Secure networked respiratory therapy systems

Inventors

HICKEY, BrianRoberts, Christopher JohnSomaiya, ChinmayeeTrull, Wendall EricTucker, Luke AnthonyFERNANDO, Amila Jeewaka

Assignees

Resmed Inc

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12453828-B2

Patent

Publication Date

2025-10-28

Expiration Date


Abstract

Methods and apparatus provide communications among respiratory therapy device (“TD”), server and intermediary (e.g., a control device (“CTLD”) for the therapy device) to improve security. More secure communication channel(s) may be established using shared secrets derived with different channels. The communications may include transmitting therapy data from TD to server for authentication. The CTLD may receive the data and a nonce from a server. The CTLD receives from the TD a signing key dependent on the nonce and a secret shared by TD and server. The CTLD generates an authorisation code with received therapy data and the key for authentication of the data by the server upon its receipt of the code and data. The server computes (1) a key from the nonce and the secret known to TD, and (2) another authorisation code from received therapy data and the key. Data authentication may involve comparing received and computed codes.

Core Innovation

A secure networked respiratory therapy system is described in which a respiratory therapy device provides respiratory therapy and generates therapy data that is uploaded to a remote server. The control device receives the therapy data from the respiratory therapy device, receives a signing key based on a secret known to the respiratory therapy device and the remote server, generates an authorisation code using the therapy data and the signing key, and sends the therapy data and the authorisation code to the remote server.

The remote server is described as authenticating the therapy data by receiving the therapy data and a first authorisation code, computing a signing key from a nonce and a secret known to the respiratory therapy device, computing a second authorisation code based on the therapy data and the signing key, and comparing the first authorisation code with the second authorisation code. Authentication of the therapy data is performed when the codes match based on the comparison.

The document further describes cryptographic authentication logic for generating and validating the authorisation code, including hashed message authorisation codes produced using a cryptographic hash function and comparison variants using an exclusive OR. It also describes secure firmware upgrade authorization and therapy data upload authorization that rely on server-derived authorization codes using respiratory-therapy-device secrets, and uses nonce/offset values with expiration checks.

Claims Coverage

The independent claims cover four closely related implementations centered on receiving therapy data, deriving signing keys from a shared secret, generating an authorisation code, and authenticating the therapy data by code comparison. Across these independent claims, the inventive features repeatedly include nonce/offset-based signing-key derivation, cryptographic authorisation-code generation, and server authentication by comparison.

Receiving therapy data and signing-key based on a shared secret

A control device receives the therapy data from the respiratory therapy device, receives a signing key from the respiratory therapy device, wherein the signing key is based on a secret known to the respiratory therapy device and the remote server, generates, using the therapy data and the signing key, an authorisation code for authenticating the therapy data, and sends the therapy data and the authorisation code to the remote server.

Authenticating therapy data by comparing authorisation codes

Non-transitory computer readable storage media comprising instructions for controlling a server to authenticate therapy data generated by a respiratory therapy device, wherein execution of the instructions by one or more processors causes the server to receive the therapy data and a first authorisation code, compute a signing key from a nonce and a secret that is known to the respiratory therapy device, compute a second authorisation code based on the therapy data and the signing key, compare the first authorisation code with the second authorisation code, and authenticate the therapy data when the first authorisation code matches the second authorisation code based on the comparison.

Uploading therapy data using signing-key based authorisation-code authentication

A respiratory therapy device comprising a respiratory therapy assembly configured to supply respiratory therapy to a patient, wherein memory comprising instructions for controlling the respiratory therapy device to upload therapy data to a remote server, and wherein the therapy data is based on the respiratory therapy supplied to the patient, and wherein the one or more processors compute a signing key based on a secret known to the remote server, generate, using the therapy data and the signing key, an authorisation code for authenticating the therapy data, and send the therapy data and the authorisation code to the remote server.

Control-device implementation using non-transitory computer readable storage media

One or more non-transitory computer readable storage media comprising processor control instructions that, when executed by one or more processors, operate a control device to upload therapy data generated by a respiratory therapy device to a remote server, the processor control instructions comprising instructions to receive the therapy data from the respiratory therapy device, receive a signing key from the respiratory therapy device, wherein the signing key is based on a secret known to the respiratory therapy device and the remote server, generate, using the therapy data and the signing key, an authorisation code for authenticating the therapy data, and send the therapy data and the authorisation code to the remote server.

Taken together, the independent claims focus on authenticating uploaded therapy data using an authorisation code generated from therapy data and a signing key derived from a secret shared between the respiratory therapy device and the remote server, with server-side authentication achieved by computing a second authorisation code and comparing it to a first authorisation code.

Stated Advantages

Secure authentication of therapy data uploaded to a remote server by using authorisation codes and server-side comparison.

Mitigation against unauthorised/spoofed/unassociated control devices is stated as being handled within the secure communication architecture.

Secure firmware upgrade authorization is described using server-derived authorization codes based on RT-device secrets.

Therapy data upload authorization is described using server-supplied nonces and offsets with expiration checks.

Documented Applications

Uploading therapy data generated by a respiratory therapy device to a remote server for authentication.

Authenticating therapy data at the remote server using authorisation-code comparison.

Secure firmware upgrade authorization for the respiratory therapy device.

Therapy data upload authorization using nonce/offset values with expiration checks.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.