Control unit for a surgical robotic system
The control unit in surgical robotic systems optimizes power cycling by maintaining valid session data and instrument states, ensuring efficient and safe surgical robot operation post-reboot.
Patent Information
- Application Number
- PCT/GB2024/052156
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-08-15
- Publication Date
- 2026-02-19
AI Technical Summary
Existing surgical robotic systems face inefficiencies during power cycling of the control unit, leading to unnecessary decrements in the number of uses allowed for surgical instruments and requiring time-consuming retraining of surgical robots, which disrupt surgical procedures.
The control unit is initialized to recognize valid session identifiers and maintain valid data, such as instrument life counts and pivot points, allowing continued use of instruments and avoiding retraining after power cycling.
This approach prevents unnecessary decrements in instrument life counts and avoids the need for retraining, enabling smoother surgical procedure resumption and increased instrument usage without safety concerns.
Smart Images

Figure GB2024052156_19022026_PF_FP_ABST
Abstract
Description
[0001] CMR01-133579PC
[0002] CONTROL UNIT FOR A SURGICAL ROBOTIC SYSTEM
[0003] BACKGROUND
[0004] The present disclosure relates to a control unit for a surgical robotic system. In particular, the present disclosure relates to initialisation of a control unit in a surgical robotic system which comprises one or more surgical robots.
[0005] It is known to use robots for assisting and performing surgery. Figure 1 illustrates a surgical robotic system 10 which comprises two surgical robots 100. In general surgical robotic systems may comprise one or more surgical robots. A surgical robot 100 consists of a base 101, a surgical robot arm 102 and a surgical instrument 104 for manipulating tissue. The base supports the robot, and may itself be attached rigidly to, for example, the operating theatre floor, the operating theatre ceiling or a cart. The surgical robot arm extends between the base and the surgical instrument. The surgical robot arm is articulated by means of multiple flexible joints 105 along its length, which are used to alter the configuration of the surgical robot arm to locate the surgical instrument in a desired location relative to a patient 113. The surgical instrument is attached to the distal end of the surgical robot arm. During a surgical procedure, the surgical instrument may penetrate the body of the patient at a port 114 so as to access the surgical site. The surgical instrument comprises a shaft 111 connected to a distal end effector 112 by a jointed articulation. The end effector performs aspects of a medical procedure, e.g. by engaging in a surgical procedure. This type of medical procedure is often referred to as a minimally invasive surgical procedure. In Figure 1, the illustrated end effector is a pair of jaws which may be used, for example, for cutting or grasping tissue or as a needle holder.
[0006] The configuration of the surgical robot arm 102 of a surgical robot 100 may be remotely controlled in response to inputs received at a remote surgeon console 116. A surgeon may provide inputs to the surgeon console. The remote surgeon console may comprise one or more surgeon input devices 120. For example, these may take the form of one or more hand controllers, foot pedals, interactive touch screens etc. A video feed of the surgical site may be captured by an endoscope, often attached to a further surgical robot arm (not shown in Figure 1 for simplicity), and displayed at a display 118 of the remote surgeon console.
[0007] A control unit 122 connects the surgeon console 116 to the surgical robot arms 100. The control unit 122 receives inputs from the surgeon input device(s) 120 and converts these to control signals to move the joints of the surgical robot arms 102 and end effectors 112. The generation of the control signals, based on the inputs, can be performed using inverse kinematics. The control unit 122 causes these control signals to be sent to the surgical robot arms in order to control the surgical robot arms. Joint controllers on the robot arms 102 drive the joints 105 to move accordingly. The control unit may be integrated into the surgeon console as shown in Figure 1. Alternatively, the control unit may be separate from the surgeon console and separate from the surgical robots. As another alternative, the control may be integrated into one of the surgical robots. Furthermore, in some systems, the functionality of the control unit may be implemented by multiple units, which may be implemented in different locations, e.g. a central control unit may be implemented separate to the robot arms (e.g. as part of the surgeon console or not as part of the surgeon console) and an arm control unit may be implemented in each of the robot arms, wherein the central control unit and the arm control unit(s) communicate with each other and work together to provide the functionality of the control unit for controlling the movement of robot arms.
[0008] As well as operating as a master-slave manipulator in which the surgical robot arms 102 are controlled in response to inputs from the surgeon input device(s) 120, in one or more modes of operation the surgical robot arms may be 'collaborative' such that a user (e.g. a member of the bedside team) can interact with the surgical robot arms directly by pushing upon them to get them to move. In these modes (which may be referred to as "compliant modes") the surgical robot arms exhibit compliant behaviour, as the control unit 122 may receive inputs indicating the forces that the user is applying to a surgical robot arm and may send control signals to the surgical robot arm to cause it to move in accordance with the forces that the user is applying to the surgical robot arm. In some systems, in the compliant modes, an arm controller located at a surgical robot, and separate to the control unit 122, may control the surgical robot arm of that surgical robot to move in accordance with the forces that the user applies to the surgical robot arm as described above. When the control unit 122 is initialised (e.g. powered on) for a current session, it establishes a connection with, and initialises, each of the surgical robots 100. The control unit has a session identifier which is set to a new value at the start of a current session. In particular, the control unit starts a new session each time it is initialised, and each session has a unique session identifier. The session identifier can be sent to each of the surgical robots 100, and each of the surgical robots can store the session identifier in a memory of the instrument of the surgical robot. The session identifier values may be integer values.
[0009] Surgical instruments are typically associated with a number of 'lives', i.e. a number of times that they can be involved in surgical procedures. This is to ensure that instruments are not put to use so many times that their performance degrades to a level which may cause a safety concern. An indication of the number of remaining lives of a surgical instrument is stored on the instrument (i.e. stored in a memory on the instrument). The surgical instrument also stores a time record when the number of remaining lives is stored. The time record stores: (i) a system ID, which identifies the surgical robotic system (e.g. by identifying the surgeon console or the control unit) which the instrument is connected to when the time record is stored; (ii) a session ID, which identifies the current session at the time that the time record is stored; and (iii) a session time which indicates a time within the current session at which the time record is stored. When a surgical instrument is connected to a surgical robot arm, the surgical robot arm establishes a data connection with the surgical instrument. This data connection may be a wired or a wireless connection. The data connection may be encrypted, and in order to establish the data connection a cryptographic signature based on a secret key may be required on both the instrument and the system. When a data connection has been established between a surgical robot arm and a surgical instrument, the surgical robotic system (e.g. the surgical robot) checks the data stored on the surgical instrument to see whether the number of remaining lives of the instrument should be decremented. For example, the surgical robotic system may determine that the number of remaining lives of the instrument should be decremented when a connection is established with the surgical instrument unless: (i) the last use of the instrument was with the same surgical robotic system, which can be determined by comparing an identifier of the system (e.g. an identifier of the surgeon console or the control unit) with the system ID stored on the surgical instrument;
[0010] (ii) the control unit, which may be implemented on the surgeon console, has not been reset since the last time the number of remaining lives of the instrument was decremented, which can be determined by comparing the session ID of the control unit for the current session with the session ID stored on the surgical instrument; and
[0011] (iii) less than a maximum amount of time (e.g. 6 hours) have elapsed since the last time the number of remaining lives of the instrument was decremented, which can be determined by comparing the current session time for the current session with the session time stored on the surgical instrument.
[0012] When the control unit is initialised, it places each of the surgical robots in the system into a mode in which it can be trained before use in the current session. In some surgical robotic systems, the training of a surgical robot involves determining a pivot point for the surgical robot (as described in more detail below). The movement of a surgical robot arm of a trained surgical robot in a surgical mode is constrained so that the shaft of a surgical instrument attached to that surgical robot arm intersects the pivot point. For example, the pivot point can be determined so that it is located within the port 114 through which the instrument passes to reach the surgical site within the patient. The training of a surgical robot is a timeconsuming process, which may be performed for each surgical robot in the surgical robotic system in response to initialisation of the control unit.
[0013] SUMMARY
[0014] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0015] There is provided a control unit for controlling one or more surgical robots of a surgical robotic system, wherein the control unit is configured to, on initialisation of the control unit: receive a session identifier from one of the one or more surgical robots; determine whether the received session identifier is valid for a current session; and in response to determining that the received session identifier is valid for the current session, set a session identifier of the control unit to match the received session identifier, and cause data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot to be treated as valid data for the current session.
[0016] The control unit may be configured to, after setting the session identifier of the control unit to match the received session identifier, send an indication of the session identifier of the control unit to one or more of the one or more surgical robots.
[0017] Each of the one or more surgical robots may comprise a surgical robot arm and a surgical instrument attached to the surgical robot arm.
[0018] Said data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot may comprise an indication of a number of remaining lives of the surgical instrument of that surgical robot.
[0019] Said data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot may comprise an indication of a pivot point, wherein the control unit may be configured to use the indication of the pivot point to control said one of the one or more surgical robots to maintain an intersection between the surgical instrument of that surgical robot and the pivot point.
[0020] The control unit may be configured to, in response to determining that the received session identifier is valid for the current session, cause said one of the one or more surgical robots to be put into a trained mode in which the pivot point is stored for use in the current session, without requiring a port training process to be performed forthat surgical robot following the determination that the received session identifier is valid.
[0021] Each of the one or more surgical robots may comprise a surgical robot arm and a surgical instrument attached to the surgical robot arm, wherein the control unit may be configured to, in response to determining that the received session identifier is not valid for the current session, cause a port training process to be performed to determine a pivot point for the current session for each of the one or more surgical robots, wherein the control unit may be configured to control each of the one or more surgical robots to maintain an intersection between the surgical instrument of that surgical robot and the pivot point determined for that surgical robot.
[0022] The control unit may be configured to, if it is determined that the received session identifier is valid for the current session, receive an indication of a session time from one of the one or more surgical robots.
[0023] The control unit may be configured to, if it is determined that the received session identifier is valid for the current session: determine an updated session time which excludes downtime of the control unit; and send an indication of the updated session time to each of the one or more surgical robots.
[0024] The control unit may be configured to: maintain a bootcounter which indicates a number of times that the control unit has been initialised; and on initialisation of the control unit, in response to determining that the received session identifier is not valid for the current session, set the session identifier of the control unit to match the bootcounter, and cause said data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot to be treated as invalid data for the current session.
[0025] The surgical robotic system may be configured to set a session identifier at each of the one or more surgical robots to be a preliminary value at the start of each session to indicate that the session identifier at that surgical robot still needs to be decided for the current session. The control unit may be configured to, on initialisation of the control unit, determine whether the session identifier received from one of the one or more surgical robots is valid for the current session by determining whether the received session identifier is equal to the preliminary value.
[0026] The control unit may be configured to: maintain a bootcounter which indicates a number of times that the control unit has been initialised; and on initialisation of the control unit, determine whether the session identifier received from one of the one or more surgical robots is valid for the current session by determining whether the received session identifier is less than a minimum possible value of the bootcounter.
[0027] The initialisation of the control unit may be part of a process of power cycling the control unit during the current session.
[0028] There may be provided a surgical robotic system comprising: one or more surgical robots; and a control unit as described herein for controlling the one or more surgical robots.
[0029] Each of the one or more surgical robots may comprise a surgical robot arm and a surgical instrument attached to the surgical robot arm. The surgical robotic system may be configured to, in response to determining that the received session identifier is not valid for the current session, decrement an indication of a number of remaining lives of each of the one or more surgical instruments attached to the one or more surgical robots.
[0030] Each of the one or more surgical robots may comprise a surgical robot arm and a surgical instrument attached to the surgical robot arm, and the surgical instrument of a surgical robot may be associated with a number of remaining lives, and the surgical robotic system may be configured to, in response to the control unit establishing a connection with that surgical robot, determine whether to decrement the number of remaining lives of the surgical instrument of that surgical robot in dependence on the session identifier of the control unit. A session identifier may be stored on the surgical instrument. The surgical robotic system may be configured to decrement the number of remaining lives of the surgical instrument if the session identifier of the control unit does not match the session identifier stored on the surgical instrument.
[0031] A system identifier, a session identifier and a session time indication may be stored on the surgical instrument. The surgical robotic system may be configured to decrement the number of remaining lives of the surgical instrument if any of: (i) the session identifier of the control unit does not match the session identifier stored on the surgical instrument, (ii) a system identifier of the surgical robotic system does not match the system identifier stored on the surgical instrument, or (iii) the session time indication stored on the surgical instrument is more than a maximum amount of time older than a current session time of the current session on the surgical robotic system.
[0032] A system identifier, a session identifier and a session time indication may be stored on the surgical instrument. The surgical robotic system may be configured to not decrement the number of remaining lives of the surgical instrument if: (i) the session identifier of the control unit matches the session identifier stored on the surgical instrument, (ii) a system identifier of the surgical robotic system matches the system identifier stored on the surgical instrument, and (iii) the session time indication stored on the surgical instrument is not more than a maximum amount of time older than a current session time of the current session on the surgical robotic system.
[0033] There is provided a method of operating a control unit for controlling one or more surgical robots of a surgical robotic system, the method comprising, on initialisation of the control unit: receiving a session identifier from one of the one or more surgical robots; determining whether the received session identifier is valid for a current session; and in response to determining that the received session identifier is valid for the current session, setting a session identifier of the control unit to match the received session identifier, and causing data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot to be treated as valid data for the current session. There may be provided a computer readable storage medium having stored thereon computer readable instructions that, when executed at a control unit of a surgical robotic system, cause the control unit to perform any of the methods described herein.
[0034] The above features may be combined as appropriate, as would be apparent to a skilled person, and may be combined with any of the aspects of the examples described herein.
[0035] BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Examples will now be described in detail with reference to the accompanying drawings in which:
[0037] Figure 1 shows an example surgical robotic system;
[0038] Figure 2 shows an example surgical robot having a surgical robot arm with a surgical instrument attached;
[0039] Figure 3 is a flow chart for a method of operating a control unit for controlling one or more surgical robots of a surgical robotic system; and
[0040] Figure 4 shows the shaft of a surgical instrument intersecting a pivot point within a port.
[0041] The accompanying drawings illustrate various examples. The skilled person will appreciate that the illustrated element boundaries (e.g., boxes, groups of boxes, or other shapes) in the drawings represent one example of the boundaries. It may be that in some examples, one element may be designed as multiple elements or that multiple elements may be designed as one element. Common reference numerals are used throughout the figures, where appropriate, to indicate similar features.
[0042] DETAILED DESCRIPTION
[0043] The following description is presented by way of example to enable a person skilled in the art to make and use the invention. The present invention is not limited to the embodiments described herein and various modifications to the disclosed embodiments will be apparent to those skilled in the art.
[0044] A surgical robotic system of the type illustrated in Figure 1 is described. As described above, the surgical robotic system 10 comprises one or more surgical robots 100 which each comprise a surgical robot arm 102 with a surgical instrument 104 attached to the distal end of the surgical robot arm. The surgical robotic system 10 comprises a remote surgeon console 116. The remote surgeon console is connected to the surgical robot(s) 100 via a control unit 122. The control unit 122 is for controlling the surgical robot(s) 100. As described above, the control unit 122 may be integrated into the surgeon console 116 as shown in Figure 1, or may be located elsewhere in the system, e.g. in one of the surgical robots or separately to both the surgeon console and the surgical robots. Furthermore, the functionality of the control unit 122 may be split between a central controller which is separate to the surgical robots (e.g. which may or may not be integrated into the surgeon console) and an arm controller integrated into each of the surgical robots.
[0045] The surgical robotic system and methods described in the following are done so with respect to one or more surgical robots which each have a surgical robot arm holding a surgical instrument having an end effector at its distal end for manipulating tissue of a patient at a surgical site. The end effector may be, for example, a pair of jaws, scalpel, suturing needle etc. However, the same surgical robot arm, control unit and methods apply equally to a surgical instrument which is an endoscope having a camera at its distal end for capturing a video feed of a surgical site.
[0046] It is possible, during a surgical procedure, for the control unit 122 to be rebooted, i.e. 'power cycled'. For example, the control unit 122 may be part of the surgeon console 116, and the surgeon console may be rebooted. There can be many causes for power cycling the control unit during a surgical procedure (i.e. mid-surgery), such as to recover from an alarm. The alarm may be a 'medium priority alarm'. To give just some examples, the control unit 122 may be rebooted due to a software failure, a loss of power at the control unit or the surgeon console, a problem with the surgeon input devices, or a problem with communication between the control unit 122 and another device in the surgical robotic system 10. The control unit 122 may be connected to a wider network, e.g. a hospital network of a hospital in which the surgical robotic system 10 is implemented. Another example of a cause for power cycling the control unit during a surgical procedure is a network failure (e.g. a failure on the hospital network). As another example, the control unit may be rebooted in response to a cyber attack. In this case, the console may act like a firewall to prevent a cyber attack from affecting the surgical robots 100 in the surgical robotic system 10.
[0047] Conventionally, when the control unit 122 is initialised (e.g. as part of rebooting, or power cycling, the control unit) the surgical instruments at each of the surgical robots would lose a life. This is because the session ID of the control unit 122 would be reassigned (e.g. incremented) upon the rebooting of the control unit, such that the session ID of the control unit will no longer match the session ID stored on the instrument, so the number of remaining lives for the instrument will be decremented. The decrementing of the number of remaining lives of an instrument in this situation may be detrimental. In particular, it may result in the number of remaining lives of an instrument providing a poor indication of how many more times the instrument could be safely used. As described herein, the control unit 122 can be initialised in a manner which will not result in these unsuitable decrements to the number of remaining lives for the instruments. In particular, use of a surgical instrument 104 attached to a surgical robot arm 102 can be resumed after a reboot of the control unit 122 during a session, without decrementing the life count for the surgical instrument. This provides a significant benefit because by avoiding unnecessarily decrementing the number of remaining lives of a surgical instrument, the surgical instrument is able / allowed to be used in more surgical procedures before it runs out of lives and its use has to be discontinued. The number of lives that a new surgical instrument has may vary depending on the type of instrument. As an example, the number of remaining lives of a new surgical instrument may be set to be between 1 and 20. Furthermore, the usage time of the active life can be retained following a reboot of the control unit 122.
[0048] Furthermore, conventionally, when the control unit 122 is initialised and connections are established between the control unit 122 and each of the surgical robots 100, each of the surgical robots will need to be retrained, e.g. to determine a pivot point for controlling that surgical robot during the current surgical session. As described herein, when the control unit 122 is rebooted during a session, the control unit 122 can be initialised in a manner which will allow a trained surgical robot to retain its pivot point so that it can be used during the current session without the need for retraining the surgical robot. This provides a significant benefit because the training procedure for determining the pivot point is a time-consuming process. Avoiding the need to perform this training procedure on each of the surgical robots in the surgical robotic system following a reboot of the control unit 122, allows the surgical procedure to be resumed much more quickly following the reboot of the control unit 122.
[0049] In general, in examples described herein, the control unit 122 can be initialised in a manner which causes data that is stored at a surgical robot relating to the state of that surgical robot (e.g. the number of remaining lives of a surgical instrument of the surgical robot or an indication of a pivot point for controlling the surgical robot) to be treated as valid data for the current session in some situations. In particular, this data can be treated as valid data for the current session if the surgical robot 100 has a valid session identifier for the current session when the control unit 122 is initialised. The control unit 122 comprises a processor and a memory. The memory of the control unit stores, in a non-transient way, software code that can be executed by the processor of the control unit to cause the processor to perform the functionality of the control unit 122 as described herein. For example, the code executed by the processor of the control unit 122 can initialise the control unit and can control the surgical robots 200 in the manner described herein.
[0050] Figure 2 illustrates an exemplary surgical robot 200, which may be implemented as one of the surgical robots 100 in the surgical robotic system 10 shown in Figure 1. The surgical robot 200 comprises a base 201 which is fixed in place when a surgical procedure is being performed. The base 201 may be mounted to a support structure. In Figure 2, the support structure is a cart 210. This cart may be a bedside cart for mounting the surgical robot at bed height. Alternatively, the support structure may be a ceiling mounted device, or a bed mounted device.
[0051] A surgical robot arm 202 extends from the base 201 of the surgical robot to a terminal end 203 which has an attachment for attaching to a surgical instrument 204. The "terminal end" of the surgical robot arm may be referred to as the "distal end" of the surgical robot arm. The surgical robot arm is flexible. It is articulated by means of multiple flexible joints 205 along its length. In between the joints are rigid arm links 206. The joints may be revolute joints. The surgical robot arm has at least seven joints between the base and the terminal end. The surgical robot arm 200 illustrated in Figure 2 has eight joints in total between the base 201 and the terminal end 203. The surgical robot arm illustrated in Figure 2 has (only) eight joints between the base and the terminal end. The joints include one or more roll joints (which have an axis of rotation along the longitudinal direction of the arm links on either side of the joint), one or more pitch joints (which have an axis of rotation transverse to the longitudinal direction of the preceding arm link), and one or more yaw joints (which also have an axis of rotation transverse to the longitudinal direction of the preceding arm link and also transverse to the rotation axis of a co-located pitch joint). In the example of Figure 2: joints 205a, 205c, 205e and 205h are roll joints; joints 205b, 205d and 205f are pitch joints; and joint 205g is a yaw joint. The order of the joints sequentially from the base 201 of the robot arm to the terminal end 203 of the robot arm is: roll, pitch, roll, pitch, roll, pitch, yaw, roll. There are no intervening joints in Figure 2.
[0052] The pitch joint 205f (which may be referred to as the "Je" joint) and yaw joint 205g (which may be referred to as the "J7" joint) form a compound joint, which may be a spherical joint. The pitch joint Je and the yaw joint J7 have intersecting axes of rotation, which may be perpendicular to each other. The compound joint formed of the pitch joint Je and the yaw joint J7 may be implemented as a "Hooke's" or universal joint. The compound joint formed of the pitch joint Je and the yaw joint J7 may be referred to as a "wrist joint" of the surgical robot arm. The surgical robot arm could be jointed differently to that illustrated in Figure 2. For example, the arm may have fewer than eight or more than eight joints. The arm may include joints that permit motion other than rotation between respective sides of the joint, for example a telescopic joint. The arm may have a different ordering of joints to the surgical robot arm depicted in Figure 2.
[0053] Returning to Figure 2, the surgical robot arm 202 comprises a set of motors 207. Each motor 207 drives one or more of the joints 205. Each motor 207 is controlled by a joint controller. The joint controller may be co-located with the motor 207. A joint controller may control one or more of the motors 207. The robot arm comprises a series of sensors 208, 209. These sensors comprise, for each joint, a position sensor 208 for sensing the position of the joint, and a torque sensor 209 for sensing the applied torque about the joint's rotation axis. The torque applied about a joint's rotation axis includes any one or combination of the following components: torque due to gravity acting on the joint, torque due to inertia, and torque due to an external force applied to the joint. One or both of the position and torque sensors for a joint may be integrated with the motor for that joint. The outputs of the sensors are passed to the control unit 122.
[0054] The surgical instrument 204 attaches to an attachment (e.g. a drive assembly) at the distal end (i.e. the terminal end) 203 of the surgical robot arm 202. During a surgical procedure, this attachment is at all times external to the patient. The surgical instrument 204 has an elongate profile, with a shaft 211 spanning between its proximal end which attaches to the robot arm and its distal end which has an end effector 212 and which accesses the surgical site within the body of the patient 113. When the surgical instrument is attached to the attachment of the surgical robot arm, it is configured to extend linearly parallel with the rotation axis of the joint 205h of the arm. For example, the surgical instrument may extend along an axis coincident with the rotation axis of the joint 205h of the arm. In other words, when the surgical instrument 204 is attached to the attachment of the surgical robot arm, the axis of rotation of the roll joint 205h is collinear with a longitudinal axis of the shaft 211 of the surgical instrument.
[0055] The proximal end of the surgical instrument and the instrument shaft may be rigid with respect to each other and rigid with respect to the distal end of the robot arm when attached to it. During a surgical procedure, an incision can be made into the patient's body, through which a port 114 can be inserted. The surgical instrument may penetrate the patient's body through the port to access the surgical site. Alternatively, the surgical instrument may penetrate the body through a natural orifice of the body to access the surgical site. At the proximal end of the instrument, the shaft is connected to an instrument interface. The instrument interface engages with the drive assembly at the distal end of the robot arm. Specifically, individual instrument interface elements of the instrument interface each engage a respective individual drive assembly interface element of the drive assembly of the surgical robot arm. The instrument interface is releasably engageable with the drive assembly. The instrument can be detached from the robot arm manually without requiring any tools. This enables the instrument to be detached from the drive assembly quickly and another instrument attached during an operation.
[0056] At the distal end of the surgical instrument 204, the distal end of the instrument shaft 211 is connected to the end effector 212 by an articulated coupling. The end effector engages in a surgical procedure at the surgical site. The end effector may be, for example, a pair of jaws, a pair of monopolar scissors, a needle holder, a fenestrated grasper, or a scalpel. The articulated coupling comprises several joints. These joints enable the pose of the end effector to be altered relative to the direction of the instrument shaft. The end effector itself may also comprise joints.
[0057] Drive is transmitted from the robot arm to the end effector in any suitable manner. For example, the joints of the instrument may be driven by driving elements such as cables, push rods or push / pull rods. These driving elements engage the instrument interface at the proximal end of the instrument. The drive assembly at the terminal end of the robot arm comprises instrument drive joints which transfer drive from the surgical robot arm to the instrument interface via the respective interface elements described above, and thereby to the instrument joints.
[0058] The instrument comprises an instrument memory 210 which is configured to store data, such as an indication of the number of remaining lives of the instrument as well as a time record, which is stored when an indication of the number of remaining lives is stored. The time record stores: (i) a system ID, which identifies the surgical robotic system (e.g. by identifying the surgeon console or the control unit) which the instrument is connected to when the time record is stored; (ii) a session ID, which identifies the current session at the time that the time record is stored; and (iii) a session time which indicates a time within the current session at which the time record is stored.
[0059] The surgical robot 200 also comprises a robot controller 214, which comprises a processor and a memory. The robot controller 214 can communicate with the control unit 122, and can store data relating to the surgical robot 200 in its memory. The robot controller 214 may receive packets of data from the control unit 122 periodically during an active surgical session, and may store information about the current session in its memory when a packet is received. The stored session information may be 'echoed' (i.e. sent) back to the control unit 122.
[0060] Figure 3 is a flow chart for a method of operating the control unit 122 for controlling the surgical robots 100 of the surgical robotic system 10. In particular, the flow chart of Figure 3 relates to the operation of the control unit 122 on initialisation (or 'during initialisation') of the control unit 122. As described above, the control unit 122 may be initialised as part of a reboot, or power cycle, of the control unit during a current session. As mentioned above, in the main examples described herein and shown in Figure 1, the control unit 122 is implemented (as a "central controller") in the surgeon console 116, but in other examples the control unit 122 may be implemented elsewhere in the system 10, e.g. in one of the surgical robots 100, or in a unit which is separate to the surgeon console and separate to the surgical robots. Furthermore, in some other examples the control unit 122 may be implemented as a plurality of separate control modules implemented in different locations in the system, e.g. implemented in the surgeon console 116 and / or in one or more of the surgical robots 100.
[0061] A reboot of the control unit 122 may be performed to recover from an alarm or failure in the surgical robotic system 10. On initialisation of the control unit 122, the control unit establishes a connection with each of the surgical robots 100. If a surgical robot has valid data relating to the current session then the control unit 122 may be able to recoverthat valid data during initialisation, e.g. in order to resume the use of previously attached instruments. A boot counter (or "bootcounter") keeps track of the number of times that the control unit 122 has been initialised. The bootcounter values may be integer values.
[0062] When the control unit 122 is initialised, a session identifier of the control unit is set to a preliminary value to indicate that the session identifier of the control unit still needs to be decided for the current session. This preliminary value may indicate that the session ID for the control unit is 'session_undecided'. The preliminary value may, for example, be zero. The preliminary value may be less than a minimum possible value ('min_bootcounter') of the bootcounter which indicates the number of times that the control unit 122 has been initialised. In other words, the bootcounter is greater than or equal to min_bootcounter, which is greater than the preliminary value which indicates that the session ID for the control unit is 'session_undecided'. For example, the minimum possible value ('min_bootcounter') of the bootcounter may be one.
[0063] When the control unit 122 is initialised, it queries the surgical robot(s) 100 of the surgical robotic system 10 to see whether any of them have a valid session ID for the current session.
[0064] In step S302 the control unit 122 receives a session identifier from one (or more) of the surgical robot(s) in the surgical robotic system. In step S304 the control unit 122 determines whether the received session identifier is valid for the current session. If it is determined in step S304 that the control unit has received a valid session identifier for the current session then the method passes to step S306 (described below). If it is determined in step S304 that the control unit has not received a valid session identifier for the current session then the method passes to step S310 (described below). The 'current session' is a session (e.g. a surgical session) that is in progress.
[0065] When the control unit is first powered on (i.e. first initialised) it does not know whether the current session is just beginning or whether the initialisation of the control unit occurred due to a power cycle of the control unit during an established session. If the control unit 122 is being initialised at the start of a new session then none of the surgical robots will have stored a valid session ID for the current session. In particular, the surgical robotic system 10 is configured to set a session identifier at each of the surgical robots 100 to be the preliminary value (e.g. zero) at the start of each session. That is, when a surgical robot is powered down and / or powered up then a session ID stored in the memory of the robot controller 214 of a surgical robot is set to the preliminary value (e.g. zero) which indicates 'session_undecided'. So at the start of a session, the surgical robots will all have session IDs indicating 'session_undecided', which cannot be a valid session ID for the current session. For example, there may be a minimum value for a valid session ID which is greater than the value used to indicate 'session_undecided'. For example, the minimum value for a valid session ID may be equal to the minimum possible value ('min_bootcounter') of the bootcounter. As described above, min_bootcounter may equal one. Before starting surgery in the current session, each of the surgical robots needs to have a valid session ID for the current session (which may be received from the control unit 122 as described below).
[0066] The control unit 122 may determine whether a received session identifier is valid for the current session in step S304 by determining whether the received session identifier is equal to the preliminary value. In particular, if the received session identifier is equal to the preliminary value then the control unit 122 may determine that the received session identifier is not valid for the current session; whereas, if the received session identifier is not equal to (e.g. is greater than) the preliminary value then the control unit 122 may determine that the received session identifier is valid for the current session. Alternatively, the control unit 122 may determine whether a received session identifier is valid for the current session in step S304 by determining whetherthe received session identifier is less than min_bootcounter. In particular, if the received session identifier is less than min_bootcounterthen the control unit 122 may determine that the received session identifier is not valid for the current session; whereas, if the received session identifier is greater than or equal to min_bootcounter then the control unit 122 may determine that the received session identifier is valid for the current session.
[0067] In response to determining that the received session identifier is valid for the current session, the method passes from step S304 to step S306. In step S306 the control unit 122 sets a session identifier of the control unit to match the received session identifier. In this way, the control unit adopts the valid session identifier for the current session that it has received from one of the surgical robots. This allows the control unit to continue operating in the current session without needing to end the current session and start a new session following a reboot of the control unit during the current session.
[0068] After setting the session identifier of the control unit to match the received session identifier in step S306, the control unit may send an indication of the session identifier of the control unit to one or more of the surgical robots in the surgical robotic system. In this way, the control unit 122 can ensure that all of the surgical robots have the same (valid) session identifier for the current session. It is noted that the control unit 122 only needs to receive a valid session identifier for the current session from at least one (not necessarily all) of the surgical robots 100 in the surgical robotic system 10, and then it can share the valid session identifier with all of the surgical robots in the surgical robotic system.
[0069] The surgical robot 100 that sent the valid session identifier to the control unit 122 stores data relating to the state of that surgical robot. In step S308, the control unit 122 causes the data that is stored at that surgical robot to be treated as valid data for the current session. The control unit 122 may also cause data stored at other surgical robots relating to the state of those surgical robots to be treated as valid data for the current session.
[0070] For example, the data that is stored at a surgical robot 100 relating to the state of that surgical robot which can be treated as valid data for the current session may comprise an indication of a number of remaining lives of the surgical instrument of that surgical robot. As another example, the data that is stored at a surgical robot 100 relating to the state of that surgical robot which can be treated as valid data for the current session may comprise an indication of a pivot point, wherein the control unit is configured to use the indication of the pivot point to control that surgical robot to maintain an intersection between the surgical instrument of that surgical robot and the pivot point. These two examples are described in detail below. Some further examples of the data that is stored at a surgical robot 100 relating to the state of that surgical robot which may be treated as valid data for the current session are also mentioned towards the end of this description.
[0071] In response to determining that the received session identifier is not valid for the current session, the method passes from step S304 to step S310. As described above, if there are multiple surgical robots in the surgical robotic system then the method may pass from step S304 to step S306 if any of the surgical robots send a valid session identifier for the current session to the control unit 122, and may pass from step S304 to step S310 if none of the surgical robots send a valid session identifier for the current session to the control unit 122.
[0072] As described above, the control unit 122 maintains a boot counter (or "bootcounter") which indicates a number of times that the control unit 122 has been initialised. In step S310 the control unit 122 sets the session identifier of the control unit 122 to match the bootcounter. This sets the session identifier to a valid value, indicating that a new session is starting on initialisation of the control unit. After setting the session identifier of the control unit to match the bootcounter in step S310, the control unit may send an indication of the session identifier of the control unit to the surgical robots in the surgical robotic system. In this way, the control unit 122 ensures that all of the surgical robots have the same (valid) session identifier for the current session.
[0073] In step S312, the control unit 122 causes data stored at a surgical robot 100, relating to the state of that surgical robot, to be treated as invalid data for the current session. As described above, the data that is stored at a surgical robot 100 relating to the state of that surgical robot which can be treated as invalid data for the current session may comprise an indication of a number of remaining lives of the surgical instrument of that surgical robot. As another example, the data that is stored at a surgical robot 100 relating to the state of that surgical robot which can be treated as invalid data for the current session may comprise an indication of a pivot point for that surgical robot.
[0074] In summary of the method shown in Figure 3, the control unit 122 will adopt the session identifier that it receives from a surgical robot for a current session if: (i) the received session identifier is valid for the current session, and (ii) the control unit has an undecided session identifier (e.g. set to a value of zero) since it has not been used for surgery since rebooting. Alternatively, the control unit 122 will make a new session identifier from the boot counter when the session identifier(s) that it receives from the surgical robot(s) are not valid for the current session.
[0075] As described above, each of the surgical robot(s) 100 in the surgical robotic system 10 comprises a surgical robot arm 102 and a surgical instrument 104 attached to the surgical robot arm, and the surgical instrument of a surgical robot is associated with a number of remaining lives. An indication of the number of remaining lives of an instrument is stored on the instrument (e.g. in the memory 210). In response to the control unit 122 establishing a connection with a surgical robot 100, the surgical robot 100 (e.g. the robot controller 214 or a joint controller of the surgical robot) determines whether to decrement the number of remaining lives of the surgical instrument 104 of that surgical robot 100 in dependence on the session identifier of the control unit. In particular, in step S308 (which is performed in response to determining that the session identifier received in step S302 is valid for the current session), the control unit 122 can cause the surgical robot 100 to not decrement the number of remaining lives of the surgical instrument 104 of that surgical robot 100. However, in step S312 (which is performed in response to determining that the session identifier received in step S302 is not valid for the current session), the control unit 122 can cause the surgical robot 100 to decrement the number of remaining lives of the surgical instrument 104 of that surgical robot 100. This is done at each of the surgical robots 100 in the surgical robotic system 10.
[0076] For example, when the control unit 122 establishes a connection with a surgical robot 100, the control unit and the surgical robot will set a session identifier for the current session as described above. Furthermore, as described above, a session identifier will be stored, as part of a time record, on the instrument 104 attached to the surgical robot 100. The surgical robot 100 can compare the session identifier of the control unit with the session identifier stored on the instrument to determine whether to decrement the number of lives of the instrument. In particular, the surgical robot 100 decrements the number of remaining lives of the surgical instrument 104 if the session identifier of the control unit 122 does not match the session identifier stored on the surgical instrument 104. However, the surgical robot 100 does not decrement the number of remaining lives of the surgical instrument 104 if the session identifier of the control unit 122 does match the session identifier stored on the surgical instrument 104.
[0077] Each life of a surgical instrument may allow the surgical instrument to be used in a surgical procedure (i.e. in a surgical session), controlled by a control unit, for up to a maximum amount of time. The instrument can be swapped between surgical robot arms attached to the same control unit during a procedure, without losing a life each time it is swapped. The 'maximum amount of time' may be between 3 and 12 hours. To give some specific examples, the maximum amount of time may be 6 hours or 8 hours. 6 hours may be a particularly suitable amount of time to set as the maximum amount of time for which a surgical instrument can be used for each of its lives because surgical practice may dictate that surgical instruments must be cleaned and sterilised between multiple uses which is a process that is likely to take more than 6 hours, and the surgical robotic system may be only required to support procedures of up to 6 hours in length.
[0078] As described above, a surgical instrument stores an indication of the number of remaining lives of the surgical instrument, a system identifier, a session identifier and a session time indication. The system identifier, session identifier and session time indication are stored in a time record and relate to the state of a session at the time that the number of remaining lives of the surgical instrument is updated. The system identifier, session identifier and session time indication that are stored on the surgical instrument can be used to determine whether to decrement the number of remaining lives of the surgical instrument. In particular, the surgical robot 100 can decrement the number of remaining lives of the surgical instrument 104 if any of: (i) the session identifier of the control unit 122 does not match the session identifier stored on the surgical instrument 104, (ii) a system identifier of the surgical robotic system 10 does not match the system identifier stored on the surgical instrument, or (iii) the session time indication stored on the surgical instrument 104 is more than the maximum amount of time olderthan a current session time of the current session on the surgical robotic system. However, the surgical robot 100 does not decrement the number of remaining lives of the surgical instrument 104 if: (i) the session identifier of the control unit 122 matches the session identifier stored on the surgical instrument 104, (ii) the system identifier of the surgical robotic system 10 matches the system identifier stored on the surgical instrument 104, and (iii) the session time indication stored on the surgical instrument 104 is not more than the maximum amount of time older than a current session time of the current session on the surgical robotic system. As described above, the maximum amount of time may, for example, be in a range from 3 hours to 12 hours, and to give some specific examples may be 6 hours or 8 hours. The system identifier of the surgical robotic system 10, may for example be an identifier of the control unit 122 or an identifier of the surgeon console 116.
[0079] It is noted that resetting the session identifier after a reboot of the control unit 122 (e.g. after a reboot of the surgeon console 116) when such a reset is not required, would unnecessarily decrement the life of any instrument that was attached to the system after the new session identifier is set (not only those instruments that are attached to a surgical robot arm in the system when the control unit 122 is rebooted). According to the examples described herein, such resetting of the session identifier (when it is not required) is avoided, thereby avoiding unnecessarily decrementing the lives of the instruments attached to the system after the reboot of the control unit.
[0080] If it is determined that the session identifier received in step S302 is valid for the current session, then the control unit 122 may receive an indication of a session time from one of the surgical robots 100, and may determine an updated session time which excludes downtime of the control unit. The control unit 122 may then send an indication of this updated session time to each of the surgical robots 100 in the surgical robotic system 10. In this way, all of the surgical robots 100 in the surgical robotic system 10 have consistent (i.e. matching) indications of the session time of the current session. Furthermore, by excluding the downtime of the control unit 122, the time taken to reboot the control unit during a surgical procedure is not counted towards determining whether to decrement the number of remaining lives of the instruments in the surgical robotic system. This can reduce the number of times in which the number of remaining lives of a surgical instrument is unnecessarily decremented, which in turn can increase the number of times that surgical instruments can be used before they are discontinued.
[0081] Constraints may be placed on the movement of a surgical instrument 104 attached to a surgical robot arm 102 of a surgical robot 100 that can be caused by the control unit 122. As described above, one such constraint is that the control unit 122 is configured to control the surgical robot arm 102, in dependence on inputs received at the surgeon input device 120, to alter the configuration of the surgical robot arm 102 whilst maintaining an intersection between the surgical instrument 104 attached to the surgical robot arm 102 and a pivot point. The control unit may be configured to control the surgical robot arm 102 in this way during a minimally invasive procedure.
[0082] Figure 4 shows part of a surgical instrument (which may correspond to the surgical instrument 104 or 204 described above) comprising a shaft 411, an articulation 406 and an end effector 412. The end effector 412 is connected to the distal end of the shaft 411 of the surgical instrument via the articulation 406. The shaft 411 of the surgical instrument penetrates the outer tissue 402 of a patient through a port 414 so that the end effector can access a surgical site within the patient. Figure 4 shows an example pivot point 404 for a surgical robot. The pivot point 404 is within the port 414. Each surgical robot may have its own pivot point. The pivot points for the surgical robots may be periodically updated during a procedure. The pivot point 404 is a point in space about which the control unit 122 is configured to cause the shaft 411 of the surgical instrument to pivot. The pivot point for a surgical robot may be defined with respect to a global frame of reference for the surgical procedure or with respect to a frame of reference of that robot. The pivot point may be referred to as a "virtual pivot point" or a "fulcrum". The pivot point 404 may be mechanically enforced or may be a software constraint enforced by the control unit 122. In the example shown in Figure 4, there is nothing physically present at the pivot point (which is why it may be referred to as a virtual pivot point or a virtual fulcrum) and the pivot point 404 is a software constraint enforced by the control unit 122 when it determines the control signals for driving the surgical robot arm 102.
[0083] As such, the surgical robot arm 102 is driven using control signals which maintain an intersection between the shaft 411 of the surgical instrument 104 and the pivot point 404. For example, during a minimally invasive procedure, the surgeon can use the surgeon input device 120 to indicate a desired position and orientation of the end effector 412 of the surgical instrument 104. In response, the control unit 122 determines a configuration of the series of joints of the surgical robot arm that will result in both (i) the end effector 412 of the surgical instrument being placed in that desired position and orientation and (ii) the shaft 411 of the surgical instrument passing through (e.g. maintaining an intersection with) the pivot point 404, and to generate a control signal to move the series of joints to that configuration.
[0084] By determining a suitable pivot point, the disruption to the outer tissues 402 of the patient caused by moving the surgical instrument during a minimally invasive procedure can be minimised. In particular, forces exerted to the patient abdomen as a result of pivotal movement of the instrument, would be minimised. For example, a suitable pivot point 404 may be located within the port 414, e.g. at or close to the centre of the port 414.
[0085] As an example, a calibration process can be performed prior to performing a minimally invasive procedure in order to determine a suitable pivot point. This calibration process may be referred to as "training" or "port training" the surgical robot, and is a time-consuming process. In order to perform the calibration process for a surgical robot 100, an operating mode of the surgical robot is set to be a calibration mode so that the surgical robotic system can act accordingly in order to calibrate the surgical robot. In the calibration mode, the configuration of the surgical robot arm 102 of the surgical robot 100 can be altered whilst the surgical instrument 104 is inside the access port 414 or natural orifice. During the calibration process, the configuration of the surgical robot arm 102 can be altered by the application of external forces directly onto the surgical robot arm 102. For example, the user (e.g. a surgeon or a member of the operating room staff) may apply forces directly to the surgical robot arm 102 (e.g. by pushing a joint of the surgical robot arm 102) -which can be sensed by the torque sensors 209 and acted on by the control unit 122 in a manner that would be understood by the skilled person. During the calibration process, when operating in the calibration mode, the control unit 122 can control the surgical robot arm 102 to maintain a position in which it is placed by means of external forces applied directly to the surgical robot arm 102.
[0086] During the calibration process, when operating in the calibration mode, the surgical robot arm 102 can be moved generally transversely to the shaft of the surgical instrument 102. The configuration of the surgical robot arm 102 may be altered such that the distal end of the surgical robot arm 102 is moved in two dimensions transverse (e.g. perpendicular) to the longitudinal axis of the shaft: e.g. with (i) components parallel to a direction that is transverse (e.g. perpendicular) to the shaft and also with (ii) components orthogonal to that direction but transverse (e.g. perpendicular) to the shaft. To do this, the user (e.g. a surgeon or a member of the operating room staff) may gyrate the distal end 203 of the surgical robot arm about a point generally aligned with the natural axis of the access port or natural orifice. This causes the surgical instrument 104 to come into contact with the access port 414 (or natural orifice) such that the access port 414 (or natural orifice) applies a lateral force on the shaft 411. That force can be accommodated by motion about the joint 205f. The force is "lateral" in the sense that it is applied to the sides of the instrument shaft and is generally in a direction that is transverse (e.g. perpendicular) to the longitudinal axis of the shaft of the instrument.
[0087] As the configuration of the surgical robot arm 102 is being altered, the position sensors 208 can record the position of each joint of the series of joints of the surgical robot arm. The position sensors 208 can record the positions of each joint of the surgical robot arm 102 at a plurality of instances in time. Position information may be recorded irregularly or at predetermined time intervals, e.g. every 20 milliseconds (ms). In other words, position information may be recorded at a predetermined frequency, e.g. of 50Hz. The position sensors provide the recorded position information to the control unit 122. The control unit may also store in memory information indicating one or more parameters of the surgical instrument 104 (e.g. including the length of the shaft and / or the orientation of its shaft relative to its base). These parameters of the surgical instrument 104 may be read from a memory (e.g. memory 210) on the surgical instrument itself and passed to the control unit 122.
[0088] The control unit 122 uses this information to determine, at each of the plurality of instances in time: (a) the position of the distal end 203 of the surgical robot arm relative to the base 201 and (b) a vector representing the surgical instrument 204 (e.g. in particular, its shaft 211) relative to the distal end 203 of the surgical robot arm 202. Position (a) and vector (b) may be termed a data pair. The vectors of the data pairs will approximately (but usually not exactly) converge, from their respective distal end position, on the natural rotation centre of the access port 414 or natural orifice. By collecting a plurality of said data pairs, and then solving for a best estimate (i.e. an estimate with the least error) of a location where the vectors converge, the control unit 122 can determine a fulcrum (e.g. a pivot point) within the access port 414 or natural orifice. For example, the control unit 122 may estimate, as the pivot point, the point in space which minimises the sum of the perpendicular distances between that point and the vectors of the data pairs. Here, a "perpendicular distance" between the point and a vector refers to the distance between the point and the vector in a direction perpendicular to the vector. Therefore, the perpendicular distance between the point and a vector is the distance between the point and the position on the vector which is closest to the point. In some examples, the control unit 122 may estimate, as the pivot point, the point in space which minimises the sum of the squares of the perpendicular distances between that point and the vectors of the data pairs. The control unit 122 can store this pivot point in memory for later use.
[0089] The method of determining the pivot point described above is a first example of how the pivot point may be determined for a surgical robot. In summary of this first example, a user manually moves the arm (once the instrument tip is inside the port) such that the wrist point of the arm (at the intersection of joints Je and J7) is constrained to move on the surface of a sphere with centre at the tip of the shaft, whilst joints Je and J7 are compliantly driven by the forces exerted at the port (or "trocar"), such that the shaft angle changes as the wrist moves and the tip of the instrument remains inside the port. By tracking the pairs of wrist positions and shaft angles over time and calculating least square solutions, a candidate pivot point is found.
[0090] A second example of how the pivot point may be determined for a surgical robot is similar to the first method described above, but instead of the arm moving compliantly when a user applies forces to it, it tracks a circular path around in the spherical surface such that a more optimal pivot point is found.
[0091] In a third example of how the pivot point may be determined for a surgical robot, an arbitrary point along the length of the shaft of the instrument (e.g. at 10 cm from the attachment point, where the instrument attaches to the robot arm) is determined once the instrument tip is inserted into the port (or "trocar"). The arbitrary point on the shaft may be marked such that a user can visually place it at a desired position on the port. This point is then determined to be the pivot point.
[0092] As described above, in response to determining that the session identifier received from a surgical robot 100 in step S302 is valid for the current session, the control unit 122 can treat an indication of the pivot point stored at the surgical robot 100 (e.g. in the memory of the robot controller 214) as an indication of a valid pivot point for the surgical robot 100 in the current session. For example, in response to determining that a session identifier that has been received from a surgical robot is valid for the current session, the control unit 122 can cause that surgical robot to be put into a "trained" mode (e.g. a trained and locked mode) in which the pivot point is stored for use in the current session, without requiring a port training process to be performed for that surgical robot following the determination that the received session identifier is valid. In a trained mode, the pivot point for the surgical robot has been set, and the surgical robot is ready to be used in a surgical mode. In a locked mode, the surgical robot arm is not able to move. The use of a locked mode is a safety mechanism to prevent unintentional harm to the patient whilst the instruments are inside the patient. For example, in response to a connection failure between a surgical robot and the control unit 122 at the surgeon console, the arm of the surgical robot can be put into a locked mode, and the arm may run on battery power if the surgeon console is normally required to power the arms. It is noted that an instrument can still be detached from the surgical robot arm when the arm is in the "trained and locked mode".
[0093] Following a reboot of the control unit 122 during a surgical procedure, if a surgical robot 100 has stored an indication of a valid pivot point for the surgical robot 100 (e.g. in the memory of the robot controller 214 of that surgical robot) then that valid pivot point can be used for controlling the surgical robot in the current session, without needing to go through the calibration process again for determining the pivot point. This significantly reduces the time taken to resume surgery when the control unit 122 has been rebooted (e.g. to recover from an alarm, which may be caused by a software failure or some other problem on the surgical robotic system) during a surgical procedure.
[0094] In response to determining that the session identifier received from a surgical robot 100 in step S302 is not valid for the current session, the control unit 122 can cause a port training process to be performed to determine a pivot point for the current session for each of the surgical robots 100 in the surgical robotic system. Therefore, when the control unit 122 determines, during its initialisation, that it is starting a new session then the surgical robots 100 in the surgical robotic system 10 are calibrated to determine their pivot points, which can then be used for the subsequent surgical procedure.
[0095] As is apparent from the description provided above, when the control unit 122 is initialised it is able to distinguish between being: (i) initialised at the start of a new session, and (ii) being initialised during an existing session, e.g. due to a reboot or power cycle of the control unit. It can distinguish between these two situations by receiving a session identifier from a surgical robot in the surgical robotic system and determining whether the received session identifier is valid. If the received session identifier is not valid then this indicates situation (i), i.e. that the control unit 122 is being initialised at the start of a new session, and data stored at the surgical robots (e.g. the number of lives of the instruments of the surgical robots, and the pivot points of the surgical robots) is not treated as being valid for the current session. However, if the received session identifier is valid then this indicates situation (ii), i.e. that the control unit 122 is being initialised during an existing session, and data stored at the surgical robots (e.g. the number of lives of the instruments of the surgical robots, and the pivot points of the surgical robots) is treated as being valid for the current session.
[0096] Each session has a unique session identifier (or "session ID"), which may be an integer number. When the control unit is initialised, its session identifier is set to be a preliminary value (or "sentinel value"), which may be referred to as "SESSION_UNDECIDED", and may have a value of zero. This sentinel value indicates that the control unit has not yet made the decision to start a new session or resume a previous one. If the decision is made to start a new session, the sessionlD shall be set to the bootcounter. When recovering a session, the sessionlD shall be set to the recovered sessionlD. This scheme of setting the sessionlD preserves its use for instrument lifetime tracking without any required changes to the algorithm used to decrement the number of lives of the instruments based on the session ID.
[0097] The decision to recover or begin a session is based on system state of the control unit and the surgical robots. If the control unit connects to a surgical robot reporting a valid session ID while the control unit's session ID is 'SESSION_UNDECIDED', the control unit adopts that surgical robot's session ID, which will subsequently be sent to all connected surgical robots.
[0098] In the description above, two examples are given of the data that can be treated as being valid or invalid in step S308 or step S312: the number of lives of the instrument and the pivot point. In other examples, the data that can be treated as being valid or invalid in step S308 or step S312 may be session data for the current session, e.g. a session identifier, a session time, or a system identifier for the current session.
[0099] In another example, the data that can be treated as being valid or invalid in step S308 or step S312 may be a colour coding of a surgical robot arm. For example, each surgical robot arm in the system may have one or more LEDs which can be illuminated in a particular colour (e.g. in green, blue or pink) to facilitate their identification during a surgical procedure. For example, each arm may be illuminated with a single colour throughout the procedure even if the arm is rebooted during the procedure. At the start of a procedure the colour assigned to each robot arm is set and information indicating the colours assigned to the robot arms may be stored at the control unit 122 and may be stored at the respective surgical robots. Conventionally, when the control unit 122 is rebooted, the colour coding information will be lost at the control unit 122 and the colours may be reassigned randomly to the surgical robot arms in the session. According to examples described herein, when the control unit 122 is initialised (e.g. rebooted) during a current session, the information indicating the colours assigned to the surgical robot arms which is stored at the surgical robots may be treated as valid by the control unit 122 (in step S308) for the current session. This allows the control unit 122 to continue to use the original colours assigned to the surgical robot arms in the current session following a reboot of the control unit 122.
[0100] In another example, the data that can be treated as being valid or invalid in step S308 or step S312 may be data indicating relative positions and orientations of the surgical robots (e.g. the bases and / or arms of the robots) in the system. The relative orientations and positions between surgical robots in the system can be used to coordinate the kinematics of more than one arm and, for example, avoid clashes between arms. Additionally, this information may be used to map the frame of reference of the hand controllers and the frame of reference of each arm. This information may be stored at the control unit 122 and may be stored at the respective surgical robots. Conventionally, when the control unit 122 is rebooted, the information indicating the relative positions and orientations of the surgical robots will be lost at the control unit 122 and may need to be re-determined before the procedure can continue. However, according to examples described herein, when the control unit 122 is initialised (e.g. rebooted) during a current session, the information indicating the relative positions and orientations of the surgical robots which is stored at the surgical robots may be treated as valid by the control unit 122 (in step S308) for the current session. This allows the control unit 122 to quickly continue with the surgical operation in the current session following a reboot of the control unit 122 without needing to re-determine the information indicating the relative positions and orientations of the surgical robots.
[0101] In another example, the data that can be treated as being valid or invalid in step S308 or step
[0102] S312 may be data relating to alarm events for a surgical robot (e.g. clashes between arms, low battery indications). If a given alarm has been raised during a procedure, it may be important for the control unit 122 to know it has happened in order to apply any necessary mitigation steps. The information relating to alarm events for the surgical robots may be stored at the control unit 122 and may be stored at the respective surgical robots. Conventionally, when the control unit 122 is rebooted, the data relating to alarm events will be lost at the control unit 122. However, according to examples described herein, when the control unit 122 is initialised (e.g. rebooted) during a current session, the information relating to alarm events which is stored at the surgical robots may be treated as valid by the control unit 122 (in step S308) for the current session. This allows the control unit 122 to continue to be aware of these alarm events and to apply any mitigation steps appropriately in the current session following a reboot of the control unit 122.
[0103] In another example, the data that can be treated as being valid or invalid in step S308 or step S312 may be data indicating a last commanded position and orientation of the instrument tip, and arm wrist of a surgical robot. This data may be stored at the control unit 122 and may be stored at the respective surgical robots. Conventionally, when the control unit 122 is rebooted, the data indicating a last commanded position and orientation of the instrument tip, and arm wrist of a surgical robot will be lost at the control unit 122. However, according to examples described herein, when the control unit 122 is initialised (e.g. rebooted) during a current session, the information indicating a last commanded position and orientation of the instrument tip, and arm wrist of a surgical robot which is stored at the surgical robots may be treated as valid by the control unit 122 (in step S308) for the current session. This may allow the control unit 122 to continue to the surgical procedure in the current session following a reboot of the control unit 122, without needing to set up the surgical robot arms again and without needing to remove the instruments from the patient. The position of the instrument and arm wrist may be determined periodically by the arm controller and fed back to the central controller. It is noted that the position of the hand controllers would normally change during a reboot of the control unit. Some systems would not attempt to match the hand controller and instrument position following a reboot and would only command subsequent movement from wherever the hand controllers are when then control unit is initiated. However, other systems may require that the hand controllers start exactly where they were left before rebooting in order to continue operating. For that to be implemented the position of the hand controllers would be stored.
[0104] The methods described herein may be implemented by executing computer program code at the control unit 122. That is, the control unit 122 may comprise a computer readable storage medium having stored thereon computer readable instructions that, when executed at the control unit 122, cause the control unit to perform any of the methods described herein.
[0105] It is to be understood that the robotic system described herein could be for purposes other than surgery. For example, the robots of the robotic system could be controlled for manipulating tissue, which is not part of a patient, e.g. for manipulating tissue of a cadaver or of any other object. As another example, the robots could control a viewing instrument for viewing inside a manufactured article such as a car engine, via an inspection port.
[0106] The applicant hereby discloses in isolation each individual feature described herein and any combination of two or more such features, to the extent that such features or combinations are capable of being carried out based on the present specification as a whole in the light of the common general knowledge of a person skilled in the art, irrespective of whether such features or combinations of features solve any problems disclosed herein, and without limitation to the scope of the claims. The applicant indicates that aspects of the present invention may consist of any such individual feature or combination of features. In view of the foregoing description it will be evident to a person skilled in the art that various modifications may be made within the scope of the invention.
Claims
CLAIMS1. A control unit for controlling one or more surgical robots of a surgical robotic system, wherein the control unit is configured to, on initialisation of the control unit: receive a session identifier from one of the one or more surgical robots; determine whether the received session identifier is valid for a current session; and in response to determining that the received session identifier is valid for the current session, set a session identifier of the control unit to match the received session identifier, and cause data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot to be treated as valid data for the current session.
2. The control unit of claim 1 wherein the control unit is configured to, after setting the session identifier of the control unit to match the received session identifier, send an indication of the session identifier of the control unit to one or more of the one or more surgical robots.
3. The control unit of claim 1 or 2 wherein each of the one or more surgical robots comprises a surgical robot arm and a surgical instrument attached to the surgical robot arm.
4. The control unit of claim 3 wherein said data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot comprises an indication of a number of remaining lives of the surgical instrument of that surgical robot.
5. The control unit of claim 3 or 4 wherein said data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot comprises an indication of a pivot point, wherein the control unit is configured to use the indication of the pivot point to control said one of the one or more surgical robots to maintain an intersection between the surgical instrument of that surgical robot and the pivot point.
6. The control unit of claim 5 wherein the control unit is configured to, in response to determining that the received session identifier is valid for the current session, cause said one of the one or more surgical robots to be put into a trained mode in which the pivotpoint is stored for use in the current session, without requiring a port training process to be performed for that surgical robot following the determination that the received session identifier is valid.
7. The control unit of any preceding claim wherein each of the one or more surgical robots comprises a surgical robot arm and a surgical instrument attached to the surgical robot arm, wherein the control unit is configured to, in response to determining that the received session identifier is not valid for the current session, cause a port training process to be performed to determine a pivot point for the current session for each of the one or more surgical robots, wherein the control unit is configured to control each of the one or more surgical robots to maintain an intersection between the surgical instrument of that surgical robot and the pivot point determined for that surgical robot.
8. The control unit of any preceding claim wherein the control unit is configured to, if it is determined that the received session identifier is valid for the current session, receive an indication of a session time from one of the one or more surgical robots.
9. The control unit of claim 8 wherein the control unit is configured to, if it is determined that the received session identifier is valid for the current session: determine an updated session time which excludes downtime of the control unit; and send an indication of the updated session time to each of the one or more surgical robots.
10. The control unit of any preceding claim wherein the control unit is configured to: maintain a bootcounter which indicates a number of times that the control unit has been initialised; and on initialisation of the control unit, in response to determining that the received session identifier is not valid for the current session, set the session identifier of the control unit to match the bootcounter, and cause said data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot to be treated as invalid data for the current session.
11. The control unit of any preceding claim wherein the surgical robotic system is configured to set a session identifier at each of the one or more surgical robots to be a preliminary value at the start of each session to indicate that the session identifier at that surgical robot still needs to be decided for the current session, and wherein the control unit is configured to, on initialisation of the control unit, determine whether the session identifier received from one of the one or more surgical robots is valid for the current session by determining whether the received session identifier is equal to the preliminary value.
12. The control unit of any of claims 1 to 10 wherein the control unit is configured to: maintain a bootcounter which indicates a number of times that the control unit has been initialised; and on initialisation of the control unit, determine whether the session identifier received from one of the one or more surgical robots is valid for the current session by determining whether the received session identifier is less than a minimum possible value of the bootcounter.
13. The control unit of any preceding claim wherein the initialisation of the control unit is part of a process of power cycling the control unit during the current session.
14. A surgical robotic system comprising: one or more surgical robots; and the control unit of any preceding claim for controlling the one or more surgical robots.
15. The surgical robotic system of claim 14 wherein each of the one or more surgical robots comprises a surgical robot arm and a surgical instrument attached to the surgical robot arm, wherein the surgical robotic system is configured to, in response to determining that the received session identifier is not valid for the current session, decrement an indication of a number of remaining lives of each of the one or more surgical instruments attached to the one or more surgical robots.
16. The surgical robotic system of claim 14 or 15 wherein each of the one or more surgical robots comprises a surgical robot arm and a surgical instrument attached to the surgical robot arm, wherein the surgical instrument of a surgical robot is associated with a number of remaining lives, and wherein the surgical robotic system is configured to, in response to the control unit establishing a connection with that surgical robot, determine whether to decrement the number of remaining lives of the surgical instrument of that surgical robot in dependence on the session identifier of the control unit.
17. The surgical robotic system of claim 16 wherein a session identifier is stored on the surgical instrument, and wherein the surgical robotic system is configured to decrement the number of remaining lives of the surgical instrument if the session identifier of the control unit does not match the session identifier stored on the surgical instrument.
18. The surgical robotic system of claim 16 or 17 wherein a system identifier, a session identifier and a session time indication are stored on the surgical instrument, and wherein the surgical robotic system is configured to decrement the number of remaining lives of the surgical instrument if any of: (i) the session identifier of the control unit does not match the session identifier stored on the surgical instrument, (ii) a system identifier of the surgical robotic system does not match the system identifier stored on the surgical instrument, or (iii) the session time indication stored on the surgical instrument is more than a maximum amount of time older than a current session time of the current session on the surgical robotic system.
19. The surgical robotic system of any of claims 16 to 18 wherein a system identifier, a session identifier and a session time indication are stored on the surgical instrument, and wherein the surgical robotic system is configured to not decrement the number of remaining lives of the surgical instrument if: (i) the session identifier of the control unit matches the session identifier stored on the surgical instrument, (ii) a system identifier of the surgical robotic system matches the system identifier stored on the surgical instrument, and (iii) the session time indication stored on the surgical instrument is not more than amaximum amount of time older than a current session time of the current session on the surgical robotic system.
20. A method of operating a control unit for controlling one or more surgical robots of a surgical robotic system, the method comprising, on initialisation of the control unit: receiving a session identifier from one of the one or more surgical robots; determining whether the received session identifier is valid for a current session; and in response to determining that the received session identifier is valid for the current session, setting a session identifier of the control unit to match the received session identifier, and causing data that is stored at said one of the one or more surgical robots relating to the state of that surgical robot to be treated as valid data for the current session.
21. A computer readable storage medium having stored thereon computer readable instructions that, when executed at a control unit of a surgical robotic system, cause the control unit to perform the method of claim 20.
Citation Information
Patent Citations
Enabling secure data exchange between a robotic surgical system and surgical tools via near field communication (NFC)
US20220249198A1
Surgical robotic system and method for restoring operational state
US20240131723A1
Method of surgical instrument management, information processor, management system, surgical instrument and surgical robot
US20240207009A1
AU2022309140A1