Continuous glucose monitoring communication with multiple display devices

The system addresses inconsistent data display and security issues in continuous glucose monitors by enabling secure communication and authentication between a glucose sensor and multiple displays, ensuring consistent data across devices and maintaining confidentiality.

JP2026077660APending Publication Date: 2026-05-13DEXCOM INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-02-05
Publication Date
2026-05-13

AI Technical Summary

Technical Problem

Existing continuous glucose monitors that wirelessly transmit data to a dedicated display are limited by user preference for smartphone applications, leading to inconsistent data display across multiple devices and potential security breaches in data transmission.

Method used

A system enabling secure communication between a continuous glucose sensor and multiple displays, including a dedicated display and a smartphone, with authentication protocols and encryption to ensure consistent data display and limit unauthorized access.

Benefits of technology

Ensures consistent data display across multiple devices and maintains confidentiality of sensitive medical data by authenticating and pairing displays, while conserving battery life through limited connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026077660000001_ABST
    Figure 2026077660000001_ABST
Patent Text Reader

Abstract

Data regarding glucose levels is transmitted securely to multiple displays. [Solution] This disclosure relates to a continuous glucose monitor for wirelessly transmitting glucose value data to multiple displays. A system and method for limiting the number of display devices that can be connected to the continuous glucose transmitter are disclosed. In addition, secure communication between the continuous glucose transmitter and the displays can be provided using security including hashing techniques and changing application keys. Other embodiments relate to a continuous glucose monitor and techniques for authenticating multiple displays, providing secure data transmission to multiple displays, and coordinating command and data update interactions between multiple displays.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a continuous glucose sensor that transmits data related to glucose values to multiple displays in a secure manner.

Background Art

[0002] Continuous glucose monitors are becoming increasingly popular as an easy way to monitor glucose values. Conventionally, users take samples of the user's blood glucose several times throughout the day, such as in the morning, around noon, and in the evening. The value can be measured by taking a small blood sample and measuring the glucose value using a test strip or a blood glucose meter. However, this technique has drawbacks, as users would prefer not to have to take blood samples, and users do not know what the user's glucose value is throughout the day between samples.

[0003] One potentially dangerous time period is at night, as the user's glucose value can drop dangerously low during sleep. As a result, continuous glucose monitors have gained popularity by providing sensors that continuously monitor glucose values and wirelessly transmit those glucose values to a display. This allows the user to monitor the user's glucose value throughout the day and further set alarms for when the glucose value reaches a predetermined value or undergoes a defined change.

[0004] Originally, continuous glucose monitors wirelessly transmitted data related to glucose values to a receiver that served as a dedicated display. The dedicated display may be a medical device designed to display glucose values, trend patterns, and other information related to the user. However, with the increasing popularity of smartphones and applications running on smartphones, some users prefer to avoid carrying a dedicated display. Instead, users will likely prefer to use an application running on a smartphone, either alone or in combination with a dedicated display, to monitor the user's glucose value.

[0005] This disclosure aims to overcome these and other challenges. [Overview of the project] [Means for solving the problem]

[0006] This disclosure relates to enabling a user to carry and use multiple displays, such as a dedicated display associated with a continuous glucose monitoring system and a smartphone, tablet, personal computer, or other device, to monitor glucose levels. The user can carry two displays and monitor glucose levels using different displays at different times. For example, the user may occasionally use their smartphone application, but then the user may turn off the smartphone application and switch to using the dedicated display. The disclosed system coordinates the transmission and display of the same data on two separate displays to ensure consistency. Commands can be received from both displays and processed in a timely manner, and both displays can display the same data.

[0007] In other embodiments, the user can send commands from a dedicated display, a smartphone, or both to control the continuous glucose monitoring system. At the time the user enters a command on a particular display, the two displays may actually be showing different data. For example, the user may enter a calibration command on the first display, but this is processed only after the current glucose data has been sent to the second display. Thus, the first display may show a different glucose value based on the new calibration, while the second display continues to show the old data. The systems and methods described later ensure consistency of data displays across multiple devices.

[0008] In addition, this disclosure provides secure communication with the system. Medical devices wirelessly transmit highly sensitive medical data about patients. Ensuring that communication occurs only between authorized and authenticated devices may be key to presenting users with an appropriate level of security that ensures the confidentiality of the transmitted data. Disseminating glucose readings and related information between glucose sensors and transmitters could lead to data leakage without authentication or other techniques to ensure communication. For example, a second user's display could receive glucose data about another user, causing confusion and a breach of privacy. Therefore, secure communication between glucose sensors and multiple displays is required. Examples of ensuring communication include requiring an authentication protocol before the device makes the data available and using encryption to prevent unauthorized access.

[0009] Transmitting glucose data to multiple displays can strain the batteries of the glucose sensor and transmitter. Each display should be authenticated and paired to receive data, and this communication is established by the addition of additional displays. Therefore, in some embodiments, the number of displays that can be connected to a particular transmitter at any given time may be limited. The user should also be able to add or remove a given display that can communicate with the glucose sensor.

[0010] In one exemplary embodiment, a method for pairing a transmitter of a continuous glucose monitoring system with multiple display devices is disclosed. This method may include connecting a first display device to the transmitter via a first wireless connection, connecting a second display device to the transmitter via a second wireless connection, and limiting the number of display devices connected to the transmitter by rejecting additional connection requests during communication intervals. The method may also include periodically exchanging an application key, which changes at the beginning of each period, with the first and second display devices.

[0011] In another embodiment, a system is disclosed for pairing a transmitter of a continuous glucose monitoring system with multiple display devices. The system may include a first display device configured to connect to the transmitter via a first wireless connection, and a second display device configured to connect to the transmitter via a second wireless connection. The transmitter may be configured to limit the number of connected display devices by rejecting additional connection requests during communication intervals, and to periodically exchange application keys, which change at the beginning of each period, with the first and second display devices.

[0012] Also disclosed is a computer-readable medium that, when executed by one or more processors, includes instructions for performing a method for pairing a transmitter of a continuous glucose monitoring system with multiple display devices. The method may include connecting a first display device to the transmitter via a first wireless connection, connecting a second display device to the transmitter via a second wireless connection, and limiting the number of display devices connected to the transmitter by rejecting additional connection requests during communication intervals. The method also includes periodically exchanging an application key, which changes at the beginning of each period, with the first and second display devices.

[0013] Another embodiment discloses a method for pairing a transmitter of a continuous glucose monitoring system with a display device. This method includes receiving a first identifier from the display device, creating a first hash value by performing a hash algorithm on the first identifier, receiving an advertisement signal from the transmitter, analyzing at least one of the advertisement signals associated with the advertisement signal to identify a second hash value that includes a portion of the transmitter identifier associated with the transmitter, comparing the first hash value with the second hash value, rejecting the connection between the transmitter and the display device if the first hash value and the second hash value do not match, and allowing the connection between the transmitter and the display device if the first hash value and the second hash value match.

[0014] In another embodiment, one or more computer-readable media are disclosed, which, when executed by one or more processors, include instructions for performing a method for pairing a transmitter of a continuous glucose monitoring system with a display device. The method may include: receiving a first identifier from the display device; creating a first hash value by performing a hash algorithm on the first identifier; receiving an advertisement signal from the transmitter; parsing at least one of the advertisement signals associated with the advertisement signal to identify a second hash value that includes a portion of the transmitter identifier associated with the transmitter; comparing the first hash value with the second hash value; rejecting the connection between the transmitter and the display device if the first hash value and the second hash value do not match; and allowing the connection between the transmitter and the display device if the first hash value and the second hash value match.

[0015] In another embodiment, a system for pairing a transmitter of a continuous glucose monitoring system with a display device is disclosed. The system includes a radio receiver in a first display device configured to receive a first identifier, and a processor in the first display device configured to create a first hash value by performing a hash algorithm on the first identifier, receive an advertisement signal from the transmitter, parse at least one of the advertisement signals associated with the advertisement signal to identify a second hash value that includes a portion of the transmitter identifier associated with the transmitter, compare the first hash value with the second hash value, and reject the connection between the transmitter and the display device if the first and second hash values ​​do not match, and allow the connection between the transmitter and the display device if the first and second hash values ​​match.

[0016] Another embodiment discloses a method for pairing a transmitter of a continuous glucose monitoring system with a display device. This method includes receiving an advertisement signal from the transmitter; establishing a connection between the transmitter and the display device; receiving a first key from the transmitter; comparing the first key with a second key stored by the display device; authenticating the transmitter using the display device when the first key matches the second key; transmitting an application key from the display device to the transmitter after authentication; receiving acceptance of the application key from the transmitter; allowing communication between the transmitter and the display device after receiving acceptance of the application key; transmitting data relating to continuous glucose values ​​from the transmitter to the display device; creating a second application key by the display device after a certain period of time; transmitting the second application key from the display device to the transmitter; receiving acceptance of the second application key from the transmitter; and allowing further communication between the transmitter and the display device after receiving acceptance of the new application key.

[0017] In another embodiment, one or more computer-readable media are disclosed, which, when executed by one or more processors, include instructions for performing a method for pairing a transmitter of a continuous glucose monitoring system with a display device. The method includes receiving an advertisement signal from a transmitter; establishing a connection between the transmitter and a display device; receiving a first key from the transmitter; comparing the first key with a second key stored by the display device; authenticating the transmitter using the display device when the first key matches the second key; transmitting an application key from the display device to the transmitter after authentication; receiving acceptance of the application key from the transmitter; allowing communication between the transmitter and the display device after receiving acceptance of the application key; transmitting data relating to continuous glucose values ​​from the transmitter to the display device; creating a second application key by the display device after a certain period of time; transmitting the second application key from the display device to the transmitter; receiving acceptance of the second application key from the transmitter; and allowing further communication between the transmitter and the display device after receiving acceptance of the new application key.

[0018] In another embodiment, a system for pairing a transmitter of a continuous glucose monitoring system with a display device is disclosed. The system includes a transmitter configured to transmit an advertising signal, a display device configured to establish a connection with the transmitter based on the advertising signal, a wireless receiver in the display device configured to receive a first key from the transmitter, a memory in the display device configured to store a second key, and a processor in the display device. The processor compares the first key with the second key, and when the first key matches the second key, authenticates the transmitter using the display device, transmits an application key to the transmitter after authentication, receives acceptance of the application key from the transmitter, allows communication with the transmitter after receiving acceptance of the application key, receives data on continuous glucose values ​​from the transmitter, creates a second application key after a certain period of time, transmits the second application key to the transmitter, receives acceptance of the second application key from the transmitter, and after receiving acceptance of the new application key, may allow further communication between the transmitter and the display device.

[0019] Another embodiment discloses a method for establishing communication between a plurality of display devices and a transmitter of a continuous glucose monitoring system. The method includes receiving a request to identify a first type of a first display device and to connect a transmitter to the first display device; comparing the first type of the first display device with a list containing a plurality of permitted types of display devices; determining whether a display device having the first type is actively connected to a transmitter; and connecting the transmitter to the first display device if the list contains fewer than a predetermined number of display devices having the first type; receiving a request to identify a second type of a second display device and to connect a transmitter to a second display device; comparing the second type of the second display device with a list containing a plurality of permitted types of display devices; determining whether a display device having the second type is actively connected to a transmitter; and connecting the transmitter to the second display device if the list contains fewer than a predetermined number of display devices having the second type.

[0020] In another embodiment, one or more computer-readable media are disclosed, which, when executed by one or more processors, include instructions for performing a method for establishing communication between a plurality of display devices and a transmitter of a continuous glucose monitoring system. The method may include: receiving a request for a first type of a first display device to connect a transmitter to the first display device; comparing the first type of the first display device to a list containing a plurality of permitted types of display devices; determining whether a display device having the first type is actively connected to a transmitter; and connecting the transmitter to the first display device if the list contains fewer than a predetermined number of display devices having the first type; receiving a request for a second type of a second display device to connect a transmitter to a second display device; comparing the second type of the second display device to a list containing a plurality of permitted types of display devices; determining whether a display device having the second type is actively connected to a transmitter; and connecting the transmitter to the second display device if the list contains fewer than a predetermined number of display devices having the second type.

[0021] In another embodiment, a system for establishing communication between a plurality of display devices and a transmitter of a continuous glucose monitoring system is disclosed. The system includes a first display device, a second display device, a wireless receiver in the transmitter configured to receive a request identifying a first type of the first display device and a request to connect the transmitter to the first display device, a memory in the transmitter configured to store a list of permitted types of display devices, and a processor in the transmitter. The processor compares the first type of the first display device with a list to determine whether a display device having the first type is actively connected to the transmitter, and if the list contains fewer than a predetermined number of display devices having the first type, it connects the transmitter to the first display device. The processor also receives a request to identify the second type of the second display device and to connect the transmitter to the second display device, and compares the second type of the second display device with a list containing multiple permitted types of display devices to determine whether a display device having the second type is actively connected to the transmitter, and if the list contains fewer than a predetermined number of display devices having the second type, it can connect the transmitter to the second display device.

[0022] Another embodiment discloses a method for establishing communication between a plurality of display devices and a transmitter of a continuous glucose monitoring system. This method may include: creating a list of authorized devices, which is a list of a plurality of types of devices; performing an authentication process using a first display device and transmitter, the authentication process including receiving an identifier for the type of the first display device; adding the first display device to the list of authorized devices; performing an authentication process using a second display device and transmitter, the authentication process including receiving an identifier for the type of the second device, wherein the type of the second device is different from the type of the first device; adding the second display device to the list of authorized devices; receiving a request to remove the first display device from the list; removing the first display device from the list of authorized devices; performing an authentication process using a third display device and transmitter, the authentication process including receiving an identifier for the type of the third device, wherein the type of the third device is the same as the type of the first device; and adding the third display device to the list of authorized devices.

[0023] In another embodiment, one or more computer-readable media are disclosed, which, when executed by one or more processors, include instructions for performing a method for establishing communication between multiple display devices and transmitters of a continuous glucose monitoring system. The method may include: creating a list of authorized devices, which is a list of multiple types of devices; performing an authentication process using a first display device and transmitter, the authentication process including receiving an identifier for the type of the first display device; adding the first display device to the list of authorized devices; performing an authentication process using a second display device and transmitter, the authentication process including receiving an identifier for the type of the second device, wherein the type of the second device is different from the type of the first device; adding the second display device to the list of authorized devices; receiving a request to remove the first display device from the list; removing the first display device from the list of authorized devices; performing an authentication process using a third display device and transmitter, the authentication process including receiving an identifier for the type of the third device, wherein the type of the third device is the same as the type of the first device; and adding the third display device to the list of authorized devices.

[0024] In another embodiment, a system for establishing communication between multiple display devices and a transmitter of a continuous glucose monitoring system is disclosed. This system includes a first display device, a second display device, a memory associated with the transmitter, a memory comprising a list of multiple device types and configured to store a list of authorized devices, and a processor associated with the transmitter. The processor may perform the following actions: perform an authentication process using a first display device and transmitter, the authentication process including receiving an identifier of the type of the first display device; add the first display device to a list of authorized devices; perform an authentication process using a second display device and transmitter, the authentication process including receiving an identifier of the type of the second device, the type of the second device being different from the type of the first device; add the second display device to a list of authorized devices; receive a request to remove the first display device from the list; remove the first display device from the list of authorized devices; and perform an authentication process using a third display device and transmitter, the authentication process including receiving an identifier of the type of the third device, the type of the third device being the same as the type of the first device; and add the third display device to a list of authorized devices.

[0025] Another embodiment discloses a method for exchanging commands between a transmitter of a continuous glucose monitoring system and one or more display devices. This method includes: putting the transmitter into an idle state; receiving a command on a first display device requesting data exchange with the transmitter; putting the first display device into an intermediate state depending on the type of command; transitioning the transmitter from an idle state to an active state; transmitting a command from the first display device to the transmitter; receiving a response from the transmitter containing updated data relating to the control of the transmitter; disengaging the first display device from the intermediate state; and displaying the updated data on the first display.

[0026] In another embodiment, one or more computer-readable media are disclosed, which, when executed by one or more processors, include instructions for performing a method for exchanging commands between a transmitter and one or more display devices of a continuous glucose monitoring system. The method includes: putting the transmitter into an idle state; receiving a command on a first display device requesting data exchange with the transmitter; putting the first display device into an intermediate state depending on the type of command; transitioning the transmitter from an idle state to an active state; transmitting the command from the first display device to the transmitter; receiving a response from the transmitter including updated data relating to control of the transmitter; disengaging the first display device from the intermediate state; and displaying the updated data on the first display.

[0027] In another embodiment, a system for exchanging commands between a transmitter of a continuous glucose monitoring system and one or more display devices is disclosed. The system includes a first display device configured to receive a command requesting an exchange of data with the transmitter and to put the first display device into an intermediate state according to the type of the command. The system also includes a processor associated with the transmitter, the processor being configured to idle the transmitter over a certain period of time, transition the transmitter from an idle state to an active state, receive a command from the first display device during the active state, and transmit a response including updated data regarding the control of the transmitter from the transmitter to the first display device. In response to receiving the response, the first display device ends the intermediate state by displaying the updated data.

[0028] In another embodiment, a method for synchronizing data displayed on a first display device and a second display device is disclosed. The method includes connecting the first display device to a transmitter of a continuous glucose monitoring system, connecting the second display device to the transmitter, permitting transmission of a command to the transmitter at a specific time, receiving data regarding glucose values from the transmitter by the first display device and the second display device, receiving a command regarding calibration of a continuous glucose sensor on the first display device, transmitting a command regarding calibration to the continuous glucose sensor at one of the specific times, calculating data regarding updated glucose values based on the command regarding calibration, and transmitting the data regarding the updated glucose values to the first display device and the second display device.

[0029] In another embodiment, one or more computer-readable media are disclosed that include instructions for implementing a method for synchronizing data displayed on a first display device and a second display device when executed by one or more processors. The method includes connecting a first display device to a transmitter of a continuous glucose monitoring system, connecting a second display device to the transmitter, permitting transmission of commands to the transmitter at a specific time, receiving data regarding glucose values from the transmitter by the first display device and the second display device, receiving a command regarding calibration of a continuous glucose sensor at the first display device, transmitting a command regarding calibration to the continuous glucose sensor at one of the specific times, calculating data regarding an updated glucose value based on the command regarding calibration, and transmitting the data regarding the updated glucose value to the first display device and the second display device.

[0030] In another embodiment, a continuous glucose sensor is configured to synchronize data displayed on a first display device and a second display device. The sensor includes a wireless transceiver configured to wirelessly connect the first display device and the second display device, and a processor. The processor can transmit data regarding glucose values to the first display device and the second display device, receive a command regarding calibration of the continuous glucose sensor at a specific time, calculate data regarding an updated glucose value based on the command regarding calibration, and transmit the data regarding the updated glucose value to the first display device and the second display device.

[0031] Another embodiment discloses a method for connecting a transmitter of a continuous glucose system to a plurality of displays. This method includes: advertising by the transmitter at a predetermined communication interval; receiving requests from a first display and a second display to connect to the transmitter in response to the advertising activity; determining whether to authorize the connection to the first display and the second display based on the device type of the first display and the device type of the second display; performing an authentication process to pair the first display and the second display with the transmitter when the connection is authorized; and storing coupling information associated with the authentication process in memory.

[0032] In another embodiment, a system for connecting a transmitter of a continuous glucose system to multiple displays is disclosed. The transmitter is configured to receive requests from a first display and a second display to connect to the transmitter in response to advertising activity, to determine whether to authorize the connection to the first display and the second display based on the device type of the first display and the device type of the second display, and, if the connection is authorized, to perform an authentication process to pair the first display and the second display with the transmitter, and to store the coupling information associated with the authentication process in memory.

[0033] In another embodiment, a computer-readable medium is disclosed that, when executed by a processor, includes instructions for performing a method for connecting a transmitter of a continuous glucose system to a plurality of displays. The method includes: advertising by the transmitter at a predetermined communication interval; receiving requests from a first display and a second display to connect to the transmitter in response to the advertising activity; determining whether to authorize the connection to the first display and the second display based on the device type of the first display and the device type of the second display; performing an authentication process to pair the first display and the second display with the transmitter when the connection is authorized; and storing in memory the coupling information associated with the authentication process.

[0034] Other systems, methods, features, and / or advantages are or may be apparent to those skilled in the art by examining the following drawings and detailed description. All such additional systems, methods, features, and / or advantages are contained herein and intended to be protected by the attached claims. [Brief explanation of the drawing]

[0035] [Figure 1] An exemplary system for monitoring glucose levels is provided. [Figure 2] This document illustrates an exemplary method for connecting to multiple display devices and ensuring wireless communication. [Figure 3] This provides an example of a method for deciding whether or not to allow a connection. [Figure 4] This document illustrates an exemplary method for authenticating and establishing communication between a continuous glucose sensor and multiple displays. [Figure 5] This document provides an example of how to update an application key. [Figure 6] An exemplary method for connecting a continuous glucose monitor to one or more displays, based on the device type, is provided. [Figure 7]An illustrative system diagram for storing connection information is provided. [Figure 8] This provides an example of how to remove a display from the list of devices that have permission to display. [Figure 9] This provides an example of how to update data in response to a command. [Figure 10A] This provides an example user interface for processing commands. [Figure 10B] This provides an example user interface for processing commands. [Figure 11] This provides an example of how to update multiple displays in response to a command. [Figure 12] An illustrative diagram of a continuous glucose sensor and its transmitter connection is provided. [Figure 13] Exemplary embodiments of communication between a continuous glucose sensor transmitter and a dedicated display or display during authentication and pairing are illustrated. [Figure 14] This provides examples of use cases where the connection may be refused. [Figure 15] This section provides an example use case for connecting to a display. [Figure 16] An illustrative state diagram of a dedicated display is provided. [Figure 17] This document illustrates an exemplary method for calibrating a continuous glucose sensor with multiple displays. [Figure 18] An exemplary system for monitoring glucose levels is provided. [Figure 19] An example computer for monitoring glucose levels is provided. [Modes for carrying out the invention]

[0036] This disclosure relates to a continuous glucose monitor and technique for authenticating multiple displays, providing secure data transmission to multiple displays, and coordinating the interaction of commands and data updates between multiple displays.

[0037] Figure 1 illustrates an exemplary system for monitoring glucose levels. Referring to Figure 1, the continuous glucose sensor system 100 obtains a series of measurements regarding the user's glucose level. The continuous glucose sensor system 100 can be, for example, implanted in the patient's abdominal region. A small sensor 103 can be placed on or inside the patient to obtain glucose readings using, for example, subcutaneous glucose or blood glucose readings. The sensor may be placed inside the patient using a needle that extends into the patient to insert the sensor, then retracts and is discarded. An applicator or other similar device may contain the needle and be used to insert the sensor. The continuous glucose sensor system 100 may be a transcutaneous, intravascular, or non-invasive device.

[0038] The continuous glucose sensor system 100 may include several components for obtaining glucose measurements, storing data, calculating glucose values, communicating with dedicated displays 104a and 106a, and performing other tasks. For example, though not illustrated, the continuous glucose sensor system 100 may include a non-volatile memory for storing historical data on glucose values, a processor, a battery, and a wireless transmitter 101. The wireless transmitter 101 can provide any type of wireless communication 102a and 102b, including Bluetooth® connectivity, WiFi connectivity, RF connectivity, etc. In some embodiments, wireless communication 102a and 102b may occur between paired and authenticated devices, and encryption and other cryptographic techniques may be used to ensure that the communication remains confidential.

[0039] Although illustrated as a single unit, the wireless transmitter 101 is detachable from the continuous glucose sensor system 100 and can be reused with multiple sensors 103 by replacing the sensors 103. Furthermore, the continuous glucose sensor system 100 may include other components to facilitate data communication. For example, the continuous glucose sensor system 100 may include wired ports such as USB ports and Ethernet® ports for communicating with other devices and providing data on glucose values. The continuous glucose sensor system 100 may include processing circuits such as a processor, memory, and battery as part of the sensor electronics. The sensor electronics may be contained within the continuous glucose sensor system 100 or the transmitter 101. The sensor portion 103 of the continuous glucose sensor system 100 may be detachable and replaceable, allowing patients to change to a new sensor regularly, such as weekly. Similarly, the transmitter 101 may be detachable and removable from the continuous glucose sensor system 100, allowing for replacement as needed, such as every six months.

[0040] The continuous glucose sensor system 100 can obtain samples at predetermined intervals, such as every few seconds, every 30 seconds, every minute, or on demand in response to a command from the user. In one embodiment, the wireless transmitter may be turned off to conserve battery life, and the measurements taken over a period of time may be transmitted wirelessly to dedicated displays 104a and 106a in batch transfer. For example, the continuous glucose sensor system 100 can activate the wireless transmitter every 5 minutes, transfer data regarding glucose measurements taken over the most recent 5 minutes, and then transfer the data to dedicated displays 104a and 106a. The wireless transmitter 101 may then be turned off again to conserve battery life. While an example of transferring data every 5 minutes has been provided, it will be understood that longer or shorter periods may be used, and these periods may be configured by the user via the dedicated displays 104a or 106a.

[0041] The system in Figure 1 may have states determined by the continuous glucose sensor system 100 and its transmitter 101. One exemplary system state includes when the system is not started but the sensor 103 has not yet been inserted into the host, or when the user has not yet activated the continuous glucose sensor system 100. Another example is a sensor warm-up period, which may last for a certain period, such as two hours, while the sensor 103 warms up and becomes accustomed to being inserted into the user's body. The sensor warm-up state may also include a calibration period. Other examples of system states include being calibrated or out of calibration. The sensor 103 and / or the continuous glucose sensor system 100 may be calibrated if they have been calibrated within a predetermined interval, such as the most recent 12 hours, and out of calibration if a predetermined duration (e.g., 12 hours) has elapsed since the most recent calibration. Another exemplary system state is sensor shutdown. The sensor shutdown state may occur, for example, when the user attempts to replace the sensor part 103 of the glucose sensor system 100.

[0042] The system in Figure 1 coordinates communication between the continuous glucose sensor system 100, a dedicated display 104a, and a display 106a to ensure consistent operation. The continuous glucose sensor system 100 can advertise and communicate with the displays during intervals of communication cycles. Advertising is the process by which the continuous glucose sensor system 100 publicizes its presence to seek other devices to connect with. Optionally, communication intervals may occur approximately every 5 minutes (for example, a communication interval may last 30 seconds, so an interval of 4 minutes and 30 seconds may occur after the end of each communication interval). During a communication interval, the continuous glucose sensor system 100 can exchange data on glucose values, system configuration information, system status information, patient identification information, and other information with the displays. The displays can receive these data transmissions and also send commands to the continuous glucose sensor system 100. A transmitter 101 within the continuous glucose sensor system 100 can update the system state in response to a command and transmit a message with the updated system state to the connected displays.

[0043] In a situation where one display has already communicated during a communication interval, and the second display is updating the calibration value, the values ​​displayed on the two displays may not match. In this example, the first display continues to show the user the old value based on the previous calibration until it is updated during the next communication interval. For example, the user can enter a command, such as a calibration command, into display 106a, and that command is sent to the continuous glucose sensor system 100 during the next communication interval. If, during the next communication interval, the continuous glucose sensor system 100 first communicates with the dedicated display 104a by providing data on glucose values ​​over the most recent 5 minutes, the dedicated display 104a will show the user that glucose data. However, if the continuous glucose sensor system 100 then communicates with display 106a and receives a calibration command, the continuous glucose sensor system 100 can calculate a new glucose value. This can result in a mismatch between the values ​​displayed on the dedicated display 104a and display 106a. Another scenario is when the user wants to start or stop the sensor when they want to replace it. As a result, the system in Figure 1 can coordinate the transmission of commands and glucose value data between the continuous glucose sensor system 100, the dedicated display 104a, and the display 106a, ensuring consistent operation. Exemplary embodiments are described in more detail later, for example, in Figures 11, 12, and 17.

[0044] The data transmitted from the continuous glucose sensor system 100 to the dedicated displays 104a and 106a may be any type of data relating to glucose level monitoring. For example, the continuous glucose sensor system 100 can exchange calibration data with the dedicated displays 104a and 106a during initial startup and periodically thereafter to maintain the accuracy of glucose measurements. A user can measure their glucose level using a blood glucose meter, input the value displayed by the meter, and use that value to calibrate the continuous glucose sensor system 100. Multiple samples from the blood glucose meter can be used to facilitate accuracy and proper calibration. Other examples of data transmitted include current or voltage measured by the continuous glucose sensor, glucose values ​​converted to, for example, mg / dL, and timestamps associated with the time each measurement or value was sampled, diagnostic data, etc. Although described as the continuous glucose sensor system 100, other medical devices may be used in the disclosed embodiments. For example, the continuous glucose sensor system 100 may be an analyte sensor, and the transmitted data may reflect the value of an analyte.

[0045] The dedicated display 104a may be a dedicated display for use with the continuous glucose sensor system 100. In one embodiment, the combination of the continuous glucose sensor system 100 and the dedicated display 104a may be an approved medical device, such as a Class III medical device. The dedicated display 104a can receive data on glucose values ​​from the continuous glucose sensor system 100 in real time, which includes both continuous streaming and batch data transmission of the data.

[0046] Since the dedicated display 104a is part of an authorized medical device with a continuous glucose sensor system 100, in one embodiment, the dedicated display 104a can receive and display an extended set of data received from the continuous glucose sensor system 100 in connection with other displays or third-party applications or system components. For example, the dedicated display 104a can display the actual glucose value associated with the measurement taken by the sensor. In contrast, a third-party application running on display 106a may be limited to receiving and displaying the actual glucose value, and instead may receive a more comprehensive indicator of the glucose value, such as whether the glucose value is low, normal, or high. Further details regarding the types of data that can be transmitted to and displayed on the dedicated displays 104a and 106a are provided below.

[0047] The dedicated display 104a may include a processor for calculating glucose values ​​based on received measurements, a memory for storing glucose values, a port for wired communication, and wireless communication circuits such as Bluetooth, WiFi, and RF circuits. In addition, the dedicated display 104a can determine the historical trend of whether the user's glucose value is decreasing, remaining stable, or increasing. As shown in Figure 1, the dedicated display 104a can display glucose readings over a long period of time so that the user can easily monitor their glucose value, and can also display the actual value of the current glucose value. In the example in Figure 1, the dedicated display 104a illustrates that the current glucose value is 94 mg / dL.

[0048] The display 106a may be any type of display associated with a personal computer, tablet, or smartphone capable of running an application for displaying data related to glucose values. As a result, the display 106a includes all hardware components associated with a personal computing device, including the processor(s), memory, wireless connectivity, USB ports, etc.

[0049] Both dedicated displays 104a and 106a can establish alarms to warn the user of their glucose status. For example, user-perceptible warnings may be triggered when the glucose level is too low (e.g., less than 55 mg / dL), at a level defined by the user as low (e.g., a value set between 55 mg / dL and 70 mg / dL), too high, above a user-defined level, rapidly decreasing, or rapidly increasing. Each display can use the same or different warning values. In addition, warnings can also be used to prompt the user to perform functions, such as performing calibration by inputting blood glucose values ​​collected using a separate measuring device. Calibration values ​​may be transmitted from the display device to a transmitter and used to calibrate glucose data sampled by the continuous glucose sensor system 100.

[0050] Warnings may be transmitted from the glucose sensor 100 to the display via a wireless transmitter. Warnings may indicate errors related to the sensor, a reminder that sensor 103 is nearing the end of its lifespan and should be replaced, and an error indicating that sensor 103 has expired. Other warnings that may be transmitted from the continuous glucose sensor system 100 may indicate low battery in the transmitter, a weak wireless signal between the continuous glucose sensor transmitter 101 and the display, failure of the pairing or authentication process, and other warnings regarding system operation and use. Warnings may be displayed to the user with increasing frequency until one or both of the user-acknowledged warnings and / or potential warning conditions are resolved.

[0051] Display 106a can run several applications 108-110 related to glucose monitoring, receiving and displaying various types of health information including exercise activity, and controlling and monitoring insulin injections, eating habits, etc. In one embodiment, display 106a receives the same data that the continuous glucose sensor system 100 transmits to dedicated display 104a. In one exemplary embodiment, display 106a may include a dedicated application 108 created by the manufacturer or affiliate of the continuous glucose sensor system 100. The dedicated application 108, display 106a, and / or continuous glucose sensor system 100 may be licensed medical devices. For example, in one embodiment, the continuous glucose sensor system 100, display 106a, and dedicated application 108, individually or in combination, are licensed Class III medical devices. The dedicated application 108 can control the distribution of medical data received from the continuous glucose sensor system 100 to other applications running on display 106a, maintaining confidentiality and user preference, as will be described in more detail later. Although not illustrated, the dedicated application 108 and authorized third-party applications 110 may be connected to other applications on the display 106a and provide information to them, or transmit it to further computing devices and / or server systems.

[0052] An authorized third-party application 110 can also receive data related to blood glucose levels. A dedicated application 108 can receive glucose data from the continuous glucose sensor system 100, determine which set of data should be provided to the authorized third-party application 110, and provide that data to the third-party application 110. The user can configure the type of medical data that the dedicated application 108 should provide to the authorized third-party application 110. In this way, the third-party application can receive the same data as that received by the dedicated application 108, a reduced set of data, or encrypted data. Although the dedicated application 108 is described to control which data is provided to the third-party application 110, an operating system or other software program running on the display 106a can also isolate the data received from the continuous glucose sensor system 100 and provide it as appropriate to applications 108, 110.

[0053] Figure 1 also illustrates additional dedicated displays 104b and 106b. These devices may be additional devices located within wireless transmission range from the continuous glucose sensor system 100. For example, a user may be in a meeting or public area where many people have the continuous glucose sensor system 100, dedicated displays 104a, and displays 106a. Displays 104b and 106b connected to another continuous glucose sensor system should not be allowed to connect to the continuous glucose sensor system 100. This could cause the display of incorrect data from another user and would also constitute a breach of security for medical data. As a result, in one embodiment, each continuous glucose sensor system 100 can limit the number of devices it connects to and can only connect to devices that are securely paired and authenticated. For example, the continuous glucose sensor system 100 can only connect to a single dedicated display 104a and displays 106a at a given time. Limiting the number of devices that the continuous glucose sensor system 100 can communicate with during a particular session can also save the battery life of the sensor 100. Further details, including exemplary techniques for limiting the number of devices to which the continuous glucose sensor system 100 can be connected in a given time, are provided below, for example, with respect to embodiments shown in Figures 2, 6-8, 11, 14, and 15.

[0054] In addition to limiting the number of devices, the system may also employ security measures to keep medical data confidential. These security measures may include one-way authentication, two-way authentication, encryption, hashing, and security keys. The encryption used may be in addition to encryption already provided by wireless standards such as Bluetooth encryption. One challenge that arises is that a third party without the authority to guess the security key may repeatedly attempt to attack the device's security. To address this challenge, in one embodiment, the application key may be exchanged between the continuous glucose sensor system 100, the dedicated display 104a, and the display 106a, and the application key may change periodically. For example, the application key may change on request, at predetermined time intervals, in response to a specific event, and in other circumstances. Therefore, the term "periodically" is not limited to predetermined time intervals, but rather refers to the period during which communication is ensured using an application key that may change during another communication cycle.

[0055] Figure 2 is a flowchart illustrating an exemplary method for connecting multiple display devices and ensuring wireless communication. In the method shown in Figure 2, the number of display devices connected to the continuous glucose sensor system 100 may be limited to, for example, two display devices. In one embodiment, each display device may be of a different type, such as a dedicated display 104a and a display 106a, while in other embodiments, both display devices may be of the same type.

[0056] In step 200, the continuous glucose sensor system 100 can be connected to the first display device. Various different techniques for authenticating and pairing the continuous glucose sensor system 100 with the first display device are used for the connection. Exemplary embodiments for authenticating and pairing the continuous glucose sensor system 100 with the display device are described below.

[0057] In step 202, the continuous glucose sensor system 100 can be connected to a second display device. Similar to the connection to the first display device, the connection used may involve various different techniques for authenticating and pairing the continuous glucose sensor system 100 with the first display device. The type of wireless connection between the continuous glucose sensor system 100 and the first display device does not have to be the same as the type of connection between the continuous glucose sensor system 100 and the second display device. For example, the continuous glucose sensor system 100 may connect to the first display device using an RF connection and to the second display device using a connection such as a Bluetooth connection.

[0058] Next, in step 204, the number of connections may be limited to a first and second display device during a specific communication interval. For example, the continuous glucose sensor system 100 may be limited to connections with two display devices at a time to conserve battery life and avoid widespread transmission of sensitive medical data. In situations where the user has, for example, multiple smartphones, tablets, laptops, or personal computers, each of which can function as a display 106a, more than two devices may be authorized to transmit. However, to conserve the battery life of the continuous glucose sensor system 100, the number of displays that can be connected at a given time may be limited.

[0059] In one embodiment, the described method for authentication between the continuous glucose sensor system 100 and the display may occur at each communication interval (e.g., every 5 minutes). The transmitter can notify each display whether communication is permitted. During a communication interval, once one device of a given type is permitted, the other device responding to the advertising activity and having the same device type as the already permitted device may be denied.

[0060] The number of devices can be limited using various different techniques. For example, the continuous glucose sensor system 100 may allow only one device of a given type (e.g., dedicated display 104a and display 106a). A list may be stored in the memory of the continuous glucose sensor system 100 to track which device types are connected to the system, and a combination of hardware-level and software-level identification and authentication may be used. Exemplary embodiments with further details on limiting the number of devices are provided below.

[0061] After pairing the devices, the user can also switch to a different device by entering a prompt through the display. In one embodiment, the user may be actively communicating with the continuous glucose sensor system 100 using a dedicated display and a smartphone and may wish to switch to using a dedicated display and a tablet. The user can request a switch by entering a command through the user interface of either the smartphone, dedicated display, or tablet. In response, the continuous glucose sensor system 100 can cease transmission to the smartphone and, after appropriate authentication, pairing, and security measures as described in detail below, can begin transmission to the tablet.

[0062] In step 206, the continuous glucose sensor system 100 may exchange the connected display device and application key. Step 206 is an optional step that occurs in several embodiments. Communication may initially be established using a fixed key. The fixed key may be based on a transmitter identifier or a portion of a transmitter identifier printed on the continuous glucose sensor system 100 or the transmitter 101. The user may establish communication by entering the transmitter identifier into dedicated displays 104a and 106a. The transmitter identifier may be transmitted from the continuous glucose sensor system 100 to the dedicated displays 104a and 106a so that a comparison can be made between the transmitter identifier received from the continuous glucose sensor system 100 and the transmitter identifier entered by the user. If the transmitter identifiers match, communication may be permitted, or additional security steps may be required to further authenticate the two devices. If the transmitter identifiers do not match, the requested connection may be rejected.

[0063] Throughout this specification, it is stated that a transmitter identifier is used to establish secure communication, but the transmitter 101 may include any other type of identifier stored in memory from the manufacturing stage. For example, a secure identifier and / or key may be stored in non-volatile memory before the initial release. The user can then download the information necessary to perform authentication on their phone, such as copying the secure identifier or key over the internet using the transmitter identifier. An online database can store decryption information for each transmitter identifier and provide this information to the user's display during the pairing process.

[0064] As an additional security measure, the continuous glucose sensor system 100 can transmit a separate application key to a connected display. The application key can remain active for a period of time, or for intervals that may be defined based on an event or other activity or inactivity. An exemplary time interval for using the application key is 4 hours. Exemplary events include taking the display offline or attempting to reconnect. In one embodiment, dedicated displays 104a and 106a may use the same application key, but in other embodiments, each display may use a different application key for secure communication.

[0065] Here, we refer to Figure 3, which illustrates an exemplary method for determining whether to allow a connection. The method in Figure 3 illustrates an exemplary implementation for connecting to a display in steps 200 and / or 202 of Figure 2. In one embodiment, a connection may be allowed when the continuous glucose sensor system 100 and the display exchange identification information. In the example in Figure 3, the identification information may include a transmitter identifier printed on the back of the continuous glucose sensor system 100 or the transmitter 101. However, transmitting the transmitter identifier itself could result in a security breach by an unauthorized device nearby that is capable of eavesdropping or intercepting the transmission. To circumvent security, an unauthorized device could eavesdrop on the transmission from the continuous glucose sensor system 100, obtain the transmitter identifier, and input the same value into another display. Therefore, the method in Figure 3 adds an additional layer of security by using a hashing algorithm on the transmitter identifier so that an unauthorized display cannot pretend to be an authorized display by eavesdropping on the transmitter identifier.

[0066] In step 300, the display can receive the first identifier. For example, the user can look at the back of the continuous glucose sensor system 100 and find the transmitter identifier printed on the back of the sensor system 100 or the transmitter 101. The display may prompt the user to enter the transmitter identifier to begin the process of establishing a connection.

[0067] In step 302, the display can create a first hash value from the first transmitter identifier. The hash value can be created using any type of hash function. The hash function is used to map data of arbitrary length to different lengths. For example, a 9-digit transmitter identifier may be entered by the user. The hash value may include the last four digits of the transmitter value. In other embodiments, the hash value may be a translation of any of the digits such that, after the execution of the hashing algorithm, combinations such as 123456789 result in ABF. It will be understood that a wide variety of hashing algorithms exist and can be used to translate data into different forms.

[0068] In step 304, the display can receive an advertising signal from the continuous glucose sensor system 100. The advertising signal is a signal used in the pairing process in which the device transmits a message advertising its effectiveness for connection. In one embodiment, the advertising activity period may last for a predetermined time interval, such as 7 seconds, and may be repeated for a predetermined number of repetitions during a given communication interval. For example, two 7-second advertising activity periods may each be used with a 5-minute communication interval. The advertising activity periods may have different durations depending on the type of device, such as 4 seconds for pairing the display and 2 seconds for pairing the dedicated display 104a.

[0069] A user can put their display into advertising activity mode, thereby causing the display to scan for any advertising signal. This process may occur, for example, when a user inserts a transmitter into the continuous glucose sensor system 100 during initial startup, or when a user wishes to add a new display to the system. A transmitter 101 on the continuous glucose sensor system 100 can broadcast advertising signals that include a hashed version of the transmitter identifier. In this embodiment, the transmitter identifier printed on the back of the continuous glucose sensor system 100 or the transmitter 101 may also be stored in memory within the continuous glucose sensor. A hashing algorithm may also be stored in memory by the continuous glucose sensor system 100, so that a hash value can be created from the stored transmitter identifier and that hash value can be transmitted to the display in the advertising signal.

[0070] After the initial connection between the continuous glucose sensor system 100 and the display, the display may enter a state where it automatically searches for advertising signals. In one embodiment, each communication interval by the transmitter includes a process of receiving an advertising signal and performing authentication. The display can enter a state where it automatically searches for advertising signals by knowing that the transmitter has started up and is periodically transmitting advertising signals. Therefore, the display does not need to continuously search for advertising signals, and the display can save battery life. However, in other embodiments, the display may remain in a state where it constantly monitors advertising signals by the user's dedicated display 104a or another display 106a such as a smartphone.

[0071] In step 306, the display analyzes at least one of the advertising signals associated with the advertising signal to identify a second hash value. In one embodiment, the second hash value may be the result of implementing a hashing algorithm on a transmitter identifier stored in memory by the continuous glucose sensor system 100. The second hash value may be transmitted to the advertising signal itself. The advertising signal may include a payload with a short name, a flag, a unique user identifier, and manufacturing data. The short name and unique user identifier may be, for example, 128 bits and can identify the transmitter. The manufacturing data area may contain the transmitter hash value used in the authentication stage. In another embodiment, the second hash value may be transmitted in the signal associated with the advertising signal. For example, after receiving the advertising signal and authorizing the connection, the second hash value may be transmitted automatically or in response to a request.

[0072] The hashing algorithm can be either one-way, meaning the original value cannot be obtained from the hash value, or two-way, meaning the hash value can be reconstructed into the original transmitter identifier. In addition, hashing may include AES 128-bit encryption using Electronic CodeBook mode, other forms of encryption, cryptography, and other techniques for transforming the transmitter identifier into a hash value. As a result, in one embodiment, the transmitter identifier is not transmitted from the continuous glucose sensor in the advertising signal. Instead, a hash value may be transmitted. An unauthorized display receiving this hash value cannot recreate the original transmitter identifier and therefore cannot improperly input the transmitter identifier into another display to gain unauthorized access. As an example, a 16-byte key may be created by repeating a first 4-byte transmitter identifier four times in sequence. The key may optionally be provided to an AES 128-bit algorithm using Electronic CodeBook mode. Both the continuous glucose sensor system 100 and the display can compute the key.

[0073] Next, the display can compare the first hash value with the second hash value. In one embodiment, the hashing algorithm may be designed such that an exact match of the same symbols results in a match. Continuing from the example above, the display can create a key and compare it with the hash value received in the advertisement signal. In other embodiments, a match occurs even if there are no identical symbols present in the first and second hash values. For example, a match may be observed if the first and second hash values ​​differ by a predetermined amount. The first hash value may be 123 and the second hash value may be 456. These two do not match in that they are the same set of symbols, but the hashing algorithm can recognize that the first numeric input in the second hash value should be one greater than the last numeric input in the first hash value. Many other examples are possible.

[0074] The second hash value may also be a key required to reverse the hashing algorithm. Instead of transmitting the hash value of the transmitter identifier, the second hash value may be a key required by the authentication device to reverse or decrypt the encrypted transmitter identifier. If the transmitter identifier can be obtained using the second hash value as a key, a match may be found. Thus, it will be understood that the hashing algorithm performed on the display and the hashing algorithm performed on the continuous glucose sensor system 100 do not need to be the same algorithm or to produce the same set of symbols. Instead, the first and second hashing algorithms may be designed to produce first and second hash values ​​that have a predetermined relationship that results in a match.

[0075] If no match is found, the connection may be rejected in step 310. However, if a match is found, the connection may be permitted in step 312. In one embodiment, communication between the continuous glucose sensor system 100 and the display can be brought about by performing the method shown in Figure 3. However, performing step 312 to permit the connection also includes embodiments in which the process of complete pairing of the devices may continue in a further step. That is, the result of step 312 may be, for example, a connection in the form of an insecure connection. An additional step may be taken to secure the connection.

[0076] For example, in addition to hashing the transmitter identifier, additional steps may be included before communication can be exchanged between the continuous glucose sensor system 100 and the display, such as access to a whitelist containing authorized devices, exchange of application keys, and use of encryption. These additional steps are described in subsequent embodiments (e.g., Figures 4-8 and 13-15) and can be used instead of or in addition to the exemplary method of Figure 3. In one embodiment, after step 312, a message indicating that the continuous glucose sensor system 100 has been paired with the display may be displayed to the user, either alone or together with a message indicating that further authentication may occur.

[0077] Therefore, the method in Figure 3 allows hash values ​​to be exchanged between the continuous glucose sensor system 100 and the display for use in the authentication process. The hash values ​​may differ based on the specific display requesting the connection. For example, as will be described later, the type of each display may also be known and can be identified within the system. The continuous glucose sensor system 100 may use a first hashing algorithm for a first type of display and a second hashing algorithm for a second type of display.

[0078] Figure 4 illustrates an exemplary method for authenticating and establishing communication between a continuous glucose sensor and multiple displays, which may be part of steps 200 and 202 in Figure 2. The embodiment in Figure 4 provides an additional level of security by exchanging application keys before transmitting data regarding glucose values ​​from the continuous glucose sensor to the displays. The application keys are generated by software and may be updated periodically, as described later.

[0079] In step 400, the display can receive an advertising signal from the continuous glucose sensor system 100, and then establish a connection in step 402. The process of establishing a connection may also include comparing identification information, such as the type of device, with a whitelist stored in memory, as will be described in more detail later in Figures 6, 7, and 13-15. In this example, Bluetooth communication can provide the advertising signal and the steps of establishing a connection.

[0080] Next, in steps 404 and 406, a first key may be received and compared with a second key. Referring to Figure 3, the first key may be a hashed version of the transmitter identifier, a key used to decrypt the transmitter identifier, or other information associated with the encryption and decryption of the transmitter identifier, thus preventing improper misuse by unauthorized devices. The first key may be received in step 404 in response to a request sent from the display to the continuous glucose sensor system 100 when the connection is established. In other embodiments, the display may receive the first key automatically when the connection is established or in an advertising signal.

[0081] A process to verify the match between a first hash value and a second hash value may occur on a continuous glucose sensor or display. After the advertising period and connection establishment, the first key may be transmitted in response to a request including a challenge value. The challenge value can be used to encrypt the transmitter identifier or to perform a hashing algorithm on the transmitter identifier to create the first key.

[0082] In step 406, the first key can be compared with the second key. As previously mentioned, a match can be found in various environments where a predetermined relationship exists between the first key and the second key. If the comparison results in a match between the first key and the second key, the continuous glucose sensor system 100 and the display can be authenticated in step 408.

[0083] Next, in step 410, an application key may be exchanged between the continuous glucose sensor system 100 and the display. In the embodiment of Figure 4, in addition to exchanging keys between the continuous glucose sensor system 100 and the display, the application key can also be used to provide secure communication. In one embodiment, the transmitter identifier may be printed on the back of the transmitter 101. As a result, an unauthorized user could see the transmitter identifier and use that information to improperly authenticate the user's display. In addition, in one embodiment, the transmitter identifier may remain the same, giving a user attempting to intercept communications a further opportunity to attempt to circumvent hashing or encryption of the transmitter identifier over a long period of time. The addition of an additional application key provides additional security and the ability to periodically change the key, ensuring continuous secure communication.

[0084] The application key can be transmitted either from the continuous glucose sensor system 100 to the display, or from the display to the continuous glucose sensor system 100. The device receiving the application key can provide an acknowledgment that it has accepted the application key in step 412. In some embodiments, the receiving device may not acknowledge the application key due to a communication error. For example, in an embodiment where the display transmits the application key to the transmitter, the display may be outside the radio range from the transmitter 101. In another example, the transmitter 101 may receive the application key and send an acknowledgment back to the display, but the display may not receive the acknowledgment. In an example where the acknowledgment is not received, the display may operate according to some arbitrary embodiment.

[0085] In one embodiment, the display may abort the communication and attempt to resend the application key. In this embodiment, steps 410 and 412 may be repeated until successful acknowledgment of the application key is received. In another embodiment, the display may switch to using the application key even if acknowledgment is not received. If the communication is successful and the display receives a response to a command based on the application key, the display may continue to use the application key even though acknowledgment is not received. Instead of confirming receipt of the application key through subsequent successful communications, the display either missed displaying the response acknowledgment message or experienced a communication error. Another option to deal with a situation where acknowledgment is not received is to continue using any previous application key. In this embodiment, the display may retain both previous and unacknowledged application keys until acknowledgment is received or a new communication interval begins. In addition, the display may repeat step 410 by sending an application key until acknowledgment is received again.

[0086] Once approval is received, communication between the continuous glucose sensor system 100 and the display can be permitted, and data regarding glucose values ​​can be transmitted from the continuous glucose sensor system 100 to the display. The process in Figure 4 may be repeated for each display connected to the continuous glucose sensor system 100. The connection process may proceed simultaneously or sequentially between the continuous glucose sensor system 100 and multiple displays. In addition, the application key does not have to be the same for each display. In one embodiment, each pair of display and continuous glucose sensor system 100 may use a different application key.

[0087] Here, we refer to Figure 5, which illustrates an exemplary method for updating the application key. The method illustrated in Figure 5 can be used in addition to the method in Figure 4, as well as in other embodiments. By regularly updating the application key, security can be enhanced and repeated attempts to access secure medical data transmissions can be neutralized.

[0088] In step 500, the continuous glucose sensor system 100 and the display may remain in a waiting state for a certain period of time or until an activity occurs. During the waiting period, communication between the continuous glucose sensor system 100 and the display can be maintained using the current application key. The process of switching to a new application key may occur at predetermined time intervals, such as every hour, or when a specific activity occurs. Examples of activities that may trigger the exchange of a new application key include taking the display offline and then bringing it back online (for example, the display losing its network connection to the continuous glucose sensor system 100 and then restoring the connection), a user switching to a new display, or rejecting an attempt by another display to connect to the continuous glucose sensor system 100.

[0089] In step 502, the display or the continuous glucose sensor system 100 can create a new application key. In embodiments where the display transmits the new application key to the continuous glucose sensor system 100, the display can create the new application key. The key may be created before step 500, during a waiting period, or for a certain period in step 500 or upon detection of activity.

[0090] In step 504, a new application key may be transmitted to a receiving device. For example, a display may transmit the new application key to the continuous glucose sensor system 100. Next, an acknowledgment indicating that the new application key has been accepted may be received in step 506. Similar to the embodiment in Figure 4, various techniques may be used to address situations where acknowledgment of the new application key is not received. Thus, the techniques described with reference to Figure 4 are similarly applied to switching to a new application key.

[0091] Once acceptance is received, further communication may occur in step 508. In one embodiment, further communication can occur even if no approval is received by continuing to use the previous key as described above. This allows the user to operate uninterrupted while the process in Figure 5 is repeated, and successfully update the application key. Figure 5 may be repeated in step 510, for example, at predetermined time intervals, when activity is detected, and when successful approval of the new key is not received.

[0092] Another problem that arises relates to both saving battery life and limiting the number of display devices that can be connected to the continuous glucose sensor system 100 in a given time. Connecting too many devices at once would require the continuous glucose sensor 100 to communicate with many devices, reducing the period during which the continuous glucose sensor 100 can enter a low-power hibernation state, thus increasing the burden on the battery lift of the continuous glucose sensor 100. Figure 6 illustrates an exemplary method for connecting a continuous glucose sensor to one or more displays based on the device type. Figure 6 is an example of limiting connections as described with reference to step 204 of Figure 2.

[0093] The continuous glucose sensor system 100 may be a small, battery-powered device worn on the user's body. Therefore, saving battery life may be an important consideration when providing a system that can continuously monitor glucose levels. Each data transmission between the continuous glucose sensor system 100 and a display consumes battery life. To save battery life, the transmitter 101 on the continuous glucose sensor system 100 may be put into a dormant state and periodically activated, such as at 5-minute intervals. In addition, the continuous glucose sensor system 100 itself may also be put into a dormant state and periodically activated. As an additional measure to save battery life, in one embodiment, the number of displays exchanging data and commands with the continuous glucose sensor system 100 can be limited. Figure 6 illustrates exemplary methods for limiting the number of devices connected to the continuous glucose sensor system 100, based on the type of device.

[0094] In step 600, the continuous glucose sensor may receive a request to pair with a first device type. For example, a dedicated display 104a may request a connection with the continuous glucose sensor system 100. In one embodiment, the request may arise as part of an advertising activity and connection process as described above. The request may include an indication of the type of device requesting a connection with the continuous glucose sensor system 100. The device type may be included in the message, or the device type may be determined by the continuous glucose sensor system 100 based on other information included in or associated with the request. For example, the device type may be determined using a device type identifier, or the user may provide input to a display indicating the type of device, such as a tablet, personal computer, or smartphone.

[0095] A continuous glucose sensor can store in memory a first list of devices and associated device types. The first list may be empty initially, and when a new device is paired, authenticated, and connected, that device may be added to the first list in memory. The first list may be a whitelist, which is a hardware-level list of permitted device types. Devices with unrecognized device types may be rejected from connection requests. Upon receiving a request indicating a first type of device requesting connection, in step 602, the continuous glucose sensor system 100 may compare the first type of device with the first list stored in memory. In step 604, the continuous glucose sensor system 100 may determine whether a device having the first type is already included in the first list. If a device having a given device type (e.g., a dedicated display or other display) is not on the first list and the device type is recognized, in step 606, the device may be added to the first list to allow pairing. If the device is already on the first list, the method may proceed to step 608.

[0096] If another device having the requested device type is already included in the first list, the continuous glucose sensor system 100 can determine whether the maximum number of devices having that device type is already included in the first list. For example, the first list may allow registration of each device having a certain number of devices of a given type, such as one device, two devices, five devices, or any other number, based on memory size and other system considerations. The process in steps 600-606 may be repeated for additional devices seeking connection with the continuous glucose sensor system 100. In one embodiment, a single dedicated display 104a and another type of single display 106a may be connected to the continuous glucose sensor system 100.

[0097] In addition, the advertising period may vary based on the number of devices in the first list. In one embodiment, if the first list is empty and no displays are authenticated, a single advertising period may be used. If a display responds but the connection is rejected during the advertising period, the advertising period may continue for the remainder of its duration. In examples where at least one display is already included in the first list, two advertising periods may be used. If a display is rejected and the advertising period in which the display was rejected still has remaining time, the continuous glucose sensor system 100 may continue advertising for the remainder of the period. Optionally, if one display is included in the first list, the second advertising period may not need to use comparison to determine whether the requested device type is included in the first list. In embodiments where the first list is full, such as when the first list includes devices of a device type that is a dedicated display and devices of a device type that is a different display, a filter using the first list may be active for two advertising periods.

[0098] In step 608, the continuous glucose sensor system 100 can proceed to determine whether the coupling information is included in a second list. The first list contains a list of devices that can proceed to the advertising activity and pairing process, while the second list may, in one embodiment, be a software-level list containing coupling information obtained from a successful pairing between the continuous glucose sensor system 100 and a display. The first and second lists may be stored in non-volatile memory. As a result, if a display requesting a connection has previously paired and connected with the continuous glucose sensor system 100, its coupling information may be stored in the second list by the continuous glucose sensor system 100. By storing the coupling information, the connection process can proceed without delay the next time a device requests a connection.

[0099] In one embodiment, the binding information may include information used to establish a connection. In addition, the binding information may include additional authentication information such as a transmitter identifier, a hashed transmitter identifier, an encryption or decryption key, a current application key, and a previous application key. If binding information relating to a device requesting a connection is already included in the second list, a connection can be established in 610, allowing the transmission of commands from the display to the continuous glucose sensor system 100 and data relating to glucose values ​​from the continuous glucose sensor to the display.

[0100] However, if the coupling information relating to the display requesting the connection is not included in the second list, the process may proceed to a pairing process, which may include steps necessary to establish a given type of connection. For example, the pairing process may occur in step 612, which may include any of the embodiments described above.

[0101] Figure 7 illustrates an exemplary system diagram for storing connection information. As described with reference to Figure 1, the continuous glucose sensor system 100 can be wirelessly connected to dedicated displays 104 and 106. The continuous glucose sensor system 100 may include a memory 700 for storing various information used to implement the disclosed embodiments. In some embodiments, a whitelist 702, also referred to as the first list, may include a list of device types permitted to connect with the continuous glucose sensor system 100.

[0102] As illustrated, the list may include two columns for each type of device, one for dedicated displays 104a and the other for other displays 106a. In other embodiments, additional columns may be included, allowing for further granularity of device types. For example, instead of a classification of devices having a certain type of display, each specific type of display, such as tablets, personal computers, laptops, or smartphones, may be stored separately. In addition, it will be understood that permitted device types may be stored in various other forms, including databases, although they are described as a first list and illustrated as a table. In the example shown in Figure 7, the whitelist 702 has previously registered dedicated displays having device identifier ID DISP1.

[0103] The continuous glucose sensor system 100 can also store coupling information, as shown in a separate Table 704, in the memory 700. The coupling information may include, for example, information used to pair and authenticate a display for communication with the continuous glucose sensor system 100. The coupling information may be stored in the display connected to the continuous glucose sensor system 100 and may be persistently retained in memory for future reconnection.

[0104] In one embodiment, the dedicated display 104 may also include, for example, a memory 706 for storing combination information 708 and an application key 710. The stored application keys may include both the current application key and previous application keys. Similarly, the display 106 may include a memory 712 having combination information 708 and an arbitrary application key 710.

[0105] Figure 8 illustrates an exemplary method for removing a display from an authorized list of displays. After a device has been added to a whitelist and its binding information has been stored, a user may want to remove a device from the whitelist or remove its binding information. For example, a user may want to clear all devices from memory or remove a single device when they switch to their smartphone. In addition, there is the challenge that a user may lose or break a display device, and therefore cannot remove the display device from the authorized list of displays. The method in Figure 8 provides an example of how older display devices may be periodically removed from the whitelist, where it can indicate that the user is no longer using that display device if they have not recently communicated with transmitter 101.

[0106] In step 800, the system may receive a request to remove a device from the list of authorized displays. For example, a user may indicate that they are using their current smartphone and wish to remove it before adding a new display. The request may be entered through the user interface on the display and transmitted to the continuous glucose sensor system 100. The continuous glucose sensor system 100 receives the request to remove the device from its list of authorized displays. In other embodiments, the user may provide input to remove a display from a device other than the display to be removed. For example, the continuous glucose sensor system 100 may provide a list of authorized devices on a dedicated display. The user can then provide a command from the dedicated display to remove a different display, such as a smartphone. In this way, a lost smartphone or other display can be removed and replaced using the dedicated display. Similarly, a command to remove and replace the dedicated display can be provided using another display, allowing for its replacement if the dedicated display is lost or malfunctioning.

[0107] Step 800 may be performed automatically without any request from the user. In one embodiment, a display may be excluded from the list if it has not been connected to the continuous glucose sensor system 100 over a given period and / or connection interval. For example, a display that has not been connected to the continuous glucose sensor for the past 15 minutes, 30 seconds, 1 hour, 1 day, or 2 weeks may be excluded from the first list. As another example, a display that has not been connected to the continuous glucose sensor for a given number of previous communication intervals, such as two, three, or four, may be excluded from the first list. However, it should be noted that in some embodiments, previous connection information may be retained in a second list to facilitate subsequent quick reconnection without requiring user input. The process of automatically excluding displays that have not been connected for a certain period of time may be used in conjunction with allowing the user to request the exclusion of the devices considered earlier.

[0108] In step 802, the continuous glucose sensor system 100 may remove a device from its first list. In one embodiment, the display to be removed may be removed from a whitelist. Alternatively, the display may be removed from a second list containing binding information. However, in one embodiment, the display may be removed from the whitelist, but its binding information may be retained in the second list to facilitate the subsequent reconnection of the removed display. The device may store up to a certain number of display devices, such as five, with devices having the most recent communications placed at the beginning of the list and devices having older communications or discontinued communications placed at the end of the list. Older devices that have not had recent communications compared to other devices on the list may be removed to make space for new devices, as new devices may need to be added to the list (as described later). The continuous glucose sensor system 100 may also transmit a message to dedicated displays and displays indicating that a particular device should be removed from the list of authorized devices.

[0109] Next, in step 804, a new device having the same device type as the excluded device may be authenticated. Naturally, in the embodiments described above, devices of different types may be added at any time until the maximum number of devices of different types is reached. However, if the whitelist is full and it is no longer possible to store any more devices of a given type, the user may wish to remove an old device from the list and replace it with a new device of the same type. One example is when a user upgrades their tablet and replaces it with a new device. The request may arise, for example, from the new device and may trigger the authentication and pairing process described above.

[0110] In step 806, the new device may be added to the whitelist using the techniques described above. In addition, the new device may complete the authentication and pairing process so that it can be stored in the second list.

[0111] Figure 9 illustrates an exemplary method for updating data in response to a command. A system having a continuous glucose sensor system 100 that transmits data to multiple displays may encounter synchronization challenges associated with the presentation of data regarding glucose values. The user expects the same glucose values ​​to be displayed on each of the dedicated display 104a and display 106a, since both displays draw the user's data from the same continuous glucose sensor system 100. However, each display may also provide the continuous glucose sensor system 100 with commands that can change the glucose data. For example, when the user replaces their sensor 103, one of the displays may send a command to activate sensor 103. In one embodiment, the command to activate sensor 103 may cause the continuous glucose sensor to enter a warm-up phase, during which a calibration level is input to ensure accuracy. In another example, one of the displays may transmit a command to the continuous glucose sensor system 100 to stop sensor 103 before removing it or when it is necessary to take sensor 103 offline. Another example is the transmission of calibration commands from a display to the continuous glucose sensor system 100.

[0112] In some embodiments, the transmitter 101 on the continuous glucose sensor system 100 is active intermittently, such as every 5 minutes, so commands may not be immediately received by the continuous glucose sensor system 100. The user expects to receive an indication that the command has been received immediately. In addition, when the continuous glucose sensor system 100 enters an active state, it may process commands from displays that did not initially send commands. As a result, the display that did not send commands may receive glucose values ​​from the most recent 5 minutes, while the second display may then send a command to stop the continuous glucose sensor system 100 or to use new calibration values. Once that command is processed, the second display will show new glucose values ​​based on the new calibration or a different sensor state, such as offline, even while the other display continues to show outdated glucose values ​​or sensor status. This means that one display may show outdated data compared to the display that sent the command until the next cycle, when the continuous glucose sensor becomes active and sends updated glucose values ​​or sensor status to both displays. Figures 9-11 illustrate exemplary embodiments for updating both displays in response to a command.

[0113] In step 900, the transmitter 101 on the continuous glucose sensor system 100 can enter an idle state. In one embodiment, the idle state may last for 5 minutes. During the idle time, the display can receive commands in step 902. Commands are queued and can be sent to the continuous glucose sensor system 100 in batch transfer when the active state is resumed. However, the display may be in an intermediate state, during which time it also provides the user with confirmation that a command has been received. For example, the user can enter a command to stop the sensor 103. Since no commands can be sent while the transmitter of the continuous glucose sensor system 100 is idle, the display may continue to indicate an active status for the sensor 103 even after the user has entered a command to stop the sensor 103.

[0114] Therefore, the display may be put into an intermediate state in step 904, for example, by displaying an indication that a command has been received and is being processed. In addition, the display may illustrate an exemplary time for the command to complete, based on the remaining time until the transmitter resumes the active state. Figure 10A illustrates an exemplary user interface in an intermediate state. A message may be displayed indicating that a command has been received and calibration is pending, as shown at 1000. In this example, the command may request recalibration, but various other commands can also be used.

[0115] During the intermediate state, before a new glucose value is received from the continuous glucose sensor system 100 based on a new calibration, the display 106a and / or dedicated display 104a may also display a new glucose value based on an estimated new calibration. Once accurate calibration is completed using the continuous glucose sensor system 100, the updated value received from the transmitter 101 may be used instead of the estimated value. While the estimated value is displayed, the user may receive, as part of the intermediate state notification, an indication that the estimated value is being displayed and optionally an indication that the estimated value will be updated when calibration is complete.

[0116] In step 906, the transmitter 101 on the continuous glucose sensor system 100 is activated, and a command may be sent from the display to the continuous glucose sensor system 100. In step 908, the continuous glucose sensor system 100 may process the command and send a response back to the display indicating that the command has been sent. Then, in step 910, the display may be removed from the intermediate state and the updated data may be displayed. For example, as shown in Figure 10B, a message 1002 may be displayed indicating that the command is complete and new data is shown.

[0117] Figure 11 illustrates an exemplary method for updating multiple displays in response to a command. In step 1100, one or more displays can be connected to transmitters on the continuous glucose sensor system 100 as described above. At specific times, for example, periodically when transmitter 101 enters an active state, a command may be authorized in step 1102. Transmitter 101 can then transmit glucose data to the connected displays in step 1104 while in the active state.

[0118] In step 1106, the display can receive a calibration command from the user and provide the calibration command to the continuous glucose sensor system 100 at a specific time. This specific time may be when the transmitter 101 of the continuous glucose sensor system 100 enters an active state. Upon receiving the calibration command, the continuous glucose sensor system 100 can perform the requested calibration and calculate the updated glucose value based on the new calibration in step 1108. In one embodiment, either the dedicated display 104a or the display 106a can provide the calibration command.

[0119] Calibration commands can be provided by the user at any time, or they may be provided by the user in response to a prompt. The continuous glucose sensor system 100 can record the time of the last calibration and track when a specified amount of time has elapsed since the last calibration. After a certain period of time, such as three weeks, the continuous glucose sensor system 100 can transmit a message to a dedicated display, another display, or both, prompting the user that it is time to perform another calibration. The continuous glucose sensor system 100 can also send a message prompting calibration in response to the detection of insertion, or otherwise the use of a new sensor 103. Messages prompting calibration can also be considered alarms, and alarms may increase over time. If the user does not perform a calibration, the continuous glucose sensor system 100 can eventually transmit an error message to the display indicating that the sensor 103 is out of calibration and that the displayed value may not be accurate. In addition, the glucose value will not be displayed until the calibration is successful. In another embodiment, the display 106a or dedicated display 104a can track the time when calibration was last performed and, once a predetermined time has elapsed, prompt the user to perform calibration.

[0120] Next, in step 1110, the continuous glucose sensor system 100 can transmit data regarding glucose values ​​based on the new calibration to both the display that requested calibration and any other connected displays. This transmission may occur even if the displays have already received updated data regarding glucose values ​​during this communication interval. In one embodiment, new data may be displayed to the user, but previously transmitted data may be stored in addition to the new data during the communication interval. For example, the user can initiate calibration through the dedicated display 104, and upon successful completion, the continuous glucose sensor system 100 can transmit updated data regarding glucose values ​​to both the dedicated display 104 and display 106 during the same communication interval. This avoids the problem of one display showing the user outdated data. The order of generated glucose values ​​may also be recorded so that only data values ​​generated after the new calibration are transmitted to the dedicated displays 104a and display 106a. In other embodiments, new and old data may be displayed to the user, with the old data being distinguished from the new data by a label, shading, color, or other type of user instruction that distinguishes the old data from the new data. In addition, both new and old data can be collected and stored for later analysis and troubleshooting.

[0121] Figure 12 illustrates an exemplary state diagram relating to the connection of a continuous glucose sensor system 100 and its transmitter. In 1200, the transmitter 101 may be in memory mode before installation or use of the continuous glucose sensor system 100. The memory mode may be the mode in which the transmitter 101 is first sold and may include a low power consumption state. When a connection to the continuous glucose sensor system 100 is detected, the transmitter 101 can enter active mode 1202 for future operation. During initial startup, the transmitter 101 can automatically enter active mode 1202 within a certain period, such as 10 minutes, after being connected to an active continuous glucose sensor system 100. A new display can scan to identify the transmitter 101 that will be active for a certain period after the user enters a transmitter identifier using the display. In one example, the display may, after the transmitter identifier is entered, scan for 10 minutes to give the user time to connect the transmitter 101 to the continuous glucose sensor system 100 and activate the transmitter 101.

[0122] As previously discussed, the transmitter 101 can periodically enter a pause mode 1204 and return from the pause mode to the active mode 1202 at predetermined intervals. The transition to the active mode can be completed in accordance with the acquisition of raw sensor data 1206, which may be an ongoing process in which the continuous glucose sensor system 100 acquires a series of raw data values ​​from the user. The raw data values ​​can be subjected to algorithmic processing 1208 by the continuous glucose sensor system 100. Algorithmic processing can convert raw data values ​​such as voltage or current measurement values ​​into familiar units of glucose value such as mg / dL.

[0123] The transmitter 101 can periodically enter an advertising activity state 1210. In the advertising activity state, it advertises to any nearby display requesting a connection with the continuous glucose sensor system 100 and receives data on glucose values ​​generated by the algorithmic processing step 1208. The advertising activity state can continue for a certain period, such as 7 seconds. If no display is detected during advertising activity, the transmitter 101 can terminate the advertising activity and enter a pause mode 1204 for a certain period, such as 5 minutes, until the next connection interval.

[0124] However, if a display is detected in response to the advertising activity state 1210, authentication mode 1212 is generated, thereby causing the transmitter 101 to perform the aforementioned authentication process. Specifically, the display can verify the advertising activity packet by implementing a hashing algorithm based on the transmitter identifier entered by the user. The authentication process may also include sending a challenge from the display to the transmitter 101 using the transmitter identifier, and sending an application key request. Furthermore, the device type of the display may be transmitted for verification against a whitelist. If authentication with a given display fails, such as when the display is not on the whitelist, or if the hashing algorithm or key exchange fails, or for other reasons, the transmitter 101 may reactivate the advertising activity state 1210 and decide whether any other displays are requesting a connection.

[0125] If the authentication mode is successful, the transmitter 101 enters a state in 1214 where it acknowledges that the display is active for this session. While active, the display can send commands to the transmitter 101 via requests. The transmitter 101 enters a command active state 1216, processes the command, for example by going through a calibration process, and sends a response. After the command has been processed, the transmitter 101 can resume advertising activity to any other display requesting communication by ending the session. If there is no response, the transmitter 101 returns to a paused mode 1204 until the next active mode state 1202.

[0126] Figure 13 illustrates an exemplary embodiment of communication between the transmitter 101 and the dedicated display 104a or display 106a during authentication and pairing. Figure 13 is an example of an implementation relating to Figure 4 described above. In step 1300, the transmitter 101 may advertise a packet containing the name of the transmitter to facilitate the connection. For example, the name of the transmitter may be displayed on the graphical user interface of the display, and the user may choose to proceed with the connection. In other embodiments, the connection process may proceed automatically, so no choice is necessary.

[0127] In step 1302, the display and the transmitter 101 may establish an insecure connection. The connection process includes the display verifying the advertising activity packets contained in the hash value of the transmitter. The verification process may be performed using a hashing algorithm on the transmitter identifier entered by the user using the display. If the hash values ​​match, the connection process continues. If they do not match, the connection process terminates.

[0128] In step 1304, the display requests a challenge by sending a challenge value. The challenge may use a transmitter identifier or application key having the requested display type. Errors in the packet may result in an error response returned from the transmitter. If the packet is received correctly, the transmitter 101 and / or the continuous glucose sensor system 100 can compute a hash using the display challenge value and, for example, the transmitter identifier as keys using the AES 128 algorithm.

[0129] Next, in step 1306, the transmitter 101 and / or the continuous glucose sensor system 100 calculate a hash value based on a display challenge value having the transmitter identifier as the key, and send the calculated hash value back to the display. The display compares the received transmitter hash value with the hash value calculated by the display. If the two match, the connection sequence continues. If they do not match, the connection is terminated. The response to the challenge from the display may include a challenge value from the transmitter 101. In this way, the display can send a challenge to the transmitter 101, and the transmitter 101 can send a challenge to the display.

[0130] In step 1308, the transmitter 101 and the display perform a coupling process. In one embodiment, the display may calculate a hash value based on a challenge value received from the transmitter 101, again using the transmitter identifier as the key. The display sends the calculated hash value back to the transmitter 101. If any errors are detected in the packet, the transmitter 101 may return an error response. If no errors are present, the transmitter 101 compares the hash value received from the display with its own calculated hash value. If the two hash values ​​match, the sequence continues. Otherwise, the connection is terminated. At this point, the display and the transmitter 101 undergo bidirectional authentication to establish a secure connection. Short-term and long-term keys may be exchanged over the first connection. Once the pairing and coupling process is complete, the coupling table or list may be updated with coupling information including hash values, keys, long-term keys, short-term keys, device types, and other values ​​used to establish communication. Here, the communication and transmission of data relating to glucose values ​​may be sent to a display, and the display can send any command or other information to the transmitter 101.

[0131] In one embodiment, the display may also transmit an application key to the transmitter 101 in step 1310. The transmitter 101 may initially use a transmitter identifier for the encryption key, but the key may change to enhance application security. The transmitter identifier may be printed on the back of the transmitter 101, which could lead to its leakage. Also, the transmitter identifier remains the same value for a long period of time, thus exposing it to repeated attacks over a long period. Switching to an application key provides enhanced security and the ability to change the key over time. The application key may be transmitted over a secure link using encryption, such as Bluetooth encryption.

[0132] The display can store the application key and the previous application key in semi-permanent non-volatile memory. The transmitter 101 records the new application key and sends back an instruction to the display that the application key has been accepted in step 1312. Upon receiving a response indicating that the application key has been accepted, in one embodiment, the transmitter 101 may delete the old application key. Before deleting the old application key, communication may also be tested using the new application key. If the display does not receive a response indicating acceptance of the application key, it retains both the old and new application keys. In the next communication cycle, when the transmitter 101 enters an awakened state, the display may first attempt to use communication with the new application key. If successful, the old application key may be deleted. If unsuccessful, communication may continue using the old application key, and the display may resume the process of sending the new application key to the transmitter 101.

[0133] Figure 14 illustrates exemplary use cases in which a connection may be rejected. One example is when an unknown device type attempts to connect to the continuous glucose sensor system 100, as shown in 1402. The device type may be an eigenvalue designed for exchange with the continuous glucose sensor system 100. As a result, a display transmitting a device type that does not match the expected value has a connection request that is rejected in 1400.

[0134] Another example is when overlapping device types occur in 1404. In one embodiment, only one device can connect to a dedicated display 104a and one display 106a during each communication interval. A user may have, for example, two smartphones, each of which can connect to the continuous glucose sensor system 100, but only one connection to that device type may be permitted during a given communication interval. A second device having overlapping device types may have connection requests that are rejected.

[0135] Devices that are actively and pre-connected to the continuous glucose sensor system 100 may also be rejected if they do not comply with the authentication protocol, as shown in 1406. In one embodiment, a display may be required to comply with the authentication protocol at each communication interval and in response to a connection request. Active and whitelisted devices may still be rejected if they attempt to circumvent the authentication protocol.

[0136] Another example of rejecting a connection request involves a hash value mismatch 1408. A hash value mismatch may occur at any step in the bidirectional authentication process, causing the continuous glucose sensor system 100 to reject the connection request within a given communication interval. Finally, another example involves repeated application key failures 1410. If authentication with the application key fails, the display may disconnect from the transmitter 101 and reject the connection. This process may be repeated during the next communication interval. In the third cycle, the display may again attempt to connect with the application key, and if that fails, it may revert to using the transmitter identifier as the key for authentication. The display may then establish and replace a new application key.

[0137] Figure 15 illustrates an exemplary use case for connecting to a display. In the first example, there may be no display in the area at 1500, so transmitter 101 advertises for a period at 1502 and then resumes from hibernation. At 1510, if a display is within wireless communication range but the display has not been properly authenticated within the allocated time, transmitter 101 can resume advertising activity if the advertising period (e.g., 7 seconds) has not yet expired. At 1512, after the advertising time has expired, transmitter 101 reverts to hibernation.

[0138] In 1520, if a display is near enough to correctly authenticate the transmitter and couple with it, the transmitter 101 may, after authentication, restrict the couple and take other activities as shown in 1522. Specifically, after authentication, couples may only be possible for the type of display currently connected. After the connection times out or is disconnected, the transmitter 101 may disable the whitelist filter and resume advertising activity during the same communication interval. In the next communication interval, the whitelist filter may be active for the duration of the first advertising activity period. The whitelist filter may then be disabled for the duration of the second advertising activity period. When the whitelist filter is active, other uncoupled displays may be rejected, and the transmitter 101 may transition to advertising activity.

[0139] In step 1530, if the two displays correctly authenticate the transmitter 101 and connect with it, the transmitter 101 has an active whitelist in 1532 and can connect both displays. Specifically, the whitelist filter may be active over two advertising activity periods through the communication interval. Both connected displays are allowed to connect to the transmitter 101 in the same communication interval. If the whitelist filter is active, other unconnected displays are rejected, and the transmitter 101 transitions to the advertising activity state.

[0140] In step 1540, if a previously connected and coupled display does not connect to the transmitter 101 over a given number of communication intervals, such as two intervals, the previously connected display may be removed from the whitelist in step 1542. The coupling information of the absent displays may be retained in the coupling list. In this example, the whitelist filter may be active for the first advertising activity period and prioritize already coupled displays. The whitelist filter may be disabled for the second communication interval, allowing the connection and authentication of other displays. Once coupling is permitted for a given type of display, another display of the same type will be rejected from coupling, even if it is properly authenticated. After this rejection, the transmitter 101 may proceed to the advertising activity state if the advertising period has not yet expired.

[0141] If a previously connected display, such as a smartphone, that has been removed from the whitelist attempts to reconnect at 1550, the previously connected display does not need to manually accept the connection request if it is still on the connection list. Instead, the connection will proceed automatically at 1552.

[0142] In 1560, if an additional device is joined when the join list is full, the join information of the oldest joined display may be overwritten in 1562. In one embodiment, the join list may maintain a circular queue that stores up to three displays. If an additional display is joined and the queue is full, the transmitter 101 may overwrite the oldest join information.

[0143] At 1570, an erase command may be provided from the authenticated and combined display to delete all combinations. Transmitter 101 can respond to the erase command at 1572 by erasing the whitelist and deleting all combination information.

[0144] Figure 16 illustrates exemplary state diagrams of dedicated displays 104a and / or 106a. One problem that arises is the transition of the displays to and from various states during use, such as an idle state between communication intervals, a state searching for available connections, and an active state for data transmission. The method in Figure 16 illustrates these transitions between various states consistent with a particular embodiment.

[0145] At 1600, the display may be in a locked state. In the locked state, the display has successfully connected and paired with transmitter 101. Synchronization characteristics can be shared between the two devices, allowing them to coordinate the next advertising activity event. In this state, the display has no radio activity with the continuous glucose sensor / transmitter between each connection cycle, which may occur approximately every 5 minutes. During this state, the display can scan for a certain period, such as 25 seconds, and reconnect to transmitter 101. In addition, an additional lead time, such as 500 milliseconds, may be added for an additional scan before the coordinated advertising event. If the display fails to connect to transmitter 101 on the first attempt, it can be retried at 5-minute intervals from the original coordinated advertising event. After 30 minutes without finding transmitter 101, the display can exit the locked state and enter the search state at 1602. In addition, if the user changes the transmitter identifier, it indicates that a new transmitter has entered the system, and the display can transition from the locked state to the search state.

[0146] In search state 1602, the display can scan frequently to find transmitter 101. For example, the display can scan for 25 seconds, followed by 5 seconds of no radio activity. If transmitter 101 is not found after 5 minutes, the display can enter an idle state at 1604. When transmitter 101 is connected and coupled, it enters a locked state as indicated at 1608. The search state may also continue if the transmitter identifier is changed by the user, if a start sensor session command is received, or if the user activates the screen or runs an application for glucose monitoring.

[0147] The display may enter an idle state 1604 if it fails to find the desired transmitter 101 during the search state. During this time, there may be no radio activity at all. After a certain period, such as one hour, the display may re-enter the search state as indicated in 1610. A transition to the search state may also occur when a user-driven command is received, such as a command to set or update the transmitter identifier, when a sensor session is started, or when a user activates the screen or runs an application for glucose monitoring.

[0148] Herein, we refer to Figure 17 illustrating an exemplary method for calibrating the continuous glucose sensor system 100 with multiple displays. The continuous glucose sensor system 100 may include sensors 103 or other devices for sampling data on glucose values ​​from the body. Sensors 103 may need to be replaced periodically, and part of the replacement process includes calibrating the new sensor 103. For example, the calibration process may occur using blood glucose measurements taken using another measuring device, such as a single-finger stick blood glucose meter. The user can stop their old sensor, insert a new sensor, and reconnect the new sensor to the transmitter. Once a new sensor is inserted, the user can start the new sensor, enter a warm-up period, and perform calibration using either the dedicated display 104a or display 106a.

[0149] Once the warm-up period is complete, the continuous glucose sensor system 100 can transmit a message to dedicated displays 104a and 106a prompting the user to perform calibration. The user can use a blood glucose meter to collect their blood glucose level and enter the value into the dedicated display 104a or display 106a to begin the calibration of the sensor 103. In some implementations, the display transmits the calibration value to the continuous glucose sensor system 100, which processes the calibration value using an algorithm to calibrate the sensor 103 and generate calibrated sensor data. This process may occur multiple times during a session using the sensor 103, allowing two blood glucose calibration values ​​to be used for greater accuracy in calibration.

[0150] In Figure 17, the user may choose to perform the calibration process using either display, although occasionally values ​​may be entered into both displays. The method in Figure 17 processes the received calibration values ​​and adjusts the calibration values ​​between the continuous glucose sensor system 100 and both displays.

[0151] In step 1700, the user can input a blood glucose value on a first display, such as a dedicated display 104a. The blood glucose value can be obtained using a single-point blood glucose meter. The first display may be updated to indicate that a calibration value has been received. Optionally, in step 1702, the user can also input the same value on a second display, such as a display 106a. The second display may also be updated to indicate that a calibration value has been received. Each of the displays can transmit the glucose value to the continuous glucose sensor system 100 in steps 1704 and 1706.

[0152] In step 1708, the continuous glucose sensor system 100 processes the first received glucose value. The transmitter 101 and / or the continuous glucose sensor system 100 perform calibration using the received first glucose value and return the updated glucose value, trend arrow, and the first glucose value to the display. Then in step 1710, a second received glucose value may be processed. In one embodiment, the second received glucose value from the second display may not be used, and instead, the transmitter 101 may send a message to the second display indicating that calibration has already been performed on another device. The second display may then request an updated value, and the transmitter 101 returns to the second display the current glucose value, trend arrow, and data regarding other glucose values. At this point, the second display is updated to show the same information as the first display.

[0153] In some embodiments, the glucose values ​​from the first and second displays do not need to be the same. The user can take multiple measurements and input the blood glucose calibration values ​​on multiple displays. Still, the blood glucose value first received within a time interval, such as 10 minutes, can be used, and the second received blood glucose value can be ignored by the transmitter 101. In some embodiments, the second received blood glucose value can be used even if it differs from the first received blood glucose value by a specified amount, even if it is provided within a time interval. This may indicate that an error occurred when taking the first received blood glucose value. For example, if the first received blood glucose value and the second received blood glucose value differ by more than 20 mg / dL, the second received blood glucose value can be used for calibration instead of, or in addition to, the first received blood glucose value.

[0154] In another embodiment, the user can input blood glucose values ​​on the first and second displays, and the first display transmits the blood glucose values ​​to the transmitter 101. The transmitter 101 transmits an acknowledgment of the blood glucose to the first display, but may indicate an error or failure in the calibration process. The first display then requests data regarding the glucose value and may receive an instruction that the calibration failed. Thus, the first display can update the display to reflect that calibration is still required due to the error status. Subsequently, the second display can transmit its blood glucose value to the transmitter 101, noting that its blood glucose value is a duplicate of the value already received from the first display. The second display, in response to a request for data regarding the glucose value, receives an instruction that the calibration failed. The user can then re-enter the blood glucose values ​​on one or both displays, thereby repeating the process in Figure 17, this time resulting in accepted values ​​and a successful calibration.

[0155] The user does not need to input blood glucose values ​​into both displays. For example, if a single display is used, calibration can occur and succeed, causing the updated data regarding glucose values ​​to be displayed on both displays. In one embodiment, the second display may receive data regarding glucose values ​​and then use the first display to initiate the calibration process. The first display may perform the calibration and display the updated value, while the second display waits for the reception of updated data regarding glucose values ​​until another communication interval. Thus, the two displays will show the same value after the next communication interval.

[0156] Figure 18 illustrates an exemplary system for monitoring glucose levels. The system in Figure 18 can be used in conjunction with the embodiments described above. The system may include a continuous glucose sensor system 1800, wireless connections 1802a-b, a dedicated display 1804, and a display 1806 for running applications. The dedicated display 1804 may be connected to a computer 1802 using either a wired or wireless connection. The computer 1802 may be, for example, a personal computer, tablet, laptop, smartphone, or server. In addition, the dedicated display 1804 may be connected to a display 1806, and the display 1806 may be connected to a computer 1802.

[0157] Computer 1802 and display 1806 can connect to cloud storage 1804, which can provide long-term storage of glucose value data, health information, system calibration, and other information related to continuous glucose monitoring. Cloud storage 1804 may include multiple storage devices, computers, and network connections. Communication between the dedicated display 104, computer 1802, display 106, and cloud storage 1804 may use encryption to prevent unauthorized access to medical data.

[0158] The cloud storage 1802 can connect to the backend system 1806. The backend system 1806 can provide technical support 1808 to users who configure and use the continuous glucose monitor. The backend system 1806 can also monitor system information such as the versions of the software running on the continuous glucose sensor system 1800, the dedicated display 1804, the display 1806, and the computer 1802. Updates may be provided upon request or imposed on users using a secure network connection.

[0159] Another display 1810 can also be connected to cloud storage 1802. Display 1810 may include a dedicated application 1812 and one or more third-party applications 1814, which can be used to monitor and display glucose levels. Users of the continuous glucose sensor system 1800 can enable additional people to monitor the user's glucose levels and other health information. For example, a child may wear a continuous glucose monitor and have associated dedicated displays 1804 and 1806. The child can designate one or both of their parents as additional users who can access the child's glucose levels and other health information using display 1810. Display 1810 may be, for example, a parent's smartphone.

[0160] Continuous glucose data is provided to cloud storage 1804 and can be monitored by cloud storage 1804, backend 1806, and / or display 1802. Display 1802 can receive and display continuous glucose values ​​as described above, either without restriction or subject to the same restrictions as a third-party application. In some embodiments, restrictions can be set by the user of the continuous glucose monitor. In other embodiments, the user of display 1810 can set arbitrary restrictions on the data received through an authenticated process between the user of the continuous glucose sensor system 1800, the user of display 1810, and backend 1806. For example, the user may call the backend and answer security questions before establishing proper operation of the system, or this process may be completed online. Once completed, the user of the continuous glucose sensor system 1800 or the user of display 1810 may have their ability to modify the data received by the user's device or the operation of the system restricted. This prevents users of the continuous glucose sensor system 1800 from limiting monitoring via the display 1810, such as when a child consumes a large amount of sweet food at a birthday party, which could cause a spike in glucose levels.

[0161] Figure 19 illustrates an exemplary computer for monitoring glucose levels. The continuous glucose sensor system 1800, dedicated display 104a, display 106a, computer 1802, cloud storage 1804, backend 1806, and display 1810 may all include the components shown in Figure 19.

[0162] A computer may include, for example, one or more hardware components such as a central processing unit (CPU) 1921, a random access memory (RAM) module 1922, a read-only memory (ROM) module 1923, storage 1924, a database 1925, one or more input / output (I / O) devices 1926, and an interface 1927. Alternatively and / or further, a computer may include one or more software components such as a computer-readable medium containing computer-executable instructions for carrying out the methods associated with the exemplary embodiments. It is intended that one or more of the hardware components listed above may be implemented using software. For example, storage 1924 may include a software partition associated with one or more other hardware components. It is understood that the components listed above are illustrative and not intended to be limiting.

[0163] The CPU 1921 may include one or more processors, each configured to execute instructions and process data to perform one or more functions associated with a computer for monitoring glucose values. The CPU 1921 may be communicatively connected to RAM 1922, ROM 1923, storage 1924, database 1925, I / O device 1926, and interface 1927. The CPU 1921 may be configured to execute a sequence of computer program instructions and perform various processes. Computer program instructions may be loaded into RAM 1922 for execution by the CPU 1921.

[0164] RAM1922 and ROM1923 may each include one or more devices for storing information associated with the operation of CPU1921. For example, ROM1923 may include a memory device configured to access and store information associated with controller1920, including information for identifying, initializing, and monitoring the operation of one or more components and subsystems. RAM1922 may include a memory device for storing data associated with one or more operations of CPU1921. For example, ROM1923 can load instructions into RAM1922 for execution by CPU1921.

[0165] Storage 1924 may include any type of mass storage device configured to store information that the CPU 1921 may need to perform a process consistent with the disclosed embodiment. For example, storage 1924 may include one or more magnetic and / or optical disk devices such as a hard drive, CD-ROM, DVD-ROM, or any other type of mass media device.

[0166] Database 1925 may include one or more software and / or hardware components that cooperate to store, organize, sort, filter, and / or arrange data used by CPU 1921. For example, database 1925 may be data relating to glucose values, associated metadata, and health information monitoring. Database 1925 is intended to store additional information to those listed above, and / or information different from those listed above.

[0167] The I / O device 1926 may include one or more components configured to communicate information with a user associated with the controller 1920. For example, the I / O device may include a console with an integrated keyboard and mouse that allows the user to maintain an image database, update associations, and access digital content. The I / O device 1926 may also include a display with a graphical user interface (GUI) for outputting information on a monitor. The I / O device 1926 may also include peripheral devices such as a printer for printing information associated with the controller 1920, and a user-accessible disk drive (e.g., a USB port, floppy disk, CD-ROM, or DVD-ROM drive) that allows the user to input stored data onto a portable media device, microphone, speaker system, or any other suitable type of interface device.

[0168] Interface 1927 may include one or more components configured to transmit and receive data over a communication network, such as the Internet, a local area network, a workstation peer-to-peer network, a direct link network, a wireless network, or any other suitable communication platform. For example, Interface 1927 may include one or more modulators, demodulators, multiplexers, demultiplexers, network communication devices, wireless devices, antennas, modems, and any other types of devices configured to enable data communication over a communication network.

[0169] Any combination of one or more computer-readable media may be used. Computer-readable media may be computer-readable signal media or computer-readable storage media. Computer-readable storage media may be, for example, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatus, or any suitable combination thereof. More specific examples of computer-readable storage media (not a completely exhaustive list) would include: electrical connections with one or more wires, portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. Program code integrated onto computer-readable media may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber cables, RF, or any suitable combination thereof.

[0170] Computer program code can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java®, Smalltalk, and C++, and traditional procedural programming languages ​​such as the C programming language or similar languages. The program code can be fully executed on an arithmetic unit.

[0171] It will be understood that each block in the flowchart example and / or block diagram, as well as combinations of blocks in the flowchart example and / or block diagram, can be implemented by computer program instructions. These computer program instructions are provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so as to create means for instructions executed via the processor of a computer or other programmable data processing device to implement the function / operation defined in the block(s) of the flowchart and / or block diagram, and thus enable the manufacture of a machine.

[0172] The term "first application" is referred to as "dedicated application 108," but it will be understood that the first application may be any or another of the third-party applications 110-116. Similarly, the second application is referred to as "authorized third-party application 110 and health application," but the second application may also be any or another of the dedicated application 108, third-party applications 112-116. Furthermore, while certain applications 110-116 are listed as third-party applications, it will be understood that applications 110-116 do not need to be provided by a third party.

[0173] It should be understood that the various techniques described herein may be implemented in conjunction with hardware or software, or, where appropriate, a combination thereof. For this reason, the methods and apparatus of the subject disclosed herein, or certain aspects or parts thereof, may take the form of program code (i.e., instructions) integrated into a tangible medium such as a floppy diskette, CD-ROM, hard drive, or any other machine-readable storage medium, and when the program code is loaded into a machine such as an arithmetic unit and executed by it, that machine becomes an apparatus for practicing the subject disclosed herein. When program code is executed on a programmable computer, the arithmetic unit generally includes a processor, a storage medium readable by the processor (including volatile and non-volatile memory and / or memory elements), at least one input device, and at least one output device. One or more programs may implement or utilize the processes described in conjunction with the subject disclosed herein, for example, through the use of an application programming interface (API), reusable controls, etc. Such programs may be implemented in a highly procedural or object-oriented programming language for communication with a computer system. However, programs may also be implemented in assembly or machine language, as desired. In any case, the language can be a compiled or interpreted language and can be combined with a hardware implementation.

[0174] This specification includes many specific implementation details, but these should not be construed as limitations on the claims. Certain features described herein in light of a separate implementation may also be implemented in combination in a single implementation. Conversely, various features described in light of a single implementation may also be implemented in multiple implementations, individually or in any preferred partial combination. Furthermore, features may be described above to operate in a particular combination, and may initially be described in the claims as such, but one or more features from the combination described in the claims may, in some cases, be removed from that combination, and the combination described in the claims may cover a partial combination or a variation of a partial combination.

[0175] Similarly, while the operations are depicted in a specific order in the diagrams, this should not be understood as requiring that such operations be performed in a specific order or sequence as shown, or that all exemplified operations be performed, in order to achieve the desired result. In certain environments, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system components in the implementation described above should not be understood as requiring such separation in all implementations, and the described program components and systems may generally be integrated into a single software product or packaged into multiple software products.

[0176] It should be understood that the logical operations described herein with respect to various drawings may be implemented as (1) as operations or program modules (i.e., software) implemented in a set of computers operating on an arithmetic unit, (2) as interconnected mechanical logic circuits or circuit modules (i.e., hardware) within the arithmetic unit, and / or (3) in combination of software and hardware of the arithmetic unit. For this reason, the logical operations considered herein are not limited to any particular combination of hardware and software. Implementation is a matter of choice depending on the performance and other requirements of the arithmetic unit. Accordingly, the logical operations described herein may be referred to in various ways as operations, structures, operations, or modules. These operations, structures, operations, and modules may be implemented in software, firmware, special-purpose digital logic, and any combination thereof. It should also be understood that more or fewer operations than those shown in the drawings and described herein may be performed. These operations may also be performed in a different order than those described herein. [Explanation of Symbols]

[0177] 100 Continuous Glucose Sensor System 101 Wireless Transmitter 102a,102b Wireless communication 103 Small Sensor 104a dedicated display 104b Dedicated display connected to another continuous glucose sensor system 106a Display 106b Display connected to another continuous glucose sensor system 108 Dedicated Application 110 Authorized Third-Party Applications

Claims

1. A method for pairing a transmitter of a continuous glucose monitoring system with multiple display devices, Connecting the first display device to the transmitter via a first wireless connection, Connecting the second display device to the transmitter via a second wireless connection, By rejecting additional connection requests during the communication interval, the number of display devices connected to the transmitter is limited, A method comprising periodically exchanging application keys that change at the beginning of each period between the first display device and the second display device.

2. The method according to claim 1, further comprising limiting the number of display devices connected to the transmitter to two display devices.

3. Determining the device type of the first display device and the second display device, Identifying whether the device type of the first display device and the second display device is an authorized device type, The method according to claim 1 or 2, further comprising limiting the number of connected display devices to one of the device types of the first display device and one of the device types of the second display device.

4. The method according to claim 3, wherein the number of display devices is limited between each of the consecutive single communication intervals, and the communication intervals occur during the low-power idle state of the transmitter.

5. Connecting the first display device and connecting the second display device are The transmission identifier is exchanged between the transmission and the first display device, The transmitter identifier is exchanged between the transmitter and the second display device, The method according to claim 1, further comprising comparing the transmitter identifier from the first display device and the transmitter identifier from the second display device with a transmitter identifier stored in the transmitter.

6. The method according to claim 5, wherein the exchanged transmitter identifier includes a hash value.

7. A system for pairing a transmitter of a continuous glucose monitoring system with multiple display devices, A first display device configured to connect to the transmitter via a first wireless connection, The system comprises a second display device configured to connect to the transmitter via a second wireless connection, wherein the transmitter is By rejecting additional connection requests during the communication interval, the number of connected display devices is limited. A system configured to periodically exchange application keys, which change at the beginning of each period, with the first display device and the second display device.

8. The system according to claim 7, wherein the transmitter is further configured to limit the number of display devices connected to the transmitter to two display devices.

9. The aforementioned transmitter, Determine the device type of the first display device and the second display device. Identify whether the device type of the first display device and the second display device is an authorized device type. The system according to claim 7 or 8, further configured to limit the number of connected display devices to one of the device types of the first display device and one of the device types of the second display device.

10. The system according to claim 9, wherein the number of display devices is limited between each of the consecutive single communication intervals, and the communication intervals occur during the low-power idle state of the transmitter.

11. While the first display device is connected and the second display device is connected, the transmitter The transmitter identifier is exchanged between the transmitter and the first display device. The transmitter identifier is exchanged between the transmitter and the second display device. The system according to claim 7, further configured to compare the transmitter identifier from the first display device and the transmitter identifier from the second display device with a transmitter identifier stored in the transmitter.

12. The system according to claim 11, wherein the exchanged transmitter identifier includes a hash value.

13. Computer-readable medium, When executed by one or more processors, the instruction includes a method for pairing a transmitter of a continuous glucose monitoring system with multiple display devices, wherein the method is: Connecting the first display device to the transmitter via a first wireless connection, Connecting the second display device to the transmitter via a second wireless connection, By rejecting additional connection requests during the communication interval, the number of display devices connected to the transmitter is limited, A computer-readable medium, comprising periodically exchanging an application key that changes at the beginning of each period between the first display device and the second display device.

14. The computer-readable medium according to claim 13, further comprising the method of limiting the number of display devices connected to the transmitter to two display devices.

15. The method described above is Determining the device type of the first display device and the second display device, Identifying whether the device type of the first display device and the second display device is an authorized device type, The computer-readable medium according to claim 13 or 14, further comprising limiting the number of connected display devices to one of the device types of the first display device and one of the device types of the second display device.

16. The computer-readable medium according to claim 15, wherein the number of display devices is limited between each of the consecutive single communication intervals, and the communication intervals occur during the low-power idle state of the transmitter.

17. Connecting the first display device and connecting the second display device are The transmission identifier is exchanged between the transmission and the first display device, The transmitter identifier is exchanged between the transmitter and the second display device, The computer-readable medium according to claim 13, further comprising comparing the transmitter identifier from the first display device and the transmitter identifier from the second display device with a transmitter identifier stored in the transmitter.

18. The computer-readable medium according to claim 17, wherein the exchanged transmitter identifier includes a hash value.

19. A method for pairing a transmitter of a continuous glucose monitoring system with a display device, Receiving a first identifier from the aforementioned display device, Creating a first hash value by applying a hash algorithm to the first identifier, Receiving an advertisement signal from the aforementioned transmitter, Analyzing at least one of the one or more advertising signals associated with the advertising signal to identify a second hash value that includes a portion of the transmitter identifier associated with the transmitter, Comparing the first hash value with the second hash value, When the first hash value and the second hash value do not match, the connection between the transmitter and the display device is rejected. A method comprising: allowing a connection between the transmitter and the display device when the first hash value and the second hash value match.

20. The method according to claim 19, further comprising pairing a second display device with the transmitter.

21. The method according to claim 20, further comprising limiting the number of display devices connected to the transmitter to two display devices.

22. The method according to claim 20, wherein the first display device includes a smartphone, and the second display device includes a dedicated display.

23. After granting the aforementioned connection, the transmitter is coupled to the display device, The application key is transmitted from the display device to the transmitter, The method according to any one of claims 19 to 22, further comprising receiving acceptance of the application key from the transmitter.

24. After a certain period of time, the display device creates a new application key, The new application key is transmitted to the transmitter, Receiving acceptance of the new application key from the transmitter, The method according to claim 23, further comprising discontinuing the use of the application key after receiving acceptance of the new application key.

25. One or more computer-readable media, When executed by one or more processors, the instruction includes instructions for performing a method for pairing a transmitter of a continuous glucose monitoring system with a display device, wherein the method is Receiving a first identifier from the aforementioned display device, Creating a first hash value by applying a hash algorithm to the first identifier, Receiving an advertisement signal from the aforementioned transmitter, Analyzing at least one of the one or more advertising signals associated with the advertising signal to identify a second hash value that includes a portion of the transmitter identifier associated with the transmitter, Comparing the first hash value with the second hash value, When the first hash value and the second hash value do not match, the connection between the transmitter and the display device is rejected. A computer-readable medium, which includes allowing a connection between the transmitter and the display device when the first hash value and the second hash value match.

26. The computer-readable medium according to claim 25, further comprising an instruction to pair a second display device with the transmitter when executed by one or more processors.

27. The computer-readable medium according to claim 26, further comprising an instruction that, when executed by one or more processors, limits the number of display devices connected to the transmitter to two display devices.

28. The computer-readable medium according to claim 26, wherein the first display device includes a smartphone and the second display device includes a dedicated display.

29. When executed by one or more processors, After granting the aforementioned connection, the transmitter is coupled to the display device. The application key is transmitted from the display device to the transmitter. The computer-readable medium according to any one of claims 25 to 28, further comprising an instruction to receive acceptance of the application key from the transmitter.

30. When executed by one or more processors, After a certain period of time, the display device creates a new application key. The new application key is transmitted to the transmitter. Upon receiving acceptance of the new application key from the transmitter, The computer-readable medium according to claim 29, further comprising an instruction to discontinue the use of the application key after receiving acceptance of the new application key.

31. A system for pairing a transmitter of a continuous glucose monitoring system with a display device, A wireless receiver in a first display device configured to receive a first identifier, The first display device comprises a processor, and the processor is A first hash value is created by applying a hash algorithm to the first identifier. The transmitter receives an advertisement signal, Analyze at least one of the one or more advertising signals associated with the advertising signal to identify a second hash value that includes a portion of the transmitter identifier associated with the transmitter. The first hash value and the second hash value are compared, When the first hash value and the second hash value do not match, the connection between the transmitter and the display device is rejected. A system configured to allow a connection between the transmitter and the display device when the first hash value and the second hash value match.

32. The system according to claim 31, further comprising a second display device paired with the transmitter.

33. The system according to claim 32, wherein the processor is further configured to limit the number of display devices connected to the transmitter to two display devices.

34. The system according to claim 32, wherein the first display device includes a smartphone and the second display device includes a dedicated display.

35. The aforementioned processor, After granting the aforementioned connection, the transmitter is coupled to the display device. The application key is transmitted from the display device to the transmitter. The system according to claim 33 or 34, further configured to receive acceptance of the application key from the transmitter.

36. The aforementioned processor, After a certain period of time, the display device creates a new application key. The new application key is transmitted to the transmitter. Upon receiving acceptance of the new application key from the transmitter, The system according to claim 35, further configured to discontinue the use of the application key after receiving acceptance of the new application key.

37. A method for pairing a transmitter of a continuous glucose monitoring system with a display device, Receiving an advertisement signal from the aforementioned transmitter, To establish a connection between the transmitter and the display device, Receiving a first key from the aforementioned transmitter, Comparing the first key with a second key stored by the display device, When the first key matches the second key, the transmitter is authenticated using the display device, After authentication, the application key is transmitted from the display device to the transmitter, Receiving acceptance of the application key from the transmitter, After receiving acceptance of the application key, communication between the transmitter and the display device is permitted. The transmission of data relating to continuous glucose values ​​from the transmitter to the display device, After a certain period of time, the display device creates a second application key, The second application key is transmitted from the display device to the transmitter, Receiving acceptance of the second application key from the transmitter, A method comprising: receiving acceptance of a new application key, and then allowing further communication between the transmitter and the display device.

38. The method according to claim 37, wherein the first key includes a transmitter identifier associated with the transmitter.

39. The method according to claim 37, wherein the first key includes a hashed version of a transmitter identifier associated with the transmitter.

40. The method according to claim 37, wherein the first key includes an encrypted version of a transmitter identifier associated with the transmitter.

41. The method according to claim 37, further comprising receiving input from the second key using a user interface.

42. The method according to claim 37, wherein the new application key is created after a predetermined time.

43. When the first key matches the second key, the transmitter is authenticated using the display device. The method according to claim 37, further comprising comparing the identifier of the transmitter with a list of authorized devices.

44. Transmitting the second application key and receiving acceptance of the second application key, After transmitting the second application key, communication using the first application key is permitted for a predetermined period of time. The method according to any one of claims 37 to 43, comprising transmitting the second application key multiple times while waiting for the acceptance of the second application key.

45. The method according to any one of claims 37 to 43, further comprising pairing the transmitter with a second display device.

46. The method according to claim 37, further comprising limiting the number of display devices paired with the transmitter.

47. The method according to claim 38, wherein the number of display devices paired with the transmitter at a given time is limited to two.

48. The method according to any one of claims 37 to 43, further comprising periodically authenticating the display device, wherein each period occurs at intervals of approximately 5 minutes.

49. One or more computer-readable media, When executed by one or more processors, the instruction includes instructions for performing a method for pairing a transmitter of a continuous glucose monitoring system with a display device, wherein the method is Receiving an advertisement signal from the aforementioned transmitter, To establish a connection between the transmitter and the display device, Receiving a first key from the aforementioned transmitter, Comparing the first key with a second key stored by the display device, When the first key matches the second key, the transmitter is authenticated using the display device, After authentication, the application key is transmitted from the display device to the transmitter, Receiving acceptance of the application key from the transmitter, After receiving acceptance of the application key, communication between the transmitter and the display device is permitted. The transmission of data relating to continuous glucose values ​​from the transmitter to the display device, After a certain period of time, the display device creates a second application key, The second application key is transmitted from the display device to the transmitter, Receiving acceptance of the second application key from the transmitter, A computer-readable medium, including allowing further communication between the transmitter and the display device after receiving acceptance of a new application key.

50. The computer-readable medium according to claim 49, wherein the first key includes a transmitter identifier associated with the transmitter.

51. The computer-readable medium according to claim 49, wherein the first key includes a hashed version of a transmitter identifier associated with the transmitter.

52. The computer-readable medium according to claim 49, wherein the first key includes an encrypted version of a transmitter identifier associated with the transmitter.

53. The computer-readable medium according to claim 49, further comprising instructions for receiving input from the second key using a user interface when executed by the one or more processors.

54. The computer-readable medium according to claim 49, wherein the new application key is created after a predetermined time.

55. When the first key matches the second key, the transmitter is authenticated using the display device. The computer-readable medium according to claim 49, further comprising comparing the identifier of the transmitter with a list of authorized devices.

56. When instructions for transmitting the second application key and receiving acceptance of the second application key are executed by one or more processors, After transmitting the second application key, communication using the first application key is permitted for a predetermined period of time. The computer-readable medium according to any one of claims 49 to 55, further comprising an instruction to transmit the second application key multiple times while waiting for the acceptance of the second application key.

57. A computer-readable medium according to any one of claims 49 to 55, further comprising an instruction to pair the transmitter with a second display device when executed by the one or more processors.

58. The computer-readable medium according to claim 49, further comprising instructions that, when executed by the one or more processors, limit the number of display devices paired with the transmitter.

59. The computer-readable medium according to claim 49, wherein the number of display devices paired with the transmitter at a given time is limited to two.

60. A computer-readable medium according to any one of claims 49 to 55, further comprising instructions for periodically authenticating the display device when executed by one or more processors, with each period occurring at intervals of approximately five minutes.

61. A system for pairing a transmitter of a continuous glucose monitoring system with a display device, A transmitter configured to transmit advertising signals, A display device configured to establish a connection with the transmitter based on the advertising signal, A wireless receiver in the display device is configured to receive a first key from the transmitter, A memory in the display device configured to store a second key, The display device comprises a processor, and the processor is The first key is compared with the second key, When the first key matches the second key, the transmitter is authenticated using the display device. After authentication, the application key is transmitted to the transmitter. Upon receiving acceptance of the application key from the transmitter, After receiving acceptance of the aforementioned application key, communication with the transmitter is permitted. The transmitter receives data relating to continuous glucose values, After a certain period of time, a second application key is created. The second application key is transmitted to the transmitter. Upon receiving acceptance of the second application key from the transmitter, A system configured to allow further communication between the transmitter and the display device after receiving acceptance of a new application key.

62. The system according to claim 61, wherein the first key includes a transmitter identifier associated with the transmitter.

63. The system according to claim 61, wherein the first key includes a hashed version of a transmitter identifier associated with the transmitter.

64. The system according to claim 61, wherein the first key includes an encrypted version of a transmitter identifier associated with the transmitter.

65. The system according to claim 61, wherein the processor is further configured to receive input from the second key that uses the user interface.

66. The system according to claim 61, wherein the new application key is created after a predetermined time.

67. The system according to claim 61, wherein the processor is further configured to compare the identifier of the transmitter with a list of authorized devices when the first key matches the second key and authenticates the transmitter using the display device.

68. When transmitting the second application key and when receiving acceptance of the second application key, the processor: After transmitting the second application key, communication using the first application key is permitted for a predetermined period of time. The system according to any one of claims 61 to 67, further configured to transmit the second application key multiple times while waiting for the acceptance of the second application key.

69. The system according to any one of claims 61 to 67, further comprising a second display device paired with the transmitter.

70. The system according to claim 61, wherein the number of display devices paired with the transmitter is limited.

71. The system according to claim 62, wherein the number of display devices paired with the transmitter at a given time is limited to two.

72. The system according to any one of claims 61 to 67, wherein the processor is further configured to periodically authenticate the display device, with each period occurring at intervals of approximately 5 minutes.

73. A method for establishing communication between multiple display devices and a transmitter of a continuous glucose monitoring system, Receiving a request to connect the transmitter to a first display device, wherein the request identifies a first type of the first display device, Comparing the first type of the first display device with a list including a plurality of permitted types of display devices, To determine whether the display device having the first type is actively connected to the transmitter, If the list includes fewer display devices of the first type than the predetermined number, the transmitter is connected to the first display device, Receiving a request to connect the transmitter to a second display device, wherein the request identifies a second type of the second display device, Comparing the second type of the second display device with the list which includes a plurality of permitted types of display devices, To determine whether the display device having the second type is actively connected to the transmitter, A method comprising connecting the transmitter to the second display device if the list includes fewer display devices of the second type than the predetermined number.

74. The method according to claim 73, wherein the first type of device includes a smartphone and the second type of device includes a dedicated display.

75. Pairing the first display device and the second display device with the transmitter, The method according to claim 74, further comprising storing coupling information, which is the result of pairing the first display device and the second display device with the transmitter, in a second list.

76. The method according to claim 73, further comprising rejecting the request to establish communication between the transmitter and the first display device when another display device having the first type is actively connected.

77. The method according to claim 73, further comprising refusing the request to establish communication between the transmitter and the second display device when another display device having the second type is actively connected.

78. The method according to claim 73, wherein the predetermined number of display devices is 2.

79. After connecting the transmitter to the first display device, the first display device is added to the list, The method according to any one of claims 73 to 78, further comprising connecting the transmitter to the second display device and then adding the second display device to the list.

80. Receiving a request to remove the aforementioned first display device from the list, Terminate communication with the aforementioned first display device, The method according to claim 73, further comprising excluding the first display device from the list.

81. The method according to any one of claims 73 to 78, further comprising periodically connecting the plurality of display devices to the transmitter at communication intervals.

82. One or more computer-readable media, When executed by one or more processors, the instruction includes a method for establishing communication between multiple display devices and transmitters of a continuous glucose monitoring system, wherein the method is Receiving a request to connect the transmitter to a first display device, wherein the request identifies a first type of the first display device, Comparing the first type of the first display device with a list including a plurality of permitted types of display devices, To determine whether the display device having the first type is actively connected to the transmitter, If the list includes fewer display devices of the first type than the predetermined number, the transmitter is connected to the first display device, Receiving a request to connect the transmitter to a second display device, wherein the request identifies a second type of the second display device, Comparing the second type of the second display device with the list which includes a plurality of permitted types of display devices, To determine whether the display device having the second type is actively connected to the transmitter, A computer-readable medium, comprising connecting the transmitter to the second display device if the list includes fewer display devices of the second type than the predetermined number.

83. The computer-readable medium according to claim 82, wherein the first type of device includes a smartphone and the second type of device includes a dedicated display.

84. When executed by the aforementioned processor, The first display device and the second display device are paired with the transmitter. The computer-readable medium according to claim 82, further comprising an instruction for storing in a second list coupling information which is the result of pairing the first display device and the second display device with the transmitter.

85. The computer-readable medium according to claim 82, further comprising an instruction to reject the request to establish communication between the transmitter and the first display device when executed by one or more processors and another display device having the first type is actively connected.

86. The computer-readable medium according to claim 82, further comprising an instruction to reject the request to establish communication between the transmitter and the second display device when executed by one or more processors and another display device having the second type is actively connected.

87. The computer-readable medium according to claim 82, wherein the predetermined number of display devices is 2.

88. When executed by one or more processors, After connecting the transmitter to the first display device, the first display device is added to the list. A computer-readable medium according to any one of claims 82 to 87, further comprising an instruction to add the second display device to the list after connecting the transmitter to the second display device.

89. When executed by one or more processors, Upon receiving a request to remove the first display device from the list, Terminate communication with the first display device. The computer-readable medium according to claim 82, further comprising an instruction to remove the first display device from the list.

90. When executed by one or more processors, The plurality of display devices are periodically connected to the transmitter at communication intervals. The computer-readable medium according to any one of claims 82 to 87, further comprising an instruction for storing the combined information resulting from the aforementioned connection in a second list.

91. A system for establishing communication between multiple display devices and a transmitter of a continuous glucose monitoring system, A first display device and A second display device, A wireless receiver within the transmitter is configured to receive a request to connect the transmitter to the first display device, wherein the request identifies a first type of the first display device. A memory in the transmitter configured to store a list of permitted types of display devices, The device comprises a processor in the aforementioned transmitter, and the processor is The first type of the first display device is compared with the list above. Determine whether the display device having the first type is actively connected to the transmitter. If the list includes fewer display devices of the first type than the predetermined number, the transmitter is connected to the first display device. A request to connect the transmitter to a second display device, and a request to identify a second type of the second display device, The second type of the second display device is compared with the list which includes a plurality of permitted types of display devices, Determine whether the display device having the second type is actively connected to the transmitter, A system in which, if the list includes fewer display devices of the second type than the predetermined number, the transmitter is configured to connect to the second display device.

92. The system according to claim 91, wherein the first type of display device includes a smartphone, and the second type of display device includes a dedicated display.

93. The aforementioned processor, The first display device and the second display device are paired with the transmitter. The system according to claim 91, further configured to store coupling information, which is the result of pairing the first display device and the second display device with the transmitter, in a second list.

94. The system according to claim 91, wherein the processor is further configured to reject the request to establish communication between the transmitter and the first display device when another display device having the first type is actively connected.

95. The system according to claim 91, wherein the processor is further configured to reject the request to establish communication between the transmitter and the second display device when another display device having the second type is actively connected.

96. The system according to claim 91, wherein the predetermined number of display devices is 2.

97. The aforementioned processor, After connecting the transmitter to the first display device, the first display device is added to the list. The system according to any one of claims 91 to 96, further configured to add the second display device to the list after connecting the transmitter to the second display device.

98. The aforementioned processor, Upon receiving a request to remove the first display device from the list, Terminate communication with the first display device. The system according to claim 91, further configured to exclude the first display device from the list.

99. The plurality of display devices are periodically connected to the transmitter at communication intervals. The system according to any one of claims 91 to 96, wherein the coupling information resulting from the aforementioned connection is stored in a second list.

100. A method for establishing communication between multiple display devices and a transmitter of a continuous glucose monitoring system, Creating a list of authorized devices, wherein the list includes multiple types of devices, Performing an authentication process using a first display device and the transmitter, wherein the authentication process includes receiving an identifier of the type of the first display device, Adding the first display device to the list of authorized devices, The authentication process is performed using a second display device and the transmitter, the authentication process includes receiving an identifier of the type of the second display device, wherein the type of the second display device is different from the type of the first display device. Adding the second display device to the list of authorized devices, Receiving a request to remove the aforementioned first display device from the list, To exclude the first display device from the list of authorized devices, Performing the authentication process using a third display device and the transmitter, wherein the authentication process includes receiving an identifier of the type of the third display device, and the type of the third display device is the same as the type of the first display device. A method comprising adding the third display device to the list of authorized devices.

101. The method according to claim 100, wherein a command from the user interface provides the request to exclude the first display device.

102. The method according to claim 100, further comprising automatically generating the request to remove the first display device from the list after the first display device has not communicated with the transmitter for a predetermined period of time.

103. The method according to claim 100, further comprising removing the first display device from the list of authorized devices and then storing authentication information relating to the first display device in memory.

104. The aforementioned authentication process, Replacing the application key, The method according to any one of claims 100 to 103, comprising updating the application key after a predetermined period of time.

105. The method according to any one of claims 100 to 103, wherein the authentication process includes entering an advertising state, the advertising state having a duration determined based on the number of devices on the list of authorized devices.

106. The method according to claim 105, wherein when the number of devices on the list of authorized devices is zero, the duration of the advertising state includes one advertising activity period.

107. The method according to claim 105, wherein when the number of devices on the list of authorized devices is one, the duration of the advertising state includes two advertising activity periods.

108. One or more computer-readable media, When executed by one or more processors, the instruction includes a method for establishing communication between multiple display devices and transmitters of a continuous glucose monitoring system, wherein the method is Creating a list of authorized devices, wherein the list includes multiple types of devices, Performing an authentication process using a first display device and the transmitter, wherein the authentication process includes receiving an identifier of the type of the first display device, Adding the first display device to the list of authorized devices, The authentication process is performed using a second display device and the transmitter, the authentication process includes receiving an identifier of the type of the second display device, wherein the type of the second display device is different from the type of the first display device. Adding the second display device to the list of authorized devices, Receiving a request to remove the aforementioned first display device from the list, To exclude the first display device from the list of authorized devices, Performing the authentication process using a third display device and the transmitter, wherein the authentication process includes receiving an identifier of the type of the third display device, and the type of the third display device is the same as the type of the first display device. A computer-readable medium, including adding the third display device to the list of authorized devices.

109. The computer-readable medium according to claim 108, wherein a command from the user interface provides the request to exclude the first display device.

110. The computer-readable medium according to claim 108, further comprising an instruction, when executed by one or more processors, for automatically generating the request to remove the first display device from the list after the first display device has not communicated with the transmitter for a predetermined period of time.

111. The computer-readable medium according to claim 108, further comprising an instruction, when executed by one or more processors, to remove the first display device from the list of authorized devices, and then store authentication information relating to the first display device in memory.

112. When the authentication process is performed by one or more processors, Replace the application key, A computer-readable medium according to any one of claims 108 to 111, comprising further instructions to update the application key after a predetermined time.

113. When the authentication process is performed by one or more processors, A computer-readable medium according to any one of claims 108 to 111, comprising further instructions for performing an advertising state, wherein the advertising state has a duration determined based on the number of authorized devices on the list of authorized devices.

114. The computer-readable medium according to claim 112, wherein when the number of devices on the list of authorized devices is zero, the duration of the advertising state includes one advertising activity period.

115. The computer-readable medium according to claim 112, wherein when the number of authorized devices on the list is one, the duration of the advertising state includes two advertising activity periods.

116. A system for establishing communication between multiple display devices and a transmitter of a continuous glucose monitoring system, A first display device and A second display device, A memory associated with the transmitter, configured to store a list of authorized devices, including a plurality of device types, The system comprises a processor associated with the continuous glucose monitoring system, and the processor is Performing an authentication process using a first display device and the transmitter, wherein the authentication process includes receiving an identifier of the type of the first display device, Adding the first display device to the list of authorized devices, The authentication process is performed using a second display device and the transmitter, the authentication process includes receiving an identifier of the type of the second display device, wherein the type of the second display device is different from the type of the first display device. Adding the second display device to the list of authorized devices, Receiving a request to remove the aforementioned first display device from the list, To exclude the first display device from the list of authorized devices, Performing the authentication process using a third display device and the transmitter, wherein the authentication process includes receiving an identifier of the type of the third display device, and the type of the third display device is the same as the type of the first display device. A system configured to add the third display device to the list of authorized devices.

117. The system according to claim 116, wherein a command from a user interface on the second display device provides the request to exclude the first display device.

118. The system according to claim 116, wherein the processor is further configured to automatically generate the request to remove the first display device from the list after the first display device has not communicated with the transmitter for a predetermined period of time.

119. The system according to claim 116, wherein the processor is further configured to hold in memory authentication information relating to the first display device after removing the first display device from the list of authorized devices.

120. The aforementioned authentication process, Replacing the application key, The system according to any one of claims 116 to 119, comprising updating the application key after a predetermined period of time.

121. The system according to any one of claims 116 to 119, wherein the authentication process includes entering an advertising state, the advertising state having a duration determined based on the number of devices on the list of authorized devices.

122. The system according to claim 120, wherein when the number of devices on the list of authorized devices is zero, the duration of the advertising state includes one advertising activity period.

123. The system according to any one of claims 116 to 119, wherein when the number of devices on the list of authorized devices is one, the duration of the advertising state includes two advertising activity periods.

124. A method for exchanging commands between a transmitter of a continuous glucose monitoring system and one or more display devices, The transmitter is put into an idle state, The first display device receives a command requesting data exchange with the transmitter, Depending on the type of the command, the first display device is set to an intermediate state, Transitioning the transmitter from the idle state to the active state, The command is transmitted from the first display device to the transmitter, Receiving a response from the transmitter that includes updated data relating to the control of the transmitter, Disconnecting the first display device from the intermediate state, A method comprising displaying the updated data using the first display device.

125. The first display device receives multiple commands, Maintaining a queue containing the aforementioned multiple commands, The method according to claim 124, further comprising transmitting the plurality of commands from the queue to the transmitter when the transmitter transitions from the idle state to the active state.

126. The second display device receives the response including the updated data, The method according to claim 124, further comprising displaying the updated data on the second display device.

127. The command includes a stop command for the transmitter, The aforementioned intermediate state includes indicating that the command has been received and is being processed. The method according to claim 124, wherein displaying the updated data includes indicating that the stop command has been processed by the transmitter.

128. The command includes a start command for the transmitter, The aforementioned intermediate state includes indicating a warm-up state for the transmitter, The method according to claim 124, wherein displaying the updated data includes indicating that the start command has been processed by the transmitter.

129. The command includes a start command for the transmitter, Putting the first display device into the intermediate state includes displaying the warm-up state for the transmitter. During the aforementioned intermediate state, the second display device displays the state of the transmitter before receiving the start command. The method according to any one of claims 124 to 128, wherein displaying the updated data includes displaying on the first display device and the second display device that the start command has been processed by the transmitter.

130. After displaying the updated data, an active communication is established between the second display device and the transmitter. The second display device receives the second command, Transmitting the second command to the transmitter, Determining that the second command has already been processed by the command previously transmitted from the first display device, Refusing to process the second command mentioned above, The method according to any one of claims 124 to 128, further comprising updating the second display device with the updated data.

131. The aforementioned command and the second command include a start command, The method according to claim 124, wherein the updated data indicates the warm-up state of the sensor.

132. One or more computer-readable media, When executed by one or more processors, the instruction includes a method for exchanging commands between a transmitter of a continuous glucose monitoring system and one or more display devices, the method being: The transmitter is put into an idle state, The first display device receives a command requesting data exchange with the transmitter, Depending on the type of the command, the first display device is set to an intermediate state, Transitioning the transmitter from the idle state to the active state, The command is transmitted from the first display device to the transmitter, Receiving a response from the transmitter that includes updated data relating to the control of the transmitter, Disconnecting the first display device from the intermediate state, A computer-readable medium, which includes displaying the updated data by the first display device.

133. When executed by one or more processors, The first display device receives multiple commands, A queue containing the aforementioned multiple commands is maintained, The computer-readable medium according to claim 132, further comprising an instruction to transmit the plurality of commands from the queue to the transmitter when the transmitter transitions from the idle state to the active state.

134. When executed by one or more processors, The second display device receives the response, which includes the updated data. The computer-readable medium according to claim 132, further comprising an instruction to display the updated data by the second display device.

135. The command includes a stop command for the transmitter, The aforementioned intermediate state includes indicating that the command has been received and is being processed. The computer-readable medium according to claim 132, wherein displaying the updated data includes indicating that the stop command has been processed by the transmitter.

136. The command includes a start command for the transmitter, The aforementioned intermediate state includes indicating a warm-up state for the transmitter, The computer-readable medium according to claim 132, wherein displaying the updated data includes indicating that the start command has been processed by the transmitter.

137. The command includes a start command for the transmitter, When the computer-readable medium is executed by one or more processors, While the first display device is in the intermediate state, it displays the warm-up state for the transmitter. During the aforementioned intermediate state, before receiving the start command, the previous state of the transmitter is displayed by the second display device. A computer-readable medium according to any one of claims 132 to 136, further including an instruction to display the updated data by indicating on the first display device and the second display device that the start command has been processed by the transmitter.

138. When executed by one or more processors, After displaying the updated data, an active communication is established between the second display device and the transmitter. The second display device receives the second command, The second command is transmitted to the transmitter, It is determined that the second command has already been processed by the command previously transmitted from the first display device, The processing of the aforementioned second command is refused. A computer-readable medium according to any one of claims 132 to 136, further comprising an instruction to update the second display device with the updated data.

139. The aforementioned command and the second command include a start command. The computer-readable medium according to claim 132, wherein the updated data indicates the warm-up state of the sensor.

140. A system for exchanging commands between a transmitter of a continuous glucose monitoring system and one or more display devices, A first display device, Upon receiving a command requesting data exchange with the aforementioned transmitter, A first display device is configured to be in an intermediate state depending on the type of command, A processor associated with the aforementioned transmitter, The transmitter is kept in an idle state for a certain period of time. The transmitter is transitioned from the idle state to the active state. During the active state, the command is received from the first display device. A processor configured to transmit a response from the transmitter to the first display device, including updated data relating to the control of the transmitter, A system in which, in response to receiving the aforementioned response, the first display device terminates the intermediate state by displaying the updated data.

141. The first display device, Received multiple commands, A queue containing the aforementioned multiple commands is maintained, The system according to claim 140, further configured to transmit the plurality of commands from the queue to the transmitter when the transmitter transitions from the idle state to the active state.

142. The system according to claim 140, further comprising a second display device configured to receive the response containing the updated data and to display the updated data.

143. The command includes a stop command for the transmitter, The aforementioned intermediate state includes indicating that the command has been received and is being processed. The system according to claim 140, wherein displaying the updated data includes indicating that the stop command has been processed by the transmitter.

144. The command includes a start command for the transmitter, The aforementioned intermediate state includes indicating a warm-up state for the transmitter, The system according to claim 140, wherein displaying the updated data includes indicating that the start command has been processed by the transmitter.

145. The command includes a start command for the transmitter, The processor is further configured to bring the first display device to the intermediate state by displaying the warm-up state for the transmitter. The aforementioned system During the aforementioned intermediate state, the previous state of the transmitter is displayed before receiving the start command. The system according to claim 140, further comprising a second display device configured to display the updated data by indicating on the first and second display devices that the start command has been processed by the transmitter.

146. After displaying the updated data, an active communication is established with the transmitter. Upon receiving the second command, The system further includes a second display device configured to transmit the second command to the transmitter, wherein the transmitter It is determined that the second command has already been processed by the command previously transmitted from the first display device, The processing of the aforementioned second command is refused. The system according to any one of claims 140 to 145, further configured to transmit the updated data to the second display device.

147. The aforementioned command and the second command include a start command, The system according to claim 146, wherein the updated data indicates the warm-up state of the sensor.

148. A method for synchronizing data displayed on a first display device and a second display device, The first display device is connected to the transmitter of the continuous glucose monitoring system, Connecting the second display device to the transmitter, Allowing the transmission of commands to the transmitter at a specific time, The first display device and the second display device receive data relating to glucose values ​​from the transmitter, The first display device receives a command related to the calibration of the continuous glucose sensor, During one of the aforementioned specific time periods, the command for calibration is transmitted to the continuous glucose sensor. Based on the aforementioned calibration command, the data for the updated glucose value is calculated, A method comprising transmitting the updated glucose value data to the first display device and the second display device.

149. The method according to claim 148, wherein the specified time includes a predetermined time interval.

150. The method according to claim 148, wherein the specific time includes a time that coincides with the receipt of a notification from the transmitter transitioning to an active state.

151. Creating data relating to glucose values ​​based on multiple glucose measurement values ​​collected over a certain period, wherein the data includes glucose values ​​calculated based on the glucose measurement values ​​and calibration, The method according to claim 148, further comprising associating a timestamp with each calculated glucose value.

152. The method according to claim 148, further comprising recording the time at which the command relating to calibration was received, wherein the data relating to the updated glucose value includes data calculated after the time recorded.

153. The method according to any one of claims 148 to 152, further comprising displaying on the first display device and the second display device a time indication associated with the data relating to the updated glucose value.

154. The method according to claim 148, wherein, when the first display device is oriented in a horizontal format, the data relating to the updated glucose value is displayed along with an indication of whether the data includes data from a period prior to when the data was re-filled into the first display device.

155. The method according to any one of claims 148 to 152, further comprising creating an alarm on the first display device that is triggered by the updated glucose value reaching a predetermined value.

156. To create a first alarm on the first display device that is triggered by the updated glucose value reaching a first predetermined value, The method according to any one of claims 148 to 152, further comprising creating a second alarm on the second display device that is triggered by the updated glucose value reaching a second predetermined value.

157. One or more computer-readable media, When executed by one or more processors, the instruction includes a method for performing a method for synchronizing data displayed on a first display device and a second display device, wherein the method is The first display device is connected to the transmitter of the continuous glucose monitoring system, Connecting the second display device to the transmitter, Allowing the transmission of commands to the transmitter at a specific time, The first display device and the second display device receive data relating to glucose values ​​from the transmitter, The first display device receives a command related to the calibration of the continuous glucose sensor, During one of the aforementioned specific time periods, the command for calibration is transmitted to the continuous glucose sensor. Based on the aforementioned calibration command, the data for the updated glucose value is calculated, A computer-readable medium comprising transmitting the data relating to the updated glucose value to the first display device and the second display device.

158. The computer-readable medium according to claim 157, wherein the specified time includes a predetermined time interval.

159. The computer-readable medium according to claim 157, wherein the specific time includes a time that coincides with the receipt of a notification from the transmitter transitioning to an active state.

160. When executed by one or more processors, The data relating to glucose values ​​is created based on a plurality of glucose measurements taken over a certain period of time, including the glucose measurement value and the glucose value calculated based on the calibration. The computer-readable medium according to claim 157, further comprising instructions for associating each calculated glucose value with a timestamp.

161. The computer-readable medium according to claim 157, further comprising an instruction for recording the time at which the calibration command was received when executed by one or more processors, wherein the data relating to the updated glucose value includes data calculated after the time at which it was recorded.

162. When executed by one or more processors, A computer-readable medium according to any one of claims 157 to 161, further comprising instructions for displaying on the first display device and the second display device an indication of time associated with the data relating to the updated glucose value.

163. When executed by the aforementioned processor, The computer-readable medium according to claim 162, further comprising an instruction to display data relating to updated glucose values, along with an instruction to indicate whether the data includes data from a previous period before it was refilled in the first display device, when the first display device is oriented in a landscape orientation.

164. When executed by one or more processors, The computer-readable medium according to any one of claims 157 to 161, further comprising on the first display device an instruction to generate an alarm triggered by the updated glucose value reaching a predetermined value.

165. When executed by one or more processors, On the first display device, a first alarm is generated that is triggered by the updated glucose value reaching a first predetermined value. The computer-readable medium according to any one of claims 157 to 161, further comprising instructions on the second display device for generating a second alarm induced by the updated glucose value reaching a second predetermined value.

166. A continuous glucose sensor configured to synchronize data displayed on a first display device and a second display device, A wireless transceiver configured to wirelessly connect to the first display device and the second display device, It is a processor, The data relating to glucose values ​​is transmitted to the first display device and the second display device. A command for calibration of the continuous glucose sensor is received at a specific time. Based on the aforementioned calibration command, the updated glucose value data is calculated, A continuous glucose sensor comprising a processor configured to transmit the updated glucose value data to the first display device and the second display device.

167. The system according to claim 166, wherein the specified time includes a predetermined time interval.

168. The system according to claim 166, wherein the specific time includes a time that coincides with the transition of the wireless transceiver to an active state.

169. The aforementioned processor, The data relating to glucose values ​​is created based on a plurality of glucose measurements taken over a certain period of time, including the glucose measurement value and the glucose value calculated based on the calibration. The system according to claim 166, further configured to associate a timestamp with each calculated glucose value.

170. The system according to claim 166, wherein the processor is further configured to record the time at which the command relating to calibration was received, and the data relating to the updated glucose value includes data calculated after the time recorded.

171. The system according to any one of claims 166 to 170, wherein at least one of the first display device or the second display device displays a time indication associated with the data relating to the updated glucose value.

172. The system according to claim 166, wherein, when the first display device is oriented in a horizontal format, the data relating to the updated glucose value is displayed along with an indication of whether the data includes data from a period prior to when the data was re-filled into the first display device.

173. The system according to any one of claims 166 to 170, wherein the first display device is further configured to store alarms, the alarms being triggered by the updated glucose value reaching a predetermined value.

174. The first display device is configured to generate a first alarm, which is triggered by the updated glucose value reaching a first predetermined value. The system according to any one of claims 166 to 170, wherein the second display device is configured to generate a second alarm, the second alarm being triggered by the updated glucose value reaching a second predetermined value.

175. A method for connecting a transmitter of a continuous glucose system to multiple displays, To advertise by the transmitter at a specified communication interval, In response to the advertising activity, the system receives requests from the first display and the second display to connect to the transmitter, Based on the device type of the first display and the device type of the second display, it is determined whether to authorize connections between the first display and the second display, When the connection is authorized, an authentication process is performed to pair the first display and the second display with the transmitter. A method comprising storing in memory the binding information associated with the authentication process.

176. Inserting a hash value associated with the transmitter identifier into the advertisement signal, The hash value in the advertising signal is compared with the hash value of the transmitter identifier from at least one of the first display or the second display, The method of claim 175, further comprising authorizing the connection when the hash value in the advertisement signal matches the hash value of the transmitter identifier from at least one of the first display or the second display.

177. The method according to claim 175, which is repeated periodically at multiple predetermined communication intervals.

178. The method according to claim 177, wherein the above-mentioned multiple specified communication intervals occur at intervals of approximately 5 minutes.

179. The method according to claim 175, wherein the authentication process includes exchanging a periodically changing application key.

180. The method according to any one of claims 175 to 179, wherein a first list, which is a hardware-level list, stores the types of authorized devices, and a second list, which is a software-level list, stores the coupling information.

181. The method according to any one of claims 175 to 179, further comprising limiting the number of displays connected to the transmitter having a given device type to one during the communication interval.

182. A system for connecting a transmitter of a continuous glucose system to multiple displays, The aforementioned transmitter, In response to advertising activities, the transmitter receives requests from the first display and the second display to connect to the transmitter. Based on the device type of the first display and the device type of the second display, it is determined whether to authorize connections between the first display and the second display. When the connection is authorized, an authentication process is performed to pair the first display and the second display with the transmitter. A system configured to store in memory the binding information associated with the authentication process.

183. The aforementioned transmitter, The hash value associated with the transmitter identifier is inserted into the advertisement signal. The hash value in the advertising signal is compared with the hash value of the transmitter identifier from at least one of the first display or the second display. The system according to claim 182, further configured to authorize the connection when the hash value in the advertising signal matches the hash value of the transmitter identifier from at least one of the first display or the second display.

184. The system according to claim 182, wherein the transmitter periodically advertises at a plurality of predetermined communication intervals.

185. The system according to claim 184, wherein the aforementioned multiple specified communication intervals occur at intervals of approximately 5 minutes.

186. The system according to claim 182, wherein the authentication process includes exchanging a periodically changing application key.

187. The system according to any one of claims 182 to 186, wherein a first list, which is a hardware-level list, stores the types of authorized devices, and a second list, which is a software-level list, stores the coupling information.

188. The system according to any one of claims 182 to 186, further comprising limiting the number of displays connected to the transmitter having a given device type to one during the communication interval.

189. Computer-readable medium, When executed by a processor, the instruction includes a method for connecting a transmitter of a continuous glucose system to a plurality of displays, the method being: To advertise by the transmitter at a specified communication interval, In response to advertising activities, the system receives requests from the first display and the second display to connect to the transmitter, Based on the device type of the first display and the device type of the second display, it is determined whether to authorize connections between the first display and the second display, When the connection is authorized, an authentication process is performed to pair the first display and the second display with the transmitter. A computer-readable medium that includes storing in memory the binding information associated with the authentication process.

190. The method described above is Inserting a hash value associated with the transmitter identifier into the advertisement signal, The hash value in the advertising signal is compared with the hash value of the transmitter identifier from at least one of the first display or the second display, The computer-readable medium according to claim 190, further comprising authorizing the connection when the hash value in the advertising signal matches the hash value of the transmitter identifier from at least one of the first display or the second display.

191. The computer-readable medium according to claim 190, wherein the method is repeated periodically at a plurality of predetermined communication intervals.

192. The computer-readable medium according to claim 191, wherein the communication intervals of the aforementioned multiple provisions occur at intervals of approximately 5 minutes.

193. The computer-readable medium according to claim 190, wherein the authentication process includes exchanging a periodically changing application key.

194. A computer-readable medium according to any one of claims 190 to 193, wherein a first list, which is a hardware-level list, stores the types of authorized devices, and a second list, which is a software-level list, stores the combined information.

195. A computer-readable medium according to any one of claims 190 to 193, further comprising limiting the number of displays connected to the transmitter having a given device type to one during the communication interval.