Secure storage system including cargo handlers

A cryptographic key management system for load handling devices in grid-based automated storage systems addresses the need for secure communication by authenticating and authorizing devices, enhancing system security and efficiency.

JP2025541597AActive Publication Date: 2025-12-22OCADO INNOVATION LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025525295
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-02-02
Filing Date
2023-11-02
Publication Date
2025-12-22
Estimated Expiration
2043-11-02

AI Technical Summary

Technical Problem

Existing grid-based automated storage and retrieval systems require secure and efficient communication systems for robotic material handlers, ensuring only authorized devices can connect and operate within the system.

Method used

Implementing a cryptographic key management system for load handling devices, where encryption keys are persistently stored and used for authentication, enabling secure installation and operation of software, and ensuring only authorized devices can connect to the wireless communication network.

Benefits of technology

Ensures secure and efficient communication within the storage system, preventing unauthorized access and ensuring only authenticated devices can operate, thereby enhancing system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025541597000001_ABST
    Figure 2025541597000001_ABST
Patent Text Reader

Abstract

The present disclosure provides a storage system in which a set of cryptographic keys is used to control the operation of a load handling device within the automated storage and retrieval system, one of which may be persistently stored in non-volatile data storage of the load handling device and used to authenticate additional keys from the set of keys to enable them to perform operations, such as connecting to a control system, being introduced into the storage and retrieval system, etc.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to methods and systems for controlling material handling devices, and in particular to such methods and systems for use with robots in storage systems. [Background technology]

[0002] Grid-based automated storage and retrieval systems are well known in the art. In such systems, a plurality of robotic material handlers operate on a horizontal grid structure, beneath which a plurality of containers are received and arranged in a plurality of stacks. The containers are used to hold the products, and the material handlers are adapted to retrieve and place the containers from and into one of the stacks. The material handlers may be routed in an autonomous (or semi-autonomous) manner on the grid, but a wireless communication system is required to send commands to the material handlers and to enable each of the material handlers to communicate with a management system. The claimed apparatus, method, system, and computer program are intended to provide improvements related to communication systems for use in automated retrieval and storage systems that use a collection of robotic material handlers. Summary of the Invention

[0003] According to a first aspect of the present disclosure, there is provided a method for operating a load handling device in a storage system, the method comprising the steps of generating a set of encryption keys associated with the load handling device, storing a first encryption key of the set of encryption keys in the load handling device, and using a second encryption key of the set of encryption keys to authenticate the first encryption key stored in the load handling device, whereby software can be installed on the load handling device only if the authentication is successful.

[0004] The first encryption key may be persistently stored on the load handling device. The first encryption key may be persistently burned into a non-volatile data storage unit, which may then be installed on the load handling device.

[0005] The method may include the further step of using a third encryption key from the set of encryption keys to authenticate a first encryption key stored in the load handling device, whereby the load handling device is introduced to the storage system only if authentication is successful. Introducing the load handling device to the storage system may include forming a connection between the load handling device and the storage system via the wireless communication system. Alternatively, the method may include the further step of using a fourth encryption key from the set of encryption keys to authenticate a first encryption key stored in the load handling device, whereby the load handling device can connect to the storage system via the wireless communication system only if authentication is successful.

[0006] The method may comprise the further step of the load handling device generating one or more local encryption keys for use in the load handling device, wherein the one or more local encryption keys may be generated based on the first encryption key stored in the load handling device.

[0007] According to a second aspect of the present disclosure, there is provided a load handling device for use in a storage system, the load handling device comprising non-volatile data storage, volatile data storage, one or more processors, and a first communication interface for communicating with a wireless communication network of the storage system, wherein, in use, a first encryption key from a set of encryption keys associated with the load handling device is stored in the non-volatile data storage of the load handling device, and software can be installed on the load handling device only if a second encryption key from the set of encryption keys successfully authenticates the first encryption key.

[0008] The first encryption key may be persistently stored in non-volatile data storage of the load handling device. The non-volatile data storage of the load handling device may comprise a one-time programmable memory device.

[0009] The load handling device may further include a cryptographic processor configured to generate one or more additional cryptographic keys based on the first cryptographic key stored in the non-volatile data storage of the load handling device.

[0010] The load handling device may be introduced into the storage system only if a third encryption key from the set of encryption keys successfully authenticates the first encryption key. Introducing the load handling device into the storage system may comprise forming a connection between the load handling device and the storage system via a wireless communication system. Alternatively, the load handling device may connect to the storage system via the first communication interface only if a fourth encryption key from the set of encryption keys successfully authenticates the first encryption key.

[0011] According to a third aspect, there is provided a storage system comprising: a first set of parallel tracks extending in an X direction and a second set of parallel tracks extending in a Y direction intersecting the first set in a substantially horizontal plane, the first set forming a grid pattern with a plurality of grid spaces; a plurality of stacks of storage containers located below the tracks and arranged such that each stack is located within the footprint of a single grid space; at least one transport device as described above; wherein the at least one transport device is arranged to selectively move in the X and / or Y directions above the stacks on the tracks to transport the storage containers; and a picking station arranged to receive the storage containers transported by the at least one transport device and transfer items from the storage containers to a shipping container. The at least one transport device may have a footprint that occupies only a single grid space in the storage system, such that a transport device occupying one grid space does not prevent the transport device from occupying or intersecting an adjacent grid space in the X and / or Y directions.

[0012] According to a further aspect, there is provided a data carrier device comprising computer executable code for performing the above-mentioned method.

[0013] The communication system will now be described in detail with reference to an example. [Brief explanation of the drawings]

[0014] [Figure 1] 1 illustrates a schematic diagram of a storage structure and a container. [Figure 2] 2 illustrates a schematic of a truck on top of the storage structure illustrated in FIG. 1; [Figure 3] 2 illustrates a schematic of a material handling device on top of the storage structure illustrated in FIG. 1; [Figure 4] 1 illustrates diagrammatically a single material handling device with the container lifting means in a lowered configuration; [Figure 5]1A and 1B illustrate diagrammatically cutaway views of a single material handling device with container lifting means in raised and lowered configurations; [Figure 6] 1 shows a schematic diagram of a communication system that allows multiple bots to communicate with a central computing device. [Figure 7] 1 shows a schematic diagram of a system that allows for deploying software to bots in an automated storage and retrieval system. [Figure 8] 8 shows a schematic diagram of a further example of the communication system of FIGS. 6 and 7; FIG. [Figure 9] A schematic diagram of a bot PC is shown. [Figure 10] 1 shows a schematic diagram of how cryptographic keys can be transferred. [Figure 11] 1 shows a schematic diagram of an example boot loader code. [Figure 12] 10 shows a schematic diagram of a computing device 1000 for use in implementing a communication system. DETAILED DESCRIPTION OF THE INVENTION

[0015] The following embodiments represent Applicant's preferred examples of how to implement a communications system for use with robots in a warehouse, but they are not necessarily the only examples of how this can be achieved.

[0016] 1 illustrates a storage structure 1 comprising upright members 3 and horizontal members 5, 7 supported by upright members 3. Horizontal members 5 extend parallel to each other and to the illustrated x-axis. Horizontal members 7 extend parallel to each other and to the illustrated y-axis and transverse to horizontal members 5. Upright members 3 extend parallel to each other and to the illustrated z-axis and transverse to horizontal members 5, 7. Horizontal members 5, 7 form a grid pattern defining a plurality of grid cells. In the illustrated example, containers 9 are arranged in stacks 11 below the grid cells defined by the grid pattern, with one stack 11 of containers 9 per grid cell.

[0017] FIG. 2 shows an enlarged plan view of a section of a track structure 13 that forms part of and is located on top of the horizontal members 5, 7 of the storage structure 1 illustrated in FIG. 1. The track structure 13 may be provided by the horizontal members 5, 7 themselves (e.g., formed in or on the surfaces of the horizontal members 5, 7) or by one or more additional components attached to the top of the horizontal members 5, 7. The illustrated track structure 13 includes x-direction tracks 17 and y-direction tracks 19, i.e., a first set of tracks 17 extending in the x-direction and a second set of tracks 19 extending in the y-direction that intersect the tracks 17 in the first set of tracks 17. The tracks 17, 19 define openings 15 in the centers of the grid cells. The openings 15 are sized to allow containers 9 located below the grid cells to be lifted and lowered through the openings 15. The x-direction tracks 17 are provided in pairs separated by channels 21, and the y-direction tracks 19 are provided in pairs separated by channels 23. Other arrangements of the track structures may be possible.

[0018] Figure 3 shows multiple load handling devices 31 moving on top of the storage structure 1 illustrated in Figure 1. The load handling devices 31, sometimes referred to as robots 31 or bots 31, are provided with sets of wheels that engage with corresponding x-direction tracks 17 or y-direction tracks 19 to enable the bots 31 to navigate across the track structure 13 and reach particular grid cells. The illustrated pair of tracks 17, 19, separated by channels 21, 23, allows the bots 31 to occupy (or pass each other on) adjacent grid cells without colliding with each other.

[0019] 4, the bot 31 comprises a body 33 having one or more components therein or attached thereto that enable the bot 31 to perform its intended functions. These functions may include traveling throughout the storage structure 1 on the track structure 13 and raising or lowering containers 9 (e.g., from or to stacks 11) so that the bot 31 can retrieve or place containers 9 at specific locations defined by a grid pattern.

[0020] The illustrated bot 31 includes a first set of wheels 35 and a second set of wheels 37 attached to the body 33 of the bot 31, enabling the bot 31 to move along tracks 17 and 19 in the x and y directions, respectively. In particular, two wheels 35 are provided on the short side of the bot 31 visible in FIG. 4, and two more wheels 35 are provided on the opposite short side of the bot 31 (this side and the two more wheels 35 are not visible in FIG. 4). The wheels 35 engage with the tracks 17 and are rotatably attached to the body 33 of the bot 31, enabling the bot 31 to move along the tracks 17. Similarly, two wheels 37 are provided on the long side of the bot 31 visible in FIG. 4, and two more wheels 37 are provided on the opposite long side of the bot 31 (this side and the two more wheels 37 are not visible in FIG. 4). Wheels 37 engage the track 19 and are rotatably mounted to the body 33 of the bot 31 to enable the bot 31 to move along the track 19 .

[0021] The bot 31 also includes container lifting means 39 configured to raise and lower the container 9. The illustrated container lifting means 39 includes four tapes or reels 41 connected at their lower ends to a container engaging assembly 43. The container engaging assembly 43 includes engagement means (which may be provided, for example, at a corner of the assembly 43, near the tapes 41) configured to engage features of the container 9. For example, the containers 9 may be provided with one or more openings on their upper sides through which the engagement means can engage. Alternatively or additionally, the engagement means may be configured to hook under a rim or lip of the container 9 and / or to clamp or grip the container 9. The tapes 41 may be wound up or wound down to raise or lower the container engaging assembly, as required. One or more motors or other means may be provided to effect or control the winding or unwinding of the tapes 41.

[0022] As can be seen in FIG. 5 , the body 33 of the illustrated bot 31 has an upper portion 45 and a lower portion 47. The upper portion 45 is configured to house one or more operating components (not shown). The lower portion 47 is disposed below the upper portion 45. The lower portion 47 comprises a container-receiving space or cavity for accommodating at least a portion of a container 9 elevated by the container lifting means 39. The container-receiving space is sized such that the container 9 can fit sufficiently within the cavity to allow the bot 31 to move across the uppermost track structure 13 of the storage structure 1 without the underside of the container 9 getting caught on the track structure 13 or another portion of the storage structure 1. When the bot 31 reaches its intended destination, the container lifting means 39 controls the tape 41 to lower the container gripping assembly 43 and corresponding container 9 out of the cavity in the lower portion 47 and into its intended position. The intended location may be a stack 11 of containers 9 or an exit point of the storage structure 1 (or an entrance point of the storage structure 1 if the bot 31 is moving to collect a container 9 for storage within the storage structure 1). In the illustrated example, the upper portion 45 and the lower portion 47 are separated by a physical partition, although the upper portion 45 and the lower portion 47 may not be physically separated by a particular component or part of the body 33 of the bot 31.

[0023] To enable the bot 31 to move in first and second directions on different wheels 35, 37, the bot 31 includes a wheel positioning mechanism for selectively engaging the first set of wheels 35 with the first set of tracks 17 or the second set of wheels 37 with the second set of tracks 19. The wheel positioning mechanism is configured to raise and lower the first set of wheels 35 and / or the second set of wheels 37 relative to the body 33, thereby enabling the loading device 31 to selectively move in either the first direction or the second direction across the tracks 17, 19 of the storage structure 1.

[0024] The wheel positioning mechanism may include one or more linear actuators, rotary components, or other means for raising and lowering at least one set of wheels 35, 37 relative to the body 33 of the bot 31 to move at least one set of wheels 35, 37 out of or into contact with the tracks 17, 19. In some examples, only one set of wheels is configured to be raised and lowered, such that the act of lowering one set of wheels can effectively lift the other set of wheels away from the corresponding tracks, and the act of raising one set of wheels can effectively lower the other set of wheels into contact with the corresponding tracks. In other examples, both sets of wheels may be raised and lowered, which advantageously means that the body 33 of the bot 31 remains substantially the same height, and therefore the wheel positioning mechanism does not need to lift or lower the weight of the body 33 and its attached components.

[0025] To remove a container 9 from the top of the stack 11, the robot 31 is moved in the X and Y directions as needed so that the container gripping assembly 43 is positioned above the stack 11. The container gripping assembly 43 is then lowered vertically in the Z direction to engage the top container 9 of the stack 11. The container gripping assembly 43 grasps the container 9 and then pulls it upward by the tape 41, with the container 9 still attached. At the top of its vertical travel, the container 9 is housed within the vehicle body and held above the truck height. In this way, the handling device 31 can be moved to different positions in the XY plane while carrying the container 9 to transport the container 9 to another location. The tape 41 is long enough to allow the handling device 31 to remove and place a container from any height in the stack 11, including at floor level. The weight of the vehicle can be partially derived from the batteries used to power the drive mechanisms for the wheels 35, 37.

[0026] As shown in FIG. 3, multiple material handling devices 31 may be provided, allowing each bot 31 to operate simultaneously to increase the throughput of the system. The system illustrated in FIG. 3 may include specific locations known as ports, where containers 9 may be transferred into or out of the system. Additional conveyor systems (not shown) may be associated with each port, such that containers 9 delivered to a port by a bot 31 may be transferred by the conveyor system to another location, e.g., a picking station (not shown). Similarly, to replenish inventory within the system, containers 9 may be moved by the conveyor system from an external location to a port, e.g., a container filling station (not shown), and delivered by a bot 31 to a stack 11.

[0027] Each bot 31 can lift and move one container 9 at a time. If a container that is not located at the top of a stack 11 (a "target container") needs to be removed, the containers above (a "non-target container") must first be moved to allow access to the target container. This is accomplished in an operation hereinafter referred to as "digging." During a digging operation, one of the bots 31 sequentially lifts each non-target container 9a from a stack 11 containing a target container 9b and places it in an empty position in another stack 11. The target container 9b can then be accessed by the bot 31 and moved to a port for further transport.

[0028] Each bot 31 is under the control of a grid controller. Each individual container 9 in the system is tracked so that the appropriate container 9 can be retrieved, transported, and replaced as needed. For example, during an excavation operation, the location of each non-target container is logged so that the non-target containers can be tracked.

[0029] 1 to 5 has many advantages and is suitable for a wide range of storage and retrieval operations. In particular, the system allows for very high density storage of products, providing a very economical way of storing a wide range of different items in containers 9 while allowing fairly economical access to all containers 9 when required for picking.

[0030] It should be understood that messages may need to be sent to the bot. The message may be a short message, such as an instruction to move a container from a first location to a second location, or the message may be larger, such as an update to the computer code used to operate the bot or a component of the bot. Similarly, it may be necessary for the bot to send a message to a central management system, for example, to report operating parameter values, operating status reports, etc. An example of a communication system that may be used is disclosed in the applicant's international patent application WO 2015 / 185726.

[0031] FIG. 6 shows a schematic diagram of a communication system 100 that enables multiple bots 31 to communicate with a central computing device 400. The central computing device executes multiple different computer programs so that it can send instructions to each of the multiple bots and receive return messages from each of the multiple bots. Messages sent from the central computing device to the bots may instruct the bots to move to a specific grid location, place the container they are carrying at its current location, remove the top container from its current location, move to a charging point to charge its batteries, etc. Messages returned by the bots to the central computing device may include an acknowledgment that a message from the computing device was received and an action has been taken, a request that the bot move to a charging point to charge its batteries, a request that the bot return for maintenance activities, etc. The central computing device controls the operation of the storage and retrieval system so that, among other things, received products are stored for subsequent retrieval, stored products are retrieved so that customer orders can be picked, packed, and dispatched in a timely manner, and products stored within the storage and retrieval system are arranged and rearranged to support efficient operation of the system.

[0032] The communication system 100 includes base stations 200A and 200B. Each bot 31 includes a wireless antenna to communicate with one of the base stations. The communication system may further include a base station controller (BSC) 300 that controls the operation of the base stations, for example, when a bot is being handed over from a first base station to a second base station. The BSC is configured to communicate with computing devices and route messages from the computing devices to the bots and vice versa via the appropriate base station. Known wireless communication systems for use with such automated storage and retrieval systems are disclosed in WO2015 / 185726, WO2018 / 127437, and WO2018 / 177788. Alternatively, the communication system may include more than two base stations, for example, if the communication system is designed to cover a large warehouse or fulfillment center. Alternatively, the communication system may include only a single base station, for example, if the communication system is designed to cover a smaller warehouse or fulfillment center. In such cases, a base station controller is not required in the communication system.

[0033] FIG. 7 shows a schematic diagram of a system that enables secure deployment of software code to bots 31 operating as part of an automated storage and retrieval system. The system includes one or more base stations 200 (only one of which is shown in FIG. 7 for clarity), a base station controller (BSC) 300, a central computing device 400, a cryptographic server 500, and a plurality of bots 31 (only one of which is shown in FIG. 7 for clarity). In addition to the above description of FIGS. 3-5, each of the plurality of bots 31 further includes a communication interface 34 and a bot PC 40. The communication interface 34 enables communication between the bots and the base station 200 and may include a suitable modem device, e.g., a 4G modem, a WiFi modem, or the like. The communication interface 34 is connected to the bot PC 40 so that signals received from the base station can be routed to the bot PC and vice versa. The structure of the bot PC 40 is described below with reference to FIG. 9.

[0034] In this manner, it can be seen that messages can be communicated between the central computing device and the bot PC of the bot, and control messages sent by the central computing device can be received by the bot PC and then processed such that the bot can take action, e.g., the bot can activate one of the bot's drive mechanisms to move the bot in its current direction, activate a container lifting means to lower or lift a container, activate a wheel positioning mechanism to change the direction the bot is moving, etc. Similarly, messages from the bot PC can be routed back to the central computing device so that, for example, if data generated from, for example, a sensor in the bot indicates an imminent failure condition, the central computing device can instruct the bot to return to a maintenance area so that preventative action can be taken, or alternatively, the bot can be remotely instructed to return to a maintenance area.

[0035] It should be understood that each fulfillment center will have such a communications system, and that a single enterprise will likely have multiple such fulfillment centers. The components forming each of these systems can be thought of as forming a separate security zone 600. Each of these security zones may be connected to an enterprise security zone 700. The enterprise security zone 700 may include an enterprise cryptographic server 710.

[0036] In use, cryptographic operations may be used during operation of the bot PC, and thus during operation of the bot. For each bot operated within a fulfillment center, a set of cryptographic keys is generated, with each set comprising one or more cryptographic keys. For example, the enterprise cryptographic server 710 may be used to generate a set of cryptographic keys for each of multiple bots operating in each of the fulfillment centers operated by the enterprise operating the enterprise cryptographic server 710. The set of keys may then be transferred to the respective bots and then used during operation of the bots. The keys may be distributed to each bot via the cryptographic server 500 for the fulfillment center in which the bot operates. Alternatively, the cryptographic server 500 may generate multiple sets of keys required for use by multiple bots active in that fulfillment center. The creation of the sets of keys by the cryptographic server may be initiated by the enterprise cryptographic server or controlled in other ways.

[0037] The enterprise cryptographic server and / or cryptographic server 500 performs the functions of a certificate authority and other entities within a public key infrastructure so that digital certificates and cryptographic keys can be securely created, managed, and revoked as needed to facilitate the operation of bots within the fulfillment center and other operations of the fulfillment center.

[0038] In some cases, it may be possible that a fulfillment center does not deploy a cryptographic server. In such cases, the required cryptographic functionality may be provided by a corporate cryptographic server. In an alternative arrangement, a cryptographic server located at one fulfillment center may provide the required cryptographic functionality for one or more additional fulfillment centers. In a further variation, a corporate cryptographic server may provide the required cryptographic functionality for all fulfillment centers.

[0039] It will be appreciated from the following description that one or more of the sets of cryptographic keys may need to be provided to different entities. For example, a company that operates an automated storage and retrieval system to deliver products to customers is unlikely to also manufacture bots that are operated within the storage and retrieval system. In such a case, a key (or keys) for each bot produced needs to be transferred. The manufacturer needs to operate a further cryptographic server that is able to receive and manage the received keys. A secure communication channel needs to be provided to ensure secure transmission of keys between different entities.

[0040] Figure 8 shows a schematic diagram of a further example of the communication system 100 described above with reference to Figures 6 and 7. In this example, the communication system 100 further comprises a second wireless communication network. In one example, the second wireless communication network is a point-to-point wireless communication network and comprises one or more point-to-point wireless transceivers. The or each transceiver 450 of the second wireless communication network is connected to the central computing device 400 by, for example, a fixed Ethernet communication link. More specifically, the second wireless communication network is a point-to-point optical free-space communication network. The cryptographic server 500 and the base station(s) 300 are not shown in Figure 8 for clarity, but it should be understood that they are still present in the communication system of Figure 8.

[0041] Each of the multiple bots may further include a second network interface 36 connected to the bot PC 40. The second network interface is also configured to enable the bot PC to communicate with a central computing device over a second wireless communications network. The central computing device may include a software repository 410 (see below with respect to FIG. 9) that includes an operating system and one or more applications necessary to control the operation of the bots. If the bot's software requires an update, the necessary files may be transferred from the software repository to the bot over the second wireless communications network and then installed on the bot PC.

[0042] It should be understood that the software repository may alternatively be stored elsewhere, for example, on a server or cloud computing platform communicatively connected to a central computing device from which the software may be transferred to the bot.

[0043] The second wireless communications network may include multiple transceivers configured to communicate with bots located at predetermined grid cell locations. In one example, if a bot requires an upgrade to one or more elements of the software operating the bot PC, the bot may navigate to one of the predetermined grid cell locations so that the bot's second network interface 36 can communicate with one of the multiple transceivers of the second wireless communications network. In a further example, the transceivers of the second wireless communications network may be configured to communicate with bots located at charging locations that may be located around the grid. Thus, when the bot travels to a charging location to recharge the battery (or batteries) powering the bot, the bot may connect to a central computing device via the second wireless communications network. If one or more elements of the software operating the bot PC require an upgrade, those elements may be transferred from a software repository to the bot via the second wireless communications network and then installed on the bot PC.

[0044] 9 shows a schematic diagram of a bot PC 40 including a central processing unit (CPU) 4010, a random access memory (RAM) 4020, a read-only memory (ROM) 4030, a non-volatile data storage unit 4040, a cryptoprocessor 4050, and a one-time programmable memory (OTPM) 4060. The non-volatile data storage unit 4040 includes a boot loader 4042, an operating system 4044, and one or more applications 4046. The bot PC is configured such that the CPU is communicatively coupled to each of the RAM, ROM, non-volatile data storage unit, and OTPM such that the CPU can access data stored in one or more of these entities, process the accessed data, or write data to the RAM and / or non-volatile data storage unit. In light of the above, it will be appreciated that the CPU is also communicatively coupled to the communication interface 34 such that data received from the communication system 100 can be forwarded to the CPU for processing, and similarly, data generated by the CPU can be routed to the central computing device 400 via the communication interface 34 and the communication system. The bot PC is further configured such that the boot loader 4042, the operating system 4044, and the one or more applications 4046 can each communicate with the cryptographic processor 4050. In one example, the operating system and the one or more applications may be integrated into a single software package that can control the operation of the bot, communicate with a communications system, etc. In a further example, the operating system may comprise a variation of Linux®, and the one or more applications may comprise a single computer program. The operating system and the one or more applications may comprise firmware.

[0045] In use, cryptographic operations may be used during operation of the bot PC, and thus during operation of the bot. For each bot operated within the fulfillment center, a set of cryptographic keys is generated, each set comprising one or more cryptographic keys. As described above, each set of cryptographic keys may be generated by the enterprise cryptographic server or by cryptographic server 500.

[0046] FIG. 10 shows a schematic diagram of a method for transferring cryptographic keys. In S1010, a key set is generated for one of a plurality of bots. One or more of the keys in the key set are then transferred to the respective bot (S1020). The received keys are then stored by the bot (S1030). The bot may then make a request to connect to the communication system 100, for example, via one of the base stations 200 (S1040). It will be understood from the following description that the bot may make different types of requests. One of the keys held by the bot may be presented, and if the cryptographic challenge passes, the bot's request is granted (S1070). For example, a private cryptographic key held in a cryptographic server may be used to decrypt a request encoded with a public cryptographic key held by the bot. If the cryptographic challenge does not pass, the bot's request is denied (S1060).

[0047] In one example, in step S1020, one or more private keys and / or one or more public keys are transferred to the bot, thereby maintaining one or more additional private keys on the cryptographic server. One or more public keys may also be maintained on the cryptographic server. The key(s) received by the bot may be stored in a non-volatile data storage unit of the bot PC. In one example, the key may be persistently written to a one-time programmable memory (OTPM) 4060 so that the key is persistently associated with the respective bot. Therefore, if the key needs to be updated or replaced with a new key, this requires removing the OTPM from the bot PC, replacing it with a new OTPM module, and then persistently writing the new key to the new OTPM. The persistently stored key may be a public key or a private key. One or more keys may be persistently stored in the OTPM.

[0048] The public key stored in the bot can be used to encrypt a message that can be sent to a cryptographic server. The cryptographic server can then decrypt the message using one of the private keys maintained within the cryptographic server, the private key being selected from the same set of cryptographic keys as the public key stored in the bot. A response to the message to the bot can then be sent. For example, the bot can request to connect to base station 200 of communication network 100. If the correct key is used to encrypt the request, the bot is allowed to connect to the communication network. It can be seen that when one or more keys are sent to the bot by the cryptographic server and the keys are persistently written to the OTPM, access to the communication network can be controlled to a more secure level than relying on credentials such as a bot ID and password.

[0049] The bot PC includes a cryptographic processor, which may be, for example, a Trusted Platform Module (TPM). The cryptographic processor may generate one or more additional keys, which may then be used by the bot for either its internal operations or operations involving entities external to the bot. These one or more additional keys may be generated based on one or more of the key(s) received from a cryptographic server. For example, the cryptographic processor may be used to generate a symmetric key that may be used to encrypt the contents of a non-volatile data storage unit. Alternatively, one or more symmetric keys may be generated and used to encrypt the contents of one or more of the boot loader, the operating system, and one or more applications. Alternatively or additionally, an asymmetric key may be generated, which is then used to create a device identity that may be used by the bot in communications with the central communication device 400.

[0050] As described above, software for a bot may be accessed by the bot from a software repository 410, which may be stored within a central computing device. To control the software deployed to the bot, software packages may be signed using cryptographic keys generated by a cryptographic server. Furthermore, keys held by the bot may be used to authenticate the or each software package that the bot needs to download. Alternatively or additionally, a bot may only be able to access the software repository if it can present the appropriate key to the central computing device.

[0051] Table 1 below provides an example set of keys that may be stored and used by a bot. [Table 1]

[0052] From Table 1, it can be seen that by using such an exemplary set of keys, cryptographic keys are utilized to ensure that only authorized bots can connect to the communications network, that only cryptographically signed firmware can be downloaded and installed on the bots, that wireless communications between the bots and the central computing device are encrypted, that data stored on the bots is encrypted, and that the central computing device can initiate secure remote logins to the bots, for example, for maintenance purposes.

[0053] It will be understood that in some deployments of bots, some of these keys may not be necessary, and therefore not all will be used. For example, a security audit may determine that if a security risk is below a predetermined level, no mitigation is necessary. Alternatively, it may be necessary to use additional keys to protect other aspects of bot operation. For example, it may be necessary to provide two separate device identity keys. One of the keys may be used to register the bot with the network, and the second key may be used for ongoing communication with base stations of the communications network. It will be understood that keys of greater strength may be used if deemed necessary.

[0054] 11 shows a schematic diagram of an example of the contents of code written to the boot loader 4042 (see FIG. 9) of a bot. A boot image 1100 includes a boot image header 1110, a secure boot descriptor 1120, peripheral configuration code 1130, and stage 2 code 1140. The secure boot 1120 descriptor includes a certificate 1 1121, a certificate 2 1122, a certificate 3 1123, a certificate 4 1124, a certificate revocation list (CRL) 1125, a peripheral configuration code signature 1126, and a stage 2 code signature 1127.

[0055] The boot-up header 1110 defines the location of the different elements of the boot image 1100 within the boot loader. At boot-up, a secure boot descriptor 1120 is loaded into memory. The four certificates (certificate 1, certificate 2, certificate 3, and certificate 4) are referred to as the certificate block 1128. A hash of the certificate block may be persistently written to the OTPM. Thus, at boot-up, the contents of the certificate block may be hashed and compared with the values ​​stored in the OTPM. If the values ​​do not match, the boot-up is aborted because the certificate values ​​have changed. If they match, the boot-up process can proceed.

[0056] The peripheral code signature code may be compared to the peripheral code stored in the boot loader. Again, if there is a match, the boot-up procedure can proceed; if there is a mismatch, boot-up is aborted. The next step is to compare the Stage 2 code signature with the Stage 2 code; if the signature and code match, boot-up proceeds. Execution of the Stage 2 code causes the operating system and then one or more applications to run. If there is a mismatch, the boot-up process is aborted. The inability of the bot to boot-up is likely due to corrupted files or an incorrect key being used to generate the certificate or signature. Such errors must be repaired so the bot can be used subsequently.

[0057] A CRL maintains a list of certificates that have been revoked and are no longer recognized, for example, by an enterprise cryptographic server. Four certificates (certificate 1, certificate 2, certificate 3, and certificate 4) are, in one example, derived from keys 1-4 listed in Table 1 above.

[0058] 12 shows a schematic diagram of a computing device 1200 used in an implementation of a communication system of the present disclosure, which may include a central processing unit (“CPU”) 1202 connected to a storage unit 1214 and random access memory 1206. The CPU 1202 may process an operating system 1201, application programs 1203, and data 1223. The operating system 1201, application programs 1203, and data 1223 may be stored in the storage unit 1214 and loaded into the memory 1206 as needed. The computing device 1200 may further include a graphics processing unit (GPU) 1222 operatively connected to the CPU 1202 and the memory 1206 to offload intensive image processing calculations from the CPU 1202 and perform these calculations in parallel with the CPU 1202.

[0059] An operator 1207 may interact with the computing device 1200 using various input / output devices, such as a video display 1208 connected by a video interface 1205, and a keyboard 1215, a mouse 1212, and a disk drive or solid state drive 1214 connected by an I / O interface 1204. In known manner, the mouse 1212 may be configured to control cursor movement within the video display 1208 and to operate various graphical user interface (GUI) controls that appear within the video display 1208 with mouse buttons. The disk drive or solid state drive 1214 may be configured to accept computer-readable media 1216. The computing device 1200 may form part of a network via a network interface 1211, enabling the computing device 1200 to communicate with other suitably configured data processing systems (not shown). One or more different types of sensors 1235 may be used to receive input from various sources.

[0060] Control of the storage system may be performed by an appropriately configured industrial computing device, although it should be understood that the functionality of the computing device may be implemented using virtually any type of computing device, including a desktop computer, a laptop computer, a tablet computer, a wireless handheld, or a cloud computing platform. One or more computing devices may execute one or more software instances, e.g., virtual machines and / or containers. The present systems and methods may also be implemented as a computer-readable / usable medium containing computer program code for enabling one or more computing devices to implement each of the various process steps in the methods of the present disclosure. When more than one computing device performs an entire operation, the computing devices are networked to distribute the various steps of the operation.

[0061] It should be understood that the term computer-readable medium or computer-usable medium comprises one or more of any type of physical embodiment of program code. In particular, computer-readable / usable medium can comprise program code embodied on one or more portable storage articles of manufacture (e.g., optical disks, magnetic disks, tapes, etc.), on one or more data storage portions of a computing device, such as memory associated with a computer and / or storage system. In a further aspect, the present disclosure provides systems, devices, methods, and computer programming products including non-transitory machine-readable instruction sets for use in implementing such methods and enabling the functionality described above.

[0062] In an alternative arrangement, the storage and retrieval system may be sized such that a single base station is sufficient to provide wireless coverage for the entire grid surface. In such cases, the BSC may be kept as a separate entity, or the BSC functionality may be incorporated into the base station.

[0063] It is envisioned that any one or more of the variations described in the preceding paragraphs may be implemented in the same embodiment of a communication system.

[0064] In this document, the phrase "movement in the n-direction," where n is one of x, y, and z (and related phrases) is intended to mean movement substantially along or parallel to the n-axis in either direction (i.e., toward the positive end of the n-axis or toward the negative end of the n-axis). In this document, the term "connect" and its derivatives are intended to include the possibility of direct connection and indirect connection. For example, "x is connected to y" is intended to include the possibility of x being directly connected to y with no intervening components, and the possibility of x being indirectly connected to y with one or more intervening components. When a direct connection is intended, "directly connected," "directly connected," or similar terms are used. Similarly, the term "support" and its derivatives are intended to include the possibility of direct contact and indirect contact. For example, "x supports y" is intended to include the possibility that x directly supports and directly contacts y with no intervening components, and the possibility that x indirectly supports y with one or more intervening components that contact x and / or y. The term "attach" and its derivatives are intended to include the possibility of direct and indirect attachment. For example, "x is attached to y" is intended to include the possibility that x is directly attached to y with no intervening components, and the possibility that x is indirectly attached to y with one or more intervening components.

[0065] In this document, the term "comprises" and its derivatives are intended to have an inclusive rather than exclusive meaning. For example, "x comprises y" is intended to include the possibility that x includes only y, multiple y's, or one or more y's and one or more other elements. When an exclusive meaning is intended, the phrase "x is composed of y" is used to mean that x includes only y and nothing else. In this document, "controller" is intended to include any hardware suitable for controlling (e.g., providing instructions to) one or more other components. For example, a processor is equipped with one or more memories and appropriate software to process data associated with one or more components and send appropriate instructions to the component(s) to enable the component(s) to perform its / their intended function(s).

[0066] In one respect, the present disclosure provides a system for managing cryptographic keys used by bots in an automated storage and retrieval system. Each bot is assigned a set of cryptographic keys, allowing various bot functions to be performed only when the appropriate cryptographic key is presented.

Claims

1. 1. A method of operating a material handling device in a storage system, comprising: generating a set of cryptographic keys associated with the load handling device; storing a first encryption key of the set of encryption keys in the loading device; using a second encryption key of the set of encryption keys to authenticate the first encryption key stored on the load handling device, whereby software can only be installed on the load handling device if the authentication is successful; A method comprising:

2. The method of claim 1 , wherein the first encryption key is persistently stored on the load handling device.

3. The method of claim 2 , wherein the first encryption key is permanently burned into a non-volatile data storage unit, the non-volatile data storage unit being subsequently installed into the load handling device.

4. 4. The method of claim 1, further comprising the step of using a third encryption key from the set of encryption keys to authenticate the first encryption key stored in the loading device, whereby the loading device is introduced into a storage system only if the authentication is successful.

5. The method of claim 4 , wherein introducing the load handling device into the storage system comprises forming a connection between the load handling device and the storage system via a wireless communication system.

6. 5. The method of claim 4, wherein the method comprises the further step of using a fourth encryption key of the set of encryption keys to authenticate the first encryption key stored in the load handling device, whereby the load handling device can connect to the storage system via a wireless communication system only if the authentication is successful.

7. The method according to any one of claims 1 to 6, wherein the method comprises the further step of the load handling device generating one or more local encryption keys for use in the load handling device.

8. The method of claim 7 , wherein the one or more local encryption keys are generated based on the first encryption key stored on the load handling device.

9. 1. A load handling device for use in a storage system, the load handling device comprising: non-volatile data storage; volatile data storage; one or more processors; and a first communications interface for communicating with a wireless communications network of the storage system, the load handling device comprising: a first encryption key from a set of encryption keys associated with the load handling device is stored in the non-volatile data storage of the load handling device; A load handling device, wherein software can be installed on said load handling device only if a second encryption key from said set of encryption keys successfully authenticates said first encryption key.

10. The load handling device of claim 9 , wherein the first encryption key is persistently stored in the non-volatile data storage of the load handling device.

11. 10. The load handling device of claim 9, wherein the non-volatile data storage of the load handling device comprises a one-time programmable memory device.

12. The load handling device according to any one of claims 9 to 11, further comprising a cryptographic processor.

13. 13. A load handling device according to claim 12, wherein the cryptographic processor is configured to generate, in use, one or more further cryptographic keys.

14. 14. The load handling device of claim 13, wherein the cryptographic processor is configured to generate, in use, one or more further cryptographic keys based on the first cryptographic key stored in the non-volatile data storage of the load handling device.

15. 15. A load handling device as claimed in any one of claims 9 to 14, wherein, in use, the load handling device is introduced into a storage system only if a third encryption key from the set of encryption keys successfully authenticates the first encryption key.

16. 16. The load handling device of claim 15, wherein introducing the load handling device to the storage system comprises forming a connection between the load handling device and the storage system via a wireless communication system.

17. 16. The load handling device of claim 15, wherein, in use, the load handling device is connected to the storage system via the first communication interface only if a fourth encryption key from the set of encryption keys successfully authenticates the first encryption key.

18. the handling device is configured to lift and move containers stacked in a stack in a storage structure, the storage structure including a first set of tracks extending in a first direction above the stack of containers and a second set of tracks extending in a second direction transverse to the first direction, the handling device being configured to move on the tracks above the stack, the handling device: a body configured to house one or more operating components; a container receiving space configured to accommodate at least a portion of a container; a first set of wheels configured to engage with the first set of tracks to guide movement of the load handling device in the first direction; and a second set of wheels configured to engage with the second set of tracks to guide movement of the load handling device in the second direction. a wheel positioning mechanism configured to selectively engage the first set of wheels with the first set of tracks or the second set of wheels with the second set of tracks, the wheel positioning mechanism configured to raise and lower the first set of wheels and / or the second set of wheels relative to the body, thereby enabling the loading device to selectively move in either the first direction or the second direction across the tracks of the storage structure; container lifting means comprising a container engaging assembly configured to releasably engage a container, and a lifting and lowering assembly configured to raise and lower said container engaging assembly; The load handling device according to any one of claims 9 to 17, further comprising:

19. 1. A storage system comprising: a first set of parallel tracks extending in an X direction and a second set of parallel tracks extending in a Y direction intersecting the first set in a substantially horizontal plane, forming a grid pattern having a plurality of grid spaces; a plurality of stacks of storage containers located beneath the truck and arranged such that each stack lies within the footprint of a single grid space; At least one material handling device according to any one of claims 9 to 18, wherein said at least one material handling device is arranged to selectively move in the X direction and / or the Y direction above said stack on said track and is arranged to transport storage containers; a picking station positioned to receive storage containers transported by the at least one material handling device and to transfer items from the storage containers to shipping containers; A storage system comprising:

20. 20. The storage system of claim 19, wherein the at least one material handling device has a footprint that occupies only a single grid space in the storage system, such that a transport device occupying one grid space does not prevent a transport device from occupying or crossing an adjacent grid space in the X direction and / or the Y direction.

21. A data carrier comprising computer executable code for performing the method of any one of claims 1 to 8.

Citation Information

Patent Citations

  • Storage system and method

    JP2021113130A

  • Building automation systems for online, offline, and hybrid licensing of distributed edge devices

    US20180119975A1

  • Systems and methods for fleet management of robotic surgical systems

    US20190374292A1

  • Online Security Services based on Security Features Implemented in Memory Devices

    US20220129389A1

  • Safety system for an automated storage and picking system and method of operation thereof

    WO2018141876A1