Smart, wearable medical devices

The wearable medical data logger addresses security and data integrity issues by implementing layered encryption and validation processes, ensuring secure and reliable data transmission and operation.

WO2026052626A1PCT designated stage Publication Date: 2026-03-12INVIVO BIONICS AS
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-02
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing wearable medical devices face challenges in ensuring secure data transmission, preventing unauthorized use, and maintaining data integrity, particularly when connected to mobile networks, which can be vulnerable to hacking and interference.

Method used

A wearable or insertable medical data logger with integrated power, data collection, and transmission modules, utilizing layered encryption, digital certificates, and validation processes to ensure secure data transmission and correct usage, including initial and subsequent activation checks.

Benefits of technology

Enhances data security and safety by validating the data logger before transmission, preventing unauthorized use, and ensuring correct operation, thus protecting patient data from misuse and ensuring reliable, secure data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025074962_12032026_PF_FP_ABST
    Figure EP2025074962_12032026_PF_FP_ABST
Patent Text Reader

Abstract

There is provided a wearable or insertable data logger for monitoring a subject. The data logger comprises: an integrated power source; a data collection module configured to obtain data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject at a sampling rate; a data transmission module configured to wirelessly transmit the data obtained by the data collection module to a remote computer at a transmission interval; and a processor configured to: monitor a power level of the integrated power source; and vary at least one of the sampling rate at which data is obtained from the sensor by the data collection module or the transmission interval at which data is transmitted to the remote computer by the data transmission module based on the power level of the integrated power source.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SMART, WEARABLE MEDICAL DEVICES

[0002] TECHNICAL FIELD

[0003] The present application relates to wearable or insertable data loggers, medical devices, systems, and computer-implemented methods for monitoring a subject.

[0004] BACKGROUND

[0005] Medical monitoring has traditionally been performed in hospital settings. While it was once only possible to perform such measurements in hospitals, improvements have allowed patients to use some monitoring systems at home, with data being collected and relayed to clinicians. For example, blood pressure monitors are now common in homes, and patients may make notes of blood pressure readings to submit to a clinician. At-home monitoring systems are beneficial for both the hospital and the patient, because they reduce the burden placed on each. A hospital does not need to provide dedicated space or staff, and the patient is provided with greater flexibility because they do not need to travel to and from the hospital.

[0006] The success of at-home monitoring has led to further improvements. Wearable devices allow patients to move freely without being tethered or attached to bulky equipment. Some medical devices, such as blood sugar monitors used by diabetics, have connectivity for communicating with a paired mobile device such as a user’s mobile phone, which allows data to be collected and transmitted more regularly via the internet, such as over a wi de-coverage mobile network or a local Wi-Fi network. Such improvements enable longer-term monitoring, as well as monitoring in common day-to-day settings and situations.

[0007] The introduction of at-home monitoring and wearable devices for monitoring some conditions and physiological parameters provides benefits, but can also present new challenges for patients and hospitals, such as how to ensure that the devices are used safely and securely, how to transmit data efficiently and securely, and how to gather sufficient, relevant data. Particularly, transmitting data via a mobile device introduces an additional device where data needs to be kept safe. Some networks used by mobile devices may also be liable to hacking or other interference. It has been suggested that medical devices could be connected directly to a mobile network to remove the mobile device altogether. While this may eliminate security concerns relating to mobile devices, there remain challenges to address, including data security in relation to the mobile network, and how introducing components for connecting to a mobile network into a medical device affect its operation, especially in relation to power usage. For conditions and parameters for which at-home monitoring and wearable devices have not previously been developed or used, there is a desire to enable their use. SUMMARY

[0008] The techniques described herein address at least some of the above challenges. Among these techniques are methods and systems utilizing validation of the data logger to enhance secure data transmission and safe use of a medical device. There are provided methods and systems that deploy layered encryptions, digital certificates to provide improved security, and / or tokens, particularly JSON web tokens, to provide secure access to data and secure activation of a medical device. There are also methods and systems in which operation of a data logger is varied depending on a power level of the data logger, so that sufficient data can be gathered. Although these are presented as different aspects, the features described in relation to each may be combined with other aspects, and will bring the same associated benefits to the new aspect.

[0009] The following aspects focus on techniques relating to validation. According to an aspect, there is provided a wearable or insertable medical data logger for monitoring a subject. The data logger comprises: an integrated power source; a data collection module for obtaining data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject; a data transmission module for wirelessly transmitting data; and a processor. The processor is configured to, upon an initial activation of the data logger: establish a first network connection for communication with at least one first remote computer using the data transmission module; validate the data logger by communicating with the at least one first remote computer via the first network connection; establish a second network connection for communication with at least one second remote computer using the data transmission module; and transmit data comprising measurements of the physiological parameter from the sensor obtained by the data collection module to the at least one second remote computer via the network connection based on the second network connection being established and the data logger being validated.

[0010] Providing a medical data logger that is first validated before subject data is transmitted results in improved data security and safety for the subject. Validating the data logger provides a safety check to ensure that the data logger is being used correctly. Validating the data logger with a first remote computer allows the first remote computer and / or an operator associated with the first remote computer to verify that the activation of the data logger is correct. Because the validation is performed with a remote computer and data transmission is dependent on such validation, it may be more difficult to tamper with the data logger to use it in an incorrect way.

[0011] By making tampering difficult, and impeding incorrect usage of the data logger, the subject may be protected from misuse of their personal data and from misuse of the data logger and any sensors to which it connects.

[0012] Validation prior to data transmission can also offer other benefits. Such benefits may be to clinicians utilizing the data logger, by ensuring, through the validation, that the data logger is operating correctly and / or has been assigned to the correct patient. Further benefits include being able to prevent use of recalled data loggers or systems with connected single-use parts that are intentionally or inadvertently being reused. The use of a standalone network connection enables remote validation and activation of the data logger, which results in faster and less complex setup.

[0013] The data logger may be referred to as a data collector, a data module, or a data recorder. As a medical data logger, the data logger is suitable for medical-grade monitoring of the subject, and may be particularly for activation, installation, and / or use by a qualified clinician. The data logger may be part of a medical device.

[0014] The term ‘wearable’ is intended to mean that the data logger can be attached to and worn by the subject. Wearable devices or apparatus are affixed to a part of the subject and move with movement of the subject. A wearable device may be an ambulatory device, meaning that the subject is able to move while the device is in use. The data logger may therefore be both ambulatory and wearable.

[0015] The term ‘insertable’ is intended to mean that the data logger may be suitable for implanting or inserting within the subject, such as beneath a skin surface of the subject or within or on an internal organ of the subject. Insertable devices may also be ambulatory devices.

[0016] The data logger may also be referred to as being an ‘in vivo’ data logger, because it is for use on living subjects. The data logger may be referred to as being a ‘standalone’ data logger, because it may be unattached to other data logging devices or systems, and communicates wirelessly with them. A standalone data logger may be part of a standalone medical device, which is one that is wholly provided on or in the subject.

[0017] The integrated power source may comprise a battery or cell, such as a lithium ion battery. The integrated power source may be sealed within a housing of the data logger and may be inaccessible from outside the housing. The power source may be a non-rechargeable power source or the data logger may lack componentry for recharging the power source. In other words, the power source may be sealed within the housing without electrical connection to an outside of the housing. The power source may be connected to and configured to provide power to the data transmission module, the data collection module, the processor, and the memory. The integrated power source, data collection module, data transmission module, and processor may be sealed within or provided within the housing. In other words, the data logger may comprise a single unit.

[0018] The sensor may be a sensor for insertion into the subject, and may be referred to as an in vivo sensor. The sensor may be for insertion into or for monitoring an organ of a subject. The sensor may be a pressure sensor, an ultrasound sensor, an image sensor, an electrochemical sensor, such as for measurement of oxygen, pH, or glucose, or another form of biosensor. The sensor may for insertion into a urinary bladder, a heart, a lung, an artery, a vein, or another organ or structure of the subject.

[0019] The data collection module may be configured to obtain data from a plurality of sensors provided on or inserted in the subject. The plurality of sensors may be configured to measure one physiological parameter of the subject or may be configured to measure a plurality of physiological parameters. The data logger may include one or more ports for connecting to the sensor, such that the data logger and the sensor can be separated. Alternatively, the sensor may be fixed to and therefore integral with the data logger.

[0020] The data logger performs the validation upon an initial activation of the data logger. The initial activation may be a first activation, an activation within a threshold number of activations, or an activation within an initialization period. The initialization period may be a predetermined time period or may be a period between a first activation and the data logger entering a normal data collection mode. An activation after the initialization period or after the first activation may not be an initial activation. Activation may comprise a powering up or start-up of the data logger. Disconnection and reconnection of the power source may result in deactivation and reactivation. An initial activation may be an activation that does not follow a termination of operation of the data logger, i.e. one that happens before the data logger has experienced or recorded a termination or termination event. A termination of operation may occur when a power source is disconnected during a normal data collection mode of the data logger, in response to a command, operation, or interaction received by the data logger over a network connection or from a local device operated by a clinician, when the sensor is removed from the subject, when the sensor is disconnected from the data logger, or when the data logger or wider medical device is removed from the subject. A termination of operation may occur as a result of the data logger being configured into a termination mode. The termination mode may follow a normal running mode, in which data is gathered and transmitted to the at least one second remote computer.

[0021] Some data may be transmitted during the initialization period, for the purposes of testing the sensor and the data logger. The data may be transmitted to the first remote computer or to the second remote computer via the corresponding network connection. Data transmitted to the first remote computer or the second remote computer during the initialization period may be transmitted to a further computer operated by or available to the clinician to view the data output prior to normal running of the data logger and wider medical device.

[0022] Network connections are established using a wireless transmission protocol over a wide- coverage mobile network, which may be referred to as a cellular network or more particularly a broadband cellular network. Examples of networks that may be used are 4G and 5G. The network may be a low-power, wide-area network. The data logger may be configured to establish a network connection using an Intemet-Of-Things (loT) communication protocol or standard. For example, a network connection may be established using the NB-IoT protocol or the LTE-M protocol. Such protocols enable higher data transmission and lower power usage. Networks using such protocols may be protected for use by machines, rather than for use by devices using voice. In some aspects of the present application, there may be provided a wearable or insertable medical data logger for monitoring a subject comprising: a data collection module configured to obtain measurements of a physiological parameter from a sensor inserted in or placed on the subject, and a data transmission module for wirelessly transmitting data comprising the measurements to at least one remote computer via a low- power, wide-area network, which may optionally utilize an loT communication protocol such as those described above.

[0023] Establishing a network connection may include establishing communication with a cellular base station. Measurements and other data are transmitted wirelessly by the data transmission module via respective network connections.

[0024] The first network connection and the second network connection may be the same network connection. In other words, establishing the second network connection may comprise confirming or determining that the first network connection remains active.

[0025] Alternatively, the first network connection may be different to the second network connection. The first and second network connections may be different by being established at different times, via a different connection path, or both. In examples, the first network connection and the second network connection may be established using a first connection path, but the first network connection may be established at a first time and the second network connection may be established at a second time that is later than the first time and that is after termination of the first network connection. In examples, the first network connection and the second network connection may be established at a first time, with the first network connection using a first connection path and the second network connection using a second connection path. In other examples, the first network connection and the second network connections may be established at different times and using different connection paths. Establishing the second network connection may comprise determining that the first network connection is inactive.

[0026] Where the first network connection and the second network connection use the same connection path, this may mean that communication is established with the same cellular base station and / or that the same transport layer or layers are used. The paths from the cellular base station to the first and second remote computers may be different.

[0027] The first network connection may use a first communication protocol and the second network connection may use a second communication protocol that is different to the first communication protocol.

[0028] The at least one first remote computer and the at least one second remote computer may be different computers or may be the same computer. Remote computers are computers that are separate from the data logger and are communicated with via a wireless network connection. The remote computers may comprise a server or a plurality of servers. The second remote computer may comprise or form part of a data storage system. Data transmitted to the data storage system may be stored for later access. The data storage system may be accessible to the first remote computer, for the purpose of preparing reports on the data or for otherwise accessing the data subsequently. Validating the data logger may comprise: transmitting data identifying the data logger to the at least one first remote computer; and receiving response data from the at least one first remote computer indicating that the activation of the data logger is a valid activation of the data logger.

[0029] Identifying the data logger to the at least one first remote computer enables the at least one first computer to check records concerning the data logger, and confirm its validity. This provides control over how the data logger is used, to prevent unsanctioned or prohibited actions. Utilizing identifying data enables the data logger’s use to be controlled more specifically.

[0030] The data logger may be configured to automatically send said identifying data to the at least one first remote computer upon activation, to ensure that said control is maintained.

[0031] The at least one first remote computer may have access to or may store records relating to a plurality of data loggers. The at least one first remote computer may check the records for identifying data matching the identifying data sent by the data logger. Upon finding one or more matching records, the at least one first remote computer may check associated data, such as data indicating whether use of the data logger is permitted, whether the activation of the data logger is an initial activation, whether the data logger has been recalled, etc. A plurality of matching records relating to different identifying data may be identified. The records stored by or accessible to the first remote computer may associate identifying data for a sensor with identifying data for a data logger. The same sensor may be associated with a group of data loggers.

[0032] Upon receiving data from the data logger, the at least one first remote computer may be configured to update a record associated with the data logger.

[0033] The at least one first remote computer may check the record associated with the data logger to determine whether the data logger has been designated for activation by the clinician prior to the activation. The at least one first remote computer may be configured to receive a designation for activation from the clinician, and to update its record associated with the data logger. Validation may comprise determining that the data logger has been designated for activation prior to the activation. Such a step may further improve security around how the data logger is used, as the data logger will only be able to be validated if it has been pre-authorized in this way.

[0034] The response data may be data indicating that the activation of the data logger is an initial activation of the data logger or data indicating that the data logger is validated. Where the responses data does not directly identify that the data logger is validated, the data logger may be configured to determine, based on the response data, that it is valid or validated.

[0035] The data logger may be configured to transmit additional data to the at least one first remote computer. The additional data may comprises data identifying a clinician or group of clinicians installing or activating the data logger, data identifying a clinical setting in which the data logger is being installed or activated, such as a hospital name or number, and / or data associated with the subject. The additional data identifying the clinician or a clinical setting may comprise a token, such as a JSON web token. The token may be issued to the clinician, a group of clinicians, or the clinical setting along with the data logger. The additional data may be provided by the clinician to the data logger for transmission during activation, using an activation device such as a local computer or mobile device. The data logger and an identifier may be provided to the physician in an offline process, and the token may be generated upon receipt of the identifier and an identification of the data logger from the physician. The data associated with the subject may comprise a number associated with a patient journal of the subject or an internal reference for the subject. The data associated with the subject may be data that is not personally identifiable information.

[0036] Validating the data logger may comprise determining that the firmware installed on the data logger is an acceptable version of the firmware.

[0037] Validating the data logger based on firmware ensures that the data is securely transmitted and that risks associated with interception or data access are reduced. Ensuring an acceptable version of the firmware may also ensure that data is transmitted in the correct format.

[0038] Validating the data logger may further comprise transmitting data relating to a firmware installed on the data logger to the at least one first remote computer and receiving response data from the at least one first remote computer relating to the firmware. The data relating to the firmware installed on the data logger may indicate a version of the firmware or schema used by the firmware for data transmission. The response data may comprise an indication that the firmware installed on the data logger is a latest version of the firmware or that it is an acceptable version of the firmware.

[0039] Validating the data logger may comprise receiving data from the at least one first remote computer relating to a firmware. The data may be data indicating a latest version of the firmware for use by the data logger, data indicating a plurality of acceptable versions of the firmware for use by the data logger, data indicating a schema used by the latest version of the firmware, or data indicating that the firmware installed on the data logger is the latest version, that it is an acceptable version, or that it uses an acceptable schema. If the data logger receives data indicating a latest version, acceptable versions, or a schema, it may compare the version, versions, or schema to its own version or schema to determine whether its firmware is acceptable.

[0040] Validating the data logger may comprise, prior to determining that the firmware installed on the data logger is an acceptable version of the firmware: determining that the firmware installed on the data logger is not an acceptable version of the firmware; and updating the firmware to be an acceptable version of the firmware.

[0041] It may be determined that the firmware is not an acceptable version based on data received from the at least one first remote computer. Updating the firmware may comprise receiving the latest version of the firmware from the at least one remote computer or accessing a latest version of the firmware from a repository. Updating the firmware may comprise receiving a schema associated with a latest version or acceptable versions of the firmware and updating the schema of the firmware of the data logger to match the received schema.

[0042] The processor may be further configured to, upon the initial activation of the data logger, validate the sensor, wherein the data comprising the measurements of the physiological parameter from the sensor obtained by the data collection module is transmitted to the at least one second remote computer via the second network connection based on the sensor being validated.

[0043] Validating a sensor may also provide improved safety for the subject and ensure data quality. Requiring a valid sensor to be used may prevent untested sensors or unauthorized sensors from being used with the data logger. The sensor may be validated by the data logger or may be validated by communication with the at least one first remote computer.

[0044] The sensor may comprise identification data. The data logger may comprise memory in which identification data for a sensor corresponding to the data logger is stored. Validating the sensor may comprise: accessing the identification data from the sensor; retrieving the identification data from the memory of the data logger; and determining that the identification data from the sensor and from the memory are matching.

[0045] In this way, the data logger and the sensor are linked such that they can be used together. The data logger may validate the sensor locally. The data logger may store identification data relating to a plurality of corresponding sensors. The sensor may be configured to provide the identification data along with data relating to the physiological measurements. The identification data may be transmitted with the data to the at least one second remote computer. The identification data may also be transmitted with test data to the at least one first remote computer. The at least one first remote computer and / or the at least one second remote computer may also be configured to validate the sensor.

[0046] The identification data may comprise a unique identifier of the sensor and sensor characterization data for the sensor.

[0047] Validating the sensor may comprise determining that both of the unique identifier and the sensor characterization data from the sensor matches corresponding data retrieved from the memory. Utilizing two pieces of identifying data enables a higher standard of security.

[0048] Sensor characterization data may be used to transform electrical readings from the sensor to usable measurements in a desired unit. The characterization data may be used to provide a transformation algorithm or equation that enables said transformation. The sensor characterization data may comprise a mapping of electrical readings to usable measurements. In other words, the sensor characterization data allows the sensor to be used to gather useful measurements of the physiological parameter. The sensor characterization data may be referred to as calibration data. Sensor characterization data may therefore be specific or unique to a particular sensor. If there is a mismatch between the sensor characterization data provided by the sensor and stored by the data logger, then sensor readings may not be useful. The sensor characterization may be used by the data collection module upon receipt of the data to convert electrical readings to measurements of the physiological parameter. The data logger may be configured to send the raw measurements, i.e. the electrical readings, along with the unique identifier to the second remote computer, and the second remote computer may be configured to access characterization data to convert the data to measurements in the desired unit. Alternatively, the data logger may send the raw measurements, the unique identifier, and the measurements in the desired unit, which have been converted by the data logger from the raw measurements using the characterization data. The second remote computer may also convert the raw measurements to measurements in the desired data, to enable the data received to be validated or checked.

[0049] The processor may be configured to, upon a subsequent activation of the data logger after the initial activation of the data logger: establish a third network connection for communication with the at least one first remote computer using the data transmission module; determine that the data logger is invalid by communicating with the at least one first remote computer via the third network connection; and prevent transmission of data to the at least one second remote computer based on the data logger being determined to be invalid.

[0050] In other words, the data logger may be deemed invalid upon an activation that does not meet particular requirements. The data logger may be deemed invalid to prevent re-use of the data logger with a different patient.

[0051] The subsequent activation may be an activation after a termination of operation of the data logger, such as those described above. The processor may be configured to determine that a termination of operation of the data logger has occurred prior to the subsequent activation. The termination of operation may be determined based on data exchanged with the at least one first remote computer. Based on the termination, the processor may be configured to determine that the data logger is invalid.

[0052] The processor may also, or alternatively, be configured to prevent collection of data from the sensor based on the data logger being determined to be invalid. The processor may be configured to perform other actions to prevent a third party from accessing the data.

[0053] A data logger may be determined to be invalid if the at least one first remote computer includes a record of a prior activation and / or a prior termination of operation. The at least one first remote computer and / or the data logger may be configured to differentiate between initial activations, reactivations during a normal running mode such as when there is a disruption to a sensor signal or to a power source, and activations after a termination of operation, which may involve ceasing of a normal running mode. The data logger may therefore be a single-use data logger, meaning that it is for use gathering and logging data relating to a single subject only.

[0054] These actions provide yet further increased security for data and improved safety of the subject by preventing unauthorized re-use of a data logger.

[0055] The data transmitted to the at least one second remote computer may be encrypted by a first encryption and by a second encryption that is different to the first encryption.

[0056] The layered encryption applied ensures that the data is protected during transmission, as well as during gathering. This is particularly useful for a data logger that is wirelessly transmitting data across a network connection, to ensure that sensitive data belonging to the subject cannot be read by third parties even with physical access to the data logger. Network connections involve data being directed through different connections and making different hops to reach the endpoint, so it is important to prevent data being stolen and intercepted utilizing tools such as encryptions. Having two different encryptions may allow receipt of the data by one second remote computer via the relatively insecure network connection, with that second remote computer performing a first decryption, and transmission to another second remote computer over a more secure connection for analysis or storage of the data, where the second remote computer performs the second decryption. Splitting the decryptions across different computers, and therefore requiring different keys to be used at different locations to correctly decrypt the data, further enhances the security afforded to the data.

[0057] To further protect the data, no identifying data relating to the subject may be sent with the data.

[0058] The first encryption may be an encryption of the data by the data logger prior to transmission, once the data to be transmitted has been determined. Encrypting using a first encryption that is different to the second encryption performed via the secure channel ensures that even if data is intercepted while being sent in the secure channel, it cannot be easily accessed.

[0059] The processor may be configured to determine data to be transmitted to the at least one second remote computer. The process may be configured to encrypt the data to be transmitted by the first encryption to provide first encrypted data.

[0060] The data to be transmitted may be determined from a memory of the data logger. The data may be stored in the memory, which may comprise a memory card such as an SD card. The data may be stored as one or more blocks of data. The data may be written into a buffer as it is obtained from the sensor by the data collection module. The data in the buffer may be stored in the memory as a block of data. The data in the buffer may subsequently be overwritten using data obtained from the sensor.

[0061] The data to be transmitted may be determined from the memory. The data to be transmitted may be any data after a previously transmitted block. The data to be transmitted may comprise a plurality of blocks of data, which may be referred to as data blocks, or a single data block. The data to be transmitted may form a packet of data comprising a block or a plurality of blocks. The packet of data may be encrypted using the first encryption.

[0062] The data to be transmitted may also be encoded into a Base64 format for whenever binary payloads are not accepted by the network involved.

[0063] The data logger may be configured to establish a secure channel with the remote computer according to a secure channel protocol via the second network connection. The second encryption and the transmission of the data may be performed according to the secure channel protocol and via the secure channel.

[0064] Establishing a secure channel provides security when transmitting the data from interception and manipulation. As the data logger is a wearable or implantable data logger, it may not be possible to directly transmit the data to the second remote computer, and the data may be transmitted through various third parties before reaching the second remote computer. Accordingly, the data may be subj ect to manipulation during sending. A secure channel may enable manipulation to be identified, by using message validation and / or message authentication.

[0065] The secure channel protocol may be a secure shell protocol (SSH), transport layer security (TLS), Hypertext Transfer Protocol Secure (HTTPS), or another suitable protocol. MQTT or HTTP may be used to transmit data in some examples.

[0066] The data may comprise values for measurements of the physiological parameter, and the values may be encoded prior to transmission based on a predefined data transform or a predefined data structure.

[0067] In other words, the values may be encoded by reducing their size based on an algorithm or transform, or with reference to an index, a mapping, a library, or another structure that is accessible to the data logger and to a receiving computer, such as a second remote computer. In this way, security may be improved as the data transform or the data structure is required to decode and interpret the data.

[0068] The use of a predefined data transform or data structure may allow for reductions in the amount of data to be transmitted. For example, where the values comprise large numbers, sending these large numbers may be inefficient and computationally expensive. If, instead, the values are determined based on a data transform or a data structure, the encoded values may occupy less space within the data, making the storage of those values and their transmission more efficient and computationally light.

[0069] The values may be encoded based on the predefined data transform or data structure to be relative to a reference value. A data transform may transform the value based on the reference value, i.e. by subtracting the reference value from the value. A predefined data structure may comprise a mapping between values and encoded values based on the reference value.

[0070] The data obtained from the sensor may be arranged into one or more data blocks for transmission to the at least one second remote computer. Each data block may have a predefined binary format. The binary format may also provide enhanced security for the data, as knowledge of the binary format will also be required to correctly decode the data.

[0071] The data logger may store a first digital certificate and a second digital certificate. The first network connection may be established using the first digital certificate. The second network connection may be established using the second digital certificate.

[0072] The first network connection and the second network connection may be cellular network connections.

[0073] According to an aspect, there is provided a medical device comprising a data logger as described above and a sensor for measuring the physiological parameter.

[0074] According to an aspect, there is provided a computer-implemented method for monitoring a subject using a wearable or insertable medical data logger. The computer-implemented method comprises, upon an initial activation of the data logger: establishing a first network connection for communication with at least one first remote computer using a data transmission module of the data logger; validating the data logger by communicating with the at least one first remote computer via the first network connection; establishing a second network connection for communication with at least one second remote computer using the data transmission module; and transmitting to the at least one second remote computer via the second network connection based on the second network connection being established and the data logger being validated, the data comprising measurements of a physiological parameter obtained by a data collection module of the data logger from a sensor inserted in or placed on the subject. Features relating to the data logger described above may be applied to the computer-implemented method.

[0075] According to an aspect, there is provided a wearable or insertable medical data logger for monitoring a subject .The data logger comprises: an integrated power source; a data collection module for obtaining data comprising measurements of the physiological parameter from the sensor; a data transmission module for wirelessly transmitting data; and a processor. The processor is configured to, upon a subsequent activation of the data logger after an initial activation of the data logger: establish a first network connection for communication with at least one first remote computer using the data transmission module; at least one of: determine that the data logger is invalid by communicating with the at least one first remote computer via the first network connection; or determine that the sensor is invalid; and prevent transmission of data to at least one second remote computer based on at least one of the sensor or the data logger being determined to be invalid.

[0076] Preventing data transmission, and therefore use of the data logger and / or sensor, provides enhanced data security. This is particularly useful as the data logger utilizes network connections to transmit data. This also provides improvements over systems that use mobile devices to read and transmit data, as the data logger can, in this way, prevent any data leakage. The data that is prevented from being transmitted may be data obtained by the sensor or all data. In some examples, upon determining that one of the sensor or the data logger is invalid, the processor may be configured to cause a message to be sent to the at least one first remote computer and / or to the at least one second remote computer.

[0077] The processor may be configured to prevent data being obtained from the sensor by the data collection module, and / or prevent storage of said data in a memory of the data logger.

[0078] Determining that the data logger is invalid may comprise: transmitting data identifying the data logger to the at least one first remote computer; and receiving response data from the at least one first remote computer indicating that the activation of the data logger is an invalid activation of the data logger.

[0079] The sensor may comprise identification data. The data logger may comprise memory in which identification data for a sensor corresponding to the data logger is stored. Determining that the sensor is invalid may comprise: accessing the identification data from the sensor; retrieving the identification data from the memory of the data logger; and determining that the identification data from the sensor and from the memory are not matching. Features described above in relation to other aspects may also be applied to this aspect.

[0080] According to an aspect, there is provided a medical device comprising a data logger as described above and a sensor for measuring the physiological parameter.

[0081] According to an aspect, there is provided a computer-implemented method for monitoring a subject using a wearable or insertable medical data logger. The computer-implemented method comprises, upon a subsequent activation of the data logger after an initial activation of the data logger: establishing a first network connection for communication with at least one first remote computer using a data transmission module of the data logger; at least one of: determining that the data logger is invalid by communicating with the at least one first remote computer via the first network connection; or determining that a sensor that is inserted in or placed on the subject and that is in communication with a data collection module of the data logger is invalid; and preventing transmission of data to at least one second remote computer based on at least one of the sensor or the data logger being determined to be invalid. Features described above in relation to other aspects may also be applied to this aspect.

[0082] The following aspects focus on techniques relating to encryption. According to an aspect, there is provided a wearable or insertable medical data logger for monitoring a subject. The data logger comprises: an integrated power source; a data collection module for obtaining data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject; a data transmission module for wirelessly transmitting data; a processor, and a memory connected to the data collection module and the processor. The data logger is configured to: obtain, by the data collection module, data comprising measurements of a physiological parameter from the sensor; encrypt the data by a first encryption to form first encrypted data; encrypt the first encrypted data by a second encryption that is different to the first encryption to form second encrypted data; and transmit, from the data transmission module, the second encrypted data to a remote computer.

[0083] As described in relation to earlier aspects, providing dual data encryption ensures that data is securely transmitted. This is particularly useful for a data logger that is wirelessly transmitting data, to ensure that sensitive data belonging to the subj ect cannot be read by third parties. Wireless connections may involve data being directed through different connections and making different hops to reach the endpoint, so it is important to prevent data being stolen and intercepted utilizing tools such as encryptions. Having two different encryptions may allow receipt of the data by one second remote computer via the relatively insecure network connection, with that second remote computer performing a first decryption, and transmission to another second remote computer over a more secure connection for analysis or storage of the data, where the second remote computer performs the second decryption. Splitting the decryptions across different computers, and therefore requiring different keys to be used at different locations to correctly decrypt the data, further enhances the security afforded to the data.

[0084] The data logger may be configured to store the data obtained from the sensor in one or more data blocks in the memory and to form a data packet comprising at least one of the one or more data blocks. At least part of the data packet may be encrypted by the first encryption.

[0085] The data packet may comprise a header and a payload. The payload may comprise the one or more data blocks. The payload may be encrypted, while a header or metadata may be unencrypted.

[0086] The data logger may be configured to determine the data to be transmitted in each data packet. Determining the data to be transmitted may comprise selecting or identifying one or more data blocks in the memory. The data blocks may be the data blocks written to memory since a previous transmission. The memory may comprise a cache or buffer, which may be volatile or non-volatile storage, and a further storage, which may be a persistent or non-volatile storage. Each data block may be formed in the cache or buffer and transferred to the further storage once complete. A next data block formed in the cache or buffer may overwrite the previous block, whereas the blocks may be stored sequentially in the further storage. Data blocks for forming the data packet may be formed from data blocks stored in the memory and / or the data block being written in the cache or buffer.

[0087] The data blocks may have a predefined binary format. Each data block may include a single timestamp and an indication of a sampling rate of the data.

[0088] The data blocks may comprise a plurality of measurements or values for the physiological parameter. Providing a single timestamp and the sampling rate for each block may enable a reduction in the size of the data to the transmitted because a timestamp does not have to be encoded for each value in the data block. This may effectively shift the burden from the data logger, which may have small computational power, to the remote computer, which may have a larger computational power. The data logger may be configured to establish a secure channel with the remote computer according to a secure channel protocol. The second encryption and transmission of the data may be performed according to the secure channel protocol and via the secure channel.

[0089] Establishing a secure channel provides a secure second encryption, as well as further benefits relating to message validation and authorization as described above.

[0090] The data logger may store a digital certificate. The digital certificate may be used to establish the secure channel. Digital certificates further improve the security of data transmission by indicating whether data has been tampered with during transmission. The digital certificate may be a key certificate. The digital certificate may include a digital signature.

[0091] The data may comprise values for measurements of the physiological parameter. The values may be encoded prior to the first encryption based on a predefined data transform or a predefined data structure. The predefined data transform or data structure may be a predefined data transform of data structure as described above.

[0092] The second encrypted data may be transmitted to a remote computer via a cellular network connection. As described above, the cellular network connection may be a 3G, 4G, 5G, or other network connection. Where the transmission is via a cellular network connection, the use of two encryptions is particularly useful, to prevent intercepted data from being interpreted.

[0093] Features of earlier aspects may be applied to the present aspect.

[0094] According to an aspect, there is provided a system for monitoring the subject comprising: the data logger of any preceding claim; and the remote computer, the remote computer being configured to wirelessly receive the second encrypted data from the data logger.

[0095] The remote computer may be a first remote computer configured to: decrypt the second encrypted data by a first decryption to retrieve the first encrypted data; and transmit the first encrypted data to a second remote computer.

[0096] The first remote computer may be the computer with which a secure channel was formed to enable the second encryption. The first remote computer may have performed a key exchange with the data logger as part of establishing the secure channel to enable the second encryption and the first decryption.

[0097] The system may comprise the second remote computer. The second remote computer may be configured to: receive the first encrypted data from the first remote computer; and decrypt the first encrypted data by a second decryption to retrieve the data comprising the measurements of a physiological parameter.

[0098] Providing two separate remote computers, each of which are able to perform one of two decryptions provides further data security, because no single computer is able to decrypt the data. The first remote computer may be a platform for receiving data from a plurality of different sources and may have lower security than the second remote computer. Accordingly, the dual encryption ensures that the data is not accessible from the first remote computer, and is only accessible to the second remote computer.

[0099] Where the data has been encoded based on a predefined data structure, such as an index, or a predefined data transform, the second remote computer may be configured to decode the data based on the predefined data transform or data structure to retrieve the values. The predefined data transform or data structure may be stored on the data logger, and may be stored on and / or accessible to the second remote computer. The second remote computer may be further configured to decode the predefined binary format.

[0100] Features of earlier aspects may be applied to the present aspect.

[0101] According to an aspect, there is provided a computer-implemented method for monitoring a subject using a wearable or insertable medical data logger. The computer-implemented method may comprise: obtaining, by a data collection module of the data logger, data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject; encrypting the data by a first encryption to form first encrypted data; encrypting the first encrypted data by a second encryption that is different to the first encryption to form second encrypted data; and transmitting, from a data transmission module of the data logger, the second encrypted data to a remote computer. Features of earlier aspects may be applied to the present aspect.

[0102] The following aspects focus on techniques relating to use of tokens. According to an aspect, there is provided a computer-implemented method for handling, by a remote computer, medical data relating to a subject. The method comprises: receiving an indication that a wearable or insertable medical data logger is to be activated by an activating user; associating a token with the data logger in a first data structure; providing the token to the activating user; receiving data relating to the subject from the data logger; storing the data in a storage system; and making at least some of the data in the storage system available to a requesting user upon receipt of the token from the requesting user.

[0103] When handling sensitive data, such as medical data, it is important to ensure that the data is handled securely. Utilizing personal details relating to a subject or even to a physician associated with a data logger or medical device may represent a risk to the data. Accordingly, the aspects above utilize a token, which acts as a substitute for personal data relating to the physician. The token, as a substitute, cannot therefore be used to identify the physician or subject, as it does not represent personal data. Furthermore, issuing it to an activating user such as a physician before the data logger is activated, and then requiring it to access data logged by the data logger ensures that the data is secure and can be securely accessed only by the activating user or a user who obtained the token from the activating user. The requesting user may therefore be the activating user or a recipient of the token from the activating user. An activating user may be a physician. The activating user may provide the indication that the data logger is to be activated via an activating user computer, i.e. by sending a signal from the activating user computer to a remote computer. Alternatively, the indication may be provided via other means, such as email or via phone, and the indication may be received by it being entered into a remote computer by an operator.

[0104] Making at least some of the data available to a requesting user may comprise displaying the data or data derived from the data on a display of a computer of the requesting user. Making at least some of the data available to the requesting user may comprise transmitting the data to the requesting user, such as in an email message.

[0105] The token may be a JSON web token.

[0106] The method may comprise, before receiving the data relating to the subject from the data logger: receiving, from the data logger, the token; and determining that the token is associated with the data logger in the first data structure. The data relating to the subject may be received based on determining that the token is associated with the data logger in the first data structure.

[0107] These features provide further security benefits, because the token is used to ensure that the data logger has been validly activated by the activating user or someone deriving the token from them. Thus, the token has a first use, which is to enable and indicate valid activation of the data logger, and a second use, which is to enable a user to subsequently view data obtained by the data logger. The use and the data gathered by the data logger are therefore secure.

[0108] The method may comprise validating a data logger based at least in part on determining that the token is associated with the data logger in the first data structure. The method may comprise permitting the data logger to transmit data to a remote computer based on validating the data logger. Permitting the data logger to transmit data may comprise transmitting a signal or message to the data logger to indicate said validation. The data logger may begin data collection in a testing or verification state before being transitioned into a monitoring state.

[0109] The method may comprise: receiving an identifier for the activating user; determining that the identifier for the activating user is associated with the data logger based on a second data structure; and associating the token with the identifier for the activating user in the second data structure based on determining that the identifier and data logger are associated.

[0110] The method may comprise, prior to receiving the indication and the identifier: generating the identifier; associating the identifier with the data logger in the second data structure; and outputting the identifier for providing to the activating user in an offline process.

[0111] These steps represent further improvements in relation to how the data logger can be securely activated. Providing an identifier to the activating user enables only known users to be able to activate data loggers, resulting in improved subject safety. The second data structure may be the same data structure as the first data structure, or may be a different data structure to the first data structure.

[0112] The method may comprise generating a report using the data stored in the storage system. The report may be made available to a requesting user upon receipt of the token. The at least some of the data in the storage system may be made available to a requesting for a predetermined time period only.

[0113] According to an aspect, there is provided a computer-implemented method for handling medical data relating to a subject by a remote computer. The method comprises: receiving an indication that a wearable or insertable medical data logger is to be activated by an activating user; associating a token with the data logger in a data structure; providing the token to the activating user; receiving, from the data logger, the token; determining that the token is associated with the data logger in the data structure; and permitting the data logger to transmit data relating to the subject to the remote computer or a further remote computer based at least in part on determining that the token is associated with the data logger in the data structure.

[0114] According to an aspect, there is provided a system comprising: a processor; and memory attached to the processor, wherein the memory stores instructions that, when implemented by the processor, cause the system to perform a method as described above.

[0115] According to an aspect, there is provided a computer program product comprising instructions that, when executed on a computer, cause the computer to perform a method as described above.

[0116] Features of other aspects described above may be combined with features of the present aspects.

[0117] The following aspects focus on techniques relating to power-level dependent operation. According to an aspect, there is provided a wearable or insertable medical data logger for monitoring a subject. The data logger comprises: an integrated power source; a data collection module configured to obtain data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject at a sampling rate; a data transmission module configured to wirelessly transmit the data obtained by the data collection module to a remote computer at a transmission interval; and a processor configured to: monitor a power level of the integrated power source; and vary at least one of the sampling rate at which data is obtained from the sensor by the data collection module or the transmission interval at which data is transmitted to the remote computer by the data transmission module based on the power level of the integrated power source.

[0118] For a wearable or insertable medical data logger, it is useful to maintain power for as long as the data is to be gathered or at least for as long as possible, so that relevant data can be gathered. This is particularly important for monitoring subjects over longer periods of time to gather overall pictures of the physiological parameter being measured. Accordingly, enabling the processor to vary how the data is gathered or transmitted based on power level can help to preserve power to enable such longterm monitoring.

[0119] Varying sampling rate and / or transmission interval specifically means that the two main uses of power, which are data logging and data transmission, can be controlled. Sampling rate, i.e. the frequency with which measurements are made using the sensor, affects the amount of data gathered, and so varying sampling rate may impact how much power is used for both logging and transmission, as more data being gathered also means more data to transmit. The data transmission module may be configured to send all data not previously transmitted to the remote computer, so varying transmission interval may also vary how much data is transmitted in each transmission.

[0120] Sampling rate and transmission interval may be varied together or may be varied independently. Variation of these parameters may be directly related to power level, or may be adjusted in other ways.

[0121] Enabling variation of transmission interval may be particularly useful for a data logger configured to wirelessly transmit data, because wireless transmission can be particularly powerintensive. Specifically, continuously maintaining an open network connection may be too powerintensive for a data logger with limited power, and so the data logger may be configured to establish a wireless connection each time it wishes to transmit data, i.e. at each transmission interval. Maintaining an open network connection may also pose a security risk. Activating the data transmission module, scanning for and identifying an appropriate cellular tower or other beacon, performing verification and other security checks all consume power. A reduced transmission interval can reduce how often these steps are performed, thereby preserving power for longer.

[0122] The processor may be configured to vary at least one of the sampling rate or the transmission interval by: at a first time: determining that the power level is above a threshold power level; causing the data collection module to obtain data from the sensor at a first sampling rate; and causing the data transmission module to transmit data to the remote system at a first transmission interval; and at a second time that is later than the first time: determining that the power level is below a threshold power level; and at least one of: causing the data collection module to obtain data from the sensor at a second sampling rate that is lower than the first sampling rate; or causing the data transmission module to transmit data to the remote system at a second transmission interval that is longer than the first transmission interval.

[0123] Utilizing threshold power levels to perform said variation enables the sampling rate and transmission interval to be kept consistent over particular periods of time, with variation being performed at intervals. The processor may be configured to vary at least one of the sampling rate or the transmission interval proportionally to the power level. This may enable a more dynamic adjustment to preserve power levels.

[0124] The processor may be configured to: determine that the power level is below a minimum threshold power level; and cause the data transmission module to cease data transmission to the remote computer.

[0125] The processor may be configured to cause a signal to be sent to the data transmission module prior to ceasing data transmission that indicates that the power level is below the minimum threshold power level. The processor may be configured to continue storing data in a memory of the data logger after causing the data transmission module to cease data transmission.

[0126] The data transmission module may be configured to wirelessly transmit the data via a cellular network connection. At the transmission interval, the data transmission module may be configured to establish the cellular network connection, transmit a packet of data obtained from the sensor, and break the cellular network connection. Cellular network connections may result in high power usage by data loggers as they search for and establish the network connection, particularly in areas with poor coverage. This is especially the case if the cellular network connection is reformed each time data is to be transmitted. Accordingly, by providing a dynamic operation of the data logger in response to monitored power levels, the data logger can be usefully used with cellular network connections without power levels prohibiting continued operation.

[0127] Transmitting data via the cellular network connection may comprise transmitting data via a secure channel established with the remote computer according to a secure channel protocol.

[0128] The cellular network connection may operate according to aLTE-M communication protocol. The cellular network connection may operate according to an NB-IoT communication protocol. The cellular network connection may be described as an LTE-M network connection or as an NB-IoT network connection.

[0129] The processor may be configured to encrypt the data prior to transmission to the remote computer using the data transmission module.

[0130] The data may comprise values for measurements of the physiological parameter, and wherein the values are encoded prior to transmission based on a predefined data transform or a predefined data structure. Transmitting according to a predefined data transform or structure may enable a reduced amount of data to be transmitted, which may therefore use less power. The data may be encoded into a predefined binary format, which may include some compression of the data, and this may also reduce the amount of data to be sent, thereby preserving power.

[0131] Reducing the amount of data by compression may also reduce the amount of data to be encoded, which may also reduce power usage. According to an aspect, there is provided a computer-implemented method for monitoring a subject using a wearable or insertable medical data logger. The computer-implemented method comprises: obtaining, by a data collection module of the data logger, data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject; wirelessly transmitting, by a data transmission module of the data logger, the data obtained by the data collection module to a remote computer; monitoring, by a processor of the data logger, a power level of an integrated power source of the data logger; and varying at least one of a frequency at which data is obtained from the sensor by the data collection module or a frequency at which data is transmitted to the remote computer by the data transmission module based on the power level of the integrated power source.

[0132] BRIEF DESCRIPTION OF DRAWINGS

[0133] The drawings, together with the detailed description, serve to explain various principles of this disclosure.

[0134] Fig. 1 shows a block diagram of a medical data logging system for monitoring a physiological parameter of a subject.

[0135] Fig. 2 shows a block diagram of a wearable or insertable medical data logger.

[0136] Fig. 3 shows how data is encoded by a medical data logger.

[0137] Fig. 4 shows a state diagram for a wearable or insertable medical data logger.

[0138] Fig. 5 shows a swim-lane diagram depicting how components of a medical data logging system interact.

[0139] Fig. 6 shows a flow chart governing how a medical data logger is operated to preserve power. DETAILED DESCRIPTION

[0140] Fig. 1 provides an overview of a system 50 for monitoring a physiological parameter of a subject 10. In this example, the subject 10 is a human subject. The techniques described herein may be applied for monitoring any physiological parameter of a subject, including physiological parameters of an organ of the subject.

[0141] The system 50 comprises a medical device 100 and a remote system 160 with which the medical device 100 is configured to communicate over a wireless network connection 125 with a network 130.

[0142] A physician 20, who may also be referred to as a clinician or medical doctor, may desire to monitor the physiological parameter. The physician 20 may provide the medical device 100 for the purposes of monitoring the physiological parameter. The medical device 100 is attached to the subject 10, with parts either being temporarily fixed to the subject or being inserted or implanted in the subject 10. The medical device 100 is then activated by the physician 20 and undergoes an initialization process in order to perform validations and verifications as will be described later on. Some of the validations are performed with the remote system 160, which involves establishing a wireless network connection 125. Subsequently, once the initialization process is completed satisfactorily, the medical device 100 gathers data relating to the physiological parameter. The data is transmitted to the remote system 160 following re-establishment of the wireless network connection 125. The remote system 160 gathers the data and subsequently provides the data to the physician 20 for viewing.

[0143] The medical device 100 includes a sensor 110 that is implanted into the subject 10. The medical device 100 further includes a data logger 120, which may also be referred to as a data collector or data module. The sensor 110 is in communication with the data logger 120. In this example, the communication is by means of a wired connection 115, although in other examples the connection may be wireless. The data logger 120 depicted in Fig. 1 may include a plurality of different modules and / or components, as will be described in more detail in relation to Fig. 2 below. Still referring to Fig. 1, the data logger 120 receives data from the sensor 110 via the wired connection 115. The data, as will be described later on in more detail, includes values for the physiological parameter obtained from or by the sensor 110 according to a sampling rate.

[0144] The data logger 120 is capable of wireless data transmission via the wireless network connection 125. The wireless network connection 125, in this example, is a 4G connection. The data logger 120 can therefore be described as being 4G-enabled. In other examples, data loggers may be 5G-enabled or may utilize another standard broadband, cellular network technology to provide such wireless network connection, including future standard network technologies for wireless communications, such as 6G.

[0145] The data logger 120 establishes the wireless network connection 125 by locating a nearby base station 140, such as a cell tower, and establishing communication with it according to 4G standards. The base station 140 provides communication to a wide-area network 150, such as the internet, to allow communication between the data logger 120 and the remote system 160.

[0146] The data logger 120 is able to communicate with a first remote computer 170, which in this example is referred to as a validation computer, and two second remote computers 180, 190, which in this example are referred to as a receiving computer and a platform computer. The validation computer 170, receiving computer 180, platform computer 190, and a storage system 195 form the remote system 160. The storage system 195 is connected to the validation computer 170 and the platform computer 190. Communication with the remote computers 170, 180, 190 may be direct through the network 150 or may be through other remote computers. Although the validation computer 170 and platform computer 190 are depicted separately here, in other examples they may be the same computer. In some examples, the receiving computer 180 may not be provided, or more intermediate computers may be provided between the network and the validation computer 170 and / or the platform computer 190.

[0147] During monitoring of the physiological parameter, the data logger 120 obtains data from the sensor 110 and transmits it via the network connection 125 to the receiving computer 180. The data logger 120 is configured to encrypt the data it transmits by a first encryption and by a second encryption, with the second encryption being for data exchange through a secure channel formed with the receiving computer 180.

[0148] Turning now to the remote system 160, the validation computer 170 is configured to perform validation of the data logger 120 upon activation of the data logger 120 by the physician 20. Validation with the validation computer includes determining that the data logger 120 is associated with the physician 20 activating the data logger 120 and has been correctly activated by the physician 20. Validation also includes determining that the data logger 120 is being used according to certain requirements, that the data logger 120 has not been recalled, and that the data logger 120 uses a valid or acceptable version of firmware. The validation computer 170 performs at least some of these tasks with reference to a data structure stored in the storage system 195.

[0149] The receiving computer 180 is configured to receive data from the data logger 120 and to pass it to the platform computer 190. The receiving computer 180 therefore acts to act as an intermediary to receive data and direct it to the platform computer 190. In addition, the receiving computer 180 acts to enable secure data transmission, by enabling a secure channel to be formed with the data logger 120 and particularly with the processor operating within the data logger 120, as well as performing other actions to verify transmissions from the data logger 120 and to ensure data security is preserved, such as by verifying a digital certificate received with data sent from the data logger 120. As a secure channel is formed with the data logger 120 by the receiving computer 180, the receiving computer 180 performs a first decryption of data received from the data logger 120. The data is encrypted by the data logger 120 by a first encryption to provide first encrypted data and the first encrypted data is encrypted by a second encryption to provide second encrypted data, meaning that decrypting the data by the receiving computer 180 retrieves the first encrypted data. The receiving computer 180 does not store the appropriate key for performing decryption of the first encrypted data, so data security is maintained.

[0150] The platform computer 190 performs two functions within the system 50 shown in Fig. 1. In other systems, a different system to the platform computer 190 may perform one or both functions.

[0151] A first function performed by the platform computer 190 is enabling activation of the data logger 120 by the physician 20. Initially, prior to any activation, an identifier is generated for the physician 20 and associated with the data logger 120 in a data structure stored in the storage system 195. The identifier is output from the platform computer 190 for providing to the physician 20 in an offline process. The physician 20 therefore has an associated general identifier. When the physician 20 wishes to activate the data logger 120, the physician 20 provides an indication that the data logger 120 is to be activated to the platform computer 190. The indication includes the identifier that was previously assigned to the physician 20, an indication of the data logger 120 to be activated, and anon- personal identifier associated with the subject, such as a journal identifier or a hospital -issued identifier so that personally identifiable and sensitive information relating to the subject is not associated with any data collected. The platform computer 190 is configured to determine that the data logger 120 is associated with the identifier belonging to the physician 20 based on the data structure in the storage system 195. If it is determined that the data logger and identifier are associated, the platform computer 190 obtains or generates a JSON web token (‘JWT’ or ‘token’ hereafter), using a token vault, for example, and issues it to the physician 20. The platform computer 190 also updates the data structure in the storage system 195 to associate the token with the data logger 120. The token may be an indication within the data structure that a ‘soft’ activation of the data logger 120 has been performed, and this may be subsequently used by the validation computer 170 to validate the data logger 120. The validation computer 170 may also receive the token during validation and validate the token as being associated with the data logger 120 using the data structure.

[0152] The second function performed by the platform computer 190 is to make data received from the data logger available for viewing by the physician 20. The platform computer 190 receives data from the receiving computer 180, which is encrypted by a first encryption. The data is decrypted by the platform computer 190 to retrieve the data obtained by the data logger 120 from the sensor 110 relating to the physiological parameter. The platform computer 190 receives a request to view the data from the physician 20 including the token provided to the physician 20 initially by the platform computer 190. The platform computer 190 confirms that the token is the correct token associated with the data logger 120 from which the data was received by reference to the data structure stored in the storage system 195 and makes the data available to view by the physician 20 at, for example, a physician computer 30. The physician computer 30 may be used by the physician 20 to communicate with the platform computer 190. Such communication may be over the network 130, although this is not shown in Fig. 1 for clarity.

[0153] By performing the first and second functions described above, the platform computer 190 acts as an interface for the physician 20.

[0154] Accordingly, both the validation computer 170 and the platform computer 190 are able to read data from and write data to the storage system 195. The storage system 195 is depicted here as a single storage system, but may store different data structures relating to different types of data. For example, the data structure referred to above storing data relating to the physician 20, data logger 120, and token may be a first data structure, and a second data structure may store the data relating to the physiological parameter obtained by the data logger 120. In other examples, the storage system 195 may be split into a plurality of sub-systems, with each storing different types of data. This may improve security around each type of data. For example, a first sub-system may store first data relating to the physician 20, data logger 120, and token, while a second sub-system may store the data obtained by the data logger 120 relating to the physiological parameter of the subject. Turning now to Fig. 2, an example data logger 220 is shown. The example data logger 220 may be used as the data logger 120 in Fig. 1. The data logger 220 has an integrated power source 230, meaning that it can be worn by or inserted into a subject, such as the subject 10 of Fig. 1, without connection to an external power source. This means that the subject does not need to be tethered to an external item. The integrated power source 230 is sealed within the data logger 220, meaning that it cannot be accessed without dismantling the data logger 220, to prevent tampering or damage during use. In this example, the integrated power source 230 is not rechargeable, but in other examples it may be, via electrical contacts provided on an outside of the data logger 220 or using an induction charging system.

[0155] When the data logger 220 is active and monitoring the physiological parameter, the data logger 220 receives data 245 from a sensor (not shown), such as sensor 110 of Fig. 1, at a data collection module 240. The data collection module 240 is configured to obtain or receive said data 245 from the sensor according to a sampling frequency. The data collection module 240 may be a separate module from other components within the data logger 220 or may be integrated with them. For example, if the data collection module 240 is integrated with other components, it may form part of a processor or processing chip on the data logger 220. The data collection module 240 may comprise a connector to which the sensor connects.

[0156] The data collection module 240 provides data it receives to a processor 250. The processor 250 encodes the data for storage and transmission using a buffer 260. The data is encoded by the processor 250 with reference to a predefined data transform and according to a predefined binary format, an example of which is described below in relation to Fig. 3. Continuing with Fig. 2, the processor 250 stores the encoded data in a memory 270. The memory 270 comprises an SD card in this example. According to a transmission interval indicating how often data is transmitted by the data logger 220, the processor 250 acts to transmit the data to a remote computer, such as the receiving computer 180 of Fig. 1, using a data transmission module 280.

[0157] The data transmission module 280 comprises a modem, an eSIM, and an antenna for wireless transmitting data across a network connection. Data is sent according to the transmission interval. The data transmission module 280 is depicted here as being separate from the processor 250 for clarity, but in some examples may be integrated with the processor 250.

[0158] The data is transmitted by the processor 250 and data transmission module 280 via a network connection and network, such as the network connection 125 and the network 130 of Fig. 1. The processor 250 and data transmission module 280 establish the network connection when transmission of the data is due, and, as part of establishing the network connection, a secure channel is also formed with the remote computer with which the data logger 220 is to communicate. The processor 250 encrypts by a first encryption the data to be sent, which in this case is all new data not previously sent to the receiving computer, forming first encrypted data. The data, representing the payload, is encrypted, but metadata or a header may not be encrypted. The processor 250 then encrypts by a second encryption the first encrypted data to provide second encrypted data. The second encryption is an encryption using a key obtained during a handshake with the remote computer performed to establish the secure channel. The data is subsequently transmitted via the data transmission module 280 as second encrypted data 285.

[0159] The processor 250 and data transmission module 280 are also configured to communicate with the validation computer, such as validation computer 170, to perform validation of the data logger 220, as described above. The memory 270 stores data relating to the data logger 220, such as an identifier of the data logger 220, and this data is communicated to the validation computer to enable validation. The data collection module 240 is configured to receive data from the physician activating the data logger 220, and the processor 250 and data transmission module 280 communicate this data to the validation computer also. The data received from the physician includes the token provided to the physician upon the ‘soft’ activation.

[0160] The data logger 220, in addition to performing a validation exchange with a validation computer, is also configured to validate the sensor or sensors to which it connects. The sensor has an associated identifier and characterization data. The identifier identifies the sensor. The characterization data indicates how electrical signals received from the sensor can be converted into a value for the desired parameter. The characterization data may therefore be considered to be a mapping or relation between sensor readings and values for the parameter. The data logger 220 is matched with the sensor in a matching process prior to dispatch to the physician, and the identifier and characterization data are pre-stored in the data logger 220. Upon activation, the data logger 220 receives the identifier and characterization data from the sensor and compares them to the stored identifier and characterization data. Upon confirmation that the identifiers and characterization data match, the data logger 220 validates the sensor and permits data to be received from it. If the sensor is not valid, because one or both of the identifier or characterization data do not match, the data logger 220 does not permit data to be obtained or received from the sensor.

[0161] Fig. 3 shows an encoding process for encoding data for transmission by a data logger 310, such as the data logger 220 or the data logger 120.

[0162] A sensor 315 provides a sensor output 320 to the data logger 310. The sensor output 320 is an electrical output from the sensor 315 and has a value, in this case 2250. As the output 320 is a raw output, it will require conversion so that it has a desired unit. This may be referred to as a dimension associated with the physiological parameter. The sensor 315, as described above, has associated characterization data for performing such conversion. The data logger 310 also stores the characterization data 330. The data logger 310 may convert the raw output to have the desired units or, as shown in Fig. 3, may send the raw data to a remote computer.

[0163] The data logger 310 performs a data transform 350 on the output 320 to determine a value 340 that is to be encoded for the output 320. The transform 350 involves adjusting the value, i.e. 2250, by a baseline or predefined amount. The predefined amount 355 in this example is 2245. 2245 is therefore subtracted from 2250 to give a value 340 for encoding of 5. This reduces the amount of data required to encode the output for transmission, and therefore reduces the computational resources and therefore power required for encryption and transmission. Where the values for the physiological parameter are large numbers or have a high precision, and would likely be represented in a binary encoding using a floating point format, using such transformed values can reduce the size of the data to be transmitted, and increase the amount of data that can be transmitted in a block of data. Once received and decrypted, a remote computer, such as platform computer 190, can effectively re-hydrate the data using the reverse transformation to reverse the conversion. In this case, the platform computer 190 would add 2245 to the value it receives.

[0164] After determining the value 340 using the transform 350, the data logger 310 writes the value 340 into a data block 360. The data block 360 is encoded in a binary format and comprises a header 362 and a body 364. The header 362 includes details of the data logger 310, the sensor 315, a timestamp, and a sampling rate, among other metadata. A single timestamp and the sampling rate reduce the amount of data occupied by timestamps and increases the amount of data relating to sensor values that can be sent in a data block 360 without losing details relating to when the measurements were made.

[0165] The body 364 comprises a plurality of entries 366 corresponding to values obtained using the transform 350. The transformed values are encoded in sequence in the body 364. When received by a remote computer and decoded, the re-hydration of the data can, in addition to determining values corresponding to the encoded values, include associating a timestamp with each value based on the timestamp and sampling rate in the header 362 and a relative position of the value within the body 364.

[0166] Each data block 360 is generated in a buffer and subsequently stored by the data logger 310 in memory (not shown in Fig. 3). One or a plurality of data blocks may be transmitted in a single transmission from the data logger 310 to the remote computer.

[0167] If more than one sensor is providing measurements to a data logger, the data logger may perform the process depicted in Fig. 3 for each sensor, and may encode the resulting values in the body of the data block as groups of values obtained at the same time.

[0168] In some examples, a data structure mapping outputs to smaller representations of those outputs or mapping dimensions to smaller representations of those dimensions may be used instead of or as well as the transform 350. During operation, a data logger such as those described above may transition through a series of different states. Fig. 4 shows a series of such states and how the data logger transitions through them.

[0169] Initially, when provided to the physician and in storage in preparation for use, the data logger is in an inactive state 410. While the data logger is in the inactive state 410, the physician attaches the sensor and data logger to the subject, and connects the sensor to the data logger via a wire or wireless connection.

[0170] The data logger is then activated by the physician, and enters an initialization state 420. Activation may be achieved by connecting the power source, which may be achieved by removing a tab separating a terminal of the power source from a terminal of the data logger, for example, or by using a further device to connect to and activate the data logger over a wired connection.

[0171] In the initialization state 420, the data logger performs several different processes, including verifying the sensor, validating itself with a remote computer, checking whether there has been a recall notice, checking that its firmware is up to date, and performing test measurements.

[0172] From the initialization state 420, the data logger may proceed to one of three states. If, in the initialization state 420, it is determined that there has been a recall of the data logger, based on communication from or with a remote computer, such as the validation computer 170 or platform computer 190, then the data logger enters a recall state 430. In the recall state, the data logger cannot be used further. Data transmission and / or data gathering by the data logger may be prevented or ceased when it is in the recall state 430. Reactivation of the data logger may also be prevented in the recall state 430. The data logger may output a signal to the physician to indicate that it has been recalled. For example, an LED or other indicator may be provided which outputs a particular signal upon entering each state, and a specific signal may indicate a recall state.

[0173] If validation of the sensor and / or the data logger is unsuccessful, and the data logger and / or sensor is deemed invalid, then the data logger may also progress to the termination state 450. In response to determining that at least one of the sensor and the data logger is invalid, the data logger may communicate this to the physician activating the data logger and / or to a remote computer. As noted above, further use of the data logger is prevented. Validation is described in more detail later in relation to Figs. 5 and 6.

[0174] During the initialization state, the data logger also confirms that it has an acceptable, correct, or up-to-date version of the firmware, which may include updating the firmware by downloading an update from a remote computer if the firmware is not a correct version. A firmware version may be deemed correct or up-to-date if a schema it uses is compatible with a schema used by a latest version of the firmware or a schema used by a remote computer, such as platform computer 190, that receives the data. During the initialization state, the data logger also allows test data to be gathered, which can then be displayed to the physician. Such test data may be sent via the remote computer that is used to gather data, such as via the receiving computer 180 and platform computer 190 in Fig. 1, and may be displayed to the physician on a local display such as on the physician computer 30. Enabling the physician to securely view data relating to the subject prior to setting the data logger to run allows the physician to ensure that data is being correctly gathered and that the data logger is functioning correctly. Should a fault be detected during this phase, either by data not being sent or data being gathered incorrectly, the physician may re-activate the data logger in order to attempt to resolve the fault or may terminate operation of the data logger altogether. In either case, the data logger may be transitioned to the termination state 450. Termination may be achieved by disconnecting a power source of the data logger or by a signal transmitted to the data logger from a physician device or computer or from a remote computer, enacted by the physician.

[0175] A re-activation of the device from the termination state 450 may be permitted by the data logger and validation computer without the data logger being deemed invalid if the re-activation is performed within a pre-determined activation time period.

[0176] Once the initialization state 420 is complete, and the data logger has been deemed valid, the data logger moves to a monitoring state 440, in which data is gathered and transmitted to a remote computer such as the platform computer 190 of Fig. 1. Upon entering the monitoring state 440, the data logger and / or a remote computer with which it was validated, such as the validation computer 170 of Fig. 1, generates and outputs a validation report, indicating the checks and outcomes performed during the initialization state 420. A similar report may be generated upon the initialization state 420 transferring to the termination state 450 or the recall state 430.

[0177] The data logger may be in the monitoring state until its power source is depleted or until a termination event is triggered. A termination event may be the physician removing the data logger and / or sensor from the subject, disconnecting the sensor from the data logger, disconnecting the data logger’s power source, or the data logger receiving a signal to enter the termination state 450, which may be sent via a remote computer or may be sent from a local physician device connected to the data logger.

[0178] The data logger may communicate with a remote computer to indicate when it enters any of the states shown in Fig. 4, so that such data can be recorded. If the data logger enters the termination state and is not re-activated within a predetermined time period, the data logger may be classed as being terminated, and may be prevented from further use without being deemed invalid.

[0179] Fig. 5 shows a swim-lane diagram for interactions between a sensor 502, a data logger 504, a network 506, avalidation computer 508, areceiving computer 510, a platform computer 512, a storage system 514, and a physician 516. The physician 516 represents both the physician 516 as an individual or group of individuals, such as physician 20 in Fig. 1, as well as a physician computer, such as physician computer 30. Which is intended will be made clear.

[0180] Initially, a registration process 518 is performed between the physician 516 and the platform computer 512. The registration process 518, which may be performed partially offline, involves the physician 516 providing registration details to the platform computer 512. An identifier for the physician 516 is generated by the platform computer 512 and is associated with an identifier of the data logger 504 at least in a data structure storage by the storage system 514. The identifier is output from the platform computer 512 for being provided to the physician 516. The identifier and the data logger are provided to the physician 516 in an offline process, so that security is preserved around the identifier.

[0181] When the physician 516 wishes to activate the data logger 504, i.e. transition it from its inactive state 410 to its initialization state 420 as shown in Fig. 4, the physician 516 transmits from the physician computer to the platform computer 512 the identifier issued to them in the registration process 518 and the identifier associated with the data logger 504.

[0182] The platform computer 512 then, at step 522, compares the received identifiers with identifiers stored in the data structure in the storage system 514 to determine that the physician 516 activating the data logger 504 is associated with the data logger 504.

[0183] Upon identifying that the identifiers received from the physician 516 are associated in the data structure, the platform computer 512 performs a ‘soft activation’ of the data logger 504 by generating or otherwise obtaining a token at step 524, associating the token with the particular data logger 504 and the physician identifier in the data structure stored in the storage system 514 at step 526, and, at step 528 communicating the token to the physician 516. The token, as described above, may be a JSON web token.

[0184] Once the token has been associated with the data logger, the token can be used by the physician 516 to both activate the data logger 504 and to subsequently view data gathered by the data logger 504, as will be described below.

[0185] Alternatively, if the identifiers are not associated in the data structure, then the platform computer 512 may terminate communication with the physician 516. As a result, the physician may attempt to activate the data logger but the data logger will prevent data gathering or transmission because the ‘soft activation’ of the data logger by the platform computer 512 has not been performed.

[0186] To activate the data logger, the physician 516 performs an activation step 530 with the data logger, thereby causing the data logger 504 to enter an initialization state, such as initialization state 420 in Fig. 4. This activation step 530 may involve connecting the power source of the data logger to bring it from the inactive state to the initialization state. At step 534, the token is provided to the data logger 504 by the physician 516. The token is used by the data logger 504 as part of validation with the validation computer 508. Accordingly, to perform such validation, the data logger 504 establishes a network connection with the network 506 at step 536. This may be referred to as a first network connection formed by the data logger 504.

[0187] Having established a network connection, the data logger 504 establishes communication with the validation computer 508. A handshake protocol or other exchange of data may initially be performed at step 538. For example, a secure channel may be formed between the data logger 504 and the validation computer 508 to protect data communicated between them. The data logger 504 transmits a first digital certificate to the validation computer 508 as part of this process to identify it to the validation computer 508. The validation computer 508 may transmit a certificate to the data logger 504 to identify itself with the data logger 504.

[0188] At step 540, the data logger 504 transmits the token received from the physician 516, identifying information relating to the data logger 504 to the validation computer 508, and information relating to the firmware run by the data logger 504. This data may be transmitted in a single transmission or in several transmissions.

[0189] The validation computer 508 performs a verification process at step 542. In the verification process, the validation computer 508 compares the token received from the data logger 504 and an identifier of the data logger 504 to the data structure stored in the storage system 514 and determines whether the token matches the identifier. The validation computer 508 also checks the data structure to determine that the activation of the data logger 504 is an initial or valid activation, i.e. it is not being reused after a termination of the data logger has occurred. An initial activation, for the purposes of this example, is an activation of the data logger 504 into the initialization state that does not follow a termination state of the data logger. The data structure may record whether the data logger 504 has previously entered the termination state, and the validation computer 508 may determine based on such a record whether the activation is an initial or valid activation. As part of the verification process, the validation computer 508 also checks that the firmware run by the data logger 504 meets predetermined requirements, such as utilizing a compatible schema.

[0190] The validation computer 508 may also determine, based on the data structure or a different data structure, whether there is a recall notice for the data logger 504.

[0191] If each of the checks performed by the validation computer 508 are successfully completed, i.e. the token is associated with the data logger 504 in the data structure, the activation is an initial or valid activation, the firmware is sufficiently up-to-date, and there is no recall notice for the data logger 504, then the validation computer 508 validates the data logger 504, and indicates that it is valid by a return message in step 544, which will allow it to proceed with the subsequent steps. If it is determined that the token is not associated with the data logger, that the activation is not an initial or valid activation, the data logger 504 may be indicated as invalid, and may be caused to enter a termination state, such as termination state 450 state, in which at least data transmission is prevented. If it is determined that the firmware is not up-to-date, then the validation computer 508 may indicate a latest version of the firmware, and / or the data logger 504 may access a repository to perform an update of the firmware. A further exchange with the validation computer 508 may subsequently be performed before the data logger 504 is deemed valid. If it is determined that a recall is associated with the data logger 504, the data logger 504 enters a recall state such as recall state 430 in which no data transmission or reactivation of the data logger is permitted.

[0192] The data logger 504 also validates the sensor 502 in step 546. Validating the sensor 502 involves accessing identification data from the sensor 502, including an identifier and characterization data of the sensor, retrieving corresponding identification data from a memory of the data logger 504, and determining that the identification data from the sensor and from memory are matching.

[0193] Once the data logger 504 is deemed to be valid, and the sensor 502 has been validated, the data logger 504 begins logging test data at step 548. Test data 548 is communicated from the data logger 504 to the validation computer 508 at step 550, which subsequently, at step 552, provides it to the physician computer 516 for viewing by the physician.

[0194] If the data logger 504 is logging data incorrectly or another fault is identified during this process, the physician may re-activate the data logger 504, perform diagnostics, or attempt to troubleshoot the fault in another way (not shown in this Figure). If the data logger 504 is performing correctly, then it proceeds, at step 554, to the next state, which is the monitoring state, which may be the monitoring state 440 in Fig. 4. At the same time or substantially concurrently, in step 555, the validation computer 508 produces a validation report and stores it in the storage system 514 for access later by the physician 516 or another computer.

[0195] In this example, the data logger 504 proceeds to step 554 because a predetermined amount of time, referred to as the activation period elapsed without reactivation or another signal indicating that it should enter the termination state or recall state. In other examples, a signal may be sent to the data logger 504 or an action may be taken to cause the data logger 504 to enter the monitoring state at step 554.

[0196] In the monitoring state, the data logger 504 receives or obtains data from the sensor 502 at step 556 according to a sampling rate. The sampling rate may be variable, as will be described below in relation to Fig. 6. Remaining with Fig. 5, at step 558, the data logger 504 acts to store the data in data blocks, as described in relation to Fig. 3 above. Steps 556 and 558 continue until a transmission interval is reached, at which time the data logger 504 acts to transmit data to the platform computer 512 via the receiving computer 510. The transmission interval may also be varied, as described below in relation to Fig. 6. Still in Fig. 5, to transmit data to the receiving computer 510, the data logger 504 establishes a further network connection with the network 506 at step 560. This further network connection may be referred to as a second network connection. Once the second network connection is established, forms a secure channel with the receiving computer 510 at step 562. As part of forming the secure channel in step 562, at least one key is shared according to a secure channel protocol associated with the secure channel. The key enables secure communications between the data logger 504 and the receiving computer 510.

[0197] The data logger 504 then prepares the data to be sent to the receiving computer 510 at step 564. Step 564 involves collating data comprising one or more data blocks stored by the data logger 504 and forming a data packet. A payload of the data packet is then encrypted using a first encryption to form first encrypted data. The first encryption is performed using a first encryption key. A corresponding first decryption key is held by the platform computer 512 for decryption. The first encryption and decryption keys may be symmetric or asymmetric keys. Step 564 also involves a second encryption, which encrypts the first encrypted data to form second encrypted data. The second encryption uses a second encryption key, which in this example is a key provided to the data logger 504 during the exchange to form the secure channel in step 562. A corresponding second decryption key is held by the validation computer 508, which was also obtained during the exchange to form the secure channel in step 562. The second encryption and decryption keys may be symmetric or asymmetric keys.

[0198] The second encrypted data is then transmitted, at step 566, across the network to the receiving computer 510. A second digital certificate is transmitted with the second encrypted data. The second digital certificate may be different to the first digital certificate that the data logger 504 transmits to the validation computer 508 in step 538. The data being transmitted has therefore been encrypted twice before being transmitted to the receiving computer 510. The receiving computer 510 only holds one of the two decryption keys required to decrypt the data, and so cannot gain access to the data relating to the subject.

[0199] Following transmission in step 566, the data logger 504 is configured to break the network connection at step 567.

[0200] At step 568, the receiving computer 510 verifies the digital certificate to ascertain that the data has not been tampered with, and decrypts the second encrypted data using its second decryption key to obtain the first encrypted data. This may be referred to as a first decryption.

[0201] The receiving computer 510, at step 570, transmits the first encrypted data and a receiving computer certificate to the platform computer 512. The platform computer 512, at step 572, decrypts the first encrypted data to retrieve the original data obtained by the data logger 504. The platform computer 512 may validate the certificate to verify that the data has not been tampered with. At step 574, the platform computer 512 stores the data in the storage system 514. The steps 556 to 574 may be repeated until step 576 is performed, so that data is gathered over the predetermined time period. Step 556 may be repeated according to the sampling rate, while steps 558, 560, 562, 564, and 566 may be performed at each transmission interval.

[0202] Once the data logger 504 has been operating for a sufficient time period, the physician 516 may wish to review the data. At step 576, the physician 516 interacts with the data logger 504, which causes it to enter the termination state at step 578. For example, at step 576, the physician may provide a signal to the data logger 504 indicating that it should enter the termination state. The data logger 504, as part of entering the termination state, may send a signal to the platform computer or another computer indicating that it has entered or will enter the termination state. The platform computer 512 may be configured to determine that the data logger 504 has entered the termination state, for example by determining that a predetermined time period has passed since data was received from the data logger 504, and / or may receive an indication from the physician 516 indicating that the data logger 504 has entered the termination state. The platform computer 512 may generate one or more reports based on the data in response to determining that the data logger 504 has entered the termination state.

[0203] Subsequently, when the physician 516 wishes to access data from the data logger 504, at step 580, the token issued to the physician in step 528 is provided to the platform computer 512. At step 582, the platform computer 512 determines data stored in the storage system 514 corresponding to the token, and then at step 584 makes that data available for viewing by the physician 516.

[0204] The steps described in Fig. 5 are representative only. In some examples, some of the steps may be omitted, different steps may be included, or some of the steps shown may be performed in a different order. At least some of the steps may, alternatively, be performed by different computers or devices. For example, a single computer may receive the data and perform the validation steps.

[0205] The process described above in relation to Fig. 5 is for when the data logger 504 is activated initially and has not previously entered a termination state. If, after steps 576 and 578, the data logger 504 is re-activated, steps 530, 532, 534, 536, 538, 540, and 542 may be performed again. In other words, the data logger 504 may be re-activated by a physician, which may be physician 516 or a different physician, and may enter the initialization state before forming a network connection and communicating with the validation computer 508. The validation computer 508 may then determine that the re-activation of the data logger 504 is an invalid activation of the data logger 504, and, at step 544, may send a signal to the data logger 504 indicating that the activation is an invalid activation. Such a signal may cause the data logger 504 to prevent further transmission of data and / or further collection of data.

[0206] The features of the data loggers are described above in relation to improving security of transmitted data. At least some of the above features may improve a lifespan of the data loggers, by changing power usage, meaning that the data logger can monitor the subject for longer periods of time. It is difficult to know how much power a wearable or insertable data logger will use when seeking connection to a network in order to transmit data. This is because the subject may be in a location where forming a network connection is difficult, and so the data logger uses more power attempting to form the connection. This is especially true of data loggers using cellular or mobile networks to transmit data, as described above. Environmental conditions can also impact power usage. By monitoring power levels and usage and varying the operation of the data logger dependent on those aspects, the data logger’s lifespan can be extended to fulfil certain criteria or to monitor for as long as possible. Monitoring for longer periods of time enables more data to be gathered, which can allow trends and events to be identified more precisely, and this, in turn, may aid a physician in performing diagnosis and / or devising treatments.

[0207] Fig. 6 shows a method 600 performed by a data logger such as those found in previous figures to vary its operation dependent on power usage. At step 602 of the method 600, data is obtained by the data logger, such as by the data collection module 240 of the data logger 220 of Fig. 2. The data obtained comprises measurements of the physiological parameter from the sensor.

[0208] At step 604, the method 600 includes determining a power level of the data logger. The power level is a power level of the integrated power source of the data logger, such as the integrated power source 230 of the data logger 220.

[0209] At step 606, the power level is compared to a first threshold power level. If the power level is determined to be above the first threshold power level (‘Y’ in response to step 606), step 608 is performed, which comprises causing a data collection module of the data logger to obtain data from the sensor at a first sampling rate and causing a data transmission module of the data logger to transmit data at a first transmission interval. Causing the data collection module to obtain data at a first sampling rate may comprise setting the sampling rate of the data collection module to the first sampling rate. Alternatively, if the sampling rate of the data collection module is already the first sampling rate, causing the data collection module to obtain data at the first sampling rate may involve no action being taken, or a confirmation being provided that the data collection module is to continue sampling at that rate. Similarly, causing the data transmission module to transmit data at the first transmission interval may include setting the transmission interval to the first transmission interval or, if the transmission interval is already the first transmission interval, maintaining that transmission interval or taking no further action.

[0210] If the power level is determined to be below the first threshold power level (‘N’ in response to step 606), then step 610 is performed. In step 610, the power level is compared to a second threshold power level that is lower than the first threshold power level. If the power level is above the second threshold power level (‘Y’ in response to step 610), then step 612 is performed, which comprises causing a data collection module of the data logger to obtain data from the sensor at a second sampling rate and causing a data transmission module of the data logger to transmit data at a second transmission interval. The second sampling rate and second transmission interval may be set by either changing an existing sampling rate or maintaining an existing sampling rate. At least one of the second sampling rate and the second transmission interval is different to the first sampling rate and the first transmission interval. In other words, either the second sampling rate is lower than the first sampling rate, the second transmission interval is longer than the first transmission interval, or both.

[0211] If the power level is determined to be lower than the second threshold power level (‘N’ in response to step 610), then step 614 is performed. Step 614 involves causing the data logger, via its data transmission module for example, to cease data transmission. Data collection may continue at the same or a lower sampling rate, but data transmission is stopped. Accordingly, data continues to be gathered and stored, so that it can be accessed later, but will not be sent for storage at a remote computer. Accordingly, the second threshold power level represents a minimum threshold power level for data transmission. By preventing data transmission, the data logger prevents the most power-costly operation, which is to seek and create a connection with the network. Power collection may continue until the power is depleted from the power source and the data logger ceases operation altogether. Because the memory of the data logger is non-volatile, the data logged during the period when the power level is below the minimum threshold power level is not lost.

[0212] Steps 604 to 614 are performed by a processor of the data logger, such as processor 250. These steps 604 to 614 may be performed periodically by the processor, at a predetermined frequency, for example. The processor may be configured to vary how often it performs these steps, so that power level can be varied more or less frequently depending on conditions. For example, if the power level is low, the processor may perform steps 604 to 614 more often, to ensure that power can be conserved as much as possible. The processor may be configured to perform the above steps when performing one or more other actions. For example, the processor may perform the steps at or after each transmission of data.

[0213] Steps 606 and 610 may generally be described as steps 616 which involve monitoring a power level of the integrated power source of the data logger.

[0214] Steps 608, 612, and 614 may generally be described as steps 618, which involve varying at least one of a frequency at which data is obtained from the sensor by the data collection module (i.e. the sampling rate) or a frequency at which data is transmitted to the remote computer by the data transmission module (the transmission interval) based on the power level of the integrated power source.

[0215] This disclosure can be embodied in a system, a method, and / or a computer program product. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present disclosure. The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device.

[0216] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network.

[0217] It will be apparent to skilled artisans that various modifications and variation can be made in this disclosure without departing from a scope thereof. Thus, it is intended that this disclosure cover modifications and variations thereof, provided that such modifications and the variations come within a scope of the claims, as recited below, and their equivalents.

[0218] EXAMPLE CLAUSES:

[0219] Any of the example clauses in this section may be used with any other of the example clauses and / or any of the other examples or embodiments described herein.

[0220] Clause Al: a wearable or insertable medical data logger for monitoring a subject, wherein the data logger comprises: an integrated power source; a data collection module for obtaining data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject; a data transmission module for wirelessly transmitting data; a processor, and a memory connected to the data collection module and the processor; wherein the data logger is configured to: obtain, by the data collection module, data comprising measurements of a physiological parameter from the sensor; encrypt the data by a first encryption to form first encrypted data; encrypt the first encrypted data by a second encryption that is different to the first encryption to form second encrypted data; and transmit, from the data transmission module, the second encrypted data to a remote computer.

[0221] Clause A2: the data logger of clause Al , wherein the data logger is configured to store the data obtained from the sensor in one or more data blocks in the memory and to form a data packet comprising at least one of the one or more data blocks, wherein the data packet is encrypted by the first encryption.

[0222] Clause A3 : the data logger of clause A2, wherein the data blocks have a predefined binary format, and wherein each data block includes a single timestamp and an indication of a sampling rate of the data.

[0223] Clause A4: the data logger of any of clauses Al to A3, wherein the data logger is configured to establish a secure channel with the remote computer according to a secure channel protocol, and wherein the second encryption and transmission of the data are performed according to the secure channel protocol and via the secure channel.

[0224] Clause A5 : the data logger of clause A4, wherein the data logger stores a digital certificate, and wherein the digital certificate is used to establish the secure channel. Clause A6: the data logger of any of clauses Al to A5, wherein the data comprises values for measurements of the physiological parameter, and wherein the values are encoded prior to the first encryption based on a predefined data transform or a predefined data structure.

[0225] Clause A7: the data logger of any of clauses Al to A6, wherein the second encrypted data is transmitted to a remote computer via a cellular network connection.

[0226] Clause A8: a medical device comprising the data logger of any preceding claim and the sensor for measuring the physiological parameter.

[0227] Clause A9: a system for monitoring the subject comprising: the data logger of any of clauses Al to A7 or the medical device of clause A8; and the remote computer, the remote computer being configured to wirelessly receive the second encrypted data from the data logger.

[0228] Clause A10: the system of clause A9, wherein the remote computer is a first remote computer configured to: decrypt the second encrypted data by a first decryption to retrieve the first encrypted data; and transmit the first encrypted data to a second remote computer.

[0229] Clause Al l: the system of clause A10, comprising the second remote computer, wherein the second remote computer is configured to: receive the first encrypted data from the first remote computer; and decrypt the first encrypted data by a second decryption to retrieve the data comprising the measurements of a physiological parameter.

[0230] Clause Al 2: a computer-implemented method for monitoring a subject using a wearable or insertable medical data logger, wherein the computer-implemented method comprises: obtaining, by a data collection module of the data logger, data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject; encrypting the data by a first encryption to form first encrypted data; encrypting the first encrypted data by a second encryption that is different to the first encryption to form second encrypted data; and transmitting, from a data transmission module of the data logger, the second encrypted data to a remote computer.

[0231] Clause A13: the computer-implemented method of clause A12, comprising: establishing a secure channel with the remote computer according to a secure channel protocol, wherein the second encryption and transmission of the data are performed according to the secure channel protocol and via the secure channel.

[0232] Clause A14: the computer-implemented method of clause A12 or clause A13, wherein the remote computer is a first remote computer, and wherein the method comprises: decrypting, at the first remote computer, the second encrypted data by a first decryption to retrieve the first encrypted data; and transmitting the first encrypted data from the first remote computer to a second remote computer.

[0233] Clause A15: the computer-implemented method of clause A14, comprising: receiving, at the second computer, the first encrypted data from the first remote computer; and decrypt, by the second computer, the first encrypted data by a second decryption to retrieve the data comprising the measurements of a physiological parameter.

[0234] Clause Cl: a computer-implemented method for handling, by a remote computer, medical data relating to a subject, the method comprising: receiving an indication that a wearable or insertable medical data logger is to be activated by an activating user; associating a token with the data logger in a first data structure; providing the token to the activating user; receiving data relating to the subject from the data logger; storing the data in a storage system; and making at least some of the data in the storage system available to a requesting user upon receipt of the token from the requesting user.

[0235] Clause C2: the method of clause Cl, comprising, before receiving the data relating to the subject from the data logger: receiving, from the data logger, the token; and determining that the token is associated with the data logger in the data structure, wherein the data relating to the subject is received based on determining that the token is associated with the data logger in the first data structure.

[0236] Clause C3: The method of clause C2, comprising: validating the data logger based at least in part on determining that the token is associated with the data logger in the data structure; and permitting the data logger to transmit data to a remote computer based on validating the data logger.

[0237] Clause C4: the method of any of clauses Cl to C3, comprising: receiving an identifier for the activating user; determining that the identifier for the activating user is associated with the data logger based on a second data structure; and associating the token with the identifier for the activating user in the second data structure based on determining that the identifier and data logger are associated.

[0238] Clause C5: the method of clause C4, comprising, prior to receiving the indication and the identifier: generating the identifier; associating the identifier with the data logger in the second data structure; and outputting the identifier for providing to the activating user in an offline process.

[0239] Clause C6: the method of any of clauses Cl to C5, comprising generating a report using the data stored in the storage system, wherein the report is made available to a requesting user upon receipt of the token.

[0240] Clause C7: the method of any of clauses Cl to C6, wherein the at least some of the data in the storage system is made available to a requesting for a predetermined time period only.

[0241] Clause C8: the method of any of clauses Cl to C7, wherein the token is a JSON web token.

[0242] Clause C9: a computer-implemented method for handling medical data relating to a subject by a remote computer, the method comprising: receiving an indication that a wearable or insertable medical data logger is to be activated by an activating user; associating a token with the data logger in a data structure; providing the token to the activating user; receiving from the data logger, the token; determining that the token is associated with the data logger in the data structure; and permitting the data logger to transmit data relating to the subject to the remote computer or a further remote computer based at least in part on determining that the token is associated with the data logger in the data structure.

[0243] Clause CIO: the method of clause C9, comprising: receiving data relating to the subject from the data logger; storing the data in a storage system; and making at least some of the data in the storage system available to a requesting user upon receipt of the token from the requesting user.

[0244] Clause Cl l: a system comprising: one or more processors; and memory associated with the one or more processors, wherein the memory stores instructions that, when implemented by the one or more processors, cause the system to perform the method of any of clauses Cl to CIO.

[0245] Clause Cl 2: a computer program product comprising instructions that, when executed on a computer, cause the computer to perform the method of any of clauses Cl to CIO.

[0246] Clause C13: a computer-implemented method for handling medical data relating to a subject, the method comprising: receiving, at a first remote computer, an indication that a wearable or insertable medical data logger is to be activated by an activating user; associating, by the first remote computer, a token with the data logger in a first data structure; providing, by the first remote computer, the token to the activating user; establishing a first network connection for communication between a wearable or insertable medical data logger and at least one second remote computer; receiving, at the at least one second remote computer from the data logger and via the first network connection, data identifying the data logger; transmitting response data from the at least one first remote computer to the data logger, the response data indicating that the activation of the data logger is a valid activation of the data logger; establishing a second network connection for communication between the data logger and the first remote computer; receiving, at the first remote computer, data relating to the subject from the data logger; storing, by the first remote computer, the data in a storage system; and making, by the first remote computer, at least some of the data in the storage system available to a requesting user upon receipt of the token from the requesting user. Clause DI : a wearable or insertable medical data logger for monitoring a subject, wherein the data logger comprises: an integrated power source; a data collection module for obtaining data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject; a data transmission module for wirelessly transmitting data; and a processor configured to, upon an initial activation of the data logger: establish a first network connection for communication with at least one first remote computer using the data transmission module; validate the data logger by communicating with the at least one first remote computer via the first network connection; establish a second network connection for communication with at least one second remote computer using the data transmission module; and transmit data comprising measurements of the physiological parameter from the sensor obtained by the data collection module to the at least one second remote computer via the network connection based on the second network connection being established and the data logger being validated.

[0247] Clause D2: the data logger of clause DI, wherein validating the data logger comprises: transmitting data identifying the data logger to the at least one first remote computer; and receiving response data from the at least one first remote computer indicating that the activation of the data logger is a valid activation of the data logger.

[0248] Clause D3 : the data logger of clause 1 or clause 2, wherein validating the data logger comprises determining that the firmware installed on the data logger is an acceptable version of the firmware. Clause D4: the data logger of clause 3, wherein validating the data logger comprises, prior to determining that the firmware installed on the data logger is an acceptable version of the firmware: determining that the firmware installed on the data logger is not an acceptable version of the firmware; and updating the firmware to be an acceptable version of the firmware.

[0249] Clause D5: the data logger of any preceding claim, wherein the processor is further configured to, upon the initial activation of the data logger, validate the sensor, wherein the data comprising the measurements of the physiological parameter from the sensor obtained by the data collection module is transmitted to the at least one second remote computer via the second network connection based on the sensor being validated.

[0250] Clause D6: the data logger of clause D5, wherein the sensor comprises identification data, and wherein the data logger comprises memory in which identification data for a sensor corresponding to the data logger is stored, and wherein validating the sensor comprises: accessing the identification data from the sensor; retrieving the identification data from the memory of the data logger; and determining that the identification data from the sensor and from the memory are matching.

[0251] Clause D7: the data logger of clause D6, wherein the identification data comprises a unique identifier of the sensor and sensor characterization data for the sensor.

[0252] Clause D8: the data logger of any of clauses DI to D7, wherein the processor is configured to, upon a subsequent activation of the data logger after the initial activation of the data logger: establish a third network connection for communication with the at least one first remote computer using the data transmission module; determine that the data logger is invalid by communicating with the at least one first remote computer via the third network connection; and prevent transmission of data to the at least one second remote computer based on the data logger being determined to be invalid.

[0253] Clause D9: the data logger of any of clauses DI to D8, wherein the data transmitted to the at least one second remote computer is encrypted by a first encryption and by a second encryption that is different to the first encryption. Clause DIO: the data logger of clause D9, wherein the processor is configured to determine data to be transmitted to the at least one second remote computer and to encrypt the data to be transmitted by the first encryption to provide first encrypted data.

[0254] Clause Dl l: the data logger of clause D9 or clause DIO, wherein the data logger is configured to establish a secure channel with the remote computer according to a secure channel protocol via the second network connection, and wherein the second encryption and transmission of the data are performed according to the secure channel protocol and via the secure channel.

[0255] Clause D12: the data logger of any of clauses DI to DI 1, wherein the data comprises values for measurements of the physiological parameter, and wherein the values are encoded prior to transmission based on a predefined data transform or a predefined data structure.

[0256] Clause DI 3: the data logger of any of clauses DI to DI 2, wherein the data logger stores a first digital certificate and a second digital certificate, and wherein the first network connection is established using the first digital certificate and the second network connection is established using the second digital certificate.

[0257] Clause DI 4: the data logger of any of clauses DI to DI 3, wherein the first network connection and the second network connection are cellular network connections.

[0258] Clause D15: a medical device comprising the data logger of any of clauses DI to D14 and a sensor for measuring the physiological parameter.

[0259] Clause DI 6: a computer-implemented method for monitoring a subject using a wearable or insertable medical data logger, wherein the computer-implemented method comprises, upon an initial activation of the data logger: establishing a first network connection for communication with at least one first remote computer using a data transmission module of the data logger; validating the data logger by communicating with the at least one first remote computer via the first network connection; establishing a second network connection for communication with at least one second remote computer using the data transmission module; and transmitting to the at least one second remote computer via the second network connection based on the second network connection being established and the data logger being validated, the data comprising measurements of a physiological parameter obtained by a data collection module of the data logger from a sensor inserted in or placed on the subject.

[0260] Clause DI 7: a wearable or insertable medical data logger for monitoring a subject, wherein the data logger comprises: an integrated power source; a data collection module for obtaining data comprising measurements of the physiological parameter from the sensor; a data transmission module for wirelessly transmitting data; and a processor configured to, upon a subsequent activation of the data logger after an initial activation of the data logger: establish a first network connection for communication with at least one first remote computer using the data transmission module; at least one of: determine that the data logger is invalid by communicating with the at least one first remote computer via the first network connection; or determine that the sensor is invalid; and prevent transmission of data to at least one second remote computer based on at least one of the sensor or the data logger being determined to be invalid.

[0261] Clause D18: the data logger of clause D17, wherein determining that the data logger is invalid comprises: transmitting data identifying the data logger to the at least one first remote computer; and receiving response data from the at least one first remote computer indicating that the activation of the data logger is an invalid activation of the data logger.

[0262] Clause D19: the data logger of clause D17 or clause D18, wherein the sensor comprises identification data, wherein the data logger comprises memory in which identification data for a sensor corresponding to the data logger is stored, and wherein determining that the sensor is invalid comprises: accessing the identification data from the sensor; retrieving the identification data from the memory of the data logger; and determining that the identification data from the sensor and from the memory are not matching.

[0263] Clause D20: a medical device comprising the data logger of any of clauses DI 7 to DI 9 and a sensor for measuring the physiological parameter.

[0264] Clause D21 : a computer-implemented method for monitoring a subject using a wearable or insertable medical data logger, wherein the computer-implemented method comprises, upon a subsequent activation of the data logger after an initial activation of the data logger: establishing a first network connection for communication with at least one first remote computer using a data transmission module of the data logger; at least one of: determining that the data logger is invalid by communicating with the at least one first remote computer via the first network connection; or determining that a sensor that is inserted in or placed on the subject and that is in communication with a data collection module of the data logger is invalid; and preventing transmission of data to at least one second remote computer based on at least one of the sensor or the data logger being determined to be invalid.

Claims

1. 44CLAIMS1. A wearable or insertable medical data logger for monitoring a subject, wherein the data logger comprises: an integrated power source; a data collection module configured to obtain data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject at a sampling rate; a data transmission module configured to wirelessly transmit the data obtained by the data collection module to a remote computer at a transmission interval; and a processor configured to: monitor a power level of the integrated power source; and vary at least one of the sampling rate at which data is obtained from the sensor by the data collection module or the transmission interval at which data is transmitted to the remote computer by the data transmission module based on the power level of the integrated power source.

2. The data logger of claim 1, wherein the processor is configured to vary at least one of the sampling rate or the transmission interval by: at a first time: determining that the power level is above a threshold power level; causing the data collection module to obtain data from the sensor at a first sampling rate; and causing the data transmission module to transmit data to the remote system at a first transmission interval; and at a second time that is later than the first time: determining that the power level is below a threshold power level; and at least one of: causing the data collection module to obtain data from the sensor at a second sampling rate that is lower than the first sampling rate; or causing the data transmission module to transmit data to the remote system at a second transmission interval that is longer than the first transmission interval.

3. The data logger of claim 1, wherein the processor is configured to vary at least one of the sampling rate or the transmission interval proportionally to the power level.

4. The data logger of any preceding claims, wherein the processor is configured to:45 determine that the power level is below a minimum threshold power level; and cause the data transmission module to cease data transmission to the remote computer.

5. The data logger of any preceding claim, wherein the data transmission module is configured to wirelessly transmit the data via a cellular network connection.

6. The data logger of claim 5, wherein, at the transmission interval, the data transmission module is configured to establish the cellular network connection, transmit a packet of data obtained from the sensor, and break the cellular network connection.

7. The data logger of claim 5 or claim 6, wherein transmitting data via the cellular network connection comprises transmitting data via a secure channel established with the remote computer according to a secure channel protocol.

8. The data logger of any of claims 5 to 7, wherein the cellular network connection operates according to a LTE-M communication protocol or according to an NB-IoT communication protocol.

9. The data logger of any preceding claim, wherein the processor is configured to encrypt the data prior to transmission to the remote computer using the data transmission module.

10. The data logger of any preceding claim, wherein the data comprises values for measurements of the physiological parameter, and wherein the values are encoded prior to transmission based on a predefined data transform or a predefined data structure.

11. A medical device comprising the data logger of any preceding claim and the sensor for measuring the physiological parameter.

12. A system comprising: the data logger of any of claims 1 to 10 or the medical device of claim 11; and the remote computer, the remote computer being configured to wirelessly receive the data from the data logger.

13. A computer-implemented method for monitoring a subject using a wearable or insertable medical data logger, wherein the computer-implemented method comprises:46 obtaining, by a data collection module of the data logger, data comprising measurements of a physiological parameter from a sensor inserted in or placed on the subject at a sampling rate; wirelessly transmitting, by a data transmission module of the data logger, the data obtained by the data collection module to a remote computer; monitoring, by a processor of the data logger, a power level of an integrated power source of the data logger at a transmission interval; and varying, by the processor, at least one of the sampling rate at which data is obtained from the sensor by the data collection module or the transmission interval at which data is transmitted to the remote computer by the data transmission module based on the power level of the integrated power source.

14. The computer-implemented method of claim 13, wherein varying at least one of the sampling rate or the transmission interval comprises: at a first time: determining, by the processor, that the power level is above a threshold power level; causing, by the processor, the data collection module to obtain data from the sensor at a first sampling rate; and causing, by the processor, the data transmission module to transmit data to the remote system at a first transmission interval; and at a second time that is later than the first time: determining, by the processor, that the power level is below a threshold power level; and at least one of: causing, by the processor, the data collection module to obtain data from the sensor at a second sampling rate that is lower than the first sampling rate; or causing, by the processor, the data transmission module to transmit data to the remote system at a second transmission interval that is longer than the first transmission interval.

15. The computer-implemented method of claim 13 or claim 14, comprising: determining, by the processor, that the power level is below a minimum threshold power level; and causing, by the processor, the data transmission module to cease data transmission to the remote computer.

Citation Information

Patent Citations

  • Criticality of data

    US20110295560A1

  • Systems and methods for monitoring and managing life of a battery in an analyte sensor system worn by a user

    US20160120448A1

  • Techniques for power source management using a wrist-worn device

    US20160161985A1

  • Methods and devices for secure communication with and operation of an implant

    US20240214798A1

  • Energy optimized sensing techniques

    WO2011106773A1