Device update transmission using bloom filters
By using the Bloom filter data structure to quickly verify whether the device is an update activity, the delay problem of existing systems when processing device update requests is solved, and a faster and more efficient device update process is achieved.
Patent Information
- Application Number
- CN202510180151.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2019-06-11
- Filing Date
- 2020-06-11
- Publication Date
- 2025-06-03
AI Technical Summary
When existing systems process large number of device update requests, they require a large amount of hardware resources and time, resulting in delays in device updates.
The Bloom filter data structure is used to quickly verify whether the computerized device is an update activity. By generating the Bloom filter data structure of multiple hash values, the use of hardware resources and time is reduced.
It realizes determining whether the device is an update activity in a short time, reducing device update delays and reducing the demand for hardware resources.
Smart Images

Figure CN120085891A_ABST
Abstract
Description
[0001] This application is a divisional application of the application with the filing date of June 11, 2020, application number 202010528167.0, and invention name of "Device Update Transmission Using a Bloom Filter", and claims the benefit of U.S. Patent Application No. 16 / 437,344, titled "DEVICE UPDATE TRANSMISSION USING A BLOOM FILTER", filed on June 11, 2019, which is hereby incorporated by reference in its entirety. Technical Field
[0002] The present disclosure generally relates to systems, devices, and methods for securely providing device updates. More specifically, the present disclosure relates to improved systems, devices, and methods for providing device updates to computerized devices (e.g., computerized devices in V2X vehicles) included in an update campaign. Background Art
[0003] With the miniaturization and commercialization of computers, manufacturers are producing more types of devices that include any number of embedded computers and processors. The computers in computerized devices can control the operation of the devices; collect, store, and share data; communicate with other computers and other computerized devices; and update their own software, etc.
[0004] The Internet of Things (IoT) is a network of computerized physical devices having embedded processors, electronics, software, data, sensors, actuators, and / or network connectivity that enable the devices to connect and exchange data via a digital network, where the digital network includes the Internet, cellular networks, and other wireless networks. Generally, each "thing" is uniquely identifiable through its embedded computing system and is capable of interoperating within the existing Internet infrastructure. The "things" in the sense of IoT can refer to a wide variety of computerized devices, such as consumer appliances, enterprise devices used in commercial and corporate environments, manufacturing machines, agricultural equipment, energy-consuming devices in homes and buildings (switches, power outlets, appliances, lighting systems, light bulbs, TVs, garage door openers, fire sprinkler systems, security systems, etc.), healthcare devices, infrastructure management devices, robots, drones, and transportation devices and vehicles, etc.
[0005] In many examples, modern vehicles and transportation machinery (e.g., cars, trucks, airplanes, trains, ships, motorcycles, scooters, etc.) include several embedded processors or embedded computers in their subsystems and are computer-controlled in at least some aspects. Similarly, an increasing number of modern transportation infrastructure devices (e.g., traffic lights, traffic cameras, traffic sensors, bridge monitors, bridge control systems, etc.) include at least one, and often include multiple, embedded processors or embedded computer systems and are computer-controlled in at least some aspects. These computer-controlled elements of the transportation network typically communicate with each other, passing various types of information back and forth, and they can react, respond, change their operations, or rely on and use information received / sent / sent to them from other vehicles in vehicle-to-vehicle (V2V, also known as car-to-car (C2C)) communication and / or infrastructure elements in vehicle-to-infrastructure (V2I, also known as car-to-infrastructure (C2I)) communication for safe, accurate, efficient, and reliable operation. V2V and V2I systems together are typically referred to as V2X systems or infrastructure.
[0006] Computers in computerized devices operate based on their software and / or firmware and data. To ensure safe and correct operation, computerized devices must be properly initialized and updated with appropriate software, firmware, executable instructions, digital certificates (e.g., public key certificates), cryptographic keys, etc. (collectively referred to hereinafter as "digital assets" or "software") in accordance with the manufacturer's intent so that the IoT consists of devices executing authorized, known-good software and data. However, problems arise when unauthorized individuals or organizations (e.g., hackers) replace or change the software in computerized devices. Problems also occur when older software, untested software, unapproved software, and / or software with known bugs are installed in computerized devices.
[0007] Conventional systems require a large amount of hardware and other resource allocations to process device update requests for "campaigns" that include a large number of devices. For example, a campaign to update the software of all vehicles with V2X capabilities of a specific brand, model, year, and / or having a specific digital asset (e.g., one in a specific set of certificates), which can number in the tens of thousands or even hundreds of thousands. For example, a conventional system for processing device update requests for a large campaign requires a large amount of memory, storage, network bandwidth, etc. to process all requests, which include requests from a set of devices that are part of the campaign (e.g., vehicles of a specific brand, model, year, and / or certificate group) interspersed with requests from devices that are not part of the campaign (e.g., vehicles that are part of the V2X environment but do not have the specific brand, model, year, and / or certificate set of that campaign). The campaigns mentioned herein can include device updates for a specific group of computerized devices, where the device updates can include software updates, firmware updates, etc.
[0008] Some conventional systems can use linear search or binary search to determine whether a computerized device should receive a device update as part of a campaign. For example, to determine whether a vehicle that issued a request is in a specific set of brands, models, years, and / or certificates included in the campaign. However, both linear search and binary search typically require storing a large amount of data, and searching the data generally requires a large amount of processing time and power. In addition, the amount of time required to complete each such search increases according to the number of devices (e.g., vehicles) in the campaign. Therefore, conventional systems cause significant delays or wait times when determining whether a computerized device is included in a device update campaign, e.g., a delay of five seconds or more for each device / request.
[0009] In some embodiments, the present technology includes improved systems, devices, and methods that can verify that a computerized device belongs to a group or set of computerized devices that are part of a campaign or are scheduled to receive a device update. In some implementations, the present technology includes systems that can reduce the hardware resources and time required to determine whether a computerized device is included in a campaign and to retrieve a device update as part of the campaign. Summary of the Invention
[0010] Accordingly, the present technology includes improved systems, devices, and methods that can provide updates to computerized devices. In some embodiments, a system for providing updates to computerized devices can include an activity management service that includes computer-executable instructions that cause a first processor to perform operations including detecting an activity initiation request indicating that a set of computerized devices is to be updated for an activity. These operations can also include generating a Bloom filter data structure including a plurality of hash values, where the plurality of hash values correspond to the set of computerized devices to be updated. Additionally, the operations can include providing the Bloom filter data structure to a network edge. And, the system can include the network edge that includes computer-executable instructions that cause a second processor to perform operations including determining that the computerized device is to receive a device update from the activity management service based on a match between a hash value associated with the computerized device and a hash value among the plurality of hash values of the Bloom filter data structure. These operations can also include obtaining, in response to the activity management service confirming that the computerized device is a member of the activity, a device update associated with the computerized device from the activity management service. Additionally, these operations can include providing the device update to the computerized device, whereby the device update modifies the computerized device.
[0011] In one embodiment, the network edge further includes computer-executable instructions that cause the second processor to perform operations including: using the Bloom filter data structure to determine that the computerized device does not belong to the activity; and providing, without communicating with the activity management service, an indication that there is no device update for the computerized device to the computerized device.
[0012] In one embodiment, the computerized device is an Internet of Things (IoT) device, a consumer appliance, or a vehicle.
[0013] In one embodiment, the device update can include a registration certificate or a pseudonym certificate.
[0014] In one embodiment, the device update can include software or firmware to be installed on the computerized device.
[0015] In one embodiment, the device update can include installation information or an installation script.
[0016] In one embodiment, the activity management service further includes computer-executable instructions that cause the first processor to perform operations including storing data corresponding to the computerized device to be updated.
[0017] In one embodiment, the data may include one or more of the following: an activity start date, an activity end date, a plurality of vehicle identification numbers, a plurality of product serial numbers, and a product model.
[0018] In one embodiment, the activity management service further includes computer-executable instructions that cause a first processor to perform an operation of determining whether the computerized device is in the activity by accessing the data.
[0019] In one embodiment, the Bloom filter data structure is of a constant size regardless of the number of computerized devices in the set.
[0020] In one embodiment, generating the Bloom filter data structure may include adjusting a plurality of hash functions that generate the hash values of the Bloom filter data structure based on a false positive rate threshold.
[0021] In one embodiment, the system enables the computerized device to poll the network edge for the device update when the Bloom filter data structure is generated.
[0022] In one embodiment, the activity management service further includes computer-executable instructions that cause a first processor to perform an operation of instructing the network edge to delete the Bloom filter data structure at the end of the activity.
[0023] In one embodiment, each computerized device in the set of computerized devices includes a uniform resource locator for communicating with the network edge.
[0024] In one embodiment, the network edge device may include computer-executable instructions that cause a processor to perform operations including obtaining a Bloom filter data structure including a plurality of hash values from the activity management service. These operations may further include determining that the computerized device is to receive a device update from the activity management service based on a match between the hash value associated with the computerized device and the hash values of the Bloom filter data structure. Additionally, these operations may include sending a device update request corresponding to the computerized device to the activity management service. Moreover, these operations may include obtaining a device update associated with the device update request from the activity management service after the activity management service confirms that the computerized device is a member of the activity. Additionally, these operations may include providing the device update to the computerized device, whereby the computerized device installs the device update.
[0025] In one embodiment, an activity management service may include computer-executable instructions that cause a processor to perform operations including detecting an activity initiation request for a plurality of computerized devices designated to be updated with a device update for an activity. The operations may also include storing data corresponding to the plurality of computerized devices to be updated and generating a Bloom filter data structure including a plurality of hash values, where each hash value is based on data of each of the plurality of computerized devices. Additionally, the operations may include providing the Bloom filter data structure to a network edge and receiving a request for the device update from a computerized device. Further, the operations may include confirming that the computerized device is a member of the activity based on data corresponding to the plurality of computerized devices to be updated. Moreover, the operations may include providing a device update associated with the request to the network edge, the device update modifying electronic data accessed or stored by the computerized device. Brief Description of the Drawings
[0026] The drawings included in this specification and constituting a part of this specification illustrate examples of numerous features of the disclosed subject matter. These drawings, together with the specification, are used to explain the principles of the various techniques described herein.
[0027] Figure 1 A block diagram of an example operating environment for computerized devices, a network edge, and an activity management service consistent with the exemplary embodiments described herein;
[0028] Figure 2 A block diagram of an example system capable of initializing a Bloom filter data structure using computerized devices, a network edge, and an activity management service consistent with the exemplary embodiments described herein;
[0029] Figure 3A and Figure 3B A block diagram of an example operating environment for computerized devices, a network edge, and an activity management service to process a device update request consistent with the exemplary embodiments described herein;
[0030] Figure 4 A process flow diagram of an example method for managing activity-related requests with a network edge consistent with the exemplary embodiments described herein;
[0031] Figure 5 A process flow diagram of an example method capable of managing activity-related requests with an activity management service consistent with the exemplary embodiments described herein;
[0032] Figure 6 A data flow diagram showing an example data flow between a computerized device, an activity management service, and a certificate management service consistent with the exemplary embodiments described herein; and
[0033] Figure 7 A block diagram of an example of a computing system that can host systems and methods consistent with the exemplary embodiments described herein. Detailed Description
[0034] Reference will now be made in detail to various embodiments of the techniques described herein, examples of which are illustrated in the accompanying drawings. In the drawings, wherever possible, the same reference numbers will be used to refer to the same or like parts. Introduction
[0035] An increasing number of devices, sensors, appliances, etc. include other hardware components, such as network components. These network components can enable various devices to communicate with any number of external devices, servers, etc. In some examples, the software and firmware used to operate the devices can become outdated or insecure. Thus, the devices can request device updates via the network components to improve device performance and prevent security issues. In some embodiments, the devices are updated in groups or campaigns. These campaigns can enable a manufacturer or any other suitable entity to provide device updates to a set of devices. In some examples, the devices can periodically poll an external server or service to determine whether there are updates available for the devices (e.g., whether there is an active campaign that includes the devices) and / or to determine whether the devices can retrieve the device updates.
[0036] In various embodiments, device updates can include updates to automotive components after they are manufactured and initialized. For example, to ensure safe and proper operation in the field, embedded devices such as electronic control units (ECUs) used in vehicles can be initialized during manufacturing by providing digital assets, such as security assets. The digital assets can include various digital certificates, keys, unique identifiers, and software. In some examples, a CMS or certificate management service generates these digital assets, and a secure provisioning system distributes these digital assets to the manufacturing plant.
[0037] Typically (but not always) after leaving the factory and being put into use, a computerized device may request a device update to retrieve new or alternative software, firmware, digital assets, etc., which may enable the computerized device to operate correctly or in a modified manner. In some of the described embodiments, the computerized device may request a device update, and these requests may be filtered using a bloom filter data structure. Various embodiments using a bloom filter data structure provide a determination as to whether a computerized device is to receive a device update within an approximately constant amount of time that is shorter than that required by a conventional system and with less storage than a conventional system.
[0038] Figure 1 A block diagram of an example operating environment for a computerized device, network edge, and activity management service that can handle device update requests. In some embodiments, system 100 may be implemented with any suitable computing device, server, external remote service network, etc. As shown in this example, system 100 may include a network edge 102, a device management server 104, a device 106, an activity management service 108, an internal service 110, a database 112, a bloom filter device 114, and a message server 116, among others.
[0039] In some implementations, the network edge 102 may include a device management server 104, which may implement an initialization 118 of device update activities, etc. The activity may specify or include any set, group, or number of devices (also referred to herein as "computerized devices") 106 for which a device update (e.g., a software update, firmware update, or new application, etc.) is to be retrieved. In some embodiments, a device update may include installation information or an installation script associated with software, firmware, or any combination thereof to be stored in the device 106. The installation information may indicate a directory or location within the memory of the device 106 to store the device update. The installation script may include executable instructions for installing the device update.
[0040] In some embodiments, device 106 can be an Internet of Things (IoT) sensor, a consumer appliance, a vehicle, or a device that is part of a vehicle. For example, device 106 can include a vehicle, a watercraft (e.g., a boat), an aircraft, a spacecraft, a medical device, a robot, a drone, a wireless or wired communication module, or an IoT device. In some examples, device 106 can correspond to an RSU of a traffic control device (e.g., a traffic signal, a traffic light, or an electronic traffic sign), a digital billboard, a pedestrian warning system, a motorcycle sensor, a bicycle sensor, an electronic sign, a streetlight sensor, or a construction warning sensor, etc.
[0041] In some examples, device management server 104 can detect 120 an activity initiation request (not shown) from a network interface, an external server, or device 106. In some implementations, device management server 104 can detect an activity initiation request from a server or device for a management activity. Then, device management server 104 can forward the activity initiation request to activity management service 108, which can belong to internal service 110. Internal service 110 includes any number of computing devices, such as servers, databases, client devices, etc. In some embodiments, internal service 110 can detect the activity initiation request through any suitable interface that sends activity-related data along a bypass via device management server 104. The activity initiation request can indicate a list or set of devices 106 to be updated as part of a device update activity. In some examples, the activity initiation request can include a set of device identifiers or a set of identification information for each device, such as a set of serial numbers, a set of product names, a set of Internet Protocol (IP) addresses, a set of Media Access Control (MAC) addresses, etc., as well as the time to start the device update, the time to end the device update, and / or optionally other information specifying activity parameters.
[0042] In some embodiments, the activity management service 108 may determine that an activity is to be initiated. In some examples, initiating an activity may include storing 122 activity data and status in a database 112 of the internal service 110. The activity data stored in the database 112 may include information from an activity initiation request, such as a set of serial numbers, a set of product names, a set of Internet Protocol (IP) addresses, a set of Media Access Control (MAC) addresses, a set of some other device identification information, a time to start device updates, a time to end device updates, etc. In some examples, the status of the activity stored in the database 112 may indicate whether the activity has started or whether the activity is invalid until a later time. In some embodiments, the database 112 may store data locally within the activity management service 108, or the database 112 may be an external database 112 accessed via a network connection (not shown).
[0043] In some embodiments, the activity management service 108 initializes 124 a data structure for an activity before processing a device update request for the activity. The data structure may include a Bloom filter data structure, a linked list, a multi-dimensional array, or any other data structure that can be used to quickly identify devices 106 and / or requests 134 included in or corresponding to the activity (e.g., devices from a list or set of device identifiers from an activity initiation request). In some examples, the Bloom filter data structure is allocated as a static or constant-sized structure that does not expand or contract based on or according to the number of devices in the activity (e.g., when a device is added to the activity). In some implementations, the Bloom filter data structure may include an array of hash values corresponding to computing devices included in the activity. In some embodiments, separate hash functions may be utilized to generate each hash value. For example, each Bloom filter data structure may be associated with X different hash functions. Each of the X different hash functions may map or hash the identification information of a computing device to a location in the array of the Bloom filter data structure. For example, to add a computing device to the Bloom filter data structure, the identification information of the computing device is provided to each of the X different hash functions. Each of the X different hash functions generates an output value corresponding to an array location. The array of the Bloom filter data structure may be modified to store one value for each array location, which is the output generated by the X different hash functions. In one example, the identification information of a computerized device may be provided to five hash functions, each of which generates a separate array location value. The Bloom filter data structure may be modified to store a binary value or any other suitable value at each array location mapped to the output of the five hash functions. Thus, after mapping the computerized device to the Bloom filter data structure, five array locations of the Bloom filter data structure may store a value of 1.
[0044] The number of hash functions that map hash values to an array of a Bloom filter data structure can be based on a false positive rate threshold. For example, reducing the number of hash functions, as compared to the number of entries in the array of the Bloom filter data structure, can reduce the false positive rate. Conversely, increasing the number of hash functions used to map hash values to the array of the Bloom filter data structure can increase the false positive rate. In some examples, the activity management service 108 can adjust the number of hash functions that generate hash values for the Bloom filter data structure based on the false positive rate threshold.
[0045] In some embodiments, the activity management service 108 can send 126 the Bloom filter data structure to the Bloom filter device 114 via the message server 116. For example, the message server 116 can cause the Bloom filter data structure to be provided 128 to the Bloom filter device 114 synchronously or asynchronously. In some examples, the network edge 102 can begin to run or execute an activity 130 by storing a cache copy of the Bloom filter data structure in the Bloom filter device 114 or the device management server 104. Thereby, the network edge 102 can begin to process device update requests after initializing the Bloom filter data structure by storing the Bloom filter data structure in the network edge 102. In some embodiments, if a device 106 requests an update and is a member of an activity for which the initialization of the Bloom filter data structure has not been completed, the network edge 102 will respond as follows: requesting that the device 106 has no available updates or is not part of an activity, as described in detail below with reference to Figure 2 as made. Thus, in some examples, the device 106 can poll the network edge 102 and wait 132 for a response indicating whether the device 106 belongs to an activity, which includes polling the network edge 102 for device updates when generating the Bloom filter data structure.
[0046] Figure 1An example of how system 100 processes a device update request from device 106 is also shown, where device 106 is included in an activity represented by a Bloom filter data structure, which may be referred to as a true positive. As shown in this example, device 106 may send a device update request 134 to network edge 102 after the Bloom filter data structure is initialized and the filtering process is running. Network edge 102 may query 136 the Bloom filter data structure (e.g., on Bloom filter device 114) to determine whether the requesting device 106 belongs to the activity. In some embodiments, querying 136 the Bloom filter data structure may include generating a hash value using a hash function applied to a device identifier (i.e., identification information) from device 106. The device identifier or identification information may be or include a MAC address, an IP address, a serial number, etc. In various implementations, a hash value that matches a hash value stored in the Bloom filter data structure for the identification information of device 106 may indicate that device 106 may belong to or is likely to belong to the activity, where the hash values stored in the Bloom filter data structure are generated from a series of device identifiers included in the activity initiation request. A match in the Bloom filter data structure does not guarantee that the requesting device 106 is part of the activity because, in various implementations, the Bloom filter may produce false positives at a rate of about 10% or lower (e.g., 8%, 6%, 5%, 4%, 3%, 2%, 1%) or less than 1% but greater than 0%. In some embodiments, network edge 102 may determine 138 whether a matching hash value for device 106 is stored in the Bloom filter data structure in an approximately constant amount of time, regardless of the number of hash values (corresponding to devices) in the Bloom filter data structure (corresponding to the activity). Thus, when determining whether device 106 belongs to the activity, the Bloom filter data structure provides a faster processing time and uses less memory compared to traditional systems; and these improvements increase as the number of devices in the activity increases.
[0047] In Figure 1 In the various embodiments shown, after a match is found, compared, or otherwise identified, Bloom filter device 114 may indicate 140 to device management server 104 that device 106 is a member of the activity. Then, device management server 104 may send device update request 134 to activity management service 108, e.g., via message server 116. In some examples, message server 116 may send 144 device update request 134 to activity management service 108 asynchronously or synchronously.
[0048] In various embodiments, the event management service 108 can detect a device update request 144 / 134 and query 146 the database 112 to find or otherwise determine whether the device 106 actually belongs to the event, which may not be the case if the Bloom filter data structure produces a false positive. In Figure 1 the example shown, the database 112 can return 148 to the event management service 108 event data, event status, a list or range of devices (e.g., device identifiers), and / or other information. In the example shown in the figure, the event management service 108 can determine 150 that the device 106 is a member of the event being looked for, and that the device 106 is going to receive or be provided with a device update as part of the event. In some embodiments, the event management server 108 can return 152 an indication that the device 106 is a member of the event to the device 106 via the message server 116, the Bloom filter device 114, and / or the device management server 104 or any combination thereof. In some embodiments, the event management service 108 returns, sends, or otherwise provides 154 device update data to the device 106 via the network edge 102. In various embodiments, the device update data can include digital assets of the device 106 that are adjusted or updated when executed or otherwise used, e.g., by modifying existing functionality, adding new functionality, deleting unwanted functionality, etc., such as software, firmware, etc.
[0049] Accordingly, Figure 1 represents a true positive example, where the device 106 matches the hash value stored in the Bloom filter data structure and the device 106 actually belongs to the event. In some embodiments, the system 100 can be implemented with any number of devices. For example, the network edge 102 can be implemented with a single server, the internal service 110 can be implemented with a single server; and, the system 100 can not include the message server 116, such that the network edge 102 and the internal service 110 communicate directly with each other.
[0050] Figure 2 A block diagram of an example system for initializing a Bloom filter data structure is shown. In some embodiments, the system 200 can be implemented with any suitable number of computing devices, such as the network edge 102, the device management server 104, the device 106, and the event management service 108, etc.
[0051] In some embodiments, system 200 may include a network edge 102, which may include a device management server 104. The device management server 104 may detect 202 an activity initiation request (not shown) from a network interface, an external server, or a device 106. In some implementations, the device management server 104 may detect an activity initiation request from a server or device for management activities. Then, the device management server 104 may send the activity request to an activity management service 108, which may belong to an internal service 110. In some embodiments, the internal service 110 may detect the activity initiation request through any suitable interface that sends activity-related data bypassing through the device management server 104. The activity initiation request may indicate a series of devices to be updated as part of a device update activity. In some examples, the activity request may include a set of serial numbers, a set of product names, a set of Internet Protocol (IP) addresses, a set of Media Access Control (MAC) addresses, a time to start device update, a time to end device update, etc.
[0052] In some embodiments, the activity management service 108 may determine that an activity is to be initiated. In some examples, initiating the activity may include storing 204 activity data and status in a database 112 of the internal service 110. The activity data stored in the database 112 may include information from the activity request, such as, a set of serial numbers, a set of product names, a set of Internet Protocol (IP) addresses, a set of Media Access Control (MAC) addresses, a time to start device update, a time to end device update, etc. In some examples, the status of the activity stored in the database 112 may indicate whether the activity has started or the subsequent time and date when the activity started. In some embodiments, the activity management service 108 generates 206 a data structure for the activity before processing the device update request for the activity. The data structure may include a Bloom filter data structure, a linked list, a multi-dimensional array, or any other data structure. In some implementations, the Bloom filter data structure may include an array of hash values corresponding to the computing devices included in the activity. In some embodiments, each hash value may be generated by a separate hash function.
[0053] Figure 2Also shown is an example of how the system 200 processes a device update request received from the device 106 before the Bloom filter data structure representing the event is ready for use by the network edge 102. In the example shown, when generating the Bloom filter data structure at the event initiation time, and / or before the Bloom filter data structure is retrieved by the network edge 102 and installed therein, the device management server 104 may receive or detect 208 a device update request 134 from the device 106, which will trigger a determination as to whether the device 106 belongs to the event. In the example shown, since the event management service 108 is in the process of generating 206 the Bloom filter data structure of the event when the request 208 / 134 arrives, the device management server 104 will return a response 214 indicating that there is no update for the device 106, or in other words, return a response 214 indicating that the device 106 is not in the event.
[0054] In this particular example, the device management server 104 may send 210 the request 208 / 134 for device update from the device 106 to the Bloom filter device 114. The Bloom filter device 114 may determine 212 whether the device 106 has event membership by generating a hash value based on the identification information of the device 106 (e.g., serial number, IP address, MAC address, etc.) included in the request 208 / 134. In various examples, the Bloom filter device 114 may compare the hash value of the device 106 with the hash value of the Bloom filter data structure stored in the Bloom filter device 114 to attempt to identify a matching hash value. In Figure 2 the example, since the Bloom filter data structure has not been received from the event management service 108, resulting in the Bloom filter device 114 not having a stored Bloom filter data structure for the event, the Bloom filter device 114 cannot perform any comparison.
[0055] For this situation of the illustrated embodiment, the Bloom filter device 114 returns 214, via the device management server 104, an exclusion response indicating that the device 106 is not in the event. This may occur even if the device 106 belongs to an event associated with the Bloom filter data structure generated, created, or produced 206 simultaneously by the event management service 108.
[0056] In some embodiments, device 106 may periodically poll network edge 102 (e.g., send a request) for device updates. For example, device 106 may send a request for device updates to device management server 104 based on a predetermined time interval (e.g., several minutes, hours, days, weeks, months, years, etc.). In such an embodiment, one or more polling requests 208 may arrive at network edge 102 while the Bloom filter data structure is being generated. In some embodiments (as shown), network edge 102 may determine that the device is not active and return an update-not or exclude response 214 to device 106 without communicating with activity management service 108.
[0057] As discussed above with respect to Figure 1 After the Bloom filter data structure is generated, activity management service 108 may send 216 the Bloom filter data structure to network edge 102, for example, via message server 116. In some examples, network edge 102 may store a cached copy of the Bloom filter data structure in device management server 104 or a separate Bloom filter device 114. In some embodiments, network edge 102 may begin processing device update requests 134 using the Bloom filter data structure after initializing the Bloom filter data structure and storing the Bloom filter data structure within network edge 102. In various embodiments, device management server 104 may return device updates 154 to any suitable device 106, where the any suitable device 106 belongs to an activity associated with the Bloom filter data structure stored after initialization of the Bloom filter data structure.
[0058] Figure 3A and Figure 3B FIG. is a block diagram of an example operating environment for computerized devices, network edges, and activity management services to process device update requests. In some embodiments, system 300 may be implemented using any suitable number of computing devices, such as, for example, network edge 102, device management server 104, device 106, and activity management service 108, etc.
[0059] In Figure 3A the example shown, the Bloom filter data structure may be as described above with respect to Figure 1 and Figure 2Generated and stored as discussed. For example, any suitable external server, web-based interface, computing device, etc. can initiate 302 the device update activity via an initialization request 304 sent to the internal service 110. In some embodiments, the activity management service 108 can initiate an activity by storing 306 the activity data and status in the database 112 of the internal service 110. In some implementations, the activity management service 108 initializes 308 the data structure of the activity before starting the activity, for example, a Bloom filter data structure. In some embodiments, the activity management service 108 can send 310 the Bloom filter data structure to the Bloom filter device 114 via the message server 116.
[0060] Figure 3A First, an example of how the system 100 processes a device update request from the device 106 is shown, where the device 106 is not included in the activity represented by the Bloom filter data structure. As shown in this example, the network edge 102 can start implementing, running, or executing the activity 312 by storing a copy of the Bloom filter data structure in the Bloom filter device 114 or the device management server 104. After that, since the Bloom filter data structure representing the activity is stored within the network edge 102, the network edge 102 can process the device update request for information about the activity. In some examples, the system 100 waits 314 until the Bloom filter data structure representing the activity is stored within the network edge 102 before processing the device request. In some embodiments, the network edge 102 can support multiple simultaneous activities related to various device updates for various devices. In some such embodiments, each activity can be represented by a separate Bloom filter data structure; while in other embodiments, a single Bloom filter data structure generated from data from multiple activities can be used to represent all activities in a single data structure.
[0061] In Figure 3AIn the example shown, the device management server 104 may receive or detect 316 an update request from the device 106, as previously described. In some examples, the device management server 104 may send 318 the device update request from the device 106 to the Bloom filter device 114. The Bloom filter device 114 may determine 320 the membership of the device 106 in the activity by generating a hash value based on or using the identification information of the device 106, where the identification information of the device 106 is included in the request 316. In some examples, the Bloom filter device 114 may compare the hash value of the device 106 with the hash values in the Bloom filter data structure stored in the Bloom filter device 114 to attempt to find or identify a matching hash value in the Bloom filter data structure. The Bloom filter does not produce false negatives; thus, the absence of a matching hash value indicates that the device 106 is not part of the activity and / or there is no available update data. In the example shown, the hash identification information of the device 106 is not in the Bloom filter data structure, and thus, the Bloom filter device 114 returns 322 a response via the device management server 104 indicating that the device 106 is not in the activity or currently does not have available updates.
[0062] Figure 3B An example of how the system 100 processes a device update request 324 from a device 106 that is not actually included in the activity but appears to be in the activity according to the representation of the Bloom filter data structure (which may be referred to as a false positive) is also shown. As previously described, in various embodiments, the Bloom filter data structure may produce false positives at a rate of about 10% or less, e.g., about 5%. As shown in this example, the device management server 104 receives or detects a request 324 from the device 106 to update, which may trigger a determination as to whether the device 106 belongs to the activity. In such an example, the request 324 may come from or correspond to a different device 106 than the device that issued the request 316 and was not included in the activity in the previous example.
[0063] In some examples, the device management server 104 may send 326 the device update request 324 from the device 106 to the Bloom filter device 114. The Bloom filter device 114 may determine 328 the membership of the requesting device 106 in the activity by generating a hash value based on the identification information of the request of the device 106 and looking for the same hash value in the Bloom filter data structure. After finding the same hash value in the Bloom filter data structure, the Bloom filter device 114 returns 330 a response to the device management server 104 indicating that the device 106 is likely in the activity (because the hash value identified in the Bloom filter data structure matches the generated hash value corresponding to the device 106).
[0064] In some embodiments, the device management server 104 may send 332 a device update request for the device 106 to the active management service 108 via the message server 116. In some examples, the active management service 108 may query 334 the database 112 to find or otherwise determine whether the device is an active member, which may not be the case if the Bloom filter data structure produces a false positive. After the database 112 returns 336 the active data and status information to the active management service 108, in this particular example, the active management service 108 determines 338 that the requesting device 106 is not a member of the active. In some examples, the active management service 108 may return 340 a response indicating that the device 106 is not an active via the message server 116, the Bloom filter device 114, and / or the device management server 104 or any combination thereof.
[0065] In Figure 3B the example, although the device 106 is not actually part of the active, the network edge 102 has produced a false positive indicating that the device 106 is part of the active and will receive the device update. This occurs when the hash value generated from the identifying information of the requesting device 106 happens to match the hash value of a different device that is actually part of the active represented by the Bloom filter data structure. As described above, this false positive error will eventually be detected when the active management service 108 accesses the active data and status information to verify that the requesting device 106 is actually a member of the active. Nevertheless, since the various embodiments of the Bloom filter device 114 never return a false negative membership response to a device 106 that is not part of the active, the overall performance of the Bloom filter device 114 reduces the wait time experienced by the requesting device 106 and reduces the end-to-end resource usage and processing time by significantly reducing the number of device update requests sent to and processed by the active management service 108, particularly the number of non-active member requests.
[0066] Figure 4 is a process flow diagram of an example method that can utilize network edge management of active-related requests. In some embodiments, the method 400 may be implemented with any suitable number of computing devices, such as, for example, the network edge 102, the device management server 104, the Bloom filter device 114, the network edge 602, the active service 608, or any combination thereof.
[0067] As shown in this example, at block 402, the network edge can detect a request to initiate an activity for a device update. In some embodiments, any suitable server, web-based interface, device, or computerized device can initiate an activity by providing a list or set of computerized devices that are in or belong to the activity, as well as data such as an activity start date and an activity end date, where each of the computerized devices in the list or set is identified by a unique identifier, such as a vehicle identification number, a product serial number, a product model number, etc. In some embodiments, a uniform resource locator for the network edge is stored in the protected memory of each computerized device (e.g., computerized device 106) that requests a device update. The uniform resource locator enables the computerized device to securely contact a predetermined authorized network edge.
[0068] At block 404, the network edge can send the request to an activity management service (e.g., activity management service 108). In some embodiments, the network edge can send the request to the activity management service via a messenger device or service (e.g., message service 116). The messenger device can support asynchronous or synchronous communication. For example, the messenger device can store any number of requests and send those requests to the activity management service at a later time. In some embodiments, the messenger device can send requests for any number of activities from one or more network edges to one or more activity management services.
[0069] At block 406, the network edge can receive, retrieve, obtain, or otherwise access a Bloom filter data structure corresponding to the requested activity from the activity management service. For example, after the activity management service processes a request to initialize an activity, the network edge can receive or retrieve the Bloom filter data structure generated by the activity management service. In some embodiments, the Bloom filter data structure can be stored within the network edge in a device management server that communicates with the computerized device. In some examples, the Bloom filter data structure can be stored within the network edge in a separate device accessible by the device management server (e.g., Bloom filter device 114).
[0070] During operation, the device management server can receive or detect requests from computerized devices to attempt to determine whether a device update for an activity is available for the requesting device. The device management server can query the Bloom filter data structure stored locally or in a separate Bloom filter device to determine whether the computerized device is not a member of the activity or whether the computerized device could be a member of the activity, depending on a possible, low-probability, false positive.
[0071] At block 408, the network edge can determine that a computerized device most likely has a device update available from the active management service based on a hash value associated with the computerized device that matches a hash value stored in the Bloom filter data structure, where the stored hash value is identified by querying the Bloom filter data structure (as described above). On the other hand, when the requesting computerized device is not part of the active or has no available updates, the network edge can return a negative response to the computerized device. This occurs when the hash value associated with the computerized device does not match any of the hash values stored in the Bloom filter data structure.
[0072] In some embodiments, the network edge can generate any number of hash values from the identification information for the computerized device and compare those hash values to the values stored in the Bloom filter data structure. For example, the Bloom filter data structure can store five or more hash values based on the output of the identification information for the computerized device applied to five or more separate hash functions. In some embodiments, any number of hash functions can be used to generate the hash values stored in the Bloom filter data structure.
[0073] At block 410, the network edge can send a device update request corresponding to the computerized device to the active management service. In some embodiments, the network edge can send the device update request to the active management service in response to detecting one or more hash values corresponding to the identification information of the requesting device that match the hash values in the Bloom filter data structure. In some examples, sending the device update request to the active management service can enable verification that the computerized device belongs to the active and is not a false positive.
[0074] At block 412, in the case where the active management service has verified, confirmed, or determined that the computerized device is indeed a member of the active, the network edge can receive, retrieve, or otherwise obtain the device update associated with the requesting computerized device from the active management service. In some embodiments, the active management service can verify that the computerized device is a member of the active based on the stored data corresponding to the active. For example, the data can include a list of identification information for computerized devices from which device updates can be retrieved as part of the active (i.e., a list of identifiers corresponding to the computerized devices included in the active); and the active management service can determine that the requesting device is on the list. In some embodiments, the network edge can receive or retrieve the device update directly from the active management service or via a messenger device, or from any other suitable computing device.
[0075] At block 414, the network edge may update, revise, provide, or modify the computerized device by sending a device update from the activity management service to the computerized device. In some embodiments, the device update may modify software, firmware, etc. stored in the computerized device. The network edge may send or otherwise supply the device update to the computerized device, which may automatically install the device update upon receipt. In some examples, the device update may modify the computerized device by installing a new application, modifying an existing application, updating a firmware driver that controls a hardware component, etc.
[0076] Figure 4 The process flow diagram of does not intend to indicate that the operations of method 400 are to be performed in any particular order, or that the operations cannot be performed simultaneously, or that all the operations of method 400 are to be included in every case. Additionally, method 400 may include any suitable number of other operations. For example, method 400 may also include the computerized device and the activity management service exchanging their transport layer security certificates before retrieving the device update. In some embodiments, the network edge may not detect a request to initiate an activity and send the request to the activity management service. For example, an external server, a web-based interface, etc. may initiate an activity by sending the activity's data directly to the activity management service without accessing the network edge.
[0077] Figure 5 is a process flow diagram of an example method that may utilize an activity management service to manage activity-related requests. In some embodiments, method 500 may be implemented using any suitable number of computing devices, such as, the activity management service 108, the database 112, the internal service 110, the activity service 608, or any combination thereof.
[0078] At block 502, the activity management service may receive or detect an activity initiation request indicating multiple computerized devices to be updated for an activity. In some embodiments, the activity management service may detect an activity initiation request from the network edge or from a messenger device that provides asynchronous or synchronous messages from the network edge. In some embodiments, the activity management service may directly detect an activity initiation request from a web-based interface, a device that manages the activity, etc. As described above, the activity initiation request may include identification information for each device that should receive a device update as part of the activity, the activity start date or time, and the activity end date or time, etc.
[0079] At block 504, the activity management service may store data corresponding to the computerized devices to be updated. In some embodiments, the activity management service may store data corresponding to the computerized devices to be updated locally or in an external database. In some implementations, the activity management service may analyze, search, or query the data to determine whether the computerized devices are part of an activity. For example, if the activity management service later detects a device update request from a computerized device with a unique identifier, the activity management service may analyze, search, or query the data to determine whether the device (e.g., the unique identifier) is included in the activity in order to provide the device update to the computerized device.
[0080] At block 506, the activity management service may generate a Bloom filter data structure representing the computerized devices included in the activity and thus to which the activity's device updates will be provided. In various implementations, the Bloom filter data structure includes a plurality of hash values, where the hash values are generated from the unique identifier (or other identifying information) of each of the computerized devices that are part of the activity. In some examples, the Bloom filter data structure may include hash values based on the data or identifying information of each of the computerized devices to be updated.
[0081] In some embodiments, the Bloom filter data structure may include any number of hash values based on the identifying information of each computerized device to be updated. For example, the Bloom filter data structure may include an array, linked list, vector, etc. that can store any number of hash values. In some embodiments, the identifying information of each computerized device is applied to any number of hash functions, and each hash function generates an output bit or series of bits stored in the Bloom filter data structure. In some embodiments, the activity management service may generate the Bloom filter data structure based on a union operation applied to a plurality of groups of computerized devices to be included in the activity.
[0082] At block 508, the activity management service may send or otherwise provide the Bloom filter data structure to the network edge, for example, after the Bloom filter data structure is initialized. In some embodiments, the activity management service may send the Bloom filter data structure to the network edge via an asynchronous messaging device (e.g., message server 116). For example, the asynchronous messaging device may receive the Bloom filter data structure and then delay sending the Bloom filter data structure to the network edge until a later time or date, which can improve communication via a network interface with high latency and / or low bandwidth limitations.
[0083] At block 510, the activity management service may receive a device update request from a computerized device. In some embodiments, the activity management service may receive the device update request only after determining, based on the Bloom filter data structure provided by the activity management service to the network edge at block 508, that the computerized device corresponding to the request is likely (except for false positives) to be part of an activity. In some such embodiments, the network edge forwards the device update request to the activity management service only when the hash value generated or obtained from the identification information of the computerized device that issued the request matches the hash value stored in the Bloom filter data structure. As described above, when the hash value generated or obtained from the identification information of the computerized device that issued the request does not match any of the hash values stored in the Bloom filter data structure, the network edge does not contact the activity management service but provides an accurate "no update" response to the computerized device that requested the device update but is not included in the activity.
[0084] At block 512, the activity management service may confirm, verify, or otherwise determine that the computerized device is a member of the activity. In some embodiments, the activity management service may compare the identification information of the computerized device that has requested a device update with the data stored for the activity (e.g., stored locally or in a database) to determine whether the activity data indicates that the computerized device is part of the activity. In various implementations, the identification information of the computerized device is included in the request. As a more specific example, the activity management service may search a list of unique identifiers (e.g., serial numbers) that are part of the activity data for the unique identifier of the computerized device, where the list of unique identifiers in the activity data includes all devices that are part of the activity.
[0085] At block 514, after determining that the computerized device is indeed a member of the activity, the activity management service may send the device update associated with the device update request (and the activity) to the network edge. In some examples, the device update may be code, instructions, binaries, etc. that are added to, replace, and / or modify the firmware, software, or any combination thereof stored on the computerized device.
[0086] If at block 512 the activity management service does not confirm, verify, or otherwise determine that the computerized device is a member of the activity, the activity management service does not perform the operation of block 514. In various implementations, the activity management service may determine that the computerized device is not a member of the activity because the computerized device (e.g., the identification information of the computerized device) is not listed, identified, or otherwise represented in the activity data.
[0087] In some embodiments, if the activity management service does not confirm, verify, or otherwise determine that the computerized device is an active member at block 512, then at block 516 the activity management service sends, provides, or otherwise indicates to the network edge that the requesting device is not part of the activity and / or that there is no message for an update for the requesting device, etc.
[0088] Figure 5 The process flow diagram is not intended to indicate that the operations of method 500 are to be performed in any particular order, or that the operations cannot be performed concurrently, or that all of the operations of method 500 are to be included in every instance. Additionally, method 500 can include any suitable number of other operations. For example, when an activity has ended (e.g., when the activity end date occurs), the activity management service can instruct the network edge to delete the Bloom filter data structure, e.g., by sending a message to the network edge to flush the cache or storage device storing the Bloom filter data structure, where the message can be triggered in response to the activity ending.
[0089] Figure 6 An example operating environment 600 is shown in which a network edge 602 interacts with a certificate management service 604, which is an example of a type of service for providing digital assets. In some embodiments, the certificate management service 604 can be a V2X certificate management service. In additional or alternative embodiments, the certificate management service 604 can be a C2X certificate management service and can be implemented as a server, one or more virtual machines on one or more computing devices, etc. As shown, the network edge 602 can submit a device update request (e.g., a certificate, etc.) for one or more computerized devices 606 to the certificate management service 604 via an activity service 608 and a network 610 (e.g., the Internet). In some embodiments, the device update can enable an application to be executed on the computerized device 606 in a secure environment. For example, the device update can include a certificate that enables the computerized device 606 to securely transmit communications with other computerized devices in a runtime environment.
[0090] In certain embodiments, the computerized device 606 corresponds to one or more of a vehicle, a watercraft (e.g., a boat), an aircraft, a spacecraft, a medical device, a robot, a drone, a wireless or wired communication module, and an IoT device. For example, the computerized device 606 can correspond to an OBU or ECU of a vehicle, a watercraft, an aircraft, a spacecraft, a robot, a drone, a medical device, or an IoT device. Also, for example, the computerized device 606 can correspond to an RSU of a traffic control facility (e.g., a traffic signal, a traffic light, or an electronic traffic sign), a digital billboard, a pedestrian warning system, a motorcycle sensor, a bicycle sensor, an electronic sign, a streetlight sensor, or a construction warning sensor, etc.
[0091] In some embodiments, the network edge 602 may use the Bloom filter data structure as described above to determine whether the computerized device 606 is to receive a device update from the certificate management service 604. In some examples, the device update may include an enrollment certificate, a pseudonym certificate, firmware, software, etc. The enrollment certificate may include any suitable digital certificate that enables a device update such as a software update, a firmware update, or any combination thereof to be provided to the computerized device 606. The pseudonym certificate may include a separate digital certificate that enables the computerized device 606 to securely exchange data or communicate during a runtime environment. In some implementations, the network edge 602 may send a response to the computerized device 606 that is not included in the device update activity. For example, the hash value of the identification information of the computerized device 606 may not match the hash value stored in the Bloom filter data structure associated with the device update activity. In some examples, the network edge 602 may determine that one or more computerized devices 606 are included in the device update activity. The network edge 602 may send a device update request to a registration authority 612, an enrollment certificate authority 614, a pseudonym certificate authority 616, or any combination thereof via the activity service 608.
[0092] In the operating environment 600, a device update or a certificate request is received by the activity service 608 from the network edge 602 via any suitable interface. For example, the activity service 608 may implement an API based on a client Representational State Transfer (REST) protocol or a Simple Object Access Protocol (SOAP), etc. As Figure 6 shown, the activity service 608 may implement a public or private API, and the certificate management service 604 may be a V2X or C2X certificate management service. The certificate management service 604 accepts a device update request, completes the task within a time frame, and then returns the result (e.g., the generated device update or certificate) to the network edge 602 via the activity service 608 and the network 610. In some implementations, the time frame may be several minutes, hours, or days, etc., depending on the processing capacity of the certificate management service 604.
[0093] The certificate management service 604 includes components for generating the requested device update. In Figure 6In the example shown, these components include a registration center 612, a registration certificate center 614, a pseudonym certificate center 616, a linkage authority 1 618, and a linkage authority 2 620.
[0094] In additional or alternative embodiments, the components of the certificate management service 604 may vary depending on whether the certificate management service 604 is configured as a V2X or C2X certificate management service. For example, in the case where the certificate management service 604 is used as a C2X certificate management service, the certificate management service 604 may include a Long Term Certificate Authority (LTCA), which is configured to perform a role similar to that of the registration certificate center 614. Similarly, when the certificate management service 604 is implemented as a C2X certificate management service, the certificate management service 604 may include an Authorization Authority (AA), which performs a role similar to that of the pseudonym certificate center 616. The components of the certificate management service 604 will be described in the following paragraphs.
[0095] In one example, the certificate management service 604 may be implemented as a CMS. Various embodiments of the certificate management service 604 can be used for a very large number of device transactions and certificate generation processes. In various embodiments, the certificate management service 604 can be implemented using multiple servers, multiple hardware security modules (HSMs), multiple computing engines, and multiple application platforms. In one example embodiment, each application platform may include one or more virtual machines (VMs) for storing the registration center 612, the registration certificate center 614, the pseudonym certificate center 616, and the linkage centers 618 and 620. In additional or alternative embodiments, each application platform may include one or more hardware platforms, such as an application server, a computer, or other computer hardware capable of storing and executing software applications. In Figure 6 In the example shown, the application platform for the registration certificate center 614 may be one or more VMs running the application program for the registration certificate center 614, and the application platform for the pseudonym certificate center 616 may be one or more VMs operable to store and run the application program for the pseudonym certificate center 616. Similarly, the application platform for the linkage authority 1 618 may be one or more VMs configured to store and run the linkage authority 1 application program, and the application platform for the linkage authority 2 620 may be one or more VMs operable to store and run the linkage authority 2 application program. Non-limiting examples of the certificate management service 604 can be implemented in a private data center, a cloud data center (e.g., Amazon web services (AWS) from Amazon), or a hybrid of a private and cloud data center.
[0096] In some embodiments, the certificate management service 604 may provide device updates including security certificates, such as enrollment certificates and pseudonym certificates, for use by the manufacturer's distributor appliance or the network edge 602. In certain embodiments, the certificate management service 604 may interact with a digital asset management system (DAMS, not shown) to provide certificates to the distributor appliance (not shown).
[0097] As Figure 6 shown, the architecture of the certificate management service 604 includes an enrollment center 612, an enrollment certificate center 614, a pseudonym certificate center 616, link center 1 618, and link center 2 620. Each of these components may utilize its own dedicated computing engine (not shown) to perform tasks. For example, the enrollment center 612 may utilize the enrollment center computing engine, the enrollment certificate center 614 may utilize the enrollment certificate center computing engine, the pseudonym certificate center 616 may utilize the pseudonym certificate center computing engine, link center 1 618 may utilize the link center 1 computing engine, and link center 2 620 may utilize the link center 2 computing engine. The functions of each of these components will be described in the following paragraphs.
[0098] In some embodiments, the architecture of the certificate management service 604 advantageously separates non-security-related applications from security functions. As Figure 6 the example shows, the enrollment center 612, the enrollment certificate center 614, the pseudonym certificate center 616, and link centers 618 and 620 are implemented as applications on their own VMs, which execute on their own dedicated computing engines, all separate from any non-security-related applications and functions. This provides technical and security advantages over traditional systems where the performance of the HSM is slower, or where the cloud service provider cannot supply the HSM, or where the proper management of the HSM is uncertain. In the certificate management service 604, cryptographic operations that utilize the HSM are performed in a computing engine (e.g., one or more computing engines).
[0099] By separating the critical security functions from each other and isolating them onto separate computing engines, as Figure 6As shown, for example, the computationally intensive encryption and security functions (e.g., elliptic curve butterfly expansion computation or elliptic curve digital signature) performed by the registration center 612, the registration certificate center 614, the pseudonym certificate center 616, and the link centers 618, 620 are much faster than those performed by existing traditional registration center systems. This design, in combination with the active service 608 described below, enables significant improvement in transaction processing in a multi-client environment by preventing any technical performance issues associated with the network 610 from interfering with or delaying the digital assets retrieved from the certificate management system 604 and supplied to the computerized devices 606. For example, the active service 608 can determine which computerized devices 606 belong to a device update activity and send a device update request. Thus, the active service 608 can determine whether a computerized device 606 belongs to a device update activity, and if so, provide the retrieved device updates (e.g., registration certificates and pseudonym certificates) to those computerized devices 606 during the supply process or at a later time. In some examples, the active service 608 can avoid bandwidth issues, network connectivity issues, etc. while supplying the computerized devices 606. For example, the active service 608 can prevent a large number of computerized devices 606 from querying the registration center 612 for device updates. The active service 608 can also quickly process device update requests with less data storage by storing hash values in a Bloom filter data structure, where the hash values can be based on the identification information from the computerized devices 606 belonging to the activity. Additionally, in some examples, the active service 608 can retrieve the registration certificates and pseudonym certificates from the CMS 604 synchronously or asynchronously and provide the registration certificates and pseudonym certificates to the computerized devices 606 synchronously or asynchronously. In some examples, the asynchronous retrieval and distribution of the registration certificates and pseudonym certificates can also reduce the time for the supply process of each computerized device. Thus, embodiments consistent with the present disclosure provide a specific, technically advantageous system architecture for determining computerized devices 606, where those computerized devices 606 are to retrieve device updates as part of an activity and retrieve device updates such as digital assets from the certificate management system 604.
[0100] In some embodiments, if the scale of the registry application executed by the registry 612 is to be modified, additional VMs can be added without changing the secure computing capabilities of the registry computing engine. Alternatively, if security computations limit performance, additional secure registry computing engines can be added. This same multi-dimensional scaling also applies to other components of the certificate management service 604. These features provide significant performance improvements and scalability compared to existing conventional certificate management services (CMS). In some implementations, the application platforms of the registry 612, the registration certificate center 614, the pseudonym certificate center 616, and the link centers 618, 620 are communicatively connected to the computing engine via their respective sets of input message queues, such that all of these components of the certificate management service 604 can be scaled independently of each other.
[0101] As described above, as Figure 6 illustrated by the non-limiting example of, each of the registry 612, the certificate centers 614, 616, and the link centers 618, 620 can be implemented as an application on its own virtual machine (VM). In additional or alternative implementations, one or more of the registry 612, the certificate centers 614, 616, and the link centers 618, 620 can be executed on a hardware platform (e.g., a server or a computing engine). The role and function of each of these applications executed on an application platform (e.g., a VM or a hardware platform) will be described in the following paragraphs.
[0102] In various embodiments, the registry 612 can be an institution in a provisioning network that validates user requests for digital certificates or other types of digital security assets and enables certificate centers (e.g., the registration certificate center 614 and the pseudonym certificate center 616) to issue digital certificates. In various embodiments, the registry 612 can perform any suitable public key infrastructure (PKI) technology. In various embodiments, the active service 608 can pass certificate requests to the registry 612, which can be implemented as a representational state transfer (REST) web service or a SOAP-based service, etc. In various embodiments, there can be multiple instances of the registry 612 executing simultaneously. This is for Figure 6Other components of the certificate management service 604 shown are similarly represented. The registry function of the certificate management service 604 is decentralized because its functions can be performed by multiple instances of the registry 612 implemented as a REST web service. One role of the registry 612 is to grant and fulfill certificate provisioning requests while preventing the signing pseudonym certificate authority 616 from determining which certificates are to be stored in a particular computerized device. The registry 612 can interact directly with the pseudonym certificate authority 616 and the linkage authorities 618, 620 via a message queue in order to fulfill its role in the certificate management service 604.
[0103] In some embodiments, the registry 612 (and Figure 6 other components therein) may be connected to a database (not shown). The certificate management service 604 may utilize a collection of data stores or databases for data storage and retrieval. For example, the databases used may consist of one or more logical or physical units of a database, where each unit has one or more tables that enable data segregation when needed. As used herein, the term "database" refers to one or more databases or data stores. In some embodiments, using multiple databases can allow for data segregation between the registry 612 and Figure 6 the other components shown. For example, this use of multiple databases allows for data segregation between the registry 612, the certificate authorities 614, 616, and the linkage authorities 618, 620.
[0104] In some embodiments, the databases used by the certificate management service 604 are a collection of one or more fast access, low latency databases. In some embodiments, the databases may be NoSQL databases or database services, such as the DynamoDB data service provided by Amazon web services. In various embodiments, the data stored in the databases depends on the application but may include previously issued certificates, various linkage authority values, data on the devices to which certificates have been issued, operator actions, etc. In some examples, the data may be stored unencrypted, encrypted, or in some combination thereof.
[0105] In various embodiments, since the digital certificates generated by the registration center 612 are divided into different parts, namely, the registration digital certificate and the pseudonym digital certificate, the certificate management service 604 includes a registration certificate center 614 and a pseudonym certificate center 616. The registration certificate center 614 is a non-central component of the certificate management service 604 because there can be multiple instances of the registration certificate center 614 that can be executed simultaneously. For example, in some embodiments, there can be multiple instances of the registration certificate center 614 that can be executed simultaneously. The registration certificate center 614 can receive requests for registration certificates from the registration center 612. One role of the registration certificate center 614 is to fulfill requests from the registration center 612 to issue registration certificates to terminal devices (e.g., dispenser devices). In some embodiments, the registration certificate center 614 directly interacts with the registration center 612 to fulfill its role in the CMS 604.
[0106] The pseudonym certificate center 616 is a non-central component of the CMS because there can be multiple instances of the pseudonym certificate center 616 that can be executed simultaneously. For the pseudonym certificate center 616, in various embodiments, there can be multiple instances of the pseudonym certificate center 616 that can be executed in parallel simultaneously. The pseudonym certificate center 616 can receive requests for pseudonym certificates from the registration center 612. One role of the pseudonym certificate center 616 is to fulfill requests from the registration center 612 to issue pseudonym certificates to terminal devices (e.g., computerized device 606). In certain embodiments, the pseudonym certificate center 616 fulfills requests for short-term pseudonym certificates for V2V functions. In some embodiments, the pseudonym certificate center 616 directly interacts with the registration center 612 to achieve its role in the CMS 604.
[0107] In various embodiments, Figure 6 The shown link centers 618, 620 link the identity of the certificate requester (i.e., the unique identifier of the certificate requester's device) to the issued pseudonym certificate for revocation. That is, link center 1 618 and link center 2 620 provide their respective link values, which are the unique identifiers of the devices as certificate requesters, to the issued pseudonym certificate. Link center 1 618 and link center 2 620 can receive requests for link values from the registration center 612, and then provide the requested link values to the registration center 612. The link centers 618, 620 directly interact with the registration center 612 to fulfill requests for link values.
[0108] In various embodiments, the computing engine of the CSM 604 can include an HSM, which allows these components to perform secure computations without being overly threatened by hackers. In some embodiments, the computing engine can be designed to perform secure computations by itself without an embedded HSM - in such embodiments, they embody the HSM.
[0109] In various embodiments, different versions of the HSM may be used in the CMS 604. For example, the HSM may include an embedded HSM installed as an insert card in one or more computing engines. In such an example embodiment, the embedded HSM may be installed in one or more computing engines as a Peripheral Component Interconnect (PCI) HSM or a PCI Express (PCIe) HSM. And, for example, the HSMs in the certificate management service 604 may include external, network-attached, or network-connected HSMs separate from the computing engines in their own enclosures.
[0110] Those skilled in the art will recognize Figure 6 The components and implementation details shown are examples given for the sake of brevity and clarity. Other components, processes, implementation details, and variations may be used without departing from the principles of the technology described herein, as this example is not intended to be limiting and many variations can be made.
[0111] Figure 7 is a block diagram of an example of a computing environment 700, which includes a computing system 702 that can be used to implement systems and methods consistent with embodiments of the present technology. Other components and / or arrangements may also be used. In some embodiments, the computing system 702 can be used to at least partially implement Figures 1 - 6 the various components of, for example, the network edge 102, the activity management service 108, the network edge 602, or the activity service 608, etc. In some embodiments, a series of computing systems similar to the computing system 700 can each be customized with specialized hardware and / or programmed as dedicated servers to implement Figures 1 - 6 one of the components shown, and these components can communicate with each other via a network 704.
[0112] In Figure 7In the example shown, computing system 700 includes multiple components, such as central processing unit (CPU) 706, memory 708, input / output (I / O) device 701, hardware security module (HSM) 712, and non-volatile storage device 714. System 700 can be implemented in various ways. For example, an implementation as an integrated platform (such as a server, workstation, personal computer, laptop, etc.) may include CPU 706, memory 708, non-volatile memory 714, and I / O device 710. In such a configuration, components 706, 708, 714, and 710 can be connected and communicate via a local data bus, and can access a data repository (implemented as, for example, a separate database system) via an external I / O connection. I / O component 710 can be connected to external devices via a direct communication link (such as a hardwired or local Wi-Fi connection), via a network such as a local area network (LAN) or a wide area network (WAN, such as a cellular phone network or the Internet), and / or via other suitable connections. System 700 can be stand-alone or a subsystem of a larger system.
[0113] CPU 706 can be one or more known processors or processing devices, such as a microprocessor of the Core series manufactured by Intel Corporation of Santa Clara, California, USA, or a microprocessor of the Athlon series manufactured by AMD Corporation of Sunnyvale, California, USA. Memory 708 can be one or more fast storage devices configured to store instructions and information executed or used by CPU 706 to perform certain functions, methods, and processes related to embodiments of the present technology. Storage 714 can be volatile or non-volatile, magnetic, semiconductor, tape, optical, or other types of storage devices or computer-readable media, and computer-readable media includes devices such as CDs and DVDs and solid-state devices for long-term storage.
[0114] In the shown embodiment, memory 708 contains one or more programs or applications 718 loaded from memory 714 or from a remote system (not shown), and when executed by CPU 706, these programs or applications 718 perform various operations, processes, procedures, or methods consistent with the present technology. Alternatively, CPU 706 can execute one or more programs remote from system 700. For example, system 700 can access one or more remote programs via network 704, and when these programs are executed, they perform functions and processes related to embodiments of the present technology.
[0115] In one embodiment, the memory 708 may include one or more programs 718 for performing the specialized functions and operations described herein for the network edge 102 and / or the active management server 108. In some embodiments, the memory 708 may also include other programs or applications that implement other methods and processes for providing auxiliary functions of the present technology. In some examples, the memory 708 may include any suitable non-transitory computer-readable medium. For example, the non-transitory computer-readable medium may include computer-executable instructions that direct the CPU 706 to execute instructions in accordance with the techniques described herein.
[0116] The memory 708 may also be configured with other programs (not shown) that are not related to the present technology and / or an operating system (not shown) that performs several functions well known in the art when executed by the CPU 706. For example, the operating system may be Microsoft Windows, Unix, Linux, an Apple Computers operating system, or other operating systems. The choice of, or even the use of, the operating system is not critical to the present technology.
[0117] The HSM 712 may be a device having its own processor that securely generates and stores digital security assets and / or securely performs various cryptographic and sensitive computations. The HSM 712 protects digital security assets (e.g., keys) and other sensitive data from access by attackers. In some embodiments, the HSM may be an insertion card or board directly attached to the computing system 700.
[0118] The I / O device 710 may include one or more input / output devices that allow data to be received and / or transmitted by the system 700. For example, the I / O device 710 may include one or more input devices that enable data to be input by a user, such as a keyboard, touch screen, mouse, etc. Additionally, the I / O device 710 may include one or more output devices that enable data to be output or presented to the user, such as a display screen, CRT monitor, LCD monitor, plasma display, printer, speaker device, etc. The I / O device 710 may also include one or more digital and / or analog communication input / output devices that allow the computing system 700 to communicate digitally with other machines and devices, for example. Other configurations and / or quantities of input and / or output devices may be included in the I / O device 710.
[0119] In the illustrated embodiment, system 700 is connected to network 704 (e.g., the Internet, a private network, a virtual private network, a cellular network, or other network or a combination thereof), and network 704 is in turn connected to various systems and computing machines, such as servers, personal computers, laptops, client devices, etc. Generally, system 700 can input data from external machines and devices and output data to external machines and devices via network 704.
[0120] In Figure 7 the illustrated example embodiment, data repository or data source 716 is an independent database external to system 700. In other embodiments, data source 716 can be hosted by system 700. In various embodiments, data source 716 can manage and store data for implementing systems and methods consistent with the present technology. For example, data source 716 can manage and store a data structure including identification information or data of each computerized device, such as an active device. Data source 716 can also manage and store a Bloom filter data structure including hash values of identification information based on any number of hash functions applied.
[0121] In some embodiments, data source 716 can include one or more databases that store information and are accessed and / or managed via system 700. For example, database 716 can be an Oracle database, a Sybase database, or other relational database. However, the systems and methods consistent with the present technology are not limited to a particular data structure or database, or even to the use of a database or data structure.
[0122] Those skilled in the art will recognize that Figure 7 the components and implementation details of the system in the example are given for purposes of explanation in brief and clear terms. Other components and implementation details can be used.
[0123] Although, for clarity of explanation, the above examples use specific examples of computerized devices such as OBU, ECU, and RSU, the present technology is not limited to these specific examples. Various embodiments consistent with the present technology can be used with a wide variety of computerized devices and can be used for a wide variety of computerized devices, such as medical equipment (e.g., dialysis machines, infusion pumps, etc.), robots, drones, autonomous vehicles, and wireless communication modules (e.g., embedded universal integrated circuit cards (eUICC)), etc.
[0124] By considering the description and practice of the technology disclosed herein, other embodiments of the present technology will be apparent to those skilled in the art. All various modifications to the exemplary embodiments and other embodiments of the subject matter that are apparent to those skilled in the art in the technical field to which the disclosed subject matter pertains are considered to fall within the scope of the disclosed subject matter.
Claims
1. A system for providing updates to a computerized device, the system comprising: one or more processors; one or more non-transitory computer storage media storing instructions that, when executed by the one or more processors, cause the processors to perform operations including: generating a filter data structure including a plurality of hash values, each of the plurality of hash values corresponding to a computerized device in a set of computerized devices to be updated; determining that a computerized device will receive a device update based on a hash value associated with the computerized device matching a hash value among the plurality of hash values of the filter data structure; and providing a device update to the computerized device based on the determination, wherein the device update includes a digital asset including one or more of software, firmware, or a digital certificate, and wherein the digital resource modifies the operation of the computerized device.
2. The system according to claim 1, wherein, the filter data structure includes a Bloom filter data structure.
3. The system according to claim 1, wherein, the filter data structure is assigned as a static size structure that does not expand and does not contract.
4. The system according to claim 1, wherein, the operations further include: confirming that a computerized device will receive a device update when a hash value associated with the computerized device matches a hash value among the plurality of hash values.
5. The system according to claim 1, wherein, an activity management service includes at least one of the one or more processors performing the generating operation; and wherein a network edge includes another of the one or more processors performing the determining operation and the providing device update operation.
6. The system according to claim 5, wherein, the system enables the computerized device to poll the network edge for device updates when generating the filter data structure.
7. The system according to claim 5, wherein, at least one of the one or more processors of the activity management service further performs operations including: detecting a request for a set of computerized devices to be updated, the request including identification information for each computerized device in the set of computerized devices to be updated; and wherein a filter data structure including a plurality of hash values is generated by providing the identification information to a hash function.
8. The system according to claim 7, wherein, the identification information includes one or more of a set of serial numbers, a set of product names, a set of Internet Protocol (IP) addresses, and a set of Media Access Control (MAC) addresses.
9. The system according to claim 7, wherein, another of the one or more processors of the network edge further performs operations including: using the plurality of hash values to determine that a second computerized device does not belong to the request; and providing an indication to the second computerized device that there is no device update for the second computerized device without communicating with the activity management service.
10. The system according to claim 7, wherein, A request for a set of computerized devices to be updated is active, and at least one of one or more processors of the activity management service further performs operations including: Storing data corresponding to the set of computerized devices to be updated, where the data includes one or more of an activity start date, an activity end date, a plurality of vehicle identification numbers, a plurality of product serial numbers, or a product model.
11. The system according to claim 2, wherein, A hash function is used to generate a plurality of hash values for the Bloom filter data structure.
12. A method for providing updates to computerized devices, the method comprising: Generating a filter data structure including a plurality of hash values, each of the plurality of hash values corresponding to one of the computerized devices in the set of computerized devices to be updated; Determining that a computerized device will receive a device update based on a hash value associated with the computerized device matching a hash value among the plurality of hash values of the filter data structure; and Providing a device update to the computerized device based on the determination, where the device update includes digital assets, the digital assets including one or more of software, firmware, or digital certificates, and where the digital resources modify the operation of the computerized device.
13. The method according to claim 12, wherein, The filter data structure is assigned as a static size structure that does not expand and does not contract.
14. The method according to claim 12, further comprising: Confirming that a computerized device will receive a device update when a hash value associated with the computerized device matches a hash value among the plurality of hash values.
15. The method according to claim 12, wherein, The generation is under the control of the activity management service; and where determining and providing the device update is performed under the control of the network edge.
16. The method according to claim 15, comprising: The network edge receives the filter data structure from the activity management service.
17. The method according to claim 15, wherein, When generating the filter data structure, the computerized device polls the network edge to obtain a device update.
18. The method according to claim 15, further comprising: Detecting a request for the set of computerized devices to be updated, the request including identification information of each computerized device in the set of computerized devices to be updated, where the detection is under the control of the activity management service; and where a filter data structure including a plurality of hash values is generated by providing the identification information to a hash function.
19. The method according to claim 18, wherein, The identification information includes one or more of a set of serial numbers, a set of product names, a set of Internet Protocol (IP) addresses, and a set of Media Access Control (MAC) addresses.
20. The method according to claim 18, further comprising: Determining, under the control of the network edge server, that a second computerized device does not belong to the request using the plurality of hash values; and Provide an indication to the second computerized device that there is no device update for the second computerized device without communicating with the activity management service.
21. The method according to claim 12, wherein, the generated filter data structure is a Bloom filter data structure, and the hash function is used to generate multiple hash values for the Bloom filter data structure.
22. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform a method, the method comprising: Generating a filter data structure including multiple hash values, each of the multiple hash values corresponding to a computerized device in a set of computerized devices to be updated; Determining that a computerized device will receive a device update based on a match between a hash value associated with the computerized device and a hash value among the multiple hash values of the filter data structure; and Providing a device update to the computerized device based on the determination, wherein the device update includes a digital asset, the digital asset including one or more of software, firmware, or a digital certificate, and wherein the digital resource modifies the operation of the computerized device.
23. The medium according to claim 22, wherein, the generated filter data structure is a Bloom filter data structure, and the hash function is used to generate multiple hash values for the Bloom filter data structure.