Possible security threats coming from IOT... | F1000Research "use strict";function _typeof(t){return(_typeof="function"==typeof Symbol&&"symbol"==typeof Symbol.iterator?function(t){return typeof t}:function(t){return t&&"function"==typeof Symbol&&t.constructor===Symbol&&t!==Symbol.prototype?"symbol":typeof t})(t)}!function(){var t=function(){var t,e,o=[],n=window,r=n;for(;r;){try{if(r.frames.__tcfapiLocator){t=r;break}}catch(t){}if(r===n.top)break;r=r.parent}t||(!function t(){var e=n.document,o=!!n.frames.__tcfapiLocator;if(!o)if(e.body){var r=e.createElement("iframe");r.style.cssText="display:none",r.name="__tcfapiLocator",e.body.appendChild(r)}else setTimeout(t,5);return!o}(),n.__tcfapi=function(){for(var t=arguments.length,n=new Array(t),r=0;r 3&&2===parseInt(n[1],10)&&"boolean"==typeof n[3]&&(e=n[3],"function"==typeof n[2]&&n[2]("set",!0)):"ping"===n[0]?"function"==typeof n[2]&&n[2]({gdprApplies:e,cmpLoaded:!1,cmpStatus:"stub"}):o.push(n)},n.addEventListener("message",(function(t){var e="string"==typeof t.data,o={};if(e)try{o=JSON.parse(t.data)}catch(t){}else o=t.data;var n="object"===_typeof(o)&&null!==o?o.__tcfapiCall:null;n&&window.__tcfapi(n.command,n.version,(function(o,r){var a={__tcfapiReturn:{returnValue:o,success:r,callId:n.callId}};t&&t.source&&t.source.postMessage&&t.source.postMessage(e?JSON.stringify(a):a,"*")}),n.parameter)}),!1))};"undefined"!=typeof module?module.exports=t:t()}(); dataLayer = dataLayer || []; // Standard GTM initialization - Google Consent Mode handles consent automatically (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl+ '>m_auth=hzk0Vc3qFsQYhCrIoHz68A>m_preview=env-1>m_cookies_win=x';f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-MWFK8L5J'); ;window.NREUM||(NREUM={});NREUM.init={distributed_tracing:{enabled:true},privacy:{cookies_enabled:true},ajax:{deny_list:["bam.nr-data.net"]}}; ;NREUM.loader_config={accountID:"438030",trustKey:"438030",agentID:"772317073",licenseKey:"97f8f67f26",applicationID:"772317073"} ;NREUM.info={beacon:"bam.nr-data.net",errorBeacon:"bam.nr-data.net",licenseKey:"97f8f67f26",applicationID:"772317073",sa:1} ;/*! For license information please see nr-loader-spa-1.236.0.min.js.LICENSE.txt */ (()=>{"use strict";var e,t,r={5763:(e,t,r)=>{r.d(t,{P_:()=>l,Mt:()=>g,C5:()=>s,DL:()=>v,OP:()=>T,lF:()=>D,Yu:()=>y,Dg:()=>h,CX:()=>c,GE:()=>b,sU:()=>_});var n=r(8632),i=r(9567);const o={beacon:n.ce.beacon,errorBeacon:n.ce.errorBeacon,licenseKey:void 0,applicationID:void 0,sa:void 0,queueTime:void 0,applicationTime:void 0,ttGuid:void 0,user:void 0,account:void 0,product:void 0,extra:void 0,jsAttributes:{},userAttributes:void 0,atts:void 0,transactionName:void 0,tNamePlain:void 0},a={};function s(e){if(!e)throw new Error("All info objects require an agent identifier!");if(!a[e])throw new Error("Info for ".concat(e," was never set"));return a[e]}function c(e,t){if(!e)throw new Error("All info objects require an agent identifier!");a[e]=(0,i.D)(t,o),(0,n.Qy)(e,a[e],"info")}var u=r(7056);const d=()=>{const e={blockSelector:"[data-nr-block]",maskInputOptions:{password:!0}};return{allow_bfcache:!0,privacy:{cookies_enabled:!0},ajax:{deny_list:void 0,enabled:!0,harvestTimeSeconds:10},distributed_tracing:{enabled:void 0,exclude_newrelic_header:void 0,cors_use_newrelic_header:void 0,cors_use_tracecontext_headers:void 0,allowed_origins:void 0},session:{domain:void 0,expiresMs:u.oD,inactiveMs:u.Hb},ssl:void 0,obfuscate:void 0,jserrors:{enabled:!0,harvestTimeSeconds:10},metrics:{enabled:!0},page_action:{enabled:!0,harvestTimeSeconds:30},page_view_event:{enabled:!0},page_view_timing:{enabled:!0,harvestTimeSeconds:30,long_task:!1},session_trace:{enabled:!0,harvestTimeSeconds:10},harvest:{tooManyRequestsDelay:60},session_replay:{enabled:!1,harvestTimeSeconds:60,sampleRate:.1,errorSampleRate:.1,maskTextSelector:"*",maskAllInputs:!0,get blockClass(){return"nr-block"},get ignoreClass(){return"nr-ignore"},get maskTextClass(){return"nr-mask"},get blockSelector(){return e.blockSelector},set blockSelector(t){e.blockSelector+=",".concat(t)},get maskInputOptions(){return e.maskInputOptions},set maskInputOptions(t){e.maskInputOptions={...t,password:!0}}},spa:{enabled:!0,harvestTimeSeconds:10}}},f={};function l(e){if(!e)throw new Error("All configuration objects require an agent identifier!");if(!f[e])throw new Error("Configuration for ".concat(e," was never set"));return f[e]}function h(e,t){if(!e)throw new Error("All configuration objects require an agent identifier!");f[e]=(0,i.D)(t,d()),(0,n.Qy)(e,f[e],"config")}function g(e,t){if(!e)throw new Error("All configuration objects require an agent identifier!");var r=l(e);if(r){for(var n=t.split("."),i=0;i {r.d(t,{D:()=>i});var n=r(50);function i(e,t){try{if(!e||"object"!=typeof e)return(0,n.Z)("Setting a Configurable requires an object as input");if(!t||"object"!=typeof t)return(0,n.Z)("Setting a Configurable requires a model to set its initial properties");const r=Object.create(Object.getPrototypeOf(t),Object.getOwnPropertyDescriptors(t)),o=0===Object.keys(r).length?e:r;for(let a in o)if(void 0!==e[a])try{"object"==typeof e[a]&&"object"==typeof t[a]?r[a]=i(e[a],t[a]):r[a]=e[a]}catch(e){(0,n.Z)("An error occurred while setting a property of a Configurable",e)}return r}catch(e){(0,n.Z)("An error occured while setting a Configurable",e)}}},6818:(e,t,r)=>{r.d(t,{Re:()=>i,gF:()=>o,q4:()=>n});const n="1.236.0",i="PROD",o="CDN"},385:(e,t,r)=>{r.d(t,{FN:()=>a,IF:()=>u,Nk:()=>f,Tt:()=>s,_A:()=>o,il:()=>n,pL:()=>c,v6:()=>i,w1:()=>d});const n="undefined"!=typeof window&&!!window.document,i="undefined"!=typeof WorkerGlobalScope&&("undefined"!=typeof self&&self instanceof WorkerGlobalScope&&self.navigator instanceof WorkerNavigator||"undefined"!=typeof globalThis&&globalThis instanceof WorkerGlobalScope&&globalThis.navigator instanceof WorkerNavigator),o=n?window:"undefined"!=typeof WorkerGlobalScope&&("undefined"!=typeof self&&self instanceof WorkerGlobalScope&&self||"undefined"!=typeof globalThis&&globalThis instanceof WorkerGlobalScope&&globalThis),a=""+o?.location,s=/iPad|iPhone|iPod/.test(navigator.userAgent),c=s&&"undefined"==typeof SharedWorker,u=(()=>{const e=navigator.userAgent.match(/Firefox[/\s](\d+\.\d+)/);return Array.isArray(e)&&e.length>=2?+e[1]:0})(),d=Boolean(n&&window.document.documentMode),f=!!navigator.sendBeacon},1117:(e,t,r)=>{r.d(t,{w:()=>o});var n=r(50);const i={agentIdentifier:"",ee:void 0};class o{constructor(e){try{if("object"!=typeof e)return(0,n.Z)("shared context requires an object as input");this.sharedContext={},Object.assign(this.sharedContext,i),Object.entries(e).forEach((e=>{let[t,r]=e;Object.keys(i).includes(t)&&(this.sharedContext[t]=r)}))}catch(e){(0,n.Z)("An error occured while setting SharedContext",e)}}}},8e3:(e,t,r)=>{r.d(t,{L:()=>d,R:()=>c});var n=r(2177),i=r(1284),o=r(4322),a=r(3325);const s={};function c(e,t){const r={staged:!1,priority:a.p[t]||0};u(e),s[e].get(t)||s[e].set(t,r)}function u(e){e&&(s[e]||(s[e]=new Map))}function d(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:"",t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:"feature";if(u(e),!e||!s[e].get(t))return a(t);s[e].get(t).staged=!0;const r=[...s[e]];function a(t){const r=e?n.ee.get(e):n.ee,a=o.X.handlers;if(r.backlog&&a){var s=r.backlog[t],c=a[t];if(c){for(var u=0;s&&u {let[t,r]=e;return r.staged}))&&(r.sort(((e,t)=>e[1].priority-t[1].priority)),r.forEach((e=>{let[t]=e;a(t)})))}function f(e,t){var r=e[1];(0,i.D)(t[r],(function(t,r){var n=e[0];if(r[0]===n){var i=r[1],o=e[3],a=e[2];i.apply(o,a)}}))}},2177:(e,t,r)=>{r.d(t,{c:()=>f,ee:()=>u});var n=r(8632),i=r(2210),o=r(1284),a=r(5763),s="nr@context";let c=(0,n.fP)();var u;function d(){}function f(e){return(0,i.X)(e,s,l)}function l(){return new d}function h(){u.aborted=!0,u.backlog={}}c.ee?u=c.ee:(u=function e(t,r){var n={},c={},f={},g=!1;try{g=16===r.length&&(0,a.OP)(r).isolatedBacklog}catch(e){}var p={on:b,addEventListener:b,removeEventListener:y,emit:v,get:x,listeners:w,context:m,buffer:A,abort:h,aborted:!1,isBuffering:E,debugId:r,backlog:g?{}:t&&"object"==typeof t.backlog?t.backlog:{}};return p;function m(e){return e&&e instanceof d?e:e?(0,i.X)(e,s,l):l()}function v(e,r,n,i,o){if(!1!==o&&(o=!0),!u.aborted||i){t&&o&&t.emit(e,r,n);for(var a=m(n),s=w(e),d=s.length,f=0;fn,p:()=>i});var n=r(2177).ee.get("handle");function i(e,t,r,i,o){o?(o.buffer([e],i),o.emit(e,t,r)):(n.buffer([e],i),n.emit(e,t,r))}},4322:(e,t,r)=>{r.d(t,{X:()=>o});var n=r(5546);o.on=a;var i=o.handlers={};function o(e,t,r,o){a(o||n.E,i,e,t,r)}function a(e,t,r,i,o){o||(o="feature"),e||(e=n.E);var a=t[o]=t[o]||{};(a[r]=a[r]||[]).push([e,i])}},3239:(e,t,r)=>{r.d(t,{bP:()=>s,iz:()=>c,m$:()=>a});var n=r(385);let i=!1,o=!1;try{const e={get passive(){return i=!0,!1},get signal(){return o=!0,!1}};n._A.addEventListener("test",null,e),n._A.removeEventListener("test",null,e)}catch(e){}function a(e,t){return i||o?{capture:!!e,passive:i,signal:t}:!!e}function s(e,t){let r=arguments.length>2&&void 0!==arguments[2]&&arguments[2],n=arguments.length>3?arguments[3]:void 0;window.addEventListener(e,t,a(r,n))}function c(e,t){let r=arguments.length>2&&void 0!==arguments[2]&&arguments[2],n=arguments.length>3?arguments[3]:void 0;document.addEventListener(e,t,a(r,n))}},4402:(e,t,r)=>{r.d(t,{Ht:()=>u,M:()=>c,Rl:()=>a,ky:()=>s});var n=r(385);const i="xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx";function o(e,t){return e?15&e[t]:16*Math.random()|0}function a(){const e=n._A?.crypto||n._A?.msCrypto;let t,r=0;return e&&e.getRandomValues&&(t=e.getRandomValues(new Uint8Array(31))),i.split("").map((e=>"x"===e?o(t,++r).toString(16):"y"===e?(3&o()|8).toString(16):e)).join("")}function s(e){const t=n._A?.crypto||n._A?.msCrypto;let r,i=0;t&&t.getRandomValues&&(r=t.getRandomValues(new Uint8Array(31)));const a=[];for(var s=0;s {r.d(t,{Bq:()=>n,Hb:()=>o,oD:()=>i});const n="NRBA",i=144e5,o=18e5},7894:(e,t,r)=>{function n(){return Math.round(performance.now())}r.d(t,{z:()=>n})},7243:(e,t,r)=>{r.d(t,{e:()=>o});var n=r(385),i={};function o(e){if(e in i)return i[e];if(0===(e||"").indexOf("data:"))return{protocol:"data"};let t;var r=n._A?.location,o={};if(n.il)t=document.createElement("a"),t.href=e;else try{t=new URL(e,r.href)}catch(e){return o}o.port=t.port;var a=t.href.split("://");!o.port&&a[1]&&(o.port=a[1].split("/")[0].split("@").pop().split(":")[1]),o.port&&"0"!==o.port||(o.port="https"===a[0]?"443":"80"),o.hostname=t.hostname||r.hostname,o.pathname=t.pathname,o.protocol=a[0],"/"!==o.pathname.charAt(0)&&(o.pathname="/"+o.pathname);var s=!t.protocol||":"===t.protocol||t.protocol===r.protocol,c=t.hostname===r.hostname&&t.port===r.port;return o.sameOrigin=s&&(!t.hostname||c),"/"===o.pathname&&(i[e]=o),o}},50:(e,t,r)=>{function n(e,t){"function"==typeof console.warn&&(console.warn("New Relic: ".concat(e)),t&&console.warn(t))}r.d(t,{Z:()=>n})},2587:(e,t,r)=>{r.d(t,{N:()=>c,T:()=>u});var n=r(2177),i=r(5546),o=r(8e3),a=r(3325);const s={stn:[a.D.sessionTrace],err:[a.D.jserrors,a.D.metrics],ins:[a.D.pageAction],spa:[a.D.spa],sr:[a.D.sessionReplay,a.D.sessionTrace]};function c(e,t){const r=n.ee.get(t);e&&"object"==typeof e&&(Object.entries(e).forEach((e=>{let[t,n]=e;void 0===u[t]&&(s[t]?s[t].forEach((e=>{n?(0,i.p)("feat-"+t,[],void 0,e,r):(0,i.p)("block-"+t,[],void 0,e,r),(0,i.p)("rumresp-"+t,[Boolean(n)],void 0,e,r)})):n&&(0,i.p)("feat-"+t,[],void 0,void 0,r),u[t]=Boolean(n))})),Object.keys(s).forEach((e=>{void 0===u[e]&&(s[e]?.forEach((t=>(0,i.p)("rumresp-"+e,[!1],void 0,t,r))),u[e]=!1)})),(0,o.L)(t,a.D.pageViewEvent))}const u={}},2210:(e,t,r)=>{r.d(t,{X:()=>i});var n=Object.prototype.hasOwnProperty;function i(e,t,r){if(n.call(e,t))return e[t];var i=r();if(Object.defineProperty&&Object.keys)try{return Object.defineProperty(e,t,{value:i,writable:!0,enumerable:!1}),i}catch(e){}return e[t]=i,i}},1284:(e,t,r)=>{r.d(t,{D:()=>n});const n=(e,t)=>Object.entries(e||{}).map((e=>{let[r,n]=e;return t(r,n)}))},4351:(e,t,r)=>{r.d(t,{P:()=>o});var n=r(2177);const i=()=>{const e=new WeakSet;return(t,r)=>{if("object"==typeof r&&null!==r){if(e.has(r))return;e.add(r)}return r}};function o(e){try{return JSON.stringify(e,i())}catch(e){try{n.ee.emit("internal-error",[e])}catch(e){}}}},3960:(e,t,r)=>{r.d(t,{K:()=>a,b:()=>o});var n=r(3239);function i(){return"undefined"==typeof document||"complete"===document.readyState}function o(e,t){if(i())return e();(0,n.bP)("load",e,t)}function a(e){if(i())return e();(0,n.iz)("DOMContentLoaded",e)}},8632:(e,t,r)=>{r.d(t,{EZ:()=>u,Qy:()=>c,ce:()=>o,fP:()=>a,gG:()=>d,mF:()=>s});var n=r(7894),i=r(385);const o={beacon:"bam.nr-data.net",errorBeacon:"bam.nr-data.net"};function a(){return i._A.NREUM||(i._A.NREUM={}),void 0===i._A.newrelic&&(i._A.newrelic=i._A.NREUM),i._A.NREUM}function s(){let e=a();return e.o||(e.o={ST:i._A.setTimeout,SI:i._A.setImmediate,CT:i._A.clearTimeout,XHR:i._A.XMLHttpRequest,REQ:i._A.Request,EV:i._A.Event,PR:i._A.Promise,MO:i._A.MutationObserver,FETCH:i._A.fetch}),e}function c(e,t,r){let i=a();const o=i.initializedAgents||{},s=o[e]||{};return Object.keys(s).length||(s.initializedAt={ms:(0,n.z)(),date:new Date}),i.initializedAgents={...o,[e]:{...s,[r]:t}},i}function u(e,t){a()[e]=t}function d(){return function(){let e=a();const t=e.info||{};e.info={beacon:o.beacon,errorBeacon:o.errorBeacon,...t}}(),function(){let e=a();const t=e.init||{};e.init={...t}}(),s(),function(){let e=a();const t=e.loader_config||{};e.loader_config={...t}}(),a()}},7956:(e,t,r)=>{r.d(t,{N:()=>i});var n=r(3239);function i(e){let t=arguments.length>1&&void 0!==arguments[1]&&arguments[1],r=arguments.length>2?arguments[2]:void 0,i=arguments.length>3?arguments[3]:void 0;return void(0,n.iz)("visibilitychange",(function(){if(t)return void("hidden"==document.visibilityState&&e());e(document.visibilityState)}),r,i)}},1214:(e,t,r)=>{r.d(t,{em:()=>v,u5:()=>N,QU:()=>S,_L:()=>I,Gm:()=>L,Lg:()=>M,gy:()=>U,BV:()=>Q,Kf:()=>ee});var n=r(2177);const i="nr@original";var o=Object.prototype.hasOwnProperty,a=!1;function s(e,t){return e||(e=n.ee),r.inPlace=function(e,t,n,i,o){n||(n="");var a,s,c,u="-"===n.charAt(0);for(c=0;c 2?n-2:0),o=2;o {r(A[T],e,w),r(E[T],e,w)})),r(l._A,"fetch",y),t.on(y+"end",(function(e,r){var n=this;if(r){var i=r.headers.get("content-length");null!==i&&(n.rxSize=i),t.emit(y+"done",[null,r],n)}else t.emit(y+"done",[e],n)})),t}const O={},j=["pushState","replaceState"];function S(e){const t=function(e){return(e||n.ee).get("history")}(e);return!l.il||O[t.debugId]++||(O[t.debugId]=1,s(t).inPlace(window.history,j,"-")),t}var P=r(3239);const C={},R=["appendChild","insertBefore","replaceChild"];function I(e){const t=function(e){return(e||n.ee).get("jsonp")}(e);if(!l.il||C[t.debugId])return t;C[t.debugId]=!0;var r=s(t),i=/[?&](?:callback|cb)=([^&#]+)/,o=/(.*)\.([^.]+)/,a=/^(\w+)(\.|$)(.*)$/;function c(e,t){var r=e.match(a),n=r[1],i=r[3];return i?c(i,t[n]):t[n]}return r.inPlace(Node.prototype,R,"dom-"),t.on("dom-start",(function(e){!function(e){if(!e||"string"!=typeof e.nodeName||"script"!==e.nodeName.toLowerCase())return;if("function"!=typeof e.addEventListener)return;var n=(a=e.src,s=a.match(i),s?s[1]:null);var a,s;if(!n)return;var u=function(e){var t=e.match(o);if(t&&t.length>=3)return{key:t[2],parent:c(t[1],window)};return{key:e,parent:window}}(n);if("function"!=typeof u.parent[u.key])return;var d={};function f(){t.emit("jsonp-end",[],d),e.removeEventListener("load",f,(0,P.m$)(!1)),e.removeEventListener("error",l,(0,P.m$)(!1))}function l(){t.emit("jsonp-error",[],d),t.emit("jsonp-end",[],d),e.removeEventListener("load",f,(0,P.m$)(!1)),e.removeEventListener("error",l,(0,P.m$)(!1))}r.inPlace(u.parent,[u.key],"cb-",d),e.addEventListener("load",f,(0,P.m$)(!1)),e.addEventListener("error",l,(0,P.m$)(!1)),t.emit("new-jsonp",[e.src],d)}(e[0])})),t}var k=r(5763);const H={};function L(e){const t=function(e){return(e||n.ee).get("mutation")}(e);if(!l.il||H[t.debugId])return t;H[t.debugId]=!0;var r=s(t),i=k.Yu.MO;return i&&(window.MutationObserver=function(e){return this instanceof i?new i(r(e,"fn-")):i.apply(this,arguments)},MutationObserver.prototype=i.prototype),t}const z={};function M(e){const t=function(e){return(e||n.ee).get("promise")}(e);if(z[t.debugId])return t;z[t.debugId]=!0;var r=n.c,o=s(t),a=k.Yu.PR;return a&&function(){function e(r){var n=t.context(),i=o(r,"executor-",n,null,!1);const s=Reflect.construct(a,[i],e);return t.context(s).getCtx=function(){return n},s}l._A.Promise=e,Object.defineProperty(e,"name",{value:"Promise"}),e.toString=function(){return a.toString()},Object.setPrototypeOf(e,a),["all","race"].forEach((function(r){const n=a[r];e[r]=function(e){let i=!1;[...e||[]].forEach((e=>{this.resolve(e).then(a("all"===r),a(!1))}));const o=n.apply(this,arguments);return o;function a(e){return function(){t.emit("propagate",[null,!i],o,!1,!1),i=i||!e}}}})),["resolve","reject"].forEach((function(r){const n=a[r];e[r]=function(e){const r=n.apply(this,arguments);return e!==r&&t.emit("propagate",[e,!0],r,!1,!1),r}})),e.prototype=a.prototype;const n=a.prototype.then;a.prototype.then=function(){var e=this,i=r(e);i.promise=e;for(var a=arguments.length,s=new Array(a),c=0;c e())),t};function m(e,t){i.inPlace(t,["onreadystatechange"],"fn-",E)}function b(){var e=this,t=r.context(e);e.readyState>3&&!t.resolved&&(t.resolved=!0,r.emit("xhr-resolved",[],e)),i.inPlace(e,f,"fn-",E)}if(function(e,t){for(var r in e)t[r]=e[r]}(o,p),p.prototype=o.prototype,i.inPlace(p.prototype,J,"-xhr-",E),r.on("send-xhr-start",(function(e,t){m(e,t),function(e){h.push(e),a&&(y?y.then(A):u?u(A):(w=-w,x.data=w))}(t)})),r.on("open-xhr-start",m),a){var y=c&&c.resolve();if(!u&&!c){var w=1,x=document.createTextNode(w);new a(A).observe(x,{characterData:!0})}}else t.on("fn-end",(function(e){e[0]&&e[0].type===d||A()}));function A(){for(var e=0;e {r.d(t,{t:()=>n});const n=r(3325).D.ajax},6660:(e,t,r)=>{r.d(t,{A:()=>i,t:()=>n});const n=r(3325).D.jserrors,i="nr@seenError"},3081:(e,t,r)=>{r.d(t,{gF:()=>o,mY:()=>i,t9:()=>n,vz:()=>s,xS:()=>a});const n=r(3325).D.metrics,i="sm",o="cm",a="storeSupportabilityMetrics",s="storeEventMetrics"},4649:(e,t,r)=>{r.d(t,{t:()=>n});const n=r(3325).D.pageAction},7633:(e,t,r)=>{r.d(t,{Dz:()=>i,OJ:()=>a,qw:()=>o,t9:()=>n});const n=r(3325).D.pageViewEvent,i="firstbyte",o="domcontent",a="windowload"},9251:(e,t,r)=>{r.d(t,{t:()=>n});const n=r(3325).D.pageViewTiming},3614:(e,t,r)=>{r.d(t,{BST_RESOURCE:()=>i,END:()=>s,FEATURE_NAME:()=>n,FN_END:()=>u,FN_START:()=>c,PUSH_STATE:()=>d,RESOURCE:()=>o,START:()=>a});const n=r(3325).D.sessionTrace,i="bstResource",o="resource",a="-start",s="-end",c="fn"+a,u="fn"+s,d="pushState"},7836:(e,t,r)=>{r.d(t,{BODY:()=>A,CB_END:()=>E,CB_START:()=>u,END:()=>x,FEATURE_NAME:()=>i,FETCH:()=>_,FETCH_BODY:()=>v,FETCH_DONE:()=>m,FETCH_START:()=>p,FN_END:()=>c,FN_START:()=>s,INTERACTION:()=>l,INTERACTION_API:()=>d,INTERACTION_EVENTS:()=>o,JSONP_END:()=>b,JSONP_NODE:()=>g,JS_TIME:()=>T,MAX_TIMER_BUDGET:()=>a,REMAINING:()=>f,SPA_NODE:()=>h,START:()=>w,originalSetTimeout:()=>y});var n=r(5763);const i=r(3325).D.spa,o=["click","submit","keypress","keydown","keyup","change"],a=999,s="fn-start",c="fn-end",u="cb-start",d="api-ixn-",f="remaining",l="interaction",h="spaNode",g="jsonpNode",p="fetch-start",m="fetch-done",v="fetch-body-",b="jsonp-end",y=n.Yu.ST,w="-start",x="-end",A="-body",E="cb"+x,T="jsTime",_="fetch"},5938:(e,t,r)=>{r.d(t,{W:()=>o});var n=r(5763),i=r(2177);class o{constructor(e,t,r){this.agentIdentifier=e,this.aggregator=t,this.ee=i.ee.get(e,(0,n.OP)(this.agentIdentifier).isolatedBacklog),this.featureName=r,this.blocked=!1}}},9144:(e,t,r)=>{r.d(t,{j:()=>m});var n=r(3325),i=r(5763),o=r(5546),a=r(2177),s=r(7894),c=r(8e3),u=r(3960),d=r(385),f=r(50),l=r(3081),h=r(8632);function g(){const e=(0,h.gG)();["setErrorHandler","finished","addToTrace","inlineHit","addRelease","addPageAction","setCurrentRouteName","setPageViewName","setCustomAttribute","interaction","noticeError","setUserId"].forEach((t=>{e[t]=function(){for(var r=arguments.length,n=new Array(r),i=0;i 1?r-1:0),i=1;i {e.exposed&&e.api[t]&&o.push(e.api[t](...n))})),o.length>1?o:o[0]}(t,...n)}}))}var p=r(2587);function m(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:{},m=arguments.length>2?arguments[2]:void 0,v=arguments.length>3?arguments[3]:void 0,{init:b,info:y,loader_config:w,runtime:x={loaderType:m},exposed:A=!0}=t;const E=(0,h.gG)();y||(b=E.init,y=E.info,w=E.loader_config),(0,i.Dg)(e,b||{}),(0,i.GE)(e,w||{}),(0,i.sU)(e,x),y.jsAttributes??={},d.v6&&(y.jsAttributes.isWorker=!0),(0,i.CX)(e,y),g();const T=function(e,t){t||(0,c.R)(e,"api");const h={};var g=a.ee.get(e),p=g.get("tracer"),m="api-",v=m+"ixn-";function b(t,r,n,o){const a=(0,i.C5)(e);return null===r?delete a.jsAttributes[t]:(0,i.CX)(e,{...a,jsAttributes:{...a.jsAttributes,[t]:r}}),x(m,n,!0,o||null===r?"session":void 0)(t,r)}function y(){}["setErrorHandler","finished","addToTrace","inlineHit","addRelease"].forEach((e=>h[e]=x(m,e,!0,"api"))),h.addPageAction=x(m,"addPageAction",!0,n.D.pageAction),h.setCurrentRouteName=x(m,"routeName",!0,n.D.spa),h.setPageViewName=function(t,r){if("string"==typeof t)return"/"!==t.charAt(0)&&(t="/"+t),(0,i.OP)(e).customTransaction=(r||"http://custom.transaction")+t,x(m,"setPageViewName",!0)()},h.setCustomAttribute=function(e,t){let r=arguments.length>2&&void 0!==arguments[2]&&arguments[2];if("string"==typeof e){if(["string","number"].includes(typeof t)||null===t)return b(e,t,"setCustomAttribute",r);(0,f.Z)("Failed to execute setCustomAttribute.\nNon-null value must be a string or number type, but a type of was provided."))}else(0,f.Z)("Failed to execute setCustomAttribute.\nName must be a string type, but a type of was provided."))},h.setUserId=function(e){if("string"==typeof e||null===e)return b("enduser.id",e,"setUserId",!0);(0,f.Z)("Failed to execute setUserId.\nNon-null value must be a string type, but a type of was provided."))},h.interaction=function(){return(new y).get()};var w=y.prototype={createTracer:function(e,t){var r={},i=this,a="function"==typeof t;return(0,o.p)(v+"tracer",[(0,s.z)(),e,r],i,n.D.spa,g),function(){if(p.emit((a?"":"no-")+"fn-start",[(0,s.z)(),i,a],r),a)try{return t.apply(this,arguments)}catch(e){throw p.emit("fn-err",[arguments,this,"string"==typeof e?new Error(e):e],r),e}finally{p.emit("fn-end",[(0,s.z)()],r)}}}};function x(e,t,r,i){return function(){return(0,o.p)(l.xS,["API/"+t+"/called"],void 0,n.D.metrics,g),i&&(0,o.p)(e+t,[(0,s.z)(),...arguments],r?null:this,i,g),r?void 0:this}}function A(){r.e(439).then(r.bind(r,7438)).then((t=>{let{setAPI:r}=t;r(e),(0,c.L)(e,"api")})).catch((()=>(0,f.Z)("Downloading runtime APIs failed...")))}return["actionText","setName","setAttribute","save","ignore","onEnd","getContext","end","get"].forEach((e=>{w[e]=x(v,e,void 0,n.D.spa)})),h.noticeError=function(e,t){"string"==typeof e&&(e=new Error(e)),(0,o.p)(l.xS,["API/noticeError/called"],void 0,n.D.metrics,g),(0,o.p)("err",[e,(0,s.z)(),!1,t],void 0,n.D.jserrors,g)},d.il?(0,u.b)((()=>A()),!0):A(),h}(e,v);return(0,h.Qy)(e,T,"api"),(0,h.Qy)(e,A,"exposed"),(0,h.EZ)("activatedFeatures",p.T),T}},3325:(e,t,r)=>{r.d(t,{D:()=>n,p:()=>i});const n={ajax:"ajax",jserrors:"jserrors",metrics:"metrics",pageAction:"page_action",pageViewEvent:"page_view_event",pageViewTiming:"page_view_timing",sessionReplay:"session_replay",sessionTrace:"session_trace",spa:"spa"},i={[n.pageViewEvent]:1,[n.pageViewTiming]:2,[n.metrics]:3,[n.jserrors]:4,[n.ajax]:5,[n.sessionTrace]:6,[n.pageAction]:7,[n.spa]:8,[n.sessionReplay]:9}}},n={};function i(e){var t=n[e];if(void 0!==t)return t.exports;var o=n[e]={exports:{}};return r[e](o,o.exports,i),o.exports}i.m=r,i.d=(e,t)=>{for(var r in t)i.o(t,r)&&!i.o(e,r)&&Object.defineProperty(e,r,{enumerable:!0,get:t[r]})},i.f={},i.e=e=>Promise.all(Object.keys(i.f).reduce(((t,r)=>(i.f[r](e,t),t)),[])),i.u=e=>(({78:"page_action-aggregate",147:"metrics-aggregate",242:"session-manager",317:"jserrors-aggregate",348:"page_view_timing-aggregate",412:"lazy-feature-loader",439:"async-api",538:"recorder",590:"session_replay-aggregate",675:"compressor",733:"session_trace-aggregate",786:"page_view_event-aggregate",873:"spa-aggregate",898:"ajax-aggregate"}[e]||e)+"."+{78:"ac76d497",147:"3dc53903",148:"1a20d5fe",242:"2a64278a",317:"49e41428",348:"bd6de33a",412:"2f55ce66",439:"30bd804e",538:"1b18459f",590:"cf0efb30",675:"ae9f91a8",733:"83105561",786:"06482edd",860:"03a8b7a5",873:"e6b09d52",898:"998ef92b"}[e]+"-1.236.0.min.js"),i.o=(e,t)=>Object.prototype.hasOwnProperty.call(e,t),e={},t="NRBA:",i.l=(r,n,o,a)=>{if(e[r])e[r].push(n);else{var s,c;if(void 0!==o)for(var u=document.getElementsByTagName("script"),d=0;d {s.onerror=s.onload=null,clearTimeout(h);var i=e[r];if(delete e[r],s.parentNode&&s.parentNode.removeChild(s),i&&i.forEach((e=>e(n))),t)return t(n)},h=setTimeout(l.bind(null,void 0,{type:"timeout",target:s}),12e4);s.onerror=l.bind(null,s.onerror),s.onload=l.bind(null,s.onload),c&&document.head.appendChild(s)}},i.r=e=>{"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})},i.j=364,i.p="https://js-agent.newrelic.com/",(()=>{var e={364:0,953:0};i.f.j=(t,r)=>{var n=i.o(e,t)?e[t]:void 0;if(0!==n)if(n)r.push(n[2]);else{var o=new Promise(((r,i)=>n=e[t]=[r,i]));r.push(n[2]=o);var a=i.p+i.u(t),s=new Error;i.l(a,(r=>{if(i.o(e,t)&&(0!==(n=e[t])&&(e[t]=void 0),n)){var o=r&&("load"===r.type?"missing":r.type),a=r&&r.target&&r.target.src;s.message="Loading chunk "+t+" failed.\n("+o+": "+a+")",s.name="ChunkLoadError",s.type=o,s.request=a,n[1](s)}}),"chunk-"+t,t)}};var t=(t,r)=>{var n,o,[a,s,c]=r,u=0;if(a.some((t=>0!==e[t]))){for(n in s)i.o(s,n)&&(i.m[n]=s[n]);if(c)c(i)}for(t&&t(r);u {i.r(o);var e=i(3325),t=i(5763);const r=Object.values(e.D);function n(e){const n={};return r.forEach((r=>{n[r]=function(e,r){return!1!==(0,t.Mt)(r,"".concat(e,".enabled"))}(r,e)})),n}var a=i(9144);var s=i(5546),c=i(385),u=i(8e3),d=i(5938),f=i(3960),l=i(50);class h extends d.W{constructor(e,t,r){let n=!(arguments.length>3&&void 0!==arguments[3])||arguments[3];super(e,t,r),this.auto=n,this.abortHandler,this.featAggregate,this.onAggregateImported,n&&(0,u.R)(e,r)}importAggregator(){let e=arguments.length>0&&void 0!==arguments[0]?arguments[0]:{};if(this.featAggregate||!this.auto)return;const r=c.il&&!0===(0,t.Mt)(this.agentIdentifier,"privacy.cookies_enabled");let n;this.onAggregateImported=new Promise((e=>{n=e}));const o=async()=>{let t;try{if(r){const{setupAgentSession:e}=await Promise.all([i.e(860),i.e(242)]).then(i.bind(i,3228));t=e(this.agentIdentifier)}}catch(e){(0,l.Z)("A problem occurred when starting up session manager. This page will not start or extend any session.",e)}try{if(!this.shouldImportAgg(this.featureName,t))return void(0,u.L)(this.agentIdentifier,this.featureName);const{lazyFeatureLoader:r}=await i.e(412).then(i.bind(i,8582)),{Aggregate:o}=await r(this.featureName,"aggregate");this.featAggregate=new o(this.agentIdentifier,this.aggregator,e),n(!0)}catch(e){(0,l.Z)("Downloading and initializing ".concat(this.featureName," failed..."),e),this.abortHandler?.(),n(!1)}};c.il?(0,f.b)((()=>o()),!0):o()}shouldImportAgg(r,n){return r!==e.D.sessionReplay||!1!==(0,t.Mt)(this.agentIdentifier,"session_trace.enabled")&&(!!n?.isNew||!!n?.state.sessionReplay)}}var g=i(7633),p=i(7894);class m extends h{static featureName=g.t9;constructor(r,n){let i=!(arguments.length>2&&void 0!==arguments[2])||arguments[2];if(super(r,n,g.t9,i),("undefined"==typeof PerformanceNavigationTiming||c.Tt)&&"undefined"!=typeof PerformanceTiming){const n=(0,t.OP)(r);n[g.Dz]=Math.max(Date.now()-n.offset,0),(0,f.K)((()=>n[g.qw]=Math.max((0,p.z)()-n[g.Dz],0))),(0,f.b)((()=>{const t=(0,p.z)();n[g.OJ]=Math.max(t-n[g.Dz],0),(0,s.p)("timing",["load",t],void 0,e.D.pageViewTiming,this.ee)}))}this.importAggregator()}}var v=i(1117),b=i(1284);class y extends v.w{constructor(e){super(e),this.aggregatedData={}}store(e,t,r,n,i){var o=this.getBucket(e,t,r,i);return o.metrics=function(e,t){t||(t={count:0});return t.count+=1,(0,b.D)(e,(function(e,r){t[e]=w(r,t[e])})),t}(n,o.metrics),o}merge(e,t,r,n,i){var o=this.getBucket(e,t,n,i);if(o.metrics){var a=o.metrics;a.count+=r.count,(0,b.D)(r,(function(e,t){if("count"!==e){var n=a[e],i=r[e];i&&!i.c?a[e]=w(i.t,n):a[e]=function(e,t){if(!t)return e;t.c||(t=x(t.t));return t.min=Math.min(e.min,t.min),t.max=Math.max(e.max,t.max),t.t+=e.t,t.sos+=e.sos,t.c+=e.c,t}(i,a[e])}}))}else o.metrics=r}storeMetric(e,t,r,n){var i=this.getBucket(e,t,r);return i.stats=w(n,i.stats),i}getBucket(e,t,r,n){this.aggregatedData[e]||(this.aggregatedData[e]={});var i=this.aggregatedData[e][t];return i||(i=this.aggregatedData[e][t]={params:r||{}},n&&(i.custom=n)),i}get(e,t){return t?this.aggregatedData[e]&&this.aggregatedData[e][t]:this.aggregatedData[e]}take(e){for(var t={},r="",n=!1,i=0;i t.max&&(t.max=e),e 2&&void 0!==arguments[2])||arguments[2];super(e,r,j.t,n),c.il&&((0,t.OP)(e).initHidden=Boolean("hidden"===document.visibilityState),(0,N.N)((()=>(0,s.p)("docHidden",[(0,p.z)()],void 0,j.t,this.ee)),!0),(0,O.bP)("pagehide",(()=>(0,s.p)("winPagehide",[(0,p.z)()],void 0,j.t,this.ee))),this.importAggregator())}}var P=i(3081);class C extends h{static featureName=P.t9;constructor(e,t){let r=!(arguments.length>2&&void 0!==arguments[2])||arguments[2];super(e,t,P.t9,r),this.importAggregator()}}var R,I=i(2210),k=i(1214),H=i(2177),L={};try{R=localStorage.getItem("__nr_flags").split(","),console&&"function"==typeof console.log&&(L.console=!0,-1!==R.indexOf("dev")&&(L.dev=!0),-1!==R.indexOf("nr_dev")&&(L.nrDev=!0))}catch(e){}function z(e){try{L.console&&z(e)}catch(e){}}L.nrDev&&H.ee.on("internal-error",(function(e){z(e.stack)})),L.dev&&H.ee.on("fn-err",(function(e,t,r){z(r.stack)})),L.dev&&(z("NR AGENT IN DEVELOPMENT MODE"),z("flags: "+(0,b.D)(L,(function(e,t){return e})).join(", ")));var M=i(6660);class B extends h{static featureName=M.t;constructor(r,n){let i=!(arguments.length>2&&void 0!==arguments[2])||arguments[2];super(r,n,M.t,i),this.skipNext=0;try{this.removeOnAbort=new AbortController}catch(e){}const o=this;o.ee.on("fn-start",(function(e,t,r){o.abortHandler&&(o.skipNext+=1)})),o.ee.on("fn-err",(function(t,r,n){o.abortHandler&&!n[M.A]&&((0,I.X)(n,M.A,(function(){return!0})),this.thrown=!0,(0,s.p)("err",[n,(0,p.z)()],void 0,e.D.jserrors,o.ee))})),o.ee.on("fn-end",(function(){o.abortHandler&&!this.thrown&&o.skipNext>0&&(o.skipNext-=1)})),o.ee.on("internal-error",(function(t){(0,s.p)("ierr",[t,(0,p.z)(),!0],void 0,e.D.jserrors,o.ee)})),this.origOnerror=c._A.onerror,c._A.onerror=this.onerrorHandler.bind(this),c._A.addEventListener("unhandledrejection",(t=>{const r=function(e){let t="Unhandled Promise Rejection: ";if(e instanceof Error)try{return e.message=t+e.message,e}catch(t){return e}if(void 0===e)return new Error(t);try{return new Error(t+(0,D.P)(e))}catch(e){return new Error(t)}}(t.reason);(0,s.p)("err",[r,(0,p.z)(),!1,{unhandledPromiseRejection:1}],void 0,e.D.jserrors,this.ee)}),(0,O.m$)(!1,this.removeOnAbort?.signal)),(0,k.gy)(this.ee),(0,k.BV)(this.ee),(0,k.em)(this.ee),(0,t.OP)(r).xhrWrappable&&(0,k.Kf)(this.ee),this.abortHandler=this.#e,this.importAggregator()}#e(){this.removeOnAbort?.abort(),this.abortHandler=void 0}onerrorHandler(t,r,n,i,o){"function"==typeof this.origOnerror&&this.origOnerror(...arguments);try{this.skipNext?this.skipNext-=1:(0,s.p)("err",[o||new F(t,r,n),(0,p.z)()],void 0,e.D.jserrors,this.ee)}catch(t){try{(0,s.p)("ierr",[t,(0,p.z)(),!0],void 0,e.D.jserrors,this.ee)}catch(e){}}return!1}}function F(e,t,r){this.message=e||"Uncaught error with no additional information",this.sourceURL=t,this.line=r}let U=1;const q="nr@id";function G(e){const t=typeof e;return!e||"object"!==t&&"function"!==t?-1:e===c._A?0:(0,I.X)(e,q,(function(){return U++}))}function V(e){if("string"==typeof e&&e.length)return e.length;if("object"==typeof e){if("undefined"!=typeof ArrayBuffer&&e instanceof ArrayBuffer&&e.byteLength)return e.byteLength;if("undefined"!=typeof Blob&&e instanceof Blob&&e.size)return e.size;if(!("undefined"!=typeof FormData&&e instanceof FormData))try{return(0,D.P)(e).length}catch(e){return}}}var X=i(7243);class W{constructor(e){this.agentIdentifier=e,this.generateTracePayload=this.generateTracePayload.bind(this),this.shouldGenerateTrace=this.shouldGenerateTrace.bind(this)}generateTracePayload(e){if(!this.shouldGenerateTrace(e))return null;var r=(0,t.DL)(this.agentIdentifier);if(!r)return null;var n=(r.accountID||"").toString()||null,i=(r.agentID||"").toString()||null,o=(r.trustKey||"").toString()||null;if(!n||!i)return null;var a=(0,_.M)(),s=(0,_.Ht)(),c=Date.now(),u={spanId:a,traceId:s,timestamp:c};return(e.sameOrigin||this.isAllowedOrigin(e)&&this.useTraceContextHeadersForCors())&&(u.traceContextParentHeader=this.generateTraceContextParentHeader(a,s),u.traceContextStateHeader=this.generateTraceContextStateHeader(a,c,n,i,o)),(e.sameOrigin&&!this.excludeNewrelicHeader()||!e.sameOrigin&&this.isAllowedOrigin(e)&&this.useNewrelicHeaderForCors())&&(u.newrelicHeader=this.generateTraceHeader(a,s,c,n,i,o)),u}generateTraceContextParentHeader(e,t){return"00-"+t+"-"+e+"-01"}generateTraceContextStateHeader(e,t,r,n,i){return i+"@nr=0-1-"+r+"-"+n+"-"+e+"----"+t}generateTraceHeader(e,t,r,n,i,o){if(!("function"==typeof c._A?.btoa))return null;var a={v:[0,1],d:{ty:"Browser",ac:n,ap:i,id:e,tr:t,ti:r}};return o&&n!==o&&(a.d.tk=o),btoa((0,D.P)(a))}shouldGenerateTrace(e){return this.isDtEnabled()&&this.isAllowedOrigin(e)}isAllowedOrigin(e){var r=!1,n={};if((0,t.Mt)(this.agentIdentifier,"distributed_tracing")&&(n=(0,t.P_)(this.agentIdentifier).distributed_tracing),e.sameOrigin)r=!0;else if(n.allowed_origins instanceof Array)for(var i=0;i 2&&void 0!==arguments[2])||arguments[2];super(r,n,Z.t,i),(0,t.OP)(r).xhrWrappable&&(this.dt=new W(r),this.handler=(e,t,r,n)=>(0,s.p)(e,t,r,n,this.ee),(0,k.u5)(this.ee),(0,k.Kf)(this.ee),function(r,n,i,o){function a(e){var t=this;t.totalCbs=0,t.called=0,t.cbTime=0,t.end=E,t.ended=!1,t.xhrGuids={},t.lastSize=null,t.loadCaptureCalled=!1,t.params=this.params||{},t.metrics=this.metrics||{},e.addEventListener("load",(function(r){_(t,e)}),(0,O.m$)(!1)),c.IF||e.addEventListener("progress",(function(e){t.lastSize=e.loaded}),(0,O.m$)(!1))}function s(e){this.params={method:e[0]},T(this,e[1]),this.metrics={}}function u(e,n){var i=(0,t.DL)(r);i.xpid&&this.sameOrigin&&n.setRequestHeader("X-NewRelic-ID",i.xpid);var a=o.generateTracePayload(this.parsedOrigin);if(a){var s=!1;a.newrelicHeader&&(n.setRequestHeader("newrelic",a.newrelicHeader),s=!0),a.traceContextParentHeader&&(n.setRequestHeader("traceparent",a.traceContextParentHeader),a.traceContextStateHeader&&n.setRequestHeader("tracestate",a.traceContextStateHeader),s=!0),s&&(this.dt=a)}}function d(e,t){var r=this.metrics,i=e[0],o=this;if(r&&i){var a=V(i);a&&(r.txSize=a)}this.startTime=(0,p.z)(),this.listener=function(e){try{"abort"!==e.type||o.loadCaptureCalled||(o.params.aborted=!0),("load"!==e.type||o.called===o.totalCbs&&(o.onloadCalled||"function"!=typeof t.onload)&&"function"==typeof o.end)&&o.end(t)}catch(e){try{n.emit("internal-error",[e])}catch(e){}}};for(var s=0;s 1?e[1]=i:e.push(i)}else e[0]&&e[0].headers&&s(e[0].headers,n)&&(this.dt=n);function s(e,t){var r=!1;return t.newrelicHeader&&(e.set("newrelic",t.newrelicHeader),r=!0),t.traceContextParentHeader&&(e.set("traceparent",t.traceContextParentHeader),t.traceContextStateHeader&&e.set("tracestate",t.traceContextStateHeader),r=!0),r}}function x(e,t){this.params={},this.metrics={},this.startTime=(0,p.z)(),this.dt=t,e.length>=1&&(this.target=e[0]),e.length>=2&&(this.opts=e[1]);var r,n=this.opts||{},i=this.target;"string"==typeof i?r=i:"object"==typeof i&&i instanceof Y?r=i.url:c._A?.URL&&"object"==typeof i&&i instanceof URL&&(r=i.href),T(this,r);var o=(""+(i&&i instanceof Y&&i.method||n.method||"GET")).toUpperCase();this.params.method=o,this.txSize=V(n.body)||0}function A(t,r){var n;this.endTime=(0,p.z)(),this.params||(this.params={}),this.params.status=r?r.status:0,"string"==typeof this.rxSize&&this.rxSize.length>0&&(n=+this.rxSize);var o={txSize:this.txSize,rxSize:n,duration:(0,p.z)()-this.startTime};i("xhr",[this.params,o,this.startTime,this.endTime,"fetch"],this,e.D.ajax)}function E(t){var r=this.params,n=this.metrics;if(!this.ended){this.ended=!0;for(var o=0;o 2&&void 0!==arguments[2])||arguments[2];super(e,t,we.t,r),this.importAggregator()}}new class{constructor(e){let t=arguments.length>1&&void 0!==arguments[1]?arguments[1]:(0,_.ky)(16);c._A?(this.agentIdentifier=t,this.sharedAggregator=new y({agentIdentifier:this.agentIdentifier}),this.features={},this.desiredFeatures=new Set(e.features||[]),this.desiredFeatures.add(m),Object.assign(this,(0,a.j)(this.agentIdentifier,e,e.loaderType||"agent")),this.start()):(0,l.Z)("Failed to initial the agent. Could not determine the runtime environment.")}get config(){return{info:(0,t.C5)(this.agentIdentifier),init:(0,t.P_)(this.agentIdentifier),loader_config:(0,t.DL)(this.agentIdentifier),runtime:(0,t.OP)(this.agentIdentifier)}}start(){const t="features";try{const r=n(this.agentIdentifier),i=[...this.desiredFeatures];i.sort(((t,r)=>e.p[t.featureName]-e.p[r.featureName])),i.forEach((t=>{if(r[t.featureName]||t.featureName===e.D.pageViewEvent){const n=function(t){switch(t){case e.D.ajax:return[e.D.jserrors];case e.D.sessionTrace:return[e.D.ajax,e.D.pageViewEvent];case e.D.sessionReplay:return[e.D.sessionTrace];case e.D.pageViewTiming:return[e.D.pageViewEvent];default:return[]}}(t.featureName);n.every((e=>r[e]))||(0,l.Z)("".concat(t.featureName," is enabled but one or more dependent features has been disabled (").concat((0,D.P)(n),"). This may cause unintended consequences or missing data...")),this.features[t.featureName]=new t(this.agentIdentifier,this.sharedAggregator)}})),(0,T.Qy)(this.agentIdentifier,this.features,t)}catch(e){(0,l.Z)("Failed to initialize all enabled instrument classes (agent aborted) -",e);for(const e in this.features)this.features[e].abortHandler?.();const r=(0,T.fP)();return delete r.initializedAgents[this.agentIdentifier]?.api,delete r.initializedAgents[this.agentIdentifier]?.[t],delete this.sharedAggregator,r.ee?.abort(),delete r.ee?.get(this.agentIdentifier),!1}}}({features:[J,m,S,class extends h{static featureName=oe;constructor(t,r){if(super(t,r,oe,!(arguments.length>2&&void 0!==arguments[2])||arguments[2]),!c.il)return;const n=this.ee;let i;(0,k.QU)(n),this.eventsEE=(0,k.em)(n),this.eventsEE.on(se,(function(e,t){this.bstStart=(0,p.z)()})),this.eventsEE.on(ae,(function(t,r){(0,s.p)("bst",[t[0],r,this.bstStart,(0,p.z)()],void 0,e.D.sessionTrace,n)})),n.on(ce+ne,(function(e){this.time=(0,p.z)(),this.startPath=location.pathname+location.hash})),n.on(ce+ie,(function(t){(0,s.p)("bstHist",[location.pathname+location.hash,this.startPath,this.time],void 0,e.D.sessionTrace,n)}));try{i=new PerformanceObserver((t=>{const r=t.getEntries();(0,s.p)(te,[r],void 0,e.D.sessionTrace,n)})),i.observe({type:re,buffered:!0})}catch(e){}this.importAggregator({resourceObserver:i})}},C,xe,B,class extends h{static featureName=de;constructor(e,r){if(super(e,r,de,!(arguments.length>2&&void 0!==arguments[2])||arguments[2]),!c.il)return;if(!(0,t.OP)(e).xhrWrappable)return;try{this.removeOnAbort=new AbortController}catch(e){}let n,i=0;const o=this.ee.get("tracer"),a=(0,k._L)(this.ee),s=(0,k.Lg)(this.ee),u=(0,k.BV)(this.ee),d=(0,k.Kf)(this.ee),f=this.ee.get("events"),l=(0,k.u5)(this.ee),h=(0,k.QU)(this.ee),g=(0,k.Gm)(this.ee);function m(e,t){h.emit("newURL",[""+window.location,t])}function v(){i++,n=window.location.hash,this[ve]=(0,p.z)()}function b(){i--,window.location.hash!==n&&m(0,!0);var e=(0,p.z)();this[pe]=~~this[pe]+e-this[ve],this[ye]=e}function y(e,t){e.on(t,(function(){this[t]=(0,p.z)()}))}this.ee.on(ve,v),s.on(be,v),a.on(be,v),this.ee.on(ye,b),s.on(ge,b),a.on(ge,b),this.ee.buffer([ve,ye,"xhr-resolved"],this.featureName),f.buffer([ve],this.featureName),u.buffer(["setTimeout"+le,"clearTimeout"+fe,ve],this.featureName),d.buffer([ve,"new-xhr","send-xhr"+fe],this.featureName),l.buffer([me+fe,me+"-done",me+he+fe,me+he+le],this.featureName),h.buffer(["newURL"],this.featureName),g.buffer([ve],this.featureName),s.buffer(["propagate",be,ge,"executor-err","resolve"+fe],this.featureName),o.buffer([ve,"no-"+ve],this.featureName),a.buffer(["new-jsonp","cb-start","jsonp-error","jsonp-end"],this.featureName),y(l,me+fe),y(l,me+"-done"),y(a,"new-jsonp"),y(a,"jsonp-end"),y(a,"cb-start"),h.on("pushState-end",m),h.on("replaceState-end",m),window.addEventListener("hashchange",m,(0,O.m$)(!0,this.removeOnAbort?.signal)),window.addEventListener("load",m,(0,O.m$)(!0,this.removeOnAbort?.signal)),window.addEventListener("popstate",(function(){m(0,i>1)}),(0,O.m$)(!0,this.removeOnAbort?.signal)),this.abortHandler=this.#e,this.importAggregator()}#e(){this.removeOnAbort?.abort(),this.abortHandler=void 0}}],loaderType:"spa"})})(),window.NRBA=o})(); window.jQuery || document.write(' ') CKEDITOR_BASEPATH='https://f1000research.com/js/vendor/ckeditor/' window.reactTheme = 'research'; window.MathJax = { CommonHTML: { linebreaks: { automatic: true } }, 'HTML-CSS': { linebreaks: { automatic: true } }, SVG: { linebreaks: { automatic: true } }, AuthorInit: function() { MathJax.Hub.Register.MessageHook('End Process', function () { let timeout = false; // holder for timeout id const delay = 250; // delay after event is "complete" to run callback const reflowMath = function() { const dispFormulas = document.querySelectorAll('.disp-formula.panel'); if (!dispFormulas) { return; } for (const dispFormula of dispFormulas) { const child = dispFormula.querySelector('.MathJax_Preview').nextSibling.firstChild; const isMultiline = MathJax.Hub.getAllJax(dispFormula)[0].root.isMultiline; if (dispFormula.offsetWidth < child.offsetWidth || isMultiline) { MathJax.Hub.Queue(['Rerender', MathJax.Hub, dispFormula]); } } }; window.addEventListener('resize', function() { clearTimeout(timeout); // clear the timeout timeout = setTimeout(reflowMath, delay); // start timing for event "completion" }); }); }, }; if (window.location.hash == '#_=_'){ window.location = window.location.href.split('#')[0] } !function(f,b,e,v,n,t,s){if(f.fbq)return;n=f.fbq=function() {n.callMethod? n.callMethod.apply(n,arguments):n.queue.push(arguments)} ;if(!f._fbq)f._fbq=n; n.push=n;n.loaded=!0;n.version='2.0';n.queue=[];t=b.createElement(e);t.async=!0; t.src=v;s=b.getElementsByTagName(e)[0];s.parentNode.insertBefore(t,s)}(window, document,'script','https://connect.facebook.net/en_US/fbevents.js'); fbq('init', '1641728616063202'); fbq('track', "PixelInitialized", {}); (function(h,o,t,j,a,r){ h.hj=h.hj||function(){(h.hj.q=h.hj.q||[]).push(arguments)}; h._hjSettings={hjid:2318163,hjsv:6}; a=o.getElementsByTagName('head')[0]; r=o.createElement('script');r.async=1; r.src=t+h._hjSettings.hjid+j+h._hjSettings.hjsv; a.appendChild(r); })(window,document,'https://static.hotjar.com/c/hotjar-','.js?sv='); search file_upload Submit your research search menu close search Browse Gateways & Collections How to Publish Submit your Research My Submissions Article Guidelines Article Guidelines (New Versions) Open Data, Software and Code Guidelines Open Data and Accessible Source Materials Guidelines (HSS) Open Data, Software and Code Guidelines (PSE) Prepublication Checks Production Process Posters and Slides Guidelines Document Guidelines Article Processing Charges Peer Review Finding Article Reviewers About How it Works For Reviewers Our Advisors Policies Glossary FAQs For Developers Newsroom Contact My Research Submissions Content and Tracking Alerts My Details Sign In file_upload Submit your research { "@context": "https://schema.org", "@type": "ScholarlyArticle", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://f1000research.com/articles/14-1327" }, "headline": "Possible security threats coming from IOT medicine sensor calibration process", "datePublished": "2025-11-27T16:16:15", "dateModified": "2025-11-27T16:16:15", "author": [ { "@type": "Person", "name": "Laimonas Kairiukstis" }, { "@type": "Person", "name": "Kamilė Kairiūkštytė" }, { "@type": "Person", "name": "Edvinas Norvilas" } ], "publisher": { "@type": "Organization", "name": "F1000Research", "logo": { "@type": "ImageObject", "url": "https://f1000research.com/img/AMP/F1000Research_image.png", "height": 480, "width": 60 } }, "image": { "@type": "ImageObject", "url": "https://f1000research.com/img/AMP/F1000Research_image.png", "height": 1200, "width": 150 }, "description": "The global deployment of over seven billion IoT measuring devices in critical fields like healthcare and industrial safety systems exposes a pressing vulnerability to cyber-attacks, where compromised data integrity can lead to severe financial or life-threatening incidents. Calibration is the fundamental process ensuring measurement uniformity, yet the immense scale of the IoT makes traditional laboratory calibration physically impossible. Consequently, the calibration process must migrate on-site, relying on remote communication with calibration standards—a paradigm known as Calibration as a Service (CaaS). This digital shift, however, introduces significant cybersecurity risks into the very foundation of measurement trust. This paper addresses this critical challenge by presenting a comprehensive Standard Operating Procedure (SOP) for Secure IoT Measuring System Calibration. The proposed framework establishes the necessary protocols to protect the calibration process within a CaaS infrastructure. We further emphasize that the development and deployment of such secure IoT systems necessitate dedicated collaboration between IT security specialists and domain experts, ensuring that device integrity is prioritized from inception to safeguard end-users in an increasingly connected and vulnerable digital ecosystem." } { "@context": "http://schema.org", "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": "1", "item": { "@id": "https://f1000research.com/", "name": "Home" } }, { "@type": "ListItem", "position": "2", "item": { "@id": "https://f1000research.com/browse/articles", "name": "Browse" } }, { "@type": "ListItem", "position": "3", "item": { "@id": "https://f1000research.com/articles/14-1327", "name": "Possible security threats coming from IOT medicine sensor calibration..." } } ] } Home Browse Possible security threats coming from IOT medicine sensor calibration... ALL Metrics - Views Downloads Get PDF Get XML Cite How to cite this article Kairiukstis L, Kairiūkštytė K and Norvilas E. Possible security threats coming from IOT medicine sensor calibration process [version 1; peer review: 1 approved with reservations] . F1000Research 2025, 14 :1327 ( https://doi.org/10.12688/f1000research.172017.1 ) NOTE: If applicable, it is important to ensure the information in square brackets after the title is included in all citations of this article. Close Copy Citation Details Export Export Citation Sciwheel EndNote Ref. Manager Bibtex ProCite Sente EXPORT Select a format first Track Share ▬ ✚ Review Possible security threats coming from IOT medicine sensor calibration process [version 1; peer review: 1 approved with reservations] Laimonas Kairiukstis https://orcid.org/0009-0000-2102-9070 1 , Kamilė Kairiūkštytė 1 , Edvinas Norvilas 1 Laimonas Kairiukstis https://orcid.org/0009-0000-2102-9070 1 , Kamilė Kairiūkštytė 1 , Edvinas Norvilas 1 PUBLISHED 27 Nov 2025 Author details Author details 1 Lietuvos Inžinerijos Kolegija Higher Education Institution, Tvirtoves al. 35, 50155 Kaunas, Lithuania Laimonas Kairiukstis Roles: Conceptualization, Formal Analysis, Methodology, Supervision, Writing – Review & Editing Kamilė Kairiūkštytė Roles: Writing – Original Draft Preparation, Writing – Review & Editing Edvinas Norvilas Roles: Resources, Visualization, Writing – Original Draft Preparation, Writing – Review & Editing OPEN PEER REVIEW DETAILS REVIEWER STATUS This article is included in the Software and Hardware Engineering gateway. This article is included in the Cybersecurity collection. Abstract The global deployment of over seven billion IoT measuring devices in critical fields like healthcare and industrial safety systems exposes a pressing vulnerability to cyber-attacks, where compromised data integrity can lead to severe financial or life-threatening incidents. Calibration is the fundamental process ensuring measurement uniformity, yet the immense scale of the IoT makes traditional laboratory calibration physically impossible. Consequently, the calibration process must migrate on-site, relying on remote communication with calibration standards—a paradigm known as Calibration as a Service (CaaS). This digital shift, however, introduces significant cybersecurity risks into the very foundation of measurement trust. This paper addresses this critical challenge by presenting a comprehensive Standard Operating Procedure (SOP) for Secure IoT Measuring System Calibration. The proposed framework establishes the necessary protocols to protect the calibration process within a CaaS infrastructure. We further emphasize that the development and deployment of such secure IoT systems necessitate dedicated collaboration between IT security specialists and domain experts, ensuring that device integrity is prioritized from inception to safeguard end-users in an increasingly connected and vulnerable digital ecosystem. READ ALL READ LESS Keywords Calibration, Security, Data, IoT Medical device, Standard Operating Procedure Corresponding Author(s) Laimonas Kairiukstis ( [email protected] ) Close Corresponding author: Laimonas Kairiukstis Competing interests: No competing interests were disclosed. Grant information: This work was supported by the Lietuvos Inžinerijos Kolegija Higher Education Institution. The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript. Copyright: © 2025 Kairiukstis L et al . This is an open access article distributed under the terms of the Creative Commons Attribution License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. How to cite: Kairiukstis L, Kairiūkštytė K and Norvilas E. Possible security threats coming from IOT medicine sensor calibration process [version 1; peer review: 1 approved with reservations] . F1000Research 2025, 14 :1327 ( https://doi.org/10.12688/f1000research.172017.1 ) First published: 27 Nov 2025, 14 :1327 ( https://doi.org/10.12688/f1000research.172017.1 ) Latest published: 27 Nov 2025, 14 :1327 ( https://doi.org/10.12688/f1000research.172017.1 ) 1. Introduction 1.1 Challenges of digital transformation in metrology The use of IoT measurement devices is rapidly increasing across all areas of life — including industry, households, agriculture, and medicine. However, this growing deployment also raises various metrological challenges caused by factors such as device aging, unstable power supply, and environmental influences like vibration, temperature fluctuations, and other external conditions. 1 Additionally, although to a lesser extent, cybersecurity issues can also impact measurement reliability. Metrology forms the foundation of the entire quality infrastructure. Without reliable measurements, it is impossible to conduct any research — from electronics and mechanics to medicine or management. To ensure product quality, prevent production losses, and avoid physical harm or even death, the calibration of IoT measuring devices (IoTM) must be performed at appropriate intervals, and their suitability for measurement must be continuously verified and validated. Due to calibration a uninterrupted link between the measuring device and the SI system units is formed. However, it is practically impossible to calibrate large number of IoTM devices in laboratories, in this situation, the solution becomes calibration performed onsite. 1 In this article we will use the terms described in the International Vocabulary of Metrology (VIM). This guidance harmonizes worldwide fundamental terminology and thus allows the science of metrology to improve. In Chapter 5 of the VIM, “Measurement standards (etalons) and metrological traceability”, calibration is defined as an operation performed on a measuring instrument or a measuring system that, under specified conditions establishes a relation between the values with measurement uncertainties provided by measurement standards and corresponding indications with associated measurement uncertainties and uses this information to establish a relation for obtaining a measurement result from an indication. 2 Some authors use the concept of calibration incorrectly, for example, calibration is not just adjustment of a measuring system or verification of calibration, which frequently inaccurately called “selfcalibration”. Calibration of devices used in the healthcare sector is a key step in protecting lives, therefore the accuracy, precision, and performance of the devices become extremely important. 3 The global medical equipment calibration services market size was estimated at US$1.7 billion in 2024 and is expected to grow over the next decade to US$4.8 billion by 2034 owing to the rising demand for accuracy and regulatory compliance in medical devices. 4 It is important to understand that calibration may be expressed by a statement, calibration function, diagram, curve or table. 2 The calibration can be performed directly between the primary measurement standard and the secondary measurement standard or using an intermediate measurement system calibrated by the primary measurement standard, with the measurement result assigned to the secondary measurement standard. 2 All measurement systems, including IoTM devices, must have an unbroken chain of metrological traceability to an international or national measurement standard. Continuous calibration monitoring is extremely important for metrological traceability, as it allows the identification of factors contributing to measurement uncertainty and a more accurate assessment of the conformity of the measurement result to the standard. 2 The measurement system, measurement result and calibration interfaces can be depicted in Figure 1 below. This diagram illustrates that data transmission occurs throughout all processes, thereby revealing two key security risks for IoTM devices: the potential for data leakage or intentional modification, and the specific locations where these threats may arise. Figure 1. Conceptual diagram about “calibration”. 2 To ensure measurement traceability and compliance with quality standards, measuring devices require accredited calibration certificates. Traditionally, these are issued on paper, which complicates the work of technical supervisors, increases logistical costs, extends device downtime, and hinders automation in facilities with numerous instruments. To address these inefficiencies, the industry is moving toward digital calibration certificates for IoT devices. However, this shift presents not only metrological challenges but also demands robust IT security and a stable data transmission network. This is particularly difficult given the constraint of limited power sources, especially when a device should operate without changing batteries for the minimum 5 years. The implementation of digital technologies in metrology, as we can see, is a slow process, historically most likely related to the tradition of providing standards and measurement services. The responsibility arising during this process makes even minimal changes slow and consistent, in order to avoid any financial, emotional or health damage. 5 National Metrology Institutes (NMIs) have plans to provide secure and traceable Digital Calibration Certificates (DCCs), but this project is still on the hold due lack of reliable, secure and traceable infrastructure, therefore the digitalization process in metrology lags behind progress in other areas and new projects just starting in this area. 6 The concept 6 of digital calibration certificates was introduced by scientist from National Metrology Institute of Germany within the project Smartcon framework 7 in 2018 and continues in the Euramet project “Development of digital calibration certificates” till 2026. The preliminary results of introduction paper free DCC inside IoT measurement systems are described in the article. 6 The requirements for DCC calibration infrastructure and certificate structure are described in the sources. 7 – 9 In order to transmit digital metrology data over public networks, such as the Internet, security must be ensured, only then will the data not be compromised by various means during transmission, especially by malicious actors on the Internet. 5 However, the implementation of DCC in any chosen measurement area to enable calibration as a service for IoTM devices without human intervention (machine-to-machine communication) makes preparation an appropriate secure infrastructure necessary. The article examines wearable and implanted devices (IMDs) in medicine, aims to determine the impact of Calibration Errors on Medical Device Security and at the end of the analysis, a Standard Operating Procedure for calibration of IoTM will be proposed as a result. 1.2 Security challenges in measurement systems used in healthcare With the growing trend that medicine should be personalized and advancements in microelectronics, materials science, and wireless communication the number of personalized IoT sensors used in the healthcare system is increasing every year. This shows US $33.85 billion global market for health care wearables in 2023 and expected rising trend with US $250 billion market by 2030. 10 The World Health Organization (WHO) believes with the Global Health Strategy for 2025-2028 6 billion people will enjoy better health and well-being and 7 billion people to be better protected from health emergencies, 11 we believe that medical devices calibration process improvement could also contribute to this plan. Since 2010 WHO organizes Global Forum on Medical Devices, in 2025 June 2-4 were the fifth forum, in which were defined methods for increasing access to essential and priority medical devices were defined, examples of best practices from countries in medical device regulation, evaluation, and governance were shared, and the development and use of innovative, appropriate, and affordable technologies to address global health priorities were demonstrated. Wearable medical devices are considered to have one or more than one of the four main functions: monitoring, screening, detection and prediction. 11 From general vital signs monitoring to specialized sensors designed to diagnose, monitor symptoms, and treat specific diseases from different body systems - cardiovascular, neurological, psychological, musculoskeletal. 12 , 13 These sensors are already incorporated in our everyday life. Continuous monitoring data collected through IoT technologies can enhance the knowledge base for decision-making and is inherently different from routine clinical consultations. 14 However, it also possesses the risk of information overload in the healthcare system. 15 The cross-sectional study in 2025 showed that female users and with higher income levels have greater likelihood of usage, on other hand data sharing declines drastically with age. 16 Implantable cardioverter defibrillators, pacemakers, insulin pumps, deep brain stimulators and drug delivery systems are examples of IMDs used for long-term use, i.e. for the treatment of chronic diseases. However, former US Vice President Dick Cheney’s wireless connectivity of heart pacemaker was disabled due to national security concerns, such as the pacemaker’s set by cybercriminals at frequency being incompatible with life. 17 This applies not only to pacemakers, but also to other devices, such as insulin pumps, which may use similar principles to regulate insulin delivery, increasing medicaments dosage or brainjacking can lead to physical or psychological harm and even to death and experiments conducted by scientists show that this is indeed possible. 18 – 20 Therefore, medical devices are subject to strict controls and regulations worldwide. In Europe, any medical device must be certified to ensure its safety, effectiveness and consistent quality level. If all regulatory requirements are met, the device can receive the CE mark in Europe. 21 It is important to notice that sensor specificity of current wearable devices can be low, which may lead to over detection of benign nonclinical related signals, resulting in misdiagnosis, unnecessary examinations, and patient anxiety. 22 Accordingly, the calibration process and protection against tampering with the set parameters become extremely important. This could give patients, their relatives and medical staff greater confidence in these devices. Bonan Zhang et al. in a 2025 survey on security and privacy issues in wearable health monitoring devices also noticed a lack of standard communication protocols, which could help manufacturers design new devices not only orienting towards development and design of risk assessment. 22 A good balance between regulation and innovation is necessary, as the constant progress in this field often outpaces regulatory updates, creating a significant gap between the development of wearable and implantable medical devices and the establishment of the necessary regulatory requirements. 1.3 Regulations, standards and guidelines for medical devices In the healthcare sector—whether in hospitals or among medical device manufacturers—patient safety remains the highest priority. To safeguard this principle, strict regulations, standards, and guidelines govern the development, calibration, use, and quality control of medical devices worldwide. Compliance with frameworks such as FDA guidelines requires structured risk management processes, comprehensive documentation, and clearly defined roles and responsibilities. 23 During data acquisition, risks inevitably arise as a combination of the potential consequences of unwanted events and the likelihood of their occurrence. Currently, no single standardized methodology exists for assessing software security and the risks specific to IoT-based measurement systems. As a result, manufacturers and researchers draw upon various standards and recommendations issued by international organizations such as ISO and WELMEC (European Cooperation in Legal Metrology). For IoT-related risk assessment, the ISO/IEC 27005:2022 standard provides guidance on managing information security, cybersecurity, and privacy risks. 26 More domain-specific is the WELMEC Guide 7.6 Software Risk Assessment for Measuring Instruments, 24 based on the EU Measuring Instruments Directive (2014/32/EU; MID). This directive defines legal requirements for measuring instruments falling under legal metrology, which manufacturers must meet before placing devices on the market. WELMEC Guide 7.6 further specifies risk classes, baseline requirements for embedded software in measurement instruments, and detailed provisions for long-term data storage and secure transmission of measurement results. In their survey, Karie et al. identified approximately 80 ISO/IEC security standards, 32 ETSI standards, and 37 conventional security assessment frameworks, including seven NIST special publications on security techniques applicable to IoT-enabled health monitoring environments. 25 Table 1 below summarizes key international and national regulations, standards, and guidelines relevant to medical device calibration, cybersecurity, data integrity, metrology, and traceability. These frameworks form the basis for the Standard Operating Procedure (SOP) for secure calibration processes presented in the final chapter of this work. Table 1. Regulation and standards for medical devices calibrations. Category Standard Key requirements/Purpose International standards for general calibration ISO/IEC 17025:2017 Ensures calibration labs are technically competent and traceable to SI units. ISO 9001:2015 Establishes a quality management system with documented calibration procedures. ANSI/NCSL Z540.3-2006 (US) Defines calibration system requirements including uncertainty evaluation. ANSI/NCSL Z540.3-2006 (US) Guides calculation and reporting of calibration uncertainty. International standards for medical devices FDA 21 CFR Part 11 Ensures secure and auditable electronic calibration records. ISO 13485 Maintains safe and effective calibration processes for medical devices. International Cybersecurity & Data Integrity Standards NIST SP 800-53 (Rev. 5) Protects calibration systems with secure access controls. IEC 62443 (Industrial IoT Security) Secures calibration in industrial systems against tampering. ISO/IEC 27001:2022 Safeguards calibration data from unauthorized changes. NISTIR 8228 (IoT Security) Recommends secure calibration practices for IoT devices. International Metrology & Traceability Standards JCGM 100:2008 (GUM) Standardizes how to report calibration uncertainty. BIPM SI Brochure (9th Edition) Ensures calibration traceability to SI units. EURAMET cg-18 (Europe) Gives regional guidance for temperature device calibration. These standards precisely describe how calibration laboratories, measurement systems and with them related processes must be done to ensure accuracy, reliability, and security. Medical devices are no exceptions; they must be calibrated following in standards described requirements. As already mentioned, they can be international or national, requirements or quality control tests may vary depending on this. Main European Union regulations are Medical Devices Regulation (MDR) describing how medical devices must be approved for safety and their performance. 26 The MDR also includes part about IT security in medical devices, to ensure data and device performance regulation from unauthorized access. As medical devices development never stops, new measurement methods, their implementation of IoT devices, hardware or software improvement also are necessary and regulations that must be regularly updated. 2. Key components of a cybersecurity protocol for calibration data security and calibration process security measures The main components ensuring the safety of the calibration process can be listed as follows: identification, protection, access control, detection, response, and recovery. During the identification phase we should understand and prioritize assets, risks, and vulnerabilities to ensure that all critical data and systems are recognized and assessed for potential threats. To make it easier to do this, it is recommended to use the following regulations on medical devices. 27 For protection of the measurement system, safeguards, firewalls should be implemented, used encryption protocols, and secure communication protocols to protect data and systems from unauthorized access and cyber threats. 27 , 28 Calibration data is particularly important; therefore, access control and multi-factor authentication should ensure only authorized personnel access of sensitive data. 29 During the system working time we should do non-stop monitoring, which will allow us to detect cybersecurity events promptly. Consequently, establishment of mechanisms detecting cybersecurity events such as intrusion detection systems which monitor for and respond to suspected security breaches. 30 During the response phase development and implementation of an effective response plan to address and mitigate the impact of cybersecurity incidents is essential. 27 Although manufacturers try to reduce the cost of equipment as much as possible, when it comes to the calibration process, we must ensure its recovery. At this stage we should ensure efficient recovery and resilience after a cybersecurity incident by having data backup and recovery plans in place. 27 , 29 It is also worth considering additional security measures such as Data Integrity and Cryptography Services, CIA Triad, Defense in Depth. Data Integrity and Cryptography Services ensure the integrity of data through cryptographic services and evaluate access requests based on roles. CIA Triad can emphasize confidentiality, integrity, and availability to prevent unauthorized access, ensure data accuracy, and optimize user access. 31 Defense in Depth (DID) implements a multilayered approach to security, making it difficult for attackers to bypass all security layers. 32 These previously mentioned components collectively form a robust cybersecurity protocol aimed at protecting calibration data from various cyber threats and ensuring the integrity and availability of the data. For IoT measuring systems, calibration security is critical to ensure data integrity, measurement accuracy, and system reliability. The calibration process must be protected against both intentional tampering and accidental errors. Key Security Measures for IoT Calibration Process Security are listed below in Table 2 . Table 2. Security measures and implementation recommendations. Security measure Method Implementation recommendations Authentication and Access Control Implemented multi-factor authentication for calibration personnel Role-based access control for calibration functions Secure credential management for calibration devices Secure Calibration Workflow: Establish a documented, auditable calibration procedure; Implement digital workflow with approval requirements; Include verification steps after calibration Data Integrity Protection Digital signatures for calibration certificates Cryptographic hash verification of calibration parameters Secure logging of all calibration activities with timestamps Device Security: Secure boot mechanisms for calibration equipment; Regular security updates for calibration software; Hardware security modules for sensitive operations Secure Communication Encrypted channels for calibration data transmission Certificate-based device authentication Protection against man-in-the-middle attacks during calibration Blockchain for immutable calibration records; AI-assisted anomaly detection in calibration data; Secure enclaves for calibration computations Physical Security Tamper-evident seals on calibration interfaces Secure storage of calibration reference standards Environmental monitoring for calibration areas Audit and Compliance: Maintain detailed calibration records with chain-of-custody; Regular security audits of calibration processes; Compliance with relevant standards (ISO/IEC 17025, NIST guidelines) Process Security Automated verification of calibration results against expected ranges Cross-validation with redundant measurement systems when possible Secure update mechanisms for calibration algorithms Anomaly Detection: Monitor for unusual calibration patterns; Implement alerts for suspicious calibration activities; Statistical process control for calibration results Proper implementation of these security measures helps ensure that IoT measurement systems maintain their accuracy and reliability throughout their operational lifecycle. 3. Standard Operating Procedure (SOP) for secure IoT measuring system calibration Standard Operating Procedures (SOPs) are structured, written instructions designed to achieve uniformity and repeatability in critical processes. They are essential in high-risk industries such as healthcare, where quality, safety, and compliance with regulatory frameworks must be consistently maintained. 33 In this section, we propose a step-by-step SOP for the calibration of IoT-enabled medical measuring devices. The procedure clearly defines roles and responsibilities across participants, establishes common terminology to facilitate communication between IT engineers, medical staff, and measurement specialists, and integrates both metrological and cybersecurity requirements. While adaptable to other domains, the SOP is particularly tailored to reducing measurement uncertainties and mitigating risks related to data integrity and system security. The SOP consists of seven key components: 1. Purpose 2. Scope 3. Responsibilities 4. Equipment & Requirements 5. Procedure 6. Records & Compliance 7. Training & Competence 1. Purpose. This SOP defines the secure calibration process for IoT measuring systems to ensure accuracy, data integrity, and protection against tampering or unauthorized modifications. 2. Scope. SOP applies to: • IoT-based measurement devices requiring periodic calibration; • Calibration technicians, engineers, and quality assurance personnel; • Third-party calibration service providers, calibration laboratories. 3. Responsibilities are distributed among the participants in the process as follows: • Quality Manager: Approves calibration procedures and audits compliance; • Calibration Technician: Performs calibration following this SOP; • IT Security Team: Ensures secure data transmission and access controls; • Device Owner: Verifies calibration status and reports anomalies. 4. Equipment & Requirements. This part describes the equipment used inside the measuring process and requirements from a metrological and IT security perspective. It describes the following requirements: • Certified reference standards (traceable to NIST/ISO/IEC 17025); • Secure calibration software/hardware with authentication; • Tamper-evident seals and logging tools; • Encrypted communication channels. 5. Procedure part is divided in following parts: 5.1 Pre-Calibration Security Checks. Authentication should be done, therefore only authorized personnel with multi-factor authentication (MFA) may access calibration tools. Additionally, role-based permissions should be set in order to restrict calibration parameter changes. Device Integrity Check should be performed in order to verify that the IoT device has no physical tampering. For example, the responsible person should check that seals have no intact. The physical inspection of the measuring instrument is followed by the equipment software inspection and a check for firmware/software version consistency is applied in order to verify that there are no unauthorized modifications to source code. During the calibration process the secure connection setup should be done and the use of TLS/SSL encryption for data transfer between IoT device and calibration tool should be established. During connection setup the person, who makes calibration, should ensure calibration equipment has valid digital certificates. 5.2 Calibration Execution is carried out by procedures and additional documents listed in ISO17025 standard. Firstly, reference standard verification is performed, i.e. it is checked if calibration standards are within validity period. Secondly, environmental conditions are recorded. In case of automated calibration process the cryptographically signed calibration scripts to prevent tampering should be used. In order to avoid environmental influences during calibration, it is necessary to ensure that as few environmental factors as possible are present during the process or their influence is minimized. For example, if wireless interference is a risk, calibration can be performed in a controlled environment like a Faraday cage. Thirdly, if applicable the cross-validation can be done to ensure the quality of calibration. In this step we can compare results with a secondary reference device and apply statistical checks to detect anomalies. 5.3 Post-Calibration Security Measures. At this step following tasks should be executed: Digital Certification & Logging, Tamper-Evident Sealing and Data Sync & Backup. A digitally signed calibration certificate will be generated, with its hash stored in a secure ledger to ensure authenticity. All actions, including the responsible technician, timestamps, and adjustments, will be logged for audit purposes. Tamper-evident seals will be applied to calibration ports, and each seal’s unique ID will be recorded in the calibration log. Calibration data will be securely transmitted to the central IoT management system, and backup logs will be preserved in a write-once, read-many (WORM) system to prevent tampering. 5.4 Anomaly Handling. During calibration, unexpected events may occur that may affect the overall performance of the measurement system, therefore, after the process we must investigate if calibration results deviate beyond acceptable limits. If so, we should flag the device for investigation. During calibration, data are exchanged between the reference device and the calibrated device. At this point, hacking is possible, therefore, a check for potential cybersecurity breaches (e.g., firmware tampering) must be performed. If malicious activity is suspected the steps of escalation of the IT security team should be defined. 6. Records & Compliance. All mandatory documentation must be maintained, including digitally signed calibration certificates, access logs identifying the personnel, who performed the calibration, environmental condition records (where applicable), and cryptographic hash values of calibration parameters. An audit trail shall be preserved for a minimum of several years in accordance with regulatory requirements, with all logs stored in an immutable format—preferably using blockchain or WORM-based systems. 7. Training & Compliance. All personnel are required to complete training in both calibration procedures and cybersecurity awareness, and annual re-certification is mandatory to maintain compliance and competence for persons involved in the calibration process. 4. Conclusions Although we can say in a simplified way that only data is exchanged during the calibration process, it is particularly important to understand how important this data is for the safety of devices. The development of the Standard Operating Procedure helps to avoid malfunctions in measuring instruments, which can result in huge losses or even fatalities, when it comes to medical devices. After conducting a literature review on the cybersecurity of medical measuring instruments, calibration and IoT devices, it is quite clear that metrology is closely related to IT and medicine and when solving the issue of security of medical measuring instruments, knowledge of only one area is not enough. Therefore, interdisciplinary cooperation is necessary, i.e. after calibration, anomaly handling must be performed by a medical technician or measurement specialist, who will be able to notice deviations of the measuring instrument from the usual mode. The IT professional from his side can program that the malfunction is noticed as soon as possible after using AI and ML tools. The ever-increasing number of IoT devices, including in medicine, poses increasing security and metrology problems, which can be solved only by digitizing the international metrology system. The use of digital calibration certificates, the creation of calibration as a service and calibration as infrastructure are the first steps towards ensuring the quality of a global quality infrastructure. As the only way to ensure the quality of the measurements made, we see ensuring periodic calibration of measuring instruments, which due to the abundance of IoT devices will be forced to move from physical laboratories as close as possible to the sensors, i.e. more and more wandering will be carried out on site instead of doing it in the laboratory. Interdisciplinary projects within educational programs are fundamentally important. They unite students from diverse fields such as medicine, electronics, and IT, providing crucial exposure to the integrated processes that ensure the reliable operation of medical Internet of Things (IoT) devices. A practical example of this approach was a project that brought together three different institutions. Under the guidance of a professor from measurement sciences, a team was formed comprising students from medical, IT, and electronics disciplines. This collaboration was highly productive, resulting in the creation of a detailed Standard Operating Procedure (SOP). This SOP is not merely an academic exercise; it is designed to serve as the foundational framework for future experiments and development. Its primary future application will be in the creation of a “calibration-as-a-service” solution for medical IoT devices. This service will streamline the development process and ensure consistent, traceable calibration. Therefore, promoting this type of interdisciplinary cooperation between the scientific fields of IT, medicine, electronics, and measurement engineering is essential. It is through such partnerships that we can develop the necessary infrastructure to guarantee data security and establish measurement uniformity. As a direct result, we will be able to confidently rely on the data generated by measuring instruments used in clinical medicine, thereby enhancing patient care and safety. Declaration of Generative AI and AI-assisted technologies in the writing process. The GPT-5 was used for language improvement and idea exploration. Data availability No data are associated with this article. References 1. Kairiūkštis L:Metrology Challenges in Implementing Digital Calibration Certificates for Internet of Things Measurement (Iotm) Devices.2023. 2. International vocabulary of metrology – Basic and general concepts and associated terms (VIM) 3rd edition.2012. Reference Source 3. Department of Pharmaceutics, Government Pharmacy Institute, Patna, Bihar-800007, IndiaKumar R:Calibration of Medical Devices: Method and Impact on Operation Quality. Int. J. Pharm. Sci. 2023; 16 : 1–14. Publisher Full Text 4. Global Market Insights Inc:Medical Equipment Calibration Services Market – By Service Type, By Equipment Type, By Calibration Type, By End Use & Global Forecast, 2025-2034.2025. 5. Mustapaa T, Autiosalo J, Nikander P, et al. :Digital Metrology for the Internet of Things. 2020 Global Internet of Things Summit (GIoTS). Dublin, Ireland:IEEE;2020; pp. 1–6. Publisher Full Text 6. Balslev-Harder D, Bošnjaković A, Brown C, et al. :DCC2GO – Supporting the implementation of Digital Calibration Certificates in the European metrology community. Measurement: Sensors. 2025; 38 : 101499. Publisher Full Text 7. Hutzschenreuter D, Härtig F, Wiedenhöfer T, et al. :SmartCom Digital-SI (D-SI) XML exchange format for metrological data version 1.3.0.2019. Publisher Full Text Reference Source 8. Nikander P, Elo T, Mustapää T, et al. :Document specifying rules for the secure use of DCC covering legal aspects of metrology.2020. Publisher Full Text 9. Grasso Toro F: PDF/A-3 solution for digital calibration certificates. 10. Grand View Research: Wearable Medical Devices Market Summary. 2024. Reference Source 11. Canali S, Schiaffonati V, Aliverti A:Challenges and recommendations for wearable devices in digital health: Data quality, interoperability, health equity, fairness. PLOS Digit. Health. 2022; 1 : e0000104. PubMed Abstract | Publisher Full Text | Free Full Text 12. Iqbal SMA, Mahgoub I, Du E, et al. :Advances in healthcare wearable devices. NPJ Flexible Electron. 2021; 5 : 9. Publisher Full Text 13. Godinho C, Domingos J, Cunha G, et al. :A systematic review of the characteristics and validity of monitoring technologies to assess Parkinson’s disease. J. NeuroEngineering Rehabil. 2016; 13 : 24. PubMed Abstract | Publisher Full Text | Free Full Text 14. Azodo I, Williams R, Sheikh A, et al. :Opportunities and Challenges Surrounding the Use of Data From Wearable Sensor Devices in Health Care: Qualitative Interview Study. J. Med. Internet Res. 2020; 22 : e19542. PubMed Abstract | Publisher Full Text | Free Full Text 15. Hall A, Walton G:Information overload within the health care system: a literature review. Health Inf. Libr. J. 2004; 21 : 102–108. Publisher Full Text 16. Chandrasekaran R, Sadiq TM, Moustakas E:Usage Trends and Data Sharing Practices of Healthcare Wearable Devices Among US Adults: Cross-Sectional Study. J. Med. Internet Res. 2025; 27 : e63879. PubMed Abstract | Publisher Full Text | Free Full Text 17. Dick Cheney RB:Reflections of a Former Vice President on Long-Time Cardiac Experiences. Baylor Univ. Med. Cent. Proc. 2009; 22 : 276–278. PubMed Abstract | Publisher Full Text | Free Full Text 18. Best J:Could implanted medical devices be hacked? BMJ. 2020; 368 : m102. PubMed Abstract | Publisher Full Text 19. Rehman MMU, Rehman HZU, Khan ZH:Cyber-Attacks on Medical Implants: A Case Study of Cardiac Pacemaker Vulnerability. IJCDS. 2020; 09 : 1229–1235. Publisher Full Text 20. Pugh J, Pycroft L, Sandberg A, et al. :Brainjacking in deep brain stimulation and autonomy. Ethics Inf. Technol. 2018; 20 : 219–232. PubMed Abstract | Publisher Full Text | Free Full Text 21. Ravizza A, De Maria C, Di Pietro L, et al. :Comprehensive Review on Current and Future Regulatory Requirements on Wearable Sensors in Preclinical and Clinical Testing. Front. Bioeng. Biotechnol. 2019; 7 : 313. PubMed Abstract | Publisher Full Text | Free Full Text 22. Zhang B, Chen C, Lee I, et al. :A survey on security and privacy issues in wearable health monitoring devices. Comput. Secur. 2025; 155 : 104453. Publisher Full Text 23. Ramalingam PS, Muthunayagam S:Medical device portfolio cleanup. Trends in Development of Medical Devices. Elsevier;2020; pp. 155–176. Publisher Full Text 24. WELMEC Guide 7.6 Software Risk Assessment for Measuring Instruments. 2021. Reference Source 25. Karie NM, Sahri NM, Yang W, et al. :A Review of Security Standards and Frameworks for IoT-Based Smart Environments. IEEE Access. 2021; 9 : 121975–121995. Publisher Full Text 26. Pandey M, Gupta A:Image encryption of medical images. Advances in Computers. Elsevier;2025; pp. 345–406. Publisher Full Text 27. Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (Text with EEA relevance.).2025. Reference Source 28. Karner M, Peltola J, Jerne M, et al. : Intelligent Secure Trustable Things. Cham:Springer Nature Switzerland;2024. Publisher Full Text 29. Xie H, Song G, Shi Z, et al. :Reinforcement learning for vehicle-to-grid: A review. Advances in Applied Energy. 2025; 17 : 100214. Publisher Full Text 30. Yalli JS, Hasan MH, Jung LT, et al. :Authentication schemes for Internet of Things (IoT) networks: A systematic review and security assessment. Internet of Things. 2025; 30 : 101469. Publisher Full Text 31. Villarreal V, Fontecha J, Hervas R, et al. :Mobile and ubiquitous architecture for the medical control of chronic diseases through the use of intelligent devices: Using the architecture for patients with diabetes. Futur. Gener. Comput. Syst. 2014; 34 : 161–175. Publisher Full Text 32. Chhor CM, Raichandani S, Du Preez L, et al. :Data governance in radiology Part I: Overview of data management approaches to radiology. Curr. Probl. Diagn. Radiol. 2025; 54 : 554–561. PubMed Abstract | Publisher Full Text 33. Johnson K, Morais C, Patelli E:Enhancing procedure quality: Advanced language tools for identifying ambiguity and high-potential violation triggers. Reliab. Eng. Syst. Saf. 2025; 264 : 111308. Publisher Full Text Comments on this article Comments (0) Version 1 VERSION 1 PUBLISHED 27 Nov 2025 ADD YOUR COMMENT Comment Author details Author details 1 Lietuvos Inžinerijos Kolegija Higher Education Institution, Tvirtoves al. 35, 50155 Kaunas, Lithuania Laimonas Kairiukstis Roles: Conceptualization, Formal Analysis, Methodology, Supervision, Writing – Review & Editing Kamilė Kairiūkštytė Roles: Writing – Original Draft Preparation, Writing – Review & Editing Edvinas Norvilas Roles: Resources, Visualization, Writing – Original Draft Preparation, Writing – Review & Editing Competing interests No competing interests were disclosed. Grant information This work was supported by the Lietuvos Inžinerijos Kolegija Higher Education Institution. The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript. Article Versions (1) version 1 Published: 27 Nov 2025, 14:1327 https://doi.org/10.12688/f1000research.172017.1 Copyright © 2025 Kairiukstis L et al . This is an open access article distributed under the terms of the Creative Commons Attribution License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. Download Export To Sciwheel Bibtex EndNote ProCite Ref. Manager (RIS) Sente metrics Views Downloads F1000Research - - PubMed Central info_outline Data from PMC are received and updated monthly. - - Citations open_in_new 0 open_in_new 0 open_in_new SEE MORE DETAILS CITE how to cite this article Kairiukstis L, Kairiūkštytė K and Norvilas E. Possible security threats coming from IOT medicine sensor calibration process [version 1; peer review: 1 approved with reservations] . F1000Research 2025, 14 :1327 ( https://doi.org/10.12688/f1000research.172017.1 ) NOTE: If applicable, it is important to ensure the information in square brackets after the title is included in all citations of this article. COPY CITATION DETAILS track receive updates on this article Track an article to receive email alerts on any updates to this article. TRACK THIS ARTICLE Share Open Peer Review Current Reviewer Status: ? Key to Reviewer Statuses VIEW HIDE Approved The paper is scientifically sound in its current form and only minor, if any, improvements are suggested Approved with reservations A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit. Not approved Fundamental flaws in the paper seriously undermine the findings and conclusions Version 1 VERSION 1 PUBLISHED 27 Nov 2025 Views 0 Cite How to cite this report: Cook DM. Reviewer Report For: Possible security threats coming from IOT medicine sensor calibration process [version 1; peer review: 1 approved with reservations] . F1000Research 2025, 14 :1327 ( https://doi.org/10.5256/f1000research.189694.r453628 ) The direct URL for this report is: https://f1000research.com/articles/14-1327/v1#referee-response-453628 NOTE: it is important to ensure the information in square brackets after the title is included in this citation. Close Copy Citation Details Reviewer Report 20 Feb 2026 David M. Cook , Edith Cowan University, Joondalup, Australia Approved with Reservations VIEWS 0 https://doi.org/10.5256/f1000research.189694.r453628 This article makes an argument that because of the sheer number of IoTs that their calibration must be handled through service-driven systems that reside on-site rather than in their own location or in buildings, labs and other areas. Whilst the ... Continue reading READ ALL This article makes an argument that because of the sheer number of IoTs that their calibration must be handled through service-driven systems that reside on-site rather than in their own location or in buildings, labs and other areas. Whilst the paper argues for a standardised approach in terms of procedure, there is an opportunity to build this into a more structured and articulated threat model. The article is well grounded and has incorporated a broad range of appropriate ISO standards to create the right connectors for this type of standard operating procedure to have merit. My suggestion to the authors is simply to take it further and devise an appropriate threat model to complete the process. With a clearly described threat model - this article can then lay a much stronger claim to assist with a greater number of calibration extensions - allowing for calibration workflows for attack surfaces, assets and trust boundaries. This would also allow for a strong link between standard operating procedures, standards controls, and specific threats. I also suggest to the authors to consider strengthening the reference material upon which this article is anchored. Some of the narrative that describes bold numbers such as wearables value by the year 2030, and numbers such as "seven billion IoT measuring devices" as stated in the abstract would seem more credible with greater support from quality citations. It is important to go beyond unsupported claims or just claims that are supported by market reports. Please consider a stronger connection to the literature that includes genuinely robust citations that are reputable and demonstrate the article's connection to a wider range of respected and valued field-weighted citations. I think there is considerable room to clarify the key area of measurement integrity. It would be very useful to show differentiation between problem areas such as metrology uncertainty, and drift, and the other side of this narrative in terms of cyber integrity such as Man in the Middle attacks, spoofing, and rollback integrity where we can get a sense of the need for the ability to restore data, restore software and return to uncorrupted environments. My suggestion is that the authors should look to clarify, define and differentiate these areas. There are several linkages to market reports and internal company reports, which are insufficient as reference material unless there is also the strong inclusion of peer-reviewed sources that carry greater weight and provide better validity to claims, especially where there are opportunities to include individual technical sources that provide more strongly weighted support in areas relating to threats and their mitigations. Overall, the article is readable and accessible. there are some annoying inconsistencies with terminology acronyms such as the different versions of IOT vs IoT vs IoTM and even IoTM devices and Iotm. I suggest a cleanup in that sense. Is the topic of the review discussed comprehensively in the context of the current literature? Partly Are all factual statements correct and adequately supported by citations? Partly Is the review written in accessible language? Yes Are the conclusions drawn appropriate in the context of the current research literature? Partly Competing Interests: No competing interests were disclosed. Reviewer Expertise: My research areas are strongly anchored to NIST-driven environments. I am genuinely interested in the subject matter of this article and its usability if improved on a more robust level. I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard, however I have significant reservations, as outlined above. Close READ LESS CITE CITE HOW TO CITE THIS REPORT Cook DM. Reviewer Report For: Possible security threats coming from IOT medicine sensor calibration process [version 1; peer review: 1 approved with reservations] . F1000Research 2025, 14 :1327 ( https://doi.org/10.5256/f1000research.189694.r453628 ) The direct URL for this report is: https://f1000research.com/articles/14-1327/v1#referee-response-453628 NOTE: it is important to ensure the information in square brackets after the title is included in all citations of this article. COPY CITATION DETAILS Report a concern Respond or Comment COMMENT ON THIS REPORT Comments on this article Comments (0) Version 1 VERSION 1 PUBLISHED 27 Nov 2025 ADD YOUR COMMENT Comment keyboard_arrow_left keyboard_arrow_right Open Peer Review Reviewer Status info_outline Alongside their report, reviewers assign a status to the article: Approved The paper is scientifically sound in its current form and only minor, if any, improvements are suggested Approved with reservations A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit. Not approved Fundamental flaws in the paper seriously undermine the findings and conclusions Reviewer Reports Invited Reviewers 1 Version 1 27 Nov 25 read David M. Cook , Edith Cowan University, Joondalup, Australia Comments on this article All Comments (0) Add a comment Sign up for content alerts Sign Up You are now signed up to receive this alert Browse by related subjects keyboard_arrow_left Back to all reports Reviewer Report 0 Views copyright © 2026 Cook D. This is an open access peer review report distributed under the terms of the Creative Commons Attribution License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. 20 Feb 2026 | for Version 1 David M. Cook , Edith Cowan University, Joondalup, Australia 0 Views copyright © 2026 Cook D. This is an open access peer review report distributed under the terms of the Creative Commons Attribution License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. format_quote Cite this report speaker_notes Responses (0) Approved With Reservations info_outline Alongside their report, reviewers assign a status to the article: Approved The paper is scientifically sound in its current form and only minor, if any, improvements are suggested Approved with reservations A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit. Not approved Fundamental flaws in the paper seriously undermine the findings and conclusions This article makes an argument that because of the sheer number of IoTs that their calibration must be handled through service-driven systems that reside on-site rather than in their own location or in buildings, labs and other areas. Whilst the paper argues for a standardised approach in terms of procedure, there is an opportunity to build this into a more structured and articulated threat model. The article is well grounded and has incorporated a broad range of appropriate ISO standards to create the right connectors for this type of standard operating procedure to have merit. My suggestion to the authors is simply to take it further and devise an appropriate threat model to complete the process. With a clearly described threat model - this article can then lay a much stronger claim to assist with a greater number of calibration extensions - allowing for calibration workflows for attack surfaces, assets and trust boundaries. This would also allow for a strong link between standard operating procedures, standards controls, and specific threats. I also suggest to the authors to consider strengthening the reference material upon which this article is anchored. Some of the narrative that describes bold numbers such as wearables value by the year 2030, and numbers such as "seven billion IoT measuring devices" as stated in the abstract would seem more credible with greater support from quality citations. It is important to go beyond unsupported claims or just claims that are supported by market reports. Please consider a stronger connection to the literature that includes genuinely robust citations that are reputable and demonstrate the article's connection to a wider range of respected and valued field-weighted citations. I think there is considerable room to clarify the key area of measurement integrity. It would be very useful to show differentiation between problem areas such as metrology uncertainty, and drift, and the other side of this narrative in terms of cyber integrity such as Man in the Middle attacks, spoofing, and rollback integrity where we can get a sense of the need for the ability to restore data, restore software and return to uncorrupted environments. My suggestion is that the authors should look to clarify, define and differentiate these areas. There are several linkages to market reports and internal company reports, which are insufficient as reference material unless there is also the strong inclusion of peer-reviewed sources that carry greater weight and provide better validity to claims, especially where there are opportunities to include individual technical sources that provide more strongly weighted support in areas relating to threats and their mitigations. Overall, the article is readable and accessible. there are some annoying inconsistencies with terminology acronyms such as the different versions of IOT vs IoT vs IoTM and even IoTM devices and Iotm. I suggest a cleanup in that sense. Is the topic of the review discussed comprehensively in the context of the current literature? Partly Are all factual statements correct and adequately supported by citations? Partly Is the review written in accessible language? Yes Are the conclusions drawn appropriate in the context of the current research literature? Partly Competing Interests No competing interests were disclosed. Reviewer Expertise My research areas are strongly anchored to NIST-driven environments. I am genuinely interested in the subject matter of this article and its usability if improved on a more robust level. I confirm that I have read this submission and believe that I have an appropriate level of expertise to confirm that it is of an acceptable scientific standard, however I have significant reservations, as outlined above. reply Respond to this report Responses (0) Cook DM. Peer Review Report For: Possible security threats coming from IOT medicine sensor calibration process [version 1; peer review: 1 approved with reservations] . F1000Research 2025, 14 :1327 ( https://doi.org/10.5256/f1000research.189694.r453628) NOTE: it is important to ensure the information in square brackets after the title is included in this citation. The direct URL for this report is: https://f1000research.com/articles/14-1327/v1#referee-response-453628 Alongside their report, reviewers assign a status to the article: Approved - the paper is scientifically sound in its current form and only minor, if any, improvements are suggested Approved with reservations - A number of small changes, sometimes more significant revisions are required to address specific details and improve the papers academic merit. Not approved - fundamental flaws in the paper seriously undermine the findings and conclusions Adjust parameters to alter display View on desktop for interactive features Includes Interactive Elements View on desktop for interactive features Competing Interests Policy Provide sufficient details of any financial or non-financial competing interests to enable users to assess whether your comments might lead a reasonable person to question your impartiality. Consider the following examples, but note that this is not an exhaustive list: Examples of 'Non-Financial Competing Interests' Within the past 4 years, you have held joint grants, published or collaborated with any of the authors of the selected paper. You have a close personal relationship (e.g. parent, spouse, sibling, or domestic partner) with any of the authors. You are a close professional associate of any of the authors (e.g. scientific mentor, recent student). You work at the same institute as any of the authors. You hope/expect to benefit (e.g. favour or employment) as a result of your submission. You are an Editor for the journal in which the article is published. Examples of 'Financial Competing Interests' You expect to receive, or in the past 4 years have received, any of the following from any commercial organisation that may gain financially from your submission: a salary, fees, funding, reimbursements. You expect to receive, or in the past 4 years have received, shared grant support or other funding with any of the authors. You hold, or are currently applying for, any patents or significant stocks/shares relating to the subject matter of the paper you are commenting on. Stay Updated Sign up for content alerts and receive a weekly or monthly email with all newly published articles Register with F1000Research Already registered? Sign in Not now, thanks close PLEASE NOTE If you are an AUTHOR of this article, please check that you signed in with the account associated with this article otherwise we cannot automatically identify your role as an author and your comment will be labelled as a “User Comment”. If you are a REVIEWER of this article, please check that you have signed in with the account associated with this article and then go to your account to submit your report, please do not post your review here. If you do not have access to your original account, please contact us . All commenters must hold a formal affiliation as per our Policies . The information that you give us will be displayed next to your comment. User comments must be in English, comprehensible and relevant to the article under discussion. We reserve the right to remove any comments that we consider to be inappropriate, offensive or otherwise in breach of the User Comment Terms and Conditions . Commenters must not use a comment for personal attacks. When criticisms of the article are based on unpublished data, the data should be made available. I accept the User Comment Terms and Conditions Please confirm that you accept the User Comment Terms and Conditions. Affiliation ✕ refresh Please enter your institution. Note: To add your institution or organisation, start typing the name and then select the correct name from the list. Where applicable, the name will appear in both the original language and in English. Do not paste in the name. If the name does not appear in the drop-down list, we will display the information you have entered. ✕ refresh Country/Region * USA UK Canada China France Germany Afghanistan Aland Islands Albania Algeria American Samoa Andorra Angola Anguilla Antarctica Antigua and Barbuda Argentina Armenia Aruba Australia Austria Azerbaijan Bahamas Bahrain Bangladesh Barbados Belarus Belgium Belize Benin Bermuda Bhutan Bolivia Bosnia and Herzegovina Botswana Bouvet Island Brazil British Indian Ocean Territory British Virgin Islands Brunei Bulgaria Burkina Faso Burundi Cambodia Cameroon Canada Cape Verde Cayman Islands Central African Republic Chad Chile China Christmas Island Cocos (Keeling) Islands Colombia Comoros Congo Cook Islands Costa Rica Cote d'Ivoire Croatia Cuba Cyprus Czech Republic Democratic Republic of the Congo Denmark Djibouti Dominica Dominican Republic Ecuador Egypt El Salvador Equatorial Guinea Eritrea Estonia Ethiopia Falkland Islands Faroe Islands Federated States of Micronesia Fiji Finland France French Guiana French Polynesia French Southern Territories Gabon Georgia Germany Ghana Gibraltar Greece Greenland Grenada Guadeloupe Guam Guatemala Guernsey Guinea Guinea-Bissau Guyana Haiti Heard Island and Mcdonald Islands Holy See (Vatican City State) Honduras Hong Kong Hungary Iceland India Indonesia Iran Iraq Ireland Israel Italy Jamaica Japan Jersey Jordan Kazakhstan Kenya Kiribati Kosovo (Serbia and Montenegro) Kuwait Kyrgyzstan Lao People's Democratic Republic Latvia Lebanon Lesotho Liberia Libya Liechtenstein Lithuania Luxembourg Macao Madagascar Malawi Malaysia Maldives Mali Malta Marshall Islands Martinique Mauritania Mauritius Mayotte Mexico Minor Outlying Islands of the United States Moldova Monaco Mongolia Montenegro Montserrat Morocco Mozambique Myanmar Namibia Nauru Nepal Netherlands Antilles New Caledonia New Zealand Nicaragua Niger Nigeria Niue Norfolk Island North Korea North Macedonia Northern Mariana Islands Norway Oman Pakistan Palau Palestinian Territory Panama Papua New Guinea Paraguay Peru Philippines Pitcairn Poland Portugal Puerto Rico Qatar Reunion Romania Russian Federation Rwanda Saint Helena Saint Kitts and Nevis Saint Lucia Saint Pierre and Miquelon Saint Vincent and the Grenadines Samoa San Marino Sao Tome and Principe Saudi Arabia Senegal Serbia Seychelles Sierra Leone Singapore Slovakia Slovenia Solomon Islands Somalia South Africa South Georgia and the South Sandwich Is South Korea South Sudan Spain Sri Lanka Sudan Suriname Svalbard and Jan Mayen Swaziland Sweden Switzerland Syria Taiwan Tajikistan Tanzania Thailand The Gambia The Netherlands Timor-Leste Togo Tokelau Tonga Trinidad and Tobago Tunisia Turkey Turkmenistan Turks and Caicos Islands Tuvalu UK USA Uganda Ukraine United Arab Emirates United States Virgin Islands Uruguay Uzbekistan Vanuatu Venezuela Vietnam Wallis and Futuna West Bank and Gaza Strip Western Sahara Yemen Zambia Zimbabwe Please select your country/region. You must enter a comment. Competing Interests Please disclose any competing interests that might be construed to influence your judgment of the article's or peer review report's validity or importance. Competing Interests Policy Provide sufficient details of any financial or non-financial competing interests to enable users to assess whether your comments might lead a reasonable person to question your impartiality. Consider the following examples, but note that this is not an exhaustive list: Examples of 'Non-Financial Competing Interests' Within the past 4 years, you have held joint grants, published or collaborated with any of the authors of the selected paper. You have a close personal relationship (e.g. parent, spouse, sibling, or domestic partner) with any of the authors. You are a close professional associate of any of the authors (e.g. scientific mentor, recent student). You work at the same institute as any of the authors. You hope/expect to benefit (e.g. favour or employment) as a result of your submission. You are an Editor for the journal in which the article is published. Examples of 'Financial Competing Interests' You expect to receive, or in the past 4 years have received, any of the following from any commercial organisation that may gain financially from your submission: a salary, fees, funding, reimbursements. You expect to receive, or in the past 4 years have received, shared grant support or other funding with any of the authors. You hold, or are currently applying for, any patents or significant stocks/shares relating to the subject matter of the paper you are commenting on. Please state your competing interests The comment has been saved. An error has occurred. Please try again. Cancel Post var lTitle = "Possible security threats coming from IOT...".replace("'", ''); var linkedInUrl = "http://www.linkedin.com/shareArticle?url=https://f1000research.com/articles/14-1327/v1" + "&title=" + encodeURIComponent(lTitle) + "&summary=" + encodeURIComponent('Read the article by '); var deliciousUrl = "https://del.icio.us/post?url=https://f1000research.com/articles/14-1327/v1&title=" + encodeURIComponent(lTitle); var redditUrl = "http://reddit.com/submit?url=https://f1000research.com/articles/14-1327/v1" + "&title=" + encodeURIComponent(lTitle); linkedInUrl += encodeURIComponent('Kairiukstis L et al.'); var offsetTop = /chrome/i.test( navigator.userAgent ) ? 4 : -10; var addthis_config = { ui_offset_top: offsetTop, services_compact : "facebook,twitter,www.linkedin.com,www.mendeley.com,reddit.com", services_expanded : "facebook,twitter,www.linkedin.com,www.mendeley.com,reddit.com", services_custom : [ { name: "LinkedIn", url: linkedInUrl, icon:"/img/icon/at_linkedin.svg" }, { name: "Mendeley", url: "http://www.mendeley.com/import/?url=https://f1000research.com/articles/14-1327/v1/mendeley", icon:"/img/icon/at_mendeley.svg" }, { name: "Reddit", url: redditUrl, icon:"/img/icon/at_reddit.svg" }, ] }; var addthis_share = { url: "https://f1000research.com/articles/14-1327", templates : { twitter : "Possible security threats coming from IOT medicine sensor calibration.... Kairiukstis L et al., published by " + "@F1000Research" + ", https://f1000research.com/articles/14-1327/v1" } }; if (typeof(addthis) != "undefined"){ addthis.addEventListener('addthis.ready', checkCount); addthis.addEventListener('addthis.menu.share', checkCount); } $(".f1r-shares-twitter").attr("href", "https://twitter.com/intent/tweet?text=" + addthis_share.templates.twitter); $(".f1r-shares-facebook").attr("href", "https://www.facebook.com/sharer/sharer.php?u=" + addthis_share.url); $(".f1r-shares-linkedin").attr("href", addthis_config.services_custom[0].url); $(".f1r-shares-reddit").attr("href", addthis_config.services_custom[2].url); $(".f1r-shares-mendelay").attr("href", addthis_config.services_custom[1].url); function checkCount(){ setTimeout(function(){ $(".addthis_button_expanded").each(function(){ var count = $(this).text(); if (count !== "" && count != "0") $(this).removeClass("is-hidden"); else $(this).addClass("is-hidden"); }); }, 1000); } close How to cite this report {{reportCitation}} Cancel Copy Citation Details $(function(){R.ui.buttonDropdowns('.dropdown-for-downloads');}); $(function(){R.ui.toolbarDropdowns('.toolbar-dropdown-for-downloads');}); $.get("/articles/acj/172017/189694") new F1000.Clipboard(); new F1000.ThesaurusTermsDisplay("articles", "article", "189694"); $(document).ready(function() { $( "#frame1" ).on('load', function() { var mydiv = $(this).contents().find("div"); var h = mydiv.height(); console.log(h) }); var tooltipLivingFigure = jQuery(".interactive-living-figure-label .icon-more-info"), titleLivingFigure = tooltipLivingFigure.attr("title"); tooltipLivingFigure.simpletip({ fixed: true, position: ["-115", "30"], baseClass: 'small-tooltip', content:titleLivingFigure + " " }); tooltipLivingFigure.removeAttr("title"); $("body").on("click", ".cite-living-figure", function(e) { e.preventDefault(); var ref = $(this).attr("data-ref"); $(this).closest(".living-figure-list-container").find("#" + ref).fadeIn(200); }); $("body").on("click", ".close-cite-living-figure", function(e) { e.preventDefault(); $(this).closest(".popup-window-wrapper").fadeOut(200); }); $(document).on("mouseup", function(e) { var metricsContainer = $(".article-metrics-popover-wrapper"); if (!metricsContainer.is(e.target) && metricsContainer.has(e.target).length === 0) { $(".article-metrics-close-button").click(); } }); var articleId = $('#articleId').val(); if($("#main-article-count-box").attachArticleMetrics) { $("#main-article-count-box").attachArticleMetrics(articleId, { articleMetricsView: true }); } }); var figshareWidget = $(".new_figshare_widget"); if (figshareWidget.length > 0) { window.figshare.load("f1000", function(Widget) { // Select a tag/tags defined in your page. In this tag we will place the widget. _.map(figshareWidget, function(el){ var widget = new Widget({ articleId: $(el).attr("figshare_articleId") //height:300 // this is the height of the viewer part. [Default: 550] }); widget.initialize(); // initialize the widget widget.mount(el); // mount it in a tag that's on your page // this will save the widget on the global scope for later use from // your JS scripts. This line is optional. //window.widget = widget; }); }); } close Error Close Add Reset F1000.MICROSERVICES.AFFILIATION = ''; $(document).ready(function () { $('.js-affiliations-form').each((index, form) => { new AffiliationForm({ formId: form.id, institutionErrorSelector: '.comment-enter-institution', departmentErrorSelector: '.comment-enter-department', placeSelector: '.js-add-comment-place', stateSelector: '.js-add-comment-state', zipCodeSelector: '.js-add-comment-zipcode', countrySelector: '.js-add-comment-country', countryErrorSelector: '.comment-enter-country', }); }); }); $(document).ready(function () { var reportIds = { "451972": 0, "451973": 0, "453634": 0, "451970": 0, "451971": 0, "453632": 0, "451968": 0, "453633": 0, "451969": 0, "455190": 0, "455191": 0, "455188": 0, "455189": 0, "455186": 0, "455187": 0, "455185": 0, "455194": 0, "455192": 0, "455193": 0, "437350": 0, "458086": 0, "437351": 0, "458087": 0, "437348": 0, "458084": 0, "437349": 0, "458085": 0, "458082": 0, "437347": 0, "458083": 0, "437356": 0, "437354": 0, "458090": 0, "437355": 0, "458091": 0, "437352": 0, "458088": 0, "437353": 0, "458089": 0, "453630": 0, "451966": 0, "453631": 0, "451967": 0, "453628": 3, "451964": 0, "453629": 0, "451965": 0, "453626": 0, "453627": 0, "453625": 0, }; $(".referee-response-container,.js-referee-report").each(function(index, el) { var reportId = $(el).attr("data-reportid"), reportCount = reportIds[reportId] || 0; $(el).find(".comments-count-container,.js-referee-report-views").html(reportCount); }); var uuidInput = $("#article_uuid"), oldUUId = uuidInput.val(), newUUId = "abc6125e-48b2-4206-a163-d9c108890cc2"; uuidInput.val(newUUId); $("a[href*='article_uuid=']").each(function(index, el) { var newHref = $(el).attr("href").replace(oldUUId, newUUId); $(el).attr("href", newHref); }); }); An innovative open access publishing platform offering rapid publication and open peer review, whilst supporting data deposition and sharing. Browse Gateways Collections How it Works Contact For Developers Cookie Notice Privacy Notice RSS Submit Your Research Follow us © 2012-2026 F1000 Research Ltd. ISSN 2046-1402 | Legal | Partner of Research4Life • CrossRef • ORCID • FAIRSharing R.templateTests.simpleTemplate = R.template(' $text $text $text $text $text '); R.templateTests.runTests(); var F1000platform = new F1000.Platform({ name: "f1000research", displayName: "F1000Research", hostName: "f1000research.com", id: "1", editorialEmail: "
[email protected]", infoEmail: "
[email protected]", usePmcStats: true }); $(function(){R.ui.dropdowns('.dropdown-for-authors, .dropdown-for-about, .dropdown-for-myresearch');}); // $(function(){R.ui.dropdowns('.dropdown-for-referees');}); $(document).ready(function () { if ($(".cookie-warning").is(":visible")) { $(".sticky").css("margin-bottom", "35px"); $(".devices").addClass("devices-and-cookie-warning"); } $(".cookie-warning .close-button").click(function (e) { $(".devices").removeClass("devices-and-cookie-warning"); $(".sticky").css("margin-bottom", "0"); }); $("#tweeter-feed .tweet-message").each(function (i, message) { var self = $(message); self.html(linkify(self.html())); }); $(".partner").on("mouseenter mouseleave", function() { $(this).find(".gray-scale, .colour").toggleClass("is-hidden"); }); }); Sign In Remember me Forgotten your password? Sign In Cancel Email or password not correct. Please try again Please wait... $(function(){ // Note: All the setup needs to run against a name attribute and *not* the id due the clonish // nature of facebox... $("a[id=googleSignInButton]").click(function(event){ event.preventDefault(); $("input[id=oAuthSystem]").val("GOOGLE"); $("form[id=oAuthForm]").submit(); }); $("a[id=facebookSignInButton]").click(function(event){ event.preventDefault(); $("input[id=oAuthSystem]").val("FACEBOOK"); $("form[id=oAuthForm]").submit(); }); $("a[id=orcidSignInButton]").click(function(event){ event.preventDefault(); $("input[id=oAuthSystem]").val("ORCID"); $("form[id=oAuthForm]").submit(); }); }); If you've forgotten your password, please enter your email address below and we'll send you instructions on how to reset your password. The email address should be the one you originally registered with F1000. Email address not valid, please try again You registered with F1000 via Google, so we cannot reset your password. To sign in, please click here . If you still need help with your Google account password, please click here . You registered with F1000 via Facebook, so we cannot reset your password. To sign in, please click here . If you still need help with your Facebook account password, please click here . Code not correct, please try again Reset password Cancel Email us for further assistance. Server error, please try again. If your email address is registered with us, we will email you instructions to reset your password. If you think you should have received this email but it has not arrived, please check your spam filters and/or contact for further assistance. Please wait... Register $(document).ready(function () { signIn.createSignInAsRow($("#sign-in-form-gfb-popup")); $(".target-field").each(function () { var uris = $(this).val().split("/"); if (uris.pop() === "login") { $(this).val(uris.toString().replace(",","/")); } }); });
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.