein, one skilled in the art will understand that the analyte sensor and one or more structured components coupled to the analyte sensor, including but not limited to one or more spring features, can be positioned in an eccentric location within the applicator relative to one or more axes thereof. In some applicator embodiments, for example, the analyte sensor and spring feature can be positioned in an eccentric location on a first side of the applicator relative to the applicator axis, and the sensor electronics can be positioned in an eccentric location on a second side of the applicator relative to the applicator axis. In other applicator embodiments, the analyte sensor, spring feature, and sensor electronics can be positioned in eccentric locations on the same side of the applicator axis. One skilled in the art will recognize that other permutations and configurations in which any or all of the analyte sensor, spring feature, sensor electronics, and other applicator components are positioned in central or eccentric locations relative to one or more axes of the applicator are possible and fully within the present disclosure.
[0124] Additional details of suitable devices, systems, methods, components, and their operation, along with related features, are described in WO 2018 / 136898 to Rao et al., WO 2019 / 236850 to Thomas et al., WO 2019 / 236859 to Thomas et al., WO 2019 / 236876 to Thomas et al., and U.S. Patent Application Publication No. 2020 / 0196919, filed June 6, 2019, the entire contents of each of which are incorporated herein by reference. Additional details regarding embodiments of the applicator, its components, and variations thereof are described in U.S. Patent Application Publication Nos. 2013 / 0150691, 2016 / 0331283, and 2018 / 0235520, the entire contents of all of which are incorporated herein by reference for all purposes. Additional details regarding embodiments of the Sharp Module, Sharp, its components, and variations thereof are described in U.S. Patent Application Publication No. 2014 / 0171771, the entire contents of which are incorporated herein by reference for all purposes.
[0125] Biochemical sensors can be described by one or more sensing properties. A common sensing property is called the sensitivity of a biochemical sensor, which is a measure of the sensor's responsiveness to the concentration or composition of the chemical it is designed to detect. In electrochemical sensors, this response can be in the form of current (amperometric) or charge (coulometric). In other types of sensors, the response can be in a different form, such as photon intensity (e.g., light). The sensitivity of a biochemical analyte sensor can vary depending on several factors, including whether the sensor is in an in vitro or in vivo state.
[0126] FIG. 14 is a graph depicting the in vitro sensitivity of an amperometric analyte sensor. In vitro sensitivity can be obtained by testing the sensor in vitro at various analyte concentrations and then performing a regression (e.g., linear or nonlinear) or other curve fit on the resulting data. In this example, the sensitivity of the analyte sensor is linear or substantially linear and can be modeled according to the equation y=mx+b, where y is the sensor's output current, x is the analyte level (or concentration), m is the sensitivity slope, and b is the sensitivity intercept, which corresponds approximately to the background signal (e.g., noise). For sensors with a linear or substantially linear response, the analyte level corresponding to a given current can be determined from the sensitivity slope and intercept. Sensors with nonlinear sensitivity require additional information to determine the analyte level resulting from the sensor's output current, and those skilled in the art will be familiar with schemes for modeling nonlinear sensitivity. In certain embodiments of in vivo sensors, the in vivo sensitivity may be the same as the in vivo sensitivity, while in other embodiments, a transfer (or transformation) function is used to convert the in vitro sensitivity to an in vivo sensitivity applicable to the sensor's intended in vivo use.
[0127] Calibration is a technique for improving or maintaining accuracy by adjusting the measured output of a sensor to reduce the difference from the sensor's expected output. One or more parameters describing the sensing characteristics of the sensor, such as sensitivity, are determined for use in making the calibration adjustments.
[0128] Certain in-vivo analyte monitor systems require calibration, either by user intervention after implantation of the sensor in a user or patient, or automatically by the system itself. For example, when user intervention is required, the user performs an in-vitro measurement (e.g., a blood glucose (BG) measurement using a fingerstick and an in-vitro test strip) while the analyte sensor is implanted and enters the measurement into the system. The system compares the in-vitro measurement to an in-vivo signal and uses the difference to determine an estimate of the sensor's in-vivo sensitivity. The in-vivo sensitivity can then be used in an algorithmic process to convert data collected with the sensor into a value indicative of the user's analyte level. This and other processes requiring user action to perform calibration are referred to as "user calibration." Systems may require user calibration due to instability in sensor sensitivity, such as sensitivity drifting or changing over time. Thus, multiple user calibrations (e.g., on a periodic (e.g., daily) schedule, according to a variable schedule, or on an as-needed basis) may be required to maintain accuracy. The embodiments described herein may incorporate some degree of user calibration as appropriate for a particular implementation, but generally user calibration is not preferred as it requires the user to perform painful or otherwise expensive BG measurements and can introduce user error.
[0129] Some in vivo analyte monitor systems can periodically adjust calibration parameters through the use of automated measurements of sensor characteristics performed by the system itself (e.g., processing circuitry running the software). Repeated adjustment of sensor sensitivity based on variables measured by the system (rather than the user) is generally referred to as "system" (or automatic) calibration, and can be performed with or without user calibration, such as an early BG measurement. As with repeated user calibration, repeated system calibration is generally necessitated by drift in sensor sensitivity over time. Thus, while the embodiments described herein can be used with some degree of automated system calibration, preferably the sensor sensitivity is relatively stable over time such that post-execution calibration is not required.
[0130] Some in vivo analyte monitor systems operate with factory-calibrated sensors. Factory calibration refers to the determination or estimation of one or more calibration parameters prior to sale to a user or healthcare professional (HCP). The calibration parameters may be determined by the sensor manufacturer (or by the manufacturer of other components of the sensor-controlled device, if different from the sensor manufacturer). Many in vivo sensor manufacturing processes process sensors in groups or batches, also called production lots, manufacturing lots, or simply lots. A single lot may contain thousands of sensors.
[0131] The sensor may include a calibration code or parameters that are derived or determined during one or more sensor manufacturing processes, encoded or programmed into a data processing device of the analyte monitoring system as part of the manufacturing process, or provided on the sensor itself, for example, as a bar code, laser tag, RFID tag, or other machine-readable information displayed on the sensor. When the code is provided to a receiver (or other data processing device), user calibration during in-vivo use of the sensor may be avoided or the frequency of in-vivo calibration while the sensor is worn may be reduced. In embodiments in which the calibration code or parameters are provided on the sensor itself, the calibration code or parameters may be automatically transmitted or provided to a data processing device in the analyte monitoring system prior to or at the start of sensor use.
[0132] Some in vivo analyte monitor systems operate with sensors that can be one or more of factory-calibrated, system-calibrated, and / or user-calibrated. For example, a sensor can be provided with a calibration code or calibration parameters that can enable factory calibration. If this information is provided to the receiver (e.g., entered by a user), the sensor can operate as a factory-calibrated sensor. If this information is not provided to the receiver, the sensor can operate as a user-calibrated sensor and / or a system-calibrated sensor.
[0133] In yet another aspect, programming or executable instructions can be provided or stored within the data processing device and / or receiver / controller unit of the analyte monitoring system for providing a time-varying adjustment algorithm to the in-vivo sensor during use. For example, based on retrospective statistical analysis of the analyte sensor used in vivo and corresponding glucose level feedback, a time series of predetermined curves or analysis curves or databases can be generated that are configured to make additional adjustments to one or more in-vivo sensor parameters to compensate for potential sensor drift or other factors in the stability profile.
[0134] In accordance with the presently disclosed subject matter, an analyte monitoring system can be configured to compensate or adjust sensor sensitivity based on a sensor drift profile. A time-varying parameter β(t) can be defined or determined based on an analysis of sensor behavior during in vivo use, and a time-varying drift profile can be determined. In certain aspects, the compensation or adjustment of sensor sensitivity can be programmed into a receiver unit, controller, or data processor of the analyte monitoring system such that the compensation or adjustment, or both, can be performed automatically and / or iteratively as sensor data is received from the analyte sensor. In accordance with the presently disclosed subject matter, the adjustment or compensation algorithm can be user-initiated or executed (rather than self-initiated or self-executing) such that the adjustment or compensation of the analyte sensor sensitivity profile is performed or executed upon user initiation or activation of a corresponding function or routine or when the user enters a sensor calibration code.
[0135] In accordance with the presently disclosed subject matter, each sensor in a sensor lot (which in some implementations does not include a sample sensor used for in vivo testing) can be non-destructively inspected to determine or measure sensor characteristics, such as film thickness at one or more points on the sensor, and other characteristics, including physical characteristics such as the area / volume of the active area. Such measurements or determinations can be performed in an automated manner, for example, using an optical scanner or other suitable measurement device or system, and the determined sensor characteristics for each sensor in the sensor lot are compared to corresponding average values based on the sample sensors with possible corrections for calibration parameters or calibration codes assigned to each sensor. For example, for a calibration parameter defined as sensor sensitivity, sensitivity is approximately inversely proportional to film thickness; thus, for example, for a sensor having a measured film thickness that is approximately 4% greater than sensors sampled from the same sensor lot, the sensitivity assigned to that sensor in one embodiment is the average selectively determined from the sample sensors divided by 1.04. Similarly, sensitivity is also roughly proportional to the active area of the sensor, so that for a sensor with a measured active area that is about 3% smaller than the average active area for sensors sampled from the same sensor lot, the sensitivity assigned to that sensor is the average sensitivity multiplied by 0.97. The assigned sensitivity can be determined from the average sensitivity from the sample sensors by multiple successive adjustments for each test or measurement of that sensor. In certain embodiments, the test or measurement of each sensor can further include measuring the viscosity or texture of the film in addition to the film thickness and / or area or volume of the active sensing area.
[0136] Additional information regarding sensor calibration is provided in U.S. Patent Application Publication Nos. 2010 / 0230285 and 2019 / 0274598, the entire contents of each of which are incorporated herein by reference.
[0137] The storage memory 5030 of the sensor control device 102 may include software blocks related to the communication protocol of the communication module. For example, the storage memory 5030 may include a BLE service software block whose functions provide an interface for making the BLE module 5041 available to the computer hardware of the sensor control device 102. These software functions may include a BLE logic interface and an interface parser. BLE services provided by the communication module 5040 may include a generic access profile service, a generic attribute service, a generic access service, a device information service, a data transmission service, and a security service. The data transmission service may be a primary service used to transmit data such as sensor control data, sensor status data, analyte measurement data (past and present), and event log data. Sensor status data may include error data, current active time, and software state. Analyte measurement data may include information such as current and past raw measurements, current and past values after processing with appropriate algorithms or models, predictions and trends of measurement levels, comparisons of other values to patient-specific averages, invocation of actions determined by algorithms or models, and other similar types of data.
[0138] According to aspects of the presently disclosed subject matter, as embodied herein, the sensor control device 102 can be configured to communicate with multiple devices simultaneously by adapting the capabilities of the communication protocols or communication media supported by its hardware and radio. As an example, the BLE module 5041 of the communication module 5040 can be provided with software or firmware to enable multiple simultaneous connections between the sensor control device 102 as a central device, or as a peripheral device if another device is the central device, and multiple other devices as peripheral devices.
[0139] A connection between two devices using a communication protocol such as BLE, and the resulting communication session, can be characterized by a similar physical channel operating between these two devices (e.g., the sensor control device 102 and the data receiving device 120). The physical channel can include a single channel or a series of channels, including, by way of example and not limitation, using an agreed-upon series of channels determined by a common clock and a channel hopping or frequency hopping sequence. The communication sessions can use a similar amount of available communication spectrum, and multiple such communication sessions can exist in the vicinity. In certain embodiments, each set of devices in a communication session uses a different physical channel or series of channels to manage interference with the same nearby devices.
[0140] For purposes of illustration and not limitation, reference will be made to an exemplary embodiment of a procedure for sensor-receiver connection suitable for use with the subject matter of this disclosure. First, the sensor control device 102 repeatedly advertises its connection information to its environment, looking for a data receiving device 120. The sensor control device 102 may repeat the advertisement periodically until a connection is established. The data receiving device 120 detects the advertisement packet and scans and filters through the data provided in the advertisement packet, looking for a sensor control device 102 to connect to. Next, the data receiving device 120 sends a scan request command, and the sensor control device 102 responds with a scan response packet providing additional details. Next, the data receiving device 120 sends a connection request using the associated Bluetooth device address. The data receiving device 120 may continually request to establish a connection to the sensor control device 102 using a specific Bluetooth device address. Next, the data receiving device establishes an initial connection that allows it and the sensor to begin exchanging data. The devices begin the process of initializing a data exchange service and performing a mutual authentication procedure.
[0141] During the initial connection between the sensor controlling device 102 and the data receiving device 120, the data receiving device 120 can initialize a service, feature, and attribute discovery procedure. The data receiving device 120 can evaluate these capabilities of the sensor controlling device 102 and store them for use during subsequent connections. The data receiving device then enables notification of each corresponding security service to be used for mutual authentication between the sensor controlling device 102 and the data receiving device 120. The mutual authentication procedure may be automated and require no user intervention. Following successful completion of the mutual authentication procedure, the sensor controlling device 102 sends a connection parameter update requesting the data receiving device 120 to use the connection parameter settings it has dominantly selected and configured to maximize longevity.
[0142] The data receiving device 120 then executes a sensor control procedure to backfill the historical data, current data, event log, and factory data. As an example, the data receiving device 120 sends a request to initiate the backfill process for each type of data. The request can specify a defined recording range, for example, based on measurements, timestamps, etc., as needed. The sensor control device 102 responds with the requested data until all previously unsent data in its memory has been sent to the data receiving device 120. The sensor control device 102 can respond to the backfill request from the data receiving device 120 by indicating that all data has been sent. Once backfilling is complete, the data receiving device 120 can notify the sensor control device 102 that it is ready to receive periodic measurement readings. The sensor control device 102 can repeatedly send the readings over multiple notification results. As embodied herein, the multiple notifications can be redundant notifications to ensure that the data is transmitted correctly. Alternatively, the multiple notifications can include a single payload.
[0143] For purposes of illustration and not limitation, reference will be made to an exemplary embodiment of a procedure for sending a shutdown command to the sensor control device 102. A shutdown operation is performed when the sensor control device 102 is in, for example, an error state, an insertion failure state, or an expired sensor state. The sensor control device 102 can log the command when not in these states and execute the shutdown when it transitions to the error state or the expired sensor state. The data receiving device 120 sends a properly formatted shutdown command to the sensor control device 102. If the sensor control device 102 is actively processing another command, it will respond with a standard error response indicating it is busy. Otherwise, the sensor control device 102 will send a response upon receiving the command. Additionally, the sensor control device 102 will send a success notification via its own sensor control to acknowledge receiving the command. The sensor control device 102 registers the shutdown command. At the next appropriate opportunity (e.g., depending on the current sensor state as described herein), the sensor control device 102 will shut down.
[0144] For purposes of illustration and not limitation, reference is made to an exemplary embodiment of a high-level depiction of a state machine representation 6000 of actions that the sensor control device 102 can take, as shown in FIG. 15 . After initialization, the sensor enters a state 6005 associated with manufacturing the sensor control device 102. In the manufacturing state 6005, the sensor control device 102 can be configured for operation, e.g., writing to the storage memory 5030. At various times while in state 6005, the sensor control device 102 checks for received commands and moves to a save state 6015. Upon entering the save state 6015, the sensor performs a software integrity check. While in the save state 6015, the sensor can receive a wake-up request command, after which it progresses to an insertion detection state 6025.
[0145] Upon entering state 6025, the sensor control device 102 may store information related to the authenticated device to communicate with the sensor as configured during startup or initialize algorithms related to communicating and interpreting measurements from the sensing hardware 5060. The sensor control device 102 may initialize a lifecycle timer responsible for maintaining its active operation time count and begin communicating with the authenticated device to transmit recorded data. While in insertion detection state 6025, the sensor may enter state 6030, where the sensor control device 102 checks whether the operation time equals a predetermined threshold. This operation time threshold may correspond to a timeout function for determining whether insertion is successful. If the operation time threshold is reached, the sensor control device 102 proceeds to state 6035, where it checks whether the average data read volume is greater than a threshold volume, which corresponds to the expected data read volume for triggering detection of a successful insertion. If the data read volume is lower than the threshold volume while in state 6035, the sensor proceeds to state 6040, which corresponds to an insertion failure. If the amount of data read meets the threshold, the sensor proceeds to the active pairing state 6055 .
[0146] The active paired state 6055 of the sensor control device 102 reflects a state in which the sensor control device 102 is operating normally by recording measurements, processing measurements, and reporting these measurements as needed. While in the active paired state 6055, the sensor control device 102 attempts to send measurements or establish a connection with the receiving device 120. The sensor control device 102 further increments the operating time. The sensor control device 102 transitions to the active lapsed state 6065 once it reaches a predetermined threshold operating time (e.g., when the operating time reaches a predetermined threshold). The active lapsed state 6065 of the sensor control device 102 reflects a state in which the sensor control device 102 has operated for its maximum predetermined amount of time.
[0147] While in the active revocation state 6065, the sensor control device 102 may generally perform operations related to gradually winding down operation and, if necessary, ensuring that collected measurements are securely transmitted to receiving devices. For example, while in the active revocation state 6065, the sensor control device 102 may transmit collected data and, if a connection is unavailable, may intensify attempts to find and establish a connection with a neighboring authenticated device. While in the active revocation state 6065, the sensor control device 102 may receive a shutdown command in state 6070. If a shutdown command is not received, the sensor control device 102 may check whether the operation time has exceeded a final operation threshold in state 6075. The final operation threshold may be based on the battery life of the sensor control device 102. The normal transmission state 6080 corresponds to a final operation of the sensor control device 102, ultimately shutting down the sensor control device 102.
[0148] Before the sensor is powered up, the ASIC 5000 is in a low-power storage mode. The power-up process can begin, for example, when an incident RF field (e.g., an NFC field) drives the voltage of the power supply to the ASIC 5000 above a reset threshold, causing the sensor control device 102 to enter a wake-up state. While in the wake-up state, the ASIC 5000 enters a power-up sequence state. The ASIC 5000 then wakes up the communications module 5040. The communications module 5040 is initialized and a power-on self-test is triggered. The power-on self-test can include the ASIC 5000 communicating with the communications module 5040 using a specified sequence of reading and writing data to verify that the memory and one-time programmable memory are not corrupted.
[0149] When the ASIC 5000 first enters measurement mode, an insertion detection sequence is executed to verify that the sensor control device 102 is properly attached to the patient's body before proper measurements can be taken. Initially, the sensor control device 102 interprets a command to initiate the measurement configuration process, placing the ASIC 5000 in measurement command mode. Next, the sensor control device 102 temporarily enters a measurement lifecycle state in which it performs several consecutive measurements to test for successful insertion. The communications module 5040 or the ASIC 5000 evaluates the measurement results to determine successful insertion. The sensor control device 102 enters the measurement state when insertion is deemed successful, where it begins taking periodic measurements using the sensing hardware 5060. If the sensor control device 102 determines that insertion was not successful, it is triggered to enter insertion failure mode, where the ASIC 5000 is instructed to return to storage mode, while the communications module 5040 disables itself.
[0150] 1B further illustrates an exemplary operating environment for applying over-the-air ("OTA") updates suitable for use with the technology described herein. An operator of the analyte monitoring system 100 can bundle updates for the data receiving device 120 or the sensor controlling device 102 with updates for applications running on the general-purpose data receiving device 130. Using a communication channel available between the data receiving device 120, the general-purpose data receiving device 130, and the sensor controlling device 102, the general-purpose data receiving device 130 can receive periodic updates for the data receiving device 120 or the sensor controlling device 102 and initiate the installation of these updates on the data receiving device 120 or the sensor controlling device 102. Applications that enable the multipurpose data receiving device 130 to communicate with the sensor control device 102, the data receiving device 120, and / or the remote application server 155 can update software or firmware on the data receiving device 120 or the sensor control device 102 without using wide area network connectivity, so that the multipurpose data receiving device 130 acts as an installation or update platform for the data receiving device 120 or the sensor control device 102.
[0151] As embodied herein, a remote application server 155 operated by the manufacturer of the sensor control device 102 and / or the operator of the analyte monitoring system 100 can provide software and firmware updates to the devices in the analyte monitoring system 100. In certain embodiments, the remote application server 155 can provide updated software and firmware to the user device 140 or directly to the general-purpose data receiving device. As embodied herein, the remote application server 155 can provide application software updates to the application storefront server 160 using an interface provided by the application storefront. The general-purpose data receiving device 130 can periodically communicate with the application storefront server 160 to download and install updates.
[0152] After the multipurpose data receiving device 130 downloads application update information including firmware or software update information for the data receiving device 120 or the sensor controlling device 102, the data receiving device 120 or the sensor controlling device 102 and the multipurpose data receiving device 130 establish a connection. The multipurpose data receiving device 130 determines that firmware or software update information for the data receiving device 120 or the sensor controlling device 102 is available. The multipurpose data receiving device 130 can provide the software or firmware update information for delivery to the data receiving device 120 or the sensor controlling device 102. As an example, the multipurpose data receiving device 130 can compress or split data related to the software update information or the firmware update information, encrypt or decrypt the firmware or software update information, or perform an integrity check on the firmware or software update information. The multipurpose data receiving device 130 sends data related to the firmware or software update to the data receiving device 120 or the sensor control device 102. Additionally, the multipurpose data receiving device 130 can send instructions to initiate the update to the data receiving device 120 or the sensor control device 102. Additionally or alternatively, the multipurpose data receiving device 130 can present a notification to its user and include instructions to expedite the update, such as instructions to keep the data receiving device 120 and the multipurpose data receiving device 130 connected to and nearby a power source until the update is complete.
[0153] The data receiving device 120 or the sensor control device 102 receives data for the update and a command to initiate the update from the multipurpose data receiving device 130. The data receiving device 120 can then install the firmware or software update. To install the update, the data receiving device 120 or the sensor control device 102 can enter or resume a so-called "safe" mode, which has only limited operational capabilities. Once the update is complete, the data receiving device 120 or the sensor control device 102 re-enters or resets in a standard operational mode. The data receiving device 120 or the sensor control device 102 can perform one or more self-diagnostic tests to determine that the firmware or software update was successfully installed. The multipurpose data receiving device 130 can receive notification of a successful update. The multipurpose data receiving device 130 can then report confirmation of the successful update to the remote application server 155.
[0154] In certain embodiments, the storage memory 5030 of the sensor control device 102 includes one-time programmable (OTP) memory. The term OTP memory can refer to memory that includes access restrictions and security to facilitate a predetermined number of writes to specific addresses or segments within the memory. The memory 5030 can be pre-organized into multiple pre-allocated memory blocks or memory bins. The bins are pre-allocated to a fixed size. When the storage memory 5030 is one-time programmable memory, the bins can be considered to be in a non-programmable state. Additional bins that have not yet been written to can be made programmable or writable. Containerizing the storage memory 5030 in this manner can improve the portability of code and data to be written to the storage memory 5030. Updating software of a device (e.g., a sensor device described herein) stored in OTP memory can be performed by replacing only the code in one or more specific bins that were previously written with the latest code written to one or more new bins, rather than replacing all of the code in the memory. In a second embodiment, the memory is not pre-organized. Instead, the space allocated to the data is dynamically allocated or determined as needed. Containers of various sizes may be defined where updates are expected, so that incremental updates can be sent.
[0155] 16 illustrates an exemplary operational and data flow diagram associated with over-the-air (OTA) programming of the storage memory 5030 in the sensor control device 102 in accordance with the subject matter of this disclosure, as well as the use of the memory during execution of processes by the sensor device 110 after OTA programming. In the exemplary OTA programming 500 illustrated in FIG. 5, a request to initiate OTA programming (or reprogramming) is sent from an external device (e.g., the data receiving device 130). At 511, the communication module 5040 of the sensor device 110 receives an OTA programming command. The communication module 5040 sends the OTA programming command to the microcontroller 5010 of the sensor device 110.
[0156] At 531, after receiving the OTA programming command, the microcontroller 5010 verifies the authenticity of the OTA programming command. For example, the microcontroller 5010 may determine whether the OTA programming command is signed with an appropriate digital signature token. Upon determining that the OTA programming command is authentic, the microcontroller 5010 may place the sensor device in an OTA programming mode. At 532, the microcontroller 5010 may verify the authenticity of the OTA programming data. At 533, the microcontroller 5010 may reset the sensor device 110 to reinitialize the sensor device 110 in the programming state. Once the sensor device 110 transitions to the OTA programming state, the microcontroller 5010 may begin writing data to the rewritable memory 540 (e.g., memory 5020) of the sensor device at 534 and may further write data to the OTP memory 550 (e.g., storage memory 5030) of the sensor device at 535. The data written by the microcontroller 5010 may be based on the authenticated OTA programming data. The microcontroller 5010 may write data that causes one or more programming blocks or programming areas of the OTP memory 550 to be marked as invalid or inaccessible. The data written to free or unused portions of the OTP memory 550 can be used to replace programming blocks of the OTP memory 550 that are deemed invalid or inaccessible. After the microcontroller 5010 writes the data to the respective memories at 534 and 535, it can perform one or more software integrity checks to ensure that no errors were introduced into the programming blocks during the writing process. After it can determine that the data was written without error, the microcontroller 5010 can resume normal operation of the sensor device.
[0157] In the execution mode, the microcontroller 5010 can retrieve 536 a programming manifest or programming profile from the rewritable memory 540. The programming manifest or programming profile can include a list of legal software programming blocks and can further include program execution guidelines for the sensor control device 102. By following the programming manifest or programming profile, the microcontroller 5010 can determine which memory blocks in the OTP memory 550 are appropriate for execution and avoid executing or referencing expired data in programming blocks that are deemed expired or fraudulent. At 537, the microcontroller 5010 can selectively retrieve memory blocks from the OTP memory 550. At 538, the microcontroller 5010 can use the retrieved memory blocks by executing programming code stored in the memory or using stored variables.
[0158] As embodied herein, a first layer of security for communications between the sensor control device 102 and other devices can be established based on security protocols dictated by and embedded in the communications protocol used for communication. Another layer of security can be based on communications protocols that require proximity of the communicating devices. Additionally, certain packets and / or certain data contained within packets can be encrypted, while other packets and / or other data within packets may or may not be otherwise encrypted. Additionally or alternatively, application layer encryption can be used in conjunction with one or more block or stream ciphers to establish mutual authentication and communications encryption with other devices in the analyte monitoring system 100.
[0159] The ASIC 5000 of the sensor control device 102 can be configured to dynamically generate authentication and encryption keys using data maintained in the storage memory 5030. The storage memory 5030 can be pre-programmed with a set of valid authentication and encryption keys for use with a particular class of device. The ASIC 5000 can be further configured to implement authentication procedures with other devices using received data and to provide a generation key to sensitive data before transmitting the sensitive data. The generation key can be unique to the sensor control device 102, unique to a pair of devices, unique to a communication session between the sensor control device 102 and another device, unique to a message sent during the communication session, or unique to a data block contained within a message.
[0160] Both the sensor control device 102 and the data receiving device 120 can vouch for the authority of the other party in a communication session, for example, to send commands or receive data. In certain embodiments, identity authentication can be performed through two mechanisms. First, the party asserting identity provides a valid certificate signed by the device manufacturer or the operator of the analyte monitoring system 100. Second, authentication can be performed using public and private keys determined by the device in the analyte monitoring system 100 or by the operator of the analyte monitoring system 100, and a shared secret derived therefrom. To verify the identity of the other party, the party can provide proof that it controls the private key.
[0161] The manufacturer of the sensor control device 102, the data receiving device 120, or the provider of the application for the general-purpose data receiving device 130 may provide the information and programming necessary for these devices to communicate securely through secure programming and updates. For example, the manufacturer may provide information that can be used to generate encryption keys for each device, including a secure root key for the sensor control device 102 and optionally the data receiving device 120, which can be used in combination with device-specific information and operational data (e.g., an entropy-based random value) to generate a unique encryption value for the device, session, or data transmission as needed.
[0162] Analyte data associated with a user is sensitive due, at least in part, to its potential use for a variety of purposes, including health monitoring and drug dosage determination. In addition to user data, the analyte monitor system 100 can implement enhanced security against reverse engineering attempts by external parties. Communication connections can be encrypted using device-specific or session-specific encryption keys. Encrypted or unencrypted communications between any two devices can be verified using transmission integrity checks built into the communications. The operation of the sensor control device 102 can be protected from tampering by restricting access to read and write functionality to the memory 5020 through the communication interface. The sensor can be configured to allow access only to known or “trusted” devices listed in a “whitelist” or devices that can provide a predetermined code associated with the manufacturer or other authorized user. The whitelist may represent a limited scope, meaning that no connection identifiers other than those included therein should be used, or a preferred scope in which the whitelist is searched first, but other devices can still be used. Additionally, the sensor control device 102 can reject connection requests and shut down if the requestor fails to complete the login procedure over the communication interface within a predetermined period of time (e.g., within 4 seconds). These features provide protection against certain denial of service attacks, particularly against BLE interfaces.
[0163] As embodied herein, the analyte monitoring system 100 may employ periodic key rotation to further reduce key revocation and tampering. The key rotation strategy employed by the analyte monitoring system 100 may be designed to accommodate backward compatibility for devices deployed or distributed across a site. As an example, the analyte monitoring system 100 may employ keys designed to be compatible with multiple generations of keys used by upstream devices for downstream devices (e.g., devices at a site or devices that cannot be provided with updated information in a feasible manner).
[0164] For purposes of illustration and not limitation, reference is made to an exemplary embodiment of a message sequence diagram 600 suitable for use with the subject matter of the present disclosure, shown in FIG. 17 , illustrating an exemplary data exchange between a pair of devices, specifically a sensor control device 102 and a data receiving device 120. The data receiving device 120 may be a data receiving device 120 or a general-purpose data receiving device 130, as specifically illustrated herein. In step 605, the data receiving device 120 may send a sensor activation command 605 to the sensor control device 102, for example, via a short-range communication protocol. Prior to step 605, the sensor control device 102 may be primarily dormant, conserving battery power until a full activation is required. After activating during step 610, the sensor control device 102 may collect data or perform other operations appropriate to the sensing hardware 5060 of the sensor control device 102. In step 615, the data receiving device 120 may initiate an authentication request command 615. In response to the authentication request command 615, both the sensor control device 102 and the data receiving device 120 can engage in a mutual authentication process 620. The mutual authentication process 620 can include the transfer of data including challenge parameters that enable the sensor control device 102 and the data receiving device 120 to ensure that the other device is sufficiently capable to adhere to the agreed-upon security framework described herein. Mutual authentication can be based on the ability of two or more entities to authenticate each other, verifying the establishment of a secret key through a challenge response with or without the involvement of an online trusted third party. Mutual authentication can be performed using two-pass, three-pass, four-pass, or five-pass authentication or similar versions thereof.
[0165] Following a successful mutual authentication process 620, in step 625, the sensor control device 102 can provide a sensor secret 625 to the data receiving device 120. The sensor secret includes a sensor-specific value and can be derived from a random value generated during manufacturing. The sensor secret can be encrypted before or during transmission to prevent third parties from accessing it. The sensor secret 625 can be encrypted by one or more of the keys generated by the mutual authentication process 620 or accordingly. In step 630, the data receiving device 120 can derive a sensor-specific encryption key from the sensor secret. The sensor-specific encryption key can further be session-specific. Thus, the sensor-specific encryption key can be determined by each device without being transmitted between the sensor control device 102 and the data receiving device 120. In step 635, the sensor control device 102 can encrypt data to be included in the payload. In step 640, the sensor control device 102 can transmit the encrypted payload 640 to the data receiving device 120 using the communication link established between its appropriate communication model and the appropriate communication model of the data receiving device 120. In step 645, the data receiving device 120 can decrypt the payload using the sensor-specific encryption key derived during step 630. Following step 645, the sensor control device 102 can deliver additional (including newly collected) data, and the data receiving device 120 can process the received data appropriately.
[0166] As described herein, the sensor control device 102 may be a device with only limited processing power, battery supply, and storage. The encryption techniques (e.g., selection of cryptographic algorithms or implementations thereof) used by the sensor control device 102 may be selected based at least in part on these limitations. The data receiving device 120 may be a more powerful device with fewer limitations of this nature. Thus, the data receiving device 120 may use more sophisticated and computationally intensive encryption techniques, such as cryptographic algorithms and implementations.
[0167] The sensor control device 102 can be configured to modify its discoverability behavior to increase the probability that a receiving device will receive a proper data packet and / or provide an acknowledgment signal, or to attempt to reduce limitations that may otherwise result in a lack of ability to receive an acknowledgment signal. Modifying the discoverability behavior of the sensor control device 102 can include, by way of example and not limitation, modifying how often connection data is included in data packets, modifying how often data packets are transmitted in general, lengthening or shortening the broadcast window for data packets, modifying the amount of time the sensor control device 102 waits to receive an acknowledgment signal or a scanning signal after a broadcast that includes a directional transmission (e.g., via one or more trial transmissions) to one or more devices that were previously in communication with the sensor control device 102 and / or one or more devices on a whitelist, modifying the transmit power associated with the communications module when broadcasting a data packet (e.g., to increase the distance of the broadcast or reduce energy consumption to extend the battery life of the analyte sensor), modifying the rate at which data packets are prepared and broadcast, or a combination of one or more other modifications. Additionally or alternatively, the receiving device may also adjust parameters associated with the device's listen behavior to increase the likelihood of receiving data packets containing connection data.
[0168] As embodied herein, the sensor control device 102 can be configured to broadcast data packets using two types of windows. The first window relates to the rate at which the sensor control device 102 is configured to operate its communications hardware. The second window relates to the rate at which the sensor control device 102 is configured to enter an active transmission (e.g., broadcast) state for data packets. As an example, the first window may indicate that the sensor control device 102 operates its communications hardware to transmit and / or receive data packets (including connection data) during the first two seconds of each 60-second period. The second window may indicate that the sensor control device 102 transmits a data packet every 60 milliseconds during each two-second window. The remaining time during the two-second window, the sensor control device 102 is scanning. The sensor control device 102 can extend or shorten either window to modify its discoverability behavior.
[0169] In certain embodiments, the discoverability behavior of an analyte sensor can be stored in a discoverability profile, and modifications can be made based on one or more factors, such as the status of the sensor controlling device 102, and / or by applying rules based on the status of the sensor controlling device 102. For example, these rules can cause the sensor controlling device 102 to reduce power consumed by the broadcast process when the battery level of the sensor controlling device 102 drops below a predetermined amount. As another example, configuration settings related to broadcasting or otherwise transmitting packets can be adjusted based on the ambient temperature, the temperature of the sensor controlling device 102, or the temperature of certain components of the communication hardware of the sensor controlling device 102. In addition to modifying transmission power, other parameters related to the transmission function or transmission process of the communication hardware of the sensor controlling device 102 can be modified, including, but not limited to, the rate, frequency, and timing of transmission. As another example, when analyte data indicates that a subject is experiencing or about to experience an adverse health event, the above-described rules can cause the sensor controlling device 102 to increase its discoverability in order to alert receiving devices of this adverse health event.
[0170] As embodied herein, certain calibration functions for the sensing hardware 5060 of the sensor control device 102 can be adjusted based on external or internal environmental functions, and also to compensate for natural degradation of the sensing hardware 5060 during extended periods of non-use (e.g., a "shelf life" before use). The calibration functions of the sensing hardware 5060 can be adjusted autonomously by the sensor control device 102 (e.g., by operation of the ASIC 5000 which modifies functions in memory 5020 or storage 5030) or by other devices in the analyte monitoring system 100.
[0171] As an example, the sensor sensitivity of the sensing hardware 5060 can be adjusted based on external temperature data or time since manufacture. When external temperature is monitored during sensor storage, the presently disclosed subject matter can adaptively change sensor sensitivity compensation over time as the device experiences changing storage conditions. By way of example and not limitation, adaptive sensitivity adjustment can be performed using an “active” storage mode in which the sensor control device 102 is periodically woken to measure temperature. These features can conserve the battery of the analyte device and extend the life of the analyte sensor. During each temperature measurement, the sensor control device 102 can calculate a sensitivity adjustment amount for that period based on the measured temperature. The temperature-weighted adjustment amounts can then be accumulated over the active storage mode period to calculate a total sensor sensitivity adjustment value at the end of the active storage mode (e.g., upon insertion). Similarly, upon insertion, the sensor control device 102 can determine the time difference between its or the sensing hardware 5060's manufacture (which can be written to the ASIC 5000's storage 5030) and modify the sensor sensitivity or other calibration functions according to one or more known natural degradation rates or natural degradation formulas.
[0172] Additionally, for purposes of illustration and not limitation, as embodied herein, the sensor sensitivity adjustment can account for other sensor conditions, such as sensor drift. For example, in the event of sensor drift, the sensor sensitivity adjustment amount can be hard-coded into the sensor control device 102 during manufacturing based on an estimate of how much an average sensor is likely to drift. The sensor control device 102 can use a calibration function having time-varying functions related to the sensor's offset and gain that can account for drift over the sensor's wear period. Thus, the sensor control device 102 can account for the sensor control device's 102 drift over time, express sensor sensitivity, and further utilize device-dependent functions, which may be device-specific, in combination with a glucose profile baseline used to convert interstitial current to an interstitial glucose value. Such functions that account for sensor sensitivity and drift can improve the accuracy of the sensor control device 102 over the wear period without requiring user calibration.
[0173] The sensor control device 102 detects raw measurements from the sensing hardware 5060. Sensor-related processing can be performed, such as by one or more models trained to interpret the raw measurements. The models can be machine learning models trained off-device to detect, predict, or interpret the raw measurements to detect, predict, or interpret one or more analyte levels. Yet another training model can be acted upon based on the output of a machine learning model trained to interact with the raw measurements. As an example, a model can be used to detect, predict, or recommend an event based on the raw measurements and the type of analyte detected by the sensing hardware 5060. Events can include the initiation or completion of a physical activity, a meal, the application of a medical procedure or medication, an emergency health event, and other events of a similar nature.
[0174] The model may be provided to the sensor controlling device 102, data receiving device 120, or general-purpose data receiving device 130 during manufacturing or during firmware or software updates. The model may be periodically refined, such as by the manufacturer of the sensor controlling device 102 or the operator of the analyte monitoring system 100, based on data received from the sensor controlling device 102 and data receiving devices of an individual user or multiple users collectively. In certain embodiments, the sensor controlling device 102 includes sufficient computer components to facilitate further training or refinement of the machine learning model based, for example, on the unique characteristics of the user to which it is attached. Machine learning models may include, by way of example and not limitation, models trained using or incorporating decision tree analysis, gradient boosting, adaptive boosting, artificial neural networks or variants thereof, linear discriminant analysis, nearest neighbor analysis, support vector machines, supervised or unsupervised classification, and others. In addition to machine learning models, models may include algorithmic or rule-based models. The model-based processing may be performed by the data receiving device 120 or other devices, including the general-purpose data receiving device 130, upon receiving data from the sensor control device 102 (or other downstream devices).
[0175] Data transmitted between the sensor control device 102 and the data receiving device 120 may include raw or processed measurements. Data transmitted between the sensor control device 102 and the data receiving device 120 may further include alarms or notifications for display to a user. The data receiving device 120 may display or otherwise communicate notifications to a user based on the raw or processed measurements, or may display alarms when received from the sensor control device 102. Alarms that can be triggered for display to a user include alarms based on direct analyte values (e.g., a transient reading that exceeds or fails to meet a threshold), trends in analyte values (e.g., average readings that exceed or fail to meet a threshold over a set period of time, slope), predictions of analyte values (e.g., when an algorithmic calculation based on the analyte value exceeds or fails to meet a threshold), sensor alerts (e.g., detection of a suspected malfunction), communication alerts (e.g., when an unknown device attempts or fails to initiate a communication session with the sensor controlling device 102 when there has been no communication between the sensor controlling device 102 and the data receiving device 120 for a threshold period of time), reminders (e.g., reminders to charge the data receiving device 120, reminders to take medication or perform other activities), and other alerts of a similar nature. By way of example and not limitation, as embodied herein, the alarm parameters described herein can be configurable by the user, or can be fixed during manufacturing, or can be a combination of user-configurable and non-user-configurable parameters.
[0176] As described herein, a software library integrated into software executing on the receiving device can facilitate communication with the analyte sensors and allow third-party applications to access sensor data for use in medically necessary applications or applications related to the health of a user. The software library can be implemented independently of the sensor and integrated into the third-party application to enable access to the sensor data. Furthermore, the sensor control module can communicate with multiple sensor assemblies in a manner to receive data from such sensor assemblies simultaneously or substantially simultaneously. The system further enables transfer of sensor information from the sensor control module to a remote management module.
[0177] FIG. 18 illustrates an example environment 1800 of an example analyte monitor system 100 in accordance with the technology described herein and the data flow between the various components of the system.
[0178] Environment 1800 includes a remote application server 155 associated with analyte monitoring system 100, a general-purpose device 130, and a data monitor device 135. Multi-purpose device 130 is running a monitor application 1810a associated with analyte monitoring system 100. Data monitor device 135 is running a monitor application 1810b. In certain embodiments, data monitor application 1810a and data monitor application 1810b may be the same application provided by analyte monitoring system 100. In certain embodiments, data monitor application 1810a and data monitor application 1810b may be applications customized to run specifically on their respective devices or operating systems.
[0179] As described herein, the multi-purpose device 130 may be a personal device of a user wearing the sensor control device 102. The sensor control device 102 may provide data to the multi-purpose device 130 directly or indirectly (e.g., through the data receiving device 120). The multi-purpose device 130 may include, for example, the user's smart phone or smart watch running one or more applications or software libraries provided by the analyte monitoring system 100. The multi-purpose device 130 provides services to the user for functions specifically associated with the analyte monitoring system 100, as well as other functions. In certain embodiments, the multi-purpose device 130 may include additional sensing or other hardware to provide functionality related to the analyte monitored by the sensor control device 102. As an example, the multi-purpose device may include an insulin pump or connected insulin pen, and the monitored analyte may be glucose or other analytes related to diabetes or other related disorders.
[0180] The data monitor device 135 may be a personal device of a user who is not wearing the sensor control device 102. In particular, the data monitor device 135 may refer to a device that receives information related to a user's monitored analyte levels through a remote application server 155. In particular, the remote application server 155 may be configured to communicate analyte levels, alerts based thereon, and other information to the monitor application 1810b for review by the user of the data monitor device 135. In other respects, the data monitor device 135 may be similar to the multi-purpose device 130 in that it may provide other functions for the user of the data monitor device 135 in addition to receiving the analyte levels being monitored.
[0181] Environment 1800 further includes notification service 1820. Notification service 1820 may be a service managed by a third party to facilitate timely and efficient delivery of messages to general purpose device 130 and data monitor device 135 (or, in certain embodiments, any device running an instance of data monitor application 1810).
[0182] According to certain embodiments, the analyte monitor system 100 may provide a mechanism for encouraging a user wearing a sensor control device 102 to share certain information with one or more monitor users. The user wearing the sensor control device 102 or another authorized user can determine which specific users or data monitor devices 135 will receive information and can select what type of information to share. The general-purpose device 130 or user device 140 then provides data from the user's sensor control device 102 to a remote application server 155, which can then send some or all of the information to a specific data monitor device 135. In one example, a user may allow their parent to receive current values for the level of a specific analyte measured by the sensor control device 102. In addition, the user may allow the parent to receive certain alerts based on the level of a specific analyte, such as alerts that are triggered when the analyte level exceeds one or more preselected thresholds. In certain embodiments, the user may customize the alerts that are sent to the data monitor device 135 if a problem is allowed to persist for a threshold period of time. As described herein, many other types of alerts can be sent to the data monitoring device 135. If the user of the data monitoring device 135 has enabled some or all of these alerts to be displayed as alerts or notifications on the data monitoring device 135, the remote application server 155 can send these notifications to the data monitoring device 135 when the alert conditions are met. The notifications can be sent through notification service 1820.
[0183] In certain embodiments, notification service 1820 may be operated or facilitated by the provider of general purpose device 130, data monitor device 135, or the operating system and other software environment running on these devices. The notification service may be a more efficient system for providing certain push notifications to data monitor device 135. In certain embodiments, the provider of data monitor device 135 may only enable push notifications to data monitor device 135 through notification service 1820 or an equivalent. Certain embodiments disclosed herein enable remote application server 155 to utilize notification service 1820 as intended.
[0184] In certain embodiments, the notification service 1820 may additionally or alternatively be provided by or as part of the analyte monitor system 100. Furthermore, the notification service 1820 is illustrated only as a single entity for purposes of simplicity. It will be understood that the notification service 1820 may include multiple opposing or cooperating notification services 1820 (e.g., intended for different device platforms or operating systems). Furthermore, the notification service may include multiple servers working in coordination and which may be geographically distinct.
[0185] In particular embodiments, the notification service 1820 can be configured to receive requests from the remote application server 155 to send notifications to one or more devices running an instance of the monitor application 1810. The requests can vary based on the number of messages to be sent, whether the messages should be repeated or recurring, and the number and selection of devices to receive a particular message or messages. As one example, a request from the remote application server 155 can include a request to send a single notification to a single device. As another example, a request can include a request to send a single notification to multiple devices simultaneously. As another example, a request can include a request to send multiple notifications to a single device at once. As another example, a request can include a request to send one or more notifications to a single device repeatedly (e.g., every hour, every five hours, every 12 hours, every 24 hours, every week, etc.). Additionally, other combinations of these elements can be included in the request.
[0186] Additionally or alternatively, the request may be customized based on which devices are selected to receive the notification. As one example, the remote application server 155 may determine that a particular data monitoring device 135 should receive the notification as soon as possible. Such a notification may be an alert based on the status of a user wearing a particular sensor control device 102 or the status of the sensor control device 102 itself. As another example, the remote application server 155 may determine that all data monitoring devices 135 manufactured by a particular manufacturer and running a particular operating system or version of the monitor application 1810 should receive the notification. Such a notification may be a recommendation to update the instance of the monitor application 135 running on the data monitoring device 135. As another example, the remote application server 155 may determine that all data monitoring devices 135 in communication with the analyte monitoring system 100 should receive the notification periodically. As described herein, such notifications may include system-wide announcements or so-called “heartbeat” notifications used to verify that an active communication channel is available between the remote application server 155 and the data monitoring device 135.
[0187] FIG. 19 illustrates an exemplary method 1900 for providing notification that there are no available or alternatively unresponsive communication channels between devices in an analyte monitoring system in accordance with certain embodiments. Method 1900 may be performed by devices within the operating environment 1800 shown in FIG. 18 , where the analyte monitoring system 100 uses a notification service 1820 to facilitate delivery of notifications to multiple data monitoring devices 135 or general-purpose devices 130 running multiple instances of a monitoring application 1810 a or 1810 b. For clarity, FIG. 19 illustrates only a single instance of the monitoring application 1810. However, it should be understood that these techniques are applicable to environments in which multiple instances are run by multiple devices.
[0188] In 1901, the remote application server 155 schedules silent notifications for connectivity alerts. As described herein, connectivity alerts are provided to enable the monitor application 1810 to send notifications to end users establishing when the communication channel between the remote application server 155 and the monitor application 1810 is unresponsive. The communication channel may be unresponsive for a variety of reasons, including those originating in or caused by the device running the monitor application 1810 or the remote application server 155. As described, the analyte monitor system 100 uses a notification service 1820 to facilitate efficient delivery of notifications to instances of the monitor application 1810. In some cases, notifications are associated with individual or personal data, and therefore, notifications generated by the remote application server 155 for distribution through the notification service 1820 may have only limited recipients (e.g., one recipient). In some cases, notifications are global or system-wide. Using the notification service 1820, the remote application server 155 can schedule both types of notifications by sending a single configuration message to the notification service.
[0189] In 1911, the notification service 1820 (e.g., its server) receives a request including instructions to schedule a silent notification for a connectivity alert. The notification service 1820 configures the notification for delivery to an appropriate application instance. The request from the remote application server 155 can determine the appropriate application instance or indicate a population to receive the notification. In the example of a connectivity alert notification, the intended recipients can include, as examples, all users or all users remotely monitoring another user's analyte level. The intended recipients may be further limited based on technical limitations or constraints. As an example, the remote application server 155 can first schedule an alert for a user of a first mobile device operating system, and then schedule an alert for a user of a second mobile device operating system. Configuring the notification can further include selecting how the receiving device is to handle the notification. In the case of a silent notification for a connectivity alert, the notification service 1820 may determine that the receiving device (or instance of the monitor application 1810) will not take any user-directed action (e.g., will not issue a visual, audible, or tactile alarm), but will take certain steps in accordance with those disclosed herein.
[0190] At 1913, the notification service 1913 pushes the configured notifications to the appropriate application instances. As an example, notifications can be pushed to all devices running an instance of a particular version of the monitor application 1810.
[0191] At 1921, the monitor application determines the type of notification when it receives a notification from the notification service 1820. In the illustrated example, the type of notification indicates that it is a silent notification from the remote application server 155 that is used to track the status of the communication channel between the remote application server 155 and the instance of the monitor application 1810. In some embodiments, such notifications may be referred to as heartbeat notifications.
[0192] After determining that the notification is a heartbeat notification, the monitor application 1810 cancels any previously scheduled user-facing connectivity alerts. As described above in this specification, the monitor application 1810 is configured to start a timer that essentially counts the time since the application last received a communication from the remote application server 155. When the application receives a new communication from the remote application server 155, the timer is restarted. To restart the timer, the monitor application 1810 can delete any pending user-facing alerts.
[0193] At 1922, the monitor application starts a new timer by scheduling a new user-facing connectivity alert. The connectivity alert can be associated with a new timer, and the amount of time associated with the timer can be determined based on, for example, a hard-coded value, a value provided by the remote application server 155 (e.g., in the request to schedule a new communication), a value provided by the notification service 1820 (e.g., based on a rate limit imposed by the notification service 1820), or a value provided by the user of the monitor application 1810. The new connectivity alert can schedule a user-facing notification to be displayed by the monitor application 1810. The connectivity alert can alert the user that the monitor application 1810 has been unable to communicate with the remote application server 155 for an extended period of time (or a user-defined period, if desired) or that the communication channel between the remote application server 155 and the monitor application 1810 has become otherwise unresponsive.
[0194] The method 1900 may be repeated periodically by the remote application server 155 periodically scheduling silent notifications for connectivity alerts provided to instances of the monitor application 1810 so that the monitor application 1810 can determine whether the communication channel between the remote application server 155 and the monitor application 1810 remains up and available. As an example, the time associated with the connectivity alert may be set to 30 minutes. The remote application server 155 may send a silent "heartbeat" notification concurrently with the timer (e.g., every 30 minutes). In certain embodiments, the remote application server 155 may use a period shorter than the timer (e.g., 5 minutes shorter than the timer) to avoid or prevent intermittent pauses.
[0195] FIG. 20A illustrates an exemplary method for determining the availability of communication channels between devices in an analyte monitoring system and providing notification of lost connectivity on a communication channel or alternatively, a non-responsive communication channel, according to certain embodiments. Method 2000a may be performed by devices within the operating environment 1800 shown in FIG. 18, where the analyte monitoring system 100 uses a notification service 1820 to facilitate delivery of notifications to multiple data monitoring devices 135 or general-purpose devices 130 running multiple instances of a monitoring application 1810a or 1810b. For clarity, FIG. 20A illustrates only a single instance of the monitoring application 1810. However, it should be understood that these techniques are applicable to environments in which multiple instances are run by multiple devices.
[0196] In 2001, the remote application server 155 receives sensor data emitted from the sensor control device 102. In certain embodiments, the sensor data may be sent directly from the sensor control device 102 or may be sent through the general purpose device 130 or the user device 140. As will be explained, the remote application server 155 may perform post-processing of the data upon the satisfaction of certain conditions, allowing alerts to be sent to certain users, including those other than the user wearing the sensor control device 102.
[0197] In 2002, the remote application server 155 processes the data and detects that an alert condition has been satisfied based on the data. As an example, the sensor data can be associated with analyte level values detected in the bodily fluid of a user wearing the sensor control device 102. The alert condition can specify a threshold level of the analyte for dangerously high or low levels, a rate of change of the analyte level, an expected or anticipated high or low level or rate of change, a level for a particular time, and other similar conditions. The remote application server 155 can be configured to provide the alert condition information to one or more users running a monitoring application 1810 on the general-purpose device 130 or other data monitoring device 135, for example, based on user permission and instructions received from the user wearing the sensor control device 102. To do so, the remote application server 155 can request that an alert notification be pushed to the monitoring application 1810 by the notification service 1820.
[0198] In 2011, notification service 1820 receives a request to push an alert notification from remote application server 155. The request from remote application server 155 can determine which one or more instances of monitor application 1810 should receive the alert notification, specify the body of the alert notification, and provide other details that enable the notification service to customize and deliver the alert notification.
[0199] In 2012, the notification service pushes alert notifications to appropriate instances of the monitor application, for example, following requests from a remote application server.
[0200] In 2021, the monitor application 1810 receives the alert notification and outputs its user-facing components. For example, the monitor application 1810 can provide a one-time or recurring visual, auditory, or tactile output to the user of the monitor application after consulting user settings regarding the type and severity of the alert.
[0201] At the same time, the monitor application 1810 can interpret the notification from the remote application server 155 as evidence that the communication channel between the remote application server 155 and the monitor application 1810 is up. At 2022, the monitor application cancels any previously scheduled connectivity alerts for the user. Thus, operation at 2022 can be similar to operation at 1921 of method 1900. The timer is restarted when the application receives any new communication from the remote application server 155, including an alert notification from the remote application server 155.
[0202] At 2023, the monitor application starts a new timer by scheduling a new user-facing connectivity alert, similar to the operations performed at 1922 of the method 1900.
[0203] FIG. 20B illustrates another exemplary method for providing notification that there are no available or alternatively unresponsive communication channels between devices in an analyte monitoring system in accordance with certain embodiments. Method 2000a may be performed by devices within the operating environment 1800 shown in FIG. 18, where the analyte monitoring system 100 uses a notification service 1820 to facilitate delivery of notifications to multiple data monitoring devices 135 or general-purpose devices 130 running multiple instances of a monitoring application 1810a or 1810b. For clarity, FIG. 20B illustrates only a single instance of the monitoring application 1810. However, it should be understood that these techniques are applicable to environments in which multiple instances are run by multiple devices.
[0204] As described herein, timers used by the monitoring application 1810 can be reset or replaced when any communication originating from the remote application server 155 is received by the monitoring application 1810. By way of example, in some embodiments, the remote application server 155 can send other data (e.g., non-alert data) to an instance of the monitoring application 1810. Exemplary data might include data with simple specimen levels or other sensitive patient information. Because the data is received directly from or sent on behalf of the remote application server 155, the monitoring application 1810 can interpret the sending of the data as evidence that the communication channel is up and available.
[0205] In 2024, the monitor application 1810 can request data from the remote application server 155. As an example, the monitor application 1810 can detect that a timer associated with data freshness has expired and stop waiting for data to be pushed to the monitor application from the remote application server 155. Alternatively, the monitor application can actively request the missing data. A user of the monitor application 1810 can manually request data freshness.
[0206] In 2003, the remote application server 155 may receive and process the request from the monitor application 1810. By way of example only and not limitation, processing the request may include determining, based on the request, whether there is further data available to the monitor application 1810.
[0207] In some examples, notification service 1820 receives requests for remote application servers 155 from monitor application 1810 and sends data requests to remote application servers 155 on behalf of monitor application 1810. In such embodiments, notification service 1820 acts as a middleman for remote application servers 155. This allows for greater flexibility regarding the configuration of remote application servers 155, and remote application servers 155 can notify notification service 1820 of changes to where such requests are sent without notifying monitor application 1810.
[0208] In 2004, the remote application server 155 can send the request data to the application instance of the monitor application 1810; in some examples, the data is communicated to the monitor application 1810 through a notification service 1820. As an example, sending the request data to the monitor application 1810 can include sending the data intended for the monitor application 1810 to the notification service 1820. In 2013, the notification service 1820 receives the data intended for the monitor application 1810 from the remote application server 155. The notification service 1820 then communicates the data to the monitor application 1810 on behalf of the remote application server 155. In some examples not shown, the data is sent directly to the monitor application 1810, bypassing the notification service 1820, which can reduce the potential delay between when the remote application server 155 sends the data and when the monitor application 1810 receives the data.
[0209] At 2025, the monitor application 1810 receives the requested data from the remote application server 155. As described herein, this receipt of data also serves as proof to the monitor application 1810 that the connection between the remote application server 155 and the monitor application 1810 is up and available. Thus, at 2026 as well as 2022, the monitor application 1810 can abort any pending connectivity alerts. Additionally, at 2027 as well as 2023, the monitor application 1810 can schedule new connectivity alerts.
[0210] The monitor application can cancel the previous user-facing connectivity alert at 2022 and schedule a new connectivity alert 2023 according to the techniques described herein. In some examples, the data can be pushed by a remote application server 155. In some examples, the data can be requested by the monitor application.
[0211] 21 illustrates an exemplary method for providing notification that there are no available or alternatively unresponsive communication channels between devices in an analyte monitoring system in accordance with certain embodiments. Method 2100 may be performed by any device within the analyte monitoring system 100 that displays data and notifications directly to a user of the analyte monitoring system. In certain embodiments, method 2100 is performed by a data monitor device 135 that receives data from a remote application server 155 of the analyte monitoring system (rather than a device that receives data directly from the sensor control device 102). In particular embodiments, method 2100 is performed by an instance of a monitor application 1810 provided by the analyte monitoring system 100.
[0212] At 2110, the application checks a local "heartbeat" timer. The heartbeat timer is so called because it acts, for example, as a mechanism for checking the expiration of a communication channel between the application and the remote application server 155. In the exemplary method 2100, the heartbeat timer is maintained locally by an instance of the monitor application 1810. The heartbeat timer can be started according to embodiments disclosed herein.
[0213] At 2115, the application determines whether a local heartbeat timer has expired. As one example, the heartbeat timer may be a countdown timer, and determining whether the timer has expired may include checking whether a value is less than or equal to zero. The countdown timer may be started with a preset value. As another example, the heartbeat timer may be a countup timer, and determining whether the timer has expired may include checking whether a value is greater than or equal to the preset value. As another example, the heartbeat timer may expire by comparing a recorded start time (e.g., saved by the application when the heartbeat timer started) with the current time and determining whether the difference between the start time and the current time exceeds the preset value. In all instances, the preset value is associated with the length of the heartbeat timer. The length of the heartbeat timer can be determined based on, for example, a hard-coded value, a value provided by the remote application server 155 (e.g., in a request to schedule a new communication), a value provided by the notification service 1820 (e.g., based on a rate limit imposed by the notification service 1820), or a value provided by a user of the monitor application 1810.
[0214] If the heartbeat timer has not expired, then the application advances a local heartbeat timer at 2120. For example, the current value of a count-up timer may be incremented or the current value of a count-down timer may be decremented. If the monitor application 1810 was in a dormant or low-power state prior to the operation at 2110, the monitor application 1810 may return to a dormant or low-power state until the next time it performs the operation at 2110 again.
[0215] If the heartbeat timer expires at 2115, the communication channel between the monitoring application 1810 and the remote application server 155 is suspected to be unresponsive or otherwise unavailable. The monitoring application 1810 can optionally take one or more explicit steps to establish or test a communication channel with the remote application server. As an example, the monitoring application attempts to establish a secondary connection between the monitoring application 1810 and the remote application server 155 at 2125. For example, the monitoring application 1810 can attempt to explicitly establish a connection (e.g., in lieu of notification or data transmission from the remote application server 155). Additionally or alternatively, the monitoring application 1810 can attempt to establish a communication channel with another remote application server 155 associated with the analyte monitoring system 100. For example, the application monitoring system 100 can include various remote application servers 155 that are geographically dispersed to improve latency and responsiveness. The monitoring application 1810 can attempt to connect to one or more designated backup remote application servers 155. In some embodiments, the analyte monitor system 100 may automatically designate a standby remote application server 155, for example, in a cloud server architecture.
[0216] If the monitor application 1810 is able to establish a secondary server connection, then at 2130 the monitor application 1810 may report the server connectivity problem to the remote application server 155. The monitor application 1810 may reset a local heartbeat timer.
[0217] If the monitor application 1810 is unable to establish a secondary server connection, then at 2140 the monitor application 1810 outputs a server connectivity alert. As an example, the monitor application 1810 may output a notification to the user of the monitor application 1810 indicating that there may be a problem with the communication channel between the remote application server 155 and the monitor application 1810 or that the communication channel has become otherwise unresponsive. The notification may indicate one or more possible causes of the problem and, depending on the possible causes, suggest possible approaches to re-establishing or repairing the communication channel. The notification may be provided as a visual, audible, or tactile alert on the data monitor device 135. The notification may be provided as a banner or other type of notification within the monitor application 1810 while the communication channel remains unresponsive (e.g., until an alternate communication channel is established or the existing communication channel is modified). Additionally, the notification may inform the user of the potential impact of a communication channel being unresponsive (e.g., temporarily unavailable), including, but not limited to, no data being sent regarding the monitored user's analyte level, no alerts being sent regarding analyte levels, and no recommendations being sent based on analyte levels. The notification may encourage the user to contact the monitored user when possible. For example, the notification may indicate the last known value of the analyte level or the last known status of the monitored user and instruct the user to contact the monitored user using conventional communication mechanisms if the last known value or last known status is of concern.
[0218] Figure 22 illustrates an exemplary method for providing notification that there are no available communication channels, e.g., a non-responsive communication channel, between devices in an analyte monitoring system in accordance with certain embodiments. While Figure 21 provided an example of an initial response by the monitor application 1810 to a determination that a local heartbeat timer has expired, the method 2200 of Figure 22 includes a more detailed analysis that can be performed by the monitor application 1810 to provide detailed instructions, recommendations, or next steps to a user of the monitor application 1810.
[0219] At 2205, the monitoring application 1810 receives data corresponding to the status of the monitored user from the remote application server 155. As an illustrative example, the monitoring application 1810 receives current (e.g., most recent) and historical values of the analyte level being monitored by the monitor user. The historical values can be used, for example, to backfill missing data and / or to enable more complex analysis and tracking than simply recording the “current” value. Additionally or alternatively, the “current” value may be associated with a different withdrawal or sampling rate than the historical data and therefore may not be directly comparable. While described as analyte level values for illustrative purposes, the current and historical data may include other information provided by or related to the monitored user. By way of example, in addition to analyte level values, the data may include detected or predicted alert conditions, events (e.g., medication administration or eating) related to the monitored user's health and potentially related to the analyte level.
[0220] In certain embodiments, the monitoring application 1810 is configured to store historical analyte level values over a predetermined period of time. As will be described, these stored historical values can be used to fill in missing data under certain circumstances. Thus, at 2210, the monitoring application 1810 can optionally provide the historical values for storage. Providing the historical values can include using or performing one or more operations on the data to facilitate secure storage on the data monitor device 135. By way of example, the monitoring application 1810 can encrypt the historical values, anonymize the historical values, label the historical values, associate certain events with the historical values, add additional time stamps to the historical values, or perform other operations to improve the quality and security of the analyte level data.
[0221] At 2215, the monitor application 1810 can store past values in memory of the data monitor device 135. In certain embodiments, past values are stored for a predetermined period of time or until associated with a particular duration. For example, past values can be automatically purged after 30 days, 14 days, 7 days, etc. As another example, past values can be automatically purged after being stored for a particular period of time.
[0222] At 2220, the monitor application 1810 displays the current and / or past values in its user interface.
[0223] In 2225, the monitor application 1810 detects that the communication channel between the remote application server 155 and the monitor application 1810 is unresponsive or otherwise unavailable. The monitor application 1810 may perform this detection using techniques consistent with those discussed herein. In certain embodiments, the monitor application may record the current geolocation of the data monitor device 135 when it first determines that the channel is unresponsive. In certain embodiments, this geolocation information may be provided to the remote application server 155 when the connection is restored. The remote application service 155 may use the approximate or precise geolocation data to suggest data loss mitigation techniques to the user, such as determining that the user is approaching an area known to cause data loss.
[0224] In 2230, monitor application 1810 determines one or more possible causes why the communication channel has become unresponsive. Depending on the type of problem, monitor application 1810 provides one or more notifications that are displayed as connectivity alerts to notify the user of monitor application 1810 that the communication channel is unresponsive, as well as to provide suggestions on how the possible causes may be corrected.
[0225] In 2235, the monitor application 1810 has determined that possible causes include one or more device or application problems. As one example, the monitor application 1810 may determine that an error has occurred within it that may be preventing a communication channel from responding. As another example, the monitor application 1810 may determine that it does not have proper permissions to use certain features of the data monitor device 135 necessary for its operation. As another example, the monitor application 1810 may determine that the data monitor device 135 does not have a working Internet connection or has enabled airplane mode.
[0226] At 2240, the monitor application 1810 prepares a notification to be displayed as or with a connectivity alert that includes steps that may resolve one or more problems with the device or application. In this case, the user may be able to resolve these problems by having these applications and devices at hand. Thus, the notification may include a preliminary identification of possible problems and simple steps to resolve them.
[0227] At 2265, the monitoring application 1810 modifies any form of its output in response to detecting that the communication channel between the monitoring application 1810 and the remote application server 155 is not responding. As one example, modifying the output of the monitoring application 1810 may include limiting the output of certain information, such as values related to current or past sensor data, to indicate that the active communication channel is unavailable. As another example, modifying the output of the monitoring application 1810 may include limiting or preventing certain functions of the monitoring application 1810. These functions may include the ability to review past data associated with a certain period of time or the ability to change settings associated with the analyte monitoring system 100. As another example, modifying the output of the monitoring application 1810 may include identifying and displaying the last known status of the sensor data or the corresponding sensor control device 102. The last known status may indicate that the current status (or sensor data) is unavailable, but may include a timestamp to indicate the duration of the last known status so that the user can respond accordingly. As an example, the last known status may be determined based on comparing the value of the most recent sensor data to one or more thresholds, each for a respective last known status.
[0228] At 2270, the monitor application outputs the provided notification. As one example, the notification can be a visual notification that is displayed temporarily or persistently within the monitor application 2270 (e.g., until the communication channel is re-established or is found to be responsive again). As another example, the notification can be a visual notification that is displayed on one or more screens (e.g., lock screen, home screen, message screen, etc.) of the data monitor device 135. In another example, the notification can include one or more non-visual components, including, but not limited to, an auditory or tactile component, to further alert the user that the communication channel is not responding and that data and alerts will be delayed while the problem persists. The notification can include additional information provided in steps 2240, 2255, or 2260 depending on the type and nature of the possible cause of the communication channel between the remote application server 155 and the monitor application 1810.
[0229] Returning to 2230, the monitoring application 1810 may determine that possible causes include a server problem. At 2245, the monitoring application 1810 has determined that possible causes include a server problem. The server problem may include an expected or unexpected outage within the remote application server 155 (or another server in the analyte monitoring system 100). As an example, the remote application server 155 may notify users in advance of a maintenance schedule. The monitoring application 1810 may determine whether the state and status of the unresponsive communication channel corresponds to a planned server outage. Furthermore, the monitoring application 1810 may determine that there is no known condition related to the data monitoring device 135 or the monitoring application 1810 and conclude that the problem may be a problem associated with the server.
[0230] At 2250, the monitoring application 1810 determines whether a backup communication channel between itself and the remote application server 155 is available. As one example, the backup communication channel may include the use of a different communication protocol to receive sensor data. As one example, the backup communication channel may include an SMS message provided to the user of the data monitoring device 135 at the request and permission of the user wearing the sensor control device 102. As another example, the backup communication channel may include communication with a different remote application server 155 within the analyte monitoring system 100. For example, the analyte monitoring system 100 may provide multiple geographically distinct remote application servers 155. While a nearby remote application server 155 may be preferred for use, if only one remote application server 155 or cluster of remote application servers 155 is unavailable, the monitoring application 135 may attempt to communicate with a distant remote application server 155 or a remote application server 155 located in another country.
[0231] If a backup channel is available, then at 2255 the monitor application prepares a notification to be displayed as or with a connectivity alert containing an announcement that a potential problem associated with the connection between the monitor application 1810 and the remote application 155 has been detected. However, because there is a backup communication channel available, the notification may further note that data from the remote application server 155, e.g., current values or alerts, can still be sent, although possibly with a delay.
[0232] If a backup channel is not available, then at 2260 the monitor application prepares a notification to be displayed as or with a connectivity alert containing an announcement that a potential problem associated with the connection between the monitor application 1810 and the remote application 155 has been detected. Because a backup communication channel is not available, the notification indicates that data from the remote application 155 will be unavailable until the problem is resolved. The notifications prepared at 2255 and 2260 may further include contacting the provider of the remote application server 155 to determine whether there are other possible steps to resolve the detected problem.
[0233] 23-25 illustrate exemplary user interfaces for applications running on the data monitor device 135 associated with the analyte monitor system.
[0234] 23 illustrates a first user interface 2300 illustrating a notification 2305 that may be displayed on the data monitoring device 135 when it is detected that the communication channel between the data monitoring device 135 and the remote application server 155 is not responding. In particular, the notification 2305 indicates that the data monitoring device 135 has lost connection with the remote application server 155 and has not received data within a predetermined period of time. The notification 2305 indicates that the data monitoring device 135 will not receive sensor data until the problem is resolved.
[0235] 23 also illustrates a second user interface 2310 showing a notification 2315 that may be displayed when the connection between the data monitor device 135 and the remote application server 155 is restored or otherwise determined to be responsive again. In certain embodiments, when the connection is restored, the remote application server 155 may cause the monitor application 1810 to send current values and missing historical data (e.g., corresponding to periods when the connection was unresponsive) for review and storage.
[0236] As described herein, both notification 2305 and notification 2315 may be displayed on the lock screen of data monitor device 135, on the home screen of data monitor device 135 (e.g., when data monitor device 135 is running but not running a particular application in the foreground), as a banner notification when a different application is running in the foreground, or as a notification within monitor application 1810 when monitor application 1810 is running in the foreground. Additionally, notifications 2305 and 2310 may be displayed using various form factors specific to the particular operating system or environment of data monitor device 135. In certain embodiments, notification 2305 may be persistently displayed within the user interface of data monitor device 135 while the communication channel remains unresponsive (e.g., either displayed within monitor application 1810 or as a notification overlaying another application).
[0237] FIG. 24 illustrates a first user interface 2400 depicting an exemplary home screen of the monitor application 1810 when the communication channel between the data monitor device 135 and the remote application server 155 is unresponsive. The home screen includes several display items indicating that recent data is unavailable and other display items indicating that the communication channel is unresponsive. As an example, the first panel 2403 of the home screen, which would normally show the most recent analyte level received from the remote application server 155, instead shows no value, indicating that recent data is unavailable. In certain embodiments, instead of showing a value, the first panel 2403 may show the most recent value in terms of a time stamp or other indicator of the duration of the value. In this way, the user of the data monitor device 135 can be reminded of the last known status of the user wearing the sensor control device 102 that measured the value, even if the displayed information prompts further action by the user. The last known status information may include last known trend information for the analyte value (e.g., increasing, decreasing, rapidly decreasing) or a predicted current value based on the last known trend information and other activity information. As another example, a second panel 2405 that would normally show a graph of historical values of analyte levels over time instead shows only an empty set of axes, thereby indicating that historical values are also unavailable.
[0238] Another user interface element includes a button 2407 that a user can select to access the logbook of the monitor application 1810. In certain embodiments, a user of the monitor application 1810 can access predetermined historical values even when the communication channel between the remote application server 155 and the data monitor device 135 is unavailable. In this example, these historical values are accessible through different screens to reduce the opportunity for confusion for a user of the data monitor device 135 regarding the status of the historical data. As described herein, the historical data can be encrypted, anonymized, quantized, or otherwise prepared for more secure long-term storage on the data monitor device 135.
[0239] FIG. 24 further illustrates a second user interface 2410 that notifies the user of one or more possible error sources that may have caused the communication channel to become unresponsive. As an example, the notification may suggest a number of potential causes, ranging from a system-wide service interruption to a loss of internet connection between devices that communicate data from the sensor control device 102 to the remote application server 155 or from the remote application server 155 to the data monitor device 135, to a lack of communication between the sensor control device 102 and a device that is expected to communicate sensor data to the remote application server 155. In certain embodiments, the monitor application 1810 may only include possible causes that correspond based on detected conditions in the operating environment of the analyte monitor system. As an example, the monitor application 1810 may determine that the data monitor device 135 does not have a working internet connection or that the device is in airplane mode. As a result, the notification may suggest that the data monitor device 135 is the source of the problem and suggest moving to an area with stronger cellular service or connecting to a wireless network. As another example, the monitor application 1810 may determine that there is a outage with or within the remote application server 155 or with the notification service 1820. As a result, the notification may provide information suggesting that the possible cause may be related to the remote application server 155 rather than the data monitor device 135.
[0240] In certain embodiments, the notification may include a suggestion to use a backup mode of communication between the data monitoring device 135 and the remote application server 155 to receive the latest sensor data. As one example, the remote application server 155 may provide a backup service that allows a user wearing the sensor control device 102 to qualify for receiving SMS messages with certain sensor data during an outage. As another example, the notification may include a suggestion to use a backup mode of communication between the data monitoring device 135 and a device that is expected to upload sensor data related to the sensor control device 102. As one example, the notification may identify that the multipurpose device 130 of the user wearing the sensor control device 102 was the last to upload data sent to the data monitoring device 135. The notification may also identify a phone number associated with the multipurpose device 130 so that the user of the data monitoring device 135 can easily contact the user of the multipurpose device 130.
[0241] FIG. 25 illustrates a first user interface 2500 that allows a user of the data monitoring device 135 to customize alerts received by the monitoring application. As one example, a user can determine whether or not they want to receive alerts regarding when a glucose level measured by the sensor control device 102 is higher than a low glucose threshold. The user can control and customize alarms through user interface element 2510. Similarly, as another example, a user can determine whether or not they want to receive alerts regarding when a glucose level exceeds a high glucose threshold, which can be controlled and customized through user interface element 2520. As another example, a user can control whether and how they want to receive alarms corresponding to the monitoring application 1810 not receiving recent data for a threshold duration. The user can control alerts through user interface element 2530. As another example, a user can control whether or not they want to receive connection-lost alerts corresponding to when the communication channel between the data monitoring device 135 and the remote application server 155 is not responding. Connection-lost alerts can be controlled and customized through user interface element 2540. The user can select additional user interface element 2545 to access additional settings related to connection loss alarms.
[0242] 25 further illustrates a second user interface 2550 showing an advanced settings page for a connection loss alarm. The first interface element 2555 includes a description of the connection loss alarm. The second interface element 2560 allows the user to customize the length of time that is considered to trigger a connection loss alarm. As an example, a user selection can be used to set the length of time for triggering a heartbeat notification. In certain embodiments, the remote application server 155 can also modify the length of time for requesting a heartbeat notification to be sent to the monitor application 1810 based on this selection.
[0243] It should be noted that all features, elements, components, functions, and steps described with respect to any embodiment provided herein are intended to be freely combinable and interchangeable with any other embodiment. When a certain feature, element, component, function, or step is described with respect to only one embodiment, it is to be understood that such feature, element, component, function, or step can be used with all other embodiments described herein, unless expressly stated otherwise. Accordingly, this paragraph serves as a predicate and written support for the introduction of claims that combine features, elements, components, functions, and steps from various embodiments or interchange features, elements, components, functions, and steps from one embodiment with another, even if the following description does not explicitly state that such combinations or interchanges are possible in specific cases. Accordingly, the foregoing descriptions of specific embodiments of the presently disclosed subject matter have been presented for purposes of illustration and description. It is expressly recognized that an explicit description of every possible combination and interchange would be unduly burdensome, particularly considering that the permissibility of each and every such combination and interchange would be readily apparent to one skilled in the art.
[0244] While the embodiments are susceptible to various modifications and variations, specific examples of these embodiments have been shown in the drawings and described in detail herein. It will be apparent to those skilled in the art that various modifications and variations can be made in the methods and systems of the presently disclosed subject matter without departing from the spirit or scope of the presently disclosed subject matter. Accordingly, the presently disclosed subject matter is intended to include modifications and variations that come within the scope of the claims and their equivalents. Furthermore, any feature, function, step, or element of the embodiments may be recited or added to the claims, and negative limitations may be recited or added that define the scope of the invention by any feature, function, step, or element not within the scope of the invention.
[0245] Exemplary embodiments are listed in the following numbered clauses: 1. A specimen monitor system comprising: a mobile device including one or more processors and a memory communicatively coupled thereto, the memory including instructions configured, when executed by the one or more processors, to cause the one or more processors to execute an application associated with the analyte monitor system; an analyte monitor system server configured to be communicatively coupled to the application; Including, When an application associated with the sample monitor system executes an instruction: receiving a notification from the analyte monitoring system server via a notification service server configured to be communicatively coupled to the application and the analyte monitoring system server; In response to receiving the notification, ceasing output of the first connectivity alert scheduled prior to receiving the notification; In response to receiving the notification, scheduling output of a second connectivity alert, the second connectivity alert being scheduled to be output upon expiration of the timer unless the mobile device receives a second notification from the analyte monitor system server; determining that a timer has expired; outputting a second connectivity alert indicating that the application has not established a connection with the analyte monitor system server for a predetermined period of time; and detecting that a communication channel between the application and the analyte monitor system server is not responding by performing an operation including: Sample monitoring system. 2. Before receiving a notification from the sample monitor system server, the application: receiving a request to establish a schedule for monitoring a communication channel between an application and an analyte monitor system server; scheduling output of the first connectivity alert in response to receiving the request; 10. The analyte monitor system of claim 1, further configured to perform operations including: 3. The specimen monitoring system of clause 1 or 2, wherein the amount of time associated with the timer is based on user input to an application associated with the specimen monitoring system. 4. The analyte monitor system of clause 1, 2, or 3, wherein the application is a monitor application of the analyte monitor system, and through the application a first user receives information related to the analyte level of a second user. 5. The sample monitoring system of any preceding clause, further configured to perform an operation including a step in which the application attempts to initiate a communication session with the sample monitoring system server using the communication channel or a backup communication channel before outputting the second connectivity alert. 6. The application receiving a second notification from the analyte monitor system server before determining that the timer has expired; ceasing the output of the second connectivity alert; scheduling output of a third connectivity alert, the third connectivity alert being scheduled to be output upon expiration of the second timer unless the mobile device receives a third notification from the analyte monitor system server; 10. The analyte monitor system of any preceding clause, further configured to perform operations including: 7. The application receiving other data from the analyte monitor system server before determining that the timer has expired; ceasing the output of the second connectivity alert; scheduling output of a third connectivity alert, the third connectivity alert being scheduled to be output upon expiration of the second timer unless the mobile device receives a third notification from the analyte monitor system server; 10. The analyte monitor system of any preceding clause, further configured to perform operations including: 8. A specimen monitor system comprising: a mobile device including one or more processors and a memory communicatively coupled thereto, the memory including instructions configured, when executed by the one or more processors, to cause the one or more processors to execute an application associated with the analyte monitor system; an analyte monitor system server configured to be communicatively coupled to the application; Including, When executing the instructions, an application associated with the sample monitor system: receiving, by the application over a communication channel between the application and the analyte monitor system server, one or more current values associated with the analyte level and one or more past values associated with the analyte level; detecting that a communication channel between the application and the analyte monitor system server is not responding; determining one or more possible causes for the communication channel not responding; modifying the output of the application based on the communication channel being unresponsive; displaying a notification including additional information for resolving the unresponsive communication channel based on one or more possible causes of the unresponsive communication channel; configured to perform operations including Sample monitoring system. 9. The analyte monitoring system of clause 8, wherein the application is a monitor application of the analyte monitoring system, and through the application a first user receives information related to the analyte level of a second user. 10. The analyte monitor system of claim 8 or 9, wherein modifying the output of the application includes restricting functionality of the application while the communication channel is unresponsive. 11. The analyte monitor system of claim 8, 9, or 10, wherein the application stores past values and the step of modifying the output of the application includes the step of displaying the past values until the application detects that the communication channel is not responding. 12. The analyte monitor system of clause 11, wherein the application is further configured to perform operations including encrypting the past values prior to storage. 13. The specimen monitoring system of clause 11 or 12, wherein the application is further configured to perform operations including anonymizing the historical values prior to storage. 14. The analyte monitor system of clause 11, 12, or 13, wherein the application is further configured to perform operations including clearing past values after a predetermined period of time has elapsed. 15. The specimen monitoring system of any one of clauses 8 to 14, wherein the step of modifying the output of the application includes a step of displaying the last known status of the specimen level. 16. The analyte monitor system of clause 15, wherein the application is further configured to perform operations including determining a last known status of the analyte level by comparing one or more current values to one or more threshold values each corresponding to a respective last known status. 17. A specimen monitoring system according to any one of clauses 8 to 16, wherein the notification is displayed by the application persistently while the communication channel is unresponsive. 18. The specimen monitoring system of any one of clauses 8 to 17, wherein the notification identifies an error in the application or the system status of the mobile device. 19. A specimen monitoring system according to any one of clauses 8 to 18, wherein the notification identifies an error in the specimen monitoring system server. 20. A specimen monitoring system according to any one of clauses 8 to 19, wherein the notification includes a recommendation to use a second communication channel between the application and the specimen monitoring system server. 21. The application detecting, after displaying the notification, that the communication channel between the application and the analyte monitor system server is responsive; receiving additional historical values associated with the samples corresponding to periods of time during which the communication channel was unresponsive; and further configured to perform operations including: A specimen monitoring system according to any one of clauses 8 to 20. 22. The application determining a geolocation of the mobile device upon detecting that the communication channel is unresponsive; detecting, after displaying the notification, that the communication channel between the application and the analyte monitor system server is responsive; providing geolocation information of the mobile device to a sample monitor system server upon detecting that the communication channel is unresponsive; and further configured to perform operations including: A specimen monitoring system according to any one of clauses 8 to 21. [Explanation of symbols]
[0246] 100 Sample Monitor System 102 Sensor Control Device 104 In vivo analyte sensors 120 Reader Device 150 Sensor Applicator
Claims
1. 1. A specimen monitor system comprising: a mobile device including one or more processors and a memory communicatively coupled to the one or more processors, the memory including instructions configured, when executed by the one or more processors, to cause the one or more processors to execute an application associated with an analyte monitor system; an analyte monitor system server configured to be communicatively coupled with the application; Including, Upon executing the instructions, the application associated with the analyte monitoring system: receiving notifications from the analyte monitoring system server via a notification service server configured to be communicatively coupled to the application and the analyte monitoring system server; In response to receiving the notification, ceasing output of a first connectivity alert scheduled prior to receiving the notification; In response to receiving the notification, scheduling output of a second connectivity alert, the second connectivity alert being scheduled to be output upon expiration of a timer unless the mobile device receives a second notification from the analyte monitor system server; determining that the timer has expired; outputting the second connectivity alert indicating that the application has not established a connection with the analyte monitoring system server for a predetermined period of time; and detecting that a communication channel between the application and the analyte monitor system server is not responding by performing an operation including: system.
2. Prior to receiving the notification from the analyte monitoring system server, the application: receiving a request to establish a schedule for monitoring the communication channel between the application and the analyte monitor system server; scheduling the output of the first connectivity alert in response to receiving the request; [0023] Further configured to perform operations including: The analyte monitor system of claim 1 .
3. The analyte monitoring system of claim 1 , wherein the amount of time associated with the timer is based on a user input to the application associated with the analyte monitoring system.
4. the application is a monitor application of a analyte monitoring system; Through the application, a first user receives information related to an analyte level of a second user. The analyte monitor system of claim 1 .
5. The sample monitoring system of claim 1, wherein the application is further configured to perform an operation including attempting to initiate a communication session with the sample monitoring system server using the communication channel or a backup communication channel before outputting the second connectivity alert.
6. The application receiving the second notification from the analyte monitor system server prior to determining that the timer has expired; ceasing the output of the second connectivity alert; scheduling the output of a third connectivity alert, the third connectivity alert being scheduled to be output upon expiration of a second timer unless the mobile device receives a third notification from the analyte monitoring system server; [0023] Further configured to perform operations including: The analyte monitor system of claim 1 .
7. The application receiving other data from the analyte monitor system server prior to determining that the timer has expired; ceasing the output of the second connectivity alert; scheduling the output of a third connectivity alert, the third connectivity alert being scheduled to be output upon expiration of a second timer unless the mobile device receives a third notification from the analyte monitoring system server; [0023] Further configured to perform operations including: The analyte monitor system of claim 1 .
8. 1. A specimen monitor system comprising: a mobile device including one or more processors and a memory communicatively coupled to the one or more processors, the memory including instructions configured, when executed by the one or more processors, to cause the one or more processors to execute an application associated with an analyte monitor system; an analyte monitor system server configured to be communicatively coupled with the application; Including, Upon executing the instructions, the application associated with the analyte monitoring system: receiving, by the application and through a communication channel between the application and the analyte monitor system server, one or more current values associated with the level of the analyte and one or more past values associated with the level of the analyte; detecting that the communication channel between the application and the analyte monitor system server is not responding; determining one or more possible causes for the communication channel not responding; modifying an output of the application based on the communication channel being unresponsive; displaying a notification including additional information for resolving the unresponsive communication channel based on the one or more possible causes for the communication channel being unresponsive; configured to perform operations including: Sample monitoring system.
9. the application is a monitor application of a analyte monitoring system; Through the application, a first user receives information related to an analyte level of a second user. The analyte monitor system of claim 8 .
10. 9. The analyte monitor system of claim 8, wherein modifying the output of the application comprises restricting functionality of the application while the communication channel is unresponsive.
11. 9. The sample monitor system of claim 8, wherein the application stores the past values and modifying the output of the application includes displaying the past values until the application detects that the communication channel is not responding.
12. 12. The analyte monitoring system of claim 11, wherein the application is further configured to perform an operation including encrypting the past value before storage.
13. 12. The analyte monitoring system of claim 11, wherein the application is further configured to perform operations including anonymizing the historical values prior to storage.
14. 12. The analyte monitoring system of claim 11, wherein the application is further configured to perform operations including clearing past values after a predetermined period of time has elapsed.
15. 10. The analyte monitoring system of claim 8, wherein modifying the output of the application comprises displaying a last known status of the level of the analyte.
16. 16. The analyte monitoring system of claim 15, wherein the application is further configured to perform operations including determining the last known status of the level of the analyte by comparing the one or more current values against one or more thresholds, each threshold corresponding to a respective last known status.
17. 9. The analyte monitor system of claim 8, wherein the notification is displayed by the application persistently while the communication channel is unresponsive.
18. 9. The analyte monitoring system of claim 8, wherein the notification identifies an error in the application or a system status of the mobile device.
19. The analyte monitoring system of claim 8 , wherein the notification identifies an error in the analyte monitoring system server.
20. The analyte monitoring system of claim 8 , wherein the notification includes a recommendation to use a second communication channel between the application and the analyte monitoring system server.
21. The application detecting, after displaying the notification, that the communication channel between the application and the analyte monitor system server is responsive; receiving additional historical values associated with the analyte corresponding to a period of time during which the communication channel was unresponsive; and further configured to perform operations including: The analyte monitor system of claim 8 .
22. The application determining a geolocation of the mobile device upon detecting that the communication channel is unresponsive; detecting, after displaying the notification, that the communication channel between the application and the analyte monitor system server is responsive; providing the geolocation information of the mobile device to the analyte monitor system server upon detecting that the communication channel is not responding; and further configured to perform operations including: The analyte monitor system of claim 8 .
Citation Information
Patent Citations
Analyte Sensors and Methods of Making and Using the Same
US20100230285A1
Analyte Sensor Devices, Connections, and Methods
US20130150691A1
Dermal layer analyte sensing devices and methods
US20140171771A1
Systems, devices, and methods for assembling an applicator and sensor control device
US20160331283A1
Systems, devices and methods for analyte sensor insertion
US20180235520A1