DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Applicant' s arguments, filed 5/26/2026, have been fully considered. The following rejections and/or objections are either reiterated or newly applied. They constitute the complete set presently being applied to the instant application.
Applicants have amended their claims, filed 5/26/2026, and therefore rejections newly made in the instant office action have been necessitated by amendment.
Claims 1-23 and 35-36 are the currently pending claims. Claims 24-34 and 37-40 have been previously canceled; Claim 16 has been previously withdrawn; and Claims 1, 9, 14, 15, 17, and 35 have been amended. Claims 1-15, 17-23, and 35-36 are hereby under examination.
Claim Interpretation
The Examiner interprets the limitation “establishing a secret key with a [display device or sensor electronics module] over one or more primary invitation channels” recited in claims 1, 9, and 14 under a broadest reasonable interpretation (BRI), in view of the specification, as establishing and sharing a cryptographic shared secret between the analyte sensor system and the display device by exchanging key establishment information using connectionless invitation or advertisement type channels used to invite or initiate communications between devices, as distinguished from data channels. This interpretation is consistent with the specification’s description that the analyte sensor system and the display device “only communicate over the three primary invitation channels” to circumvent pairing, bonding, connecting, and disconnecting, and that the devices “establish[] and shar[e] a shared secret (hereinafter, ‘secret key’) … over the primary invitation channels,” including by participating in a cryptographic key exchange protocol over the primary invitation channels (Instant Application, [0079]-[0080]).
Claim Objections
Claims 2, 5, 10, 14, and 35 are objected to because of the following informalities:
In claim 2, line 2: “the display device” should be “the first display device”;
In claim 5, line 2: “the display device” should be “the first display device”;
In claim 10, line 2: “the display device” should be “the first display device”;
In claim 14, lines 5-6: "from a server over a first secure channel established between the first display device and a server” where "a server" is recited twice and should "from a server over a first secure channel established between the first display device and the server”; and
In claim 35, lines 14: “second display” should be “second display device”.
Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 8, 13, 18, and 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as failing to set forth the subject matter which the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the applicant regards as the invention.
Claim 8 recites "wherein the encrypted analyte data is broadcast without establishing a connection with the display device” in line 2. Claim 1, from which claim 8 depends, was amended to recite both "a first display device" and "a second display device." As a result, "the display device" in claim 8 lacks a clear antecedent basis, and a person of ordinary skill in the art would not be able to determine the scope of the claim because it cannot be ascertained whether the broadcast occurs without establishing a connection with the first display device, with which the secret key is established, or with the second display device, which receives the broadcast encrypted analyte data. For purposes of examination, and consistent with the specification's description of communicating over the primary invitation channels while circumventing pairing, bonding, connecting, and disconnecting (Instant Application, [0079]-[0080]), the limitation is interpreted as the encrypted analyte data being broadcast without establishing a connection with either the first display device or the second display device.
Claim 13 recites "wherein the encrypted analyte data is broadcast without establishing a connection with the display device” in line 2. Claim 9, from which claim 13 depends, was amended to recite both "a first display device" and "a second display device." As a result, "the display device" in claim 13 lacks a clear antecedent basis, and a person of ordinary skill in the art would not be able to determine the scope of the claim because it cannot be ascertained whether the broadcast occurs without establishing a connection with the first display device, with which the secret key is established, or with the second display device, which receives the broadcast encrypted analyte data. For purposes of examination, and consistent with the specification's description of communicating over the primary invitation channels while circumventing pairing, bonding, connecting, and disconnecting (Instant Application, [0079]-[0080]), the limitation is interpreted as the encrypted analyte data being broadcast without establishing a connection with either the first display device or the second display device.
Claim 18 recites "wherein the data is encrypted at an application layer of a communication protocol stack at the display device” in lines 1-2. Claim 14, from which claim 18 depends through claim 17, was amended to recite both "a first display device" and "a second display device”. As a result, "the display device" in claim 18 lacks a clear antecedent basis, and a person of ordinary skill in the art would not be able to determine the scope of the claim because it cannot be ascertained whether the recited encryption occurs at the first display device or at the second display device. For purposes of examination, and consistent with claim 17, which recites generating and broadcasting the encrypted data in a method performed by the first display device, "the display device" in claim 18 is interpreted as the first display device.
Claim 20 depends from claim 17, which depends from claim 14. Claim 14 recites that the method is performed by a first display device and includes receiving encrypted analyte data from a server over a first secure channel, where the encrypted data is received by the server from a second display device and the second display device receives the encrypted data from a broadcast by the sensor electronics module over the one or more primary invitation channels. Claim 17 further recites “generating the encrypted analyte data by encrypting data using the secret key; and broadcasting the encrypted data over the one or more primary invitation channels” (lines 3-4). Claim 20 then recites “wherein the encrypted analyte data is received in response to the encrypted data being broadcast over the one or more primary invitation channels” (lines 1-3). It is unclear whether “the encrypted analyte data” in claim 20 refers to the encrypted analyte data received by the first display device from the server in claim 14, the encrypted analyte data generated by the first display device in claim 17, or the encrypted data broadcast by the sensor electronics module and received by the second display device in claim 14. It is also unclear whether the recited receiving in claim 20 occurs from the server over the first secure channel, as required by claim 14, or from the sensor electronics module over the one or more primary invitation channels, as suggested by the responsive broadcast language of claim 20. Therefore, a person of ordinary skill in the art would not be able to determine the scope of claim 20 with reasonable certainty. For purposes of examination, claim 20 is interpreted as requiring that the encrypted analyte data received by the first display device, as recited in claim 14, is received as a result of or in response to the encrypted data broadcast over the one or more primary invitation channels as recited in claim 17. Under this interpretation, claim 20 does not require that the first display device directly receive the encrypted analyte data from the sensor electronics module over the primary invitation channels. Rather, claim 20 broadly encompasses a responsive exchange in which encrypted data broadcast over the primary invitation channels causes the sensor electronics module to broadcast encrypted analyte data, which is then received by the second display device and relayed through the server to the first display device as recited in claim 14.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 35-36 are non-provisionally rejected on the grounds of nonstatutory double patenting as being unpatentable over claim 13 of U.S. Patent No. US 12,284,519 B2, hereinafter referred to as Reference or Ref, and further in view of Mandapaka et al. (US-20180027104-A1), Keenan et al. (Keenan, Kathryn E. et al., “Development and Evaluation of Bluetooth Low-Energy Device for Electronic Encounter Metrics,” Journal of Research of the National Institute of Standards and Technology 126 (2021)), Loh et al. (US-20040198223-A1), Mensinger et al. (US-20160335409-A1), and Klinkner et al. (US-20210092599-A1).
The analysis as follows (please note the bolded portions of the entries under the Instant Application, IA, are those portions of the IA claims that the claims of Patent Application 18/781767, Reference, does not have or are different from in some form):
Instant Application (IA) claim language(bold = not in / different from reference)
Reference – US 12,284,519 B2 (key claim language)
Analysis (DP / obviousness-type)
Claim 35:
A computer-implemented method for communicating analyte data performed by a sensor electronics module of an analyte sensor system, comprising:
Ref Claim 13 preamble: “A method of facilitating secure communications between a sensor system for measuring analyte levels and a display device, comprising:”
Same general subject matter of secure communications between an analyte sensor system and a display device. The “computer-implemented” and “sensor electronics module” wording is an implementation framing of the sensor-system functionality recited in Ref claim 13.
obtaining analyte data from an analyte sensor electrically coupled to the sensor electronics module;
Ref Cl.13: “transmitting, from the sensor system to the display device, analyte data indicative of measured analyte levels …”
Ref claim 13 teaches secure transmission of analyte data from the sensor system. To the extent Ref claim 13 does not expressly recite obtaining the analyte data from an electrically coupled analyte sensor, obtaining measured analyte data before transmitting it from the sensor system would have been inherent in, or at least obvious from, the analyte-sensor system context.
establishing a secret key with a first display device, based on executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module;
Ref Cl.13: “executing, at an application layer of the sensor system, a password authenticated key exchange (PAKE) protocol with the display device to derive an authentication key;”
Ref claim 13 teaches the core application-layer key-exchange concept between the sensor system and display device. The “first display device” wording distinguishes the authorized display device from the later-recited relay display device. To the extent the IA claim is broader than PAKE or requires a communication protocol stack, Keenan teaches a Diffie-Hellman cryptographic key exchange in which each device broadcasts its public key using Bluetooth advertisements to generate a shared secret key, and Loh teaches an application layer as part of a communication protocol stack (Keenan, p. 3-4, Sec. 2.1.1; Loh, [0050]-[0051]).
encrypting the analyte data using the secret key;
Ref Cl.13: “after the authenticating is successful, establishing an encrypted connection …” and “transmitting … analyte data … via the encrypted connection.”
Ref claim 13 teaches secure transmission of analyte data after application-layer key establishment, but does not expressly recite payload encryption of the analyte data using the derived key. Mandapaka makes this implementation obvious by teaching that an application key shared between the analyte sensor system and display device may be used by the analyte sensor system to encrypt analyte data and by the display device to decrypt received analyte data (Mandapaka, [0354]).
and transmitting the encrypted analyte data, via a broadcast over one or more primary invitation channels, to a second display device;
Ref Cl.13: “transmitting, from the sensor system to the display device, analyte data indicative of measured analyte levels via the encrypted connection.”
Ref claim 13 teaches secure transmission of analyte data from the sensor system to a display device, but does not expressly teach a broadcast over primary invitation channels to a second display device. Mandapaka teaches encrypted analyte values transmitted in advertisement messages, and Keenan teaches Bluetooth advertising channels and use of Bluetooth advertisements for key exchange (Mandapaka, [0010]; Keenan, p. 3-4, Sec. 2.1.1). Transmitting the encrypted analyte data by advertisement/invitation-channel broadcast to another display device would have been an obvious transport and receiver selection in the multi-display secure analyte communication environment.
wherein the broadcast encrypted analyte data is transmitted from the second display device to a server over a first secure channel established between the server and the second display device;
Ref Cl.13 does not recite server relay through a second display device.
Mensinger teaches, in the CGM field, that display devices transmit glucose data to cloud infrastructure, that communications can be encrypted and secured such as by HTTPS/SSL, and that a display can act as a pass-through for encrypted CGM data to a server (Mensinger, [0054]-[0055], [0072], [0092]). Mensinger therefore supplies the obvious second-display-to-server secure relay portion.
wherein the encrypted analyte data transmitted by the second display is transmitted from the server to the first display device over a second secure channel established between the server and the first display device;
Ref Cl.13 does not recite server distribution from a server to the first display device.
Mensinger teaches cloud/server distribution of glucose data to other display devices and remote monitor display devices, and teaches secure communications such as HTTPS/SSL for communications within the system (Mensinger, [0055], [0173], [0186]). Klinkner teaches an end-to-end relay architecture in which encrypted data is relayed through a server to an authorized owner device for decryption by the authorized device (Klinkner, Abstract, [0130]-[0133]). It would have been obvious to use the server to forward encrypted analyte data received from the second display device to the first display device over a secure server-display channel.
and wherein the encrypted analyte data transmitted by the server is received by the first display device, decrypted by the first display device using the secret key, and displayed by the first display device.
Ref Cl.13 teaches secure analyte communications between the sensor system and display device after application-layer key exchange, but does not recite the server-relayed encrypted analyte data being decrypted and displayed by the first display device.
Mandapaka teaches that the display device uses the application key to decrypt received analyte data (Mandapaka, [0354]). Klinkner teaches preserving protected data through intermediary devices and a server so that only the authorized key-holding device decrypts the data, and teaches displaying the decrypted data to the user (Klinkner, [0130]-[0133]). Displaying decrypted analyte data is an expected function of an analyte display device.
Accordingly, amended claim 35 is not patentably distinct from Reference claim 13 in view of Mandapaka, Keenan, Loh, Mensinger, and Klinkner. Reference claim 13 teaches the core secure analyte communication workflow between a sensor system and display device using application-layer key exchange. Mandapaka makes it obvious to use the shared key for analyte-payload encryption and decryption. Keenan makes it obvious to use Bluetooth advertising or invitation-channel communications in connection with cryptographic exchange. Loh supports the application layer as part of a communication protocol stack. Mensinger makes it obvious in the CGM field to relay glucose data from a display device to cloud/server infrastructure and distribute glucose data to other display devices over secure communications. Klinkner makes it obvious to preserve end-to-end encrypted data through intermediary devices and a server so that only the authorized key-holding device decrypts the protected data. Therefore, the amended relay limitations do not render claim 35 patentably distinct.
Instant Application (IA) claim language(bold = not in / different from reference)
Reference – US 12,284,519 B2 (key claim language)
Analysis (DP / obviousness-type)
Claim 36:
The computer-implemented method of claim 35, wherein the analyte data is encrypted at the application layer of the communication protocol stack at the sensor electronics module.
Ref Cl.13: application-layer PAKE (“executing, at an application layer … a PAKE … to derive an authentication key”), plus establishing an encrypted connection and transmitting analyte data via the encrypted connection.
Claim 36 depends from amended claim 35, which is not patentably distinct for the reasons set forth above. Claim 36 further specifies application-layer payload encryption at the sensor electronics module. Ref claim 13 teaches application-layer key establishment for secure analyte communications. Mandapaka teaches that the application key may be generated at the software/application level of the analyte sensor system and may be used by the analyte sensor system to encrypt analyte data (Mandapaka, [0354]-[0355]). Loh teaches an application layer in a communication protocol stack (Loh, [0050]-[0051]). Thus, encrypting the analyte payload at the application layer of the sensor electronics module’s communication protocol stack would have been an obvious protocol-stack placement choice for implementing confidentiality once shared key material is established.
Accordingly, claim 36 is not patentably distinct from Reference claim 13 in view of Mandapaka, Keenan, Loh, Mensinger, and Klinkner for the reasons discussed with respect to claim 35, and further because encrypting analyte data at the application layer of the communication protocol stack at the sensor electronics module would have been an obvious implementation of the secure analyte-data communication workflow taught by Reference claim 13, Mandapaka, and Loh.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 2, 8-10, 13-15, 17, 21, and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Burnette et al. (US-20170181628-A1), hereinafter referred to as Burnette, in view of Mandapaka et al. (US-20180027104-A1), hereinafter referred to as Mandapaka, in view of Keenan et al. (Keenan, Kathryn E. et al., “Development and Evaluation of Bluetooth Low-Energy Device for Electronic Encounter Metrics,” Journal of Research of the National Institute of Standards and Technology 126 (2021)), hereinafter referred to as Keenan, in view of Mensinger et al. (US-20160335409-A1), hereinafter referred to as Mensinger, and in view of Klinkner et al. (US-20210092599-A1), hereinafter referred to as Klinkner.
Regarding claim 1, Burnette teaches a computer-implemented method for communicating analyte data performed by a sensor electronics module of an analyte sensor system (Burnette, [0098], “CGM processor 506 may then transmit raw sensor data 504 from AFE 500, apply one or more algorithms to create/calculate an EGV value, and store that EGV value in memory, e.g., flash database”, Burnette describes processor-executed operations performed by the CGM electronics/module in an analyte sensor system, i.e., a computer implemented method performed by the sensor electronics module) comprising: obtaining analyte data from an analyte sensor electrically coupled to the sensor electronics module (Burnette, [0029], “a sensor electronics module physically connected to the continuous analyte sensor to receive the analyte concentration measurements and communicate them to display devices”, Burnette expressly teaches the sensor electronics module receiving analyte concentration measurements from a continuous analyte sensor that is physically connected to the module; [0084], “CGM processor 506... can take a measurement(s) of one or more analyte values... using implantable continuous analyte sensor 312 and sensor measurement circuitry 310 or AFE 500”, Burnette further explains that the sensor electronics module actively takes analyte measurements via the coupled analyte sensor and associated measurement circuitry); and broadcasting the encrypted analyte data over the one or more primary invitation channels (Burnette, [0151], “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol”, Burnette shows broadcasting encrypted analyte data in advertising beacons, which are broadcast signals usable to communicate data without first establishing a two-way protocol).
Also regarding claim 1, Burnette does not fully teach establishing a secret key with a first display device over one or more primary invitation channels and encrypting the analyte data using the secret key. Rather, Burnette teaches broadcasting “first advertising beacons 700 (also referred as advertisement signals 412 in FIG. 4)” (Burnette, [0099]) and that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, [0151]). Burnette further teaches a bonding exchange context with a display device, stating that the whitelist may be populated with “a Generic Access Profile (GAP) Address or an Identity Resolving Key (IRK) entry upon a display device... sending its configuration during a bonding exchange when a wireless connection is being established” (Burnette, [0097]). However, Burnette does not expressly teach that the encryption uses a secret key established with the first display device over the primary invitation channel(s), nor does Burnette expressly teach encrypting the analyte data using such an established secret key.
Mandapaka teaches establishing a shared secret key, namely an application key, between an analyte sensor system and a display device and using that shared key to encrypt analyte data for transmission. Mandapaka discloses that “the information related to authentication includes an application key” and that the application key may be used to encrypt analyte data, stating that “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710, and display device 710 may use the application key to decrypt the received analyte data” (Mandapaka, [0008]; [0354]). Mandapaka further teaches that encrypted analyte values may be transmitted using invitation type signaling, disclosing that “at least a portion of the encrypted analyte value is transmitted to the display device in one or more advertisement messages transmitted by the analyte sensor system” (Mandapaka, [0010]). In context, Mandapaka’s application key functions as a shared secret key established between the analyte sensor system and the display device and is used to encrypt analyte data that is transmitted via advertisement messages.
Keenan teaches establishing a shared secret key via Bluetooth advertising channels, stating that “a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1). Keenan further teaches generating a shared secret key using Diffie-Hellman, where “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519” and “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” and “each device could generate a shared secret unique key” (Keenan, p. 3-4, Sec. 2.1.1). One of ordinary skill in the art would have used Keenan’s Diffie-Hellman derived shared secret key as the application key of Mandapaka for encrypting analyte data, and would have applied that encryption to the analyte data placed in Burnette’s advertising beacons.
It would have been prima facie obvious before the effective filing date of the claimed invention to modify Burnette in view of Mandapaka and Keenan to establish a secret key with a first display device over one or more primary invitation channels and to encrypt the analyte data using the secret key. It would have been possible to combine the teachings of Burnette, Mandapaka, and Keenan because Burnette already employs Bluetooth advertising beacons as invitation signaling for communicating analyte data to display devices, Keenan teaches performing a cryptographic key exchange by broadcasting public keys via those same Bluetooth advertising channels and generating a shared secret key using Diffie-Hellman, and Mandapaka teaches using a shared application key between an analyte sensor system and a display device to encrypt analyte data that is transmitted via advertisement messages. One of ordinary skill in the art would have understood that Keenan’s advertising-channel Diffie-Hellman exchange could be used during Burnette’s advertising-based invitation phase to establish a shared secret key with a first display device, and that Mandapaka’s application-key-based encryption could then be applied to encrypt analyte data prior to broadcasting it in Burnette’s advertising beacons. The benefit of the combination would have been enabling Burnette’s encrypted advertising-beacon analyte communications to use a shared secret established over the advertising or invitation channels themselves, improving privacy and security for broadcast analyte-data communications while maintaining low power operation and avoiding the overhead of connection establishment when transmitting analyte data.
Also regarding claim 1, the modified Burnette does not fully teach wherein the encrypted data broadcast over the one or more primary invitation channels is received, by a second display device, and transmitted from the second display device to a server over a first secure channel established between the second display device and the server, wherein the encrypted data transmitted to the server is transmitted by the server to the first display device over a second secure channel established between the first display device and the server, and wherein the encrypted data transmitted by the server is received by the first display device, decrypted, by the first display device, using the secret key, and displayed, by the first display device. In particular, Burnette teaches broadcasting encrypted analyte data in advertising beacons to display devices and teaches that sensor information may be transmitted from one display device to another display device, and also teaches that “data transmission of sensor information can be effectuated directly from display device 120c to a second display device, e.g., display device 120b” (Burnette, [0007]-[0008], [0151]). Mandapaka teaches that an application key shared between the analyte sensor system and a display device may be used by the analyte sensor system to encrypt analyte data for transmission to the display device, and that the display device may use the application key to decrypt the received analyte data, including encrypted analyte values transmitted in advertisement messages (Mandapaka, [0354], [0378]-[0382]). Keenan teaches that Bluetooth devices can broadcast on the three advertising channels and can exchange public keys using Bluetooth advertisements to generate a shared secret key (Keenan, p. 3-4, Sec. 2.1.1). Thus, Burnette in view of Mandapaka and Keenan teaches or suggests encrypted analyte data broadcast over primary invitation channels, receipt by display devices, and decryption of encrypted analyte data by an authorized display device using a shared secret key. However, Burnette, Mandapaka, and Keenan do not fully teach that a second display device that receives the encrypted broadcast transmits that encrypted data to a server over a first secure channel, that the server transmits the encrypted data to the first display device over a second secure channel, and that the first display device decrypts the server-relayed encrypted data using the secret key and displays the decrypted analyte data.
Mensinger teaches a continuous glucose monitoring distributed architecture in which displays receive glucose data from a continuous glucose sensor unit and forward the glucose data to a cloud computing architecture. Mensinger teaches that displays 104a-c receive data relating to glucose levels from continuous glucose sensor units 100a-c at predetermined time intervals, and that the displays present glucose readings over time and display the actual current glucose value (Mensinger, [0050]). Mensinger further teaches that the displays 104a-e or continuous glucose sensor units 100a-c transmit data to the distributed cloud computing architecture 106, which organizes, stores, and provides access to the data by other computers, applications, and third parties (Mensinger, [0054]). Mensinger teaches that communications within the system can be encrypted and secured, such as HTTPS and SSL communications, and that patient data including all data posts from the displays can be encrypted and stored in a secure fashion by the cloud computing architecture 106 (Mensinger, [0055]). Thus, Mensinger teaches display-to-server secure channel communications in the same CGM context.
Mensinger further teaches using a display device as a pass-through for encrypted data received from a continuous glucose monitor transmitter. Mensinger teaches that the transmitter in a continuous glucose monitor can encrypt all or a portion of data and pass it through the associated display 104 to the services server 300, and that the display 104 does not have a decryption key for the encrypted bulk data and therefore acts simply as a pass-through for encrypted bulk data (Mensinger, [0072]). Mensinger further teaches that the transmitter sends an encrypted message to a display, such as a smartphone or dedicated receiver, which sends the encrypted message on to the services server, and that the display acts as a pass-through without the ability to decrypt all of the data (Mensinger, [0092]). Mensinger therefore teaches the use of a display device that receives encrypted data from a CGM transmitter and forwards the encrypted data to a server without decrypting all of the encrypted data.
Mensinger further teaches server distribution of glucose data to other display devices. Mensinger teaches that the cloud infrastructure can forward a subset of data relating to glucose levels to a second display device, the subset including current and past glucose levels (Mensinger, [0173]). Mensinger also teaches a cloud server architecture having a plurality of servers that receives data from a plurality of display devices, and a plurality of remote monitor display devices that receive data from one of the plurality of servers, where the data sent to each remote monitor display device depends upon the data type and the display device that transmitted the data to the server (Mensinger, [0186]). Thus, Mensinger teaches the use of server-side distribution of glucose data received from display devices to other display devices. Mensinger does not expressly teach that the server-relayed encrypted data remains encrypted until decryption by the first display device using the sensor-to-display secret key.
Klinkner teaches an end-to-end encrypted relay architecture in which information associated with a short-range broadcast is detected by an intermediate mobile device, encrypted data is relayed through a server, and only the owner or authorized device holding the corresponding key receives, decrypts, and displays the protected data. Klinkner teaches that a tracking device can provide a hashed identifier to a mobile device, for instance within an advertisement packet, that the mobile device can receive a public key from an entity, determine a location, encrypt the location with the public key, and provide the hashed identifier and encrypted location to the entity, which provides the encrypted location to an owner of the tracking device for decryption using a private key corresponding to the public key (Klinkner, Abstract). Klinkner further teaches that the owner device receives encrypted location data from the entity and decrypts the encrypted location data using a private key, and that the decrypted data can then be displayed to the user (Klinkner, [0130]-[0132]). Klinkner expressly teaches the reason for this architecture, stating that encrypting the location data at the mobile device protects the data from the point of access until the encrypted data is received by the owner device, and that where the intermediate mobile device and entities do not have access to the private key, “no system or entity between the mobile device 102 and the owner device 1224 is able to decrypt the encrypted location data 1220,” thereby enabling end-to-end protection (Klinkner, [0133]).
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the Burnette system as modified by Mandapaka and Keenan in view of Mensinger and Klinkner such that the encrypted analyte data broadcast over the one or more primary invitation channels is received by a second display device, transmitted from the second display device to a server over a first secure channel, transmitted by the server to the first display device over a second secure channel, and then received, decrypted using the secret key, and displayed by the first display device. It would have been possible to combine the teachings because Burnette already teaches a CGM system having multiple display devices and advertising beacons containing encrypted analyte data; Mandapaka teaches use of a shared secret key to encrypt analyte data and allow a display device to decrypt the encrypted analyte data; Keenan teaches establishing the shared secret by exchanging public keys over advertising channels; Mensinger teaches in the same CGM field that displays receiving glucose data can forward data to cloud infrastructure over secure communications and can act as pass-through devices for encrypted CGM data; and Klinkner teaches preserving end-to-end protection through an intermediate mobile device and server so that only the authorized key-holding device can decrypt the protected data.
One of ordinary skill in the art would have been motivated to apply Mensinger’s CGM cloud relay architecture to Burnette’s encrypted advertising-beacon analyte data so that glucose data received by one display device could be made available to another authorized display device through cloud infrastructure. One of ordinary skill in the art would have further been motivated by Klinkner’s end-to-end protection teaching to preserve the encrypted form of the analyte data through the second display device and server so that intermediate devices and server-side components need not decrypt the patient’s analyte data. Klinkner expressly teaches that no system or entity between the detecting mobile device and the owner device can decrypt the protected data where those intermediaries lack the corresponding key (Klinkner, [0133]). The predictable result would have been using known CGM cloud relay infrastructure to deliver Burnette/Mandapaka/Keenan’s encrypted analyte broadcast to the authorized first display device while maintaining privacy by allowing decryption and display at the first display device using the shared secret key.
Regarding claim 2, the modified Burnette does not fully teach establishing the secret key comprises participating in a cryptographic key exchange with the display device over the one or more primary invitation channels. Rather, the modified Burnette teaches establishing a secret key with the display device and further teaches a sensor electronics module communicating with a display device in a BLE environment where device association information may be exchanged, including that a display device sends configuration “during a bonding exchange when a wireless connection is being established” (Burnette, ¶[0097]). However, the modified Burnette does not teach that establishing the secret key comprises participating in a cryptographic key exchange with the display device over the one or more primary invitation channels.
Keenan teaches performing a cryptographic key exchange over Bluetooth advertisements on the advertising channels. Keenan discloses that “In the Bluetooth Standard [10], a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1). Keenan further discloses that “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” (Keenan, p. 4, Sec. 2.1.1), and that “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519 [12–13]” (Keenan, p. 4, Sec. 2.1.1). In context, Keenan teaches that the devices participate in a cryptographic key exchange by broadcasting the public keys using Bluetooth advertisements over the advertising channels, and that the result of that key exchange is a shared secret key.
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Keenan to have establishing the secret key comprise participating in a cryptographic key exchange with the display device over the one or more primary invitation channels. It would have been possible to combine the teachings because the modified Burnette already operates using Bluetooth Low Energy communications between a sensor electronics module and a display device and already employs advertising-based signaling as part of its communication framework, and Keenan teaches a specific, implementable cryptographic key exchange in which devices broadcast public keys within Bluetooth advertisement payloads transmitted on the advertising channels and independently compute a shared secret key using Diffie-Hellman. One of ordinary skill in the art would have recognized that Keenan’s advertisement-based public key exchange could be incorporated into the modified Burnette’s advertising phase, such that the sensor electronics module and the display device exchange public keys via advertisement messages and derive the shared secret key prior to or in parallel with subsequent secure communications. The benefit of the combination would have been enabling a shared secret key to be established using the primary invitation channels, thereby improving privacy and security for invitation-channel communications while reducing reliance on extended connection establishment overhead.
Regarding claim 8, the modified Burnette teaches that the encrypted analyte data is broadcast without establishing a connection with the display device (Burnette, ¶[0148], “the advertising beacons can be configured to include EGV trend data, for example, and a wireless communications session need not be established”, Burnette explains that advertising beacons may be configured to include analyte related data and that a wireless communications session need not be established, which corresponds to broadcasting the encrypted analyte data without establishing a connection with the display device; ¶[0151], “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol”, Burnette shows that encrypted analyte data may be directly communicated in advertising beacons without establishing a two-way communication protocol, which is conceptually and functionally consistent with broadcasting the encrypted analyte data without establishing a connection with the display device).
Regarding claim 9, Burnette teaches an analyte sensor system comprising: an analyte sensor; and a sensor electronics module electrically coupled to the analyte sensor and configured to perform an operation comprising: (Burnette, [0029], “a sensor electronics module physically connected to the continuous analyte sensor to receive the analyte concentration measurements and communicate them to display devices”, Burnette expressly teaches an analyte sensor system including a continuous analyte sensor and a sensor electronics module physically connected to the analyte sensor) obtaining analyte data from the analyte sensor (Burnette, [0029], “a sensor electronics module physically connected to the continuous analyte sensor to receive the analyte concentration measurements and communicate them to display devices”, Burnette expressly teaches the sensor electronics module receiving analyte concentration measurements from a continuous analyte sensor that is physically connected to the module; [0084], “CGM processor 506... can take a measurement(s) of one or more analyte values... using implantable continuous analyte sensor 312 and sensor measurement circuitry 310 or AFE 500”, Burnette further explains that the sensor electronics module actively takes analyte measurements via the coupled analyte sensor and associated measurement circuitry); and broadcasting the encrypted analyte data over the one or more primary invitation channels (Burnette, [0151], “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two way communication protocol”, Burnette shows broadcasting encrypted analyte data in advertising beacons, which are broadcast signals usable to communicate data without first establishing a two way protocol).
Also regarding claim 9, Burnette does not fully teach establishing a secret key with a first display device over one or more primary invitation channels and encrypting the analyte data using the secret key. Rather, Burnette teaches broadcasting “first advertising beacons 700 (also referred as advertisement signals 412 in FIG. 4)” (Burnette, [0099]) and that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two way communication protocol” (Burnette, [0151]). Burnette further teaches a bonding exchange context with a display device, stating that the whitelist may be populated with “a Generic Access Profile (GAP) Address or an Identity Resolving Key (IRK) entry upon a display device... sending its configuration during a bonding exchange when a wireless connection is being established” (Burnette, [0097]). However, Burnette does not expressly teach that the encryption uses a secret key established with the first display device over the primary invitation channel(s), nor does Burnette expressly teach encrypting the analyte data using such an established secret key.
Mandapaka teaches establishing a shared secret key, namely an application key, between an analyte sensor system and a display device and using that shared key to encrypt analyte data for transmission. Mandapaka discloses that “the information related to authentication includes an application key” and that the application key may be used to encrypt analyte data, stating that “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710, and display device 710 may use the application key to decrypt the received analyte data” (Mandapaka, [0008]; [0354]). Mandapaka further teaches that encrypted analyte values may be transmitted using invitation type signaling, disclosing that “at least a portion of the encrypted analyte value is transmitted to the display device in one or more advertisement messages transmitted by the analyte sensor system” (Mandapaka, [0010]). In context, Mandapaka’s application key functions as a shared secret key established between the analyte sensor system and the display device and is used to encrypt analyte data that is transmitted via advertisement messages.
Keenan teaches establishing a shared secret key via Bluetooth advertising channels, stating that “a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1). Keenan further teaches generating a shared secret key using Diffie Hellman, where “This shared secret key was generated by using the Diffie Hellman key exchange using Curve 25519” and “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” and “each device could generate a shared secret unique key” (Keenan, p. 3-4, Sec. 2.1.1). One of ordinary skill in the art would have used Keenan’s Diffie Hellman derived shared secret key as the application key of Mandapaka for encrypting analyte data, and would have applied that encryption to the analyte data placed in Burnette’s advertising beacons.
It would have been prima facie obvious before the effective filing date of the claimed invention to modify Burnette in view of Mandapaka and Keenan to establish a secret key with a first display device over one or more primary invitation channels and to encrypt the analyte data using the secret key. It would have been possible to combine the teachings of Burnette, Mandapaka, and Keenan because Burnette already employs Bluetooth advertising beacons as invitation signaling for communicating analyte data to display devices, Keenan teaches performing a cryptographic key exchange by broadcasting public keys via those same Bluetooth advertising channels and generating a shared secret key using Diffie Hellman, and Mandapaka teaches using a shared application key between an analyte sensor system and a display device to encrypt analyte data that is transmitted via advertisement messages. One of ordinary skill in the art would have understood that Keenan’s advertising channel Diffie Hellman exchange could be used during Burnette’s advertising based invitation phase to establish a shared secret key with a first display device, and that Mandapaka’s application key based encryption could then be applied to encrypt analyte data prior to broadcasting it in Burnette’s advertising beacons. The benefit of the combination would have been enabling Burnette’s encrypted advertising beacon analyte communications to use a shared secret established over the advertising or invitation channels themselves, improving privacy and security for broadcast analyte data communications while maintaining low power operation and avoiding the overhead of connection establishment when transmitting analyte data.
Also regarding claim 9, the modified Burnette does not fully teach wherein the encrypted data broadcast over the one or more primary invitation channels is received, by a second display device, and transmitted from the second display device to a server over a first secure channel established between the second display device and the server, wherein the encrypted data transmitted to the server is transmitted by the server to the first display device over a second secure channel established between the first display device and the server, and wherein the encrypted data transmitted by the server is received by the first display device, decrypted, by the first display device, using the secret key, and displayed, by the first display device. In particular, Burnette teaches broadcasting encrypted analyte data in advertising beacons to display devices and teaches that sensor information may be transmitted from one display device to another display device, and also teaches that “data transmission of sensor information can be effectuated directly from display device 120c to a second display device, e.g., display device 120b” (Burnette, [0007]-[0008], [0151]). Mandapaka teaches that an application key shared between the analyte sensor system and a display device may be used by the analyte sensor system to encrypt analyte data for transmission to the display device, and that the display device may use the application key to decrypt the received analyte data, including encrypted analyte values transmitted in advertisement messages (Mandapaka, [0354], [0378]-[0382]). Keenan teaches that Bluetooth devices can broadcast on the three advertising channels and can exchange public keys using Bluetooth advertisements to generate a shared secret key (Keenan, p. 3-4, Sec. 2.1.1). Thus, Burnette in view of Mandapaka and Keenan teaches or suggests encrypted analyte data broadcast over primary invitation channels, receipt by display devices, and decryption of encrypted analyte data by an authorized display device using a shared secret key. However, Burnette, Mandapaka, and Keenan do not fully teach that a second display device that receives the encrypted broadcast transmits that encrypted data to a server over a first secure channel, that the server transmits the encrypted data to the first display device over a second secure channel, and that the first display device decrypts the server relayed encrypted data using the secret key and displays the decrypted analyte data.
Mensinger teaches a continuous glucose monitoring distributed architecture in which displays receive glucose data from a continuous glucose sensor unit and forward the glucose data to a cloud computing architecture. Mensinger teaches that displays 104a-c receive data relating to glucose levels from continuous glucose sensor units 100a-c at predetermined time intervals, and that the displays present glucose readings over time and display the actual current glucose value (Mensinger, [0050]). Mensinger further teaches that the displays 104a-e or continuous glucose sensor units 100a-c transmit data to the distributed cloud computing architecture 106, which organizes, stores, and provides access to the data by other computers, applications, and third parties (Mensinger, [0054]). Mensinger teaches that communications within the system can be encrypted and secured, such as HTTPS and SSL communications, and that patient data including all data posts from the displays can be encrypted and stored in a secure fashion by the cloud computing architecture 106 (Mensinger, [0055]). Thus, Mensinger teaches display to server secure channel communications in the same CGM context.
Mensinger further teaches using a display device as a pass through for encrypted data received from a continuous glucose monitor transmitter. Mensinger teaches that the transmitter in a continuous glucose monitor can encrypt all or a portion of data and pass it through the associated display 104 to the services server 300, and that the display 104 does not have a decryption key for the encrypted bulk data and therefore acts simply as a pass through for encrypted bulk data (Mensinger, [0072]). Mensinger further teaches that the transmitter sends an encrypted message to a display, such as a smartphone or dedicated receiver, which sends the encrypted message on to the services server, and that the display acts as a pass through without the ability to decrypt all of the data (Mensinger, [0092]). Mensinger therefore teaches the use of a display device that receives encrypted data from a CGM transmitter and forwards the encrypted data to a server without decrypting all of the encrypted data.
Mensinger further teaches server distribution of glucose data to other display devices. Mensinger teaches that the cloud infrastructure can forward a subset of data relating to glucose levels to a second display device, the subset including current and past glucose levels (Mensinger, [0173]). Mensinger also teaches a cloud server architecture having a plurality of servers that receives data from a plurality of display devices, and a plurality of remote monitor display devices that receive data from one of the plurality of servers, where the data sent to each remote monitor display device depends upon the data type and the display device that transmitted the data to the server (Mensinger, [0186]). Thus, Mensinger teaches the use of server side distribution of glucose data received from display devices to other display devices. Mensinger does not expressly teach that the server relayed encrypted data remains encrypted until decryption by the first display device using the sensor to display secret key.
Klinkner teaches an end to end encrypted relay architecture in which information associated with a short range broadcast is detected by an intermediate mobile device, encrypted data is relayed through a server, and only the owner or authorized device holding the corresponding key receives, decrypts, and displays the protected data. Klinkner teaches that a tracking device can provide a hashed identifier to a mobile device, for instance within an advertisement packet, that the mobile device can receive a public key from an entity, determine a location, encrypt the location with the public key, and provide the hashed identifier and encrypted location to the entity, which provides the encrypted location to an owner of the tracking device for decryption using a private key corresponding to the public key (Klinkner, Abstract). Klinkner further teaches that the owner device receives encrypted location data from the entity and decrypts the encrypted location data using a private key, and that the decrypted data can then be displayed to the user (Klinkner, [0130]-[0132]). Klinkner expressly teaches the reason for this architecture, stating that encrypting the location data at the mobile device protects the data from the point of access until the encrypted data is received by the owner device, and that where the intermediate mobile device and entities do not have access to the private key, “no system or entity between the mobile device 102 and the owner device 1224 is able to decrypt the encrypted location data 1220,” thereby enabling end to end protection (Klinkner, [0133]).
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Mensinger and Klinkner such that the encrypted analyte data broadcast over the one or more primary invitation channels is received by a second display device, transmitted from the second display device to a server over a first secure channel, transmitted by the server to the first display device over a second secure channel, and then received, decrypted using the secret key, and displayed by the first display device. It would have been possible to combine the teachings because Burnette already teaches a CGM system having multiple display devices and advertising beacons containing encrypted analyte data; Mandapaka teaches use of a shared secret key to encrypt analyte data and allow a display device to decrypt the encrypted analyte data; Keenan teaches establishing the shared secret by exchanging public keys over advertising channels; Mensinger teaches in the same CGM field that displays receiving glucose data can forward data to cloud infrastructure over secure communications and can act as pass through devices for encrypted CGM data; and Klinkner teaches preserving end to end protection through an intermediate mobile device and server so that only the authorized key holding device can decrypt the protected data.
One of ordinary skill in the art would have been motivated to apply Mensinger’s CGM cloud relay architecture to Burnette’s encrypted advertising beacon analyte data so that glucose data received by one display device could be made available to another authorized display device through cloud infrastructure. One of ordinary skill in the art would have further been motivated by Klinkner’s end to end protection teaching to preserve the encrypted form of the analyte data through the second display device and server so that intermediate devices and server side components need not decrypt the patient’s analyte data. Klinkner expressly teaches that no system or entity between the detecting mobile device and the owner device can decrypt the protected data where those intermediaries lack the corresponding key (Klinkner, [0133]). The predictable result would have been using known CGM cloud relay infrastructure to deliver Burnette/Mandapaka/Keenan’s encrypted analyte broadcast to the authorized first display device while maintaining privacy by allowing decryption and display at the first display device using the shared secret key.
Regarding claim 10, the modified Burnette does not fully teach establishing the secret key comprises participating in a cryptographic key exchange with the display device over the one or more primary invitation channels. Rather, the modified Burnette teaches establishing secure communications with a display device in a Bluetooth Low Energy environment and exchanging device-related information during association or bonding procedures, including that a whitelist entry may be populated when a display device sends its configuration information “during a bonding exchange when a wireless connection is being established” (Burnette, ¶[0097]). However, the modified Burnette does not teach that establishing the secret key comprises participating in a cryptographic key exchange with the display device over the one or more primary invitation channels, i.e., over advertising or invitation signaling used prior to or independent of a connected communication session.
Keenan teaches performing a cryptographic key exchange over Bluetooth advertisements on the advertising channels. Keenan discloses that “In the Bluetooth Standard [10], a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1). Keenan further discloses that “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” (Keenan, p. 4, Sec. 2.1.1), and that “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519 [12–13]” (Keenan, p. 4, Sec. 2.1.1). In context, Keenan teaches that the devices participate in a cryptographic key exchange by broadcasting the public keys using Bluetooth advertisements over the advertising channels, and that the result of that key exchange is a shared secret key.
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Keenan to have establishing the secret key comprise participating in a cryptographic key exchange with the display device over the one or more primary invitation channels. It would have been possible to combine the teachings because the modified Burnette already operates using Bluetooth Low Energy communications between a sensor electronics module and a display device and already employs advertising-based signaling as part of its communication framework, and Keenan teaches a specific, implementable cryptographic key exchange in which devices broadcast public keys within Bluetooth advertisement payloads transmitted on the advertising channels and independently compute a shared secret key using Diffie-Hellman. One of ordinary skill in the art would have recognized that Keenan’s advertisement-based public key exchange could be incorporated into the modified Burnette’s advertising phase, such that the sensor electronics module and the display device exchange public keys via advertisement messages and derive the shared secret key prior to or in parallel with subsequent secure communications. The benefit of the combination would have been enabling a shared secret key to be established using the primary invitation channels, thereby improving privacy and security for invitation-channel communications while reducing reliance on extended connection establishment overhead.
Regarding claim 13, the modified Burnette teaches wherein the encrypted analyte data is broadcast without establishing a connection with the display device (Burnette, ¶[0148], “the advertising beacons can be configured to include EGV trend data, for example, and a wireless communications session need not be established”, Burnette explains that advertising beacons may be configured to include analyte related data and that a wireless communications session need not be established, which corresponds to broadcasting the encrypted analyte data without establishing a connection with the display device; ¶[0151], “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol”, Burnette shows that encrypted analyte data may be directly communicated in advertising beacons without establishing a two-way communication protocol, which is conceptually and functionally consistent with broadcasting the encrypted analyte data without establishing a connection with the display device).
Regarding claim 14, Burnette teaches a computer-implemented method for communicating analyte data performed by a first display device (Burnette, [0161]-[0163], “computing module 1000 may be one embodiment of one of display devices 120, sensor electronics module 106, etc.” and “might include, for example, one or more processors”, Burnette explains that the display device includes computing or processing capabilities; [0029], “a sensor electronics module physically connected to the continuous analyte sensor to receive the analyte concentration measurements and communicate them to display devices”, Burnette expressly teaches the analyte sensor system communicating analyte concentration measurements to display devices, which corresponds to operations performed by a display device in communicating analyte data).
Also regarding claim 14, Burnette does not fully teach establishing a secret key with a sensor electronics module of an analyte sensor system over one or more primary invitation channels and decrypting the encrypted analyte data using the secret key. Rather, Burnette teaches broadcasting “first advertising beacons 700 (also referred as advertisement signals 412 in FIG. 4)” (Burnette, [0099]) and that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, [0151]). Burnette further teaches a bonding exchange context with a display device, stating that the whitelist may be populated with “a Generic Access Profile (GAP) Address or an Identity Resolving Key (IRK) entry upon a display device... sending its configuration during a bonding exchange when a wireless connection is being established” (Burnette, [0097]). However, Burnette does not expressly teach that the first display device establishes a secret key with the sensor electronics module over the primary invitation channel(s), nor does Burnette expressly teach decrypting the encrypted analyte data using such an established secret key.
Mandapaka teaches establishing a shared secret key, namely an application key, between an analyte sensor system and a display device and using that shared key to encrypt and decrypt analyte data. Mandapaka discloses that “the information related to authentication includes an application key” and that the application key may be used to encrypt and decrypt analyte data, stating that “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710, and display device 710 may use the application key to decrypt the received analyte data” (Mandapaka, [0008]; [0354]). Mandapaka further teaches that encrypted analyte values may be transmitted using invitation type signaling, disclosing that “at least a portion of the encrypted analyte value is transmitted to the display device in one or more advertisement messages transmitted by the analyte sensor system” (Mandapaka, [0010]). In context, Mandapaka’s application key functions as a shared secret key established between the analyte sensor system and the display device and is used by the display device to decrypt encrypted analyte data.
Keenan teaches establishing a shared secret key via Bluetooth advertising channels, stating that “a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1). Keenan further teaches generating a shared secret key using Diffie-Hellman, where “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519” and “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” and “each device could generate a shared secret unique key” (Keenan, p. 3-4, Sec. 2.1.1). One of ordinary skill in the art would have used Keenan’s Diffie-Hellman derived shared secret key as the application key of Mandapaka for decrypting analyte data received by the display device.
It would have been prima facie obvious before the effective filing date of the claimed invention to modify Burnette in view of Mandapaka and Keenan to establish a secret key with a sensor electronics module of an analyte sensor system over one or more primary invitation channels and to decrypt the encrypted analyte data using the secret key. It would have been possible to combine the teachings of Burnette, Mandapaka, and Keenan because Burnette already employs Bluetooth advertising beacons as invitation signaling for communicating analyte data to display devices, Keenan teaches performing a cryptographic key exchange by broadcasting public keys via those same Bluetooth advertising channels and generating a shared secret key using Diffie-Hellman, and Mandapaka teaches using a shared application key between an analyte sensor system and a display device to decrypt encrypted analyte data transmitted via advertisement messages. One of ordinary skill in the art would have understood that Keenan’s advertising-channel Diffie-Hellman exchange could be used during Burnette’s advertising-based invitation phase to establish a shared secret key between the display device and the sensor electronics module, and that Mandapaka’s application-key-based decryption could then be applied by the display device to decrypt the encrypted analyte data. The benefit of the combination would have been enabling Burnette’s encrypted advertising-beacon analyte communications to use a shared secret established over the advertising or invitation channels themselves, improving privacy and security for broadcast analyte-data communications while maintaining low power operation and avoiding the overhead of connection establishment when transmitting analyte data.
Also regarding claim 14, the modified Burnette does not fully teach receiving encrypted analyte data from a server over a first secure channel established between the first display device and a server, wherein the encrypted data is received by the server from a second display device over a second secure channel established between the second display device and the server, and wherein the encrypted data is received by the second display device from a broadcast of the encrypted data by the sensor electronics module over the one or more primary invitation channels. In particular, Burnette teaches broadcasting encrypted analyte data in advertising beacons to display devices and teaches that sensor information may be transmitted from one display device to another display device, and also teaches that “data transmission of sensor information can be effectuated directly from display device 120c to a second display device, e.g., display device 120b” (Burnette, [0007]-[0008], [0151]). Mandapaka teaches that an application key shared between the analyte sensor system and a display device may be used by the display device to decrypt the received encrypted analyte data, including encrypted analyte values transmitted in advertisement messages (Mandapaka, [0354], [0378]-[0382]). Keenan teaches that Bluetooth devices can broadcast on the three advertising channels and can exchange public keys using Bluetooth advertisements to generate a shared secret key (Keenan, p. 3-4, Sec. 2.1.1). Thus, Burnette in view of Mandapaka and Keenan teaches or suggests encrypted analyte data broadcast over primary invitation channels, receipt by display devices, and decryption of encrypted analyte data by an authorized display device using a shared secret key. However, Burnette, Mandapaka, and Keenan do not fully teach that the encrypted analyte data is received by the first display device from a server over a first secure channel between the first display device and the server, that the server receives the encrypted data from a second display device over a second secure channel between the second display device and the server, and that the encrypted data received by the second display device was received from a broadcast by the sensor electronics module over the one or more primary invitation channels.
Mensinger teaches a continuous glucose monitoring distributed architecture in which displays receive glucose data from a continuous glucose sensor unit and forward the glucose data to a cloud computing architecture. Mensinger teaches that displays 104a-c receive data relating to glucose levels from continuous glucose sensor units 100a-c at predetermined time intervals, and that the displays present glucose readings over time and display the actual current glucose value (Mensinger, [0050]). Mensinger further teaches that the displays 104a-e or continuous glucose sensor units 100a-c transmit data to the distributed cloud computing architecture 106, which organizes, stores, and provides access to the data by other computers, applications, and third parties (Mensinger, [0054]). Mensinger teaches that communications within the system can be encrypted and secured, such as HTTPS and SSL communications, and that patient data including all data posts from the displays can be encrypted and stored in a secure fashion by the cloud computing architecture 106 (Mensinger, [0055]). Thus, Mensinger teaches secure communications between display devices and a server in the same CGM context, which corresponds to the claimed first secure channel between the first display device and the server and the claimed second secure channel between the second display device and the server.
Mensinger further teaches using a display device as a pass-through for encrypted data received from a continuous glucose monitor transmitter. Mensinger teaches that the transmitter in a continuous glucose monitor can encrypt all or a portion of data and pass it through the associated display 104 to the services server 300, and that the display 104 does not have a decryption key for the encrypted bulk data and therefore acts simply as a pass-through for encrypted bulk data (Mensinger, [0072]). Mensinger further teaches that the transmitter sends an encrypted message to a display, such as a smartphone or dedicated receiver, which sends the encrypted message on to the services server, and that the display acts as a pass-through without the ability to decrypt all of the data (Mensinger, [0092]). Mensinger therefore teaches the use of a display device that receives encrypted data from a CGM transmitter and forwards the encrypted data to a server without decrypting all of the encrypted data, which corresponds to the second display device receiving encrypted data broadcast by the sensor electronics module and transmitting the encrypted data to the server over the second secure channel.
Mensinger further teaches server distribution of glucose data to other display devices. Mensinger teaches that the cloud infrastructure can forward a subset of data relating to glucose levels to a second display device, the subset including current and past glucose levels (Mensinger, [0173]). Mensinger also teaches a cloud server architecture having a plurality of servers that receives data from a plurality of display devices, and a plurality of remote monitor display devices that receive data from one of the plurality of servers, where the data sent to each remote monitor display device depends upon the data type and the display device that transmitted the data to the server (Mensinger, [0186]). Thus, Mensinger teaches the use of server-side distribution of glucose data received from display devices to other display devices, which corresponds to the first display device receiving encrypted analyte data from the server over the first secure channel.
Mensinger does not expressly teach that the server-distributed encrypted data remains encrypted until decryption by the first display device using the sensor-to-display secret key.
Klinkner teaches an end to end encrypted relay architecture in which information associated with a short range broadcast is detected by an intermediate mobile device, encrypted data is relayed through a server, and only the owner or authorized device holding the corresponding key receives and decrypts the protected data. Klinkner teaches that a tracking device can provide a hashed identifier to a mobile device, for instance within an advertisement packet, that the mobile device can receive a public key from an entity, determine a location, encrypt the location with the public key, and provide the hashed identifier and encrypted location to the entity, which provides the encrypted location to an owner of the tracking device for decryption using a private key corresponding to the public key (Klinkner, Abstract). Klinkner further teaches that the owner device receives encrypted location data from the entity and decrypts the encrypted location data using a private key, and that the decrypted data can then be displayed to the user (Klinkner, [0130]-[0132]). Klinkner expressly teaches the reason for this architecture, stating that encrypting the location data at the mobile device protects the data from the point of access until the encrypted data is received by the owner device, and that where the intermediate mobile device and entities do not have access to the private key, “no system or entity between the mobile device 102 and the owner device 1224 is able to decrypt the encrypted location data 1220,” thereby enabling end to end protection (Klinkner, [0133]).
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette in view of Mensinger and Klinkner such that the encrypted analyte data is received by the first display device from a server over a first secure channel between the first display device and the server, where the encrypted data is received by the server from a second display device over a second secure channel between the second display device and the server, and where the encrypted data was received by the second display device from a broadcast of the encrypted data by the sensor electronics module over the one or more primary invitation channels. It would have been possible to combine the teachings because Burnette already teaches a CGM system having multiple display devices and advertising beacons containing encrypted analyte data; Mandapaka teaches use of a shared secret key to allow a display device to decrypt encrypted analyte data; Keenan teaches establishing the shared secret by exchanging public keys over advertising channels; Mensinger teaches in the same CGM field that displays receiving glucose data can forward data to cloud infrastructure over secure communications and that the cloud infrastructure can distribute glucose data to display devices over secure communications; and Klinkner teaches preserving end to end protection through an intermediate mobile device and server so that only the authorized key-holding device can decrypt the protected data.
One of ordinary skill in the art would have been motivated to apply Mensinger’s CGM cloud relay architecture to Burnette’s encrypted advertising-beacon analyte data so that glucose data received by a second display device could be made available to an authorized first display device through cloud infrastructure. One of ordinary skill in the art would have further been motivated by Klinkner’s end to end protection teaching to preserve the encrypted form of the analyte data through the second display device and server so that intermediate devices and server-side components need not decrypt the patient’s analyte data. Klinkner expressly teaches that no system or entity between the detecting mobile device and the owner device can decrypt the protected data where those intermediaries lack the corresponding key (Klinkner, [0133]). The predictable result would have been using known CGM cloud relay infrastructure to deliver Burnette/Mandapaka/Keenan’s encrypted analyte data to the authorized first display device over the first secure channel, after receipt by the server from the second display device over the second secure channel, while maintaining privacy by allowing decryption at the first display device using the shared secret key.
Regarding claim 15, Burnette teaches that further comprising displaying the decrypted analyte data (Burnette, ¶[0044], “display devices 120 are configured for displaying, alarming, and/or basing medicament delivery on the sensor information that has been transmitted by the sensor electronics module 106”, Burnette explains that the display device displays sensor information communicated from the sensor electronics module, which corresponds to displaying the decrypted analyte data; ¶[0045], “one of the plurality of display devices 120 may be a custom display device 120 a specially designed for displaying certain types of displayable sensor information associated with analyte values received from the sensor electronics module 106”, Burnette explains that the display device is specially designed to display sensor information associated with analyte values received from the sensor electronics module, which corresponds to displaying the decrypted analyte data).
Regarding claim 17, the modified Burnette does not fully teach generating the encrypted analyte data by encrypting data using the secret key; and broadcasting the encrypted data over the one or more primary invitation channels. Rather, the modified Burnette teaches that advertising beacons may be used for invitation-channel communications, including that “first advertising beacons 700 (also referred as advertisement signals 412 in FIG. 4)” are broadcast (Burnette, [0099]) and that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, [0151]). However, it does not expressly teach that the first display device generates encrypted analyte data by encrypting data using the secret key and broadcasts the encrypted data over the one or more primary invitation channels.
Mandapaka teaches that a display device can use the application key to encrypt information sent to the analyte sensor system. Mandapaka teaches that, after receiving the application key, the display device may use the key to authenticate or communicate with the analyte sensor system and to decrypt encrypted information received from the analyte sensor system “and also encrypt information being sent thereto” (Mandapaka, [0357]). Mandapaka further teaches that the application key can be used for encryption and decryption of analyte data sent by the analyte sensor system, that the application key may be shared between the analyte sensor system and display device, that the encryption method applied using the application key may be AES-128 or a proprietary encryption method, and that the encryption method may be run on display device 710, including on an application running on display device 710 (Mandapaka, [0357]-[0359]). Thus, Mandapaka teaches that the shared application key can be used by the display device to encrypt information being sent to the analyte sensor system, and supports display-side encryption using the same shared key framework.
Keenan teaches establishing the shared secret key used for encryption via Bluetooth advertising channels. Keenan discloses that “a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1), that “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” (Keenan, p. 4, Sec. 2.1.1), and that “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519” (Keenan, p. 4, Sec. 2.1.1). In context, Keenan teaches that each participating device, including the display-side device, can broadcast key exchange information using Bluetooth advertisements and generate a shared secret key.
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Mandapaka and Keenan to have the first display device generate encrypted analyte data by encrypting data using the secret key and broadcast the encrypted data over the one or more primary invitation channels. It would have been possible to combine the teachings because the modified Burnette system already includes a first display device and sensor electronics module that establish a shared secret key over primary invitation channels, the first display device receives and decrypts encrypted analyte data using the secret key as discussed above regarding claim 14, Mandapaka teaches that the display device can use the application key to encrypt information being sent to the analyte sensor system, and Keenan teaches that participating devices can broadcast information over Bluetooth advertising channels and generate a shared secret key using those advertising-channel broadcasts. One of ordinary skill in the art would have understood that, after the first display device and sensor electronics module establish the shared secret key, the first display device could use that same key to encrypt data and broadcast the encrypted data over the same primary invitation channels used by the sensor electronics module. The benefit of the combination would have been enabling secure, low-power, connectionless transmission of encrypted data from the first display device to the analyte sensor system using the same shared-key and invitation-channel communication framework already used for secure analyte-data communications.
Regarding claim 21, the modified Burnette does not fully teach that establishing the secret key comprises participating in a cryptographic key exchange with the sensor electronics module over the one or more primary invitation channels. Rather, Burnette teaches a display device and a sensor electronics module communicating in a BLE environment where device association information may be exchanged, including that the whitelist may be populated with “a Generic Access Profile (GAP) Address or an Identity Resolving Key (IRK) entry upon a display device … sending its configuration during a bonding exchange when a wireless connection is being established” (Burnette, ¶[0097]). However, it does not teach that establishing the secret key comprises participating in a cryptographic key exchange with the sensor electronics module over the one or more primary invitation channels.
Keenan teaches performing a cryptographic key exchange over Bluetooth advertisements on the advertising channels. Keenan discloses that “In the Bluetooth Standard [10], a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1). Keenan further discloses that “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” (Keenan, p. 4, Sec. 2.1.1), and that “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519 [12–13]” (Keenan, p. 4, Sec. 2.1.1). In context, Keenan teaches that the devices participate in a cryptographic key exchange by broadcasting the public keys using Bluetooth advertisements over the advertising channels, and that the result of that key exchange is a shared secret key.
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Keenan to have establishing the secret key comprise participating in a cryptographic key exchange with the sensor electronics module over the one or more primary invitation channels. It would have been possible to combine the teachings because the modified Burnette already operates using Bluetooth Low Energy communications between a display device and a sensor electronics module and already employs advertising-based signaling as the primary invitation channels, and Keenan teaches a specific, implementable cryptographic key exchange in which devices broadcast public keys within Bluetooth advertisement payloads transmitted on the advertising channels and independently compute a shared secret key using Diffie-Hellman. One of ordinary skill in the art would have recognized that Keenan’s advertisement-based public key exchange could be incorporated into the modified Burnette’s advertising phase, such that the display device and the sensor electronics module exchange public keys via advertisement messages and derive the shared secret key prior to or in parallel with subsequent secure communications. The benefit of the combination would have been enabling a shared secret key to be established using the primary invitation channels, thereby improving privacy and security for invitation-channel communications while reducing reliance on extended connection establishment overhead.
Regarding claim 23, claim 23 depends from claim 14 and further recites wherein the encrypted analyte data is received from the sensor electronics module without establishing a connection with the sensor electronics module. Consistent with claim 14, this limitation is interpreted as further specifying that the encrypted data received by the second display device from the broadcast of the encrypted data by the sensor electronics module over the one or more primary invitation channels is received without establishing a connection with the sensor electronics module. The modified Burnette teaches this limitation because Burnette teaches that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, [0151]). Burnette further teaches that advertising beacons can include analyte-related data such as EGV trend data and that “a wireless communications session need not be established” (Burnette, [0148]). Thus, Burnette teaches receiving encrypted analyte data from the sensor electronics module through advertising-beacon communications without establishing a connection or wireless communication session with the sensor electronics module.
Claims 3-4, 11-12, 18, 22, and 35-36 are rejected under 35 U.S.C. 103 as being unpatentable over Burnette et al. (US-20170181628-A1), hereinafter referred to as Burnette, in view of Mandapaka et al. (US-20180027104-A1), hereinafter referred to as Mandapaka, in view of Keenan et al. (Keenan, Kathryn E. et al., “Development and Evaluation of Bluetooth Low-Energy Device for Electronic Encounter Metrics,” Journal of Research of the National Institute of Standards and Technology 126 (2021)), hereinafter referred to as Keenan, in view of Mensinger et al. (US-20160335409-A1), hereinafter referred to as Mensinger, and in view of Klinkner et al. (US-20210092599-A1), hereinafter referred to as Klinkner, in view of Loh et al. (US-20040198223-A1), hereinafter referred to as Loh.
The modified Burnette teaches claim 1 as described above.
The modified Burnette teaches claim 9 as described above.
Regarding claim 3, the modified Burnette does not fully teach that participating in the cryptographic key exchange comprises executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module. Rather, the modified Burnette (as modified for claim 1 and claim 2) teaches participating in a cryptographic key exchange with a display device over one or more primary invitation channels, but does not teach that the cryptographic key exchange comprises executing a cryptographic key exchange algorithm specifically at an application layer of a communication protocol stack at the sensor electronics module.
Keenan teaches executing a cryptographic key exchange algorithm to generate a shared secret key, specifically disclosing that a “shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519” (Keenan, p. 3-4, Sec. 2.1.1, “shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519”).
Loh does not teach executing a cryptographic key exchange algorithm; rather, Loh is relied upon solely to establish that Bluetooth communications are implemented using a protocol stack that includes a software-implemented application layer above L2CAP, within which higher-level applications may be executed (Loh, ¶[0050]: “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21-24, and higher typically Software implemented layers including an application layer 29”) and that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” (Loh, ¶[0051]).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Keenan and Loh to have participating in the cryptographic key exchange comprise executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module. It would have been possible to combine the teachings because the modified Burnette already relies on invitation-channel communications between the sensor electronics module and a display device (as modified for claim 1 and claim 2), Keenan provides an explicit Diffie-Hellman key exchange technique for generating a shared secret key between devices, and Loh establishes that Bluetooth communications are implemented using a protocol stack in which higher-level software functionality resides in an application layer that interacts with L2CAP for transmitting and receiving data, such that the sensor electronics module could execute Keenan’s key exchange algorithm within the application-layer software of its Bluetooth protocol stack while using the existing invitation-channel messaging path to exchange the key material. The benefit of the combination would have been enabling the sensor electronics module to implement the key exchange as application-layer software within the protocol stack (rather than as a lower-layer function), improving design flexibility for security updates while maintaining Bluetooth stack interoperability and secure communications
Regarding claim 4, the modified Burnette does not fully teach that the analyte data is encrypted at an application layer of a communication protocol stack at the sensor electronics module. Rather, the modified Burnette (as modified for claim 1) teaches encrypting analyte data using a secret key, but does not teach that the analyte data is encrypted specifically at an application layer of a communication protocol stack at the sensor electronics module.
Mandapaka teaches application-level encryption in an analyte sensor system context, including that “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710” (Mandapaka, ¶[0354], “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710”, Mandapaka explains that the analyte sensor system encrypts analyte data using an application key) and that “the application key may be generated at a software / application level of analyte sensor system 708 and / or display device 710” (Mandapaka, ¶[0355], “the application key may be generated at a software / application level of analyte sensor system 708 and / or display device 710”, Mandapaka shows that the encryption key is generated at a software or application level of the analyte sensor system). In context, Mandapaka’s disclosure that the application key is generated at a software / application level and is used by the analyte sensor system to encrypt analyte data indicates that the encryption operation is performed as part of application-level processing, rather than as a lower-layer communication function.
Loh teaches that Bluetooth communications are implemented using a protocol stack that includes a software-implemented application layer above L2CAP, including that “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21-24, and higher typically Software implemented layers including an application layer 29” (Loh, ¶[0050]) and that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” showing that higher-level applications in the application layer interact with L2CAP to transmit and receive data (Loh, ¶[0051]).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Mandapaka and Loh to have the analyte data encrypted at an application layer of a communication protocol stack at the sensor electronics module. It would have been possible to combine the teachings because the modified Burnette already transmits analyte information from the sensor electronics module to a display device over invitation channels and already uses cryptography to protect transmitted analyte information, Mandapaka provides a directly applicable analyte-sensor context where an application key generated at a software or application level of the analyte sensor system is used to encrypt analyte data for transmission to a display device, and Loh shows that Bluetooth communications employ a protocol stack in which higher-level software applications reside in an application layer above L2CAP and transmit and receive data via that stack, such that implementing Mandapaka’s application-level encryption within the application-layer software of the sensor electronics module’s Bluetooth protocol stack would have been a feasible modification to the modified Burnette system. The benefit of the combination would have been implementing analyte-data encryption at the application layer for improved flexibility and updatability of security functions while maintaining interoperability with the underlying Bluetooth communication stack
Regarding claim 11, the modified Burnette does not fully teach that participating in the cryptographic key exchange comprises executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module. Rather, the modified Burnette (as modified for claim 9 and claim 10) teaches participating in a cryptographic key exchange with a display device over one or more primary invitation channels, but does not teach that the cryptographic key exchange comprises executing a cryptographic key exchange algorithm specifically at an application layer of a communication protocol stack at the sensor electronics module.
Keenan teaches executing a cryptographic key exchange algorithm to generate a shared secret key, specifically disclosing that a “shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519” (Keenan, p. 3-4, Sec. 2.1.1, “shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519”).
Loh does not teach executing a cryptographic key exchange algorithm; rather, Loh is relied upon solely to establish that Bluetooth communications are implemented using a protocol stack that includes a software-implemented application layer above L2CAP, within which higher-level applications may be executed (Loh, ¶[0050]: “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21-24, and higher typically Software implemented layers including an application layer 29”) and that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” (Loh, ¶[0051]).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Keenan and Loh to have participating in the cryptographic key exchange comprise executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module. It would have been possible to combine the teachings because the modified Burnette already relies on invitation-channel communications between the sensor electronics module and a display device (as modified for claim 9 and claim 10), Keenan provides an explicit Diffie-Hellman key exchange technique for generating a shared secret key between devices, and Loh establishes that Bluetooth communications are implemented using a protocol stack in which higher-level software functionality resides in an application layer that interacts with L2CAP for transmitting and receiving data, such that the sensor electronics module could execute Keenan’s key exchange algorithm within the application-layer software of its Bluetooth protocol stack while using the existing invitation-channel messaging path to exchange the key material. The benefit of the combination would have been enabling the sensor electronics module to implement the key exchange as application-layer software within the protocol stack (rather than as a lower-layer function), improving design flexibility for security updates while maintaining Bluetooth stack interoperability and secure communications.
Regarding claim 12, the modified Burnette does not fully teach that the analyte data is encrypted at an application layer of a communication protocol stack at the sensor electronics module. Rather, the modified Burnette teaches encrypting analyte data for broadcast and transmission, including that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values” (Burnette, ¶[0151]), but does not teach that the encryption of the analyte data is performed specifically at an application layer of a communication protocol stack at the sensor electronics module.
Loh teaches that Bluetooth communications are implemented using a protocol stack that includes an application layer implemented in software above lower protocol layers, disclosing that “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21–24, and higher typically Software implemented layers including an application layer 29” (Loh, ¶[0050]) and that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” (Loh, ¶[0051]).
Mandapaka teaches encrypting analyte data using an application-level key shared between an analyte sensor system and a display device, disclosing that “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710” (Mandapaka, ¶[0354]). In context, Mandapaka teaches that encryption of analyte data is performed by application-level functionality of the analyte sensor system rather than by lower-layer radio hardware.
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Mandapaka and Loh to have the analyte data encrypted at an application layer of a communication protocol stack at the sensor electronics module. It would have been possible to combine the teachings because the modified Burnette already encrypts analyte data for broadcast, Mandapaka teaches performing analyte-data encryption using an application key at the system level, and Loh establishes that Bluetooth protocol stacks implement higher-level processing, including data handling and security functions, in an application layer above L2CAP. One of ordinary skill in the art would have understood that implementing Mandapaka’s analyte-data encryption within the application-layer software of the modified Burnette’s Bluetooth protocol stack would have been a routine design choice. The benefit of the combination would have been enabling flexible, software-based encryption of analyte data at the application layer while maintaining compatibility with the underlying Bluetooth communication stack and improving maintainability and upgradability of security functions.
Regarding claim 18, the modified Burnette does not fully teach wherein the data is encrypted at an application layer of a communication protocol stack at the display device. As discussed above regarding claim 17, the modified Burnette teaches advertising-beacon communications over primary invitation channels, and Mandapaka teaches that a display device can use the shared application key to encrypt information being sent to the analyte sensor system. However, it does not expressly teach that the data encrypted by the first display device is encrypted at an application layer of a communication protocol stack at the first display device.
Mandapaka teaches application-level encryption at a display device. Mandapaka teaches that “the application key may be generated at a software/application level of analyte sensor system 708 and/or display device 710” (Mandapaka, [0355]). Mandapaka further teaches that the encryption method using the application key may be run on display device 710, including in some cases on an application running on display device 710 (Mandapaka, [0359]). Thus, Mandapaka teaches that encryption using the application key may be performed by application-level software on the display device.
Loh teaches that Bluetooth communications are implemented using a communication protocol stack having an application layer above lower communication layers. Loh teaches that “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21-24, and higher typically Software implemented layers including an application layer 29” (Loh, [0050]). Loh further teaches that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” (Loh, [0051]). Thus, Loh teaches an application layer of a communication protocol stack at a Bluetooth-capable device, where higher-level applications interact with lower protocol layers to transmit and receive data.
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Loh such that the data encrypted by the first display device is encrypted at an application layer of a communication protocol stack at the first display device. It would have been possible to combine the teachings because the modified Burnette system already uses Bluetooth advertising-beacon communications between the sensor electronics module and display devices, Mandapaka teaches encryption using an application key at software or application level on the display device, and Loh teaches a Bluetooth communication protocol stack having an application layer whose applications interact with lower layers to transmit and receive data. One of ordinary skill in the art would have understood that Mandapaka’s display-device encryption using the application key could be implemented within the application layer of the display device’s communication protocol stack as taught by Loh. The benefit of the combination would have been providing flexible, software-implemented, application-layer encryption at the first display device while maintaining compatibility with the lower-layer Bluetooth communication stack used for transmitting the encrypted data over the primary invitation channels.
Regarding claim 22, the modified Burnette does not fully teach that participating in the cryptographic key exchange comprises executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the display device. Rather, the modified Burnette, as modified for claim 21, teaches participating in a cryptographic key exchange with the sensor electronics module over the one or more primary invitation channels, but does not teach that the cryptographic key exchange comprises executing a cryptographic key exchange algorithm specifically at an application layer of a communication protocol stack at the display device.
Keenan teaches executing a cryptographic key exchange algorithm to generate a shared secret key, disclosing that “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519 [12–13]” (Keenan, p. 3-4, Sec. 2.1.1).
Loh teaches that Bluetooth communications are implemented using a protocol stack that includes a software-implemented application layer above L2CAP, disclosing that “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21-24, and higher typically Software implemented layers including an application layer 29” (Loh, ¶[0050]) and that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” (Loh, ¶[0051]).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Keenan and Loh to have participating in the cryptographic key exchange comprise executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the display device. It would have been possible to combine the teachings because the modified Burnette already relies on invitation-channel communications between the display device and the sensor electronics module and has been modified to participate in a cryptographic key exchange over those invitation channels, Keenan provides an explicit Diffie-Hellman key exchange technique for generating a shared secret key between devices, and Loh establishes that Bluetooth communications are implemented using a protocol stack in which higher-level software functionality resides in an application layer that interacts with L2CAP for transmitting and receiving data, such that the display device could execute Keenan’s key exchange algorithm within the application-layer software of its Bluetooth protocol stack while using the existing invitation-channel messaging path to exchange the key material. The benefit of the combination would have been enabling the display device to implement the key exchange as application-layer software within the protocol stack, improving design flexibility for security updates while maintaining Bluetooth stack interoperability and secure communications.
Regarding claim 35, Burnette teaches a computer-implemented method for communicating analyte data performed by a sensor electronics module of an analyte sensor system (Burnette, [0098], “CGM processor 506 may then transmit raw sensor data 504 from AFE 500, apply one or more algorithms to create/calculate an EGV value, and store that EGV value in memory, e.g., flash database”, Burnette describes processor-executed operations performed by the CGM electronics/module in an analyte sensor system, i.e., a computer implemented method performed by the sensor electronics module) comprising: obtaining analyte data from an analyte sensor electrically coupled to the sensor electronics module (Burnette, [0029], “a sensor electronics module physically connected to the continuous analyte sensor to receive the analyte concentration measurements and communicate them to display devices”, Burnette expressly teaches the sensor electronics module receiving analyte concentration measurements from a continuous analyte sensor that is physically connected to the module; [0084], “CGM processor 506... can take a measurement(s) of one or more analyte values... using implantable continuous analyte sensor 312 and sensor measurement circuitry 310 or AFE 500”, Burnette further explains that the sensor electronics module actively takes analyte measurements via the coupled analyte sensor and associated measurement circuitry); and transmitting the encrypted analyte data (Burnette, [0151], “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol”, Burnette shows transmitting encrypted analyte data in advertising beacons).
Also regarding claim 35, Burnette does not fully teach establishing a secret key with a first display device, based on executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module and encrypting the analyte data using the secret key. Rather, Burnette teaches broadcasting “first advertising beacons 700 (also referred as advertisement signals 412 in FIG. 4)” (Burnette, [0099]) and that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, [0151]). Burnette further teaches a bonding exchange context with a display device, stating that the whitelist may be populated with “a Generic Access Profile (GAP) Address or an Identity Resolving Key (IRK) entry upon a display device... sending its configuration during a bonding exchange when a wireless connection is being established” (Burnette, [0097]). However, Burnette does not expressly teach that the encryption uses a secret key established with the first display device based on executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module, nor does Burnette expressly teach encrypting the analyte data using such an established secret key.
Mandapaka teaches establishing a shared secret key, namely an application key, between an analyte sensor system and a display device and using that shared key to encrypt analyte data for transmission. Mandapaka discloses that “the information related to authentication includes an application key” and that the application key may be used to encrypt analyte data, stating that “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710, and display device 710 may use the application key to decrypt the received analyte data” (Mandapaka, [0008]; [0354]). Mandapaka further teaches that the application key may be generated at a software level, stating that “an application key may be generated at the application level of each of analyte sensor system 708 and display device 710” (Mandapaka, [0355]). Mandapaka further teaches that encrypted analyte values may be transmitted using invitation type signaling, disclosing that “at least a portion of the encrypted analyte value is transmitted to the display device in one or more advertisement messages transmitted by the analyte sensor system” (Mandapaka, [0010]). In context, Mandapaka’s application key functions as a shared secret key established between the analyte sensor system and the display device and is used to encrypt analyte data that is transmitted via advertisement messages.
Keenan teaches executing a cryptographic key exchange algorithm to generate a shared secret key using Bluetooth advertisements. Keenan teaches establishing a shared secret key via Bluetooth advertising channels, stating that “a device can advertise its presence by transmitting a short message in one of three channels designated for advertising (channels 37, 38, and 39)” (Keenan, p. 3, Sec. 2.1.1). Keenan further teaches generating a shared secret key using Diffie-Hellman, where “This shared secret key was generated by using the Diffie-Hellman key exchange using Curve 25519” and “Each device then broadcast its 32 byte public key using the Bluetooth advertisements” and “each device could generate a shared secret unique key” (Keenan, p. 3-4, Sec. 2.1.1). In context, Keenan teaches that the devices participate in a cryptographic key exchange by broadcasting the public keys using Bluetooth advertisements, and that the result of that key exchange is a shared secret key.
Loh teaches that an application layer is part of a communication protocol stack and interacts with lower layers to transmit and receive data, disclosing that “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21-24, and higher typically Software implemented layers including an application layer 29” (Loh, [0050]) and that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” (Loh, [0051]). In context, Mandapaka supplies the shared key used to encrypt analyte data for transmission, Keenan supplies the cryptographic key exchange algorithm that establishes the shared secret key over Bluetooth advertising channels, and Loh supplies that these operations are executed at an application layer of a communication protocol stack at the sensor electronics module.
It would have been prima facie obvious before the effective filing date of the claimed invention to modify Burnette in view of Mandapaka, Keenan, and Loh to establish a secret key with a first display device, based on executing a cryptographic key exchange algorithm at an application layer of a communication protocol stack at the sensor electronics module, to encrypt the analyte data using the secret key, and to transmit the encrypted analyte data. It would have been possible to combine the teachings because Burnette already transmits encrypted analyte data to display devices via advertising beacons and discloses a bonding exchange context with a display device; Mandapaka teaches a key that may effectively be shared between an analyte sensor system and a display device, used to encrypt analyte data for transmission, and generated at a software or application level; Keenan teaches executing a Diffie-Hellman key exchange using Bluetooth advertisements to generate a shared secret key; and Loh teaches an application layer of a protocol stack that interacts with lower layers to transmit and receive data. One of ordinary skill in the art would have understood that Keenan’s Diffie-Hellman key exchange could be executed within the application layer of the sensor electronics module’s protocol stack as taught by Loh to establish the shared key described by Mandapaka with the first display device, and that Mandapaka’s shared key could then be used to encrypt analyte data for transmission consistent with Burnette’s encrypted analyte beacon communications. The benefit of the combination would have been enabling application layer establishment of a shared secret key for encrypting transmitted analyte data, improving privacy and security of analyte communications while remaining compatible with the communication protocol stack and advertisement based transmission approach.
Also regarding claim 35, the modified Burnette does not fully teach transmitting the encrypted analyte data, via a broadcast over one or more primary invitation channels, to a second display device, wherein the broadcast encrypted analyte data is transmitted from the second display device to a server over a first secure channel established between the server and the second display device, wherein the encrypted analyte data transmitted by the second display is transmitted from the server to the first display device over a second secure channel established between the server and the first display device, and wherein the encrypted analyte data transmitted by the server is received by the first display device, decrypted by the first display device using the secret key, and displayed by the first display device. In particular, Burnette teaches broadcasting encrypted analyte data in advertising beacons to display devices and teaches that sensor information may be transmitted from one display device to another display device, and also teaches that “data transmission of sensor information can be effectuated directly from display device 120c to a second display device, e.g., display device 120b” (Burnette, [0007]-[0008], [0151]). Mandapaka teaches that an application key shared between the analyte sensor system and a display device may be used by the analyte sensor system to encrypt analyte data for transmission to the display device, and that the display device may use the application key to decrypt the received analyte data, including encrypted analyte values transmitted in advertisement messages (Mandapaka, [0354], [0378]-[0382]). Keenan teaches that Bluetooth devices can broadcast on the three advertising channels and can exchange public keys using Bluetooth advertisements to generate a shared secret key (Keenan, p. 3-4, Sec. 2.1.1). Loh teaches an application layer of a protocol stack that interacts with lower layers to transmit and receive data over a Bluetooth wireless communication network (Loh, [0050]-[0051]). Thus, Burnette in view of Mandapaka, Keenan, and Loh teaches or suggests encrypted analyte data broadcast over primary invitation channels, receipt by display devices, and decryption of encrypted analyte data by an authorized display device using a shared secret key established by a cryptographic key exchange algorithm executed at an application layer of a communication protocol stack at the sensor electronics module. However, Burnette, Mandapaka, Keenan, and Loh do not fully teach that the encrypted analyte data is transmitted via broadcast to a second display device, that the second display device transmits the broadcast encrypted analyte data to a server over a first secure channel, that the server transmits the encrypted analyte data to the first display device over a second secure channel, and that the first display device receives, decrypts using the secret key, and displays the server relayed encrypted analyte data.
Mensinger teaches a continuous glucose monitoring distributed architecture in which displays receive glucose data from a continuous glucose sensor unit and forward the glucose data to a cloud computing architecture. Mensinger teaches that displays 104a-c receive data relating to glucose levels from continuous glucose sensor units 100a-c at predetermined time intervals, and that the displays present glucose readings over time and display the actual current glucose value (Mensinger, [0050]). Mensinger further teaches that the displays 104a-e or continuous glucose sensor units 100a-c transmit data to the distributed cloud computing architecture 106, which organizes, stores, and provides access to the data by other computers, applications, and third parties (Mensinger, [0054]). Mensinger teaches that communications within the system can be encrypted and secured, such as HTTPS and SSL communications, and that patient data including all data posts from the displays can be encrypted and stored in a secure fashion by the cloud computing architecture 106 (Mensinger, [0055]). Thus, Mensinger teaches display to server secure channel communications in the same CGM context.
Mensinger further teaches using a display device as a pass through for encrypted data received from a continuous glucose monitor transmitter. Mensinger teaches that the transmitter in a continuous glucose monitor can encrypt all or a portion of data and pass it through the associated display 104 to the services server 300, and that the display 104 does not have a decryption key for the encrypted bulk data and therefore acts simply as a pass through for encrypted bulk data (Mensinger, [0072]). Mensinger further teaches that the transmitter sends an encrypted message to a display, such as a smartphone or dedicated receiver, which sends the encrypted message on to the services server, and that the display acts as a pass through without the ability to decrypt all of the data (Mensinger, [0092]). Mensinger therefore teaches the use of a display device that receives encrypted data from a CGM transmitter and forwards the encrypted data to a server without decrypting all of the encrypted data, which corresponds to the second display device receiving broadcast encrypted analyte data and transmitting the encrypted analyte data to the server over the first secure channel.
Mensinger further teaches server distribution of glucose data to other display devices. Mensinger teaches that the cloud infrastructure can forward a subset of data relating to glucose levels to a second display device, the subset including current and past glucose levels (Mensinger, [0173]). Mensinger also teaches a cloud server architecture having a plurality of servers that receives data from a plurality of display devices, and a plurality of remote monitor display devices that receive data from one of the plurality of servers, where the data sent to each remote monitor display device depends upon the data type and the display device that transmitted the data to the server (Mensinger, [0186]). Thus, Mensinger teaches the use of server side distribution of glucose data received from display devices to other display devices, which corresponds to the server transmitting encrypted analyte data to the first display device over the second secure channel.
Mensinger does not expressly teach that the server relayed encrypted data remains encrypted until decryption by the first display device using the sensor to display secret key.
Klinkner teaches an end to end encrypted relay architecture in which information associated with a short range broadcast is detected by an intermediate mobile device, encrypted data is relayed through a server, and only the owner or authorized device holding the corresponding key receives, decrypts, and displays the protected data. Klinkner teaches that a tracking device can provide a hashed identifier to a mobile device, for instance within an advertisement packet, that the mobile device can receive a public key from an entity, determine a location, encrypt the location with the public key, and provide the hashed identifier and encrypted location to the entity, which provides the encrypted location to an owner of the tracking device for decryption using a private key corresponding to the public key (Klinkner, Abstract). Klinkner further teaches that the owner device receives encrypted location data from the entity and decrypts the encrypted location data using a private key, and that the decrypted data can then be displayed to the user (Klinkner, [0130]-[0132]). Klinkner expressly teaches the reason for this architecture, stating that encrypting the location data at the mobile device protects the data from the point of access until the encrypted data is received by the owner device, and that where the intermediate mobile device and entities do not have access to the private key, “no system or entity between the mobile device 102 and the owner device 1224 is able to decrypt the encrypted location data 1220,” thereby enabling end to end protection (Klinkner, [0133]).
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Mensinger and Klinkner such that the encrypted analyte data is transmitted, via a broadcast over one or more primary invitation channels, to a second display device, where the broadcast encrypted analyte data is transmitted from the second display device to a server over a first secure channel established between the server and the second display device, where the encrypted analyte data transmitted by the second display device is transmitted from the server to the first display device over a second secure channel established between the server and the first display device, and where the encrypted analyte data transmitted by the server is received by the first display device, decrypted by the first display device using the secret key, and displayed by the first display device. It would have been possible to combine the teachings because Burnette already teaches a CGM system having multiple display devices and advertising beacons containing encrypted analyte data; Mandapaka teaches use of a shared secret key to encrypt analyte data and allow a display device to decrypt the encrypted analyte data; Keenan teaches establishing the shared secret by exchanging public keys over advertising channels; Loh teaches executing communication operations at an application layer of a communication protocol stack; Mensinger teaches in the same CGM field that displays receiving glucose data can forward data to cloud infrastructure over secure communications and can act as pass through devices for encrypted CGM data; and Klinkner teaches preserving end to end protection through an intermediate mobile device and server so that only the authorized key holding device can decrypt the protected data.
One of ordinary skill in the art would have been motivated to apply Mensinger’s CGM cloud relay architecture to Burnette’s encrypted advertising beacon analyte data so that glucose data received by one display device could be made available to another authorized display device through cloud infrastructure. One of ordinary skill in the art would have further been motivated by Klinkner’s end to end protection teaching to preserve the encrypted form of the analyte data through the second display device and server so that intermediate devices and server side components need not decrypt the patient’s analyte data. Klinkner expressly teaches that no system or entity between the detecting mobile device and the owner device can decrypt the protected data where those intermediaries lack the corresponding key (Klinkner, [0133]). The predictable result would have been using known CGM cloud relay infrastructure to deliver Burnette/Mandapaka/Keenan/Loh’s encrypted analyte data broadcast to the authorized first display device while maintaining privacy by allowing decryption and display at the first display device using the shared secret key.
Regarding claim 36, the modified Burnette does not fully teach that the analyte data is encrypted at the application layer of the communication protocol stack at the sensor electronics module. Rather, the modified Burnette as modified for claim 35 teaches transmitting encrypted analyte data to a display device using advertising beacons, including that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, ¶[0151]). However, the modified Burnette does not expressly teach that the analyte data is encrypted at the application layer of the communication protocol stack at the sensor electronics module.
Mandapaka teaches that encryption of analyte data is performed at a software or application level of the analyte sensor system, disclosing that “the application key may be generated at a software / application level of analyte sensor system 708 and / or display device 710” (Mandapaka, ¶[0355]) and that “the application key may be used for example by analyte sensor system 708 to encrypt analyte data for transmission to display device 710 , and display device 710 may use the application key to decrypt the received analyte data” (Mandapaka, ¶[0354]). Thus, Mandapaka expressly places the encryption operation at the software or application level of the analyte sensor system.
Loh teaches that the application layer is a defined layer of a communication protocol stack implemented in software and positioned above lower communication layers, disclosing that “A L2CAP (Logical Link Control and Adaptation Protocol) layer 25 provides a logical interface between the lower mainly hardware implemented layers 21-24, and higher typically Software implemented layers including an application layer 29” (Loh, ¶[0050]) and that “The application layer 29 contains one or more higher-level applications 291, which interact with the L2CAP layer 25 to transmit and receive data over the Bluetooth wireless communication network” (Loh, ¶[0051]). In context, Loh defines the application layer as a software-implemented layer of the communication protocol stack that performs higher-level processing and interacts with lower protocol layers to transmit and receive data.
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have further modified the modified Burnette in view of Mandapaka and Loh to encrypt the analyte data at the application layer of the communication protocol stack at the sensor electronics module. It would have been possible to combine the teachings because Mandapaka expressly teaches performing encryption of analyte data at a software or application level of the analyte sensor system, Loh expressly teaches that the application layer is the software-implemented layer of the communication protocol stack responsible for higher-level processing and for interacting with lower layers to transmit data, and Burnette already transmits encrypted analyte data to display devices. One of ordinary skill in the art would have understood that implementing Mandapaka’s software-level encryption within Loh’s defined application layer of the communication protocol stack at the sensor electronics module is a straightforward and technically consistent implementation, as encryption of payload data logically occurs before the data is passed to lower protocol layers for transmission. The benefit of the combination would have been providing encryption at the application layer of the protocol stack, improving modularity, security, and separation of concerns within the communication architecture while maintaining compatibility with advertisement-based transmission of analyte data.
Claims 5-7 are rejected under 35 U.S.C. 103 as being unpatentable over Burnette et al. (US-20170181628-A1), hereinafter referred to as Burnette, in view of Mandapaka et al. (US-20180027104-A1), hereinafter referred to as Mandapaka, in view of Keenan et al. (Keenan, Kathryn E. et al., “Development and Evaluation of Bluetooth Low-Energy Device for Electronic Encounter Metrics,” Journal of Research of the National Institute of Standards and Technology 126 (2021)), hereinafter referred to as Keenan, in view of Mensinger et al. (US-20160335409-A1), hereinafter referred to as Mensinger, and in view of Klinkner et al. (US-20210092599-A1), hereinafter referred to as Klinkner, and further in view of Hyun et al. (KR-20180081308-A), hereinafter referred to as Hyun.
The modified Burnette teaches claim 1 as described above.
Regarding claim 5, the modified Burnette does not fully teach receiving encrypted data from the display device over the one or more primary invitation channels; and decrypting the encrypted data using the secret key. For purposes of examination, and consistent with amended claim 1’s recitation of establishing the secret key with the first display device, “the display device” in claim 5 is interpreted as the first display device. As discussed above regarding claim 1, Burnette teaches broadcasting encrypted analyte data in advertising beacons over invitation signaling, including that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, [0151]). Mandapaka and Keenan teach establishing a shared secret key over advertising channels and using that key for encryption and decryption. However, Burnette in view of Mandapaka, Keenan, Mensinger, and Klinkner does not expressly teach the sensor electronics module receiving encrypted data from the first display device over the one or more primary invitation channels and decrypting the encrypted data using the secret key.
Hyun teaches encrypted data being broadcast over a BLE advertising channel, received by another device, and decrypted using the same encryption key used for encryption. Hyun teaches that a BLE advertising device “encrypts authentication data to be transmitted through the BLE advertising channel using the same encryption key stored in the BLE scanning device” (Hyun, [0034]) and that the BLE advertising device “broadcasts the encrypted authentication data” through the BLE advertising channel (Hyun, [0037]). Hyun further teaches that the receiving device “receives encrypted authentication data... through a BLE advertising channel” (Hyun, [0038]) and “stores the same encryption key used for encryption... and uses it to decrypt the encrypted authentication data received through the BLE advertising channel” (Hyun, [0041]). Thus, Hyun teaches receiving encrypted data over an advertising channel and decrypting that data using a shared encryption key.
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the Burnette system as modified by Mandapaka, Keenan, Mensinger, and Klinkner in view of Hyun such that the sensor electronics module receives encrypted data from the first display device over the one or more primary invitation channels and decrypts the encrypted data using the secret key. It would have been possible to combine the teachings because the modified Burnette system already uses advertising-based invitation signaling for communications between the sensor electronics module and display devices and already transmits encrypted analyte data in advertising beacons, Mandapaka and Keenan provide the shared secret key used for encryption and decryption, and Hyun provides a compatible BLE advertising-channel technique in which encrypted data is broadcast, received through the advertising channel, and decrypted using the shared key. One of ordinary skill in the art would have understood that the first display device in the modified Burnette system could transmit encrypted data to the sensor electronics module using the same primary invitation-channel advertising framework, and that the sensor electronics module could decrypt that encrypted data using the secret key established with the first display device. The benefit of the combination would have been enabling secure reverse-direction control or messaging from the first display device to the sensor electronics module over the same low-power, connectionless invitation channels while maintaining confidentiality of the transmitted data.
Regarding claim 6, the modified Burnette does not expressly teach wherein the decrypted data comprises an opcode. As discussed above regarding claim 5, Hyun teaches receiving encrypted data over a BLE advertising channel and decrypting the encrypted data using a shared encryption key (Hyun, [0038], [0041]). However, Hyun does not expressly characterize the decrypted data as an opcode.
Burnette teaches command-and-payload messaging between a display device and the sensor electronics module. Burnette teaches that “a CGM receive command is triggered when the display device sends a connection request on the wireless communications protocol API” and that the command “takes the payload and sends it to CGM processor 506” (Burnette, [0088]). Burnette further teaches command types that control communication operations, including that “[t]he start communication command is the first command radio 508 sees” and that “[a] stop communication command may be used to ensure radio 508 does not exceed a predefined ‘communication window’” (Burnette, [0086]). Thus, Burnette teaches command values or command types that cause the sensor electronics module or radio to perform particular operations.
Hyun teaches that decrypted data may be used to determine whether to permit or perform an operation. Hyun teaches that, if decrypted authentication data matches expected data, the BLE scanning device performs a preset operation to release security (Hyun, [0043]). Hyun further teaches that the BLE scanning device can open the door if the decrypted data is “HELLO” (Hyun, [0048]). Thus, Hyun teaches decrypted data having an operation-controlling value that determines whether a particular operation is performed.
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Hyun such that the decrypted data comprises an opcode. It would have been possible to combine the teachings because the modified Burnette system already includes command-and-payload messaging between a display device and the sensor electronics module, Hyun teaches encrypted advertising-channel data that is decrypted and used to determine whether a preset operation is performed, and claim 5’s modified system already provides for receiving encrypted data from the first display device over the primary invitation channels and decrypting the encrypted data using the secret key. One of ordinary skill in the art would have understood that the decrypted payload received from the first display device could include an opcode, namely an operation code or command value identifying the operation to be performed, consistent with Burnette’s command-based control framework and Hyun’s decrypted operation-triggering value. The benefit of the combination would have been enabling secure command-and-control signaling in which the decrypted data identifies the operation to be performed by the sensor electronics module.
Regarding claim 7, the modified Burnette does not expressly teach wherein a value of the opcode triggers the broadcasting of the encrypted analyte data over the one or more primary invitation channels. As discussed above regarding claim 6, the modified system teaches receiving encrypted data from the first display device over the one or more primary invitation channels, decrypting the encrypted data using the secret key, and structuring the decrypted data to include an opcode. However, the modified Burnette in view of Mandapaka, Keenan, Mensinger, Klinkner, and Hyun does not expressly teach that a value of the decrypted opcode triggers broadcasting of the encrypted analyte data over the one or more primary invitation channels.
Burnette teaches command-triggered advertising by the sensor electronics module. Burnette teaches that “CGM processor 506 may signal radio 508 to ‘start communication’” (Burnette, [0085]). Burnette further teaches that “[t]he start communication command is the first command radio 508 sees” (Burnette, [0086]) and that, after entering the advertising state, “Radio 508 may begin advertising” (Burnette, [0087]). Burnette also teaches that “advertising beacons containing encrypted analyte data can be used to directly communicate those measured analyte values, e.g., glucose values, without establishing a two-way communication protocol” (Burnette, [0151]). Thus, Burnette teaches that a command can cause the radio of the sensor electronics module to begin advertising, and that the advertising beacons can contain encrypted analyte data.
Hyun teaches that a decrypted value can trigger performance of a preset operation. Hyun teaches that, if the decrypted authentication data matches expected data, the BLE scanning device performs a preset operation to release security (Hyun, [0043]). Hyun further teaches that the BLE scanning device can open the door if the decrypted data is “HELLO” (Hyun, [0048]). Thus, Hyun teaches using a decrypted value to determine whether a corresponding operation is performed.
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Hyun such that a value of the opcode triggers the broadcasting of the encrypted analyte data over the one or more primary invitation channels. It would have been possible to combine the teachings because the modified Burnette system already provides encrypted invitation-channel communication between the first display device and the sensor electronics module, claim 6’s modified system already provides decrypted opcode-based command information, Burnette teaches command-triggered advertising by the sensor electronics module and advertising beacons containing encrypted analyte data, and Hyun teaches that decrypted data values can trigger preset operations. One of ordinary skill in the art would have understood that the decrypted opcode received from the first display device could specify a start-communication or advertising operation, and that the sensor electronics module could respond to that opcode value by broadcasting encrypted analyte data over the primary invitation channels. The benefit of the combination would have been enabling secure display-triggered control of when the sensor electronics module broadcasts encrypted analyte data, thereby supporting low-power operation by initiating advertising-based analyte-data broadcasting in response to an authenticated encrypted command.
Claims 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Burnette et al. (US-20170181628-A1), hereinafter referred to as Burnette, in view of Mandapaka et al. (US-20180027104-A1), hereinafter referred to as Mandapaka, in view of Keenan et al. (Keenan, Kathryn E. et al., “Development and Evaluation of Bluetooth Low-Energy Device for Electronic Encounter Metrics,” Journal of Research of the National Institute of Standards and Technology 126 (2021)), hereinafter referred to as Keenan, in view of Mensinger et al. (US-20160335409-A1), hereinafter referred to as Mensinger, and in view of Klinkner et al. (US-20210092599-A1), hereinafter referred to as Klinkner, and further in view of Wang et al. (US-20220070971-A1), hereinafter referred to as Wang.
The modified Burnette teaches claim 14 as described above.
Regarding claim 19, the modified Burnette does not fully teach wherein the encrypted data is broadcast in response to receiving the encrypted analyte data from the sensor electronics module. As discussed above regarding claim 17, Burnette teaches advertising-beacon communications over primary invitation channels and encrypted analyte data in advertising beacons, and Mandapaka and Keenan teach use of a shared secret key established over advertising channels for encryption and decryption. However, the modified Burnette does not expressly teach that the first display device broadcasts encrypted data over the one or more primary invitation channels specifically in response to receiving encrypted analyte data from the sensor electronics module.
Burnette teaches responsive behavior by a display device after receiving an advertising beacon from the sensor electronics module. Burnette teaches that a display device may “receive an advertising beacon 700 and send a connection request back to radio 508” (Burnette, [0100]). Thus, Burnette teaches that receipt of an advertising beacon from the sensor electronics module can trigger responsive communication from the display device.
Wang teaches broadcasting encrypted data in response to receiving data over an advertising channel. Wang teaches that “After receiving the status information advertising packet, the electronic device 102 may send, to the electronic device 101 through an advertising channel, a content message advertising packet encrypted by using the public key” (Wang, [0186]). Wang is relied upon for the responsive advertising-channel trigger relationship, not for the specific key type used for encryption.
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Wang such that the encrypted data broadcast by the first display device over the one or more primary invitation channels is broadcast in response to receiving encrypted analyte data from the sensor electronics module. It would have been possible to combine the teachings because the modified Burnette system already uses advertising beacons as primary invitation channels to transmit encrypted analyte data and already teaches responsive display-device communication after receiving an advertising beacon; claim 17’s modified system already provides display-side encryption using the established secret key and broadcasting over the primary invitation channels; and Wang teaches that after receiving an advertising packet, a device may send an encrypted advertising packet through an advertising channel. One of ordinary skill in the art would have understood that Wang’s responsive advertising-channel exchange could be applied to the modified Burnette system so that, after the first display device receives encrypted analyte data from the sensor electronics module, the first display device broadcasts encrypted data using the same primary invitation-channel advertising mechanism. The benefit of the combination would have been enabling secure bidirectional exchange over the primary invitation channels using a received-data trigger while maintaining low-power, connectionless advertisement-based communication.
Regarding claim 20, the modified Burnette does not fully teach wherein the encrypted analyte data is received in response to the encrypted data being broadcast over the one or more primary invitation channels. For purposes of examination, this limitation is interpreted as requiring that the encrypted analyte data received by the first display device through the server-relay path recited in claim 14 is received as a result of, or in response to, the encrypted data broadcast over the one or more primary invitation channels as recited in claim 17. The limitation is not interpreted as requiring direct receipt by the first display device from the sensor electronics module over the primary invitation channels. As discussed above regarding claim 17, Burnette teaches advertising-beacon communications over primary invitation channels and encrypted analyte data in advertising beacons, and Mandapaka and Keenan teach use of a shared secret key established over advertising channels for encryption and decryption. However, the modified Burnette does not expressly teach that encrypted analyte data is ultimately received by the first display device through the server-relay path recited in claim 14 in response to encrypted data being broadcast by the first display device over the one or more primary invitation channels.
Burnette teaches advertising-based responsive communication between a display device and the sensor electronics module. Burnette teaches that a display device may “receive an advertising beacon 700 and send a connection request back to radio 508” (Burnette, [0100]). Burnette also teaches that advertising beacons containing encrypted analyte data may directly communicate measured analyte values without establishing a two-way communication protocol (Burnette, [0151]). Thus, Burnette teaches advertising-beacon analyte-data communication and responsive communication behavior involving a display device and the sensor electronics module, but does not expressly teach the specific sequence in which the first display device broadcasts encrypted data over the primary invitation channels and, in response, encrypted analyte data is broadcast by the sensor electronics module, received by the second display device, transmitted to the server, and ultimately received by the first display device through the server-relay path recited in claim 14.
Wang teaches a responsive advertising-channel exchange in which encrypted data is transmitted through an advertising channel after an advertising packet is received. Wang teaches that “After receiving the status information advertising packet, the electronic device 102 may send, to the electronic device 101 through an advertising channel, a content message advertising packet encrypted by using the public key” (Wang, [0186]). Wang is relied upon for the responsive advertising-channel exchange pattern, not for the specific type of medical data or the specific key type used for encryption.
It would have been prima facie obvious before the effective filing date of the claimed invention to further modify the modified Burnette system in view of Wang such that the encrypted analyte data is received in response to the encrypted data being broadcast over the one or more primary invitation channels. It would have been possible to combine the teachings because the modified Burnette system already uses advertising beacons as primary invitation channels for encrypted analyte-data communication, claim 17’s modified system already provides display-side encrypted broadcasting over the primary invitation channels using the established secret key, Mensinger and Klinkner provide the server-relay path for delivering encrypted analyte data to the first display device, and Wang teaches a responsive advertising-channel exchange in which receipt of an advertising packet causes transmission of an encrypted advertising packet through an advertising channel. One of ordinary skill in the art would have understood that Wang’s responsive advertising-channel exchange pattern could be applied to the modified Burnette system so that, after the first display device broadcasts encrypted data over the primary invitation channels, the sensor electronics module responds by broadcasting encrypted analyte data over the same primary invitation channels, the second display device receives the broadcast encrypted analyte data, and the encrypted analyte data is ultimately delivered to the first display device through the server-relay path recited in claim 14. The benefit of the combination would have been enabling the first display device to solicit or trigger encrypted analyte-data delivery using secure, low-power, connectionless advertising-channel communications while still using the server-relay architecture applied in claim 14.
Response to Arguments
Objections
Applicant's arguments filed 5/26/2026, page 8, regarding the previous Objections of claim 17 have been fully considered and are persuasive. The previous Objections have been withdrawn. However, there are new Objections as shown above.
Double Patenting
Applicant's arguments filed 5/26/2026, pages 8-9, regarding the previous double patenting Rejections of claims 35-36 have been fully considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. That is, there are new grounds of rejection.
Applicant’s Argument: Applicant argues that the nonstatutory double patenting rejections of claims 35 and 36 are moot in view of the amendments to independent claim 35. Applicant further states that a terminal disclaimer will be filed, if necessary.
Examiner’s Response: Applicant’s argument has been considered but is not persuasive. The amendments to claim 35 have been considered, and the double patenting rejection has been updated to address the amended claim language. The amended claim language does not obviate the nonstatutory double patenting rejection for the reasons set forth above. Additionally, Applicant’s statement that a terminal disclaimer may be filed in the future does not overcome the rejection because no terminal disclaimer has been filed and accepted. Accordingly, the nonstatutory double patenting rejections of claims 35 and 36 are maintained.
35 U.S.C. §103
Applicant's arguments filed 5/26/2026, pages 9-11, regarding the previous 103 Rejections of claims 1-15, 17-23, and 35-36 have been fully considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. That is, there are new grounds of rejection.
Applicant’s Argument: Applicant argues that Burnette in view of Mandapaka and Keenan fails to disclose all of the features of independent claims 1, 9, and 14, including the amended limitations involving a first display device, a second display device, server relay over secure channels, and decryption by the first display device using the secret key. Applicant further argues that Burnette in view of Mandapaka, Keenan, and Loh fails to disclose the amended limitations of independent claim 35. Applicant additionally argues that the remaining cited references do not cure the asserted deficiencies.
Examiner’s Response: Applicant’s arguments have been considered but are moot in view of the new grounds of rejection and are not persuasive as applied to the rejections set forth in the present Office action. The prior rejections relied on Burnette, Mandapaka, Keenan, and, for certain claims, Loh, Hyun, or Wang. The present rejections have been revised in view of the amended claim language and now additionally rely on Mensinger and Klinkner to address the amended relay path involving receipt by a second display device, transmission to a server over a secure channel, transmission from the server to the first display device over a secure channel, and decryption by the authorized first display device.
As explained in the rejections above, Burnette teaches encrypted analyte data in advertising beacons in a continuous glucose monitoring system having display devices; Mandapaka teaches use of a shared application key to encrypt analyte data and allow a display device to decrypt received analyte data; Keenan teaches establishing a shared secret key using Bluetooth advertisements; Mensinger teaches a continuous glucose monitoring cloud architecture in which display devices forward glucose data to cloud/server infrastructure over secure communications and the server distributes glucose data to other display devices; and Klinkner teaches an end-to-end protected relay architecture in which encrypted data is relayed through intermediary devices and a server so that only the authorized key-holding device decrypts the protected data. Accordingly, the present combination addresses the amended independent claim limitations and overcomes the deficiencies alleged against the prior rejection.
For claim 35, the rejection has also been revised in view of the amended language. Loh continues to be relied upon for the application layer of a communication protocol stack, while Mensinger and Klinkner are additionally relied upon for the amended server-relay and end-to-end encrypted delivery features. Thus, Applicant’s arguments directed to the prior claim 35 rejection do not overcome the present rejection.
Applicant’s Argument: Applicant argues that claims 2-8, 10-13, 15, 17-23, and 36 are patentable at least by virtue of their dependency from independent claims 1, 9, 14, and 35. Applicant also states generally that the dependent claims recite patentably distinct, novel, and non-obvious combinations that stand on their own merits.
Examiner’s Response: Applicant’s arguments have been considered but are not persuasive. Applicant has not presented separate substantive arguments directed to the specific limitations of dependent claims 2-8, 10-13, 15, 17-23, and 36. Therefore, except to the extent separately addressed in the rejections above, the dependent claims stand or fall with their respective independent claims. Because the rejections of independent claims 1, 9, 14, and 35 are maintained as set forth above, Applicant’s dependency-based arguments do not overcome the rejections of the dependent claims.
Further, the specific dependent-claim limitations have been addressed in the present rejections. For example, Loh is relied upon for the application-layer protocol-stack limitations, Hyun is relied upon for encrypted data received over advertising channels and decrypted using a shared key and related opcode-triggered operation teachings, and Wang is relied upon for responsive advertising-channel exchange features. Accordingly, the dependent claims remain rejected for the reasons set forth above.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the
examiner should be directed to AARON MERRIAM whose telephone number is (703) 756-
5938. The examiner can normally be reached M-F 8:00 am - 5:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing
using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is
encouraged to use the USPTO Automated Interview Request (AIR) at
http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s
supervisor, Jason Sims can be reached on (571)272-4867. The fax phone number for the
organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained
from Patent Center. Unpublished application information in Patent Center is available to
registered users. To file and manage patent submissions in Patent Center, visit:
https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for
more information about Patent Center and https://www.uspto.gov/patents/docx for
information about filing in DOCX format. For additional questions, contact the Electronic
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO
Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AARON MERRIAM/Examiner, Art Unit 3791
/MATTHEW KREMER/Primary Examiner, Art Unit 3791