Devices used in the Internet of Things

By using a microcontroller with a communication interface and configuration memory in IoT devices, cloud service switching without firmware updates is achieved, solving the problem of complex and costly switching in existing technologies and improving the flexibility and efficiency of connectivity.

CN115943620BActive Publication Date: 2026-04-03SIEMENS AG
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-09
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

The current IoT devices require firmware updates when switching to another parent structure, which is complex and costly, making it difficult to achieve a simplified switching process.

Method used

A microcontroller device with a communication interface and configuration memory is used to establish a connection with the first cloud service through the control unit and switch to the second cloud service according to the control command, avoiding firmware updates and using the configuration data in the configuration memory to achieve connection switching.

Benefits of technology

It simplifies the process of switching IoT devices between different cloud services, reduces the need for firmware changes, and improves the flexibility and efficiency of connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115943620B_ABST
    Figure CN115943620B_ABST
Patent Text Reader

Abstract

A microcontroller-controlled device for connection to the Internet of Things is configured to terminate its existing connection with a cloud service and initiate a new connection with another cloud service in response to a pre-given trigger signal from an external source.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The Internet of Things (IoT) is a system that connects objects—devices—through a network (typically the Internet) so that they can exchange data with each other. For example, in the industrial sector, this data exchange involves the transmission of measurement data by machines and the collection and evaluation of that measurement data by programs.

[0002] Unlike local data collection, such as in factory facilities, the Internet of Things (IoT) offers the possibility of collecting data independently of its source. Furthermore, IoT platforms offer the advantage of decoupling the data provided by devices from their specific performance by sending the data, thereby enabling broad interoperability between devices of different types, manufacturing years, or manufacturers.

[0003] Devices that need to communicate with or become part of the Internet of Things (IoT) are typically connected to a higher-level infrastructure, such as an internet-based cloud service. Many such internet-based cloud services exist, such as Amazon Web Services, Azure, or MindSphere. However, as an alternative to a purely internet-based, cloud-service-oriented upper-level infrastructure, a local server can also be used.

[0004] Here, for a device with a microcontroller and controlled by means of firmware for the microcontroller, the upper-level structure to which it establishes a connection is determined in the initial firmware. Changes to the upper-level structure are performed within the scope of firmware updates, i.e., with significant changes to the running software.

[0005] The objective of this invention is to provide a device for use in the Internet of Things (IoT) that avoids the aforementioned drawbacks, particularly by enabling simplified switching to another parent structure. Another objective is to describe a corresponding method, which, in particular, enables simplified switching to another parent structure.

[0006] This task is achieved in terms of devices used in the Internet of Things. Regarding the method, the solution lies in the method having the features of claim 9.

[0007] The device according to the present invention, applied in the Internet of Things, includes a communication interface and a configuration memory. The device includes a microcontroller with firmware as a control unit for controlling the communication interface.

[0008] The device's control unit is configured to establish a connection with the first cloud service based on the configuration stored in the configuration memory.

[0009] In addition, the device's control unit is designed to receive control commands and, upon receiving them, establish a connection with the second cloud service.

[0010] A microcontroller unit (MCU) is a chip typically used in devices that function as control units. This chip has a clock frequency of less than 1 GHz, particularly less than 300 MHz, and connected to it volatile memory (RAM) of particularly less than 16 MB. In other words, it is not the more powerful microprocessor (MPU) typically used in PCs and related devices. Therefore, the size of the configuration memory, which is non-volatile memory, is limited, particularly less than 16 MB. Microcontrollers preferably include input / output interfaces, ROM (Read-Only Memory), and RAM (Random Access Memory) and are configured for use as embedded systems.

[0011] A communication interface is an interface that allows connection to cloud services. This connection can be, for example, a direct or indirect connection to the Internet. Therefore, a communication interface can be an Ethernet LAN interface, a WLAN interface, or an interface that operates according to another principle.

[0012] Advantageously, the device can thus establish a connection with the second cloud service based on control commands. Here, firmware changes, including corresponding modifications to configuration data, are unnecessary. This greatly simplifies the overhead of changing the connection to the cloud service.

[0013] Other advantageous designs of the device according to the invention are derived from the dependent claims of claim 1. Here, the embodiments of the independent claim may be combined with features of one of the dependent claims, or preferably also with features of several dependent claims. Therefore, the following features may also be additionally provided:

[0014] The control unit can be configured to, after establishing a connection with a first cloud service, exchange data generated during operation unidirectionally or bidirectionally with the first cloud service, and after establishing a connection with a second cloud service, exchange data generated during operation unidirectionally or bidirectionally with the second cloud service. In other words, it exchanges data generated during operation with two cloud services. It should also be noted that the cloud services are not merely provisioning services for the initial setup of the device. More precisely, cloud services are services with which the device maintains or desires to maintain a connection for an extended period in order to exchange data generated during operation.

[0015] The control unit can also be configured to send operational data to a first cloud service after establishing a connection with it, and to send operational data to a second cloud service after establishing a connection with it. The operational data is selected from a non-exhaustive list of measurement data, timestamps, calculation results, and control command data for actuators and / or interfaces. Therefore, unlike the provisioning service, the cloud service also processes operational data of the device, such as measurement data.

[0016] The control unit can be designed to establish a connection with a picking server (also known as a supply service) before establishing a connection with the first cloud service, and to receive address data and / or password data from the picking server, and to establish a connection with the first cloud service based on the address data and / or password data.

[0017] Alternatively, the control unit can be designed to perform connection establishment with the first cloud service based on the configuration stored in the configuration memory.

[0018] The device's control unit can be designed to receive address data for a second cloud service upon receiving control commands, and to establish a connection to the second cloud service using that address data. Such address data could be, for example, an Internet URL (Uniform Resource Locator). This makes changes to the connected cloud service flexible and future-proof, as the address data does not need to be specified when creating the initial firmware, thus preventing issues with subsequent changes or device-specific URLs.

[0019] Preferably, the control unit is configured to store address data for the second cloud service in the configuration memory after receiving a control command. It is feasible to overwrite the corresponding address data for the first cloud service to optimally utilize the existing storage space of the configuration memory.

[0020] In one design possibility, which can be alternatively or additionally implemented, the address data for the second cloud service already exists in the configuration memory. Therefore, the second cloud service or multiple additional cloud services can be pre-configured. Then, in response to control commands, a connection to the second cloud service is established based on the stored address data. Thus, the control commands can remain very simple and do not necessarily contain any data, but only instructions to the device.

[0021] Here, the control unit can be designed to automatically select a second cloud service from the parent structure stored in the configuration memory upon receiving a control command. This can be achieved in its simplest form by cyclically using the cloud services stored in the configuration memory.

[0022] Preferably, the device's control unit is designed to receive and store certificates from the second cloud service after a connection is established. For example, the certificates are digital certificates according to ITU-T standard X.509. These digital certificates, in particular, allow secure communication over the Internet, such as via HTTPS protocols and digital signatures of messages (e.g., emails).

[0023] In one embodiment of the invention, the device's control unit is designed to receive certificates from a specific address. This specific address could be, for example, an address specifically provided for downloading certificates from a second cloud service.

[0024] In an alternative design, the device's control unit is configured to send identification information to a second cloud service and receive a certificate in response to that identification information. Therefore, in this case, no address is provided; instead, direct communication is used. The identification information could be, for example, a serial number or a combination of serial number, device type, username, and current date.

[0025] The device's control unit can also be configured to receive control commands from a local connection, particularly a Bluetooth or WLAN connection. Thus, control commands can be provided to the device from a locally located PC or mobile terminal, such as a smartphone or tablet. In a particular design, the control unit is configured to receive control commands only from a local connection. Specifically, the control unit can be configured to reject control commands from the internet.

[0026] However, alternatively, the control unit can also be configured to receive control commands from a source (where the device is only accessible via the internet), such as a higher-level controller for multiple such devices (which may, for example, reside at the manufacturer of such devices) or a first or second higher-level structure. Multiple such devices can then be controlled accordingly via a central administrator. This also enables control of devices whose installation locations make them difficult to access. This higher-level control can also be referred to as provisioning services. Although provisioning services and cloud services can be implemented technically similarly, i.e., in the form of one or more internet servers, their purposes are entirely different. Therefore, provisioning services are typically controlled by the device manufacturer, while cloud services are not. Furthermore, the functionality of provisioning services is usually limited to enable the most secure possible operation. A key characteristic of provisioning services is long-term secure access under a fixed internet address, thus allowing secure connection even to devices stored in a warehouse for a year. In contrast, cloud services are constantly evolving in both technology and content.

[0027] The control unit can be designed to receive control commands in HTTP push messages.

[0028] The device's control unit can be configured to terminate the connection with the cloud service when establishing a connection with the second cloud service. In other words, instead of establishing a second connection, the connection with the first cloud service is replaced by a connection with the second cloud service. Here, connections to both parent structures can exist for a short period if this is advantageous for certificate reception or other transmission processes.

[0029] Another solution to the proposed task lies in a method according to the invention for connecting a device connected to a first cloud service to a second cloud service, wherein a triggering device sends a control command to the device, and the device establishes a connection with the second cloud service in response to the control command. Here, the triggering device generates a certificate provision in the second cloud service. The device receives the certificate from the second cloud service.

[0030] The triggering device can be a smartphone, tablet, PC, or cloud service. Its interaction with the second cloud service and the device causes a change in the device-to-cloud service connection.

[0031] Here, the triggering device can advantageously obtain the address generated for providing the certificate to the device from the second cloud service and transmit that address to the device. Preferably, the certificate can only be received from that address under certain restrictions, such as only being downloaded once, in order to prevent unauthorized use.

[0032] In an alternative design, the triggering device transmits its identification information to a second cloud service. If the device itself subsequently transmits the identification information to a second upper-level architecture, the second cloud service transmits a certificate to the device after obtaining consistent identification information.

[0033] The invention will now be described and explained in more detail with reference to the embodiments shown in the accompanying drawings.

[0034] The accompanying drawings schematically illustrate:

[0035] Figure 1 The image shows a manufacturing machine with connectivity to an internet-based cloud service.

[0036] Figure 2 This shows the status of the manufacturing machine after the first step of connecting to another internet-based cloud service.

[0037] Figure 3 This shows the status of the manufacturing machine after the second step, which involves connecting to another internet-based cloud service.

[0038] Figure 1A schematic internet connection is shown between manufacturing machine 10 (e.g., a milling machine) and a first internet-based cloud service 20 (e.g., Azure). For example, this connection uses the known MQTT protocol (Message Queuing Telemetry Transport Protocol). To establish the connection, the milling machine includes a microcontroller 12 and a communication interface 13, which establishes a wired LAN connection 14, for example, to a router 16. The router 16 itself is connected to the internet 18 and thus enables data exchange between the manufacturing machine 10 and the first cloud service 20.

[0039] Data required to establish a connection with the first cloud service, such as Internet address data and certificates, is stored in configuration memory 11 within manufacturing machine 10. Configuration memory 11 need not be a separate component here, but may be part of microcontroller 12. Microcontroller 12 is controlled by firmware, which is also stored and loaded into manufacturing machine 10 during its provision.

[0040] exist Figure 1 In the first state shown, manufacturing machine 10 can, for example, transmit measurement data or data about its own state to first cloud service 20. First cloud service 20 receives this data and further processes it, for example, by storing the data or forwarding it to subscribers 24 who provide data for manufacturing machine 10.

[0041] Figure 2 The manufacturing machine 10 is shown at a later point in time. The manufacturing machine 10 is placed into a configuration mode by the control command 25 it has received, in which the configuration of the manufacturing machine 10 can be changed, such as regarding the connection to the first cloud service 20.

[0042] In this example, the control command is issued by a mobile device, such as smartphone 22, and reaches manufacturing machine 10 via Bluetooth connection 21. Therefore, control command 25 originates from another device located in the immediate surrounding environment of manufacturing machine 10. Control command 25 can also be transmitted by a local device via a (W)LAN connection.

[0043] Another possibility for generating control command 25 is that it is generated within the manufacturing machine 10 itself through the operation of the equipment. For example, the manufacturing machine 10 may have a graphical user interface where a menu item, for example, is provided: "Change Cloud Service". The selection of this menu item corresponds to control command 25 and triggers a corresponding processing internally. Alternatively, a simpler approach can be adopted to cause a change in the configuration of the manufacturing machine 10. For example, the manufacturing machine 10 may have multiple operation buttons. Here, each operation button is directly associated with the selection of a specific cloud service 20, 31. Pressing one of the operation buttons represents control command 25, which causes a corresponding change in cloud service 20, 31, provided that the operation button is associated with a cloud provider 20, 31 different from the cloud provider 20, 31 currently connected to the equipment.

[0044] In other embodiments, control command 25 can also be sent to manufacturing machine 10 from a remote device, for example, via the Internet. In this way, control command 25 can also be transmitted from a remote PC to manufacturing machine 10. It is also possible to transmit control command 25 to manufacturing machine 10 from cloud services 20 and 31, which can be achieved through the currently connected cloud service 20 or through another cloud service 31, whereby a connection to the other cloud service is first established.

[0045] In this embodiment, control instruction 25 includes address data 23 in URL form for the second cloud service 31. In configuration mode, manufacturing machine 10 takes over the address data 23 and establishes a connection to the address given by the address data on the Internet. This establishes a connection with the second cloud service 31.

[0046] In an alternative design, address data 23 may already be stored in the configuration memory 11 of the manufacturing machine 10. In this case, control command 25 need not include address data 23. Alternatively, control command 25 may either contain no information about the second cloud service 31 at all, or it may contain an identifier for the second cloud service 31, which the manufacturing machine 10 can use to determine the address data 23 to be selected from the configuration memory 22. If control command 25 does not contain any address data 23, the microcontroller 12 of the manufacturing machine 10 itself can select from cloud services 31 that can be determined at a fixed, pre-given address in the configuration memory 11 or on the Internet.

[0047] After establishing a connection with the second cloud service 31, the following is obtained: Figure 3The diagram illustrates a scenario where manufacturing machine 10 is connected to a second cloud service 31 via router 16 and the Internet 18. The connection to the first cloud service 20 is interrupted, meaning it is no longer maintained in this embodiment. In an alternative embodiment, the two connections can also be maintained in parallel.

[0048] Advantageously, and in some applications, it is necessary to ensure data exchange between manufacturing machine 10 and the second cloud service 31, and thus protect it from unauthorized access. For this purpose, manufacturing machine 10 can obtain a certificate (e.g., according to standard X.509) from the second cloud service 31, which can be used to perform encryption and thus protection. Mutual identification can also be performed in this way.

[0049] To obtain the certificate, the certificate can be provided for download by the second cloud service 31 via an Internet address, i.e., a URL. For example, such a URL could be "cloudservice.org / Z_123456_20200102 / ". Here, 123456 could be an identifier, such as the serial number of manufacturing machine 10, or another sequence of bytes known to both the second cloud service 31 and manufacturing machine 10. Therefore, in association with the date, manufacturing machine 10 can determine the URL based on its known data without obtaining it from an external source.

[0050] Another possibility is that the smartphone 22 or tablet (from which control commands 25 are provided to the manufacturing machine 10) establishes its own connection with the cloud service 31. Due to the significantly higher processing speed and memory size in such a device compared to the manufacturing machine 10 with its microcontroller 12, there is generally no issue with the smartphone 22 performing these management steps. The cloud service 31 then provides the smartphone with a URL under which a certificate can be obtained. The smartphone 22 transmits this URL to the manufacturing machine 10. This can already be achieved via control commands 25.

[0051] If production machine 10 has a corresponding URL available, it performs the certificate download. For security reasons, it is advantageous to ensure, on the cloud service 31 side, that such download is performed only once. Alternatively, the public key of production machine 10 can be transmitted to cloud service 31, and the certificate can be encrypted therefrom, making it difficult to use outside of production machine 10.

[0052] Overall, this provides a terminal device with connectivity to cloud services, enabling flexible handling of IoT connectivity despite significant limitations imposed by the control provided by the microcontroller 12.

[0053] It should be understood that manufacturing machine 10 is merely an example of use, and the invention can also be used on other devices and other types of devices. For example, the invention can be advantageously used in conjunction with a suction robot, a lawnmower robot, or an industrial controller.

[0054] List of reference numerals

[0055] 10 Manufacturing Machines

[0056] 11 Configure Memory

[0057] 12 microcontrollers

[0058] 13 communication devices

[0059] 14 LAN connections

[0060] 16 routers

[0061] 18 Internet

[0062] 20, 31 Cloud Services

[0063] 24 subscribers

[0064] 21 Bluetooth connections

[0065] 22 smartphones

[0066] 23 address data

[0067] 25 Control Commands

Claims

1. A system comprising a device (10) used in the Internet of Things and a triggering device, characterized in that, The devices (10) used in the Internet of Things include: - Communication interface (13), - Configure memory (11), - A microcontroller (12), which has firmware and serves as a control unit for controlling the communication interface (13). The control unit is configured as follows: - A connection to the first cloud service (20) is established based on the configuration stored in the configuration storage (11). - Receive control commands (25), and establish a connection with the second cloud service (31) upon receiving the control commands (25). - The control command (25) is used to receive address data (23) for the second cloud service (31), and the connection is established using the address data (23). - After establishing a connection with the second cloud service (31), receive and store the certificate from the second cloud service (31). Furthermore, the triggering device (22) is configured to transmit control commands (25) to the device (10) and provide a certificate that can be received in a limited manner in the second cloud service (31).

2. The system according to claim 1, characterized in that, The control unit is configured to exchange data occurring during operation with the first cloud service (20) unidirectionally or bidirectionally after establishing a connection with the first cloud service (20), and to exchange data occurring during operation with the second cloud service (31) unidirectionally or bidirectionally after establishing a connection with the second cloud service (31).

3. The system according to claim 2, characterized in that, The control unit is configured to send operational data to the first cloud service (20) after establishing a connection with the first cloud service (20), and to send operational data to the second cloud service (31) after establishing a connection with the second cloud service (31), wherein the operational data is selected from a non-exhaustive list of the following: measurement data, timestamps, calculation results, and control instruction data for actuators and / or interfaces.

4. The system according to any one of claims 1 to 3, characterized in that, The control unit is configured to establish a connection with the picking server before establishing a connection with the first cloud service (20), and to receive address data and / or password data from the picking server, and to establish a connection with the first cloud service (20) based on the address data and / or password data.

5. The system according to any one of claims 1 to 3, characterized in that, The control unit is configured to establish a connection with the first cloud service (20) based on the configuration stored in the configuration memory (11).

6. The system according to claim 1, characterized in that, The control unit is configured to send identification information to the second cloud service (31) and receive the certificate in response to the identification information.

7. The system according to claim 1, characterized in that, The control unit is configured to receive the control command (25) from a local connection.

8. The system according to claim 7, characterized in that, The control unit is configured to receive the control command (25) from a Bluetooth connection (21) or a WLAN connection.

9. The system according to claim 7, characterized in that, The control unit is configured to receive the control commands only from a local connection.

10. The system according to claim 1, characterized in that, The control unit is configured to receive the control command (25) in an HTTP push message.

11. The system according to claim 1, characterized in that, The control unit is configured to select the second cloud service (31) from the upper-level structure stored in the configuration memory (11) when it receives the control command (25).

12. The system according to claim 1, characterized in that, The control unit is configured to terminate the connection with the first cloud service (20) when establishing a connection with the second cloud service (31).

13. A method for connecting a device (10) to a second cloud service (31), said device being connected to a first cloud service (20), characterized in that, - Using the system according to any one of claims 1 to 12, - The triggering device (22) transmits the control command (25) to the device (10). - The device (10) establishes a connection with the second cloud service (31) in response to the control command (25). - The triggering device (22) provides a limited-acceptability certificate in the second cloud service (31). - The device (10) receives a certificate from the second cloud service (31).

14. The method according to claim 13, characterized in that, The triggering device (22) obtains an address generated for providing a certificate to the device (10) from the second cloud service (31) and transmits the address to the device (10).

15. The method according to claim 13, characterized in that, The triggering device (10) transmits identification information for the device (10) to the second cloud service (31), the device (10) transmits the identification information to the second cloud service (31), and the second cloud service (31) transmits or provides the certificate to the device (10) after obtaining the identification information.

Citation Information

Patent Citations

  • Configurable Wireless Power Control and Management

    US20200050753A1