Sensor with digital signature of data relating to sensor
Abstract
Problem to be solved.To provide a sensor which has codes useful for a monitor which can be authenticated as accurate.
Solution.The sensor has the codes useful for the monitor which can be authenticated as accurate. The sensor produces a signal corresponding to a measured physiological characteristic and provides codes which can be assured of being accurate and authentic when used by a monitor. A memory associated with the sensor stores both data relating to the sensor and a digital signature. The digital signature authenticates the quality of the code by ensuring it was generated by an entity having predetermined quality controls, and ensure the code is accurate.
Copyright (C)2011,JPO&INPIT
Term
Projected expiry 13 December 2030.
- Priority
- Filed
- Published
- Today
- Projected expiry
2 claims: 1 independent, 1 dependent
- 1It s a way to operate the sensor,To store at least one field of data in memory associated with the sensor,Storing required / optional flags in the fields of the dataReading the flag with a sensor readerIf the sensor reader does not recognize the field of data and the flag indicates that the field is optional, then ignoring the field of data andIf the sensor reader does not recognize the field of data and the flag indicates that the field is mandatory, it will generate an error signal indicating that the sensor cannot be used.Including, methods. センサを動作させるための方法であって、該センサと関連したメモリ内のデータの少なくとも1つのフィールドを格納することと、該データのフィールド内に必須/オプションのフラグを格納することと、センサ読み取り器によって、該フラグを読み取ることと、該センサ読み取り器が該データのフィールドを認識せず、該フラグが該フィールドがオプションであることを示す場合、該データのフィールドを無視することと、該センサ読み取り器が該データのフィールドを認識せず、該フラグが該フィールドが必須であることを示す場合、該センサを用いることが出来ないことを示すエラー信号を生成することとを包含する、方法。
47 paragraphs, as filed
(Background of invention) The present invention relates to a sensor having a memory. In particular, although the pulse oximeter sensor will be described, it is equally applicable to other types of sensors.
(Pulse oxygen measurement method) Pulsed oxygen measurements typically include, but are not limited to, the saturation of blood oxygen in the blood pigment in arterial blood, and the pulsating rate of blood corresponding to the patient's heart rate. It is used to measure various blood flow characteristics. Measuring these properties is a non-invasive sensor that allows blood to permeate through tissue, allow light to pass through a portion of the patient's tissue, and photoelectrically sense light absorption within such tissue. Is achieved by using. A monitor connected to the sensor determines the amount of light absorbed and calculates the measured amount of blood components, eg, arterial oxygen saturation.
When selecting light to pass through a tissue, the selection is made so that one or more light wavelengths are absorbed in the blood by an amount representing the amount of blood components present in the blood. The amount of transmitted or reflected light passing through a tissue varies by varying the amount of blood components and associated light absorption within the tissue. For measuring blood oxygen levels, such sensors include a light source and a photodetector adapted to operate at two different light wavelengths by a known technique for measuring blood oxygen saturation.
Various methods of coding information within the sensor have been proposed in the past, including pulse oximeter sensors that convey useful information to the monitor. For example, the encoding mechanism is set out in US Pat. No. 4,700,708 to Nellcor, the disclosure of which is incorporated herein by reference. This mechanism uses a pair of light emitting diodes (LEDs) to direct light through tissues that have been perfused into the blood, and an optical oximeter probe with a detector that detects light that has not been absorbed by the tissue. Regarding. The accuracy of calculating the oxygen saturation depends on knowing the wavelength of the LED light. Since the light wavelength of the LED can change, the monitor shows the oximeter oxygen saturation rate calculation coefficient suitable for at least one of the actual light wavelengths of the LED, or a combination of LED light wavelengths for this sensor. A coding register with a value is placed inside the probe. When the oximeter instrument is powered on, the oximeter instrument first applies current to the coding register, then measures the voltage, and then calculates the register value and, therefore, the appropriate saturation factor for the light wavelength of the LED in the probe. The coefficient is determined.
Other coding mechanisms include US Pat. Nos. 5,259,381, 4,942,877, 4,446,715, 3,790,910, 4,303,984, 4,621,643, 5,246,003, 3,720,177, 4,684,245, 5,645,059, 5,058. Also proposed in Nos. 4,858,615 and 4,942,877, the disclosure of all these documents is incorporated herein by reference. No. 877 specifically discloses the process of storing various data in the pulse oximeter sensor memory, including the coefficients of the equation for the saturation rate of the oximeter.
The problem with prior art sensor coding techniques is that the encoding of information is sometimes inaccurate and / or not authentic. As a result, the monitor sometimes fails to get enough readings from the patient, and in worse cases makes inaccurate calculations, and in extreme cases inaccurate code and resulting readings. Insufficiency significantly impairs patient safety and adversely affects the patient. Inaccurate code can occur in a variety of environments. For example, errors can occur during the sensor manufacturing process or during sensor shipment. But more generally, inaccurate code is a cheap, low quality third party that supplies compatible, high quality sensors, is not licensed or licensed by the corresponding monitor manufacturer. Used by some sensor manufacturers for some purposes. These third parties often make a minimal investment in research and do not understand how the monitor works and how the monitor uses the code, so they simply do not understand what the code is for. Since these third parties are not licensed by the monitor manufacturer, it is generally not possible to obtain this information from the monitor manufacturer. Often, these third parties are reverse engineering techniques or original science. By science), we do not choose to invest time and money to study how monitors work and how we use code to ensure patient safety. Rather, such a third party simply investigates the range of code values used in the market for each encoded data feature and averages all these sensors to be "compatible" with a particular monitor. There are many examples of using code values. In many cases where the average code value is used, the read is simply out of specification (especially dangerous in this case), but the average code value causes significant errors in the calculation algorithm used by the monitor and is patient safe. It may be wrong enough to cause significant problems. In addition, if a third party's inaccurate code adversely affects the patient, the affected patient, or the patient's successor, may seek to assist the monitor manufacturer with a responsible, direct caregiver. .. As is often the case, if the caregiver does not hold the sensor of the low quality third party used and does not keep a record of this use, then the low quality third party with another high quality monitor that is not of low quality. It is difficult for the monitor manufacturer to prove that the problem was caused by using the sensor.
Another reason for the need to authenticate digital data stored in association with medical sensors is that the data can be corrupted between the time recorded at the factory and the time read by the instrument monitoring the patient's condition. There are few, but they are. A well-cited example of a mechanism that can lead to such corruption is the change in value recorded in digital memory due to the rate of cosmic ray generation of energy. A more common cause of damage is damage to memory cells caused by electrostatic discharge.
Therefore, there is a need in the art to devise a method of communicating an accurate and authenticated composite code from the sensor to the monitor to ensure accurate calculation by the monitor and accurate patient monitoring.
<p> (Gist of the invention) Therefore, it is an object of the present invention to provide a sensor having a code useful for a monitor that can be authenticated as accurate.</p>
<p> This and other objectives are achieved by sensors that generate signals that correspond to the patient's measured physiological characteristics and provide a code that can be guaranteed to be accurate and authenticated when used by a monitor. .. The memory associated with the sensor stores the code and other data about the sensor, and the memory also includes a digital signature. The digital signature authenticates the quality of the code and data and ensures that the code is accurate by ensuring that the code was generated by an entity with a given quality control.</p><p> In one embodiment, the electronic signature is generated during the sensor manufacturing process using a pair of private keys, a private key and a public key. The signature is then verified by a public key embedded within the processor in an external sensor reader (eg, monitor). The signature can be separated from the data. Alternatively, instead of attaching the signature to the data, the signature itself may include all of the data, or at least some of the data, thereby providing a masking level for the data.</p><p> According to one embodiment of the invention, any one of several known public / private key signing methods can be used. These methods include Diffie-Hellman (and this variant of the National Institute of Standards & Technolog's digital signature standard, El Gamal, or elliptic curve approach), RSA (developed at the Massachusetts Institute of Technology) and Rabin-Williams. Including.</p><p> In a further embodiment of the invention, a digest of a portion of the data to be signed is included in the signature to verify that no error has occurred in the data. Each piece of data is preferably organized to include a field ID to indicate the type of data that follows, the length factor of the data, and each piece of data. The required bits are also preferably provided to indicate whether knowledge of how each data is used by the monitor is essential for the operation of the sensor by the monitor. Therefore, older monitors that do not recognize non-essential data simply discard this data. This is probably because older monitors do not implement the improved features for each piece of data. However, if each data is required for proper operation of the sensor, the required bits are set to indicate that the sensor reader / monitor cannot use the particular sensor with the plug plugged in.</p><p> In yet another embodiment, the signature data stored by the sensor comprises at least a sensor-dependent saturation calibration curve coefficient used to calculate the oxygen saturation rate by the monitor. In addition, the data may include a sensor OFF threshold and a thermistor calibration factor suitable for the sensor, including the thermistor. Some of such data may be contained within the signature, and this data or other data may be contained outside the signature. Unsigned data can, if desired, be encrypted (or masked) by a symmetric key encryption algorithm such as NIST's Data Encryption Standard (DES), where the symmetric key is in the signature. Can be included. Alternatively, the symmetric key can be obtained from the digest contained within the signature.<u style="single">The present invention includes, for example, the following items.</u></p><p><u style="single"> (Item 1) Installed outside a sensor (15) that has an output to provide a signal corresponding to the measured physiological characteristics and a monitor (206) that is associated with the sensor and receives the signal of the sensor. A device comprising a memory (12), the memory comprising data relating to the sensor, the memory further comprising an electronic signature.</u></p><p><u style="single"> (Item 2) The device according to item 1, wherein the signature is signed using a private key, and the signature can be verified by a public key in the monitor.</u></p><p><u style="single"> (Item 3) The device according to item 1, wherein the signature is a Rabin-Williams signature, an RSA signature, a Diffie-Hellman signature, an El Gamal signature, or an elliptic curve signature.</u></p><p><u style="single"> (Item 4) The apparatus according to item 1, wherein at least the first part of the data is included in the electronic signature.</u></p><p><u style="single"> (Item 5) The apparatus according to item 4, wherein the second part of the data is outside the electronic signature and is masked with a symmetric key contained within the electronic signature.</u></p><p><u style="single"> (Item 6) The device according to item 5, wherein the memory includes a hash function of a digest of a part of the data, and the digest is included in the electronic signature.</u></p><p><u style="single"> (Item 7) The device according to item 6, wherein the symmetric key can be obtained from the digest.</u></p><p><u style="single"> (Item 8) The device according to item 7, wherein the third part of the data is unmasked and is outside the electronic signature, and the digest is generated from the first, second and third parts. ..</u></p><p><u style="single"> (Item 9) The device according to item 1, wherein the data includes masking data outside the signature and a symmetric key for decoding the masking data, and the symmetric key is included in the electronic signature. ..</u></p><p><u style="single"> (Item 10) The device of item 9, wherein the message digest is contained within the signature to authenticate the accuracy of at least some of the data.</u></p><p><u style="single"> (Item 11) The data field includes a required / optional bit flag, which means that the monitor reading the memory knows how to use the data field in the operation of the monitor by the sensor. The device according to item 1, which indicates whether or not it is essential.</u></p><p><u style="single"> (Item 12) The sensor is a pulse oximeter sensor, and at least a part of the data is included in the signature, and the part is among the saturation rate calculation coefficient, the sensor OFF threshold, and the thermistor calibration coefficient. The device of item 1, comprising at least one.</u></p><p><u style="single"> (Item 13) The data includes manufacturing date, lot code, defective sensor flag, manufacturing component test data, LED transfer V / I features, LED light source features, detector efficiency features, maximum safe LED power, and sensor data. The device of item 12, including at least one of the revision level, light once / light many flags, page size, number of pages, sensor model type, maximum number of recycling events and adult / newborn query flags set by.</u></p><p><u style="single"> (Item 14) A method of generating a digital signal in a device including a memory associated with a sensor having an output to provide a signal corresponding to the measured physiological characteristics.</u><u style="single"> The process of signing at least a portion of the data relating to the sensor to generate an electronic signature.</u><u style="single"> The process of storing the electronic signature in the memory and</u><u style="single"> The process of storing data related to the sensor in the memory and</u><u style="single">Including, methods.</u></p><p><u style="single"> (Item 15) The process of generating a pair of public key and private key,</u><u style="single"> The process of incorporating the public key in memory into the sensor reader,</u><u style="single"> A process of using the private key to sign the data and generate the electronic signature.</u><u style="single">14. The method of item 14, further comprising.</u></p><p><u style="single"> (Item 16) The method according to item 14, wherein the electronic signature is a Rabin-Williams signature, an RSA signature, a Diffie-Hellman signature, an El Gamal signature, or an elliptic curve signature.</u></p><p><u style="single"> (Item 17) The method of item 14, further comprising incorporating at least a portion of the data into the electronic signature.</u></p><p><u style="single"> (Item 18) By reading the message obtained from the memory digital data, the electronic signature is verified and authenticated, a first digest is generated from the message, and the first digest and the electronic signature are included. 14. The method of item 14, further comprising a program for comparison to identify with a second digest contained in.</u></p><p><u style="single"> (Item 19) The method of item 14, wherein the second portion of the data is outside the electronic signature and is masked with a symmetric key.</u></p><p><u style="single"> (Item 20) The method according to item 19, further comprising the step of generating a hash function of a digest of a portion of the data to be signed, wherein the digest is contained within the electronic signature.</u></p><p><u style="single"> (Item 21) The method according to item 20, wherein the symmetric key can be obtained from the digest.</u></p><p><u style="single"> (Item 22) The third part of the data is unmasked and is outside the electronic signature, and the digest is generated from the first, second and third data parts, according to item 21. Method.</u></p><p><u style="single"> (Item 23) With the housing</u><u style="single"> Sensor input for receiving signals from sensors corresponding to the measured physiological characteristics,</u><u style="single"> The sensor processing circuit connected to the sensor input and</u><u style="single"> A memory input for receiving digital data stored in a memory associated with the sensor, wherein the digital data includes a memory input including an electronic signature.</u><u style="single"> A first sensor read memory connected to the memory input for storing the digital data,</u><u style="single"> A second sensor read memory that stores the signature verification key,</u><u style="single"> Using the signature verification key, a third sensor read memory for storing a program for verifying the digital signature of the digital data, and</u><u style="single"> A transfer circuit for providing at least a part of the digital data to the sensor processing circuit, and</u><u style="single">Including sensor reader.</u></p><p><u style="single"> (Item 24) The sensor reader according to item 23, wherein the first and second sensor reader memories are different parts of the physically same memory.</u></p><p><u style="single"> (Item 25) The sensor reader according to item 23, wherein the sensor processing circuit includes a microprocessor.</u></p><p><u style="single"> (Item 26) The sensor reader according to item 23, wherein the signature verification key is a public key of a pair of a private key and a public key.</u></p><p><u style="single"> (Item 27) The sensor reader according to item 23, wherein the signature is a Rabin-Williams signature.</u></p><p><u style="single"> (Item 28) The sensor reader according to item 23, wherein at least a portion of the digital data is embedded in the electronic signature.</u></p><p><u style="single"> (Item 29) (a) A sensor having an output to provide a signal corresponding to the measured physiological characteristics, and</u><u style="single"> A sensor memory associated with the sensor, wherein the sensor memory has digital data about the sensor and further has an electronic signature, the electronic signature being the signature of at least a portion of the data. Memory and</u><u style="single"> With sensor devices including</u><u style="single"> (b) Sensor reading housing and</u><u style="single"> A sensor input for receiving the signal from the sensor corresponding to the measured physiological characteristics,</u><u style="single"> The sensor processing circuit connected to the sensor input and</u><u style="single"> A memory input for receiving the digital data from the sensor memory and</u><u style="single"> A first sensor read memory connected to the memory input for storing the digital data,</u><u style="single"> A second sensor read memory that stores the signature verification key,</u><u style="single"> Using the signature verification key, a third sensor read memory for storing a program for verifying the electronic signature, and</u><u style="single"> With sensor readers, including</u><u style="single">System with.</u></p><p><u style="single"> (Item 30) The process of storing at least one field of data in memory associated with the sensor, and</u><u style="single"> The process of storing required / optional flags in the fields of the data,</u><u style="single"> The process of reading the flag with a sensor reader,</u><u style="single"> If the sensor reader does not recognize the field of data and the flag indicates that the field is optional, then the step of ignoring the field of data.</u><u style="single"> When the sensor reader does not recognize the field of data and the flag indicates that the field is mandatory, the step of generating an error signal indicating that the sensor cannot be used.</u><u style="single">A method for operating a sensor, including.</u></p><p><u style="single"> (Item 31) The process of storing the length of the field associated with the field and</u><u style="single"> The process of reading the length of the field and</u><u style="single"> When the sensor reader does not recognize the field and the flag indicates that the field is optional, the step of skipping the field by using the length of the field.</u><u style="single">30. The method of item 30, further comprising.</u></p><p><u style="single"> (Item 32) The device according to item 1, wherein the memory associated with the sensor is mounted in an adapter connected between the sensor and the monitor.</u></p><p><u style="single"> (Item 33) The method of item 14, wherein the memory associated with the sensor is mounted in an adapter connected between the sensor and the monitor.</u></p><p><u style="single"> (Item 34) The system of item 29, wherein the memory associated with the sensor is mounted in an adapter connected between the sensor and the sensor reader.</u></p><p><u style="single"> (Item 35) A sensor that has an output to provide a sensor signal corresponding to the measured physiological characteristics, and</u><u style="single"> An adapter connected to the sensor, the adapter comprising a memory, the memory comprising the sensor data, including an electronic signature, and an adapter.</u><u style="single">A device equipped with.</u></p><p><u style="single"> (Item 36) An internal monitor in the adapter for providing an output signal corresponding to the physiological characteristics, and</u><u style="single"> A circuit inspection for modifying the sensor signal to generate a synthetic sensor signal, whereby the second external monitor corresponds to the output signal of the internal monitor using the synthetic sensor signal. Circuit inspection and</u><u style="single">35. The device according to item 35.</u></p><p><u style="single"> (Item 37) The first element configured to output a signal corresponding to the measured physiological characteristics, and</u><u style="single"> With a second element configured to provide the digital signature of the data to the output,</u><u style="single">Equipment including.</u></p><p><u style="single"> (Item 38) The process of providing a signal corresponding to the measured physiological characteristics, and</u><u style="single"> The process of providing the digital signature of the data to the output,</u><u style="single">A method of including.</u></p>
<figref num="1">FIG. 1 is a block diagram of a sensor and a sensor reading system incorporating the present invention.</figref><figref num="2">FIG. 2 is a block diagram of the contents of the sensor memory shown in FIG.</figref><figref num="3">FIG. 3 is a block diagram showing a system for signing data during sensor manufacturing.</figref><figref num="4">FIG. 4 shows the mechanism being signed by the system of FIG.</figref><figref num="5">FIG. 5 is a data flow diagram showing the data generated by the method of FIG.</figref><figref num="6">FIG. 6 is a diagram of an embodiment of a sensor reading or monitor showing different software modules.</figref><figref num="7">FIG. 7 is a flowchart showing the reading of the sensor according to the present invention.</figref><figref num="8">FIG. 8 is a diagram showing a flow of data read by the method of FIG. 7.</figref><figref num="9">FIG. 9 is a diagram of different fields in the data.</figref><figref num="10">FIG. 10 is a block diagram of a sensor system using an adapter that includes an electronic signature inside the adapter.</figref>
For further understanding of the properties and advantages of the present invention, refer to the following description along with the accompanying drawings.
(Details of a specific embodiment) (Definition) The signature data is the data included in the digest calculation (by using a hash function). This digest is included in the calculation of the digital signature so that any subsequent data changes can be detected by the failure of the digital signature verification result. The signed data can ultimately be placed either inside or outside the digital signature. In a process known as a "message recovery digital signature", the data is entirely within the digital signature. The data is in a scrambled state so that accidental observers cannot understand the data until the signature is verified. The mathematical process of verifying the signature either leaves the scrambled state or "recovers" the data. In a process known as a "partially recovering electronic signature" suitable for the present invention as described herein, some of the signed data is contained within the signature and additional data is outside the signature. The data portion within the signature is obscured until the signature is verified, while the non-signature portion remains easily readable until this portion is obscured by a masking process.
As used herein, masking data is data that is encrypted so that it can be recovered by the non-masking key contained within the signature. The unmasking key is recovered during signature verification. The non-masking key can then be used to decrypt the masking data. In a preferred embodiment, the masking data is encrypted under a symmetric key. Symmetric keys are the same encryption and decryption keys (ie, masking and non-masking keys). In a particularly preferred embodiment, the message digest incorporated in the digital signature is used as a symmetric key for unsigned masking and non-masking data.
(Sensor reader / monitor) FIG. 1 is a block diagram of a preferred embodiment of the present invention. FIG. 1 shows a pulse oximeter 17 (or sensor reader) connected to a non-invasive sensor 15 attached to patient tissue 18. The light from the sensor LED 14 passes through the patient's tissue 18 and is received by the light sensor 16 after being transmitted through or reflected from the tissue 18. Depending on the embodiment of the present invention, it is possible to use two or more LEDs. The optical sensor 16 converts the received energy into an electrical signal, which is then supplied to the input amplifier 20.
It is possible to use a light source other than LED. For example, a laser may be used, or a white light source with a suitable light wavelength filter may be used on either the sending side or the receiving side.
The time processing unit (TPU) 48 sends a control signal to the LED drive 32 and normally takes turns activating the LEDs. Again, depending on the embodiment, the drive may control two or any additional desired number of LEDs.
The signal received from the input amplifier 20 passes through three different channels for three different light wavelengths, as shown in the embodiment of FIG. Alternatively, two channels may be used for two light wavelengths, or N channels may be used for N light wavelengths. Each channel includes an analog switch 40, a lowpass filter 42 and an analog / digital (A / D) converter 38. The control line from the TPU48 simultaneously selects the appropriate channel at the time the corresponding LED 14 is driven. The queued serial module (QSM) 46 receives digital data from each of the channels via a data line from an analog-to-digital converter. The CPU 50 transmits data from the QSM 46 into the RAM 52 because the QSM 46 fills up periodically. In one embodiment, the QSM46, TPU48, CPU50 and RAM52 are part of an integrated circuit, such as a microcontroller.
(Sensor memory) The sensor 15 including the photodetector 16 and the LED 14 has a sensor memory 12 for this sensor. The memory 12 is connected to the sensor reader or the CPU 50 in the monitor 17. The memory 12 may be packaged within the body of the sensor 15 or within an electrical plug connected to the sensor. Alternatively, the memory 12 may be packaged in a housing that can be mounted on the outer surface of the monitor, or the memory 12 may be installed anywhere in the signal path between the sensor body and the monitor. In particular, according to some preferred embodiments, the content of the sensor memory 12 can be constant for all sensors associated with a particular sensor model. In this case, instead of placing an individual memory 12 on each sensor associated with this model, it is possible to include the memory 12 within a reusable extension cable associated with the sensor model. If the sensor model is a disposable sensor, one memory 12 can be incorporated into a reusable extension cable. Reusable cables can then be used with multiple disposable sensors.
FIG. 2 is a diagram of the contents of the memory 12 of FIG. 1 according to a preferred embodiment. The digital signature 60, along with a signature that preferably contains data about the sensor, occupies a first portion of memory. The second part 62 contains the signed and masked data. The third part 64 contains data that is signed but remains clear (ie, unmasked). Finally, portion 66 is reserved for writing to sensor memory by the sensor reader. Part 66 is unsigned and unmasked. This preferred embodiment is illustrated for illustration purposes and it is understood that the memory 12 may contain many different data blocks outside the digital signal, each of which may be signed and / or masked according to the requirements of the particular embodiment. Should be. These different data blocks may be arranged in any desired order. For example, multiple signed and unsigned blocks may be interlocated, or multiple masked and unmasked blocks may be interlocated. It should also be understood that the data written to memory 12 by the sensor reader is an optional feature and such data can be masked as needed.
(Writing a signature at the factory) FIG. 3 is a block diagram of an embodiment of a system used in a factory to write a signature in the sensor memory 12. Shown in FIG. 3 is a personal computer 70 and a related cryptographic joint processor 72 that includes and utilizes the private key of a private / public key pair. The private key is contained in memory within the joint processor 72. To maintain security, it is preferable that not everyone can read this key. The corresponding public key may be known to both the PC 70 and the co-processor 72, or may be output by the co-processor 72.
The data signed by the co-processor 72 can come from more than one source. Illustrated is a tester 76 for testing sensors that determine the values of a particular sensor component 78, such as LED light wavelength, thermistor resistance, and so on. These data values are then fed to the PC 70 via line 80. Further information 82 may be entered by keyboard or from another database via line 84. This data may include, for example, the serial number of the sensor, the date of manufacture, the lot number, a digest of some of the data to be signed, or other information.
The data to be signed and other data to be contained in the memory 12 are transmitted from the PC to the cryptographic co-processor 72. The co-processor 72 calculates the digest from the signed data and signs it with the private key, digest and other data for which it is desirable to sign. The signatures and data contained herein may include other masked data, or symmetric keys for information from which symmetric keys can be obtained. The co-processor transmits the signature back to the PC70. The PC 70 preferably masks some of the data not contained within the signature, combines the masked data, the signature and the clear data, and transmits all of these to the memory 12 on line 86.
FIG. 4 is a diagram showing the operation of the system of FIG. FIG. 5 shows the data flow by the method of FIG.
First, the sensor is tested and provided with the measured parameters 88 of the sensor, such as LED light wavelength. Then any other data 89 is entered. The data is then sorted (step 90). This sorting results in a first data 91 to be signed, a second data 92 to be masked, and a third data 93 to be cleared, i.e. neither masked nor signed. During manufacturing, or during the read / decryption process after the sensor has been used, a digest 95 is provided during manufacturing to verify that no errors occur in any of the data 91, 92, or 93. Manufactured from all of data 91, 92, 93 (step 94) and included in the signature. The digest is generated as the output of the hash function applied to the data 91, 92, 93. It is possible to compare the digest with a complex CRC. If the monitor later reads the data and digest after decoding and an error greater than one bit occurs in any of the data 91, 92, or 93, the second digest generated by the monitor from the read data is from memory. It does not correspond to the extracted digest, thus indicating that one or more errors occurred somewhere in the write or signature verification process. An example of a suitable hash function is SHA-1, which is Federal Information Processing. Described in Standard Publication FIPS, PUB 180-1, "Secure Hash Standard", National Institute of Standards & Technology, 1995. Digest 95 and data 91 are signed with formatting data 99 added in step 100 to generate signature 101 in step 96. Formatting data is added in step 100, for example, according to the International Standard ISO / IEC 9796-2 digital signature standard. Data 92 is masked in step 103. Next, the signature 101, the masking data 103, and the clear data 93 are combined by the joint processor 72 and the PC 70 and stored in the sensor memory 12.
The private key used to sign the data is preferably the Rabin-Williams digital signature algorithm (an example described in ISO9796-2).
In one embodiment, the original data block to be signed, block 91, is a byte less than 73 bytes plus a 20-byte digest plus a 3-byte formatting data 99. This results in a 96-byte signature message. Longer signatures, such as signatures with 128 bytes, of which 106 bytes can be received as useful data 91 can also be used. The length of the signature depends on the desired degree of security and the amount of decryption power of the monitor.
(Reading the signature by the reader / monitor in the field) FIG. 6 shows a portion of a sensor reader or monitor 17 for verifying a digital signature and recovering data from a sensor when used in a patient. First, the data is taken out from the sensor memory and stored in the memory 110 by the CPU 50. The sensor reader has a public key in memory 112, which is typically loaded at monitor manufacturing or provided as a monitor upgrade. The signature verification and data recovery program is stored in a portion of memory 114.
FIG. 7 shows the operation of signature verification and the data recovery program of the memory portion 114 of FIG. FIG. 8 is a diagram showing the movement of data according to the flowchart of FIG. 7. In step 106, the data is first retrieved from the sensor memory. The retrieved data 102 formed from the signature 101, masking data 107 and clear data 93 is shown in FIG. The public key 112 is then removed from the monitor's memory (step 108).
The signature and public key are then provided as inputs to the cryptographic transformation to obtain the signature data 91 and the memory digest 95 (step 109).
A memory digest is used to determine the masking data symmetric key, which is then used to decipher the masking data 107 to obtain the original masked data 92 (step 116).
To verify the accuracy of all data 91, 92, 93, then a second digest from the signature data 91, unmasked data 92 and clear data 93 decrypted by the monitor using the hash function 118. Generate (step 120). This creates a new digest 122 in step 124 that can be compared to the original digest 95 (read from memory). If the digests are the same, the signature is verified and the message (combined data 91, 92, 93) is authenticated (step 126). The monitor then uses this message in operation. On the other hand, if the digests are not the same, the message is determined to be invalid and the monitor will indicate a bad sensor signal to the monitor user and will not use this message (step 128).
As can be seen, the present invention uniquely assigns electronic signatures to sensors, especially pulse oximeters. By uniquely assigning to the sensor, the sensor reader / monitor verifies the authenticity of the message (data), the reliability of the source and the quality of the sensor, and the non-innovative sensor manufacturer can specify the sensitivity sensor. Protect information from easy discovery and misuse.
(Signature field) FIG. 9 shows in more detail one embodiment of signature data 91, digest 95 and formatting data 99. In particular, the signature data 91 is divided into any number of fields 132, followed by CRC134. Each field 132 contains a 1-byte field ID 136 that identifies the type of data in the field. 1-bit 138 indicates whether the field is required or not. Then there are 7 bits in block 140, which identifies the length of the field. Finally, the field data is provided within a 1-byte block 142.
If an existing monitor or sensor reader is unable to handle a particular field ID 136 or does not recognize a particular field ID 136 during operation, it will look for field length 140 and arrive at the next field. It is possible to calculate how much data to skip. However, the monitor or sensor reader first checks the required bits 138 to determine if this data is essential for the operation of the sensor. If this data is required, the monitor or sensor reader will generate an error message indicating that the attached sensor cannot be read correctly. If this data is not required, the monitor or sensor reader simply ignores this data field.
Therefore, this field format provides flexibility when packing data within signature data blocks, and also provides the possibility and compatibility of upgrades with existing sensor readers and future generations of sensors and monitors. To do.
In one embodiment, the field identifier of the selected value is designated as an "escape character" indicating that the next character is an extended set of identifiers. This allows the ability to add, remove, move, compress or decompress fields contained within a message without having to rely on fixed addresses.
(Data type) The following is an example of the types of data that can be contained in the memory 12 in one embodiment.
It may store the actual coefficients or data to be applied to the equation for calculating the saturation rate of the pulse oximeter. Instead of storing the values corresponding to the measured LED light wavelengths, store these coefficients. As a result, the calibration curve is not limited to a small set of curves provided within the instrument, which significantly increases the design flexibility of the sensor.
The LED light wavelengths may simply be stored on behalf of or in addition to the coefficients. In addition, the characteristics of the secondary emission wavelength and other LED parameters may be stored.
A particular sensor may have a thermistor used to measure low temperatures or to prevent patient burns, such as to compensate for a calibration curve for sensor temperature. The calibration factor for the thermistor may be stored.
Other data that may be contained in memory 12 include, for example, lot codes that allow sensor traceability, defective sensor flags, date of manufacture, manufacturing test information, version of signing software program used for signing, LED transfer V / I features, LED light source features, detector efficiency features, maximum safe LED power, revision level set by sensor data (indicating features contained within the sensor), sensor model ID, adult / newborn query flag (newborn) Or, depending on whether the adult is monitored or not, the desired warning limit range is triggered by different normal oxygen saturation levels for pulsed oxygen measurements), write once / write many flags. ), Page size, multiple pages and maximum number of recycle events.
Alternatively, any type of data described in the prior art references described above or cited may be used and stored in either masking data 92, signature data 91, or clear data 93.
FIG. 10 is a block diagram of a sensor system in which an adapter having an electronic signature is incorporated in the adapter. FIG. 10 shows a sensor 202 connected to the adapter 204 (the adapter 204 is then connected to the monitor 206). The adapter includes a signal circuit inspection 208, a memory with a digital signature 210 and an internal monitor 212. One use for such an adapter is for a class of sensors designed to be connected to such an adapter without a digital signature. The adapter itself may provide a digital signature to the external monitor 206. Thus, for example, instead of accrediting each sensor, it is possible to use different methods of determining that the sensor is accredited by an adapter that provides accreditation to an external monitor.
In the embodiment shown in FIG. 10, the adapter also includes an internal monitor 212. This is to provide an output display or other signal that is different from the output or display provided by the external monitor 206 in the field or is a variant of the output or display provided by the external monitor 206 in the field. It is possible to use an internal monitor. To ensure that any output or display from the two monitors match, the signal inspection block 208 may modify the sensor signal, thereby in its modified form, an external monitor on line 214. Due to the signal output to 206, the external monitor 206 generates an output signal corresponding to the output signal generated by the internal monitor 212. For example, it is possible to acquire the patient's signal from the sensor 202 corresponding to the value of the pulsed oxygen measurement method. It is possible to generate an estimated saturation rate and heart rate on the internal monitor 212 by block 208, which produces a synthetic AC signal, which block 208 sends to the external monitor 206. The construction of the synthetic signal is done to ensure that the external monitor calculates the same heart rate and saturation rate as the internal monitor 212.
The electronic signature can be the signature of any data, including unfiltered patient data, filtered patient data, synthetic patient physiological signals or any other data.
Those skilled in the art will appreciate that the invention can be embodied in other particular forms without departing from the essential features of the invention. Therefore, the above description is within the scope of the present invention described within the scope of the above-mentioned claims and is exemplary, but is not intended to limit the present invention.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0078213A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO9729678A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO9816152A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JPH06510624A | Cites | Japan | Search report |
| JPH06511172A | Cites | Japan | Search report |
36 members in 16 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 15648899 | United States of America | P | |
| 15648899 | United States of America | P | |
| 60156488 | United States of America | – | |
| 09662246 | United States of America | – | |
| 66224600 | United States of America | A | |
| 66224600 | United States of America | A | |
| 1999156488 | – | – | – |
| 2000662246 | – | – | – |
| US19990156488P | – | – | – |
| US20000662246 | – | – | – |
Members36
| Document | Office | Kind | |
|---|---|---|---|
| CA2382960A1 | Canada | A1 | |
| WO0122873A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU7843000A | Australia | A | |
| WO0122873A8 | World Intellectual Property Organization (WIPO) | A8 | |
| BR0014345A | Brazil | A | |
| EP1215995A1 | European Patent Office (EPO) | A1 | |
| KR20020064292A | Republic of Korea | A | |
| WO0122873A9 | World Intellectual Property Organization (WIPO) | A9 | |
| CN1407870A | China | A | |
| JP2003524948A | Japan | A | |
| MXPA02003166A | Mexico | A | |
| NZ517977A | New Zealand | A | |
| HK1054675A | Hong Kong, China | A | |
| HK1054675A1 | Hong Kong, China | A1 | |
| US6708049B1 | United States of America | B1 | |
| US2004162472A1 | United States of America | A1 | |
| AU778152B2 | Australia | B2 | |
| EP1215995B1 | European Patent Office (EPO) | B1 | |
| AT313292T | Austria | T | |
| ATE313292T1 | Austria | T1 | |
| DE60025009D1 | Germany | D1 | |
| ES2258022T3 | Spain | T3 | |
| DE60025009T2 | Germany | T2 | |
| SG125110A1 | Singapore | A1 | |
| CN1290468C | China | C | |
| KR100679762B1 | Republic of Korea | B1 | |
| US2008287757A1 | United States of America | A1 | |
| US7522949B2 | United States of America | B2 | |
| CA2382960C | Canada | C | |
| JP2011062547AThis record | Japan | A | |
| US8190226B2 | United States of America | B2 | |
| US2012237022A1 | United States of America | A1 | |
| JP5366922B2 | Japan | B2 | |
| US8818474B2 | United States of America | B2 | |
| BRPI0014345B1 | Brazil | B1 | |
| BRPI0014345B8 | Brazil | B8 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A711A711 | A711 |
Numbers
- Publication
- 2011062547
- Publication, DOCDB
- 2011062547
- Publication, EPODOC
- JP2011062547
- Application
- 277547
- Application, DOCDB
- 2010277547
- Application, EPODOC
- JP20100277547
Titles3
- English
- A sensor with a digital signature of data about the sensor
- Japanese
- センサに関するデータの電子署名を有するセンサ
- English
- SENSOR WITH DIGITAL SIGNATURE OF DATA RELATING TO SENSOR
Classification
- CPC, 10
- A61B5/14551
- A61B2562/08
- G06F21/64
- G06F2211/008
- G06F2221/2107
- H04L9/3247
- H04L2209/805
- A61B2562/085
- G06F21/6209
- H04L2209/88
- IPC, 7
- A61B5 1455
- H04L9 32
- A61B5 145
- A61B5 00
- G06F1 00
- G06F12 14
- G06F21 24