Remote communication and control system for robotic intervention treatment

The system addresses remote operation challenges in robotic medical treatment by using PTP for time synchronization and secure communication, ensuring stable and precise control of robotic devices, enhancing the capability for timely interventions.

JP7714719B2Active Publication Date: 2025-07-29SIEMENS HEALTHINEERS ENDOVASCULAR ROBOTICS INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024053334
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-08-20
Filing Date
2024-03-28
Publication Date
2025-07-29
Estimated Expiration
2039-05-17

AI Technical Summary

Technical Problem

Existing robotic medical treatment systems face challenges in allowing remote operation due to network delays, jitter, and the need for secure and stable communication between remote and local sites, particularly in critical procedures like neurovascular interventions and coronary interventions, which require precise control and real-time imaging.

Method used

A system utilizing Precision Time Protocol (PTP) for time synchronization and secure communication tunnels to manage delays and ensure stable control, enabling remote operation of robotic medical devices through control centers connected via a secure network, with reference clocks at both ends for precise timestamping and delay management.

Benefits of technology

Enables secure and stable remote operation of robotic medical devices, reducing transmission delays and ensuring precise control, thus facilitating timely intervention procedures even in remote locations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007714719000005
    Figure 0007714719000005
  • Figure 0007714719000006
    Figure 0007714719000006
  • Figure 0007714719000007
    Figure 0007714719000007
Patent Text Reader

Abstract

To provide a method of using a control center located in a remote site so as to control operation of a robot medical device system located in a local site.SOLUTION: Provided is a method of using a control center 202 located in a remote site so as to control operation of a robot medical device system 204 located in a local site. The method includes transmitting a control signal from the control center to the robot medical device system, determining a delay in the transmission of the control signal, and operating the robot medical device system on the basis of comparison between the delay and a threshold delay value.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This application claims priority to and incorporates by reference in its entirety U.S. Application No. 62 / 719,757, entitled "Remote Communication System and Control System for a Robotic Medical Device", filed on Aug. 20, 2018, and U.S. Application No. 62 / 673,307, entitled "Remote Communication System and Control System for a Robotic Medical Device", filed on May 18, 2018.

[0002] The present invention generally relates to the field of robotic medical treatment systems, and more particularly, to a remote communication and control system for devices used in robotic intervention procedures.

Background Art

[0003] Catheters (and other elongate medical devices) can be used for many minimally invasive medical procedures aimed at the diagnosis and treatment of various vascular diseases, including neurovascular interventions (NVIs), also known as neurointerventional procedures, percutaneous coronary interventions (PCIs), and peripheral vascular interventions (PVIs). These procedures typically involve guiding a guidewire through a vasculature and advancing a working catheter through the guidewire to perform a treatment. A catheterization procedure begins by gaining access to a suitable blood vessel, such as an artery or vein, using a sheath or guiding catheter with standard percutaneous techniques. The sheath or guiding catheter is then advanced via a diagnostic guidewire to a primary location, such as the internal carotid artery for an NVI, the coronary ostium for a PCI, or the superficial femoral artery for a PVI. A guidewire suitable for the vasculature is then guided through the sheath or guiding catheter to a target location within the vasculature. In certain situations, such as a tortuous anatomical structure, a support catheter or microcatheter is inserted via the guidewire to assist in guiding the guidewire. A physician or operator can select a stationary frame to be used as a roadmap for guiding the guidewire or catheter to a target location, such as a lesion, by acquiring a cine via contrast injection using an imaging system (e.g., a fluoroscope). Since contrast images are obtained while the physician delivers the guidewire or catheter device, the physician can confirm that the device is moving along the correct path to the target location. While observing the anatomical structure using fluoroscopy, the physician manipulates the proximal end of the guidewire or catheter and directs the distal tip into the appropriate blood vessel and towards the lesion while avoiding progression into a collateral.

[0004] Robot catheter treatment systems have been developed to assist physicians when performing catheter treatments such as NVI, PCI, and PVI. Examples of neurovascular intervention (NVI) catheter treatments include coil embolization of aneurysms, liquid embolization of arteriovenous malformations, and mechanical thrombectomy of large vessel occlusions in the setting of acute ischemic stroke. In NVI, the physician uses a robotic system to operate a neurovascular guidewire and a microcatheter to gain access to the lesion and perform treatment to restore normal blood flow. This access is enabled by a sheath or guide catheter, but an intermediate catheter may also be required for more distal regions or to obtain proper support for the microcatheter and guidewire. The distal tip of the guidewire is guided into or through the lesion depending on the type of lesion and treatment. For the treatment of aneurysms, the microcatheter is advanced into the lesion, the guidewire is removed, and several coils are deployed through the microcatheter into the aneurysm to embolize the aneurysm. For the treatment of arteriovenous malformations, liquid embolic is injected into the malformation through the microcatheter. Mechanical thrombectomy for treating vascular occlusions can be achieved by aspiration or by using a stent-type embolus retrieval device. Aspiration can be performed directly through the microcatheter or using a large-bore aspiration catheter. Once the aspiration catheter reaches the lesion, negative pressure is applied to remove the thrombus through the catheter. Alternatively, the thrombus may be removed by deploying a stent-type embolus retrieval device through the microcatheter. Once the thrombus is incorporated into the stent-type embolus retrieval device, the thrombus is retrieved by retracting the stent-type embolus retrieval device and the microcatheter into the guide catheter.

[0005] In PCI, the physician uses a robotic system to access the lesion and perform treatment by manipulating a coronary guidewire to restore normal blood flow. This access is made possible by placing a guide catheter at the coronary ostium. The distal tip of the guidewire is guided to pass through the lesion, and due to the complex anatomical structure, a microcatheter is used to properly support the guidewire. Blood flow is restored by delivering and deploying a stent or balloon to the lesion. The lesion requires pretreatment prior to stent implantation. This pretreatment may involve delivering a balloon for pre-dilation of the lesion or performing atherectomy using, for example, a laser or rotational atherectomy catheter and balloon via the guidewire. Imaging and physiological measurements can also be performed by using an imaging catheter or FFR measurement to determine the appropriate treatment.

[0006] In PVI, the physician uses a robotic system to perform treatment and restore blood flow using techniques similar to those in NVI. The distal tip of the guidewire is guided to pass through the lesion, and a microcatheter is used to provide appropriate support to the guidewire for the purpose of the complex anatomical structure. Blood flow is restored by delivering and deploying a stent or balloon to the lesion. Similar to PCI, pretreatment of the lesion and diagnostic imaging can also be used.

[0007] The operator of a robotic system used in medical treatment typically has a location in the same room or an adjacent room as the patient and the robotic system. However, it may be desirable to allow an operator located at a remote location (e.g., a different building, a different city) to operate the robotic system to perform a medical treatment. A system that allows an operator at a remote location to control and operate a robotic medical treatment system, for example, provides access to specialists who may not be available in the local area for patients in a small community. In addition, patients in need of emergency medical treatment can receive treatment at a local hospital by specialists located at a remote location, thus shortening the time until an intervention procedure is performed. For example, it is advantageous to complete an intervention procedure to treat a patient with acute ischemic stroke due to large vessel occlusion (LVO) or to treat a patient with ST-segment elevation myocardial infarction (STEMI) as soon as possible. Various remote surgery systems have been developed for general vascular, cardiac, and urological procedures. For example, remote surgery systems are used for laparoscopic procedures. There are many challenges in the development of a system that allows an operator to perform medical treatment remotely. It is necessary to establish and maintain a secure network connection via a network (e.g., the Internet). Delays and jitter in the transmission of control signals and images affect both the stability of the system and the safety of the treatment. Deadlocks related to the control of the local medical treatment system can occur between the local location and the remote location. There may also be an issue of providing a many-to-many configuration that allows multiple remote locations to connect to and operate a local medical treatment system.

Prior Art Documents

Patent Documents

[0008]

Patent Document 1

Patent Document 2

Patent Document 3

[0009] According to one embodiment, a method of using a control center at a remote site to control the operation of a robotic medical device system at a local site includes transmitting a control signal from the control center to the robotic medical device system, determining a delay in the transmission of the control signal, and operating the robotic medical device system based on a comparison of the delay with a threshold delay value.

[0010] According to other embodiments, a method of using a control center at a remote site to control the operation of an elongate medical device in a robotic medical device system at a local site includes receiving a control signal from the control center, determining a delay in the transmission of the control signal, determining a threshold delay value based on at least one parameter of the robotic medical device system, comparing the delay with the threshold delay value, and adjusting the operation of the elongate medical device based on a comparison of the delay with the threshold delay value.

[0011] According to other embodiments, a method of using a control center at a remote site to control the operation of a robotic medical device system at a local site includes receiving a control signal from the control center, determining a delay in the transmission of the control signal, comparing the delay with a threshold delay value, and adjusting the speed of a medical device of the robotic medical device system based on the delay when the delay is less than the threshold delay value, and setting the speed of the medical device to zero when the delay is greater than the threshold delay value.

[0012] According to other embodiments, a system for controlling a medical device includes a control center located at a remote site. The control center includes a control console and...Connection a first command and control module, and a first clock configured to use the Precision Time Protocol and receive time data from a reference time source, which is coupled to the first command and control module. The system further includes a robotic medical device system at a local site, which communicates with a control center. The robotic medical service system includes at least one medical device, a second command and control module configured to communicate with the first command and control module, and a second clock configured to use the Precision Time Protocol and receive time data from a reference time source, which is coupled to the second command and control module. The control center and the remote medical device communicate via a secure tunnel. The control console of the control center is configured to communicate with and control at least one medical device. Connection a first clock configured to use the Precision Time Protocol and receive time data from a reference time source, which is coupled to the first command and control module. The system further includes a robotic medical device system at a local site, which communicates with a control center. The robotic medical service system includes at least one medical device, a second command and control module configured to communicate with the first command and control module, and a second clock configured to use the Precision Time Protocol and receive time data from a reference time source, which is coupled to the second command and control module. The control center and the remote medical device communicate via a secure tunnel. The control console of the control center is configured to communicate with and control at least one medical device. Connection a second command and control module configured to communicate with the first command and control module, and a second clock configured to use the Precision Time Protocol and receive time data from a reference time source, which is coupled to the second command and control module. Connection a second clock configured to use the Precision Time Protocol and receive time data from a reference time source, which is coupled to the second command and control module. said second The control center and the remote medical device communicate via a secure tunnel. The control console of the control center is configured to communicate with and control at least one medical device. configured to communicate with and control at least one medical device.

[0013] According to other embodiments, a system for managing the control of at least one medical device by a remote site and a local site includes a control center having a location at the remote site, a robotic medical device system at the local site that communicates with the control center, and a virtual control token that determines the control state of the control center and the robotic medical device system. The location of the virtual control token determines the control state.

[0014] According to another embodiment, a method for reducing the bandwidth of data transmission from a robotic medical device system at a local site to a control center at a remote site, the control center being configured to control the operation of the robotic medical device system, includes generating a display of data in the robotic medical device system. This data includes at least one image and non-image patient information. The method further includes selecting a section of the generated display, transmitting the selected section of the display to the control center, and displaying the selected section on a display of the control center. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The present invention will be more fully understood from the following detailed description taken in conjunction with the accompanying drawings in which like reference numerals refer to like elements.

[0016]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Mode for Carrying Out the Invention

[0017] FIG. 1 is a perspective view of a typical catheter treatment system according to an embodiment. In FIG. 1, the catheter treatment system 100 can be used to perform catheter-based medical treatments, such as percutaneous coronary intervention (PCI), neurovascular intervention procedures (e.g., treatment of large vessel occlusion (LVO)), PCI for ST-elevation myocardial infarction, percutaneous intervention procedures such as peripheral vascular intervention procedures, etc. Catheter-based medical treatments can include diagnostic catheter procedures in which one or more catheters (or other elongated medical devices) are used to assist in the diagnosis of a patient's disease. For example, during one embodiment of a catheter-based diagnostic procedure, a contrast agent is injected through the catheter into one or more coronary arteries, and an image of the patient's heart is taken. Catheter-based medical treatments can also include catheter-based treatment procedures (e.g., angioplasty, stent placement, treatment of peripheral vascular diseases, etc.). During such procedures, a catheter (or other elongated medical device) is used to treat the disease. However, it should be noted that those skilled in the art will understand that a given specific percutaneous intervention device or component (e.g., guidewire type, catheter type, etc.) is selected based on the type of procedure being performed. The catheter treatment system 100 can perform any number of catheter-based medical treatments by fine-tuning to adapt to the specific percutaneous intervention device used in the treatment. Specifically, while the embodiments of the catheter treatment system 100 described herein are mainly described in relation to the diagnosis and / or treatment of coronary artery disease, the catheter treatment system 100 can be used to diagnose and / or treat any type of disease or condition suitable for diagnosis and / or treatment via catheter-based procedures.

[0018] The catheter treatment system 100 includes a lab unit 106 and a workstation 116. The catheter treatment system 100 includes a robotic catheter system shown as a bedside system 110, which is disposed adjacent to the patient 102 within the lab unit 106. The patient 102 is supported on a table 108. Generally, the bedside system 110 allows a user to perform catheter-based medical treatments via the robotic system by operating various control devices such as a control device disposed at the workstation 116. Appropriate percutaneous intervention devices or other components (e.g., working catheters such as guidewires, guide catheters, balloon catheters, and stent delivery systems, contrast agents, drugs, diagnostic catheters, etc.) are provided. The bedside system 110 can include any number and / or any combination of components to provide the functionality described herein to the bedside system 110. The bedside system 110 includes, among other things, a robotic arm 112 supported by a drive assembly 111 including. The drive assembly 111 includes a cassette 114 mounted on a robotic drive 113 that can be used to drive an elongate medical device 115 such as a catheter or a guidewire. For example, the drive assembly 111 is used to automatically supply a guidewire into a guide catheter placed in an artery of the patient 102.

[0019] The bedside system 110 communicates with the workstation 116, and signals generated by user input at the workstation 116 can be transmitted to the bedside system 110 to control various functions of the bedside system 110. The bedside system 110 may also supply feedback signals (such as operating conditions, warning signals, error codes, etc.) to the workstation 116. The bedside system 110 may be connected to the workstation 116 via a communication link 140 (shown in FIG. 2), which may be a wireless connection, a cable connection, or any other means capable of causing communication between the workstation 116 and the bedside system 110.

[0020] The workstation 116 is 100 configured to receive user input for operating various components or systems of the catheter treatment system. 126 The user interface includes a control device 118 that allows the user to control the bedside system 110 to perform catheter-based medical procedures. For example, the control device 118 can be configured to cause the bedside system 110 to perform various tasks using various percutaneous intervention devices (such as elongated medical devices) that may be equipped on the bedside system 110 (e.g., advancing, retracting, or rotating a guide wire, advancing, retracting, or rotating a working catheter, advancing, retracting, or rotating a guiding catheter, inflating or deflating a balloon disposed on the catheter, positioning and / or deploying a stent, injecting a contrast agent into the catheter, injecting a drug into the catheter, or performing any other function that can be carried out as part of a catheter-based medical procedure). The drive assembly 111 includes various drive mechanisms that cause movement (such as axial and rotational movement) of components of the bedside system 110 that include percutaneous intervention devices.

[0021] In one embodiment, the control device 118 includes a touch screen 124, one or more joysticks 128, and buttons 130, 132. The joystick 128 can be configured to advance, retreat, or rotate various component percutaneous intervention devices, such as guide wires, guide catheters, or working catheters. The buttons 130, 132 can include, for example, an emergency stop button and a multipliers button. When the emergency stop button is pressed, a relay is triggered and the power supply to the bedside system 110 is cut off. The multipliers button acts to increase or decrease the speed at which the associated component is moved in response to the operation of the control device 118. In one embodiment, the control device 118 can include one or more control devices or icons (not shown) displayed on the touch screen 124 that, when actuated, cause the operation of the components of the catheter treatment system 100. The control device 118 may also include a control device for a balloon and / or stent configured to inflate or deflate the balloon and / or stent. Each control device can include one or more buttons, joysticks, touch screens, etc. desirable for controlling a specific component for which the control device is dedicated. Additionally, the touch screen 124 can display one or more icons (not shown) related to various parts of the control device 118 or various components of the catheter treatment system 100.

[0022] The user interface 126 includes a first monitor (or display) 120 and a second monitor (or display)It may include 122. In other embodiments, the user interface 126 may include one display or more than two displays. The first monitor 120 and the second monitor 122 may be configured to display information or patient-specific data to a user having a location at the workstation 116. For example, the first monitor 120 and the second monitor 122 may be configured to display image data (e.g., X-ray images, MRI images, CT images, ultrasound images, etc.), hemodynamic data (e.g., blood pressure, heart rate, etc.), patient record information (e.g., medical history, age, weight, etc.). In addition, the first monitor 120 and the second monitor 122 may be configured to display procedure-specific information (e.g., procedure time, position of a catheter or guidewire, amount of drug or contrast agent delivered, etc.). The monitors 120 and 122 may be configured to display information regarding the position of a guide catheter. Further, First monitors 120 and Second monitors 122 may be configured to display information providing functions associated with the controller 134 (shown in FIG. 3). In other embodiments, the user interface 126 includes a single screen sized to display one or more of the display components and / or touch screen components described herein.

[0023] The catheter treatment system 100 also includes an imaging system 104 disposed within the lab unit 106. The imaging system 104 can be any medical imaging system that can be used in conjunction with catheter-based medical treatments (e.g., non-digital X-ray, digital X-ray, CT, MRI, ultrasound, etc.). In a typical embodiment, the imaging system 104 is a digital X-ray imaging device that communicates with the workstation 116. In one embodiment, the imaging system 104 may include a C-arm (not shown). Thereby, the imaging system 104 can rotate partially or completely around the patient 102 to acquire images at different angular positions (e.g., sagittal view, caudal view, anteroposterior view, etc.) with respect to the patient 102.

[0024] Imaging system 104 may be configured to capture X-ray images of an appropriate region of patient 102 during a particular procedure. For example, imaging system 104 may be configured to capture one or more X-ray images of the heart to diagnose the condition of the heart. Imaging system 104 may also be configured to capture one or more X-ray images (e.g., real-time images) during a catheter-based medical procedure to assist a user at workstation 116 in properly positioning a guide wire, guide catheter, stent, etc. during the procedure. The single or plural images may be displayed on the first monitor 120 and / or the second monitor 122. In particular, the images can be displayed on the first monitor 120 and / or the second monitor 122 to allow the user to accurately move, for example, the guide catheter to an appropriate position.

[0025] Referring to FIG. 2, a block diagram of a catheter treatment system 100 according to an exemplary embodiment is shown. Catheter treatment system 100 may include a controller 134. Controller 134 may be part of workstation 116 (shown in FIG. 1). Controller 134 may generally be an electronic control unit suitable for providing catheter treatment system 100 with the various functions described herein. For example, controller 134 may be an embedded system, a dedicated circuit, a general-purpose system programmed with the functionality described herein, etc. Controller 134 communicates with one or more bedside systems 110, control device 118, First monitor 120 and Second monitor 122, imaging system 104, and patient sensor 136 (e.g., an electrocardiogram (“ECG”) device, an electroencephalogram (“EEG”) device, a blood pressure monitor, a temperature monitor, a heart rate monitor, a respiratory monitor, etc.). In one embodiment, controller 134 may also communicate with contrast agent injection system 152 and intravascular ultrasound (IVUS) system 154. Controller 134It may also communicate with other medical systems 156, such as, for example, an OCT system, an FFR system, or a suction pump. In various embodiments, the controller 134 is configured to generate control signals based on the interaction between the user and the control device 118 and / or based on information accessible to the controller 134 so as to be able to perform a medical procedure using the catheter treatment system 100. In addition, the controller 134 can communicate with a hospital data management system or hospital network 142, and one or more additional output devices 138 (such as a printer, a disk drive, a CD / DVD writer, etc.).

[0026] Communication between the various components of the catheter treatment system 100 can be achieved via a communication link 140. The communication link 140 may be a dedicated line or a wireless connection. The communication link 140 may represent communication via a network. The catheter treatment system 100 can be connected or configured to include any other system and / or device not explicitly shown. For example, the catheter treatment system 100 can include an image processing engine, a data storage and storage system, an automatic balloon and / or stent inflation system, a drug injection system, a drug tracking and / or recording system, a user log, an encryption system, a system for restricting access to or use of the catheter treatment system 100, etc.

[0027] As described above, the controller 134 communicates with the bedside system 110 and can provide a control signal to the bedside system 110 to control the operation of the motor and drive mechanism used to drive a percutaneous intervention device (such as a guide wire, catheter, etc.). The bedside system 110 can include, for example, a guide wire axial drive mechanism that provides forward and / or backward movement of the guide wire, a working catheter axial drive mechanism that provides forward and / or backward movement of the working catheter, and a guide wire rotational drive mechanism configured to rotate the guide wire about its longitudinal axis. In one embodiment, the various drive mechanisms are housed in a drive assembly 111 (shown in FIG. 1).

[0028] A robotic medical device system, such as the example of the catheter treatment system described above with respect to FIGS. 1 and 2, is remotely controlled. FIG. 3 is a block diagram of a communication and control system of a robotic medical device system according to an embodiment. The communication and control system 10 includes a control center 12 at a remote site or a local site, and includes a robotic medical device system 14 at a local site or a local location. As used herein, the local site is the location of the robotic medical device system and the patient or subject, and the remote site is the location of the operator (e.g., a doctor) and the control center used to remotely control the robotic medical device system. The control center 12 and the robotic medical device system 14 communicate via a network 16 such as the Internet. In one embodiment, the remote site and the local site are separated from each other, for example, different rooms in the same building, different buildings in the same city, different cities, or other different locations where the remote site does not have physical access to the robotic medical device system or the patient at the local site. The control center 12 and the robotic medical device system 14 communicate via the network 16 (e.g., data, images, instructions, and control signals). An operator at the remote site can use the control center 12 to control and operate the robotic medical device system 14 at the local site to perform a medical treatment. In one embodiment, a number of control centers 12 can communicate with one robotic medical device system 14 via the network 16, and each control center 12 can be used to control the robotic medical device system 14 from a separate location. In other embodiments, a number of control centers 12 can communicate with a number of robotic medical device systems 14 via the network 16, and each control center 12 can be used to control each of the robotic medical device systems 14.

[0029] The robotic medical device system 14 may be, for example, a catheter treatment system or other medical device system that can be robotically controlled to perform a treatment. In one embodiment, the network 16 is a secure network such as, for example, a virtual private network. The control center 12 may include, for example, a workstation having a user interface. In one embodiment, the control center 12 includes a user interface similar to the user interface provided in the robotic medical device system 14. For example, if the robotic medical device system 14 is a catheter treatment system such as the system described above with respect to FIGS. 1 and 2, the control center 12 may include a workstation having a user interface and a control device similar to the workstation 116, the user interface 126, and the control device 118 of the catheter treatment system 100. In other embodiments, the control center 12 includes a workstation or user interface that is part of a robotic medical device system at a remote site. The control center 12 is configured to allow an operator to operate various components of the robotic medical device system 14 from a remote site. Data, images, and information such as commands and control signals are transmitted from the control center 12 to the robotic medical device system 14 via the network 16, and information such as data and images is transmitted from the robotic medical device system 14 to the control center 12 via the network 16.

[0030] Figure 4 is a block diagram of a communication and control system of a robotic medical device system according to an embodiment. The communication and control system 200 includes a control center 202 at a remote site and a robotic medical device system 204 at a local site. The control center 202 and the robotic medical device system 204 communicate via a network 206. In one embodiment, the network 206 is a secure network in which a remote firewall 208 is established within the control center 202 and a local firewall 210 is established within the robotic medical device system 204. For example, the network 206 may be a virtual private network (VPN). The network 206 is configured to transmit and receive data, images, and command and control signals. As shown in FIG. 4 Communication and control system in 200, one control center 202 and one robotic medical device system 204 are shown. In one embodiment, a number of control centers 202 may communicate with one robotic medical device system 204 via the network 206, and each control center 202 may use the robotic system 204 within the robotic medical device system 245 to control one or more medical devices 246 from separate locations. The robotic system 245 may be, for example, a robotic arm, a robotic drive, and / or other robotic devices that can be used to drive the medical device. In one embodiment where the robotic medical device system is a catheter system, the robotic system 245 may be the robotic arm 112 and the drive assembly 111 described above with respect to FIG. 1. In other embodiments, a number of control centers 20 may communicate with a number of robotic medical device systems 204 via the network 206. Here, each control center 202 may use the robotic system 245 in each robotic medical device system 204 to control one or more medical devices 246 as appropriate.

[0031] The control center 202 also includes a remote command and control module 212 and a remote controller 216 that are coupled to and communicate with a remote firewall 208 . In one embodiment, the remote firewall 208, the remote command and control module 212, and the remote controller 216 are implemented on separate hardware (e.g., a computer system). In other embodiments, the remote firewall 208, the remote command and control module 212, and the remote controller 216 are implemented as separate software components or logical subsystem components within the same computer system. The software components or logical subsystem components can be achieved, for example, using a microkernel, a virtual machine, or a conventional operating system with real-time extensions. In other embodiments, the remote controller 216 and the remote firewall 208 may be implemented as software programs executed on the remote command and control module 212. The remote command and control module 212 receives commands and control signals from the of control console 236. The control console 236 is configured to receive user input from an operator at a remote site for the operation of the robotic medical device system 204 and other systems and devices at a local site. For example, the control console 236 can include a display and control devices such as a touch screen, one or more joysticks, and buttons. The 202 in the control center Display 240 is coupled to the remote command and control module 212 and can be used to display data and images received from the robotic medical device system 204. The remote command and control module 212 can be configured to decompress images received from the robotic medical device system 204.

[0032] The remote command and control module 212 is also coupled to a time synchronization reference clock, such as a remote reference clock 220, and receives time information from the remote reference clock 220. The remote reference clock 220 can be, for example, a grandmaster clock. As further described below, the time information can be used to calculate the delay in the transmission of signals and data (such as command and control signals, and images) between the remote site and the local site. The remote reference clock 220 is coupled to an antenna 232 to receive time information from an external time source, such as a satellite-based time source or an external network, and provide timestamp information to the remote command and control module 212. In one embodiment, the time information is provided from a Global Positioning System (GPS). In other embodiments, the time information is provided from a Satellite Time and Location (STL) system. The remote switch 224 may be coupled to the remote reference clock 220. In one embodiment, the remote reference clock 220, the remote switch 224, and the remote command and control module 212 use a Precision Time Protocol (PTP) network. The remote command and control module 212 uses the timestamp information from the remote reference clock 220 to timestamp the commands and control signals received from the control console 236. The timestamped commands and control signals are transmitted via the network 206 to the local command and control module 204 in the robotic medical device system 214It is transmitted thereto. The local command and control module 214 is configured to provide its commands and control signals via the network 206 to, for example, the robot system 245 in the robotic medical device system 204 to control the operation of the medical device 246. The time stamp provided by the remote command and control module 212 to the commands and control signals based on the information from the remote reference clock 220 is used to monitor and control the delay in the transmission of the commands and control signals via the network 206 during the medical procedure performed using the medical device 246. The local command and control module 214 determines the delay when receiving the commands and control signals from the control center 202 based on the time stamp, and is configured to take appropriate actions based on the amount of the delay, as will be described later with respect to FIG. 5.

[0033] The local command and control module 214 and the local controller 218 are coupled to and communicate with the local firewall 210. In one embodiment, the local firewall 210, the local command and control module 214, and the local controller 218 are implemented on separate hardware (e.g., a computer system). In other embodiments, the local firewall 210, the local command and control module 214, and the local controller 218 are implemented as separate software components or logical subsystem components on the same computer system. The software components or logical subsystem components can be achieved using, for example, a microkernel, a virtual machine, or a conventional operating system with real-time extensions. In other embodiments, the local controller 218 and the local firewall 210 may be implemented as software programs executed on the local command and control module 214. The local command and control module 214 also... ofIt may receive commands and control signals from the control console 238. The control console 238 is configured to receive user input from an operator at the local site for the operation of the robotic medical device system 204 at the local site. For example, the control console 238 may include a display and control devices such as a touch screen, one or more joysticks, and buttons. The display 241 is coupled to the local command and control module 214 and may be used to display data and images. The local command and control module 214 also receives images from the imaging system 248 and hemodynamic data from the patient sensor 250. In one embodiment where the robotic medical device system 204 is the catheter treatment system described above with respect to FIGS. 2 and 3, the local controller 218 may be First and second monitors coupled to 120, 122, or the touch screen 124. Images from the imaging system 248 may be captured and scaled using the first video capture and scaling device 242, and hemodynamic data may be captured and scaled using the second video capture and scaling device 244. The local command and control module 214 may be configured to compress the image data before transmitting it to the control center 202, and the local controller 218 may be configured to compress the hemodynamic data before transmitting it to the control center 202. In other embodiments, the local command and control module 214 is coupled to an intravascular ultrasound (IVUS) system 254 and receives data from this IVUS system 254. The data from the IVUS system 254 is transmitted to the control center 202.

[0034] The local command and control module 214 is also coupled to a time synchronization reference clock, such as the local reference clock 226, to receive time information from the local reference clock 226. The local reference clock may be, for example, a grandmaster clock. The time information can be used to calculate the delay in the transmission of signals and data (e.g., commands and control signals, and images) between the remote site and the local site. The local reference clock 226 is coupled to an antenna 234 to receive time information from an external time source, such as a satellite-based time source, and provide timestamp information to the local command and control module 214. In one embodiment, the time information is provided from a Global Positioning System (GPS). In other embodiments, the time information is provided from a Satellite Time and Location (STL) system. The local switch 230 may be coupled to the local reference clock 226. In one embodiment, the local reference clock 226, the local switch 230, and the local command and control module 212 use a Precision Time Protocol network. The local command and control module 214 uses the timestamp information from the local reference clock 226 to timestamp the image data received from the first video capture and scaling device 242. In other embodiments, the local controller 218 uses the timestamp information from the local reference clock 226 to timestamp the hemodynamic data received from the second video capture and scaling device 244. The timestamped image and hemodynamic data can be transmitted via the network 206 to the remote command and control module 202 at the control center 212 The remote command and control module 212 is configured to provide the image to a display 202 at the control center 240 and provide the hemodynamic data to the display 240 or another display at the control center 202. The local command and control module 226 based on information from the local reference clock 214The timestamps applied to the image and hemodynamic data may be used to monitor and control delays in the transmission of the image and hemodynamic data via the network 206 during a medical procedure executed using the control center 202 to control the robot system 245 and the medical device 246. Based on the delays in the transmission of the image and / or hemodynamic data, Communication and control system various components of 200, or system control passing between the control center 202 and the robotic medical device system 204, may be paused or suspended.

[0035] As described above, the control center 202 includes a remote reference clock 220 that can use the Precision Time Protocol, and the robotic medical device system 204 includes a local reference clock 226 that can use the Precision Time Protocol. The remote reference clock 220 and the local reference clock 226 can communicate with a common external time source, such as a satellite-based time source like GPS or STL, to receive time information. Advantageously, in this embodiment, the control center 202 and the robotic medical device system 204 communicate via a secure tunnel over a network 206 (e.g., the Internet), making it possible to calculate command delays and round-trip delays to ensure safe and secure operation. Each site uses a dedicated reference clock (e.g., reference clocks 220, 226 respectively) and an independent Ethernet (registered trademark) network for time synchronization. In this embodiment, either NTP (Network Time Protocol) or PTP may be used for synchronization purposes. However, a PTP network may allow better synchronization than NTP. Another advantage of using a dedicated reference clock at each site on a separate network is to eliminate the attack surface for network attacks targeting time references accessible on the Internet. Such vulnerabilities include, but are not limited to, denial-of-service (DoS) that renders the GMC inoperable, and stack overflows that place the command and control modules under the attacker's control. As will be further described below with reference to FIG. 16, in one embodiment, a firewall can be used to establish an IPSec encrypted tunnel with dedicated hardware between two nodes with private keys for the purpose of high-level security and minimal delay impact on communication.

[0036] In other embodiments, the control center 202 and the robotic medical device system 204 may not include their own reference clocks. Rather, the control center 202 and the robotic medical device system 204 are configured to utilize NTP and communicate with a single network grandmaster clock to receive time information. As described above, the time information can be used to generate time stamps for commands and control signals as well as other data (e.g., images and hemodynamic data). In one embodiment, the time stamp is provided by a common time source (e.g., GPS or STL) to determine the delay in the transmission of the sum of a plurality of commands and control signals. In other embodiments, the time stamp is provided by a single time source (e.g., the master clock of the network or an internal clock) to determine the delay in the transmission of the sum of a plurality of commands and control signals. In this embodiment, a time stamp from a "remote" site is used, and then when this time stamp is received as returning from an image transmission from a "local" site, the round-trip delay of the commands and control signals as well as the image is calculated.

[0037] As described above, the control center 202 may be used by an operator at a remote site to operate and control the robotic medical device system 204 and other systems and devices at the local site. In one embodiment, the control center 202 can provide commands and control signals to the imaging system 248 or Contrast agent injection system 252 via the network 206. For example, the control center 202 can be used to control image capture by the imaging system 248. In another example, the control center 202 can be used to control the injection of a contrast agent by the contrast agent injection system 252. In another example, the control center 202 can be used to control the operation of a suction pump or the deployment of a stent type occluder retriever.

[0038] The control center 202 includes a telepresence module 260, and the robotic medical device system 204 includes a telepresence module 262. The telepresence modules 260, 262 are each configured to provide audio and video communication (e.g., telepresence, videoconferencing) between an operator at a remote site and a user or local staff at a local site. In one embodiment, as shown in FIG. 4, the telepresence modules 260, 262 are stand-alone modules and may be coupled to the remote firewall 208 and the local firewall 210, respectively. In other embodiments, the elements of the telepresence modules 260, 262 may be software programs executed at each of the remote controller 216 or the local controller 218. The telepresence modules 260 and 262 may include, for example, a video camera, a monitor, a speaker, and a microphone. In one embodiment, a videoconference can be established between the telepresence module 260 at the remote site and the telepresence module 262 at the local site. As a result, the robotic system 245 at the local site is used to operate the medical device 246 An operator at a remote site who utilizes the control center 202 to operate the medical device can view the treatment room and the device when the treatment is being performed and communicate with the personnel (e.g., technicians, doctors, etc.) who support the treatment at the local site via audio and video. In one embodiment, by using a dedicated audio and video communication system that establishes secure communication via a computer network (e.g., a cloud network), audio and video communication can be established between the telepresence module 260 at the remote site and the telepresence module 262 at the local site. This is possible. For example, the telepresence module 260 at the remote site may be configured to transmit audio (e.g., speech) and video from the remote site in an encrypted format (e.g., SRTP / AES-128) and to receive and decrypt audio (e.g., speech) and video from the telepresence module 262 at the local site. The telepresence module 262 at the local site may be configured to transmit audio (e.g., speech) and video from the local site in an encrypted format (e.g., SRTP / AES-128) and to receive and decrypt audio (e.g., speech) and video from the telepresence module 260 at the remote site. Signaling and routing between the telepresence module 260 and the telepresence module 262 can be established using a cloud network. In one embodiment, the encrypted audio and video data may be transmitted between the remote firewall 208 and the local firewall 210 without further encryption (e.g., the audio and video data may be whitelisted).

[0039] FIG. 5 shows a method for controlling the operation of a robotic medical device system according to an embodiment. Referring to FIGS. 4 and 5, at block 302, commands and control signals are received from a control center 202 at a remote site by, for example, a local command and control module 214 at a local site. At block 304, a delay in the reception of the commands and control signals is determined based on timestamp information by, for example, the local command and control module 214. At block 306, the delay is compared to a threshold value. In one embodiment, the threshold value is a predefined value based on, for example, a value perceptible to the user such as 250 ms. In other embodiments described further below, the threshold value is determined at block 316 based on at least one parameter of the robotic medical device system, for example, a procedure performed by the robotic medical device system, a patient's anatomical structure, a type of medical device, and a location of the medical device. If the delay is greater than the threshold value at block 308, a corrective action may be performed at block 314. In one embodiment, Robotic medical device systemThe medical device 246 of 204 and other components can be paused or stopped. In one example of pausing, if the delay is greater than a threshold and then the delay falls below the threshold, the device or component is paused. Then, once the delay exceeds the threshold, movement can resume. In another example, if the delay is too large, the movement of the device or component can be paused until the delay is small enough to resume operation. In other embodiments, the speed or velocity of the components of the robotic medical device system (e.g., while moving forward, backward, or rotating) can be reduced. If the network connection is lost, or if the speed of the network 206 becomes slower than a predetermined speed, the control center 202 may return the control of the robotic system 245 and the medical device 246 to the robotic medical device system 204. Also, an emergency stop device may be provided so that a user at the local site can stop emergency treatment. In one embodiment, the threshold is a range of thresholds. When the control center 202 has control of the robotic system 245 and the medical device 246 and the delay of the command and control signal is greater than a first threshold but less than a second threshold, the control console 236 of the control center 202 (e.g., a joystick) may be disabled, but the control console 236 maintains control of the robotic system 245 and the medical device 246. When the control center 202 has control of the robotic system 245 and the medical device 246 and the delay of the command and control signal is greater than the second threshold, the control center 202 may be disabled.

[0040] In block 308, when the control center 202 has control of the robotic system 245 and the medical device 246 if the delay of the command and control signal is less than the threshold, the control console 236 of the control center 202 is used to control and operate the robotic medical device system 204 including the robotic system 245 and the medical device 246 in block 310. BlockIn 312, the speed of the medical device 246 when being controlled by the control center 202 can be adjusted based on the delay of the command and control signal. The control center 202 has control over the robot system 245 and the medical device 246, and when the delay (t delay ) of the command and control signal is less than a predetermined amount (t predetermined ) but greater than zero, the speed (v command ) commanded from the command and control signal received from the control console 236 (e.g., joystick) is scaled such that as the delay increases towards the predetermined amount Medical device the speed (v device ) of 246 decreases. Medical device The speed is given as follows. [Equation (1)] JPEG0007714719000001.jpg10168For example, when the delay t delay is equal to half of the predetermined amount t predetermined , the speed v device of the device becomes half of the commanded speed v command . As the delay t delay increases Medical device slowing down 246 can be used, for example, to ensure system stability and mitigate the risks associated with device control, Medical device such as to avoid excessive forward or backward movement of delay . When the delay t predetermined is greater than the predetermined amount t Medical device the speed v device of Medical device 246 becomes zero and Medical device the movement of 246 stops (block 314). In other embodiments, device the speed v delay of can be adjusted based on the total network delay. The total network delay includes the delay t imagedelay of the command and control signal, and the delay t [Equation (2)] JPEG0007714719000002.jpg10170The total network delay ttotal =(t delay +t imagedelay ) based on Medical device the command speed (v command ), stable operation and robust performance for the position control of Medical device can be ensured. Various embodiments for scaling the above command speed can be tuned to ensure stability regardless of any total delay. If the delay is unknown, instability may occur if the delay is too large. The frequency response of the open-loop system under a fixed total delay is given as follows. [Equation (3)] JPEG0007714719000003.jpg11165 From the Nyquist stability criterion, to ensure stability for direct proportional feedback, the total network delay should satisfy the following constraint, i.e., t total ≤ π / 2 seconds. Using the scaling of Equation (2) above, when t predetermined = π / 2, the following frequency response is obtained. [Equation (4)] JPEG0007714719000004.jpg15168 In other embodiments, other optimal values for t predetermined may be calculated and used in the scaling of Equation (2). From Equation (4), since the gain margin is now infinite for direct proportional feedback, stability for proportional direct feedback can be ensured. To ensure stability, other methods may also be used in a similar manner with knowledge of the feedback delay. Medical deviceSimilar to the case of using velocity commands to control the position, an example of an approach that uses wave variables to ensure stability without knowledge of feedback delay is described in "Design of Networked Control Systems Using Passivity," N. Kottenstette, J. F. Hall, X. Koutsoukos, J. Sztipanovits and P. Antsaklis, IEEE Transactions on Control Systems Technology, vol. 21, no. 3, pp. 649-665, May 2013, the entire content of which is incorporated herein by reference.

[0041] As described above, in block 316, the delay threshold can be determined based on at least one parameter of the robotic medical device system 204. This parameter includes, for example, that a treatment is to be performed by the robotic medical device system. For example, the robotic medical device system 204 may be a catheter treatment system that controls the movement and operation of an elongate medical device (such as a catheter, guide wire, balloon catheter, microcatheter, etc.). The allowable amount of delay can vary depending on various parameters of the catheter treatment system. The delay threshold (i.e., the allowable amount of delay) is based on, for example, the type of treatment being performed, the patient's anatomical structure, the type of elongate medical device (such as a catheter, balloon catheter, guide catheter, guide wire, microcatheter), the location of the elongate medical device, the distance between the elongate medical device (such as the tip or distal end of the device) and the target location, or the type of movement being performed by the elongate medical device (such as forward, rotation, backward). For example, if the elongate medical device (such as the tip of the elongate medical device) is further away from the target location, if the elongate medical device is being retracted, or if the elongate medical device is a device that moves on a wire (such as a microcatheter or balloon catheter) or a guide wire, a longer delay may be tolerated.

[0042] In one embodiment, the remote controller 216 (shown in FIG. 4) and the local controller 218 (shown in FIG. 4) each generate and display a similar graphical user interface. FIG. 6 shows a typical graphical user interface for a control center according to one embodiment, and FIG. 7 shows a typical graphical user interface for a robotic medical device system according to one embodiment. In FIGS. 6 and 7, the illustrated graphical user interfaces 460, 462 are for the purpose of controlling a typical catheter treatment system. The graphical user interfaces 460 for the control center and 462 for the robotic medical device system are configured to indicate, for example, the same measurements, speeds, stored set values, and which controls of the control console are operative at the active site (i.e., either the control center at the remote site or the robotic medical device system at the local site). Each graphical user interface 460, 462 displays an image delay 464, 466 transmitted from the robotic medical device system to the control console and a command and control signal delay 468, 470 from the control center to the robotic medical device system.

[0043] As described above with respect to FIG. 4, the display 240 of the control center 202 can be used to display data and images received from the robotic medical device system 204 via the network 206. FIG. 8 shows a typical display of data and images for a robotic medical device system according to one embodiment. The display 500 includes data and images captured in the robotic medical device system 204, such as hemodynamic data 502, a reference image 506, and a live image 508, related to the operation of the robotic medical device to perform a procedure. Specifically, in the embodiment shown in FIG. 8, the data and images relate to a catheter procedure. The robotic medical device system 204 is for sending to a control center at a remote site 202 a display 500It may be configured to select a region of interest or area. Thus, the display 500 may be cropped so that, for example, the hemodynamic data 502, the reference image 506, and the live image 508 are transmitted separately. The region of interest or area selected may have any shape to capture the desired information for transmission. By cropping the display 500, the bandwidth required to transmit the images and data can be reduced. FIG. 9 shows a typical display for a control center of a remote site having a selected region of interest including hemodynamic data according to one embodiment. In FIG. 9, the display 600 includes hemodynamic data received from the robotic medical device system 204. In other embodiments, the remote controller 216 and the display 240 may be configured to allow an operator to selectively circularly buffer live image data (e.g., fluoroscopic image data for a catheter procedure) up to a predetermined time (e.g., 10 seconds), as shown in FIG. 10. For example, the user may activate controls to start the capture and create a circular buffer for a predetermined time for playback. In the embodiment shown in FIG. 10, the playback image shown on the display 700 is scaled to the same scale as the live image 704. Reconstructed image 702 may be in real time at a predetermined number of frames per second. In one embodiment, the operator is provided with controls that allow the playback image 702 to be paused, fast-forwarded, and rewound. The playback image may be used, for example, to facilitate the generation of a roadmap and capture the progress of the case.

[0044] In other embodiments, the display of an image at a remote site (e.g., on display 240 shown in FIG. 4) may be configured to display an image delay time, as well as command and control signal delay times, as shown in FIG. 14. In FIG. 14, display 1100 includes a reproduced image 1102 and a live image 1104. The display of the live image includes the display of a delay 1106 of an image transmitted from the robotic medical device system to the control console and a delay 1108 of commands and control signals from the control center to the robotic medical device system. In other embodiments, the display of an image at a remote site (e.g., on display 240 shown in FIG. 4) may be configured to display a total delay, as shown in FIG. 15. The total delay is the sum of the image delay time and the command and control signal delay time. In FIG. 15, display 1200 includes a reproduced image 1202 and a live image 1204, and this live image may include additional live information regarding the procedure, such as the total delay and frame rate of an image acquired by an imaging system associated with robotic medical device system 204 at the local site. In one embodiment, the reproduced image 1202 may be scrolled to the region of interest after the image is captured. The display of the live image 1204 includes the display of a total delay 1206 and a frame rate 1208. The frame rate 1208 may be calculated with respect to the number of received frames per second. The total delay 1206 and the frame rate 1208 may be updated in real time and / or filtered to an appropriate bandwidth to improve the viewer's perception of these values.

[0045] As described above with respect to FIG. 4, the communication and control system 200 is configured such that an operator (e.g., a physician) at a remote site can control and operate the robotic medical device system 204 at the local site. Communication and control system200 is also configured to enable an operator at a local site to control and operate the robotic medical device system 204. The control management process is provided to manage whether the control center 202 or the robotic medical device system 204 has control of the robotic system 245 and the medical device 246. The control management system is configured to prevent, for example, a deadlock between a remote site and a local site. In one embodiment, a control token is used to determine whether the control center 202 or the robotic medical device system 204 has control of the actions to perform a treatment. The control token is a virtual token implemented in software. The system that owns the control token (e.g., either the control center 202 or the robotic medical device system 204) is given control of the robotic system 245 and the medical device 246 of the robotic medical device system 204, and the other systems are disabled and prevented from controlling the robotic system 245 and the medical device 246. In a first state, the control token is "free" and can be acquired by either the control center 202 or the robotic medical device system 204. FIG. 11 shows a typical user interface when neither the control center nor the robotic medical device system according to one embodiment is controlling a robotic medical device. The illustrated graphical user interfaces 802, 804 are for the purpose of controlling a typical catheter treatment system (e.g., the catheter treatment system 100 shown in FIGS. 2 and 3). When the control token is "free", the robotic medical device system is in a state without a control token, and this robotic medical device system can obtain control by activating, for example, the "All Enabled" button in the graphical user interface 802 for the robotic medical device system to acquire the control token. The control center is also without a control token and can obtain control, for example, by activating the "RCL Disabled" button for the robotic medical device system in the graphical user interface 804 for the control center.In one embodiment, the "All Enabled" button of the graphical user interface 804 may be indicated with a background or color indicating that the control center has no control. For example, the text and background of the button may be grayed out.

[0046] In the second state, the control token is acquired by the robotic medical device system 204. FIG. 12 shows a typical user interface when the robotic medical device system controls a robotic medical device according to one embodiment. The illustrated graphical user interfaces 902, 904 are for the control of a typical catheter treatment system (e.g., the catheter treatment system 100 shown in FIGS. 2 and 3). When the control token is received by the robotic medical device system, the robotic medical device system is given control and can be used to operate the robotic medical device. In FIG. 12, when the robotic medical device system obtains control by the control token, the "All Enabled" button is disabled and changed to "All Disabled" in the graphical user interface 902 for the robotic medical device system. The operator can "free" the control token by activating the "All Disabled" button. In the graphical user interface 904 for the control center, the "Disabled" button for the robotic medical device system is disabled. In one embodiment, the "All Enabled" button and the "RCL Enabled" button of the graphical user interface 904 may be indicated with a background or color indicating that the control center has no control. For example, the text and background of the button may be grayed out.

[0047] In the third state, the control token is received by the control center 202. FIG. 13 shows a typical user interface when the control center controls a robotic medical device according to one embodiment. The illustrated graphical user interfaces 1002, 1004 are for the control of a typical catheter treatment system (e.g., the catheter treatment system 100 shown in FIGS. 2 and 3). When the control token is received by the control center, the control center is given control and can be used to operate the robotic medical device. In FIG. 13, when the control center obtains control by the control token, the "All Enabled" button is enabled in the graphical user interface 1004 for the control center. In addition, "RCL Disabled" in the graphical user interface 1004 for the control center is enabled. In one embodiment, the "RCL Disabled" button of the graphical user interface 1004 may be indicated by a highlight, background, or color indicating that the control center has control. For example, the graphical user interface 1004 is shown with an underline under "RCL Disabled". In other embodiments, the "RCL Disabled" button is indicated by a color such as green. In the graphical user interface 1002 for the robotic medical device system, when the "All Enabled" button is disabled, the robotic medical device system cannot receive the control token. In one embodiment, the "All Enabled" button of the graphical user interface 1002 may be indicated by a background or color indicating that the robotic medical device system has no control, for example, by graying out the button text and background.

[0048] In one embodiment, in the second and third states where one of the control center or the robotic medical device system has a control token, a site without a control token may have a request token or a mandatory request token. The request token or the mandatory request token is a virtual token implemented in software. The request token and the mandatory request token can be used to request control or to enforce a change in control. For example, when the control center has a control token, the robotic medical device system can send a request token to the control center to request that the control token be made "free" so that the robotic medical device system can receive the control token. In response to receiving the request token, the control center can, for example, make the control token "free", choose to hold the control token or a timeout, and be able to hold the control token. In another example, when the control center has a control token, the robotic medical device system can send a mandatory request token to the control center to request that the control token be made "free" so that the robotic medical device system can acquire the control token. In response to the mandatory request token, the control center can, for example, make the control token "free", choose to hold the control token or a timeout, and be able to release the control token.

[0049] As described above with respect to FIGS. 3 and 4, a number of control centers 202 may communicate with a number of robotic medical device systems 204 via a network 206 (e.g., a many-to-many configuration). FIG. 16 is a block diagram of a many-to-many configuration of a number of control centers and a number of robotic medical device systems according to one embodiment. In FIG. 16, a first control center 1302, a second control center 1304, a first robotic medical device system 1306, and a second robotic medical device system 1308 are communicating via a network 1350. In one embodiment, each site (i.e., the first control center 1302, SecondControl Center 1304, the first robotic medical device system 1306, and Second the robotic medical device system 1308) may be in different locations and may be separated from each other. The first control center 1302 is at the first remote site, the second control center 1304 is at the second remote site, the first robotic medical device system 1306 is at the first local site, and the second robotic medical device system 1308 is at the second local site. The first control center 1302 can be used to control either the first robotic medical device system 1306 or the second robotic medical device system 1308. The second control center 1304 can be used to control either the first robotic medical device system 1306 or the second robotic medical device system 1308. The first control center 1302 includes the first remote firewall 1310, the second control center 1304 includes the second remote firewall 1312, the first robotic medical device system 1306 includes the first local firewall 1314, and the second robotic medical device system 1308 includes the second local firewall 1316. The first remote firewall 1310 is Connection connected to the first remote controller 1318, the second remote firewall 1312 is Connection connected to the second remote controller 1320, the first local firewall 1314 is Connection connected to the first local controller 1322, and the second local firewall 1316 is Connection connected to the second local controller 1324. The first remote firewall 1310 includes a LAN port 1334 and a WAN port 1336. The second remote firewall 1312 includes a LAN port 1332 and a WAN port 1330. The first local firewall 1314 includes a LAN port 1340 and a WAN port 1338. The second local firewall 1316 includes a LAN port 1326 and a WAN port 1328.

[0050] Firewalls 1310, 1312, 1314, and 1316 are configured to establish and disconnect secure connections with other sites. Preferably, the control and management of establishing and disconnecting secure connections are automatically handled by each firewall, maintaining separation from other hardware and software functions at each site. In one embodiment, the command line interface (CLI) and Secure Shell (SSH) protocol are used to establish a secure connection between two sites. In this embodiment, each firewall 1310, 1312, 1314, and 1316 has a unique static IP address. The following description describes establishing a secure connection between the second control center 1304 and the second robotic medical device system 1308, but the methods described herein can be used to establish and disconnect connections between any combination of multiple sites in a multi-to-multi configuration. In one embodiment, a centralized approach is used. In the centralized approach, the WAN port of the second control center 1304 and the WAN port of the second robotic medical device system 1330 are opened for SSH login. In this configuration, either site (e.g., the second control center 1304 and the second robotic medical device system 1308) can create a tunnel through the LAN port of its local firewall and the WAN port of the other site. For example, the second local controller of the second robotic medical device system 1308 can connect to the local LAN port of the second local firewall 1328 via SSH, and the second local controller 1324 can connect to the WAN port of the second remote firewall 1312 of the second control center 1308 1324 1316 1326 1304 1330 ​​​​​It is possible to establish a tunnel by connecting via SSH. In another example of a centralized approach, a second remote controller 1320 of a second control center 1304 can make an SSH connection to a WAN port 1328 of a second local firewall 1316 of a second robotic medical device system 1308, and the second remote controller 1320 of the second control center 1304 can make an SSH connection to a local LAN port 1332 of a second remote firewall 1312. In other embodiments, a distributed approach is used. In the distributed approach, the WAN port 1330 of the second control center 1304 and the WAN port 1328 of the second robotic medical device system 1308 do not permit SSH logins. In this embodiment, each site can establish a corresponding tunnel connection via the LAN port of its respective local firewall so that the WAN port can remain closed to SSH logins to enhance security. For example, a second local controller 1324 can make an SSH connection to the LAN port 1326, and the second remote controller 1320 can make an SSH connection to the LAN port 1332.

[0051] In other embodiments, a secure connection can be established using patch panel direct routing where physical direct wiring is used between all sites (or nodes) on a patch panel. If a connection to a particular site is needed, the connected port can be switched. In still other embodiments, a secure connection can be established by using two static IP addresses for all sites (or nodes). The same two static IP addresses are reserved in the routers of all sites. Only one site is plugged into (by the user) the system when it is being used and unplugged from the Ethernet port (by the user) when it is not being used. In other embodiments, a secure connection can be established by using the same static IP address for all sites (or nodes). The static IP address and Ethernet port mapping can be manually reset on the router.

[0052] In other embodiments, the secure tunnel established between the two firewalls is a secure virtual private network such as, for example, an IPSec tunnel. To establish an IPSec tunnel, in one example, the first control center 1302 and the first robotic medical device system 1306 have a shared key. The first local firewall 1314 of the first robotic medical device system 1306 establishes a tunnel towards the first remote firewall 1310 of the first control center 1302. Thereafter, the first remote firewall 1310 establishes a tunnel towards the first local firewall 1314. In this example, neither site opens a WAN port to accept SSH logins. In other examples, to establish an IPSec tunnel, the first local firewall 1314 permits an SSH logon. The first remote firewall 1310 logs on to the first local firewall 1314 using SSH. Thereafter, the first remote firewall 1310 establishes the first local firewall 1314 at the end of the tunnel towards the first remote firewall 1310. The first remote firewall 1310 directs the tunnel towards the first local firewall 1314. Thereafter, the first remote firewall 1310 can determine the keys for both sites. In one embodiment, there is a priori network topology map for all local and remote sites to recognize their network locations.

[0053] In other embodiments, the management of multiple systems and connections in a many-to-many configuration can be managed using cloud computing. For example, a cloud-based infrastructure management solution can be used to manage the firewall of each site (or node). Each firewall (e.g., the first remote firewall 1310, the second remote firewall 1312, the first local firewall 1314, and the second local firewall 1316 shown in FIG. 16) is connected to the Internet and the cloud used for management. With cloud-based management, an operator at one of the sites, or an operator at a separate location from various sites, can monitor and manage the firewall.

[0054] Computer-executable instructions for a communication and control system according to the above method may be stored in the form of a computer-readable medium. The computer-readable medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. The computer-readable medium includes random access memory (RAM), read-only memory (ROM), electrically erasable programmable ROM (EEPROM), flash memory or other memory technologies, compact disc ROM (CD-ROM), digital versatile disc (DVD) or other optical storage devices, magnetic cassettes, magnetic tapes, magnetic disk storage devices or other magnetic storage devices, or other media that can be used to store desired instructions and includes access in the form of the Internet or other computer networks. Communication and control system including, but not limited to, other media that can be accessed by 10 (shown in FIG. 1).

[0055] This written description uses a number of examples to disclose the invention, including the best mode, and to enable one of ordinary skill in the art to make and use the invention. The scope of the invention that can be patented is defined by the claims and may include other examples that occur to one of ordinary skill in the art. Such other examples are intended to be within the scope of the claims if they have structural elements that do not differ from the literal language of the claims, or if they include equivalent structural elements that do not differ from the literal language of the claims. The order and sequence of any process or method steps can be varied or rearranged according to alternative embodiments.

[0056] Without departing from the spirit of the invention, many other changes and modifications can be made to the invention. The scope of these and other changes will become apparent from the appended claims.

Claims

1. A system including a robotic medical device system at a local site related to a patient, wherein the robotic medical device system is configured to have a local reference clock or receive time information from a common external time source with a control center at a remote site, and the control center is configured to have a remote reference clock or receive time information from the external time source, the control center is configured to control the robotic medical device system, the robotic medical device system includes at least one elongated medical device, the robotic medical device system, receives a control signal including a time stamp based on the remote reference clock or the external time source from the control center, determines a delay in transmission of the control signal based on the time stamp, compares the delay with a threshold delay value, operates and controls the at least one elongated medical device based on a comparison between the delay and the threshold delay value, and adjusts the speed of the at least one elongated medical device to decrease the speed of the at least one elongated medical device as the delay increases towards the threshold delay value. A system configured as such.

2. The system according to claim 1, wherein the robotic medical device system is configured to operate and control the at least one elongated medical device to stop the movement of the at least one elongated medical device based on a comparison between the delay and the threshold delay value.

3. The system according to claim 1, wherein the robotic medical device system is configured to operate and control the at least one elongated medical device to temporarily stop the movement of the at least one elongated medical device based on a comparison between the delay and the threshold delay value.

4. The system according to claim 1, wherein the robotic medical device system is configured to shift control of the at least one elongated medical device from the remote site to the robotic medical device system when the delay exceeds the threshold delay value.

5. The threshold delay value is based on at least one parameter of the robotic medical device system, the at least one parameter is, The type of treatment performed by the robotic medical device system, The type of the elongated medical device, The location of the tip of the elongated medical device, The direction of movement of the elongated medical device, The system according to claim 1, comprising at least one of the above.

6. The threshold delay value is set such that a long delay is allowed when the elongated medical device is away from the target location, when the elongated medical device is being withdrawn, or when the elongated medical device is a device that moves on a wire or a guide wire. The system according to claim 5.

7. When the delay exceeds the threshold delay value, the control center Stops the elongated medical device, Changes the control of the elongated medical device to the robotic medical device system, Adjusts the speed of the elongated medical device, The system according to claim 1, wherein the operation of the elongated medical device is controlled by at least one of the above.

8. Adjusting the speed of the elongated medical device includes adjusting at least one of the forward, backward, and rotational speeds of the elongated medical device. The system according to claim 7.

9. A system including a control center at a remote site, The control center is configured to have a remote reference clock or receive time information from a common external time source, The control center, Controls a robotic medical device system at a local site related to the patient, and the robotic medical device system is configured to have a local reference clock or receive time information from the common external time source, Receives at least one image from the robotic medical device system, Determines the delay in transmitting the image from the robotic medical device system to the control center, Determines the total delay based on the delay in transmitting the image and the delay in transmitting a control signal from the control center to the robotic medical device system, Compares the total delay with a threshold delay value, Configured to adjust the operation of the robotic medical device system based on the comparison between the total delay and the threshold delay value. The robot medical device system is configured to adjust the speed of at least one elongated medical device so as to decrease the speed of the at least one elongated medical device as the total delay increases towards the threshold delay value.

10. The threshold delay value is based on at least one parameter of the robot medical device system, The at least one parameter is the type of treatment performed by the robot medical device system, the type of the elongated medical device, the location of the tip of the elongated medical device, the direction of movement of the elongated medical device, The system according to claim 9, comprising at least one of them.

11. The threshold delay value is set such that a long delay is allowed when the elongated medical device is away from the target location, when the elongated medical device is being withdrawn, or when the elongated medical device is a device moving on a wire or a guide wire. The system according to claim 10.

12. When the total delay exceeds the threshold delay value, the control center stops the elongated medical device, changes the control of the elongated medical device to the robot medical device system, adjusts the speed of the elongated medical device, The system according to claim 9 is configured to adjust the operation of the elongated medical device by at least one of the above.

13. Adjusting the speed of the elongated medical device includes adjusting at least one of the forward, backward, and rotational speeds of the elongated medical device. The system according to claim 12.

14. Adjusting the speed of the elongated medical device includes setting the speed of the elongated medical device to zero. The system according to claim 12.

Citation Information

Patent Citations

  • Master-slave device, master device, slave device, control method, and computer program

    JP2008119757A

  • Surgical robot system using augmented reality, and method for controlling same

    US20110306986A1

  • Telerobotic System with a Dual Application Screen Presentation

    US20120191464A1

  • Mobile videoconferencing robot system with network adaptive driving

    US8340819B2