Remote computer update system for a fleet of computing objects

EP4681104A1Pending Publication Date: 2026-01-21PA COTTE SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2024710724
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-03-15
Filing Date
2024-03-08
Publication Date
2026-01-21

AI Technical Summary

Technical Problem

Existing systems for managing a fleet of intelligent and connected computer objects face challenges in efficiently updating digital data across multiple devices while ensuring energy efficiency and security, particularly in scenarios where direct one-to-one updates consume significant energy and data flow, and battery discharge is a concern.

Method used

A system where an active computer object receives updates via long-distance communication and switches to an open broadcast mode using low-consumption Bluetooth technology to transmit the updates to nearby passive objects, which remain in a low-power state until receiving the data, with authentication and encryption mechanisms to ensure security, and geolocation and confirmation actuator integration for controlled updates.

Benefits of technology

This approach allows for efficient, secure, and energy-saving updates across a fleet of computer objects, reducing energy consumption and data flow while ensuring that only authorized updates are applied, maintaining battery life and optimizing update execution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024056190_19092024_PF_FP_ABST
    Figure EP2024056190_19092024_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a system for managing a fleet of computing objects, each comprising: - an embedded computing unit (5) including data storage means (4); - first proximity wireless communication means (2) for communicating with first proximity wireless communication means (2) of another computing object; - second long-distance communication means (3), the system also comprising a computing platform (6) which includes third long-distance communication means (61) for communicating with the second long-distance communication means (3) of the computing objects, characterised in that the embedded computing unit (5) of at least one of the computing objects, referred to as an active computing object, is configured to receive digital update information from the computing platform (6), and in that the embedded computing unit (5) of the active computing object is configured to switch, after receiving the digital update information, the first proximity wireless communication means (2) of the active computing object to an open broadcast mode.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Remote computer update system for a fleet of computer objects

[0002] The field of the invention is that of the management of digital data stored by computer objects.

[0003] More specifically, the invention relates to a system for managing a fleet of intelligent and connected objects, which may be mobile, each comprising:

[0004] - an on-board computer unit including data storage means,

[0005] - first wireless proximity communication means, capable of communicating with first wireless proximity communication means of another computer object,

[0006] - second means of long-distance communication.

[0007] Such management systems also typically include a computer platform including third long-distance communication means capable of communicating with the second long-distance communication means of the computer objects.

[0008] According to an example of application of the invention, such computer objects can take the form of reusable boxes, implemented in a system for transporting products contained in these reusable boxes.

[0009] In this example, as in other possible applications, the computer objects, in this case the reusable boxes, are regularly grouped together in warehouses in which they are stored directly next to each other. In addition, through the wireless proximity communication means they integrate, they can exchange information or digital data between them.

[0010] Of course, these connected and intelligent objects integrate, in their storage means, digital data dedicated to their operation and their IT behavior. Thus, it may be necessary, occasionally, to modify and / or update the IT data (for example the embedded software) contained in the storage means of the IT objects. These modifications or updates may then concern sensitive information, capable of protecting the objects against hacking or may also concern the IT configuration of the objects, their update, encryption and / or decryption keys, temporary data (routing for example).

[0011] In this context, the modification or updating of computer data can be carried out through the computer platform to which all the computer objects of the fleet are connected via long-distance communication means.

[0012] A simple and classic solution therefore consists of sending modifications or updates directly via the IT platform, to each IT object, one by one.

[0013] Such a solution is generally very secure, but has the disadvantage of consuming a lot of energy and involving large data flows via telecommunications.

[0014] According to another solution, the update is sent to a computer object which is located near other computer objects, then the computer object which has received the update pairs successively, one by one, with the other objects in the vicinity and transmits the update to them.

[0015] This solution is less energy-intensive than the previous one and avoids large flows via telecommunications, by reducing the transmission of the update to a local network, and even to a network in the immediate vicinity (for example via Bluetooth).

[0016] However, the battery of the first computer object to receive the update may drain quickly if the object has to pair with many objects in succession. In this case, it is possible that the electrical autonomy of the first computer object to receive the update will not allow the update to be transmitted to all nearby objects.

[0017] The invention aims in particular to overcome this drawback of the prior art.

[0018] More specifically, the invention aims to propose a system for remote management of digital data from a fleet of computer objects which is more reliable than the solutions of the prior art, while being very energy efficient.

[0019] The invention also aims to provide such a system which can be easily integrated into a system for transporting products contained in reusable boxes of a product transport system, in which the boxes are computer objects.

[0020] These objectives, as well as others which will appear subsequently, are achieved thanks to the invention which has as its subject a system for managing a fleet of computer objects, including said computer objects which each comprise:

[0021] - an on-board computer unit including data storage means,

[0022] - first wireless proximity communication means, capable of communicating with first wireless proximity communication means of another computer object,

[0023] - second long-distance communication means, the system also comprising a computer platform including third long-distance communication means capable of communicating with the second long-distance communication means of the computer objects, and being characterized in that the on-board computer unit of at least one of the computer objects, called active computer object, is configured to receive, from the computer platform, digital update information via the third communication means, the on-board computer unit of said active computer object being configured to, after receiving digital update information, switch the first wireless proximity communication means of said active computer object to an open broadcast mode so as to broadcast the digital update information to other computer objects, called passive computer objects,remotely from said active computer object allowing communication with it via the first means of wireless proximity communication.,

[0024] Thanks to a system according to the invention, it is possible to transmit update information to an entire fleet of computer objects, in a low-energy manner and in a minimum of time.

[0025] Indeed, the computer object that received the update data first acts like a relay or a local broadcast terminal, transmitting using an open wireless broadcast mode or, in "broadcast" according to the English term, to all the computer objects in the vicinity, that is to say located within a radius around the "first" computer object allowing reception of the data by the other computer objects, using short-distance communication means such as Bluetooth, and more specifically using low-energy Bluetooth technology.

[0026] In other words, the "first" computing object acts as a local broadcast terminal that sends update data in packets to other computing objects that then form peripherals of the central device. These peripherals remain in sleep mode and "wake up" to receive update data by "listening" to the local broadcast terminal.

[0027] According to a preferred embodiment, the on-board computer unit of the passive computer objects is configured to transmit, to the computer platform, a request for authentication of the digital update information, and the computer platform is configured to receive the authentication request and return, to the passive computer objects, an authorization code or a rejection code.

[0028] This provides an additional level of security, as passive objects check with the platform that the data update can be applied.

[0029] Certainly, by connecting one by one to the platform, the computer objects generate electricity consumption and a flow of data via telecommunications, but in a significantly reduced way compared to the solutions of the prior art. Advantageously, the embedded computer unit of each passive computer object is configured to erase the digital update information after receiving a rejection code.

[0030] This avoids cluttering up a buffer memory of the on-board computer unit of the objects.

[0031] According to another advantageous embodiment, the on-board computing unit of the active computing object is configured to broadcast the digital update information in an encrypted manner with an encryption key, and the on-board computing unit of the passive computing objects is configured with a decryption key matching the encryption key.

[0032] The reception of data by active objects is thus secure.

[0033] According to a particular application of the invention, the computer objects take the form of reusable boxes, and the management system is integrated into a system for routing products contained in the reusable boxes.

[0034] Thus, the logistics fleet of reusable boxes of a company or a carrier can benefit from corrections and / or software developments providing new functionalities.

[0035] According to an advantageous embodiment, the on-board computer unit of the active computer object integrates geolocation means and is configured with predetermined location coordinates, the on-board computer unit being further configured to authorize a switch to open broadcast mode if the geolocation means detect a location of the active computer object included in the predetermined location coordinates.

[0036] In this way, the active computing object only broadcasts data in an identified area such as a known logistics warehouse, thus providing an additional level of security. According to a particular embodiment, the on-board computing unit is configured to authorize update instructions after detecting an intervention on a confirmation actuator carried by the computing object.

[0037] Thus, the passive computer object having received the update data only carries out the actions required by the update after intervention by a user or operator, for example pressing a button, passing a contactless badge, etc. This action is previously configured as a confirmation action.

[0038] Preferably, the on-board computer unit of each computer object is configured to transmit, to the computer platform and / or an active computer object, a signal for receiving digital data update information.

[0039] The IT platform can then track the progress of updates to the fleet of IT objects, and therefore optimize their execution in a grouped manner when the objects are positioned in the right place.

[0040] According to a particular embodiment, each computer object comprises a private key / public key pair which is specific to it, and the key for decrypting the digital update information is, for each computer object, individually encrypted by the computer platform using the specific public key before transmission to the recipient computer object.

[0041] Furthermore, if a block of data forming the digital update information is not received by the passive computing object, the passive computing object then transmits a request for rebroadcasting of said block to the active computing object and / or to the computing platform which can accept or refuse this rebroadcasting.

[0042] Other characteristics and advantages of the invention will appear more clearly on reading the following description of a preferred embodiment of the invention, given as a simple illustrative and non-limiting example, and the appended drawing consisting of: Figure 1 which schematically illustrates a system for managing a fleet of computer objects integrated into a product routing system. As illustrated by Figure 1, a system for managing a fleet of computer objects according to the invention comprises, in a manner known per se: at least two objects A, B (or more generally a fleet of N computer objects), each including an embedded intelligence and communication means described below, each computer object carrying in particular a computer recognition code 1; a computer platform 6 including at least one database 60 listing the computer recognition codes 1 of all the computer objects.

[0043] The computer object recognition code allows the IT platform to identify that the IT object is indeed part of the fleet of IT objects that the system manages.

[0044] In addition to the computer recognition code, each computer object integrates: an on-board computer unit 5, including data storage means 4; first wireless proximity communication means 2, typically a Bluetooth antenna, or even BLE (“Bluetooth Low Energy”, i.e. Bluetooth low consumption), capable of communicating with first wireless proximity communication means 2 of another computer object; second long-distance communication means 3.

[0045] Furthermore, each computer object of course integrates means of power supply 7 for the computer unit and means of communication in particular.

[0046] The computer platform 6 includes third long-distance communication means 61, capable of communicating with the second long-distance communication means 3 of the objects.

[0047] According to the principle of the invention, the on-board computer unit 5 of at least one of the computer objects, called active computer object A, is configured to receive, from the computer platform 6, digital update information, via the third communication means 61. In addition, the on-board computer unit 5 of the active computer object A is configured to receive the digital update information and to switch the first wireless proximity communication means 2 of said active computer object to an open broadcast mode.

[0048] To do this, the computing object embeds a microcontroller that controls a 4G mobile telephone network module, which communicates with the computing platform, and a low-energy Bluetooth (“BLE”) module, or other, for local broadcasting. The embedded computing unit 5 manages these two modules. The BLE (or other) module can switch from a “peer-to-peer” mode (known as “peer-to-peer”) to an open local broadcasting mode (known as “broadcast”). In practice, in “broadcast”, the computing object A transmits by wireless radio a series of messages, each containing a part of the encrypted update. The computing objects B, located in the local perimeter of the computing object A, each receive the broadcast messages little by little and simultaneously.Following this unique open broadcast of each message by computer object A, computer objects B are all capable of reconstructing the complete message, deciphering it and using it.

[0049] With such a system, one or more active objects A of a fleet of IT objects therefore receive an update file sent by the IT platform via long-distance communication means.

[0050] This file is processed by the computing unit of the active computing object A in such a way that the first wireless proximity communication means 2 of said active computing object A are switched to an open broadcast mode.

[0051] According to a preferred embodiment, the first wireless proximity communication means 2 of said active computer object A implement Bluetooth low energy technology (known by the acronym “BLE”). Then, the open broadcast mode is designated by the term “BLE advertising”. The wireless proximity communication means can of course implement other communication protocols, such as Wifi or the Zigbee protocol or DMB-T, or even specific proprietary protocols.

[0052] Once switched to open broadcast mode, the active computer object A therefore transmits the digital update information to other objects in the immediate vicinity, called passive objects B, located at a distance from the active computer object A, allowing communication with it via the first wireless proximity communication means 2.

[0053] To increase the level of security of the updates with regard to their authentication, it is planned to only implement the updates by the passive objects after having executed a step of checking the origin of the updates. For this, the computer unit 5 of the passive computer objects B is configured to transmit, to the computer platform 6, a request for authentication of the digital update information. In return, the computer platform 6 is configured to receive the authentication request and return, to the passive computer objects B, an authorization code or a rejection code.

[0054] If a rejection code is returned by the computing platform 6 to the passive computing objects B awaiting authentication of the received data, the computing unit of the passive computing objects is configured to erase the data previously stored in a buffer memory.

[0055] In a complementary or alternative manner, the on-board computing unit 5 of the active computing object A is configured to broadcast the digital update information in an encrypted manner with an encryption key. In this case, the on-board computing unit of the passive computing objects B is configured with a decryption key matching the encryption key.

[0056] Preferably, the on-board computer unit of each computer object is configured to transmit, to the computer platform and / or the active computer object that transmitted the update to it, a signal for receiving the digital data update information. As illustrated in Figure 1, the computer objects can take the form of reusable, connected and intelligent boxes, which can be mobile. In this case, the system for managing the fleet of computer objects, with regard to updating the data contained in the storage means of the on-board computer unit of the objects, is integrated into a system for routing products contained and transported in the reusable boxes.

[0057] According to an advantageous embodiment, the on-board computer unit 5 of the active computer object A integrates geolocation means 50 and is configured with predetermined location coordinates. In this case, the on-board computer unit 5 is further configured to authorize a switch to open broadcast mode of the active computer object if the latter is physically located in an “authorized” location. In other words, the computer object only broadcasts the update information if the geolocation means detect a location of the active computer object included in the predetermined location coordinates.

[0058] In this context, a computer object equipped with localization means can initially be a passive computer object, having received the digital update information, then become in a second stage, after having been moved into a zone configured in its computer unit, active and broadcast the digital update information to other nearby objects. This creates a mesh network (of the "Mesh" type according to the Anglo-Saxon term).

[0059] Furthermore, the computer objects may have a confirmation actuator 8, accessible from outside the computer objects, and intended to be actuated by a user or an operator. In this case, the on-board computer unit 5 of the computer objects is configured to authorize update instructions after detection of an intervention on the confirmation actuator carried by the computer object.

[0060] Thus, the passive computer object having received the update data only carries out the actions required by the update after intervention by a user or operator on the confirmation actuator. The actuator in question can, for example, take the form of a button (which must be pressed to confirm the update), a badge reader (in front of which a badge must be presented to confirm the update).

[0061] In addition, the computing platform 6 can simultaneously order an update for several fleets of computing objects located in different locations. In this context, for each fleet, a computing object becomes an active object A while the other computing objects in the fleet remain passive computing objects B.

[0062] According to a particular embodiment, each computer object B that has received an encrypted data or update file in its entirety from the computer object A requests a decryption key for the data file from the remote computer platform 6. In response, the remote computer platform 6, to ensure double security, then transmits this decryption key to the computer object B that requested it, via a communication channel different from the transmission channel for the data file. In other words, when the update data file is received via a local broadcast channel of the “BLE” type, the different communication channel is, for example, a mobile telephone network, of the 2G / 4G / 5G type. In addition, this decryption key is itself encrypted for security purposes when it is sent. For example, the decryption key is encrypted using a public key specific to the computer object B, known to the remote computer platform 6.Thus, the computer object B, the only holder of a private key forming a key pair specific to it, is able to decrypt the decryption key of the data file.

[0063] Furthermore, when a block of the data file is not correctly received by one of the computer objects B, decryption of the complete data file is not possible by this computer object B. The latter can then request a new broadcast of the corrupted block only. Thus, it can either issue a request directly to the computer object A, or transmit a request to the remote computer platform 6. The computer object A or the remote computer platform 6 can then accept or reject this broadcast. The rejection may be linked to security constraints, such as geolocation, or a high failure rate of block reception indicating an insufficient reception quality level. If the request for rebroadcast of the corrupted block is rejected, the computer object B is not updated on this occasion.The encryption operation(s) used to secure the data transmitted according to the invention may be carried out by any known encryption algorithm, symmetric or asymmetric, for example public key, private key, as well as their combinations.

[0064] This includes block encryption of the data, using a secret key, necessary for decryption. This secret key is furthermore transmitted encrypted by asymmetric encryption using the recipient's public key. This secret key is, in addition, transmitted with its fingerprint to verify its integrity. This fingerprint is calculated using a hash function applied to the encrypted secret key. The resulting fingerprint is further encrypted with the sender's private key. Thus, the recipient in possession of the sender's public key capable of decrypting the fingerprint, verifies the integrity of the encrypted secret key, according to methods known from the prior art. He can then, with his own private key, decrypt the secret key, then use it.

[0065] In one variant, the fingerprint is calculated on the cleartext secret key and then encrypted. Consequently, the secret key which has been subsequently encrypted must first be decrypted so that its integrity can be checked according to methods known from the prior art with this fingerprint.

[0066] Thus, by combining the encryption of the secret key and the signature of the fingerprint, we ensure that we can verify on the one hand the origin of the fingerprint and on the other the integrity of the data received which cannot be decrypted with a corrupted secret key.

Claims

CLAIMS 1. System for managing a fleet of IT objects, including said IT objects (A), (B) which each comprise: - an on-board computer unit (5) including data storage means (4), - first wireless proximity communication means (2), capable of communicating with first wireless proximity communication means (2) of another computer object, - second long-distance communication means (3), the system also comprising a computer platform (6) including third long-distance communication means (61) capable of communicating with the second long-distance communication means (3) of the computer objects, characterized in that the on-board computer unit (5) of at least one of the computer objects, called the active computer object, is configured to receive, from the computer platform (6), digital update information via the third communication means (3), and in that the on-board computer unit (5) of said active computer object is configured to, after receiving digital update information, switch the first wireless proximity communication means (2) of said active computer object to an open broadcast mode so as to broadcast the digital update information to other computer objects,said passive computer objects, at a distance from said active computer object authorizing communication with it via the first wireless proximity communication means (2), and in that the on-board computer unit (5) of the passive computer objects is configured to transmit, to the computer platform (6), a request for authentication of the digital update information, and in that the computer platform (6) is configured to receive the authentication request and return, to the passive computer objects, an authorization code or a rejection code., 2. System for managing a fleet of computer objects according to claim 1, characterized in that the on-board computer unit (5) of each passive computer object is configured to erase the digital update information after receiving a rejection code.

3. System for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the on-board computer unit (5) of the active computer object is configured to broadcast the digital update information in an encrypted manner with an encryption key, and in that the on-board computer unit (5) of the passive computer objects is configured with a decryption key matching the encryption key.

4. System for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the computer objects (A), (B) take the form of reusable boxes and in that the management system is integrated into a system for routing products contained in the reusable boxes.

5. System for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the on-board computer unit (5) of the active computer object integrates geolocation means (50) and is configured with predetermined location coordinates, the on-board computer unit (5) being further configured to authorize a switch to open broadcast mode if the geolocation means (50) detect a location of the active computer object included in the predetermined location coordinates.

6. System for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the on-board computer unit (5) is configured to authorize update instructions after detection of an intervention on a confirmation actuator (8) carried by the computer object.

7. System for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the on-board computer unit (5) of each computer object is configured to transmit, to the computer platform (6) and / or an active computer object, a signal for receiving digital data update information.

8. System for managing a fleet of computer objects according to claim 3, characterized in that each computer object comprises a private key / public key pair which is specific to it, and in that the decryption key for the digital update information is, for each computer object, individually encrypted by the computer platform using the specific public key before transmission to the recipient computer object.

9. System for managing a fleet of computer objects according to any one of the preceding claims, characterized in that if a block of data forming the digital update information is not received by the passive computer object, the passive computer object then transmits a request for rebroadcasting of said block, to the active computer object, and / or to the computer platform which can accept or refuse this rebroadcasting.