IP Library Granted Patent US 9,148,443
Granted Patent B2
US 9,148,443 · App. 13/935,436 · Granted Sep 29, 2015

Enhanced security and safety in telerobotic systems

Inventors: Howard Jay Chizeck (Mercer Island, WA); Tamara Bonaci (Redmond, WA); Thomas Lendvay (Seattle, WA)
Assignee: University of Washington Through its Center for Commericalization
H04L63/1425G06F21/316G06F21/552H04L63/126G06F21/00H04L29/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,148,443
App. No.
13/935,436
Granted
Sep 29, 2015
Kind
B2
Abstract

Methods and systems for securing remotely-operable devices are provided. A security device can receive a plurality of commands to control a remotely-operable device in a remote environment. At least one command in the plurality of commands can include command data that is related to the remotely-operable device. The security device can receive a plurality of responses to the plurality of commands. The security device can process the plurality of commands and the plurality of responses to determine a signature related to an operator that issued the plurality of commands for the remotely-operable device. The security device can determine an identity of the operator based on the signature. The security device can generate an identity report that includes the identity of the operator.

Claims (61)

1. A method, comprising:

receiving, at a security device, a plurality of commands to control a remotely-operable device in a remote environment, wherein at least one command in the plurality of commands comprises command data related to the remotely-operable device;

receiving a plurality of responses to the plurality of commands at the security device;

processing the plurality of commands and the plurality of responses using the security device to determine a signature related to an operator that issued the plurality of commands to control the remotely-operable device, wherein the signature is determined based on a pattern of use related to one or more tasks as indicated by the plurality of commands and plurality of responses, wherein the plurality of commands comprises a first command and a second command, wherein the first command is associated with a first time, wherein the second command is associated with a second time, wherein the second command is immediately subsequent to the first command, and wherein processing the plurality of commands and the plurality of responses to determine the signature comprises determining a difference between the second time and the first time;

determining an identity of the operator based on the signature using the security device; and

generating an identity report comprising the identity of the operator using the security device.

2. The method of claim 1 , further comprising:

after generating the identity report, receiving a second plurality of commands;

detecting an anomaly in the second plurality of commands based on the identity of the operator; and

generating an anomaly report indicating the detected anomaly in the second plurality of commands.

3. The method of claim 1 , wherein generating the identity report comprises:

determining whether the identity of the operator corresponds to an authorized operator by at least searching for the identity of the operator in one or more authorized operator records, wherein at least one record of the one or more authorized operator records comprises an identity of an authorized operator of the remotely-operable device; and

after determining that the identity of the operator corresponds to an identity of an authorized operator; generating an identity report indicating that the identity of the operator corresponds to an authorized operator.

4. The method of claim 3 , further comprising:

after determining that the identity of the operator does not corresponds to the identity of an authorized operator; generating an identity report indicating the identity of the operator does not correspond to an authorized operator.

5. The method of claim 1 , wherein the remotely-operable device in the remote environment comprises a surgical robot.

6. The method of claim 5 , wherein the plurality of responses comprise a force-feedback response from the surgical robot.

7. The method of claim 1 , wherein the plurality of commands comprises at least one encrypted command, and wherein the method further comprises:

decrypting the at least one encrypted command.

8. The method of claim 1 , wherein the identity report further comprises identification information about the remotely-operable device.

9. The method of claim 1 , wherein the plurality of commands comprises a first command, wherein the plurality of responses comprises a first response to the first command, and wherein processing the plurality of commands and the plurality of responses to determine the signature comprises:

determining at least one characteristic of the first response; and

determining the signature based on the at least one characteristic of the first response.

10. The method of claim 9 , wherein the at least one characteristic comprises a characteristic related to force feedback.

11. The method of claim 1 , wherein the command data comprises at least one data item selected from the group consisting of: a data item for a location related to the remotely-operable device, a data item for a position related to the remotely-operable device, a data item for an applied force related to the remotely-operable device, and a data item for an torque related to the remotely-operable device.

12. A security device, comprising:

a processor; and

non-transitory tangible computer readable medium configured to store instructions that, when executed by the processor, cause the security device to perform functions comprising:

receiving a plurality of commands to control a remotely-operable device in a remote environment, wherein at least one command in the plurality of commands comprises command data related to the remotely-operable device;

receiving a plurality of responses to the plurality of commands;

processing the plurality of commands and the plurality of responses to determine a signature related to an operator of the remotely-operable device, wherein the operator issued the plurality of commands, and wherein the signature is determined based on a pattern of use related to one or more tasks as indicated by the plurality of commands and plurality of responses, wherein the plurality of commands comprises a first command and a second command, wherein the first command is associated with a first time, wherein the second command is associated with a second time, wherein the second command is immediately subsequent to the first command, and wherein processing the plurality of commands and the plurality of responses to determine the signature comprises determining a difference between the second time and the first time;

determining an identity of the operator based on the signature, and

generating an identity report comprising the identity of the operator.

13. The security device of claim 12 , wherein the functions further comprise:

after generating the identity report, receiving a second plurality of commands;

detecting an anomaly in the second plurality of commands based on the identity of the operator; and

generating an anomaly report indicating the detected anomaly in the second plurality of commands.

14. The security device of claim 12 , wherein the remotely-operable device in the remote environment comprises a surgical robot.

15. The security device of claim 12 , wherein processing the plurality of commands to determine the signature comprises determining the signature based on a characteristic of a signal carrying at least one command of the plurality of commands and/or at least one response of the plurality of responses.

16. The security device of claim 12 , wherein the plurality of commands comprises a first command, wherein the plurality of responses comprises a first response to the first command, and wherein processing the plurality of commands to determine the signature comprises:

determining at least one characteristic of the first response; and

determining the signature based on the at least one characteristic of the first response.

17. The security device of claim 12 , wherein the command data comprises at least one data item selected from the group consisting of: a data item for a location related to the remotely-operable device, a data item for a position related to the remotely-operable device, a data item for an applied force related to the remotely-operable device, and a data item for an torque related to the remotely-operable device.

18. A method, comprising:

recording a first identity at a security device;

receiving, at the security device, a plurality of commands to control a remotely-operable device in a remote environment, wherein at least one command in the plurality of commands comprises command data related to the remotely-operable device;

receiving, at the security device, a plurality of responses to the plurality of commands;

processing the plurality of commands and the plurality of responses using the security device to determine a current signature related to a current operator that issued the plurality of commands to control the remotely-operable device, wherein the current signature is determined based on a pattern of use related to one or more tasks as indicated by the plurality of commands and plurality of responses, wherein the plurality of commands comprises a first command and a second command, wherein the first command is associated with a first time, wherein the second command is associated with a second time, wherein the second command is immediately subsequent to the first command, and wherein processing the plurality of commands and the plurality of responses to determine the signature comprises determining a difference between the second time and the first time;

determining a current identity of the current operator based on the current signature using the security device;

determining whether the first identity is the same as the current identity using the security device; and

after determining that the first identity is not the same as the current identity, the security device performing a first action based on the first identity not being the same as the current identity.

19. The method of claim 18 , wherein the first action comprises generating an anomaly report indicating that the first identity is not the same as the current identity.

20. The method of claim 18 , wherein the first action comprises inhibiting subsequent commands issued by the current operator from controlling the remotely-operable device.

21. The method of claim 20 , wherein inhibiting the subsequent commands comprises inhibiting transmission of the subsequent commands to the remotely-operable device.

22. The method of claim 18 , further comprising:

after determining that the first identity is the same as the current identity, the security device performing a second action based on the first identity being the same as the current identity, wherein the first action differs from the second action.

23. The method of claim 22 , wherein the second action comprises enabling subsequent commands issued by the current operator to control the remotely-operable device.

24. The method of claim 23 , wherein enabling the subsequent commands comprises enabling transmission of the subsequent commands to the remotely-operable device.

25. The method of claim 18 , wherein determining whether the first identity equals the identity of the current operator comprises:

accessing a first signature stored with the first identity; and

determining whether the first identity equals the current identity by at least determining whether the first signature equals the current signature.

Assignments (2)
CONFIRMATORY LICENSE Recorded Nov 22, 2016
From: UNIVERSITY OF WASHINGTON
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 040665/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2013
From: CHIZECK, HOWARD JAY; BONACI, TAMARA; LENDVAY, THOMAS
To: UNIVERSITY OF WASHINGTON THROUGH ITS CENTER FOR COMMERCIALIZATION
Reel/Frame 030993/0459 →
Continuity (2)
Provisional Application 61668590 · Jul 6, 2012
Related Publication 20140068770A1 · Mar 6, 2014