Remote IT update system for a fleet of IT devices
The remote management system uses an active device to broadcast updates via BLE to nearby passive devices, addressing energy inefficiencies and security concerns in existing update methods, ensuring secure and efficient data transmission.
Patent Information
- Application Number
- FR2023002394
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-15
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2043-03-15
AI Technical Summary
Existing solutions for updating computer data in a fleet of devices are energy-intensive and inefficient, particularly when using direct telecommunications, and can deplete the battery of the first device if it needs to pair with many others.
A remote management system where an active computer object receives updates via long-distance communication and switches to an open broadcast mode using Bluetooth Low Energy (BLE) to transmit data to nearby passive objects, ensuring authentication and encryption, with passive objects verifying the update's origin and applying it only after user confirmation.
This system reduces energy consumption and data flow while ensuring secure and efficient updates across a fleet of devices, optimizing battery life and minimizing telecommunications usage.
Smart Images

Figure 00000014_0000
Abstract
Description
Title of the invention: Remote computer update system for a fleet of computer devices Scope of the invention
[0001] The field of the invention is that of the management of digital data stored by computer objects.
[0002] More specifically, the invention relates to a fleet management system for smart and connected objects, which may be mobile, each comprising: - an embedded computer unit including data storage means, - the first means of short-range wireless communication, capable of communicating with the first means of short-range wireless communication of another computing device, - second means of long-distance communication.
[0003] Such management systems also classically include a computer platform including third means of long-distance communication capable of communicating with the second means of long-distance communication of computer objects.
[0004] According to one example of application of the invention, such computer objects can take the form of reusable boxes, implemented in a system for routing products contained in these reusable boxes.
[0005] In this example, as in other conceivable applications, the computer objects, in this case the reusable boxes, are regularly grouped together in warehouses where they are stored in close proximity to one another. Furthermore, thanks to the wireless proximity communication means they incorporate, they can exchange information or digital data with each other.
[0006] Of course, these connected and intelligent objects integrate, in their means of memorization, digital data dedicated to their operation and their computer behavior.
[0007] Thus, it may occasionally be necessary to modify and / or update the computer data (for example, the embedded software) contained in the storage devices of the computing objects. These modifications or updates may then concern sensitive information, information capable of protecting the objects against hacking, or information likely to concern the computer configuration of the objects, their updates, encryption and / or decryption keys, temporary data. poraires (for example, for transport).
[0008] In this context, the modification or updating of computer data can be carried out via the computer platform to which all the computer objects of the fleet are connected via long-distance communication means. State of the art
[0009] A simple and classic solution is therefore to send the modifications or updates directly via the computer platform, to each computer object, one by one.
[0010] Such a solution is generally very secure, but has the disadvantage of consuming a lot of energy and involving large data flows via telecommunications.
[0011] According to another solution, the update is sent to a computer object that is in close proximity to other computer objects, then the computer object that received the update pairs successively, one by one, with the other objects in close proximity and transmits the update to them.
[0012] This solution proves to be less energy-intensive than the previous one and avoids large flows via telecommunications, by reducing the transmission of the update to a local network, and even to a network in the immediate vicinity (for example by Bluetooth).
[0013] However, the battery of the first computer device to receive the update will discharge rapidly if the device has to pair successively with many devices. In this case, it is possible that the battery life of the first computer device to receive the update will not be sufficient to transmit the update to all nearby devices. Objectives of the invention
[0014] The invention aims in particular to overcome this drawback of the prior art.
[0015] More specifically, the invention aims to provide a remote management system for digital data of a fleet of computer objects that is more reliable than prior art solutions, while being very energy efficient.
[0016] The invention also aims to provide such a system which can be easily integrated into a product delivery system containing reusable boxes, in which the boxes are computer objects. Description of the invention
[0017] These objectives, as well as others that will subsequently emerge, are achieved through the invention, which relates to a system for managing a fleet of computer objects. including said computer objects, each of which comprises:
[0018] - an embedded computer unit including means for storing data,
[0019] - the first means of wireless short-range communication, capable of communicating with initial means of short-range wireless communication with another computing device,
[0020] - of the second means of long-distance communication,
[0021] the system also comprising a computer platform including third long-distance communication means capable of communicating with the second long-distance communication means of the computer objects, and being characterized in that the embedded computer unit of at least one of the computer objects, referred to as the active computer object, is configured to receive, from the computer platform, digital update information via the third communication means, the embedded computer unit of said active computer object being configured to, after receiving digital update information, switch the first wireless proximity communication means of said active computer object to an open broadcasting mode so as to broadcast the digital update information to other computer objects, referred to as passive computer objects,at a distance from said active computing object, allowing communication with it via the first means of wireless proximity communication.
[0022] Thanks to a system according to the invention, it is possible to transmit update information to an entire fleet of computer objects, in a low-energy and minimal-time manner.
[0023] Indeed, the computer object which received the update data first acts in the manner of a relay or a local broadcasting terminal, transmitting in an open wireless broadcast mode or, in "broadcast" according to the English term, to all nearby computer objects, that is to say located within a radius around the "first" computer object allowing the other computer objects to receive the data, using short-range communication means such as Bluetooth, and more specifically according to Bluetooth low energy technology.
[0024] In other words, the "first" computing object acts as a local broadcast terminal that addresses update data in packets to other computing objects, which then form peripherals of the central device. These peripherals remain in standby mode and "wake up" to receive update data by "listening" to the local broadcast terminal.
[0025] According to a preferred embodiment, the embedded computing unit of the passive computing objects is configured to transmit, to the platform in In the computer system, an authentication request for the digital update information is made, and the computer platform is configured to receive the authentication request and return, to the passive computer objects, an authorization code or a rejection code.
[0026] In this way, an additional level of security is obtained insofar as the passive objects ensure with the platform that the data update can indeed be applied.
[0027] Certainly, by connecting one by one to the platform, the computer objects generate electricity consumption and a flow of data via telecommunication, but in a greatly reduced way compared to prior art solutions.
[0028] Advantageously, the embedded computing unit of each passive computing object is configured to erase the digital update information after receiving a rejection code.
[0029] This avoids cluttering a buffer memory of the embedded computer unit of the objects.
[0030] According to another advantageous embodiment, the embedded computing unit of the active computing object is configured to disseminate the digital update information in encrypted form with an encryption key, and the embedded computing unit of the passive computing objects is configured with a decryption key that matches the encryption key.
[0031] The reception of data by the active objects is thus secured.
[0032] According to a particular application of the invention, the computer objects take the form of reusable boxes, and the management system is integrated into a product routing system for the contents of the reusable boxes. Thus, the logistics fleet of reusable boxes of a company or carrier can benefit from correction and / or software evolution bringing new functionalities.
[0033] According to an advantageous embodiment, the embedded computing unit of the active computing object integrates geolocation means and is parameterized with predetermined location coordinates, the embedded computing unit being further parameterized to allow a switch to open broadcast mode if the geolocation means detect a location of the active computing object within the predetermined location coordinates.
[0034] In this way, the active computer object only broadcasts data in an identified area such as a known logistics warehouse, thus providing an additional level of security.
[0035] According to a particular embodiment, the embedded computer unit is configured to allow update instructions after detection of an in- intervention on a confirmation actuator carried by the computer object.
[0036] Thus, the passive computer object which has received the update data does not carry out the actions required by the update, only after intervention by a user or an operator, for example pressing a button, passing a contactless badge... This action is previously configured as a confirmation action.
[0037] Preferably, the embedded computing unit of each computing object is configured to emit, to the computing platform and / or an active computing object, a signal for receiving digital data update information. The IT platform can then track the evolution of updates to the fleet of IT objects, and consequently optimize their execution in a grouped manner when the objects are positioned in the right place.
[0038] According to a particular embodiment, each computer object includes a private / public key pair specific to it, and the decryption key for the digital update information is, for each computer object, individually encrypted by the computer platform using its own public key before transmission to the recipient computer object.
[0039] Furthermore, if a block of data forming the digital update information is not received by the passive computer object, the passive computer object then transmits a request for redistribution of said block to the active computer object, and / or to the computer platform which may accept or refuse this redistribution. Figures
[0040] Other features and advantages of the invention will become more apparent upon reading the following description of a preferred embodiment of the invention, given by way of simple illustrative and non-limiting example, and the accompanying drawing consisting of: - the [Fig.1] which schematically illustrates a management system for a fleet of computer objects integrated into a product routing system.
[0041] Detailed description of the invention As illustrated in [Fig. 1], a system for managing a fleet of computer objects according to the invention comprises, in a manner known per se: - at least two objects A, B (or more generally a fleet of N computer objects), each including embedded intelligence and means of communication described below, each computer object bearing in particular a computer recognition code 1; - a computer platform 6 including at least one database 60 listing the computer recognition codes 1 of all computer objects.
[0042] The computer recognition code for computer objects allows the computer platform to identify that the computer object is indeed part of the fleet of computer objects that the system has under management.
[0043] In addition to the computer recognition code, each computer object integrates: - an embedded computer unit 5, including means for storing data 4; - the first means of wireless proximity communication 2, typically a Bluetooth antenna, or even BLE (“Bluetooth Low Energy”, i.e., low-power Bluetooth), capable of communicating with the first means of wireless proximity communication 2 of another computing object; - of the second means of communication 3 long distance.
[0044] Furthermore, each computer object naturally includes means of powering the computer unit and means of communication in particular.
[0045] The computer platform 6 includes third means of long-distance communication 61, capable of communicating with the second means of long-distance communication 3 of the objects.
[0046] According to the principle of the invention, the computer unit 5 embedded in at least one of the computer objects, called active computer object A, is configured to receive, from the computer platform 6, digital update information, via the third means of communication 61.
[0047] Furthermore, the embedded computing unit 5 of the active computing object A is configured to receive digital update information and switch the first wireless proximity communication means 2 of said active computing object to an open broadcast mode.
[0048] To this end, the computer object incorporates a microcontroller that controls a 4G mobile telephony network module, which communicates with the computer platform, and a Bluetooth Low Energy (“BLE”) module, or other, for local broadcasting. The embedded computer unit 5 manages these two modules. The BLE (or other) module can switch from a “peer-to-peer” mode (known by the Anglo-Saxon term "peer-to-peer") to an open local broadcast mode (known in English as "broadcast"). In practice, in "broadcast," computer object A wirelessly transmits a series of messages, each containing a portion of the encrypted update. Computer objects B, located within the local area of computer object A, each receive the broadcast messages gradually and simultaneously. Following this single open broadcast of each message by computer object A, computer objects B are all able to reconstruct the complete message, to decipher and use it.
[0049] With such a system, one or more active objects A of a fleet of computer objects therefore receive an update file issued by the computer platform via long-distance communication means.
[0050] This file is processed by the computer unit of the active computer object A in such a way that the first means of wireless proximity communication 2 of said active computer object A are switched to an open broadcast mode.
[0051] According to a preferred embodiment, the first wireless proximity communication means 2 of said active computing object A implement Bluetooth Low Energy technology (known by the acronym "BLE"). The open broadcasting mode is then designated by the term "BLE Advertising".
[0052] Wireless proximity communication means can of course implement other communication protocols, such as Wifi or the Zigbee protocol or DMB-T, or even specific proprietary protocols.
[0053] Once switched to open broadcast mode, the active computing object A therefore emits the digital update information to other objects in the immediate vicinity, called passive objects B, located at a distance from the active computing object A, allowing communication with it via the first means of wireless proximity communication 2.
[0054] To increase the security level of updates with regard to their authentication, it is planned to implement updates via passive objects only after performing a verification step to verify the origin of the updates. To this end, the computing unit 5 of the passive computing objects B is configured to send an authentication request for the update's digital information to the computing platform 6. In return, the computing platform 6 is configured to receive the authentication request and return an authorization or rejection code to the passive computing objects B.
[0055] If a rejection code is returned by the computer platform 6 to the passive computer objects B awaiting authentication of the received data, the computer unit of the passive computer objects is configured to erase the data previously stored in a buffer.
[0056] Alternatively or in addition, the embedded computing unit 5 of the active computing object A is configured to transmit the digital update information in encrypted form using an encryption key. In this case, the embedded computing unit of the passive computing objects B is configured with a decryption key that matches the encryption key.
[0057] Preferably, the embedded computer unit of each computer object is configured to emit, to the computer platform and / or the active computer object that transmitted the update to it, a signal of receipt of the digital information for updating the data.
[0058] As illustrated in [Fig. 1], computer objects can take the form of reusable, connected, and intelligent boxes, which may be mobile. In this case, the fleet management system for computer objects, with regard to updating the data contained in the storage means of the objects' embedded computer unit, is integrated into a system for routing products contained and transported in the reusable boxes.
[0059] According to an advantageous embodiment, the embedded computing unit 5 of the active computing object A integrates geolocation means 50 and is configured with predetermined location coordinates. In this case, the embedded computing unit 5 is further configured to allow the active computing object to switch to open broadcast mode if it is physically located in an "authorized" location. In other words, the computing object only broadcasts update information if the geolocation means detect a location of the active computing object within the predetermined location coordinates.
[0060] In this context, a computer object equipped with location means can initially be a passive computer object, having received the digital update information, and then subsequently, after being moved to a parameterized area within its computer unit, become active and broadcast the digital update information to other nearby objects. This creates a mesh network (of the "Mesh" type, according to the Anglo-Saxon term).
[0061] Furthermore, the computer objects may have a confirmation actuator 8, accessible from outside the computer objects, and intended to be activated by a user or operator. In this case, the embedded computer unit 5 of the computer objects is configured to allow update instructions after detection of an intervention on the confirmation actuator carried by the computer object.
[0062] Thus, the passive computer object that has received the update data only performs the actions required by the update after intervention by a user or operator on the confirmation actuator. The actuator in question can, for example, take the form of a button (which must be pressed to confirm the update), or a badge reader (in front of which a badge must be presented to confirm the update).
[0063] In addition, the computer platform 6 can simultaneously order an update day for the attention of several fleets of IT objects located in different places. In this context, for each fleet, an IT object becomes an active object A when the other IT objects in the fleet remain passive IT objects B.
[0064] According to a particular embodiment, each computer object B that has received a complete encrypted data or update file from computer object A requests a decryption key for the data file from the remote computer platform 6. In response, the remote computer platform 6, to ensure double security, then transmits this decryption key to the requesting computer object B via a communication channel different from the data file transmission channel. In other words, when the update data file is received via a local broadcast channel of the "BLE" type, the different communication channel is, for example, a mobile telephone network of the 2G / 4G / 5G type. Furthermore, this decryption key is itself encrypted for security purposes during transmission.For example, the decryption key is encrypted using a public key specific to the computer object B, known to the remote computer platform 6. Thus, computer object B, being the sole holder of a private key forming its own key pair, is able to decrypt the decryption key of the data file.
[0065] Furthermore, when a block of the data file is not correctly received by one of the computer objects B, decryption of the entire data file is not possible for that computer object B. It can then request a retransmission of only the corrupted block. Thus, it can either send a request directly to computer object A or transmit a request to the remote computer platform 6. Computer object A or the remote computer platform 6 can then accept or refuse this retransmission. Rejection may be due to security constraints, such as geolocation, or a high block reception failure rate indicating insufficient reception quality. If the request to retransmit the corrupted block is refused, computer object B is not updated.
[0066] The encryption operation(s) used to secure the data transmitted according to the invention can be carried out by any known encryption algorithm, symmetric or asymmetric, for example public key, private key, and combinations thereof.
[0067] This includes block encryption of the data, using a secret key, which is necessary for decryption. This secret key is also transmitted encrypted using asymmetric encryption with the recipient's public key. Furthermore, this secret key is transmitted with its hash to verify its integrity. This hash is calculated using a hash function applied to the encrypted secret key. The resulting fingerprint is then encrypted with the sender's private key. The recipient, possessing the sender's public key capable of decrypting the fingerprint, verifies the integrity of the encrypted secret key using methods known in the prior art. They can then decrypt the secret key with their own private key and use it.
[0068] In one variant, the hash is calculated on the secret key in plaintext, then encrypted. Consequently, the secret key, which has subsequently been encrypted, must first be decrypted so that its integrity can be checked using prior art methods with this hash.
[0069] Thus, by combining the encryption of the secret key and the signing of the fingerprint, it is ensured that it is possible to verify on the one hand the origin of the fingerprint and on the other hand the integrity of the data received which cannot be decrypted with a corrupted secret key.
Claims
Demands
1. A system for managing a fleet of computer objects, including said computer objects (A), (B), each of which comprises: - an embedded computer unit (5) including means for storing data (4), - the first means of wireless proximity communication (2), capable of communicating with the first means of wireless proximity communication (2) of another computing object, - second means of long-distance communication (3), the system also comprising a computer platform (6) including third means of long-distance communication (61) capable of communicating with the second means of long-distance communication (3) of the computer objects, characterized in that the embedded computer unit (5) of at least one of the computer objects, referred to as the active computer object, is configured to receive, from the computer platform (6), digital update information via the third means of communication (3), and in that the embedded computer unit (5) of said active computer object is configured to, after receiving digital update information, switch the first means of wireless proximity communication (2) of said active computer object to an open broadcast mode so as to broadcast the digital update information to other computer objects,said passive computing objects, at a distance from said active computing object allowing communication with it via the first means of wireless proximity communication (2), and in that the embedded computing unit (5) of the passive computing objects is configured to send, to the computing platform (6), a request for authentication of the digital update information, and in that the computing platform (6) is configured to receive the authentication request and return, to the passive computing objects, an authorization code or a rejection code.
2. A system for managing a fleet of computing objects according to claim 1, characterized in that the embedded computing unit (5) of each passive computing object is configured to erase the digital update information after receiving a code of rejection.
3. A system for managing a fleet of computing objects according to any one of the preceding claims, characterized in that the embedded computing unit (5) of the active computing object is configured to disseminate digital update information in encrypted form with an encryption key, and in that the embedded computing unit (5) of the passive computing objects is configured with a decryption key that matches the encryption key.
4. A system for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the computer objects (A), (B) take the form of reusable boxes and in that the management system is integrated with a system for routing products contained in the reusable boxes.
5. A system for managing a fleet of computing objects according to any one of the preceding claims, characterized in that the embedded computing unit (5) of the active computing object integrates geolocation means (50) and is parameterized with predetermined location coordinates, the embedded computing unit (5) being further parameterized to allow a switchover to open broadcast mode if the geolocation means (50) detect a location of the active computing object within the predetermined location coordinates.
6. A system for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the embedded computer unit (5) is configured to allow update instructions after detection of an intervention on a confirmation action (8) carried by the computer object.
7. A system for managing a fleet of computer objects according to any one of the preceding claims, characterized in that the embedded computer unit (5) of each computer object is configured to emit, to the computer platform (6) and / or an active computer object, a signal for receiving digital data update information.
8. A system for managing a fleet of computer objects according to claim 3, characterized in that each computer object comprises a private / public key pair specific to it, and in that the decryption key for the digital update information is, for each computer object, individually encrypted by the computer platform using its own public key before transmission to the recipient computer object.
9. A system for managing a fleet of computer objects according to any one of the preceding claims, characterized in that if a block of data forming the digital update information is not received by the passive computer object, the passive computer object then transmits a request for rebroadcasting said block to the active computer object, and / or to the computer platform which may accept or refuse this rebroadcasting.