Self-test for analgesic product.
Abstract
Electrotransport drug delivery devices, system and methods of using configured to determine if a current is present between the anode and cathode when drug is not intended to be delivered by the device. These devices/systems may include an off-current module to determine that any current (e.g., which may be inferred by measuring potential difference between the anode and cathode of the device) flowing between the anode and cathode is below a threshold value when the device is not supposed to be delivering drug, thereby preventing unintended delivery of drug and/or alerting a user that unintended delivery of drug may occur.

Term
6.4 yearsleft in the term
Expires 5 March 2033.
- Priority
- Filed
- Granted
- Today
- Expires
29 claims: 5 independent, 24 dependent
- 1CLAIMS REIVINDICACIONES Habiéndose descrito la invención como antecede, se reclama como propiedad lo contenido en las siguientes reivindicaciones:Having described the invention as above, the content of the following claims is claimed as property: 1. An electrotransport drug delivery device that prevents unwanted drug delivery while in an off state when the device is turned on, characterized in that it comprises: an anode;1. Un dispositivo de administración de fármaco por electrotransporte que impide administración no deseada de fármaco mientras que está en un estado apagado cuando el dispositivo se enciende, el cual caracterizado porque comprende: un ánodo;a cathode;un cátodo;a drive circuit configured to apply current between the anode and cathode to deliver a drug by electrotransport when the device is in an on state and not in the off state;and a current off module, the module configured to automatically and periodically determine whether there is a current flowing between the anode and cathode when the drive circuit is in the off state while being turned on. un circuito de activación configurado para aplicar corriente entre el ánodo y cátodo para administrar un fármaco por electrotransporte cuando el dispositivo está en un estado encendido y no en el estado apagado;y un módulo de corriente apagada, el módulo configurado para determinar automáticamente y de manera periódica si existe una corriente que fluye entre el ánodo y cátodo cuando el circuito de activación está en el estado apagado mientras se enciende.
- 16The device in accordance with the 16. El dispositivo de conformidad con la 123 123 IMPI IMPI INSTITUTO MRXiqANQ DE LA PROPIEDAD INDUSTRIAL reivindicación 1, caracterizado porque comprende además una prueba de diferencia de voltaje de ánodo/cátodo que mide el voltaje de ánodo y el voltaje de cátodo usando el ADC y calcula la diferencia de voltaje entre los dos. MRXiqANQ INSTITUTE OF INDUSTRIAL PROPERTY claim 1, characterized in that it further comprises an anode / cathode voltage difference test that measures the anode voltage and the cathode voltage using the ADC and calculates the voltage difference between the two.
- 17An electrotransport drug delivery device that prevents unwanted drug delivery while in an off state, characterized by comprising:17. Un dispositivo de administración de fármaco por electrotransporte que impide administración no deseada de fármaco mientras está en un estado apagado, el cual caracterizado porque comprende: a reservoir module including: an anode, a cathode, and a drug source;un módulo de depósito que incluye: un ánodo, un cátodo y una fuente de fármaco;an electrical module that includes: un módulo eléctrico que incluye: a drive circuit configured to apply current between the anode and cathode to deliver a drug by electrotransport when the device is in an on state and not in the off state;and a current off module, the module configured to automatically and periodically determine whether there is a current flowing between the anode and cathode greater than an Output Current Shutdown Threshold of 9 μΑ when the drive circuit is in the off state while power on;un circuito de activación configurado para aplicar corriente entre el ánodo y cátodo para administrar un fármaco por electrotransporte cuando el dispositivo está en un estado encendido y no en el estado apagado;y un módulo de corriente apagada, el módulo configurado para determinar automáticamente y de manera periódica si existe una corriente que fluye entre el ánodo y el cátodo mayor que un Umbral de Apagado de Corriente de Salida de 9 μΑ cuando el circuito de activación está en el estado apagado mientras se enciende;en donde el módulo de depósito y el módulo eléctrico se configuran para combinarse antes de que se apliquen a un paciente. wherein the reservoir module and the electrical module are configured to combine prior to being applied to a patient.
- 18A method that automatically confirms and 18. Un método que confirma de forma automática y 124 124 IMPI IMPI INSTITUTO MEXICANO MEXICAN INSTITUTE DE LA PROPIEDAD INDUSTRIAL OF INDUSTRIAL PROPERTY periodically that a drug will not be delivered by an electrotransport drug delivery device according to any of claims 1 to 17, when the device is in a periódica que un fármaco no se administrará por un dispositivo de administración de fármaco por electrotransporte de conformidad con cualquiera de las reivindicaciones 1 a 17, cuando el dispositivo está en un 5 off state while turning on, characterized in that it comprises:5 estado de apagado mientras se enciende, el cual caracterizado porque comprende: determinar si existe una corriente que fluye entre un ánodo y un cátodo del dispositivo de administración de fármaco por electrotransporte cuando el dispositivo de determine if there is a current flowing between an anode and a cathode of the electrotransport drug delivery device when the device 10 electrotransport drug delivery is in an off state while being turned on, wherein the electrotransport drug delivery device includes a trigger circuit that is configured to apply current between the anode and cathode to deliver a 10 administración de fármaco por electrotransporte está en un estado apagado mientras se enciende, en donde el dispositivo de administración de fármaco por electrotransporte incluye un circuito de activación que se configura para aplicar corriente entre el ánodo y el cátodo para administrar un 15 fármaco cuando el dispositivo está en un estado encendido y no administrar fármaco en el estado apagado;y activar un indicador si existe una corriente que fluye entre el ánodo y cátodo que es mayor que un Umbral de Apagado de Corriente de Salida cuando el dispositivo de administración de fifteen drug when the device is in an on state and do not deliver drug in the off state;and activate an indicator if there is a current flowing between the anode and cathode that is greater than an Output Current Shutdown Threshold when the power delivery device 20 fármaco por electrotransporte está en un estado apagado mientras se enciende, en donde la activación de un indicador comprende realizar una interrupción del dispositivo. twenty Electrotransport drug is in an off state while being turned on, wherein activation of an indicator comprises performing an interrupt of the device.
- 19The method according to claim 19. El método de conformidad con la reivindicación 18, caracterizado porque comprende además repetir el paso de 18, characterized in that it also comprises repeating the step of 25 determination periodically while the 25 determinación de manera periódica mientras el circuito de activación está en un estado apagado. activation is in an off state.
Independent claims5
629 paragraphs in 128 sections, as filed
(54) Title: SELF-TEST FOR ANALGESIC PRODUCT.
(54) Title: SELF-TEST FOR ANALGESIC PRODUCT.
(57) Summary
Electrotransport drug delivery devices, systems, and methods of use configured to determine whether a current is present between the anode and cathode when it is not intended that drug be delivered by the device. These devices / systems may include a current off module to determine that any current (for example, which can be inferred by measuring the potential difference between the device's anode and cathode) flowing between the anode and cathode is below a threshold value when the device is not supposed to be delivering drug, thereby preventing accidental drug administration and / or alerting a user that accidental drug administration may occur.
(57) Abstract
Electrotransport drug delivery devices, system and methods of using configured to determine if a current is present between the anode and cathode when drug is not intended to be delivered by the device. These devices / sysfems may include an off-current module to determine that any current (eg, which may be inferred by measuring potential difference between the anode and cathode of the device) flowing between the anode and cathode is below a threshold value when the device is not supposed to be delivering drug, thereby preventing unintended delivery of drug and / or alerting a user that unintended delivery of drug may occur.
Mexican Property Institute
<img file="MX347308B_D0001.tif" />
Industrial □
PATENT TITLE NO. 347308
Owner (s): INCLINE THERAPEUTICS, INC .; ALZA CORPORATION
Address: 900 Saginaw Drive, Suite 200, Redwood City, California, 94063, USA; 700
Eubanks Drive, Vacaville, California, 95688, USA
Denomination: SELF-TEST FOR ANALGESIC PRODUCT
Classification: lnt.CI.8: A61M31 / 00; A61N1 / 18; A61N1 / 30
Inventor (s): BRADLEY E. WHITE; JOHN LEMKE: PAUL HAYTER: CORINNA X. CHEN;
BRIAN W. READ; JASON E. DOUGHERTY
REQUEST
Number! International filing date:
MX / a / 2014/013951 March 05, 2013
PRIORITY
<td>Country:</td><td>Date:</td><td>Number:</td>
<td>US</td><td>May 21, 2012</td><td> 13/476,960</td>
Validity: Twenty years
Expiration Date: March 5, 2033
The reference patent is granted based on articles 1, 2, section V, 6, section III, and 59 of the Industrial Property Law.
In accordance with article 23 of the Industrial Property Law, this patent has a validity of twenty years, non-extendable, counted from the filing date of the international application and will be subject to the payment of the fee to keep the rights in force. . ·;> '' ... :. ::::
Whoever signs this title does so based on the provisions of articles β * sections III and 7 bis 2 of the Industrial Property Law (Official Gazette of the Federation (DOF) 06/27/1981, amended on 0í ®BM994, 10/25/1996, 12/26/1997, 05/17/1999, 01/26/2004, 06/16/2005, 01/25/2006, 05/06/2009, 06/01/2010 , 06/18/2010, 06/28/2010, 01/27/2012 and 04/09/2012); Articles 1, 3rd section V subsection a), 4th and 12th sections i and III of the Regulations of the Mexican Institute of Industrial Property (POF 12/14/1999, amended on 07/01/2002,15/07/2004 , 07/28/2004 and 09/07/2007); Articles 1 ·, 9 ·, 4 ·, 5 · fraction V subparagraph a), 18 fractions! and ttf and 30 of! Organic Statute of the Mexican Institute of Industrial Property (DOF 12/27/1999, amended on 10/10/2002, 07/29/2004, 08/04/2004 and 09/13/2007), 1st, 3rd and 5th subsection a) of the Agreement that delegates powers to the Deputy General Directors, Coordinator, Divisional Directors, Heads of Regional Offices, Divisional Deputy Directors, Departmental Coordinators and other subordinates of the Mexican Institute of Industrial Property. (DOF 12/15/1999, amended on 02/04/2000, 07/29/2004, 08/04/2004 and 09/13/2007).
<img file="MX347308B_D0002.tif" />
MX / 2017/34310
<img file="MX347308B_D0003.tif" />
<sup>1</sup>
<img file="MX347308B_D0004.tif" />
IMPI
MEXICAN INSTITUTE
OF INDUSTRIAL currency
SELF-TEST FOR ANALGESIC PRODUCT
Field of Invention
The present invention relates generally to electrotransport drug delivery devices and to methods of operation and use. These drug delivery devices can have improved safety. In particular, the invention relates to drug delivery devices that include automated self-testing.
Background of the Invention
A variety of drug delivery systems are known, including automated drug delivery systems. Because the consequences of administering an inappropriate dose (eg, too much or too little) of a drug can be life threatening, it is critically important that drug delivery systems are extremely accurate. Drug delivery systems that are configured to deliver medication to patients must be configured to prevent even unlikely accidental delivery events. In particular, drug delivery systems that electrically deliver drug to a patient, including transdermal delivery devices or other electrotransport of drugs, should ideally prevent accidental delivery of drug to the patient.
Ref.:252409 <sup>2</sup> IMPI.
INSTITUTO MEXICAN .. DE LA MONEDAD industrial
The term electrotransport as I know US a — en —'l · ^ - · «present refers generally to the administration of an agent (eg, a drug) through a biological membrane, such as the skin, mucous membrane or nail. Administration is induced or assisted by the application of an electrical potential. For example, a beneficial therapeutic agent can be introduced into the systemic circulation of a human body by electrotransport administration through the skin. A widely used electrotransport process, electromigration (also called iontophoresis), involves the electrically induced transport of charged ions. Another type of electrotransport, electro-osmosis, comprises the flow of a liquid. The liquid contains the agent to be administered, under the influence of an electric field. Yet another type of electrotransport process, electroporation, comprises the formation of momentary pores in a biological membrane through the application of an electric field. An agent can be administered via the pros either passively (ie without electrical assistance) or actively (ie under the influence of an electrical potential). However, in any given electrotransport process, more than one of these processes may be simultaneously exhibiting to some degree. Therefore, the term electrotransport, as used herein, should be given its broadest interpretation.
IMPI
INSTITUTO MEXICANO DE LA MOHEDAL
INDUSTRIAL
<img file="MX347308B_D0005.tif" />
possible to include the induced or enhanced 'ctrícameñEe' transport of at least one agent, which may be charged, uncharged, or a mixture thereof, regardless of the specific mechanism (s) by which the agent is transported.
In general, electrotransport devices use at least two electrodes that are in electrical contact with some portion of the skin, nails, mucous membrane, or other body surface. An electrode, commonly called the donor or active electrode, is the electrode from which the agent is delivered into the body. The other electrode, typically called the counter or return electrode, serves to close the electrical circuit through the body. For example, if the agent to be delivered is positively charged, that is, a cation, then the anode is the active or donor electrode, while the cathode serves to complete the circuit. Alternatively, if an agent is negatively charged, i.e., an anion, the cathode is the donor electrode. Additionally, both the anode and the cathode can be considered donor electrodes if both anionic and cationic ions of the agent are to be delivered, or if the dissolved agents are uncharged.
Additionally, electrotransport delivery systems generally require at least one reservoir or source to be delivered to the body. Examples of these
IMPI
INSTITUTO MEXICANO r> E LA rROriEDAE
INDUSTRIAL
<img file="MX347308B_D0006.tif" />
Donor reservoirs include a pocket or cavity - a porous sponge or pad, and a hydrophilic polymer or gel matrix. These donor reservoirs are electrically connected to, and positioned between, the anode or cathode and the body surface, 5 to provide a fixed or renewable source of one or more agents or drugs. Electrotransport devices also have a source of electrical energy such as one or more batteries. Typically, one pole of the power source is electrically connected to the donor electrode, while the opposite pole is electrically connected to the counter electrode.
Also, some electrotransport devices have an electrical controller that controls the current applied through the electrodes, thereby regulating the rate of agent delivery. Passive flow control membranes 15, adhesives for maintaining device contact with a body surface, insulating members, and waterproof backing members are some other potential components of an electrotransport system that can be used.
Small, self-contained electrotransport drug delivery devices have been proposed, adapted for use on the skin for prolonged periods of time. See, for example, US Patent No. 6,171,294, US Patent
No. 6,881,208, US Patent No. 5,843,014, <sup>5</sup> IMPI ιιΜΗτυτο μ · (£ ανο D € L * eo * e> * r> iwBurrtiAi
United States Patent No. 6,181,963, Pd't
United States No. 7,027,859, United States Patent No. 6,975,902, and United States Patent No. 6,216,033. These electrotransport agent delivery devices typically use an electrical circuit to electrically connect the power source (eg, a battery) and the electrodes. The electrical components in these miniaturized iontophoretic drug delivery devices are preferably miniaturized, and can be in the form of either integrated circuits (ie, microchips) or small printed circuits. Electronic components, such as batteries, resistors, pulse regulators, capacitors, etc., are electrically connected to form an electronic circuit that controls the amplitude, polarity, synchronizes the waveform, etc., of the electrical current supplied by the power source. Other examples of small self-contained electrotransport delivery devices are described in US Patent 5,224,927; United States Patent No. 5,203,768; United States Patent No. 5,224,928; and United States Patent No. 5,246,418.
One of the concerns, particularly with the small self-contained electrotransport delivery devices that are manufactured with the drug to be delivered already in them, is the potential for delivery
<img file="MX347308B_D0007.tif" />
IMPI
INSTITUTO MtXIGANO οε LA P10HEDAO industriai
<img file="MX347308B_D0008.tif" />
Non-proposed drug due to eTECTRIC energy pumped from an external source, or due to an internal short. Any difference in current or potential between the anode and cathode of the device can result in drug delivery by a device that makes contact with the skin, even if the device is not activated or is in an off state. For example, the drug can be administered unintentionally if it is applied to a current through the devices or to a subject wearing a device, even if the device is in an off (still unplugged) mode. This risk, while unlikely, has not previously been addressed by electrotransport drug delivery devices.
Although an electrotransport device may include control circuitry and / or control modules (e.g., software, firmware, hardware, etc.) specifically configured to regulate the current (and therefore the drug dose) applied when the device is on, these devices typically do not monitor the devices when they are in an off state.
Described herein are methods, devices, and systems for monitoring and controlling electrotransport drug delivery devices to detect and / or prevent drug delivery by the device when in an off state or mode. In particular, in the? IMPI IWTTTJMO MKICAMO OF THE NEW iMwmiAX present describes devices, systems and methods that confirm that no voltage or current is applied between the electrodes (anode and cathode) of the device when it is in an off mode or state.
Brief Description of the Invention
In general, devices and methods are described herein that include self-testing for preventing drug delivery from an electrotransport drug delivery device when the device is not activated or is in an off state.
For example, herein described electrotransport drug delivery devices that prevent unwanted drug delivery while in an off state. The device may include: an anode; a cathode; a drive circuit configured to apply current between the cathode and the anode to deliver a drug by electrotransport when the device is in an on state and not in an off state; and a current off module that is configured to automatically and periodically determine whether there is a current flowing between the anode and the cathode when the drive circuit is in the off state, as long as it is on.
In general, the anode and / or cathode can be connected to a source of the drug to be delivered, such as an analgesic such as fentanyl and sufantanyl within a matrix.
<img file="MX347308B_D0009.tif" />
<sup>8</sup> IMPIAS muicaro institute
OF U «OHBDAD
INDUSTRIAL gel. The device may include a controller or other electronic components (including software, hardware, and / or firmware) that make up the drive circuit and / or the current off module. In some variations, the current off module is integrated with other control systems (subsystem) to form the device.
As used herein, a module, such as the current off module, may include hardware, software, and / or firmware configured to perform the specified function (for example, determining whether a current is flowing between the anode and the cathode. ). The module may include a combination of these and may be a separate or separable region of the device or it may make use of shared components of the device (eg, a microcontroller, resistive elements, etc.). For example, a current off module may comprise firmware, software and / or hardware configured to determine if there is a potential difference between the anode and the cathode when the drive circuit is in the off state as long as it is on. A module, such as the current off module may include executable logic that operates on elements (eg, a microcontroller) of the device. For example, the current off module may include current off monitoring logic that controls monitoring for the presence of a current (or current indicator such as
<img file="MX347308B_D0010.tif" />
IMPI INSTITUTO MEXiCAHí DE LA PBOFIEDAB INDUSTRIA!
electric potential, inductive changes or capacitance. ^ ·. ei-c.-X ».. between the anode and the cathode when the device is otherwise in an off state.
In some variations of the device, systems, and methods described herein, the current off module operates to monitor and / or act on identifying a current between the anode and cathode when the device is on but in an off state. Examples of off states are provided below, but can include a ready state, a standby state, or the like, and can include any state during which the device is not in a dosing state and is not intended to deliver the drug. . The dosing state can be referred to as an on state and can indicate that the device is delivering the drug. The off state described herein may occur when the device is otherwise on. In some variations, the off state includes the disconnected state while in some variations the off state does not include the disconnected state, but only includes off states when the device is on.
In general, the current off module can be configured to detect current flow between the anode and cathode in an off state either directly or indirectly. For example, in some variations, the module
IMPI ^ r
MEXICAN INSTITUTE
OF MANKIND
INDUSTRY »—Current off determines whether the current fe'Stá ΡΤΉγ5ΪΤ <Τβ 'between the anode and the cathode by monitoring a voltage or potential difference between the anode and cathode in the off state. For example, in some variations, the current off module comprises software, firmware, and / or hardware configured to determine if there is a change in capacitance between the anode and cathode when the drive circuit is in the off state as long as it is on. . In one example, a current off module comprises software, firmware, and / or hardware configured to determine if there is a change in inductance between the anode and cathode when the drive circuit is in the off state as long as it is on. In this way, it can be inferred that current is flowing between the anode and cathode by indirectly monitoring the presence of, or changes in, the potential difference (e.g., voltage), capacitance, inductance, or the like, between the anode and device cathode.
In general, the current off module can indicate that current is flowing between the anode and cathode only when the sensed current (or a current indicator such as potential difference, inductance, capacitance, etc.) is above a value. threshold. The threshold value is typically above the noise threshold of the device / system. This threshold can be predetermined. For example, in some variations, the current off module
<img file="MX347308B_D0011.tif" />
IMPI
MEXICAN INSTITUTE
OF THE PHONITY INmimiAi may comprise a detection circuit that independently determines an anode voltage and a cathode voltage and compares the power difference between the anode voltage and the cathode voltage at a threshold value. For example, a current off module can be configured to indicate that a current is flowing between the anode and the cathode when the drive circuit is in the off state while it is on where the current flowing is above a threshold. output current shutdown. Any appropriate output current shutdown threshold can be used, for example approximately 1 μΑ, 3 μΑ, 5 μΑ, 9 μΑ, 10 μΑ, 15 μΑ, 25 μΑ, 30 μΑ, 50 μΑ, 100 μΑ, etc. In some variations, the output current shutdown threshold is approximately 9 µΑ.
An electrotransport device may comprise a switch connected between a reference voltage source and a sense resistor, such that the current-off module is configured to periodically close the switch to determine the potential difference between the anode voltage and the cathode voltage.
In this way, in some variations, the current off module can be configured to determine if there is a potential difference between the anode and cathode before the device allows current to travel through the anode and cathode. For example, the current module
IMPI
MEXICAN INSTITUTE OF EA MONEDAD INDUSTRIAL
<img file="MX347308B_D0012.tif" />
turned off. The device may include: a reservoir module including: an anode, a cathode, and a source of drug; an electrical module including: a drive circuit configured to apply current between the anode and cathode to deliver a drug by electrotransport when the device is in an on state and not in the off state; and a current off module, the module configured to automatically and periodically determine whether there is a current flowing between the anode and cathode greater than an output current off threshold of 9 μΆ when the drive circuit is in the off state as long as it is on; wherein the reservoir module and the electrical module are configured to combine before it is applied to a patient.
Also disclosed herein are methods for automatically and periodically confirming that drug will not be delivered by an electrotransport drug delivery device when the device is in an off state. For example, a method of automatically and periodically confirming that drug will not be delivered by an electrotransport drug delivery device when the device is in an off state as long as it is on may include the steps of: determining whether there is a current flowing between an anode and a cathode of the drug delivery device by
IMPI
INKTITUT · MEXICANO et LA ntOntDAL 'INDUSTRIAL
<img file="MX347308B_D0013.tif" />
electrotransport when the electrotransport drug delivery device is in an off state as long as it is turned on, wherein the electrotransport drug delivery device includes a trigger circuit that is configured to apply current between the anode and the cathode for delivering a drug when the device is in an on state and not in the off state; and activating an indicator if there is a current flowing between the anode and the cathode that is greater than an output current shutdown threshold when the electrotransport drug delivery device is in an off state as long as it is on. The method may also include repeating the determination step periodically while the drive circuit is in an off state. In some variations, the method also includes repeating the determination step at least once every 10 minutes as long as the trigger circuit is in an off state and the device is on.
As mentioned above, any appropriate output current shutdown threshold can be used. For example, an output current shutdown threshold may be approximately 9 µΑ. The step of determining whether there is a current flowing between the anode and cathode of the electrotransport drug delivery device may include independently determining an anode voltage.
IMPI
ΙΝΪΤΓΤυτυ MEXICAN DE LA FKOBIEDAl INDUSTRIA!
<img file="MX347308B_D0014.tif" />
and a cathode voltage and comparing the potonoial differential · · between the anode voltage and the cathode voltage to the threshold value. Any appropriate threshold value can be used (eg, above noise). For example, a threshold value can be approximately 2.5 V. In some variations, the threshold value is approximately 0.85 V.
In some variations, the step of determining whether there is a current flowing between the anode and cathode of the electrotransport drug delivery device may include independently connecting a reference voltage source and a sensing resistor to each of the anode and the cathode to determine the potential difference between anode voltage and cathode voltage.
Any of the methods described herein may also include activating the drive circuit to enter the on state and applying current between the anode and cathode after determining that there is no current above the output current shutdown threshold that is flowing between the anode and cathode while the electrotransport drug delivery device is in the off state.
In any of the devices, systems and methods described herein, the electrotransport device can activate an indicator and / or modify the state of the device when a current is detected or inferred, among
IMPI
MEXICAN INSTITUTE
OF THE INDUSTRIAL NOPIEDAL
<img file="MX347308B_D0015.tif" />
the anode and cathode as long as the device is-in. the-is off. For example, in some variations, the device may activate an indicator comprising a visible, audible and / or tactile alarm or alert. For example, an indicator may include illuminating a light and / or sounding an alarm on the device. In some variations, the system may transmit (eg electronically, wirelessly, etc.) a signal to another device such as a computer, portable device, server, and / or monitoring station that indicates the alarm status of the device.
In any of the variations described herein, the device, system, or method can be configured so that when the current-off module detects or infers that a current is flowing between the anode and the cathode while the device is in the off state (for example, as long as the device is otherwise on), activation of an indicator may include switching the device to an end of the live state, for example, such as performing a device outage. In this way, when the current off module determines or infers that current is flowing between the anode and cathode when the device is not supposed to be delivering drug, the device (for example, the current off module) can prevent any additional unwanted drug administration.
<img file="MX347308B_D0016.tif" />
IMPb
INSTITUTO MÜUCANO DF. LA PROVIDA »industrial
In general, when the device or system methods of operating them) it is described as detecting current flowing between the anode and cathode of the device when the device is not supposed to be delivering drug (e.g. when a current off module detects current flow between the anode and the cathode in an off state) this can be interpreted in some variations as determining if there is a current above some threshold flowing between the anode and the cathode. As described above, depending on the way in which the current off module detects or infers the current flow between the anode and the cathode, this threshold can be a current threshold, a potential difference threshold (i.e. voltage), an inductive threshold, a capacitive threshold, or the like. The threshold can be predetermined (preset) on the device.
Brief Description of Figures
Figure 1A is a block diagram of an exemplary potential difference detection system that includes a controller, an electrotransport drug delivery circuit, a detection circuit, an anode, and a cathode.
Figure IB is a flow chart of an example automated self-test method of a configured electrotransport drug delivery system.
IMPI
INSTITUTO MEXICANO de la nomoAu INDUSTRIAL
<img file="MX347308B_D0017.tif" />
as a current shutdown test 'CodlffetétTSi'a' of anode / cathode voltage).
Figure 2A illustrates an exemplary two-part therapeutic agent delivery system.
Figure 2B shows the example system of Figure 1 combined to form a single, unitary device.
Figure 3 shows a perspective view with separation of parts of a two-part device.
Figure 4 shows a detached perspective view of an example tank module.
Figure 5 is a cross-sectional perspective view of a reservoir contact.
Figure 6 shows a bottom view of an electrical module and a top view of a tank module.
Figures 7A and 7B show cross-sectional views of a power ignition connector when opened (prior to actuation) and closed by a power ignition post acting through a power ignition receptacle.
Figure 8 shows a cross-sectional view of an outlet of the electrical module making contact with an inlet connector on the reservoir module.
Figure 9 is a circuit diagram of the electronics within an electrical module of the device
IMPI
INSTITUTO MEXICANO Dt LA MOHEDAL industrial
<img file="MX347308B_D0018.tif" />
described herein.
Figure 10 is a flow chart showing a device power-up sequence as described herein.
Figure 11 is a second flow chart showing an alternate power-up sequence for a device as described herein.
Figure 12 is a diagram showing the user mode diagram for an example mode and of a system that includes a shutdown self-test module.
Figure 13 shows an example of a software block diagram for the example in Figure 12.
Figure 14 illustrates a variation in the procedure for system initialization.
Figure 15 shows a software status graph for the example in Figure 12.
Figure 16 is an example diagram of a current control circuit for a variation of a drug delivery device.
Figure 17 shows a dosing mode flow chart.
Figure 18 shows a dose initiation flow chart.
Figure 19 shows a dose control flow chart.
Figure 20 shows a flow chart of
<img file="MX347308B_D0019.tif" />
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY determination of dose.
Figure 21 shows Table 1, which indicates a variation of the self-test sequence (the mode diagram in Figure 12 may correspond to this table).
Detailed description of the invention
Reference will now be made in detail to exemplary embodiments of the invention, examples of which are illustrated in the accompanying figures. While the invention will be described in conjunction with exemplary embodiments, it will be understood that it is not intended to limit the invention to these embodiments. Rather, it is proposed that the invention covers alternatives, modifications and equivalents, which may be included within the spirit and scope of the invention as defined by the appended claims.
One method for the transdermal administration of active agents comprises the use of electrical current to actively transport the active agent in the body through intact skin by electrotransport. Electrotransport techniques can include iontophoresis, electro-osmosis, and electroporation. Electrotransport devices, such as iontophoretic devices are known in the art. An electrode, which may be referred to as the donor active electrode, is the electrode from which the active agent is delivered into the body. The other electrode, which may be referred to as the counter electrode or return electrode, serves to
<img file="MX347308B_D0020.tif" />
IMPI Mexican institute • E LA MONEDAD
INDUSTRIAL close the electrical circuit through the ULltiipU. ΕΪ1 Uftldri tí <5 To the patient's body tissue, for example, the skin, the circuit is completed by connecting the electrodes to a source of electrical energy, and usually to circuitry capable of controlling the current 5 that passes through the device when the device is on and delivering power. If the substance to be propelled into the body is ionic and positively charged, then the electrode (anode) will be the active electrode and the negative electrode (the cathode) will serve as the counter electrode. If the ionic substance to be delivered is negatively charged, then the cathode electrode will be the active electrode and the anode electrode will be the counter electrode.
A switch-operated therapeutic agent delivery device 15 can deliver one dose or multiple doses of a therapeutic agent to a patient by activating a switch. On activation, this device delivers a therapeutic agent to a patient. A patient controlled device offers the patient the ability to self-administer a therapeutic agent as the need arises, for example, the therapeutic agent can be an analgesic agent that a patient can administer whenever sufficient pain is felt.
As described in greater detail below, any appropriate drug (or drugs) can be administered.
<img file="MX347308B_D0021.tif" />
IMPI • rsnTOTO MEXICAN
OF THE INDUSTRY CURRENCY!
by the devices described herein — For example, the drug may be an analgesic such as fentanyl (eg, fentanyl-HCL) or sufantanyl.
In some variations, the different parts of the electrotransport system are stored separately and connected together for use. For example, examples of electrotransport devices that have parts that connect together prior to use include those described US Patent No. 5,320,597 (Sage, Jr. et al); United States Patent No. 4,731,926 (Sibalis), United States Patent No. 5,358,483 (Sibalis), US Patent No. 5,135,479 (Sibalis et al.), UK Patent Publication GB2239803 (Devane et al), US Patent No. 5,919,155 (Lattin et al.), US Patent No. US Patent No. 5,445,609 (Lattin et al.), US Patent No. 5,603,693 (Frenkel et al.), WO 1996036394 (Lattin et al.), and US 2008/0234628 Al (Dent et al.).
In general, the devices and systems described herein include an anode and a cathode for the electrotransport of a drug or drugs into the patient, for example, through the skin or other membrane and a controller to control delivery (for example , turning on or off the administration); All of the variations described herein may also include a shutdown module for
<img file="MX347308B_D0022.tif" />
monitor the anode and cathode when the drive circuit is in the off state while on to determine if there is a potential and / or current (above a threshold value) between the anode and the cathode when the controller for the device to otherwise turn off the device so that no drug must be delivered to the patient. The controller may include a trigger controller (eg, a trigger module or trigger circuitry) to regulate, when the device is on, the application of current / voltage between the anode and the cathode and thereby deliver the drug.
Throughout this description, unless otherwise indicated, the singular forms a, an, the, and the are intended to include the plural references, thus, for example, reference to a polymer includes a polymer. individual as well as a mixture of two or more different polymers, a contact can include several contacts, a post can include several posts, etc.
As used herein, the term "user" indicates anyone who uses the device, be it a healthcare professional, a patient, or another individual, for the purpose of administering a therapeutic agent to a patient.
In general, the shutdown module can include hardware, software, firmware, or some combination of these (including control logic). For example, as illustrated
IMPI
MEXICAN INSTITUTE
DE LA FROFIEDAD 'INDUSTRIA!
<img file="MX347308B_D0023.tif" />
In FIG. 1A, a system may include an anode "urT'or" SCOCli "and a detection circuit. The sensing circuit may be part of (or may be used by) the shutdown module to detect any current between the anode and the cathode when the device is otherwise off. The device may also include a controller that controls the operation of the device. The controller can include a processor or ASIC that includes the shutdown module.
In general, the shutdown module can also be referred to as a type of self-test that is performed by the device. In some variations, the shutdown module includes or is referred to as an anode / cathode difference test or shutdown test, because in some variations it can determine if there is a voltage difference between the anode and cathode when the device should be off. .
Figure IB illustrates a simplified version of a method of performing an anode / cathode voltage difference test (also referred to as a shutdown test). Initially, when the device is turned on but not activated to deliver drug (for example, it is turned on but in an off state), the device can periodically perform any number of self-tests, as long as it is in the ready mode. In particular, the device can perform the shutdown test to confirm that as long as
<img file="MX347308B_D0024.tif" />
IMPI * ΐχπτυτο MIXICAN »·
OF VA CURRENCY I ΙΝΒΙ'ΓΜΙΑ 'that the device is otherwise switched off, - »or · there is<sup>1</sup> a significant current flowing (which can be inferred, for example, by determining that there is no potential difference above a threshold level sufficient to deliver drug to the patient) between the anode and the cathode. In some embodiments in which current is determined by monitoring the potential difference, this potential difference can easily be determined by examining the difference between the anode voltage and the cathode voltage. Any other subsystem or method for measuring and / or inferring current flow between the anode and cathode can also be used, as long as the test method does not by itself result in undesirable drug delivery.
Returning to Figure IB, in initial step 102 self-tests, such as the power-off self-test, can be performed periodically and automatically while the device is in the ready mode. The paid self-test can be synchronized and executed by control logic (for example, running in a controller), which can be part of another controller or it can be a controller. In general, the controller (or a portion of a controller) performs the shutdown test can be referred to as a shutdown module. The self-test can be activated at regular intervals, such as every 30 seconds, every minute, every two minutes, and so on. Once the self-test is activated, in some variations the
<img file="MX347308B_D0025.tif" />
IMPI
MEXICAN INSTITUTE
DE PRONF.DAL INDUSTRIAL can be made by determining the difference between the uul'LúJé and the anode and the voltage at the cathode in a way that does not activate the release of the drug. For example, the determination of the node voltage can be isolated from the determination of the voltage of the cathode 104. The difference in the voltages can then be compared to a threshold value 106, which can be referred to as the turn-off threshold. Examples of this threshold include 0.5V, 0.75V, 0.85V, 2.5V, and so on. If the difference is less than the threshold value then the device passes the self-test, and can continue in ready mode 110, or if device activation has been activated (for example, by pressing a button), the device can start to administer the drug 112-116. Alternatively, if a leakage current is detected, for example when the voltage difference is greater than (or equal to) the threshold voltage (fault 122), the device can trigger an alert and / or it can park to prevent unwanted drug administration.
Example 1: Two-part system
An example of a two-part system is described below that may include self-tests, including in particular, an anode / cathode voltage difference test. For example, in some variations, the devices that include the shutdown self-test are configured as two-part electrotransport therapeutic agent delivery devices, such as
<img file="MX347308B_D0026.tif" />
iontophoresis devices, in which the two parts of the device are provided separately and assembled to form a unitary device, switched on at the point of use, that is just before use. In this example, a part of the device, which may be referred to herein as the electrical module, supports essentially all of the circuitry, as well as the power source (eg, battery), for the device; and the other part, which may be referred to herein as the reservoir module, contains the therapeutic agent to be delivered along with electrodes and hydrogels necessary to deliver the therapeutic agent to a patient. The device is configured such that the power source is kept electrically isolated from the rest of the circuitry in the electrical module until the electrical module is combined with the reservoir module. In this way, the modalities provided herein allow the combination of the electrical module and the tank module, whereby in a single action the two modules form a single unit and the battery is inserted into the circuitry, thus turning on the device, in a single action by the user.
As used herein, the term simultaneous, and grammatical variants thereof, indicate that two or more events occur at approximately the same time and / or that they can occur without any intervention steps. For example, when the connection of the modules is presented ^ e ^ 'way' simultaneously with the connection of the battery in the circuit, the term simultaneously indicates that when the modules are connected, the battery is connected in the circuit at approximately the same time , in a single action by the user, and that there is no additional step necessary on the part of the user to connect the battery to the circuit. The term "substantially homogeneous" and grammatical variants thereof indicate that two events occur at approximately the same time and no significant action is required by the user between the two events. For ease of illustration only, this significant action may be the activation of a separate switch (other than the ignition switches described herein), removal of a tab, or other action to connect the battery in the electrical module to the circuitry in the same in the connection of the two modules to each other.
Unless otherwise modified herein, the term break and grammatical variants thereof refer to destroying or deforming something to the point that it is no longer operable for its intended purpose.
An electrotransport device can be assembled prior to use for electrotransport delivery of ionic compounds (eg, ionic drugs such as fentanyl and analogs, polypeptides, and the like) across a surface, such as the skin. A device of
<img file="MX347308B_D0027.tif" />
The electrotransportation industry may comprise an upper or protruding portion, referred to herein as an electrical module, and a lower or bottom portion, referred to herein as a reservoir module. The electrical module may contain circuitry (for example, a printed circuit board), a power source (for example, a battery), one or more ignition switches, and other circuitry as may be deemed desirable for the operation of the device (such as such as an activation switch, a controller, a liquid crystal diode (LCD) display, a connector, a light-emitting diode (LED), an audible indicator (for example , a sound transducer), or combinations of these), as well as electrical output contacts for electrically connecting the electrical module to a tank module. When obtained by the user, the electrical module is separate from the tank module. In this state, the battery is kept outside the electrical circuit (although within the electrical module), thereby preventing the battery from being discharged through the circuit prior to use. Because the battery is electrically isolated from the circuitry prior to combining the electrical and reservoir modules, the circuitry has essentially no electrical charge applied to it prior to combining the two modules, thereby rendering the circuitry less susceptible to corrosion than if the battery
<img file="MX347308B_D0028.tif" />
IMPI
INSTITUTO MEXICANO DSMr »ORl» AD INDUSTRIAL was on the circuit. In some variaoio »& g<sub>r</sub>the module · ele · off can be configured to operate even when the two parts of the device / system are not connected (for example, even with the device turned off, and / or with the battery that activates the drug administration, disconnected). In this way, a separate power source / battery can turn the module off in some variations. In other variations the module off can be configured to operate when the device is in an off state, but otherwise on (for example, when the two halves of the system / device are connected). In any of the variations described herein the shutdown module can be electrically isolated from the drug delivery sub-components of the device / system. In this way, even if a short occurs in the drug delivery component of the device, the shutdown module can operate.
The reservoir module can contain electrodes and reservoirs for the administration of therapeutic agent to a patient. At least one reservoir can contain the therapeutic agent to be administered. At least one counter reservoir is provided, which generally does not contain a therapeutic agent, although in some embodiments the counter reservoir may contain a therapeutic agent. Before the electrical module is connected, the tank module is kept both physically and electrically isolated from the electrical module.
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX347308B_D0029.tif" />
For example, one or both of the modules can be placed in a bag, such as a plastic bag or foil, in order to prevent contamination with water, particles, vapors, and the like. As a non-limiting example, both the electrical module and the reservoir module can be sealed in the same bag. As a further non-limiting example, the reservoir module can be sealed in a bag and the electrical module is left outside the sealed bag. In other non-limiting examples, the two modules can be sealed in separate bags 10.
Before use (for example, just before use), the electrical module is combined with the reservoir module to form a single unit, which in a single action, connects the battery in the circuit and powers the device. The 15 terms before use and just before use are described in more detail later herein. In general, these terms are intended to indicate that the two parts of the device are combined by a user, and that the device is then used to deliver the therapeutic agent to a patient within a predetermined window of time, eg, 0. to 8 hrs or 0 to 72 hours, after the two parts of the device are combined. This predetermined window of time may vary, depending on the therapeutic agent, the amount of the agent to be administered, the requirements of the various regulatory agencies, and so on.
IMPI
MEXICAN INSTITUTE
OF INDUSTRIAL NONITY
<img file="MX347308B_D0030.tif" />
For the sake of clarity, it is to be understood that the combination of electrical modules and warehouse is postponed after manufacture and is carried out at the point of use, so that during shipment and storage, the energy source enclosed within the The electrical module is electrically isolated from the circuitry until the two modules are combined by the user.
As noted above, the combination of the electrical and reservoir modules connects the battery in the circuit to achieve an on state, without any additional action required by the user. For example, there is no need for the user to activate an ignition switch or remove a tab in order to connect the battery in the circuit. Once the two modules have been properly combined, power is supplied to the circuitry. The circuitry can then operate normally. Normal operation may include various circuitry tests, operation of various indicators (such as the LCD, LEDs, and sound transducers, mentioned above), the setting of various logic markers, detection of error states and / or logic markers, and so on. . Normal operation also includes receiving an activation signal, for example, through an activation button or switch, and supplying power to the electrodes through electrical outputs connected to electrical inputs on the reservoir module.
<img file="MX347308B_D0031.tif" />
IMPI
INJTTTVTO MEXICANO DE LA nenEDA · INDUSTRIAL
In addition to reducing corrosion and battery discharge before use, another advantage of the device is that the electrical outputs of the electrical module and the inputs to the reservoir module (i.e., the contacts between the two modules) are physically and seamlessly separated. from the ignition switches that connect the battery in the circuit. This is advantageous, at least because it allows the ignition devices, which connect the battery in the circuit, to remain completely internal to the electrical module. This in turn allows the contacts comprising the ignition switches to be kept free of contaminants, since the electrical module is at least in some ways sealed against contaminants, such as water (including water vapor) and / or particles. As described herein, an ignition switch is enclosed by an actuator through an elastomeric seal, which allows the battery to be connected in the circuit without the contacts that comprise the switch that is exposed to the environment external to the electrical module.
In some embodiments, two or more power switches are used. In some particular embodiments, the ignition switches are physically far from each other, for example, on the order of 0.1 cm to several cm. In some embodiments, the switches are separated by at least 0.5 cm.
<img file="MX347308B_D0032.tif" />
Since the two modules form a unitary ri i spns it í vn, they thus advantageously include one or more pairs of mechanical couplers to hold the two modules together. These pairs of couplers can include pairs of snap-fit receptacles, which in some embodiments are designed to become inoperative (deform and / or break) if the two modules are forced apart after they are combined. Thus, the devices described herein are well suited for one-time use only, since mechanical means can be adapted to ensure that the device is used only once.
In some embodiments, the device may alternatively or additionally employ electrical means to ensure that the device is used only once. For example, an electrical means may employ a controller in the electrical module that increments an on counter when the device is on. In these modes, before or after the controller increments the counter, it detects the number of counts on the counter, and if it finds that the power-on counts exceed some predetermined value, it runs a routine to turn off the device. As a non-limiting example, the counter may be initially set to zero at manufacture. The device can then be switched on briefly by an external power supply during post-manufacturing testing, which the controller
<img file="MX347308B_D0033.tif" />
IMPI
MEXICAN INSTITUTE
DE LA WftBAD INDUSTRIAL interprets it as a power-on event, and ................ _manpr ^ increments the power-on counter by 1 count. Then, when the device is assembled by the user before use, the controller interprets the battery connection in the circuit as a power-on event, and increments the power-on counter by 1. The controller then detects the count on the counter. If the count is 2 or less, the controller allows the device to operate normally. However, if the count is 3 or more, the controller initiates a shutdown sequence.
As a second non-limiting example, the counter may be initially set to zero at manufacture. The device can then be turned on briefly by an external power supply during post-fabrication testing, which the controller interprets as a power-on event, thereby incrementing the power-on counter by 1 count. So when the device is assembled by the user before use, the controller detects the count on the counter. If the count is 1 or less, the controller increments the power-on counter and allows the device to operate normally. However, if the count is 2 or more, the controller initiates a shutdown sequence.
Although reference is made here to counting power-up sequences, still other events can be counted, either in place of power-up events, in addition to power-on events.
<img file="MX347308B_D0034.tif" />
IMPI
INSTITUTE MBUCANO
OF THE INDUSTRIAL nOHEDAC ignition, or as a substitute variant for ignition events.
The quench sequence can be a sequence such as described in US Patent No. 6,216,003 Bl, which is incorporated herein in its entirety.
In some embodiments, the device combines both mechanical (eg, one-way snaps) and electrical (eg, ignition counter) means to ensure that the device cannot be used more than once.
A single use device / system can include multiple administrations of a therapeutic agent, for example, within a particular window of time after the device has been turned on. The length of time for which the therapeutic agent can be delivered and / or the number of total doses allowed to be delivered by the device, can be predetermined and programmed into a controller. Means of controlling the number of doses that can be administered and / or the period during which the therapeutic agent can be administered are described, for example, in US Patent Nos. 6,216,003 Bl, which is incorporated herein. its entirety. For the sake of clarity, the term single use is not intended to limit the device to a single drug administration. Rather, the term single use is intended to exclude the use of the device by more than one patient or on more than one occasion;
<img file="MX347308B_D0035.tif" />
it is also proposed that it excludes the use of an electrical module with more than one tank module and / or the tank module with more than one module and / or detachment of the tank module from the electrical module and re-coupling. Thus, the single use feature is in some embodiments employed to prevent the patient or another person from releasing the drug and using it at a later time. In some embodiments, this feature can be employed to prevent abuse of the therapeutic agent.
In at least some embodiments of the device described herein, the device is configured to prevent contamination of the circuitry before and during use to reduce the likelihood of device malfunction. For example, the environment of use may include emergency rooms, operative, post-operative, or other medical treatment environments, in which liquids and potential particles are prevalent. Accordingly, at least some embodiments of the device are configured so that one or more seals are formed in order to exclude ambient contaminants from entering the working parts of the device, such as, in particular, the circuitry. In some embodiments, one or more seals are formed around the electrical contacts between the electrical outputs on the electrical module and the electrical inputs on the reservoir module.
<img file="MX347308B_D0036.tif" />
IMPI
ΙΝΜΤΠΓΓΟ MBUCANC OF INDUSTRIAL CURRENCY
In some modes, the conEacWü til! uiiciíiiJide »are sealed from the ingress of contaminants, such as particles and fluids. In particular embodiments, the ignition contacts are sealed before the modules are combined, during the act of combining, and after the two modules are combined. In at least some of these cases, the ignition contacts can be actuated (switched to a closed position) by an actuator acting through an interposed elastomer, which maintains a watertight seal while at the same time being deformed by an actuator. (such as a post or other elongated member) to push the ignition switch to a closed position.
Other stamps are possible and may be desirable. For example, a seal can be formed between the two parts (modules) when they are combined.
The device described herein can be appreciated by the person skilled in the art in consideration of the non-limiting examples, which are represented in the attached figures. Starting with FIG. 2A, an exemplary electrotransport device 10 is depicted. The device comprises two parts, an upper part referred to herein as the electrical module 20 and a lower part, referred to herein as the reservoir module 30. The electrical module 20 includes an electrical module body 200, with a top (proximal) surface 220 and a surface of
<img file="MX347308B_D0037.tif" />
IMPI • fSTTFUTO MEXICANO DE LA FROPIEDAP INDUSTRIAL fund (distant) (not represented in this view). Module body 200 has a rounded end 234 and a square end 254. Top surface 220 includes a window or aperture 204 for viewing an LCD screen 208, an activation button 202, and an LED window or aperture 232. In this view An alignment feature 206 is also visible.
The reservoir module 3 0 includes a reservoir module body 3 00, which supports electrodes, reservoirs (see description herein), and input contacts 316. In this view, top surface 320 can be seen, in which the Input contact seals 322, circumscribe input contacts 316. Seals 322 form contaminant impervious seals with corresponding members of electrical module 20 (see description herein). The upper surface 320 of the reservoir module body 300 has a rounded end 352 and a square end 356. Also visible are snap-fit receivers 310 and 312, which are configured to cooperate with corresponding snaps on the lower surface. of the electrical module 20. In some embodiments, the snaps 310 and 312 are of different dimensions so that each can receive a snap of the correct dimension only, with the result that the device 10 cannot be mounted in the wrong orientation. As a visual aid for proper alignment of the two modules 20, 30, the module
<img file="MX347308B_D0038.tif" />
Reservoir 30 also has an alignment feature 306, which a user can align with alignment feature 206 on electrical module 20 to ensure that the two modules 20, 30 are properly aligned.
Also visible in this view is a depression 314, which in some embodiments is shaped to accept a complementary protruding member on the lower surface of electrical module 20 in only one orientation. The depression 314 and the bulge in the electrical module 20 thus perform a keying function, further ensuring that the two modules can be mounted in only one orientation and / or guiding the user to mount the two modules in the correct orientation. Another illustrative and non-limiting keying (alignment) feature is the asymmetry of electrical module 20 with respect to reservoir module 30. As shown for example in FIG. 2A, the rounded end 234 of the electrical module 20 corresponds to the rounded end 352 of the tank module; and the square end 254 of the electrical module 20 corresponds to the square end 356 of the tank module. The resulting asymmetry helps the user align the electrical module 20 with the magazine module 30 and ensures that the user can mount the two modules in only one orientation. While representing the rounded end in this illustration as being distant from the viewer, one skilled in the art will recognize that this is <sup>42</sup> IMPI Mexican institute OE LA PROPERTY industrial only one possible orientation. As an example, the rounded portion may be at the other end or one side of the device. Additional keying features are discussed in more detail herein.
Also depicted in this view is an ignition post 318, protruding from the upper surface 320 of the reservoir module 30. The ignition post 318 is configured to contact a corresponding feature on the electrical module to actuate the ignition switches, thereby electrically connecting the battery within the electrical module 20 in the circuitry contained therein. These features will be described in more detail later. However, it should be noted that while there is only one ignition post 318 depicted in this view, one of the proposed ignition posts is obstructed from the perspective of the device. In some embodiments, at least two posts and at least two ignition switches are considered advantageous, as this is considered the minimum number of switches necessary to electrically isolate the battery from the rest of the circuit before use. However, this number is illustrative only and any number of poles and power switches may be employed in the devices described herein.
Similarly, while there are two input contacts 322 represented, and it is considered necessary that there be
<img file="MX347308B_D0039.tif" />
at least two of these contacts, one posiTIOL) and one aeijjütti ¿Tirgi<sub>FI </sub>this number is also illustrative only; and any number of contacts can be used, eg, two positive and one negative, one positive and two negative, two positive and two negative, equal to or greater than two in the devices according to this invention.
The two modules 20, 3 0 are combined (assembled) before use to form the unitary device 10 shown in Figure 2B, in which those parts that are visible in Figure 2B have the same numbers as used in Figure 2A .
The device 10 can be further understood by considering Figure 3, in which the electrical module 20 and the tank module 30 are depicted in perspective views with separation of parts. On the left side of Figure 3, electrical module 20 is visible with the upper body 228 of the electrical module, the lower body 238 of the electrical module, and the interior assembly 248 of the electrical module. Visible in the upper body 228 of the electrical module are the activation button 202, the aperture or LED window 232, the aperture or LCD window 208. While it is also desirable in some embodiments to have an alignment feature in the upper body 228 of the electrical module, this view does not include this alignment feature.
Visible in the lower body 238 of the module
<img file="MX347308B_D0040.tif" />
IMPI
MEXICAN INSTITUTE
OF ELECTRICAL INDUSTRIAL FROHSITY are the upper surface of —iee · elastomeric ignition receptacles 218, as well as springs 224. The function of springs 224 will be written in more detail later. At this point it is noted that springs 224 provide bias for connectors on the opposite side of lower electrical module body 238.
The electrical circuit assembly 248 comprises a controller 244 below an LCD display 204, an LED 236, and an activation switch 242, all of which are arranged on a printed circuit board (PCB) 252. Also Barely visible in this part-spaced view 290 is battery 292 on the underside of PCB 252. Battery 290 fits within battery compartment 292 on lower electrical module body 238. A flex circuit 294, which provides an electrical connection from PCB 252 to LCD display 204, is also depicted in this view. The LCD display 204 can be configured to communicate various data to a user, such as a ready indicator, a number of doses delivered, a number of doses remaining, time elapsed since the start of treatment, time remaining in the cycle of use of the device, battery level, error codes, etc. Similarly, LED 236 can be used to provide various data to a user, such as indicating that it is on, the number of doses delivered, and so on. He
<img file="MX347308B_D0041.tif" />
IMPI
Μ * ΚΑΝΟ INSTITUTE OF CURRENCY industrial 248 electrical circuit assembly t-amhlyn include a 246 sound transducer that can be configured to provide an audible signal on, an audible signal at starting dose administration, an audible alarm of 5 error, etc. .
The tank module 30 is shown in the perspective view with part separation on the right side of Figure 3. The tank module 30 comprises a tank body 300, an electrode housing 370, an adhesive 380 10 and a liner release 390. Upper surface 320 of reservoir body 300 includes depression 314, ignition posts 318, inlet connectors 316, seals 322, and coupler receptacles 310 and 312. Electrode housing 370 includes reservoir compartments 388. Electrode pads 374 and reservoirs 376 are inserted into reservoir compartments 388. Electrodes 374 make contact with input contacts 316 through openings 378. Adhesive 380, which provides a means of attaching device 10 to a patient, has openings 382, 20 through which reservoirs 376 make contact with the skin of a patient when adhesive 380 is attached to a patient. Removable release liner 390 covers reservoirs 376 and reservoirs 376 prior to use, and is removed to allow device 10 to attach to a patient. Assembled, the 25 electrode pads 374 make contact with the part
<img file="MX347308B_D0042.tif" />
IMPI
INSTITUTO MEXICANO DE LA MOPCDAP INDUSTRIAL inferior of the inlet connectors 316 through the openings 378, providing an electrical connection between the inlet connectors 316 and the reservoirs 376. The connection between the reservoirs 376 and the patient's skin is made through openings 3 82 after release liner 390 is removed. Also visible in this view is a tab 372, which can be used to remove the electrode housing 370 from the deposit body 300 for deposit removal 374, which in some embodiments contains residual therapeutic agent, after the electrode has been used. device 10.
Another view of the tank module 3 0 appears in Figure 4. In this view, the electrodes 374 are seen through the openings 378 in the tank compartments 388. Notable in Figure 4 is the depression 314 which has a notch 354 , which is adapted to access a complementary feature at the bottom of an electrical module. This is one of many possible keys that can be provided for the device. In some embodiments, depression 314 may receive the bottom of a battery compartment in the electrical module; however, the person skilled in the art will recognize that many of these keying features are possible. This keying feature may be the dimensions of the snap-fit receptacles 310, 312 and the
<img file="MX347308B_D0043.tif" />
<img file="MX347308B_D0044.tif" />
INSTITUTO MEXICANO DE LA RROHBOAD INDUSTRIAL corresponding snap fasteners, which allow the assembly of the two modules in just one configuration. Other keying characteristics may include the size and / or position of the electrical inputs 316 on the tank module 30 and the corresponding electrical outputs on the electrical module, the size and / or positions of the ignition posts 318, complementary shapes of the tank module 30 and electrical module 20.
Figure 5 is a cross-sectional perspective view of an inlet connector 316 in a reservoir module 30. Visible in this view are the upper surfaces 320 of reservoir body 300. Circumscribing the inlet connector 316 is a seal 322. Seal 322 is configured to contact a corresponding seal on an electrical module to prevent contaminants from entering the device assembly. Contact 316 is in some embodiments, advantageously, a flat (flat or substantially flat) metal contact. The contact can be essentially any conductive metal, such as copper, brass, nickel, stainless steel, gold, silver, or a combination of these. In some modalities, the contact is made of gold or gold plate.
Also visible on the upper surface 320 of the reservoir module 3 0 is an ignition post 318 that protrudes from the surface 320. The lower portion of the input connector 316 is configured to contact
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL CURRENCY
<img file="MX347308B_D0045.tif" />
a reservoir (not shown) through an opening 378 in reservoir compartment 388 in electrode housing 370.
Additionally, part of the battery receptacle 314 can be seen in Figure 5.
Figure 6 is another view of the two modules 20, 30 side by side. On the left side of Figure 6 is the bottom side of the electrical module body 200; and on the right side is the upper side of the tank module 30. The bottom surface 230 of the electrical module body 200 has snaps 210, 212 protruding therefrom, which are made of a size and shape to fit within the snap-fit receptacles 310, 312 on top of the tank module body 300. As discussed above, in some embodiments the snaps 210 and 212 are made a different size so that the snap 210 will not fit within the snap socket 312 and / or the snap 212 will not fit. will fit within snap-fit receptacle 310. This is one of several keying features that can be incorporated into device 10. As an illustrative example, the snap 212 cannot be adjusted at 310, because the snap 212 is larger than the receptacle 310; but snap 210 can fit into receptacle 312, because the snap is smaller and the receptacle is larger.
<img file="MX347308B_D0046.tif" />
big. In other embodiments, it is possible to size the snaps as well as the receptacles so that one snap / receptacle pair is larger in one dimension (for example, horizontally), while the other snap / receptacle pair it is greater in the other dimension (for example, longitudinally). Another keying feature is the boss 214, which can house the battery or other component, and which is formed to fit into a configuration only within the depression 314.
The snaps 210, 212 at least in some embodiments are one-way snaps, meaning that they deflect to fit within the receptacles 310, 312 in such a way that they are not easily removed, and in at least some preferred embodiments, they are configured to fit. break (or deform to the extent that they are no longer operable) if forced to separate, so that modules 20, 30 cannot be reassembled to form a single unitary device. In some embodiments, this feature is provided as an anti-abuse character to the device, such that the tank module 3 0 cannot be salvaged after use and used with a different (or the same) electrical module 20.
The lower surface 230 of the electrical module body 200 also has two electrical outlets 216, also referred to herein as outlet mounts, which in
INSTITUTO MEXICANO DE LA PROPERTY INDUSTRIAL certain modalities have one or more protrusions 266 that protrude from the surface of the same. These mounts 216 are circumscribed by mount seals 222. Mounts 216 are configured to contact 316 inlet connectors on reservoir body 300. Additionally, mount seals 222 are configured to contact and create a seal. waterproof with outlet seals 322. Advantageously, the saddle seals 222 are made of an elastomeric material that creates a contaminant impervious seal around the saddles 216 and when mated with the inlet connector seals 322, creates additional contaminant impervious seals.
The ignition receptacles 218 are configured to receive the input posts 318. In some embodiments, the ignition receptacles 218 are made of a deformable (eg elastomeric) material. In these embodiments, the ignition posts 318 deform the ignition receptacles 218 so that they contact the ignition contacts (described in more detail below) and move them to a closed position, thereby connecting the battery in the circuit. . Once the two modules 20, 30 are snapped together, the posts maintain pressure on the ignition contacts through the receptacles 218 and keep the battery in circuit.
While the 216 mounts and the <sup>51</sup> ΙΜΡΙ ^%
NSTttyTO MEXICANO • DE LA PROPERTY industrial entry 316 are represented in the f igS ^ a ^ - ^ g ^ ceme — qua —.- are essentially the same size and are placed symmetrically along the longitudinal axis of device 10, it is You can introduce another keying feature into the device by changing the position and / or size relative to the longitudinal axis of the mounts 216 and contacts 316, the ignition posts 318 and the receptacles 218, and so on.
A cross section of one embodiment of an on switch 270 is shown in Figures 7A and 7B. The on switch 270 comprises the movable contact 272 and a stationary contact 274. Each of the movable contact 272 and the stationary contact 274 connects to a portion of circuitry on printed circuit board (PCB) 252. In the open position shown in Figure 7A, the movable contact 272 is deflected away from the stationary contact 274, while in the closed position shown in Figure 7B, the contacts 272 and 274 are pressed together by the ignition post 318, protruding from the upper surface 320 of the reservoir module 30. Ignition post 318 acts through ignition flexible (elastomeric) receptacle 218 to force to force movable contact 272 downward until it is in contact with stationary contact 274. For reasons of visibility, stationary contact 274 is
<img file="MX347308B_D0047.tif" />
IHSTTrUTO MEXICANO DE LA MONEDAD industrial shows elevated PCB 252. However, the stationary contact 274 does not need, and in general will not be, elevated from PCB 252. In at least some modalities, the contact stationary 274 'will be an exposed metallic trace on the surface of PCB 252, although other configurations are also possible. Stationary contact 272 is made of a suitably resilient material, such as a copper alloy, which deflects to remain in the first open position unless actuated by ignition post 318. Receptacle 218 may resemble a dome when used. viewed from the side facing the contacts 272, 274 and is formed in at least some embodiments of a suitable elastomeric substance that allows the ignition post 318 to deform without breaking the seal. In some embodiments, the receptacle 218 can also be flat or the dome can be placed in the opposite direction. In at least some embodiments, the receptacle 18 provides a contaminating seal between the external and internal parts of the electrical module 20.
Figure 8 shows a cross section of a part of a device 10 in an assembled state. Device 10 comprises upper electrical module 20, comprising upper body 200, and reservoir module 30, comprising reservoir body 300, which are shown in this cross-sectional view as combined. The parts of the electrical module 20 that are visible in this sectional view
IMPI
MEXICAN INSTITUTE
SAY THE MOHEDA OR
INDUSTRIAL
<img file="MX347308B_D0048.tif" />
transverse include module body 200 · -eAeoferioo, -y »™ contains sound transducer 246, LCD 2 04, controller 242, and battery 290, all of which are on printed circuit board (PCB) 252. A flex circuit 294 provides a connection between the PCB 252 and the LCD 204. Also visible are the contact mount 216, which has the protrusions 266, and the snap 210. As can be seen, contact mount 216 is biased toward reservoir module 300 by a coil spring 224, which fits within contact mount 216 and exerts a force through contact mount 216 to press the Contact mount 16 against input connector 316 of reservoir module 30. Mount 16 is circumscribed by a mount seal 220, which contacts mount 16 throughout its full length of travel. In at least some embodiments, this mount seal 222 is an elastomeric seal that provides a contaminant-tight fit between the mount seal 222 and the mount 216, whereby the electrical module 20 is sealed against contaminants such as particles and fluids ( for example, humidity) in the environment.
The reservoir module 30 includes a reservoir 376 and an electrode 374 within the reservoir compartment 388 in the electrode housing 370, which also has an electrode housing tab 372. In the assembled state, the snap 210 is caught in socket flange 324
<img file="MX347308B_D0049.tif" />
snap-fit 310. In at least in giimn mnHulidadpg. snap 210 is made of a strong polymer and is deflected to maintain contact with flange 324 so that the two modules 20, 30 cannot easily be separated. In some preferred embodiments, snap 210 is configured that if the two modules 20, 30 are separated, snap 210 (and / or flange 324) will break (or deform to the extent that they are no longer operable). time) and are subsequently unable to couple the two modules together.
Also depicted in this view is an inlet connector seal 322, which in this illustration forms a ridge 326 (inlet connector seal ridge) that circumscribes the inlet connector 316. When the two modules 20, 30 are assembled, this inlet connector seal ridge 326 contacts and presses on the elastomeric mount seal 222, thereby preventing the entry of contaminants, such as particles and liquids, into the space between them. Contains output contact mount 216 and input contact 316.
Mount 216 exits through aperture 378 in reservoir compartments 388. At least protrusions 266 on mount 216 contact input connector 316 to provide electrical contact between electrical module 20 and reservoir module 30. . He
<img file="MX347308B_D0050.tif" />
IMPI
MEXICAN INSTITUTE
OF INDUSTRIAL PROPERTY spring 224 provides mechanical deflection to force, the protrusions 266 to maintain contact with the input connector 316. Although the mount 216 is shown to be deflected by a coil spring 224, the person skilled in the art You will recognize that other springs and dock-type devices can be used within the scope of the device described herein. For example, and without limitation, coil spring 224 can be replaced with a bundle spring or similar device.
As can be seen in Figure 9, which is a high-level schematic diagram of the electronics 50 within the electrical module 20, the electronics 50 can be viewed as including the circuitry 40 (including the controller, various indicators, etc.). ) connected to battery 290 via ignition switches SI and S2 (corresponding to ignition switch 270 in Figures 7A, 7B). Circuitry 40 controls the voltage distribution Vout across outputs 216a, 216b, which are connected to corresponding inputs on the reservoir module. It will be understood that, although the configuration of the power switches SI and S2 shown in Figures 7A and 7B is considered to provide certain advantages, such as ease of operation and manufacture, other switch configurations may be employed within the scope of the invention. device described herein. These switches can
<img file="MX347308B_D0051.tif" />
IMPI
MEXICAN INSTITUTE
PE THE INDUSTRIAL TROMEDAP include HarTizamipnto switches mee «<=> —doανία» mechanically to the open position, which can be pushed to the closed position by an ignition post or similar actuator. As can be seen in this figure, the circuit 50 comprising the battery 209 and the rest of the circuitry 40 is only completed if both SI and S2 are both kept closed. Before SI and S2 are closed, for example, through the mechanical action of the ignition posts, battery 290 is isolated from circuitry 40, since the circuit is open and does not allow current to flow through the same. As mentioned above, this reduces drain on the battery before use and reduces corrosion for the most part, since the circuitry is not powered and thus has no extrinsic charge applied to it. Also, if during operation before use one of the switches is closed, for example for a short time, the device will not turn on. In at least some embodiments, it is considered advantageous for the controller to detect the brief false closure of both switches SI and S2 in order to account for the occasional, accidental closure of the switches before use. Also, as discussed above, it is considered advantageous in some embodiments for the two switches SI and S2 to be physically and / or electrically distant from each other. Separating the two switches reduces the probability that something will cause one of the switches to malfunction.
ΙΜΡΙ «^
Mexican INSTITUTE
OF THE INDUSTRIAL PROHIDITY operation (for example, closing, either permanently, irreversibly or intermittently) will not affect the other switch. Additionally or alternatively, the two switches may be located on two different sides of the battery or on the same side of the battery. Thus, while in Figure 9 the switches SI, S2 are depicted on the positive (+) side of battery 290, one or both may be located on the other side of the battery. This way you can place 1, 2, 3 or more switches on one side (positive or negative) of the battery and you can place 0, 1, 2, 3 or more switches on the other side (negative or positive) of the battery. drums. The physical separation of the two switches can be 0.1 cm to several cm and in some embodiments at least 0.5 cm.
Also evident in Figure 9 is that the switches SI, S2 are far from the outputs 216a, 216b. In this way, the outputs from the electrical module to the tank module are separated from the switches SI, S2. Although in some preferred embodiments, the closing of the SI, S2 switches occurs as a result of the same action that connects the outputs 216a, 216b to the corresponding inputs in the tank module, the SI, S2 switches are far from the outputs 216a, 216b. This allows the SI, S2 switches to be completely internal to the electrical module, and in some modes they
IMPI INSTITUTO MEXICANO DE LA EROHIDAP INDUSTRIAL -seal against the entry of contaminantac, toír gama agua<sup>1</sup>, (including steam) and / or particles.
Figures 10 and 11 provide two alternative firing sequences for a device 10 as described herein. The first alternative shows that in the first step, S502, four events are presented, all at once, in a single action by the user; the snaps snap into their respective receptacles; the output and input contacts engage to provide electrical contact between the reservoirs in the reservoir module and the electrical module circuitry; the ignition posts close the ignition switches on the electrical module; and thus the battery is plugged into the circuit and begins to provide power to the circuitry. In step S504, the controller waits a minimum period of time (eg 10-500 ms) before proceeding to the next step. In some embodiments, S504 is removed from the power-up sequence. In some modes in which S504 is included in the power-up sequence, if the controller fails to maintain power for a predetermined minimum period of time, that is, for example if it loses power during this period, the timer is reset to zero. Assuming that the power is maintained through the time period in step S504, the controller then increments the on counter by one in step S506. In step
<img file="MX347308B_D0052.tif" />
IMPI
INSTITUTO MEX1CANC DE LA MOHEDAL. INDUSTRIAL
S508, the controller then checks the uúmpfQ Hp m ^ nt-aa on the ignition counter, and if it is less than or equal to a certain predetermined number (in this example 2, assuming the counter has been set to 1 by a test in factory, although other values are possible) the controller proceeds to step S510, which includes a self-check. However, if the count is greater than the predetermined number, then the controller initiates step S516, which includes a shutdown sequence, which may include sending an error message to an LCD screen, activating an LED indicator, and / or sounding an audible alarm. After the self-test of S510 is completed, the controller determines whether the circuitry has passed the self-test, and if not, starts step S516. If the circuitry passes the self-test check, the controller then initiates S512, which may include signaling to the user that the device is ready (eg via the LCD, LED and / or sound transducer). The device is then ready to be applied to the body of a patient and operated in a normal manner, for example as described in US 6,216,033 Bl, which is incorporated herein by reference in its entirety.
A second alternative in Figure 11 shows that in the first step S602, four events are presented all at once in a single action by the user; the snaps snap into their respective receptacles; the
<img file="MX347308B_D0053.tif" />
output and input contacts mate to provide electrical contact between the reservoirs in the reservoir module and the circuitry in the electrical module; the ignition posts close the ignition switches on the electrical module; and the battery 290 is thus connected into the circuit and begins to provide potential to the circuitry. In step S604, the controller waits a minimum period of time (eg, 10-500 ms) before proceeding to the next step. If the controller fails to maintain power for this period of time, that is, power is lost during this period, the timer is set to zero. Assuming that the energy is maintained through the time period in step S604, the controller then checks the number of counts in the ignition counter at S606, and if it is less than or equal to a certain predetermined number (in this example 1 , assuming the counter is set to 1 by a factory test, although other values are possible) the controller proceeds to step S610, which includes a self-check. However, if the count is greater than the predetermined number, then the controller initiates step S616, which includes a shutdown sequence, which may include sending an error message to an LCD screen, activating an LED indicator, and / or sounding. an audible alarm. If the count is less than or equal to the predetermined number, the controller starts step S610.
After the self-test of S610 is completed, the
<img file="MX347308B_D0054.tif" />
IMPI
MEXICAN INSTITUTE
OR £ THE INDUSTRIAL PROPERTY controller determines whether the circuitry has passed the self-test, and if not, initiates step S616. If the circuitry passes the self-test check, the controller then initiates S612, which includes incrementing the counter by 1. The controller then initiates S614, which may include signaling to the user that the device is ready (for example, through the LCD, LED and / or sound transducer). The device is then ready to be applied to the body of a patient and to operate normally, as described in US 6,216,033 Bl, which is thus incorporated by reference in its entirety.
Briefly described, the device is applied to the surface of a patient's skin. The patient or a healthcare professional then presses button 2 02 (see for example Figures 2A, 2B and 3). In some embodiments, the device is configured to require the patient or healthcare professional to press the button twice within a predetermined time to prevent accidental or false administration of the therapeutic agent. Provided that the patient or healthcare professional appropriately presses button 202, device 10 then begins delivering the therapeutic agent to the patient. Between doses, the device can enter a ready mode during which delivery is off even though the device is on. While
<img file="MX347308B_D0055.tif" />
IMPI
MEXICAN INSTITUTE
FROM THE INDUSTRIAL MOPIITY that is in ready mode, the device will perform various self-tests including the shutdown self-test described above. If the user presses the button to receive another dose, the device may first perform one or more self-tests (including the power-off self-test) before delivering the dose (which enters the activated state and delivers doses by passing current between anode and cathode). Once a predetermined number of doses have been delivered and / or a predetermined period of time has elapsed since the device was turned on, the device initiates a shutdown sequence, which may include sending a shutdown signal to the user via a LCD screen, an LED and / or an audio transducer. See especially US claims 6,216,033 Bl, which are incorporated herein by reference.
The person skilled in the art will recognize that other alternative firing sequences may be employed. For example, the controller can increment the counter immediately after the counter verifies the process outlined in Figures 10 or 11.
The reservoir of electrotransport delivery devices generally contains a gel matrix, with the drug solution uniformly dispersed in at least one of the reservoirs. Other types of deposits such as membrane confined deposits are possible and contemplated. The
<img file="MX347308B_D0056.tif" />
IMPI Mexican institute DE LA HtonmAD INDUSTRIAL application of the present invention is not limited by the type of tank used. Gel deposits are described for example in US Patent Nos. 6,039,977 and
6,181,963, which are incorporated herein by reference in their entirety. Suitable polymers for the gel matrix can comprise essentially any synthetic and / or naturally occurring polymeric material suitable for producing gels. A polar nature is preferred when the active agent is polar and / or capable of ionization to improve the solubility of the agent. Optionally, the gel matrix can be a water-swellable nonionic material.
Examples of suitable synthetic polymers include, but are not limited to, poly (acrylamide), poly (2-hydroxyethyl acrylate), poly (2-hydroxypropyl acrylate), poly (N-vinyl-2-pyrrolidone), poly ( n-methylol acrylamide), poly (diacetone acrylamide), poly (2-hydroxyethyl methacrylate), poly (vinyl alcohol), and poly (allyl alcohol). Condensation polymers with hydroxyl functional groups (eg polyesters, polycarbonates, polyurethanes) are also examples of suitable synthetic polar polymers. Naturally occurring polar polymers (or derivatives thereof) suitable for use as the gel matrix are exemplified by cellulose ethers, methyl cellulose ethers, cellulose and hydroxylated cellulose, methyl cellulose and methyl cellulose hydroxylated,
<img file="MX347308B_D0057.tif" />
IMPI iMjrnm »mmcano D> THE CURRENCY gums such as guar, acacia,> araya - d <» vant-ann. dp gelatin and derivatives thereof. Ionic polymers can also be used for the matrix provided that the available counter ions are either drug ions or other ions that are oppositely charged relative to the active agent.
Incorporation of the drug solution into the gel matrix in a reservoir can be done in many ways, i.e. by embedding the reservoir matrix, by mixing the drug solution with the matrix material prior to the formation of the hydrogel, or similar. In additional embodiments, the drug reservoir may optionally contain additional components, such as additives, permeation enhancers, stabilizers, dyes, diluents, plasticizers, tackifiers, pigments, carriers, inert fillers, antioxidants, excipients, builders. gel, anti-irritants, vasoconstrictors and other materials as are generally generally known transdermally. These materials can be included by one of ordinary skill in the art.
The drug reservoir can be formed from any material as is known in the prior art suitable for producing drug reservoirs. The depot formulation for transdermally administering cationic drugs by electrotransport is preferably composed of a solution
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX347308B_D0058.tif" />
aqueous salt of a water soluble salt, such as HCiU, uilriLMW salts of a cationic drug, such as fentanyl or sufentanil. More preferably, the aqueous solution is contained within a hydrophilic polymer matrix such as a hydrogel matrix. The drug salt is preferably present in an amount sufficient to deliver an effective dose by electrotransport over a period of administration of up to about 20 minutes, to achieve a systemic effect. The drug salt typically includes about 0.05 to 20% by weight of the donor depot formulation (including the weight of the polymeric matrix) in a fully hydrated base, and more preferably about 0.1 to 10% by weight of the donor depot formulation in a fully hydrated base. In one embodiment the drug depot formulation includes at least 30% by weight of water during transdermal drug delivery. The administration of fentanyl and sufentanil has been described in US Patent No. 6,171,294, which is incorporated herein by reference. Parameter such as concentration, speed, current, as described in US Patent No. 6,171,294 can be similarly employed here, since the electronics and reservoirs of the present invention can be made substantially similar to those described in United States Patent No. 6,171,294.
IMPI
INSTITUTO MEXICANO DE LA FROPieoAr INDUSTRIA!
<img file="MX347308B_D0059.tif" />
The drug reservoir containing the nictrogel can be suitably produced from any number of materials but is preferably composed of a hydrophilic polymeric material, preferably one that is polar in nature to enhance the solubility of the drug. Suitable polar polymers for the hydrogel matrix include a variety of synthetic and naturally occurring polymeric materials. A preferred hydrogel formulation contains a suitable hydrophilic polymer, a buffer, a humectant, a thickener, water, and a water-soluble drug salt (eg, HCl salt of a cationic drug). A preferred hydrophilic polymer matrix is polyvinyl alcohol such as a washed and fully hydrolyzed polyvinyl alcohol (PVOH), for example MOWIOL 66-100 commercially available from Hoechst Aktiengeselleschaft. A suitable buffer is an ion exchange resin which is a copolymer of methacrylic acid and divinylbenzene in both acid and salt form. An example of this buffer is a mixture of POLACRILIN (the copolymer of methacrylic acid and divinyl-benzene available from Rohm & Haas, Philadelphia, Pa.) And the potassium salt thereof. A mixture of the acid and potassium salt forms of POLACRLIN functions as a polymeric buffer to adjust the pH of the hydrogel to approximately pH 6. The use of a humectant in the hydrogel formulation is beneficial in inhibiting the loss of moisture from the hydrogel.
IMPI ^
MEXICAN INSTITUTE
OF INDUSTRIAL HUMANITY
An example of a suitable humectant is guar gum. Thickeners in a hydrogel formulation are also beneficial. For example, a polyvinyl alcohol thickener such as hydroxypropyl methylcellulose (eg, METHOCEL K100 MP available from Dow Chemical, Midland, Mich.) Helps modify the rheology of a hot polymer solution as it is dispensed into a mold or cavity. Hydroxypropyl methylcellulose increases viscosity on cooling and significantly reduces the propensity of a cooled polymer solution to overfill the mold or cavity.
Polyvinyl alcohol hydrogels can be prepared, for example as described in US Patent No. 6,039,977. The weight percent of the polyvinyl alcohol used to prepare hydrogel matrices for the reservoirs of electrotransport delivery devices, in certain embodiments may be from about 10% to about 30%, from about 15% to about 25%, and so on. more preferably about 19%. Preferably, for ease of processing and application, the gel matrix has a viscosity of from about 1,000 to about 200,000 poise, preferably from about 5,000 to about 50,000 poise. In certain preferred embodiments, the drug-containing hydrogel formulation includes from about 10 to 15% by weight of alcohol.
<img file="MX347308B_D0060.tif" />
<img file="MX347308B_D0061.tif" />
<img file="MX347308B_D0062.tif" />
INSTITUTO MEXICANO μ LA MOHEDAL) INDUSTRIAL polyvinyl, 0.1 to 0.4% by weight of sea bass buffer and approximately 1 to 30% by weight, preferably 1 to 2% by weight of drug. The rest is water and ingredients such as humectants, thickeners, etc. The polyvinyl alcohol (PVOH) -based hydrogel formulation is prepared by mixing all the materials, including the drug, in a single container at elevated temperatures of about 90 degrees C to 95 degrees C for at least about 0.5 hours. The hot mix is then poured into foam molds and stored at a freezing temperature of about minus 35 degrees C overnight to crosslink the PVOH. On heating to room temperature, a coarse elastomeric gel suitable for electrotransport of ionic drugs is obtained.
A variety of drugs can be delivered by electrotransport devices. In certain embodiments, the drug is a narcotic analgesic agent and is preferably selected from the group consisting of fentanyl and related molecules such as remifentanil, sufenatanil, alfentanil, lofentanyl, carfentanil, trefentanil as well as simple derivatives of fentanyl such as alpha-methyl -fentanil, 3-methyl-fentanyl and 4-methyl-fentanyl, and other compounds that have narcotic analgesic activity such as alpha-prodine, anileridine, benzylmorphine, beta-promedol, becitramide, buprenorphine, butorphanol, clonitacene, codeine, desomorphine,
IMPI nvrm / WMMCANü
FROM INDUSTRIAL MDRlDAn dextromoramide, dezocine, diampromide, 'dihiarocodSlin, dihydrocodeinone-enol-acetate, dihydromorphine, dimenoxadol, dimeheptanol, dimethylthiambutene, dioxaphethyl butyrate, dipipanone, ethylmethorphinem, hydrocodone, ethylmethorphonyl amine, ethylmethyloxymorine, isomethadone, ketobemidone, levorphanol, meperidine, meptazinol, metazocine, methadone, methadyl acetate, metopon, morphine, heroin, myrophin, nalbuphine, nicomorphine, norlevorphanol, normorphine, norpipanone, oxycodone, oxymorphone, pentazocine, fenadoxone, phenazocin, phenoperidine, piminodine, pyritramide, prohetptazine, promedol, properidine, propyram, propoxyphene, and tilidine.
Some ionic drugs are polypeptides, proteins, hormones or derivatives, analogs, mimics thereof. For example, insulin or mimics are ionic drugs that can be activated by electrical force in the electrotransport.
For the most effective administration by electrotransport, salts of certain pharmaceutical analgesic agents are preferably included in the drug reservoir. Suitable salts of cationic drugs, such as narcotic analgesic agents include, without limitation, acetate, propionate, butyrate, pentanoate, hexanoate, heptanoate, levulinate, chloride, bromide, citrate.
succinate, maleate, glycolate, gluconate, glucuronate,
370
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX347308B_D0063.tif" />
hydroxyisobutyrate, tricarbalilicate, maluuatu, adipafee / citracodone, glutarate, itaconate, mesaconate, citramalate, dimethylolpropionate, tiglicate, glycerate, methacrylate, isocrotonate, beta-hydroxybutyrate, crotonate, angeutyrate, hydrazilate, asparalate, 2-asparalate, glutamate, glutamate, asparahydrate, 2 pyruvate, fumarate, tartrate, nitrate, phosphate, benzene, sulfonate, methanesulfonate, sulfate, and sulfonate. The most preferred salt is chloride.
A counter ion is present in the drug reservoir in amounts necessary to neutralize the positive charge present in the cationic drug, eg, narcotic analgesic agent, at the pH of the formulation. Excess counter ion (as the free acid or as a salt) can be added to the reservoir in order to control the pH and to provide adequate buffering capacity. In one embodiment of the invention, the drug reservoir includes at least one buffer to control the pH in the drug reservoir. Suitable damping systems are known in the art.
The device described herein is also applicable where the drug is an anionic drug. In this case, the drug remains in the cation reservoir (and negative pole) and the anion reservoir will maintain the counterion. Several drugs are anionic, such as cromolyn (anti-asthmatic), indomethacin (anti-inflammatory), ketoprofen<sup>71</sup> IMPIgfo
MEXICAN INSTITUTE
OT THE INHERITANCE
INDUSTRIAL ™ (anti-inflammatory) and ketorolac tromethamine (ΝΰΑΙΙΙ and analgesic activity) and certain biological products such as certain proteins or polypeptides.
Although drug delivery devices and systems, which include a power-off self-test (and thus a power-off module to perform the self-test) may be or include two-part drug delivery devices As described above, the current-off module can be included as part of virtually any drug delivery system that has a power-on, but delivery mode (e.g., prepared) in which no drug is to be administered until appropriately triggered. Thus, one-part drug delivery unit devices are also contemplated.
Any of the systems and devices described herein, including a two-part system as exemplified, may include logic to control self-tests, including the current-off self-test (an anode-cathode voltage difference). Described in Example 2 below and in the attached Figures, is the variation of a system and control logic to be implemented in the system, including a power shutdown self-test. This example logic includes a current off module and can be implemented in the two-part system described in
<img file="MX347308B_D0064.tif" />
IMPI «τπυτο mwicano DI LA INDUSTRIAL PROPERTY Example 1 above.
Example 2: Control Logic
In one example, a system / device that includes a shutdown current control module configured to include a current shutdown self-test may include a processor or other controller that executes the control logic. For convenience, this control logic is referred to herein as software, however it should be understood that it may include hardware, firmware, or the like, in addition to software.
The following acronyms used in this example are defined below:
<td>Finished</td><td>Definition</td>
<td>ITSIC</td><td>ASIC designated and produced for / by this example</td>
<td>SO C</td><td>Application Specific Integrated Circuit</td>
<td>IONSYS<sup>MR</sup></td><td>Lontphoretic Fentanyl Transdermal System</td>
<td>ITSIC</td><td>Specific Integrated Circuit (previously called ALZIC) for this example</td>
<td>JTAG</td><td>(Joint Test Action Group) An interface to the ITSIC that allows access and control by external equipment</td>
<td>Nibble</td><td>Half an 8-bit byte. Four bits aligned to bit zero or bit four of an 8-bit byte</td>
<td>Bit Syndrome</td><td>Code Hamming Parity Bit</td>
<td>TDI</td><td>Technical Design Entry</td>
<td>UML</td><td>Unified Modeling Language</td>
In this example, the software (control logic circuit) described herein can be run on the ITSIC ASIC, which contains a CAST R80515 CPU core. In addition to the core, the ITSIC contains peripherals for interfacing with input and output devices including buttons, LEDs, an LCD, and a piezoelectric transducer. The ITSIC
<img file="MX347308B_D0065.tif" />
<img file="MX347308B_D0066.tif" />
MKICANO INSTITUTE
DE LA M0P1E0AD INDUSTRIAL also includes a rofuer ™ A? Converter. aH-r> vnlFajo a current source and an analog-to-digital converter (ADC).
The example CAST R80515 kernel operates at 32 kHz and takes between one and six cycles to execute each instruction. This equals execution times ranging from 31.25 to 187.5 μΞ per instruction. The ITSIC contains 256 bytes of RAM, of which 32 bytes are reserved for core registers, 1024 bytes of non-volatile storage in the form of EEPROM arranged in 64-bit pages, and 16 KB of ROM for program memory. The ITSIC can execute code from program memory on internal ROM, or from external EEPROM. Execution transfers from the internal ROM to the external EEPROM are controlled by a hardware register setting that can be configured via JTAG or by software.
The IT101 can operate in one of seven modes, determined by user input, defined operational parameters, and internal device status. Figure 12 shows the behavior of each mode and the transitions between the modes.
Figure 13 shows the high-level decomposition of software into functional blocks. The software architecture in this example is modular and layered with low-level actuator modules that encapsulate and provide an interface to the electronic hardware, while the
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX347308B_D0067.tif" />
Higher-level applications use drivers to provide device functionality to the user. The modules in the lower layer are independent of the modules in the layers above them.
Before entering the state machine, the software goes through an initialization routine. This routine includes checking the RAM and EEPROM for corruption, checking the boot mode, and initializing the drivers. In Figure 14 you can see more details of this initialization.
The ITSIC supports execution from either the internal mask ROM or an external EEPROM. The default configuration is run from ROM. Additionally, the software includes a stop mode that initializes the system when it enters an infinite loop to allow external control via JTAG lines. Stop mode does not service the watchdog timer, so if external control is not enforced before the first watchdog expiration, the watchdog timer will reset the system. The system boot mode is determined by the boot flag in NVM.
During system initialization, the EEPROM is initialized and the first page is checked for data integrity. If the boot marker value is not corrupted, the value is read from EEPROM.
<sup>75</sup> ΪΜΡΙ »5
INSTITUTO M1XICANO CE LA PROPERTY
INDUSTRIAL
If the marker is set to κτ ^ τ-ηι-γ ^ - g ^ f + ^ - rp it continues to run from ROM. If the marker is set to External, the EXTMEM register is set by the software, which is set by the CPU and subsequently booted from the external EEPROM. If the marker is set to stop, the drivers are initialized first and then the software enters stop mode.
The processing of tasks in the system can be periodic and synchronized with a system countermark that occurs every eight milliseconds. The system counter-mark function is provided by the timer controller, using a periodic hardware interrupt to produce the counter-mark. The main circuit simply waits for the system countermark to appear, then calls the appropriate processing functions for the timer controller and the state machine.
The timer processing function updates any active timers, such as those for the system lifetime and dose time. The state machine processing function dispatches processing to the currently active state, which then performs its periodic tasks. Periodic tasks can be scheduled to run as frequently as every 8 ms, or with any period that is an integer multiple of 8 ms, up to 2,048 seconds. The upper limit of the period is set by
<img file="MX347308B_D0068.tif" />
IMPI
INSTITUTO MEXICANO DE LA PROBIDAD INDUSTRIAL displacement of the 8-bit system countermark. The timer controller provides functions to facilitate periodic execution at various speeds. To reduce demands on the processor core, tasks can be scheduled to run at speeds no faster than necessary.
There is a single thread of execution that executes tasks in a non-preemptive, run to completion model. The active task must be completed before the next task can be run, so the task is not allowed to wait for an extended period of time to present itself. If the execution of a particular task runs beyond the scheduled time for one or more different tasks, the delayed tasks will run in order, until the completion of the delayed task. Execution of all periodic processing tasks will generally take longer than the duration of an individual system countermark. Normal programming will continue on the next system countermark.
The software in this example operates as a finite state machine, the behavior of which is defined in the UML state graph shown in Figure 15. The state machine is implemented with processing and state transitions handled centrally by the state module. State machine. Each state has input and output functions, as well as a
<img file="MX347308B_D0069.tif" />
IMPI
MEXICAN INSTITUTE
OF INDUSTRIAL PROPERTY processing function. The state aotuai ^ del -'- eÍ9 ^ ema -''- is stored in an individual private variable within the State Machine module.
Every time a system countermark is presented, the main circuit requires the state machine processing function, which in turn requires the current state processing function. If the current state processing results in a transition, the processing function returns a reference to the new state. The state machine then requires the output function for the current state, changes the state variable, and then requires the input function for the new state. This ensures that the system state remains consistent at all times with guaranteed state entry and exit actions performed in the correct order. If a state processing function does not result in a transition, it returns null and a state change does not take place.
Each state contains its own list of periodic tasks that run at speeds appropriate for their processing function. Tasks are scheduled in a monotonic speed manner - periodic tasks with the highest execution speed are executed first, followed by tasks in order of increasing execution speed. This minimizes variability in period, particularly for those tasks with the fastest execution speeds.
<img file="MX347308B_D0070.tif" />
IMPI of U PíOREDAC industrial high. Task scheduling is static and fixed at compile time, so the priority is deterministic. state
Power-on self-test status
In the power-on self-test (POST) state, the software employs the user interface elements and runs a sequence of self-tests. On power-up, the buzzer sounds a tone at 2000 Hz for 250 ms. After the tone, the red LED is flashed once for 500 ms. After the LED flashes, the LCD will flash 88 once per second for the remainder of the POST.
While the user interface elements are employed, the software runs a sequence of self-tests to confirm that the hardware device is operating correctly. In order to complete POST as quickly as possible, the tests are run continuously until they are complete, rather than using a periodic task for execution. There are two periodic tasks in the POST state. A 250 ms task is used to produce the user interface sequences. A one-second task is used to trigger the watchdog timer.
Ready state
In the ready state, the software searches for the Button input, flashes the green LED for half a second every two seconds, and periodically runs self-tests for
<img file="MX347308B_D0071.tif" />
IMPI
INSTITUTO MEXICANO DE LA MONSOAD INDUSTRIAL according to the schedule. There are three tasks in the ready state, running with periods of 50 ms, 250 ms, and one second.
The 50 ms task is used to detect Button presses, using the functions provided by the Button controller. The software looks for a dose request, defined as two button presses separated by at least 0.3 seconds and at most three seconds. Time is measured from the point of the first pulse to the point of the second release. On each detected Button release, the software performs an analog switch validation test. When a dose request is detected, the software performs a digital switch validation test. If all tests pass, a transition to the dosing state is initialized.
The 250 ms task is used to produce the green LED flash sequence. The green LED turns on for half a second every two seconds.
The one-second task is used to schedule and run self-tests, and commission the watchdog timer.
Dosage status
The Dosing State is responsible for delivering the 170 µΑ drug delivery stream over the 10 minute dose. For reference, the number 16
<img file="MX347308B_D0072.tif" />
IMPI
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL illustrates a variation of a circuit that controls the anode and cathode. The current control block contains circuitry to connect the output of the step-up converter (VHV) to the anode electrode (EL_A) through the SI switch. The 10-bit DAC is used to set the current output to a set value proportional to the desired dosing current. The DAC drives AMP1 which controls the current that flows through EL_A and EL_C when driving the gate of M2. The drain of M2 determines the current flow through Rsense causing the voltage drop that is fed back into AMP1. As the skin resistance is varied between EL_A and EL_C, so does the current through Rsense, which triggers a change in the output of AMP1. The VLOW signal is used in mode 0 to monitor the output of AMP1 as it approaches the 2 volt saturation point. AMP1 becomes saturated if there is not enough voltage to deliver the programmed current with the resistance between EL_A and EL_C. Drive functions are available to control and monitor various points in this circuit.
Dosing status is grouped into three sub-streams: Dose Initiation Sequence, Dose Control, and Dose Termination Sequence. Following the transition from the ready state to the dosing state, the dose initialization subflow is started. At dose initialization
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX347308B_D0073.tif" />
The software configures the various current control points and verifies their proper operation. The dose control sub-flow is then started. This flow controls the device over the 10 minute dose, monitors error conditions and controls voltage boost to conserve power. Finally, the dose termination sub-flow begins. This flow disables drug delivery and verifies correct operation of the current source by measuring the various points on the current control block.
Dose completion sequence always runs upon exiting dosing state regardless of the event that caused the software to exit dosing state. Dose completion sequence always opens YES, sets DAC current source to 0, sets voltage boost to 0, and disables boost circuit. Also, the dose termination sequence disables both the green LED and the buzzer. In some cases, the dose termination sequence performs actions already completed in the sub-stream processing. Almost all cases of dosing status flow error are handled similarly - with a resulting transition to dose termination. The exception to this is poor skin contact detection handling.
If an error occurs during dose initiation or dose completion the software exits the dose state, completes the dose completion sequence and
<img file="MX347308B_D0074.tif" />
IMPI
INSTITUTO MEXICANO Of LA MOriEDAD INDUSTRIAL changes at the End of Life. Similarly, if there is another error other than poor skin contact during dose control, the software completes the dose termination sequence and changes at the end of life. When a poor skin contact error is found in the dosing state, the software immediately starts the dose completion sequence, but the dose count is not updated. When an error occurs in the dose termination sequence the software immediately completes the dose termination sequence and changes at the end of life.
There are three periodic tasks in the dosing state, which run with periods of 50 ms, 500 ms and one second.
The 50-ms task is used to detect dose requests while in the dosing state. The Double Button push detection mechanism is identical to ready mode, except that the switch validation tests are not run. If the software detects a double button press in the dosing status, the dose request counter is incremented. This count is recorded during dose completion, but not when handling poor skin contact error.
The 500-ms task is used only the first time your countermark is presented. On that first occurrence, the buzzer is disabled.
<img file="MX347308B_D0075.tif" />
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
The one second task in this - example - ae-uteíliea-- to program the dose control sub-flow and watchdog timer service. The one-second task also schedules the lowest-speed dosing status self-tests (i.e., the ADC and reference voltages test, oscillator accuracy test, battery voltage test, and timer integrity test. Software).
Figure 17 shows a dosage mode flow chart illustrating the highest level flow between each of the dosage mode sub-streams, the dose termination sequence, and the transition to other states. Dose initiation sequence
The dose initiation sequence begins upon completion of the green LED power-up sequence and enables the piezo buzzer at 2000 Hz for a duration of 500 milliseconds. The software then completes the self-tests required to enter dosing mode. At this point, the software begins to configure the device for drug delivery.
First the software writes the initial start voltage setting of 3.4375 V and reads the register again to verify the writing. Then the boost is enabled and the software confirms that the boost circuit is operational by measuring the raised voltage using the ADC.
The software then verifies that SI is open by measuring the
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX347308B_D0076.tif" />
voltage on EL_A and confirm that it is weak.<sup>1</sup> T. Ü V: -ab - · software verifies that there is no large potential difference between anode and cathode by completing the anode / cathode voltage difference test. Then SI is closed and the voltage across EL_A is measured again to confirm that SI is closed. The software verifies that the output current is off by conducting the output current shutdown self-test. At this point, the software sets the DAC current source to the calibrated value to start current flow. The software reads the register again to verify the writing. The software then conducts the high output current self-test to verify that the current source is within range. Finally, the software measures both the anode and the cathode and conducts two checks. The first one checks if there is a voltage difference between EL_A and EL_C; the second verifies that the boost circuit is still available to supply the current-enabled voltage. If the measured values are not as expected, the software has detected an error, completes the dose termination sequence, and switches to end of life. Figure 18 shows a dose initiation flow chart.
Dose control sequence
Upon successful completion of the dose initiation sequence the software enters dose control. He
<img file="MX347308B_D0077.tif" />
ΙΜΡΙ6
INSTITUTO MEXICANO DE LA MONEDAD V INDUSTRIAL software starts the dogig cuexca jitras timer with a duration of 10 minutes and starts the dose control loop in a period of 1 second.
Each time through the loop the software first verifies that the output current is below 187 μΑ upon completion of the high output current self-test. The software then verifies that EL_A is within the tolerance of the VHV current setting. After 1 minute has elapsed, the compromised skin barrier test is performed each time through the loop and after 4 min the poor skin contract test is performed each time through the loop.
After the self-tests are completed the software enters the VHV control portion of the loop. The software controls the VHV to provide enough voltage to deliver the drug current while minimizing power consumption. The VHV control loop lowers the voltage to the required level, starting at 3.4375 V, but never going above 11.25 V. To control the VHV the software monitors the status of the VLOW signal. The signal
VLOW is configured to monitor the M2 gate voltage. The signal locks when the AMP1 output exceeds 2 V. The VLOW signal indicates that AMP1 is not capable of delivering the 170 µΑ current due to insufficient supply voltage. If the VLOW signal is secured, the software
<img file="MX347308B_D0078.tif" />
IMPI
IMSTTTUTO MEXICANO
OF INDUSTRIAL PROPERTY increases VHV by 1 account (0.3125 V), to
11.25 V. The first several iterations through the control loop lower the VHV to the necessary level, depending on the resistance of the skin. If the resistance of the skin increases during the dose, the VLOW signal is ensured and consequently the VHV increases.
To conserve potency and manage decreased skin resistance during dosing, the software lowers VHV periodically. Decrease is triggered by a 20 second timeout. The timeout is set to 0 each time VHV is increased or decreased. The timeout is increased every time the control loop detects that the VLOW signal has not been secured. When the timeout reaches 20 (ie, 20 seconds) VHV is determined. If the skin resistance has not changed the VLOW signal is secured and the software ramps the VHV back to the necessary level the next time through the loop. On the other hand, VHV is held at the new voltage setting until the next timeout or until the VLOW signal is secured.
Finally, the dose control sequence programs the dosage mode self-tests that occur with periods greater than 1 second. These tests are the ADC reference voltage test, oscillator accuracy test, battery voltage test, and
<img file="MX347308B_D0079.tif" />
IMPI
INSTITUTO Mexicano DS LA PROPERTY industrial software timer. If any one of these auTO-prtreLias fails the software completes the dose termination sequence and switches to EOL.
If an error other than the poor skin contact error is encountered during the control loop, the software completes the termination sequence change at the end of life. If poor skin contact is detected, the software starts the dose completion sub-flow, but the dose count is not increased. The dose control loop is removed under normal conditions after the 10 minute dose time has elapsed. Figure 19 shows the flow for dose control.
Dose completion sequence
The dose termination sequence begins on successful administration of a dose or when poor skin contact is detected. First the software opens SI and sets the DAC current source to 0 counts. The register write is read again and verified. The software then conducts the output current shutdown self-test to verify that the current is not above the leakage threshold. The software sets VHV to 0 V and verifies the log recording by reading it back. The software verifies that VHV is off by measuring VHV and verifying that it is less than 4.0 V; the expected value is Vbat. The software then disables the boost circuit and verifies the register write. The voltage of
IMPI Mexican iNSTrruro
OF THE PROPERTY
INDUSTRIAL
<img file="MX347308B_D0080.tif" />
Anode is measured to verify that the potential is low * 'After T * the anode / cathode voltage difference test (current off test) is completed.
If the software controls for poor skin contact detection, the software exits the dose completion sequence and switches to standby. On the other hand, the software performs the dose count integrity test, if the test passes the dose count is incremented and the LCD is updated. If the dose count is 80, the software switches to end of use, otherwise the software switches to ready. If the software detects an error in the dose termination sequence, the dose termination sequence completes and the software switches to end of life. Figure 20 shows an example of a flow chart for dose termination.
Standby state
The standby state is used to indicate that poor skin contact was detected during the dosing state. On entry to the state, the software records a time-stamped standby record for NVM. While in the standby state, the output current is disabled, self-tests are suspended, and the software flashes the red LED twice a second and sounds a sequence of long and short beeps on the buzzer. After 15 seconds, the software changes to the ready state.
<img file="MX347308B_D0081.tif" />
IMPI fNSTTrUTU MEXICAN
OF INDUSTRIAL PROPERTY
The 250 ms task is used .pradncir la.
flashing sequence of the red LED and the tones played on the buzzer. This task is also used to detect when 15 seconds have passed and start the transition to the next state.
The one-second task is used to trigger the watchdog timer.
End of use status
The software enters the end of use state when the device has reached its 80 dose limit or its 24 hour time limit. On entry to the state, the software records the completion code, timestamp, and battery voltage to NVM. While in the end use state, the output current is disabled, the final dose count is displayed on the LCD, and the red LED is flashed. The software monitors the Button for a push and hold event and periodically runs the self-tests.
The 50-ms task is used to detect Button presses, using the functions provided by the Button controller. If the software detects a button press and waits for 6 seconds, a transition to the interrupt state is initialized.
The 250-ms task is used to produce the red LED flash sequence.
The one-second task is used to schedule and
<img file="MX347308B_D0082.tif" />
run self-tests, and to commission -gl <t-emporí ~ zadgy<sup>,</sup>** ~ surveillance. This task can also be used to run the battery voltage test once every 10 minutes. If the battery is below the low voltage threshold, the software initiates a transition to the end of life state.
End of life status
On entry to the end of life state, the software records the transition ratio, time stamp, battery voltage to NVM. The device may enter the end of life (EOL) state when forced by errors (including failure of a self-test such as the current off test). In the end of life state, the output current is disabled, the red LED flashes and the buzzer sounds short sequence tones. The software monitors the Button for a press and hold event and periodically checks the battery level every 10 minutes.
The 50-ms task is used to detect Button presses, using the functions provided by the Button controller. If the software detects a button press and waits for 6 seconds, a transition to the interrupt state is initialized.
The 250-ms task is used to produce the red LED flash sequence and produces the short tones on the buzzer.
<img file="MX347308B_D0083.tif" />
IMPI
INSTITUTE MBXJCANC
Dt LA rtOPlEDA »
INDUSTRIAL
The one-second task is used to schedule and run self-tests, and commission the watchdog timer. This task is also used to run the battery voltage test once every 10 minutes. If the battery is below the reduced threshold, the software initiates a transition to the shutdown state.
State of interruption
The interrupt state is the final state of the device. On input to state, the software records the transition ratio, timestamp, and battery voltage to NVM and disables the LEDs, LCD, and buzzer.
While in the interruption state, the output current is disabled. The software does nothing but services the watchdog timer using the one-second task. The software does not go out of this state. Self-tests
As discussed above, the system or device may include a set of self-tests to monitor device operating parameters for device hardware or software failure, or usage conditions. The current off module can be a form of a self-test. Self-test can be derived from requirements, risk, and reliability analysis activities. The tolerance intervals specified for test limits derived and included herein (which
IMPI ^
INSTITUTO MEXICANO de LA xL industrial —-— τ include thresholds such as threshold of corriunLu aum.l'düá) are for example only. These example tolerances may depend on the tolerances of the hardware components. Software, hardware and firmware (including logic / algorithms) of self-tests can verify against a specific limit value that does not vary.
Self-test scheduling and sequencing
The subset of running the self-tests and the scheduling of those tests may vary depending on the device's mode of operation, as discussed above. Figure 21 shows Table 1, which shows self-tests that can be run in each mode and when those tests are run. The standby mode is not displayed because the self-tests are suspended until the return to standby mode. Standby mode lasts only 15 seconds, and with the most frequent tests running only once a minute in non-dosing modes, it would exit standby before any tests were run.
The test schedule indicated in Figure 21 is in some cases more frequent than would be suggested by the detection times indicated in the requirements. This allows for an implementation that requires several consecutive failures before a failure is adjusted in cases where there can be significant variability from the measured results from trial to trial. In the case of precision testing
<img file="MX347308B_D0084.tif" />
IMPI
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL of oscillator, this allows detection, gives failure tlenüLU dgl '~ real time required indicated in the requirements, even if the oscillator is operating at the extreme low limit, just above the point of a hardware reset .
In many cases, the correct execution of a particular test depends on the correct operation of other hardware, firmware and / or software items that are verified by other tests. This can help determine an order in which the tests should be run for valid results. Predecessor tests are those that must pass before the result of a given test can be considered valid. For example, the reference voltage test and ADC must pass before any test using ADC.
A special case is the ROM test. Since all code, including that of the ROM test, is stored in ROM, it is not possible to pass the ROM test using ROM.
RAM test
The RAM test verifies that each address in RAM can be read and written. The test is performed in assembly language startup code, before the RAM and stack initialization or C. The 0x55 and OxAA values are written to and read from each byte of RAM to verify that each bit is working . The first test writes 0x55 to each byte of RAM. So it reads each byte, compares it to
<img file="MX347308B_D0085.tif" />
IMPIí
MMUCANC 'INSTITUTE OF INDUSTRIAL PROPERTY
0x55, and write OxAA to the byte. Finally, read each byte of the
RAM and compares the values with OxAA. If any of the comparisons fail, the test fails. On the other hand, the pclScl.
ROM test
ROM test verifies the contents of the
ROM. The test calculates an 8-bit checksum of the ROM, which is a sum of all the values in the ROM. In manufacturing the last byte of the ROM will be set such that the checksum will equal OxFF. When the test is run, the checksum for ROM is calculated and compared to OxFF. If the sum is not equal to OxFF, the test fails. Otherwise, the test passes.
Calibration data integrity test
The Calibration Data Integrity Test verifies the contents of the calibration data stored in the internal EEPROM. This data includes the start flag, the oscillator limit values, the ADC calibrated current source setting, the Rsense reading when braking, and the offset values for the ADC and the oscillator. These values are encoded with error detection and correction codes. The first time the calibration data integrity check is run, all calibration values are decoded by the EEPROM controller and fails if the EEPROM controller
<img file="MX347308B_D0086.tif" />
<sup>95</sup> IMPI
MEXICAN INSTITUTE <sup>N</sup> FROM THE rtOnWAU
INDUSTRIAL detects data corruption that is not -putudu irurrggír '^ in any of the values.
After it is validated by a successful first integrity test, the ADC calibration values are stored in RAM to improve the performance of the ADC controller. In subsequent integrity checks of these values, the test compares the values stored in RAM with the values stored in EEPROM. This reduces processing time by avoiding decoding error code overload. The test passes if the value in RAM and EEPROM match and fails otherwise.
For all calibration data other than ADC calibration, subsequent integrity tests behave the same as the first. Error codes are decoded for all values, and any corruption that cannot be corrected results in a test failure. Oscillator Accuracy Test
The Oscillator Accuracy Test verifies the accuracy of the oscillator frequency using the frequency-to-voltage conversion channel of the ADC. During manufacture, the oscillator calibrates at 2,048 MHz ± 1%, and the frequency-to-voltage readings in the high and low limits are stored in non-volatile memory. Stored limits are between + 3% and + 5% on the high side, and -3% and -5% on the low side. Tolerance on the frequency converter
<img file="MX347308B_D0087.tif" />
at voltage is + 5%. The accumulation of these tolerances can result in the detection threshold being close to, but not more than 10% of nominal, which is within the required + 10% limits of the oscillator accuracy test.
When the oscillator accuracy test is run, the ADC frequency-to-voltage reading is compared to the 12-bit cutoff values stored in non-volatile memory. If the ADC reading is not within limits, the test fails. Otherwise, the test passes.
In order to detect an oscillator error within the real time required in the case where the oscillator is running slowly, the test is run more frequently than it would be if the oscillator were running at nominal frequency. Reset does not occur at 0.8 MHz. This is a 2.5 divider at the nominal value of 2,048 MHz, and the same divider can be applied to the test programming period. For example, to ensure the detection of a low limit oscillator within 10 minutes, the test should be run every 4 minutes.
Reference voltage test and ADC
The ADC and reference voltage test verifies the correct operation of the ADC, the ADC multiplexer, and the relative levels of the ADC reference voltage and the main reference voltage. This test measures the voltage of
<img file="MX347308B_D0088.tif" />
IMPI
MEXICAN INSTITUTE
W LA MOHEDAL · INDUSTRIAL main reference using the ADC and compare it. “CorTT ^ volb in order to pass the test, the ADC, the ADC multiplexer, and the main voltage reference and the ADC voltage reference should all work correctly . If the test fails, the component that is failing cannot be determined. The test fails if the main reference voltage is greater than 1.1 volts or less than 0.9 volts. Otherwise, the test passes.
Software timer integrity test
The software timer integrity test verifies the speed of the primary software timers using a secondary software timer. The secondary software timer is given as a countdown length and the current value of one of the primary timers. During standby mode, the secondary timer initiates a primary system time check every ten minutes. During dosing mode, the secondary timer starts a primary timer check every minute. After counting down for the specified length of time, the secondary timer compares the current primary timer value with the initial value. If the value differs by more than 10% the test fails. Otherwise, the test passes. Dose count integrity test
Dose count integrity test verifies
<img file="MX347308B_D0089.tif" />
INSTITUTO MEXICANO DE U PROREDAD INDUSTRIAL that the value of dose counts in the RAM has not been corrupted. A redundant copy of the dose count is stored in the internal EEPROM and initialized to zero. The test runs on successful dose completion. After increasing the dose count, the current value stored in RAM is compared against the copy in EEPROM. If the two values match, both are incremented and the EEPROM value is ignored. The test fails if the two values do not match.
Rsense Accuracy Test
The Rsense Accuracy Test verifies the accuracy of the Rsense resistor value. The resistor Rsense has a tolerance of 1%. During manufacturing, RSENSE start-up charging is allowed and voltage is measured across Rsense with the ADC. The 12-bit ADC value is written to the RSENSE location in NVM. This test duplicates that manufacturing measurement. Rsense startup is allowed and ADC is used to measure Rsense voltage. The measurement is compared to one stored in NVM. The test fails if the two values differ by more than 5%. Otherwise, the test passes.
Battery voltage test
The battery voltage test returns the state of the battery relative to various threshold values. The test measures the battery voltage using the ADC and compares it to the battery thresholds. The test reports that the battery is<sup>99</sup> IMPI »*
INSTITUTO MEXICANO J *
OF LA FROHEDAO
INDI) STÍUA l *>
OK if the voltage measurement is greater than ~ 2-r? ~ velfra i / -5¿ - The test reports that the battery is low if the voltage measurement is less than 2.7 volts +/- 5% and greater than 2.3 volts + / 5%. This test reports that the battery is dead, if the voltage measurement is less than 2.3 volts +/- 5%.
Analog switch validation test
The Analog Switch Validation Test measures the voltage levels on both the high and low sides of the Dose Button switch in order to detect potential problems that could lead to erroneous switch readings. Under normal conditions with the switch open, the voltage on the high side of the switch will be slightly less than the battery voltage after accounting for the small voltage drop caused by the electronic components connected to the switch circuit. Under normal conditions, the voltage on the low side of the switch will be very close to ground.
Some conditions, such as contamination or corrosion, can cause the high side voltage to drop or the low side voltage to rise. If the high-side voltage drops to less than (0.8 x battery voltage), or the low-side voltage rises to more than (0.2 x battery voltage), the switch input is in a digital logic level range indeterminate with respect to digital switch input. A switch voltage in this range can give<sup>100</sup> IMPI
INSTITUTO MEXICANO de la frof <»ai taSz
INDUSTRIAL —IT-by result in erroneous switch reads, which can manifest as false Button transitions not being initiated by the user. The analog switch validation test detects the condition before the switch voltage levels reach the point where erroneous readings can occur.
The analog switch validation test should be run when the switch is in its normally open condition so that both the high side and low side voltages can be measured. Any change in the switch state while the test is running may cause the test to falsely fail due to the high side voltage measurement while the switch is closed. The user can press or release the Button at any time, but there are mechanical and human limits to the minimum time between presses. Therefore, the point where the switch state is known to most certainly open is immediately after a detected release of the Button.
The analog switch validation test runs immediately after each detected Button release. That test uses the ITSIC ADC to make sequential measurements of high-side voltage, low-side voltage, and battery voltage. The ADC is configured to sample for 6.25 ms for each measurement. If he
101
<img file="MX347308B_D0090.tif" />
<img file="MX347308B_D0091.tif" />
INSTITUTO MEXICANO DE LA nOHBDAP INDUSTRIAL voltage on the high switch side is less than or equal to— (6 * · »- 'x battery voltage), or if the voltage on the low side is greater than or equal to (0.2 x battery voltage), the test fails. Digital switch validation tests
The digital switch validation test is similar in purpose to the analog switch validation test, but it can be simpler, faster, and more ordinary in its measurements.
The test uses secondary digital inputs, connected to each side of the Dose Button switch, to confirm digital logic levels, while the switch is open (No Push Button). The secondary digital inputs are of the same type as the primary digital inputs, and the corresponding values are expected to match.
The digital switch validation test runs after the analog switch validation test of the release of the second Double Push Button that matches the criteria for a dose initiation sequence.
If the secondary digital input on the high side of the switch is low, or if the secondary digital input on the low side of the switch is high, the test fails. Output current shutdown test
In some variations, the current module
<img file="MX347308B_D0092.tif" />
102
IMPI
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL shutdown can be configured to perform an output current shutdown test. The output current shutdown test can verify that the leakage current is less than some threshold (for example, 3 μ 9, 9 μΑ, etc.) when the current source is off. The test can calculate Rsense voltage leakage current and low limit Rsense resistance of 3.96 kOhm.
I leak = Vsense
Rsense
VRsense = Ifuga * RRsense
Vsense = <(3μΑ * 3.96 kOhms)
VRsense <sup>=</sup> <12 mV
The test measures the Rsense voltage using the ADC, while the current source is off. Therefore, in some modes, the Rsense voltage measurement is greater than some threshold (eg 12mV, 36mV, etc.) the test fails. Otherwise, the test passes.
Anode / Cathode Voltage Difference Test
In some modes the current off module can also be configured to perform an anode / cathode voltage difference test. The anode / cathode voltage difference test can verify that when SI is open and the current source is disabled, there is a small voltage difference between the anode and the cathode. This test can verify the case of current flow failure
103
<img file="MX347308B_D0093.tif" />
IMPI
INSTITUTO MEXICANO Dt LA mof UDAU industrial from anode to cathode resulting from any failure in the output circuit. The test measures the anode voltage and the cathode voltage using the ADC and calculates the voltage difference between the two points. The test fails if the voltage difference is greater than some threshold (for example, 0.85 V, 2.5 V, and so on). Otherwise, the test passes.
High output current test
The high output current test verifies that the dosing current is less than 187 μΑ. The test measures the voltage across Rsense using the ADC and uses that voltage to calculate the current.
liposification = VRsense / RRsense
VRsense - Dosage * RRsense
VRsense <(187 μΑ * 3.96 kohms)
See <741 mV
A low-limit Rsense resistance of 3.96 KOmhs will result in the lowest Rsense voltage measured at 187 μΑ. The test fails if the measured Rsense voltage is less than 741 mV. Otherwise the test passes.
Poor Skin Contact Test
The poor skin contact test verifies that the skin resistance is less than 432 kOhms +/- 5%. The test measures the voltage across Rsense using the ADC and uses that voltage to calculate the resistance of the skin.
104
<img file="MX347308B_D0094.tif" />
IMPI
BWTmJTO MEXICAN
OF INDUSTRIAL RXOHETY
Idosing - (Vánode ”Vcathode) / J? Paal <sup>1</sup> *......* *****
Dosage <sup>=</sup> 9.25 V / 432 kOhms = 21.4 μΑ
VRsense = Dosage * Rsense
VRsense}> 21.4 μΑ * 3.96 kOhms
VRsense> 84.7 mV
At 432 kOmhs, this example assumes that the difference between the anode and the cathode is 9.25 V. Since the Rsense has a tolerance of 1%, 3.96 kOhms is the lowest resistance it can have. The test fails if the voltage across Rsense is less than 84.7 mV. Otherwise, the test passes.
Compromised Skin Barrier Test
The compromised skin barrier test verifies that the skin resistance is greater than 5000 Omhs +/- 5%. The test measures the cathode voltage and the anode voltage using the ADC. The test uses these two measurements to calculate the resistance of the skin.
Rpiel <sup>=</sup> (Vánode “Vcathode) / Dosage
V-cathode Vanode <sup>=</sup> idosification * Rpiel (Vánode - Vcathode)> (17 0 μΑ * 5 0 00 Omhs) (Vánode - Vcathode)> 0.85 V
The test fails if the difference between the anode voltage and the cathode voltage is less than 0.85 V. Otherwise, the test passes.
Low-level hardware drivers provide functions to configure and use hardware
<img file="MX347308B_D0095.tif" />
105
IMPI
MEXICAN INSTITUTE
OF THE INDUSTRIAL nOHEDAP of the corresponding system. CONTROLLERS<sup>l</sup>They do not keep timing information. The modules that the controllers use can handle any necessary timing. In some cases the controllers maintain the status information that pertains to the hardware to which they provide an interface.
Timer
The timer controller uses the hardware timers in the CPU to provide a variety of timing functions, including: (a) a system counter clock triggered by a periodic interrupt every 8 ms; (b) periodic countermarks derived from the system countermark and that occur every 50, 100, 250, 500 or 1000 ms; (c) a system timer that counts the number of seconds since power was applied to the system; (d) a dose timer that counts down the duration of a dose, in seconds; and (e) a button timer that counts down the time window for a double button press for dose initiation.
The timer controller uses timer hardware OR such as an 8-bit timer in an auto-reload mode to provide the 8ms system counter clock. TimerO generates an interrupt each time it is reset. To minimize interrupt processing time, the interrupt handler simply
106
<img file="MX347308B_D0096.tif" />
IMPI
Mbucano INSTITUTE DE LA MONEDAD INDUSTRIAL increments an 8-bit counter, sets an Inral qua flag. indicates that the system countermark was displayed, and samples the button input (see section 5.4.2 dose button). The controller provides a function for the main loop to verify the occurrence of the counter mark. The 8-bit counter is reset every 2.04 8 seconds. This allows the generation of periodic countermarks with periods up to that value.
When the main loop makes sure that the system counter flag has been presented, it calls the timer processing function, which updates the software timers as appropriate. This feature uses the system counter dial counter to decrease the dose and / or button timers once per second if they are active, and increases the system lifetime timer once per second. It also clears the system countermark flag, which indicates that processing was completed for that countermark.
The timer controller uses the system countermark to calculate periodic countermarks with periods that are multiples of the system countermark. Nominally available periods are 50, 100, 250, 500, or 1000 ms. However, not all of these periods are integer multiples of 8 ms, so the exact period is less in some cases, due to truncation. The timer controller
<img file="MX347308B_D0097.tif" />
107
IMPI flWWVTO MBUCANO * S INDUSTRIAL PROPERTY provides functions to verify the occurrence of each periodic countermark, as well as a function to synchronize all periodic countermark with the current system countermark value.
Dose Button
The dose button controller contains functions for sampling, bouncing, and detecting transitions on the button input.
The enter button is sampled every 8 ms in the timer controller periodic interrupt handler. This is necessary to achieve button sampling at a regular and sufficiently high rate. The execution of each iteration of the main loop spans several periodic interrupts and varies in duration with the execution path.
The button is sampled in a circular buffer that holds eight samples. The six most recent samples are used by the bounce removal algorithm to determine the button state. All six displays must be the same to identify a valid button state. If the buffer contains a mix of high and low samples, the button is determined to be in a bounce or transition state.
The button controller keeps track of the button state from the time before the button was applied. <sup>108</sup> IMPIAS
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL W ** and bounce elimination algorithm and by ^ T ^ fSíTfU can identify transitions. A function is provided to verify a button release. It can be called approximately every 50 ms by tasks reading the button to provide acceptable user responsiveness to inputs. A release transition requires at least six samples with the button depressed, followed by at least six samples with the button released. Therefore approximately 100 ms of sampling is required to identify a button press.
LCD
The LCD controller provides the software interface to display a two-digit number on the LCD. The controller supports the display of integers from 0-99. Input values 0-9 do not show a leading zero. The controller also displays the LCD control functions: enable, disable, and blank.
The digits to the left and right are designated Digit 1 and Digit 2 respectively. Each of the two digits has seven segments. The segments are labeled AF, starting at the top segment and moving clockwise, and the middle segment is labeled G. The ITSIC may be capable of controlling up to 80 LCD segments. There are 20 segment control lines and four backplane lines (also called lines
<img file="MX347308B_D0098.tif" />
IMPI
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL common) that are multiplexed to control ca4q one he los. eighty____ segments available. Only 14 LCD segments are used in this application with the four back planes. LEDs The LED driver provides the software interface to control the green and red LEDs. Fixed current settings are used to drive the LEds according to the power supply of the device. The green LED connects to the current source of LED1 and is driven at 2.5 mA. The red LEd connects to the LED2 current source and is driven at 1.4 mA. The controller uses the LED_BEEP register to turn each Led on and off or toggle. Buzzer
The buzzer controller provides the software interface to control the audio transducer. The operating frequency range is 1000-4875 Hz in 125 Hz steps.
When the audio transducer is turned on, the controller configures the transducer to be driven by the boost circuit. This allows control of the audio volume by adjusting the boost voltage. However, the controller does not adjust the voltage boost. This application is responsible for adjusting the appropriate elevation level before enabling the transducer. The voltage boost can be set using the lift controller controller.
<img file="MX347308B_D0099.tif" />
110
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
The driver controls the traxitOT 'through the LED_BEEP and BEEP_FC registers. Voltage Boost Controller
The boost controller provides the software interface to control the boost block. This circuit is responsible for raising the battery voltage to higher levels required to maintain the dosing current output or to drive the piezoelectric audio transducer at a sufficient volume.
The controller supports boost levels above the full operating range: 0.0 to 19.6875 volts in 0.3125 volt steps. The minimum boost voltage is determined by the battery voltage; settings below the battery voltage result in output equal to the battery voltage. The step-up load time can be configured in hardware but is set to a fixed value of 1.5 microseconds at controller initialization. Additionally, the controller provides functions to reread the voltage control setting and enable / disable the boost circuit.
The controller provides a function to poll the boost over voltage signal. The overvoltage signal is secured if the voltage output exceeds 21.0 volts. The controller controls the boost circuit through the BOOST_0, BOOST_1, EOV, and ITI registers.
111
IMPI ^^
INSTITUTO MEXICANO Jj
OF THE INDUSTRIAL RRONEBAD
Current Controller
The current controller controller provides the software interface to control the current source block. The current source output level is controlled by a 10-bit DAC. The controller allows current output above the full operating range of the current source. The controller controls the current source through registers ISRC_0, ISRC_1, EVL and ITO
The controller provides functions to enable and disable the current source, adjust the DAC value, read the DAC value again, and enable or disable the braking resistor Rsense.
The controller also provides an interface for the low voltage signal from the current control block (VLOW). During initialization this signal will be configured to monitor the M2 gate voltage. A function is provided to monitor the signal status. Compensation
The current controller requires compensation to achieve the desired accuracy at 170 μΑ. The uncalibrated current driver is accurate to ± 5%, while the calibrated current driver is accurate to ± 0.5%. The 10-bit DAC value to produce a 170 μΑ stream is determined and written to the location
112
<img file="MX347308B_D0100.tif" />
IMPI
MEXICAN INSTITUTE
OF INDUSTRIAL PROPERTY
ISRC_170 in NVM during manufacturing. Estyvdlm · -ye · ice dg NVM and is written to the ISRC registers when the current source is enabled.
Analog to Digital Converter (ADC) The ADC controller provides the software interface to configure and use the ADC. The ADC has 12-bit resolution with three possible input ranges, configurable conversion time, and selectable inputs. The ADC inputs are grouped into full scale groups: low (0.0 to 2.0 volts), medium (0.0 to 3.6 volts), and high (0.0 to 24.0 volts).
The driver provides a function to configure the input selection, specify the conversion time, and start a conversion. The conversion time interval is 0.78125 to 100 ms. The start conversion function is non-blocking and the conversion is asynchronous. Completion of the conversion is signaled by interrupt ADC terminated. The controller is responsible for handling this interruption and storing the accounts. A function is provided for the application to determine whether an ADC reading is in progress.
The ADC controller is responsible for applying calibration gain and offsets for the appropriate input range. Calibrations are applied when the application reads the result of a completed conversion. The
113
<img file="MX347308B_D0101.tif" />
IMPI
INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL calibrations are stored 1ηπ3Ϊ „.ηη to nnnt-rnladnr. and a function is provided to return a reference to the data structure. This reference is used to equip the NVM calibration values and to perform the calibration data integrity test.
The controller controls the ADC through the ADC_CTRL, ADC_MSB, ADC_LSB, and EADC registers.
Compensation
The ADC output must be trimmed to achieve the desired accuracy. The ADC output has a gain error of + 5% and a deviation error of + 5%. After compensation, the ADC output is accurate to + 0.5%. The offset calculation requires two NVM 9-bit signed values for each of the three ADC bins. Each gain and offset is stored in an 8-bit unsigned value in NVM and there is a 6-bit value that stores all signed bits. Therefore, there are 7 values that are written to NVM by manufacture: ADC_GAIN_HIGH, ADC_OFFSET_HIGH, ADC GAIN MID, ADC OFFSET MID, ADC GAIN LOW, ADC OFSSET LOW, and ADC_SIGNS. High Interval ADC result = ADC out * (l + (ADC GAIN HIGH / 4096)) +
ADC_OFFSET_HIGH ADC_result = (ADC_MSB << 4) | (ADC_LSB >> 4);
ADC_result = ((ADC_GAIN_HIGH * ADC_MSB) >> 8) & OxFF;
114
ADC_result = ADC_OFFSET_HIGH;
Medium Range
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL PROPERTY
<img file="MX347308B_D0102.tif" />
ADC_result = ADC_out * (l + (ADC_GAIN_HIGH / 4096)) +
ADC_OFFSET_MID
ADC_result = (ADC_MSB << 4) | (ADC_LSB >> 4);
ADC_result = ((ADC_GAIN_MID * ADC_MSB) >> 8) & OxFF;
ADC_result = ADC_OFFSET_MID;
Low Range
ADC_result = ADC_out * (l + (ADC_GAIN_HIGH / 4096)) +
ADC_OFFSET_LOW
ADC_result = (ADC_MSB << 4) | (ADC_LSB >> 4);
ADC_result = ((ADC_GAIN_LOW * ADC_MSB) >> 8) & OxFF;
ADC_result = ADC_OFFSET_LOW;
Watchdog Timer
The watchdog timer controller provides the software interface to initialize and commission the watchdog timer. The watchdog timer timeout is set to 6.144 seconds by the initialization function. If the watchdog timer is not brought into service within this period, the watchdog hardware reinitializes the processor. The watchdog timer starts at controller initialization. The application is responsible for commissioning the watchdog timer.
<img file="MX347308B_D0103.tif" />
115
IMPI
MEXICAN INSTITUTE OF INDUSTRIAL MOHEDAD
ITSIC Core - ..........
The ITSIC core driver provides the software interface to control general ITSIC related functions. These functions include: enabling and disabling all interrupts using the general enable bit, and reading and writing the oscillator calibration value. The controller uses the EA and OSC_CAL registers. After controller initialization the oscillator calibration is set to 0.0% with interrupts disabled.
Oscillator Calibration
The oscillator requires calibration to achieve ± 1% accuracy at the 2,048 MHz system clock. The uncalibrated oscillator is ± 30% accurate. The 8-bit calibration value adjusts the frequency of the oscillator and is determined and written to the OSC_CAL_VALUE location in NVM during manufacture. OSC_CAL_VALUE is read from NVM and written directly to the OSC_CAL register. After writing to the register, the oscillator requires a setting time of 1 millisecond. Internal EEPROM
ITSIC non-volatile memory is used by firmware for two purposes: persistent data storage and redundant storage of critical runtime data. Persistent storage includes usage log and device calibration data. Redundant storage includes runtime data
<img file="MX347308B_D0104.tif" />
IMPI
INSTITUTO MÜUCAÍKJ
MIAMOMEDAD industrial
116 that have been identified as critical to safety through risk analysis. The firmware is designed to read from and write to non-volatile memory.
ITSIC non-volatile memory is an 8k on-chip EEPROM organized as a 128 x 64 bit array. EEPROM access is always a full page (64 bit wide). EEPROM is memory mapped and code referenced by external data addressing. External data addresses are declared in code using the C51 xdata keyword.
To improve reliability, thereby decreasing the effectiveness of the error rate, the firmware applies error detection and correction mechanisms on the EEPROM. Three mechanisms are used, each with different integrity properties. Hamming codes are used to encode entire pages.
Hamming codes are used to encode specific data fields when full page encoding is not required. Finally, parity bits are used to verify the integrity of the data that is not used by the device during operation. Two Hamming codes are capable of correlating all one-bit errors and detecting all two-bit errors. The parity bits are capable of detecting any odd number of bit errors. The software interface for the EEPROM can exercise
<img file="MX347308B_D0105.tif" />
117
IMPI
INSTITUTO MEXICANO DE LA FEOTIÍDAD INDUSTRIAL influences the design of the system of data. Read access is transparent to the firmware. The kernel reads the entire page in a 64-bit duplicate register. If the requested page is already loaded, the EEPROM is not read at all. Write access requires the firmware to control the timing of the page repository. A write access first reads the corresponding EEPROM page in the duplicate record. When the firmware is ready to deposit the page, it ensures a page erase for 1 ms, a page write for 1 ms, and then reinitializes both the page write and the erase bits.
Controller Structure
The EEPROM driver encapsulates access to the EEPROM by providing functions to read from and write to the EEPROM. The controller provides functions to decode and read data from EEPROM. These functions provide access to device calibration values, boot parameters, and the device ID field.
The driver also provides function to validate the integrity of these values after device initialization. Variation functions compare the value stored in RAM with the value stored in EEPROM to ensure that the copy in RAM has not been corrupted.
118
<img file="MX347308B_D0106.tif" />
Finally, the controller provides funnin ^
IMPI institute μεχκλνο MtAraOHtpAD INDUSTRIAL to write to EEPROM. These features include usage log and device power code update.
As needed the controller can handle Hamming encoding and decoding operations as well as calculating parity bits in write-only fields.
The above descriptions of specific embodiments of the present invention have been presented for purposes of illustration and description. They are not intended to be exhaustive or to limit the invention to the precise forms described, and obviously many modifications and variations are possible taking into account the above teaching. The modalities were chosen and described in order to better explain the principles of the invention and its practical application, therefore to allow other persons skilled in the art to make better use of the invention and various modalities with various modifications as appropriate to the particular use contemplated. . It is proposed that the scope of the invention be defined by the claims appended thereto and their equivalents.
It is noted that in relation to this date, the best method known to the applicant to carry out the present invention is the one that is clear from the present description of the invention.
119
<img file="MX347308B_D0107.tif" />
Contents128
138 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78 Sheet 79 Sheet 80 Sheet 81 Sheet 82 Sheet 83 Sheet 84 Sheet 85 Sheet 86 Sheet 87 Sheet 88 Sheet 89 Sheet 90 Sheet 91 Sheet 92 Sheet 93 Sheet 94 Sheet 95 Sheet 96 Sheet 97 Sheet 98 Sheet 99 Sheet 100 Sheet 101 Sheet 102 Sheet 103 Sheet 104 Sheet 105 Sheet 106 Sheet 107 Sheet 108 Sheet 109 Sheet 110 Sheet 111 Sheet 112 Sheet 113 Sheet 114 Sheet 115 Sheet 116 Sheet 117 Sheet 118 Sheet 119 Sheet 120 Sheet 121 Sheet 122 Sheet 123 Sheet 124 Sheet 125 Sheet 126 Sheet 127 Sheet 128 Sheet 129 Sheet 130 Sheet 131 Sheet 132 Sheet 133 Sheet 134 Sheet 135 Sheet 136 Sheet 137 Sheet 138
124 members in 19 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 13476960 | United States of America | – | |
| 201213476960 | United States of America | A | |
| 201213476960 | United States of America | A | |
| 2013029104 | United States of America | W | |
| 2013029104 | United States of America | W | |
| 13476960 | – | – | – |
| PCTUS2013029104 | – | – | – |
| US201213476960 | – | – | – |
| WO2013US29104 | – | – | – |
Members124
| Document | Office | Kind | |
|---|---|---|---|
| CA2828613A1 | Canada | A1 | |
| CA2828617A1 | Canada | A1 | |
| US2012253262A1 | United States of America | A1 | |
| US2012253263A1 | United States of America | A1 | |
| WO2012134766A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2012134767A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US8301238B2 | United States of America | B2 | |
| WO2012134766A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2012134767A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US8428708B1 | United States of America | B1 | |
| US8428709B1 | United States of America | B1 | |
| AU2012238095A1 | Australia | A1 | |
| AU2012238096A1 | Australia | A1 | |
| SG192950A1 | Singapore | A1 | |
| SG193236A1 | Singapore | A1 | |
| US2013310729A1 | United States of America | A1 | |
| CA2873425A1 | Canada | A1 | |
| WO2013176728A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CA2874983A1 | Canada | A1 | |
| WO2013187951A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN103492018A | China | A | |
| CN103501854A | China | A | |
| EP2691145A2 | European Patent Office (EPO) | A2 | |
| EP2691148A2 | European Patent Office (EPO) | A2 | |
| MX2013010199A | Mexico | A | |
| KR20140024355A | Republic of Korea | A | |
| KR20140039184A | Republic of Korea | A | |
| MX2013009929A | Mexico | A | |
| US2014115882A1 | United States of America | A1 | |
| JP2014513621A | Japan | A | |
| JP2014516281A | Japan | A | |
| US8781571B2 | United States of America | B2 | |
| EP2691145A4 | European Patent Office (EPO) | A4 | |
| US2014288526A1 | United States of America | A1 | |
| EP2691148A4 | European Patent Office (EPO) | A4 | |
| AU2013266914A1 | Australia | A1 | |
| AU2013274873A1 | Australia | A1 | |
| SG11201407396VA | Singapore | A | |
| SG11201408039YA | Singapore | A | |
| KR20150022879A | Republic of Korea | A | |
| KR20150023004A | Republic of Korea | A | |
| CN104487132A | China | A | |
| EP2852433A1 | European Patent Office (EPO) | A1 | |
| CN104519947A | China | A | |
| EP2858715A1 | European Patent Office (EPO) | A1 | |
| RU2013148572A | Russian Federation | A | |
| RU2013148574A | Russian Federation | A | |
| MX2014013951A | Mexico | A | |
| MX2014014788A | Mexico | A | |
| IN12DEN2015A | India | A | |
| JP2015517382A | Japan | A | |
| JP2015519177A | Japan | A | |
| US2015196754A1 | United States of America | A1 | |
| RU2557690C2 | Russian Federation | C2 | |
| US9095706B2 | United States of America | B2 | |
| IN10505DEN2014A | India | A | |
| NZ614605A | New Zealand | A | |
| RU2564084C2 | Russian Federation | C2 | |
| HK1202830A1 | Hong Kong, China | A1 | |
| JP5813856B2 | Japan | B2 | |
| US2015338445A1 | United States of America | A1 | |
| NZ615719A | New Zealand | A | |
| CA2949709A1 | Canada | A1 | |
| WO2015187834A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2858715A4 | European Patent Office (EPO) | A4 | |
| JP2016000351A | Japan | A | |
| EP2852433A4 | European Patent Office (EPO) | A4 | |
| MX337312B | Mexico | B | |
| AU2012238095B2 | Australia | B2 | |
| AU2012238096B2 | Australia | B2 | |
| US9364656B2 | United States of America | B2 | |
| CN103501854B | China | B | |
| EP2691148B1 | European Patent Office (EPO) | B1 | |
| RU2014151720A | Russian Federation | A | |
| RU2014153102A | Russian Federation | A | |
| NZ701761A | New Zealand | A | |
| PT2691148T | Portugal | T | |
| CN103492018B | China | B | |
| NZ702360A | New Zealand | A | |
| MX342033B | Mexico | B | |
| AU2013266914B2 | Australia | B2 | |
| DK2691148T3 | Denmark | T3 | |
| ES2585560T3 | Spain | T3 | |
| US2016296750A1 | United States of America | A1 | |
| AU2013274873B2 | Australia | B2 | |
| JP6027089B2 | Japan | B2 | |
| AU2015271708A1 | Australia | A1 | |
| BR112013025000A2 | Brazil | A2 | |
| BR112013024783A2 | Brazil | A2 | |
| SG11201609567WA | Singapore | A | |
| IL228075A | Israel | A | |
| KR20170016890A | Republic of Korea | A | |
| MX2016015453A | Mexico | A | |
| CN104487132B | China | B | |
| EP3151905A1 | European Patent Office (EPO) | A1 | |
| CN106573136A | China | A | |
| EP2858715B1 | European Patent Office (EPO) | B1 | |
| MX347308BThis record | Mexico | B | |
| US9645179B2 | United States of America | B2 | |
| CN104519947B | China | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 347308
- Publication, DOCDB
- 347308
- Publication, EPODOC
- MX347308
- Application
- 2014013951
- Application, DOCDB
- 2014013951
- Application, EPODOC
- MX20140013951
Titles2
- Spanish
- AUTOPRUEBA PARA PRODUCTO ANALGESICO.
- English
- SELF-TEST FOR ANALGESIC PRODUCT.
Classification
- CPC, 15
- A61N1/303
- G01R19/145
- A61N1/325
- A61N1/0432
- A61N1/0416
- A61N1/327
- A61N1/025
- A61M37/00
- A61N1/0428
- A61N1/08
- A61M2037/0007
- A61N1/30
- G01R19/165
- G08B21/182
- A61N1/18
- IPC, 3
- A61N1 18
- A61M31 00
- A61N1 30