Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11998692-B2

Patent

Publication Date

2024-06-04

Expiration Date


Abstract

Methods and apparatus provide communications among respiratory therapy device (“TD”), server and intermediary (e.g., a control device (“CTLD”) for the therapy device) to improve security. More secure communication channel(s) may be established using shared secrets derived with different channels. The communications may include transmitting therapy data from TD to server for authentication. The CTLD may receive the data and a nonce from a server. The CTLD receives from the TD a signing key dependent on the nonce and a secret shared by TD and server. The CTLD generates an authorisation code with received therapy data and the key for authentication of the data by the server upon its receipt of the code and data. The server computes (1) a key from the nonce and the secret known to TD, and (2) another authorisation code from received therapy data and the key. Data authentication may involve comparing received and computed codes.

Core Innovation

The disclosed invention relates to authenticating and securely uploading therapy data generated by a respiratory therapy device to a remote server via a control device. The control device receives therapy data from the respiratory therapy device and receives a nonce from the remote server, and sends the nonce to the respiratory therapy device. The therapy device provides a signing key to the control device, where the signing key is dependent on the nonce and a secret known to the respiratory therapy device and the remote server.

The control device generates an authorisation code using the therapy data and the signing key for authenticating the therapy data and sends the therapy data and the authorisation code to the remote server. Authenticating the therapy data is performed by comparing a first authorisation code with a second authorisation code computed from the received therapy data and a signing key derived from a nonce and a secret known to the respiratory therapy device. The authorisation code is generated based on the therapy data and the signing key.

Additionally, the disclosed secure channel and authentication concepts include deriving a signing key from a pseudo-random nonce and a shared secret, including an offset into a shared secret. The control device and remote server independently derive the signing key from the nonce and the offset into the shared secret and verify authenticity by comparing computed and received authorisation codes. The document also describes secure firmware upgrade authentication using an authorisation code derived from an upgrade file and a key derived from the respiratory therapy device secret, together with secure channel establishment between the respiratory therapy device and the control device using an out-of-band first shared secret and an insecure wireless link to reduce eavesdropping/man-in-the-middle risk.

Claims Coverage

The independent claims cover uploading therapy data with server-reliant nonce-based signing key derivation and authorisation-code authentication, implementations in a control device and a server, authentication by comparing received and computed authorisation codes, and a respiratory therapy device-side upload workflow. Across these independent claims, the main inventive features are the nonce-dependent signing key from a device/remote-known secret, generating an authorisation code from therapy data and the signing key, and authenticating by comparing authorization codes.

Nonce-dependent signing key from a shared secret

Receiving, by the control device, a nonce from the remote server, sending the nonce to the respiratory therapy device, receiving a signing key from the respiratory therapy device, wherein the signing key is dependent on the nonce and a secret known to the respiratory therapy device and the remote server.

Authorisation code generated from therapy data and signing key

Generating, by the control device, an authorisation code using the therapy data and the signing key, the authorisation code for authenticating the therapy data.

Uploading therapy data with authorisation code to remote server

Sending the therapy data and the authorisation code to the remote server.

Authentication by comparing first and second authorisation codes

Authenticating the therapy data by comparing the first authorisation code with the second authorisation code.

Server-side computing of signing key and second authorisation code

Compute a signing key from a nonce and a secret that is known to the respiratory therapy device; compute a second authorisation code from the received therapy data and the signing key; and authenticate the therapy data by comparing the first authorisation code with the second authorisation code.

Device-side nonce reception, signing key computation, and authorisation code generation

Receiving, by the respiratory therapy device, a nonce from the remote server; computing, by the respiratory therapy device, a signing key from the nonce and a secret known to the remote server; generating, by the respiratory therapy device, an authorisation code using the therapy data and the signing key, the authorisation code for authenticating the therapy data; and sending, by the respiratory therapy device, the therapy data and the authorisation code to the remote server.

Respiratory therapy device configured to upload nonce-authenticated therapy data

A respiratory therapy device comprising a pressure generator adapted to couple with a patient interface and supply a flow of air at positive pressure, and program instructions that control the respiratory therapy device to receive a nonce from the remote server, compute a signing key from the nonce and a secret known to the remote server, generate an authorisation code using the therapy data and the signing key, and send the therapy data and the authorisation code to the remote server.

Across the independent claims, the document’s claim coverage centers on deriving a signing key from a nonce and a secret known to the respiratory therapy device and the remote server, generating an authorisation code using the therapy data and the signing key, and authenticating therapy data either by uploading the therapy data with the authorisation code to the remote server or by computing a second authorisation code and authenticating by comparing the first and second authorisation codes. Separate independent claims cover implementations in a control device, a server, and the respiratory therapy device itself.

Stated Advantages

Not explicitly described in patent.

Documented Applications

Not explicitly described in patent.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.