Anti-tamper circuit
The integration of a tamper-resistant circuit in medical imaging systems addresses the issue of unauthorized component replacement by disabling critical functions if the device is removed and reattached to a different system, ensuring system integrity and performance.
Patent Information
- Application Number
- JP2023202112
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-03-05
- Filing Date
- 2023-11-29
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2039-08-29
AI Technical Summary
Existing systems face performance issues and damage due to the unauthorized replacement of components, particularly in medical imaging systems like CT and x-ray systems, where third-party suppliers may install used or third-party manufactured components.
Incorporating a tamper-resistant circuit in devices that disables at least one function when removed from their original system, preventing unauthorized reuse and ensuring compatibility with original components.
The tamper-resistant circuit effectively prevents the reuse of unauthorized components, ensuring system integrity and performance by disabling critical functions if the device is removed and reattached to a different system.
Smart Images

Figure 0007683893000001 
Figure 0007683893000002 
Figure 0007683893000003
Abstract
Description
Background Art
[0001] A system can be formed from various different devices. Manufacturers, system integrators, etc. may design and install a specific system using certified components. However, third-party suppliers may replace devices on a similar system or install used components or third-party manufactured components, resulting in performance issues and / or damage to the system components.
Brief Description of the Drawings
[0002]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5A
Figure 5B
Figure 5C
Figure 5D
Figure 6
Figure 7
Figure 8A
Figure 8B
Figure 9A
Figure 9B
Figure 9C
Figure 9D
Figure 10A
Figure 10B
Figure 10C
[0003] Before explaining any embodiment of the present invention in detail, it should be understood that the present invention is not limited to the details of the configurations and the arrangements of components described in the following description or illustrated in the following drawings when applied. The present invention can have other embodiments and can be implemented or executed in various ways. The numbers shown in the flowcharts and processes are given to clarify the steps and operations and do not necessarily indicate a specific order or sequence. Unless otherwise defined, the term "or" can refer to a selection of alternatives (e.g., logical disjunction operator, or exclusive or) or a combination of alternatives (e.g., conjunction operator, and / or, logical or, or Boolean OR).
[0004] Some embodiments generally relate to mechanisms, methods, and systems for disabling a component authentication system when a component is removed. Some embodiments generally relate to switches and disabling components and / or circuitry.
[0005] An electronic device may be used in an attempt to prevent third-party components from being used in systems such as computer tomography (CT) and x-ray systems. However, such an electronic device may be removed from a system that includes old components such as x-ray tubes, damaged components, or worn components. The electronic device may then be attached to a third-party tube or a used tube and sold for use in an original equipment manufacturer (OEM) system of a counterparty brand. For example, a third party may have access to an old x-ray tube, a used x-ray tube, or a damaged x-ray tube from which the electronic device can be removed. The electronic device can then be attached to a new tube, a used tube, or a third-party tube so that the tube can act as an original tube within the system.
[0006] As described herein, a tamper-resistant circuit cannot prevent the removal of a component or the electronic device itself, but can disable at least a portion to all of the functions of the device (e.g., disabling authentication or other functions, deleting configuration information, etc.). As a result, the electronic device cannot perform these functions unless reprogrammed by the manufacturer or an authorized service person. Thus, an unauthorized party can no longer reuse the electronic device and access at least a portion to all of the functions. As will be described in more detail later, the effect of losing at least a portion to all of the functions can lead to various effects, from a warning message to the invalidation of the electronic device or the system including the electronic device.
[0007] In some embodiments, in an x-ray system, an x-ray tube designed and manufactured by a manufacturer may include tube-specific information to be used with a tube assistance unit (TAU) in order to function properly for imaging without damaging the tube. The tube-specific information may be in the non-volatile random access memory (NVRAM) (e.g., flash memory or solid-state storage device) of the TAU. Since some of the information stored in the TAU is unique to the tube, if the TAU is intended to be replaced with a different tube, the tube-specific information will no longer match that particular x-ray tube. Such a mismatch may cause image quality problems and / or irreparable x-ray tube damage if used. An anti-tamper circuit can reduce or eliminate the possibility that the TAU is replaced between different x-ray tubes and the system is provided with incorrect tube-specific information.
[0008] FIGS. 1A-1C are block diagrams of a system including a device with an anti-tamper circuit according to some embodiments. FIG. 2 is a block diagram of a device with an anti-tamper circuit according to some embodiments.
[0009] Referring to FIGS. 1A and 2, system 100a includes a device 102 configured to be implemented on an external component 104. Device 102 includes an anti-tamper circuit 110 and a circuit 112.
[0010] Examples of device 102 may include a device with a circuit 112 that may include customized components, firmware, software, data, etc. The firmware or software may include instructions for implementing unique communication and / or control techniques with other circuits 122 or circuit 120 of the external component 104. In other embodiments, the data may include authentication information, cryptographic information, performance data, etc. Specific examples of device 102 may include an authentication circuit for the system, a control circuit for the x-ray tube, etc.
[0011] External component 104 may include a pure structural component and / or a circuit with some functions. For example, in some embodiments, external component 104 is the housing of the system including device 102. Device 102 may be implemented in its housing, and thus may be implemented in external component 104.
[0012] Device 102 includes a housing 116 configured to restrict access to deactivate the tamper-resistant circuit 110 when device 102 is implemented in external component 104. For example, housing 116 may include a sealed case surrounding tamper-resistant circuit 110 and circuit 112. When housing 116 is implemented in external component 104, the combination of housing 116 and external component 104 (e.g., wall 124 of external component 104) may completely enclose tamper-resistant circuit 110 and circuit 112. In some embodiments, the combination may sufficiently enclose tamper-resistant circuit 110 and circuit 112 to prevent access to tamper-resistant circuit 110 or circuit 112 without significantly modifying or destroying housing 116. The combination of housing 116 and external component 104 may be configured such that accessing tamper-resistant circuit 110 or circuit 112 is much more difficult than when device 102 is removed from external component 104.
[0013] Device 102 includes a tamper-resistant circuit 110 electrically connected to circuit 112. The tamper-resistant circuit 110 is configured to disable at least one function of circuit 112 when device 102 is removed from external component 104. Specifically, the tamper-resistant circuit 110 is coupled to external component 104 through coupling 114. This coupling 114 may be mechanical, electrical, optical, magnetic, other similar couplings, or combinations of such couplings. For example, a switch may be toggled when device 102 is mounted to external component 104. Toggling can refer to toggling from an on state to an off state or from an off state to an on state. The switch may have mechanically or magnetically switchable poles. The state of the switch may change depending on whether device 102 is mounted to external component 104 or removed from the external component. In other embodiments, the switch may change state when the fastener used to mount device 102 to the external component is removed. In other embodiments, an electrical circuit may be formed through a portion of external component 104, such as through the metal portion of wall 124. The removal of device 102 from the external component may be detected by a break in the circuit. Although some circuits and structures have been used as examples of configurations in which the tamper-resistant circuit 110 can detect that device 102 has been removed from external component 104, the tamper-resistant circuit 110 may detect removal in other ways.
[0014] The embodiments described herein may be used in any case where device 102 must remain physically paired with system 100a, external component circuit 120, other circuit 122, or another component or device in which they are implemented and / or with which they are associated. In this sense, being paired can mean physically contacting, being in proximity to, communicating with, being incorporated into, etc. the device.
[0015] The tamper-resistant circuit 110 may be configured to disable at least one function of the circuit 112 in response to detecting that the tamper-resistant circuit 110 has been removed from the external component 104. Specific functions of the circuit 112 may include the ability to perform general-purpose processing, use specific data, and appropriately respond to authentication requests. In some embodiments, the data stored in the circuit 112 may be erased. The data may include cryptographic information, authentication information, identification information, operation information, firmware, software, and the like. In some embodiments, the non-volatile memory of the circuit 112 may be erased to disable at least one function. In other embodiments, the fuse that affects the operation of the circuit 112 may be blown to disable at least one function. In some embodiments, at least one function can be disabled, while in other embodiments, the tamper-resistant circuit 110 may be configured to disable all functions of the circuit 112 or the entire device 102.
[0016] In some embodiments, the circuit 112 is configured to control an external component. The circuit 112 may be coupled to the external component circuit 120. In a specific example, the circuit 112 may include a control circuit for an x-ray tube. Examples of the external component circuit 120 may include an anode, a cathode, a filament, a radiator, a motor, steering electronics, focusing electronics, or other circuits that may be part of the x-ray tube.
[0017] In some embodiments, other techniques for preventing reuse can be triggered by radio frequency identification sensors (RFID), optical sensors, proximity sensors, barcode readers, cameras that process tube serial numbers or other identification features, trip wires, tamper-resistant mounts, or any combination of such techniques. These techniques can be paired with the ability of the tamper-resistant circuit 110 to disable at least one function of the circuit 112 as described herein.
[0018] Referring to FIGS. 1B and 2, in some embodiments, the external component 104 may be another device 106. For example, the device 106 may be an interface circuit board configured to provide an interface between the system control component and other components of the system. In a specific example, the device 106 may be an interface board that converts control and / or communication between a system control device for an x-ray system and a specific subsystem (such as an x-ray generation subsystem, a power subsystem, a detector subsystem, a cooling subsystem, a user interface subsystem, etc.).
[0019] The device 102 may be an authentication daughter board (ADB) configured to store authentication information, execute an authentication function, and negotiate authentication between the system control device and the device 106 or other subsystems of the system 100b.
[0020] Referring to FIG. 1C, in some embodiments, two or more devices 102 may be implemented on the external component 104. In this example, N devices 102 are implemented on the external component 104. The devices 102-1 to 102-N may be the same, similar, or different. However, some or all of the devices 102-1 to 102-N may include the anti-tamper circuit 110 described herein.
[0021] In some embodiments, the anti-tamper circuit 110 prevents the reuse, modification, unauthorized modification, replacement, or reinstallation of the device 102 by a third party or on a third-party manufactured component. As described above, the device 102 may be part of an authentication system. The authentication system may be configured to determine whether a component (which may be the device 102, the external component 104, or another component) within the system is an original manufacturer component or an OEM component by having the component issue an encrypted challenge question to an encrypted electronic device on the component.
[0022] In certain examples, device 102 may include an encrypted electronic device as part of circuit 112. Device 102 includes circuitry for controlling external component 104. If the encrypted electronic device can be removed from an authentic component and attached onto a counterfeit component, the intent of the authentication system can be bypassed. However, when device 102 is removed, temper-resistant circuit 110 is triggered. At least one function of circuit 112 that is disabled may include an authentication function, authentication information, and the like. After temper-resistant circuit 110 is triggered, the encrypted electronic device will no longer respond appropriately to authentication requests. As a result, system 100 displays that device 102 and / or external component 104 can no longer be trusted as being authentic manufacturer or OEM components.
[0023] In some embodiments, service contracts can be a major revenue source for an OEM. The temper-resistant circuit 110 described herein can be used by an OEM to reduce or eliminate the attachment of third-party manufacturers' or resellers' competing or alternative, or non-compatible components, which can lead to performance and patient safety issues.
[0024] Figures 3A-3C are block diagrams of circuits of devices with a temper-resistant circuit according to some embodiments. In these embodiments, the circuit includes a temper-resistant circuit 110 (similar to that described above), a processor 113, and a memory 118. Processor 113 and memory 118 are examples of circuit 112 described above.
[0025] Processor 113 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit, a microcontroller, a programmable logic device, discrete circuitry, or a combination of such devices. Processor 113 may include internal components such as registers, cache memory, volatile memory, non-volatile memory, and processing cores, and may also include external interfaces such as address and data bus interfaces and interrupt interfaces. Only one processor 113 is illustrated, but multiple processors 113 may exist. Additionally, other interface devices such as logic chip sets, hubs, memory controllers, and communication interfaces may be included to connect processor 113 to internal and external components.
[0026] Processor 113 is coupled to memory 118. Memory 118 includes data such as cryptographic information, authentication information, identification information, operation information, firmware, and software as described above. Tamper-resistant circuit 110 is configured to erase at least a portion of memory 118 used by processor 113 when device 102 is removed from external component 104. In some embodiments, the erasure may be all of such data. In other embodiments, the erasure may be an amount and quality of data sufficient to render device 102 inoperable (e.g., erasure of secret information such as cryptographic keys).
[0027] Referring to FIG. 3A, in some embodiments, processor 113 includes on-chip or otherwise integrated memory 118a. As a result, when tamper-resistant circuit 110 erases at least a portion of memory 118a, the erased memory is memory integrated with processor 113.
[0028] Referring to FIG. 3B, in some embodiments, the tamper-resistant circuit 110 is coupled to the processor 113. The processor 113 is coupled to an external memory 118b. The tamper-resistant circuit 110 may be configured to cause the processor 113 to execute a command to erase at least a portion of the external memory 118b. For example, the tamper-resistant circuit 110 may cause the processor to execute an interrupt service routine that erases a portion of the memory 118b. In another example, the tamper-resistant circuit 110 may be configured to start the processor 113 in a mode specifically designed to erase a portion of the memory 118b. Although the processor 113 is illustrated as being directly coupled to the memory 118b, in other embodiments, other intervening circuits, such as a memory controller, may be present.
[0029] Referring to FIG. 3C, in some embodiments, the tamper-resistant circuit 110 may be configured to access the memory 118c without accessing the processor 113. Thus, the tamper-resistant circuit 110 may be configured to erase a portion of the memory by controlling the memory 118c.
[0030] Although various configurations of the tamper-resistant circuit 110, the processor 113, and the memory 118 have been described above, in other embodiments, the tamper-resistant circuit 110, the processor 113, and the memory 118 may be coupled in any manner such that the portion of the memory 118 used by the processor 113 can be erased by the tamper-resistant circuit 110.
[0031] FIGS. 4A-4B are cross-sectional views illustrating, in some embodiments, mounting a device with a tamper-resistant circuit on an external component. FIG. 4A illustrates the state of the device 102 and the external component 104 before the device 102 is mounted on the external component 104 or after the device 102 is removed from the external component 104. FIG. 4B illustrates the state of the device 102 and the external component 104 when the device 102 is mounted on the external component 104.
[0032] Referring to FIGS. 4A and 4B, in some embodiments, the device 102 includes a housing 116. The device 102 includes a switch 220. The switch 220 is coupled to the housing 116. Although the housing 116 is illustrated as an example of an implementation structure of the device 102, in other embodiments, the implementation structure may be a structure other than the housing 116. The implementation structure may be any structure, substrate, component, etc. that remains with the device 102 when the device is moved relative to the external component 104. The housing includes a flange 212. Fasteners 214 may be used to attach the housing 116 to the wall 124 of the external component 104. Although components such as the flange 212 and the fasteners 214 are used as examples for implementation, different implementation techniques may be used in other embodiments.
[0033] The switch 220 is configured to switch when the device 102 is removed from the external component 104. When the device 102 is in the state illustrated in FIG. 4A, the pole 222 of the switch 220 is in a first state. In a specific example, the switch 220 may be a momentary normally closed switch. Thus, in the state illustrated in FIG. 4A, the switch 220 is closed.
[0034] As illustrated in FIG. 4B, when the device 102 is mounted on the external component 104, the pole 222 of the switch 220 is switched by the structure 204 of the external component 104. Thus, the switch 220 is open.
[0035] In some embodiments, the structure 204 is a protrusion, wall, rib, gusset, fastener, etc. The structure 204 is disposed on the external component 104 such that the state of the switch 220 is toggled by the structure 204 when the device 102 is mounted on the external component 104.
[0036] Although the specific structures of device 102, external component 104, and switch 220 have been used as an example, any mechanism and associated structure that places switch 220 in an implemented first state and a removed second state may be used. Specifically, before accessing anti-tamper circuit 110 to disable anti-tamper circuit 110 or, alternatively, before anti-tamper circuit 110 can prevent at least one function of circuit 112 from being disabled as described above, a mechanism and associated structure may be formed such that switch 220 changes state.
[0037] In addition, it is not necessary to mechanically switch switch 220. For example, switch 220 may be switched magnetically. Structure 204 may include a magnet or ferromagnetic material that follows the structure of switch 220 such that switch 220 changes state when device 102 is implemented in external component 104 or removed from external component 104.
[0038] Although a single switch 220 has been used as an example, in other embodiments, multiple switches 220 in different locations and / or different configurations may be used. In some embodiments, anti-tamper circuit 110 may use any one of these switches 220 to disable at least one function of circuit 112.
[0039] Figures 5A - 5D are schematic circuit diagrams of anti-tamper circuits according to some embodiments. Referring to Figure 5A, anti-tamper circuit 110a includes a power supply 502 and a disabling circuit 504. Power supply 502 is configured to generate power that disabling circuit 504 and potentially a portion of circuit 112 may use.
[0040] The power supply 502 is disposed within the device 102. The power supply 502 is configured to supply power after it is detected that the device 102 has been removed from the external component 104. The power supply 502 may include a battery, a capacitor, a supercapacitor, or any other energy storage device that may be disposed within the device 102. In some embodiments, the power supply 502 may be charged by an external power supply 506.
[0041] In some embodiments, the power supply 502 may include a switch that connects the power supply 502 to other components of the tamper-resistant circuit 110 when the device 102 is removed from the external component 104.
[0042] The disabling circuit 504 is a circuit configured to disable at least one function of the circuit 112. In this example, the disabling circuit 504 includes an ERASE output. The ERASE output is a signal coupled to an ERASE input on a processor, memory, etc. of the circuit 112 that initiates an erase command to erase the memory or otherwise disable at least one function.
[0043] In some embodiments, power PWR may be supplied to some components of the circuit 112. Specifically, when the device 102 is removed from the external component 104, it may not be necessary to connect the device 102 to an external power supply or the external power supply may be disabled. Instead, the power supply 502 may supply the power necessary to enable the disabling circuit 504 to disable at least one function of the circuit 112.
[0044] Referring to FIG. 5B, the anti-tamper circuit 110b includes a battery B1 and a switch SW1. Although a single battery B1 is illustrated, in other embodiments, a plurality of batteries may be used. The switch SW1 is a two-pole / double-throw switch (DPDT). In the illustrated state, the connection of the switch SW1 is made such that 3.3V is coupled to VDD_CPU and no connection is formed to ERASE-CPU. In the other state, both VDD_CPU and ERASE_CPU are coupled to the battery B1.
[0045] VDD_CPU is a power supply for a processor that may be part of circuit 112. ERASE_CPU is a signal that commands the processor of circuit 112 to erase some or all of its memory. As a result, at least one function of circuit 112 may be disabled. The state when the corresponding device 102 is implemented in the external component 104 is illustrated with the switch SW1. When removed, the switch SW1 transitions to the other state, supplying power to the processor through VDD_CPU and supplying an erase signal through ERASE_CPU.
[0046] The isolator I is a removable structure configured to disconnect the battery B1 from the switch. When in a fixed position, the battery B1 is disconnected and does not supply power to the switch SW1. Accordingly, ERASE_CPU does not operate. The isolator I can be in a fixed position while attached to disable the anti-tamper circuit 110b.
[0047] The other circuits shown can provide a status indicator for various states. R1 is coupled to VDD_CPU and pulls down the input to AND gate U1. The other input to AND gate U1 is the error signal ERROR_N. When device 102 is being attached and 3.3V power is applied, switch SW1 is in the opposite state as shown. However, due to the presence of isolator I, the battery does not activate ERASE_CPU. VDD_CPU is not coupled to 3.3V and is pulled down by R1. Therefore, the output of AND gate U1 is low and LED D1 is on. When device 102 is properly attached, switch SW1 changes to the state shown and VDD_CPU is set to 3.3V. Assuming there is no error indicated by ERROR_N being low, the output of AND gate U1 switches high. Since the output is high, LED D1 turns off. As a result, the installer receives a visual indication that device 102 has been attached such that switch SW1 is in the state shown.
[0048] Once the attachment is made, isolator I can be removed. ERROR_N controls whether the output of AND gate U1 and LED D1 are turned on. In this way, LED D1 serves as an error indicator. However, when device 102 is removed, switch SW1 changes state and activates VDD_CPU and ERASE_CPU.
[0049] In one example, switch SW1 is a normally closed (NC) double pole double throw (DPDT) switch that couples battery B1 to ERASE_CPU in the closed state. This switch is normally closed (NC) and can be made to open when pushed, such as when device 102 is attached and the switch is pushed by the function of external component 104.
[0050] Referring to FIG. 5C, the operation may be the same as that of FIG. 5B. However, VCC_INSTALL is the voltage of the power supply supplied when 3.3V does not operate while it is attached. Resistors R3 and R4 are in series with LED D2 with respect to either VCC_INSTALL or 3.3V. Therefore, when the cathode of LED D2 is pulled down to low, LED D2 turns on. Buffer U2 is an open-drain buffer. Inverter U3 is an open-drain inverter. Therefore, when the input to U2 is low, or when the input to U3 is high, LED D2 turns on.
[0051] When the switch is in the device with the device attached, the nodes connected to ERASE_CPU, and registers R5, R6, R7, and transistor Q1 are pulled down to ground, and transistor Q1 is off. However, when device 102 is removed from external component 104, the state of switch SW1 changes, the voltage of node N1 rises, and ERASE_CPU outputs a pulse until C1 is charged. R5 and C1 are selected to provide a pulse sufficient to erase part of the memory and disable at least one function.
[0052] Referring to FIG. 5D, the operations of U2, U3, registers R8, R9, and R10, diodes D3, D4, and LED D5 may be the same as those in FIG. 5C. Here, diodes D3 and D4 separate VCC_INSTALL from 3.3V. The operation of the anti-tamper circuit 110d may be the same as that of the anti-tamper circuit 110c in FIG. 5C.
[0053] Although 3.3V is used as an example of the power supply voltage, in other embodiments, the power supply voltage may be different.
[0054] Figures 6A and 6B are flowcharts showing techniques for operating a device with an anti-tamper circuit according to some embodiments. Referring to Figure 6A, at 604, the removal of device 102 from external component 104 is detected. As described above, various techniques can be used to detect the removal of device 102. For example, changes in the state of a switch, changes in a magnetic field, disconnection of a circuit, etc. can indicate whether device 102 is being removed from external component 104.
[0055] At 606, at least one function of device 102 is disabled. As described above, at least one function can be disabled by data erasure, disabling components such as a processor, etc. Various forms of anti-tamper circuit 110 can be used to perform the disabling.
[0056] In some embodiments, the detection of the removal of device 102 can include detecting a physical separation between the structure of device 102 and the structure of external component 104. For example, switch 220 can detect when device 102 has moved relative to external component 104.
[0057] Referring to Figure 6B, at 600, device 102 is attached to external component 104. For example, during an authorized attachment, component replacement, and / or system maintenance, device 102 can be prepared and mounted on external component 104. During the attachment, anti-tamper circuit 110 can be deactivated. For example, as described above, a removable isolator I such as insulating tape can be placed between the contacts of power supply 502 and disabling circuit 504.
[0058] At 602, the anti-tamper circuit 110 can be made operable. For example, the anti-tamper circuit 110 can be made operable by removing the insulating tape when the device 102 is attached. Before removing the insulating tape, the device 102 can be repeatedly mounted and removed without operating the anti-tamper circuit 110. However, once the insulating tape is removed, the anti-tamper circuit 110 becomes operable, and all attempts to remove the device 102 from the external component 104 are detected and can be used to disable at least one function of the circuit 112 of the device 102 in operations 604 and 606.
[0059] When the anti-tamper circuit 110 is triggered and at least one function of the circuit 112 is disabled, the device 102 can be reset at 608. Resetting the device 102 includes the operation of returning the device 102 to a state where it can be reinstalled or operated again in an authorized manner. For example, the device 102 may be returned to an authorized repair site. Restoration of the erased data to the device 102, reactivation of the disabled components, replacement of the disabled components, reinstallation of the above isolator I, etc. may be performed so that the device 102 is in the same state as the device 102 without disabling at least one function of the circuit 112. Although the return of the device 102 to an authorized repair site is used as an example, the reset of the device 102 can be performed by an authorized repair technician using appropriate data and / or components. Unauthorized parties may not have the appropriate data and / or components and cannot restore the device 102 to an operating state.
[0060] FIG. 7 is a block diagram of an X-ray system according to some embodiments. The X-ray system 700 includes a host controller 702, an interface board (IFB) 704, a tube auxiliary unit (TAU) 732, and an X-ray tube 736. These components may be mounted on a rotatable gantry 710.
[0061] In some embodiments, device 102 is or is part of an IFB 704. The external component 104 may be a gantry 710. Thus, if the IFB 704 is removed from the gantry, at least one function of the IFB 704 may be disabled if the interface board is removed from the gantry 710. The IFB 704 may include secret information such as firmware, software, calibration data, keys, IDs, or other cryptographic information that can be erased to disable at least one function.
[0062] In some embodiments, device 102 is an authentication daughter board (ADB) 703 mounted on the IFB 704. The external component 104 may be the IFB 704. Information as described above is deleted when the ADB 703 is removed from the IFB 704.
[0063] In some embodiments, device 102 is a TAU 732. The TAU 732 may be attached to an x-ray tube 736. The external component 104 may be the x-ray tube 736. Thus, if the TAU 732 is removed from the x-ray tube 736, at least one function of the TAU 732 can be disabled. The TAU 732 may include data or firmware that can be erased similar to the IFB 704 or the ADB 703.
[0064] In some embodiments, the host controller 702 is configured to control the operation of components such as the gantry 710, IFB 704, x-ray tube 736, etc. via the TAU 732. These components are used as examples, but there may be other components such as an image detector, a high voltage (HV) generator, a heat exchanger, etc. The host controller 702 may also be configured to communicate with the IFB 704 and perform various actions such as identification and authentication in addition to instructing the control of the system 700.
[0065] As described above, in some embodiments, IFB704 includes ADB703. This structure may make it easier to incorporate ADB703 into an existing CT system. IFB704 has a communication link to host controller 702 and another communication link to TAU732. ADB703 includes cryptographic authentication hardware / firmware that enables encrypted communication with both host controller 702 and TAU732. IFB704 is a device that holds ADB 703, powers it, and converts communication to the native communication protocol of ADB703.
[0066] TAU732 includes cryptographic authentication hardware / firmware that enables encrypted communication with IFB704 / ADB703 and is attached to x-ray tube 736. When a hospital installs a new x-ray tube with TAU732 attached, IFB704 / ADB703 can request that TAU732 confirm whether it is an original manufacturer's x-ray tube or an OEM x-ray tube.
[0067] In some embodiments, the authentication unit of TAU732 is mounted on x-ray tube 736, but the authentication unit may also be an integrated part of x-ray tube 736. Tamper-resistant circuit 110 is part of that authentication unit. Similarly, other components such as an x-ray detector or imaging device, an accelerator, or other devices that it is beneficial to make unusable after removal from their original mounting location may include device 102. Each of these may have an associated tamper-resistant circuit 110.
[0068] In a particular example, removal of a used x-ray tube, x-ray detector, or imaging device from an x-ray or mammography system for the purpose of reselling to another system can be prevented. When device 102 is removed, the switch of tamper-resistant circuit 110 is triggered, disabling the authentication function, making the firmware unusable, and preventing all other important functions that allow communication or further use of device 102.
[0069] In some embodiments, the software / firmware (SW / FW) usage license of TAU732, X-ray tube 736, detector, or other device software sold to a particular company under a license agreement that permits the use of the firmware / software (FW / SW) or hardware only to the original purchaser can also be enhanced using the tamper-resistant circuit 110. In such embodiments, when the device is removed, each FW / SW is automatically erased.
[0070] Although a CT system with a rotating gantry 710 has been used as an example of the X-ray system 700, the X-ray system 700 can take other forms.
[0071] Some embodiments generally relate to mechanisms, methods, and systems that use a system identifier (ID) (or device ID) in encrypted form for components.
[0072] In some embodiments, a manufacturer or OEM can detect, by the mechanisms, methods, and systems described herein, that a component has been attached to the system without authorization. Currently, third-party suppliers can replace components on the system with used OEM components or third-party components. This can lead to warranty issues, quality issues, and in the case of imaging systems, image quality issues, diagnostic issues, and misdiagnosis. In the embodiments described herein, it is possible to detect changes to components that have not been given such authorization and ensure the integrity of the system.
[0073] In the absence of a system as described herein, a third party can purchase used components and sell them to customers, gaining an advantage in terms of lower price over OEM service contracts. In contrast, according to the embodiments described herein, the OEM host system can determine whether its components have been replaced without permission and / or prevent the attachment of old, obsolete, or hazardous components to the system that may affect operation, such as the replacement of components of the imaging system that affect patient diagnosis. Defective or sub-optimally functioning components can lead to misdiagnosis and, in extreme cases, permanent damage to the patient and even death.
[0074] Figures 8A and 8B are block diagrams of a system including an authentication system according to some embodiments. Referring to Figure 8A, system 800a includes a first device 802 and a second device 804. Devices 802 and 804 are coupled via a communication link 806. The communication link can be any medium through which devices 802 and 804 can communicate. For example, communication link 806 can include a serial link, a parallel link, and automation communication links such as Modbus, CAN bus, computer buses such as Peripheral Component Interconnect Express (PCIe), Non-Volatile Memory Express (NVMe), and / or networks such as Ethernet (registered trademark) network, Fibre Channel network.
[0075] The second device 804 includes a non-volatile memory 808. The memory 808 can include any of a variety of non-volatile memories such as static random access memory (SRAM), flash memory, electrically erasable programmable read-only memory (EEPROM), magnetic storage, etc. In particular, the memory 808 includes a portion that is operable in a one-time write (OTW) mode for at least a part of it. The memory 808 can include other non-volatile memories not configured for one-time writing and / or volatile memories such as dynamic random access memory (DRAM) compliant with various standards such as DDR, DDR2, DDR3, DDR4, double data rate synchronous dynamic random access memory (DDR SDRAM), etc.
[0076] Being one-time write means that a part of the memory 808 can be written once with a normal write operation. In some embodiments, the one-time write memory 808 cannot be erased by other means. As a result, to change the value stored in the memory 808, it is necessary to replace the memory 808. However, in other embodiments, a part of the memory 808 can be erased by erasing the entire memory 808.
[0077] The memory 808 is configured to store a system identifier (ID) in the one-time write portion. The system ID is an identifier associated with the system 800a. The system ID can be unique to the system 800a by being a universally unique ID (UUID) or a globally unique ID (GUID). The system IDs of all devices 804 and 812 may be the same. However, in other embodiments, the system ID of a particular device 804 or 812 can be unique to both the system 800a and that device 804 or 812. In some embodiments, the system ID can include a portion unique to the system 800a, a portion unique to a particular device 804 or 812, and a particular device type 804 or 812, etc.
[0078] The value of the system ID can take various forms. For example, the system ID may exist in its original form where the stored data is the system ID. However, in other examples, an encrypted form of the system ID, a hash of the system ID, or other representations of the system ID are stored as the system ID and are appropriately decrypted or otherwise manipulated for proper handling.
[0079] As will be described in more detail below, the system ID can be stored in a device 804 within the system 800a. The first device 802 can verify that the system ID stored in the second device 804 or the third device 812 matches an expected system ID, such as the system ID associated with the system 800a. A match of the system ID can indicate that the second device 804 or the third device 812 is a genuine component intended for and originally attached to the system 800a. If the system IDs do not match, the device 804 or 812 may have been provided or attached by an unauthorized party. As a result, an exchange with a device from another system of the same manufacturer or a third party can be detected.
[0080] In some embodiments, the first device 802 can be coupled to a plurality of second devices 804-1 through 804-N. Each second device 804 can be coupled to zero to a plurality of third devices 812-1 through 812-M.
[0081] Figures 9A through 10C are flowcharts showing examples of techniques for operating an authentication system according to some embodiments. In the following description of the techniques for operating the system, the operations of the first device 802, the second device 804, and the third device 812 of FIG. 8A are used as examples.
[0082] Referring to FIGS. 8A and 9A, at 902, the first device 802 sends a request to the second device to obtain the system ID stored in the second device 804. The second device 804 receives the request at 903. This transmission and other similar operations can occur via the communication link 806.
[0083] At 904, the second device 804 determines whether the system ID stored in the second device has a null value. A null value represents a state where the second device 804 does not store the system ID in the memory 808. The actual value may not be stored in the memory 808. Instead, a flag, register, status, etc. may indicate that the system ID is not programmed in the memory 808. Checking such an indication can be part of determining whether the system ID has a null value. The processor of the second device 804 may be configured to attempt to read the system ID, flag, register, status, etc. to make the determination.
[0084] At 906, a response based on the null value is sent to the first device 802. In some embodiments, the response can be a system ID having a specific meaning. For example, all zeros or all ones can be designated as the null value of the system ID. In other embodiments, one or more specific values of the system ID may be designated as the null value. The specific value can be unique to the second device 804 or the type of the second device 804, unique to the system 800a or the type of the system 800a, etc. In any case, the value is one that the first device 802 recognizes as indicating that the second device 804 does not store the system ID or that the system ID has a null value.
[0085] In other embodiments, the null value response may be a different type of message than that used to send the actual system ID. For example, the null value response may be an error message. The error message can have an error number or code indicating that the system ID is null.
[0086] At 908, a response with a null value is received by the first device 802. In response, at 910, the first device 802 transmits the system ID to the second device 804. The second device 804 receives the system ID at 912 and stores it in the one-time write portion of the memory 808. Once the system ID is stored, the memory 808 cannot be reprogrammed with a different system ID without the special steps as described above. As a result, the second device 804 is paired with the system 800a. If the second device 804 is removed from the system 800a and attached to another system, even if it is the exact same system, the system IDs will not match.
[0087]
[0088] If it is determined at 904 that the system ID is to be stored in the second device 804, then at 914, a response based on the system ID is returned to the first device 802. For example, the second device 804 can read the system ID, encrypt it, and transmit the encrypted system ID to the first device 802.
[0089] The first device 802 receives the response based on the system ID stored in the second device 804 at 916 and determines at 918 whether the response indicates that the system ID stored in the second device 804 matches the actual system ID. For example, the first device 802 can read the system ID from the response, extract the system ID by decrypting the encrypted response, etc., and compare it with the system ID stored in the first device 802. As described above, the system ID can be stored or encrypted in various forms. The comparison can be performed in a manner suitable for various forms.If the system ID indicated by the response from the second device 804 is incorrect, if the second device 804 does not respond or times out, or if the second device 804 returns an inappropriate response, etc., then countermeasures are executed at 920. The countermeasures can take various forms. For example, in some embodiments, the system 800a can be shut down, devices 802, 804, 816, etc. can be temporarily or permanently disabled, certain functions can be disabled, the operating range can be reduced or restricted, etc. In other embodiments, notifications, warnings, or other communications regarding the mismatched system ID can be provided to the user of the system 800a and reported via the network. In other embodiments, information related to the mismatched system ID can be recorded in the memory 808 of the first device 802 and / or the second device 804. The related information can include a timestamp, model number, and / or serial number of the first device 802 and / or the second device 804, the number of times the system IDs did not match, the mismatched system ID, the entire response received at 916, etc.
[0090] In some embodiments, at 914, when a response based on the system ID is transmitted from the second device 804 to the first device 802, the communication can be encrypted. For example, a secure communication link can be established between the first device 802 and the second device 804, the response or a part thereof can be encrypted, the system ID stored in the second device 804 can be encrypted, etc. As a result, it can be made more difficult for eavesdroppers to obtain the correct system ID response from the second device 804.
[0091] System 800a may be a hierarchical system that includes one or more third devices 812 downstream of an associated second device 804. In some embodiments, some or all of the communication between the first device 802 and the third device 812 may pass through, or be operated by, the associated second device 804. However, in other embodiments, only communication related to the system ID may pass through, or be operated by, the associated second device 804.
[0092] In some embodiments, the interaction between the second device 804 and the third device 812 may be the same as, or similar to, the operations described with respect to the first device 802 and the second device 804. That is, after the second device 804 stores the system ID, requests for the system ID, storage in the case of being empty, and verification can be performed between the second device 804 and the third device 812.
[0093] Referring to FIGS. 8A, 9A, and 9B, in some embodiments, after the second device 804 transmits a system ID response at 914, the second device 804 may start the operations described above with respect to FIG. 9B. A request for the system ID stored in the third device 812 may be transmitted from the second device 804 to the third device 812 at 922. The third device 812 may receive a request for the system ID stored in the third device 812 at 924. At 926 and 928, similar to the operations at 904 and 906 in FIG. 9A, the third device 812 determines whether the system ID is a null value or not stored, and if so, returns a null value response. At 930 and 932, similar to the operations at 908 and 910 in FIG. 9A, the second device 803 receives a response indicating that the system ID stored in the third device 812 has a null value, and transmits the system ID as a response. At 934, the third device 812 stores the system ID in the memory 808. At 936 and 938, similar to the operations at 914 and 916, the third device 812 transmits a response based on the system ID stored in the third device 812, and that response is received by the second device 804. The operations of the second device 804 and the third device 812 have been described as being similar to the operations of the first device 802 and the second device 804, but in other embodiments, the operations may be different. For example, different system ID encodings, encryptions used in transmission, response formats, specific protocols, etc. may be used.
[0094] At 940, the second device 804 can prepare a verification response based on the response from the third device 812. In some embodiments, the verification response can include a system ID response from the third device 812 itself. In other embodiments, the second device 804 may determine whether the system ID stored in the third device 812 matches the system ID stored in the second device 804, similar to the interaction of the first device 802 at 918 in FIG. 9A. The verification response can include an indication of whether the system ID stored in the third device 812 is the correct system ID.
[0095] Referring to FIGS. 8A and 9A - 9C, in some embodiments, when it is determined at 918 that the system ID stored in the second device 804 is the correct system ID, the first device 802 may send a verification request to the second device 804 at 941. At 942, the second device 804 receives the verification request. As described above, the second device 804 can prepare a verification response at 940. This verification response can be sent by the second device 804 to the first device 802 at 944. The first device 802 receives the verification response at 946 and makes a determination at 948 based on the response as to whether the verification was successful. If the verification is successful, the operation continues at 952.
[0096] However, if the verification is not successful, a countermeasure can be executed at 950. The countermeasure can be similar to the countermeasures described with respect to 920. However, since the verification response can be associated with the third device 812, the countermeasure also applies to the third device 812. For example, the third device 812 may be disabled, or a notification identifying the third device 812 may be provided.
[0097] Referring to FIGS. 8A, 9A, 9B, and 9D, in some embodiments, after the second device 804 prepares a verification response at 940, the second device 804 can transmit the verification response to the first device 802 at 944 without waiting for a request to be transmitted at 941. The operations of the first device 802 at 946, 948, 950, and 952 can be the same as those described above.
[0098] The operations of the first device 802 and the second device 804 have been described in the context of communication between the first device 802 and one second device. However, the same or similar communication can occur between the first device 802 and a plurality of second devices 804-1 to 804-N. That is, the first device 802 can request a system ID for each of the second devices 804-1 to 804-N and perform operations similar to those described above. The operations for different second devices 804-1 to 804-N can be executed sequentially or in parallel. The determination can be based on the responses of only one of the second devices 804-1 to 804-N, a part of the second devices 804-1 to 804-N, or all of the second devices 804-1 to 804-N. The results of system ID matching or mismatching can be the same, similar, or different for different second devices 803-1 to 804-N. The operations described between the second device 804 and the third device 812 can be similarly executed between a plurality of third devices 812. Further, although a three-layer hierarchy has been used as an example, the hierarchy of devices can be part of a system 800a in which the first device 802 queries other devices about the system ID.
[0099] Referring to FIG. 8B, in some embodiments, the X-ray system 800b includes a host controller 822, an ADB 824, a TAU 832, and an X-ray tube 836. The host controller 822 can be the system controller of the X-ray system 800b. The host controller 822 serves as the first device 802 in FIG. 8A and can perform the associated operations described in FIGS. 9A to 9D.
[0100] ADB824 may be a circuit that manages the system ID and authentication operations of system 800b. ADB824 can include memory 808. ADB824 can serve as the second device 804 in FIG. 8A and perform the associated operations described in FIGS. 9A-9D.
[0101] TAU832 is a circuit configured to control the operation of x-ray tube 836. For example, TAU832 can be configured to control cathode voltage / current, anode voltage / current, filament voltage / current, focus adjustment electronics, steering electronics, motors, etc., depending on a particular x-ray tube 836. TAU832 includes memory 808, serves as the third device 812 in FIG. 8A, and can perform the associated operations described in FIGS. 9A-9D.
[0102] TAU832 is used as an example of a device of x-ray system 800b that can operate using the system ID described herein, but other devices of x-ray system 800b can operate similarly. For example, heat exchanger 840, detector 842, high voltage (HV) power supply 844, accelerator 846, etc. can operate using the system ID described in this specification.
[0103] In some embodiments, at initialization or installation, the system ID can be transmitted from host controller 822 to ADB824 and stored in memory 808. ADB 824 can similarly propagate the system ID to other devices 832, 840, 842, 844, 846, 848, etc. for storage in the corresponding memory 808 of those devices. Thus, the devices of system 800b can be paired with that system 800b. During normal operation, the device reports the correct system ID and system 800b can continue operation. However, if components are illicitly replaced with an existing different system ID, the countermeasures described above may be implemented.
[0104] In some embodiments, the host controller uses the ADB824 to communicate with the remaining manufacturers or OEM components in the system 800b. In some embodiments, the only components paired with the system 800b are the ADB824 and the TAU832.
[0105] The use of the system ID described herein in the X-ray system 800b can improve the safety and / or lifespan of the system 800b. In particular, the components of the system 800b can be aligned, calibrated, or otherwise configured for that particular X-ray system 800b. When the system 800b is first installed, the empty system IDs of the various devices of the X-ray system 800b can be initialized to the system ID unique to that particular X-ray system 800b. If a device in the X-ray system 800b is replaced with a device from another system having a different system ID, the operation of the X-ray system 800b may not be the same and can be dangerous, such as by a device like the X-ray tube 836. As described above, the X-ray system 800b can notify the user and take measures such as shutting down the X-ray system 800b or its components if such a situation is detected. As a result, the opportunity for the X-ray system 800b to operate in a way that can result in incorrect results and / or dangerous operating conditions can be reduced or eliminated.
[0106] In some embodiments, the storage and verification of the system IDs described herein can limit the ability of a manufacturer or vendor's customer to replace components themselves or through a third party. The verification process checks to confirm whether components such as ADB824 and TAU832 are genuine manufacturer or OEM products and have not been exchanged with other X-ray systems. This prevents third-party service organizations from purchasing used X-ray tubes on the open market, refurbishing them, and then selling them to customers such as hospitals. Manufacturers, vendors, system integrators, etc. can reduce the chance that their systems will be altered by devices from other systems, which could lead to undesirable or dangerous results.
[0107] In some embodiments, the use of the system IDs described herein can reduce the chance that a reprocessed device will be installed in an unintended system. For example, a device paired with a system and having a system ID may be returned for repair, update, etc. The device can be programmed with the original system ID or the system ID can be left as is. As a result, when the device is provided to a customer or installer, the system ID will match that of the original system. If the device is installed in another system, even if it is a similar or the same type of system, the system IDs will not match and the measures described above can be implemented. In some embodiments, if a known customer or installer reinstalls a device in the same system, the system ID can be left unprogrammed.
[0108] Referring to FIGS. 8A and 9A - 10C, in some embodiments, after the verification in 948 is successful, the authentication operation can be executed. For example, at 1002, the first device 802 sends an authentication request to the second device 804. At 1004, the authentication request is received by the second device 804. The second device 804 sends the authentication request to the third device 812 at 1006.
[0109] The third device 812 receives the authentication request at 1008. At 1010, the third device generates an authentication response and sends the authentication response to the second device 804 at 1012.
[0110] The second device 804 receives the authentication response from the third device 812 at 1014. The second device 804 analyzes the authentication response at 1016, records a failure at 1018, and generates its own authentication response at 1020. The authentication response generated at 1020 can aggregate the authentication response or responses received from one or more third devices 812 and the authentication response of the second device 804 itself.
[0111] At 1022, the first device 802 can send a request for the authentication status received by the second device at 1024 as shown in FIG. 10B. In response, the second device 804 sends an authentication response to the first device 802 at 1026. Alternatively, the second device 804 may send an authentication response to the first device 802 at 1026 after generation at 1020 as shown in FIGS. 10A and 10C.
[0112] When the authentication response is received at 1028, the response can be analyzed at 1030 to determine whether the authentication was successful. If successful, the operation can continue at 1034. If not, countermeasures are taken at 1032 as in the above - mentioned countermeasures.
[0113] Devices 804 and 812 can be authenticated using a variety of different techniques. In some embodiments, authentication can be performed using challenges that use a hidden number. Encryption algorithms can use an initialization vector (IV) and an encryption key (key). The first device 802 and / or the second device 804 can use its IV and key to create a challenge (mathematical problem) and send it to the downstream second device 804 or third device 812. If that device has the key and IV, it can execute the same mathematical problem to obtain the same result. Then, the "challenged" second device 804 or third device 812 can return an "answer" to that mathematical problem in encrypted form, and the original component can verify that it is answering the challenge correctly. If it responds with the correct answer, the first device 802 and / or the second device 804 can treat the corresponding second device 804 or third device 812 as an authentic component.
[0114] In some embodiments, the IV and key are held in the limited memory of an authentication integrated circuit. For example, an ATSHA integrated circuit can include such limited memory and can perform calculations related to encrypted communications. If the IV and key are stored in such limited memory, the authentication operation can be made more secure.
[0115] In some embodiments, an authentication process is used to confirm that all required components are present in the system, designed for a particular customer, and / or are genuine manufacturer or OEM components. Different customers can own customer-specific encryption keys so that third parties cannot obtain components designed for one customer and sell them to others. Any missing components will fail the authentication process because they do not verify whether they are present. The authentication process can prevent third parties from supplying parts of the system. If a complete computed tomography (CT) system is designed to have five manufacturer or OEM components, but only four of them are legitimate and the fifth is supplied by a third party, the authentication process will identify that fifth component as not genuine.
[0116] As described above, the system 800a may include two or more second devices 804 and two or more third devices 812. Authentication is performed with each of these as described for a single second device 804 and a single third device 812.
[0117] The system 800a of FIG. 8A was used as an example, but the authentication operations described above with respect to FIGS. 10A - 10C may be implemented by other systems such as the X-ray system 800b of FIG. 8B.
[0118] Some embodiments include a device 102 comprising: an attachment structure configured to attach the device 102 to an external component 104; a first circuit 112; and an anti-tamper circuit configured to electrically connect to the first circuit 112 and disable at least one function of the first circuit 112 when the device 102 is removed from the external component 104. In some embodiments, the external component 104 may include a wall, a housing, or other structure not controlled by the first circuit 112.
[0119] In some embodiments, the first circuit 112 is configured to control the external component 104. In some embodiments, at least one function of the first circuit 112 includes functions not related to the control of the external component 104.
[0120] In some embodiments, at least one function of the first circuit 112 includes the function of the first circuit 112 that controls the external component 104.
[0121] In some embodiments, the device 102 further comprises a housing 116 coupled to the attachment structure, and the housing 116 is configured to restrict access to release the anti-tamper circuit when the device 102 is attached to the external component 104.
[0122] In some embodiments, the anti-tamper circuit 110 comprises a switch 220 or SW1 coupled to the attachment structure 116 and configured to switch when the device 102 is removed from the external component 104.
[0123] In some embodiments, the switch 220 or SW1 is configured to switch by the structure of the external component 104 when attached to the external component 104.
[0124] In some embodiments, the anti-tamper circuit 110 comprises a power supply 502 configured to supply power after detecting the removal of the device 102 from the external component 104 and disposed inside the device 102, and a disabling circuit 504 configured to disable at least one function of the first circuit 112. The switch 220 or SW1 is configured to electrically connect the power supply 502 to the disabling circuit 504 when the device 102 is removed from the external component 104.
[0125] In some embodiments, the first circuit 112 includes a processor 113, and the anti-tamper circuit 110 is configured to erase at least a portion of the memory 118 or 808 used by the processor 113 when the device 102 is removed from the external component 104.
[0126] In some embodiments, at least a portion of the memory 118 or 808 used by the processor 113 comprises the memory 118 or 808 integrated with the processor 113.
[0127] In some embodiments, at least a portion of the memory 118 or 808 used by the processor 113 stores encrypted information.
[0128] In some embodiments, the device 102 is part of an electronic device associated with an X-ray system, and the external component 104 is the X-ray tube 736 or 836 of the X-ray system 700 or 800b.
[0129] In some embodiments, the device 102 is part of a component authentication system associated with the X-ray system 700 or 800b.
[0130] Some embodiments include a method comprising detecting removal of the device 102 from an external component 104 of the device 102 by the device 102, and disabling at least one function of the circuit 112 of the device 102 in response to detecting removal of the device 102 from the component 104.
[0131] In some embodiments, detecting removal of the device 102 from the component 104 by the device 102 comprises detecting a physical separation between the structure of the device 102 and the structure of the external component 104 of the device 102.
[0132] In some embodiments, disabling at least one function of circuit 112 of device 102 comprises powering disabling circuit 504 from internal power source 502 and using disabling circuit 504 to disable at least one function of the circuits of device 102.
[0133] In some embodiments, detecting removal of device 102 from component 104 by device 102 comprises detecting a physical separation between the structure of device 102 and the structure of component 104 external to device 102.
[0134] In some embodiments, the method further comprises installing device 102 on component 104 and activating a tamper-resistant circuit 110 configured to disable at least one function of the circuits of device 102.
[0135] In some embodiments, the method further comprises resetting a tamper-resistant circuit 110 configured to disable at least one function of circuit 112 of device 102.
[0136] Some embodiments include a device comprising means for detecting removal of the device from a component external to the device by the device, and means for disabling at least one function of the circuits of the device in response to detecting removal of the device from the component. Examples of the means for detecting include a tamper-resistant circuit 110, a switch 220, or SW1, etc. Examples of the means for disabling at least one function of the circuits of the device include a tamper-resistant circuit 110, a processor 113, a memory 118, or 808, etc.
[0137] In some embodiments, the device further comprises means for detecting physical separation of the device from a component, and means for erasing at least a portion of the memory of the circuit in response to detecting physical separation of the device 102 from the component. Examples of means for detecting physical separation of the device from a component include a tamper-resistant circuit 110, a switch 220, or SW1, etc. Examples of means for erasing at least a portion of the memory of the circuit include a tamper-resistant circuit 110, a processor 113, a memory 118, or 808, etc.
[0138] Some embodiments include a method comprising receiving, at a second device 804, a request for a system identifier (ID) stored in the second device 804 from a first device 802, determining, by the second device 804, whether the system ID stored in the second device 804 has a null value, and transmitting, by the second device 804, a response based on the system ID stored in the second device 804 to the first device 802 if the system ID stored in the second device 804 does not have a null value.
[0139] In some embodiments, the method further comprises communicating, by the second device 804 to the first device 802, that the system ID stored in the second device 804 has a null value if the system ID stored in the second device 804 has a null value.
[0140] In some embodiments, the method further comprises receiving, by the second device 804 from the first device 802, a system ID, and storing, by the second device 804, the system ID received from the first device 802 as the system ID stored in the second device 804.
[0141] In some embodiments, storing, by the second device 804, the system ID received from the first device 802 as the system ID stored in the second device 804 comprises storing the system ID received from the first device 802 in a one-time write memory 808 by the second device 804.
[0142] In some embodiments, transmitting, by the second device 804, a response based on the system ID stored in the second device 804 to the first device 802 comprises encrypting the system ID stored in the second device 804 and transmitting the encrypted system ID to the first device 802 by the second device 804.
[0143] In some embodiments, the method further comprises transmitting, by the second device 804, a request for the system ID stored in the third device 812 to the third device 812 and receiving, by the second device 804, a response to the request for the system ID stored in the third device 812 from the third device 812.
[0144] In some embodiments, the method further comprises transmitting, by the second device 804, a response based on the response to the request for the system ID stored in the third device 812 to the first device 802.
[0145] In some embodiments, the method further comprises determining, by the third device 812, whether the system ID stored in the third device 812 has a null value and, if the system ID stored in the third device 812 has a null value, communicating, by the third device 812, to the second device 804 that the system ID stored in the third device 812 has a null value.
[0146] In some embodiments, the method further comprises storing, by a third device 812, the system ID received from a second device 804 as the system ID stored in the third device 812.
[0147] In some embodiments, the second device 804 is an authentication device for the X-ray system 800b, and the third device 812 is a control device for the X-ray tube 836 of the X-ray system 800b.
[0148] Some embodiments include transmitting, from a first device 802 to a second device 804, a request for the system identifier (ID) stored in the second device 804; receiving, by the first device 802 from the second device 804, a response to the request for the system ID stored in the second device 804; determining, by the first device 802, whether the system ID stored in the second device 804 is the correct system ID of the system including the second device 804; and operating, by the first device 802, the system including the second device 804 based on whether the system ID stored in the second device 804 is the correct system ID of the system including the second device 804.
[0149] In some embodiments, operating the system including the second device 804 comprises activating countermeasures if the system ID stored in the second device 804 is not the correct system ID of the system including the second device 804.
[0150] In some embodiments, the countermeasures include at least one of disabling the second device 804, disabling the system including the second device 804, and presenting a warning to the user that the system ID stored in the second device 804 and the correct system ID of the system including the second device 804 do not match.
[0151] In some embodiments, operating a system that includes a second device 804 comprises the first device 802 sending a request to verify devices that are subordinate to the second device 804 to the second device 804 if the system ID stored in the second device 804 matches the correct system ID of the system that includes the second device 804.
[0152] In some embodiments, the method further comprises the first device 802 receiving, from the second device 804, a response to the request to verify devices that are subordinate to the second device 804, and operating a system that includes the second device 804 comprises operating the system based on the response to the request to verify at least one device that is subordinate to the second device 804.
[0153] In some embodiments, the second device 804 is an authentication device for the X-ray system 800b, and at least one device that is subordinate to the second device 804 is a control device for the X-ray tube 836 of the X-ray system 800b.
[0154] In some embodiments, the method further comprises the first device 802 sending an authentication request for the second device 804 to the second device 804, and the first device 802 receiving, from the second device 804, a response to the authentication request for the second device 804, and operating a system that includes the second device 804 comprises operating the system that includes the second device 804 based on the response to the authentication request for the second device 804.
[0155] Some embodiments include a device comprising means for receiving, from a first external device, a request for a system identifier (ID) stored in the device, means for determining whether the system ID stored in the device has a null value, and means for transmitting, to the first device, a response based on the system ID stored in the device if the system ID stored in the device does not have a null value. Examples of means for receiving, from a first external device, a request for a system identifier and means for transmitting, to a device, a response based on the system ID include the second device 804, the third device 812, and the like.
[0156] In some embodiments, the device further comprises means for transmitting, to a second external device, a request for a system ID stored in the second external device and means for receiving, from a third device, a response to the request for the system ID stored in the second external device. Examples of means for transmitting, to a second external device, a request for a system ID and means for receiving, from a third device, a response to the request for the system ID include the second device 804, the third device 812, and the like.
[0157] Some embodiments include at least one non-transitory computer-readable storage medium including a plurality of instructions configured to be executed to implement the methods described above.
[0158] The above provided summary is illustrative and is not intended to be limiting in any way. In addition to the examples described above, further aspects, features, and advantages of the present invention will become apparent by reference to the drawings, the following detailed description, and the appended claims.
[0159] The circuitry can include hardware, firmware, program code, executable code, computer instructions, and / or software. The non-transitory computer-readable storage medium can be a computer-readable storage medium that does not include a signal.
[0160] The above-described operations may be implemented in various circuits. For example, although not limited thereto, the operations may be performed as a hardware circuit comprising a custom very large scale integration (VLSI) circuit or a gate array including logic chips, transistors, or other components. The operations may also be performed in a programmable hardware device including, but not limited to, a field programmable gate array (FPGA), a programmable array logic, a programmable logic device, or a similar device.
[0161] References throughout this specification to "example" or "embodiment" mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the invention. Thus, the appearances of the phrases "example" or "embodiment" in various places throughout this specification are not necessarily all referring to the same embodiment.
[0162] Furthermore, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of embodiments of the invention. However, one of ordinary skill in the art will recognize that the invention may be practiced without one or more of the specific details, or with other methods, components, layouts, and the like. In other instances, well-known structures, components, or operations are not shown or described in detail to avoid obscuring aspects of the invention.
[0163] Elements specifically described in means-plus-function format are intended to be construed to cover the corresponding structures, materials, or acts and their equivalents described herein, in accordance with 35 U.S.C. § 112, paragraph 6, if applicable.
[0164] The foregoing examples are illustrative of the principles of the present invention in one or more specific applications, but many changes in form, usage, and details of implementation can be made without departing from the principles and concepts of the present invention and without exercising inventive faculty, as will be apparent to those skilled in the art. Accordingly, it is not intended that the present invention be limited. The various features and advantages of the present invention are set forth in the following claims.
Claims
1. Receiving, at a second device from a first device, a request for a system identifier (system ID) stored on the second device; Determining, by the second device, whether the system ID stored on the second device has a null value, the null value representing a state where no value is stored as the system ID on the second device; If the system ID stored on the second device does not have the null value, transmitting, by the second device, a response based on the system ID stored on the second device to the first device; Determining, by the first device based on the response, whether the system ID stored on the second device is the correct system ID for a system including the second device; A method comprising the above steps.
2. The method according to claim 1, further comprising, when the system ID stored on the second device has the null value, the second device communicating to the first device that the system ID stored on the second device has the null value.
3. In response to the communication that the system ID stored on the second device has the null value, receiving, by the second device, the system ID from the first device; Storing, by the second device, the system ID received from the first device as the system ID stored on the second device; The method according to claim 2, further comprising the above steps.
4. The method according to claim 3, wherein the step of the second device storing the system ID received from the first device as the system ID stored on the second device includes the second device storing the system ID received from the first device in a one-time write memory.
5. The method according to any one of claims 1 to 4, wherein the step of the second device transmitting the response based on the system ID stored on the second device to the first device includes encrypting the system ID stored on the second device and the second device transmitting the encrypted system ID to the first device.
6. The second device transmitting a request for a system ID stored on the third device to the third device; The second device receiving a response to the request for the system ID stored on the third device from the third device; The method according to any one of claims 1 to 5, further comprising.
7. The method according to claim 6, further comprising the second device transmitting a response based on the response to the request for the system ID stored on the third device to the first device.
8. The third device determining whether the system ID stored on the third device has the null value; When the system ID stored on the third device has the null value, the third device communicating to the second device that the system ID stored on the third device has the null value; The method according to claim 6 or 7, further comprising.
9. The method according to claim 8, further comprising the third device storing the system ID received from the second device as the system ID stored on the third device.
10. The second device is an authentication device for an X-ray system, The third device is a control device for an X-ray tube of the X-ray system, The method according to any one of claims 6 to 9.
11. At least one non-transitory machine-readable storage medium comprising a plurality of instructions configured to be executed to implement the method according to any one of claims 1 to 10.
12. The step of the second device determining whether the system ID stored on the second device has the null value includes the second device determining whether the system ID stored on the second device has the null value without comparing the system ID stored on the second device with a valid system ID. The method according to any one of claims 1 to 10.
13. Transmitting a request for a system identifier (system ID) stored on the second device from a first device to a second device; The second device determines whether the system ID stored on the second device has a null value; The first device receives, from the second device, a response to the request for the system ID stored on the second device; The first device determines whether the system ID stored on the second device is the correct system ID for the system including the second device; The first device operates the system including the second device based on whether the system ID stored on the second device is the correct system ID for the system including the second device, the method comprising: The step of operating the system including the second device includes: when the system ID stored on the second device matches the correct system ID for the system including the second device, the first device transmits a request for verification of the system ID stored on one or more devices subordinate to the second device to the second device.
14. The method according to claim 13, wherein the step of operating the system including the second device includes enabling a countermeasure when the system ID stored on the second device is not the correct system ID for the system including the second device.
15. The method according to claim 14, wherein the countermeasure includes at least one of disabling the second device, disabling the system including the second device, and presenting a warning to the user that the system ID stored on the second device does not match the correct system ID for the system including the second device.
16. The first device further comprises receiving, from the second device, a response to the request for verification of a device subordinate to the second device; The step of operating the system including the second device includes operating the system based on the response to the request for verification of at least one device subordinate to the second device. The method according to any one of claims 13 to 15.
17. The second device is an authentication device for an X-ray system, The at least one device subordinate to the second device is a control device for an X-ray tube of the X-ray system, The method according to claim 16.
18. Transmitting a request for authentication of the second device from the first device to the second device; The first device further comprising receiving, from the second device, a response to the request for authentication of the second device; The step of operating the system including the second device includes operating the system including the second device based on the response to the request for authentication of the second device. The method according to any one of claims 13 to 17.
19. A device, comprising: A memory configured to store a system identifier (system ID); A processor, comprising: Receiving a request for the system ID from a first external device; Determining whether the system ID stored on the device has a null value, the null value representing a state where no value is stored as the system ID on the device; Receiving a system ID from the first external device in response to a determination that the system ID has the null value; Transmitting, to the first external device, a response based on the system ID stored on the device when the system ID stored on the device does not have the null value; and A device comprising the processor configured to perform the above steps.
Citation Information
Patent Citations
Data communication system and data communication method
JP1999008625A
Management device and management device program
JP2005352656A
Method for checking component of computer system using radio tag
JP2006268128A
Communication device, communication method of communication device, program, and storage medium
JP2009044575A