Modular appliance configuration and recovery
Patent Information
- Application Number
- US19/091322
- Authority / Receiving Office
- US · United States
- Patent Type
- Applications(United States)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2026-10-01
AI Technical Summary
While modular appliance designs may provide significant technical benefits, it also introduces technical challenges related to initial programming and configuration as well as ongoing maintenance and repairs.
Smart Images

Figure US20260298501A1-D00000_ABST
Abstract
Description
FIELD
[0001] The present disclosure relates to appliances such as water heating systems and, more particularly, to control systems for appliances.SUMMARY
[0002] Appliances, such as water heating systems, may be manufactured using modular components designed to support a range of configurations. To further streamline the manufacturing process, these components can be programmed post-manufacture to meet specific operational requirements. Such approaches may offer numerous manufacturing-related technical benefits, including increased production efficiency, reduced waste, and shorter delivery times. By delivering appliances in a universal, unprogrammed state, manufacturers may allow distributors or end users to configure the appliances to their desired specifications post-delivery. Standardizing components in such manners may simplify production workflows, reduce manufacturing complexity, and minimize lead times, ultimately lowering costs for end users. Additionally, modular, programmable designs provide significant supply chain advantages. For example, instead of maintaining a large inventory of hardware specific to each appliance variant, manufacturers, distributors, and service providers can stock a smaller set of universal, interchangeable components. These components can then be configured or reconfigured as needed, simplifying inventory management, reducing storage requirements, and supporting more flexible servicing and repair operations.
[0003] While modular appliance designs may provide significant technical benefits, it also introduces technical challenges related to initial programming and configuration as well as ongoing maintenance and repairs. For example, a replacement component designed for broad compatibility may need to be programmed or reprogrammed to match the appliance's original specifications. Errors in this process can create potential failure points, disrupting appliance functionality and leading to downtime, operational inefficiencies, and other issues. Moreover, since appliances may be programmed at various post-manufacturing locations—such as distribution centers, installation sites, or end-use locations, etc.—it may be technically challenging to consistently track the correct configuration for each appliance and ensure trusted access to this data during subsequent repairs.
[0004] Systems, methods, apparatuses, and techniques described in this specification address these challenges by employing a trusted appliance configuration platform that serves as a centralized “source of truth” for configuration data. The appliance configuration platform may securely store and manage appliance-specific information, such as configuration settings, software updates, firmware parameters, etc., which may be linked to a unique identifier assigned to each appliance. As a result, even when components fail or are replaced, accurate and trusted configuration data remains accessible for programming or reprogramming replacement components. By maintaining reliable access to configuration data throughout the appliance lifecycle, the appliance configuration platform reduces the risk of configuration errors, minimizes downtime, and ensures operational reliability by preserving the integrity of each appliance's intended configuration.
[0005] The appliance configuration platform may be accessible to various devices, including user devices operated by factory personnel, distributors, service technicians, and end users, as well as the appliances themselves. For example, when a component fails and reprogramming of a replacement component becomes necessary, the appliance configuration platform can generate a recovery code, which facilitates the appliance automatically programming or reprogramming its components and restore the correct configuration. The recovery code may be provided to user devices or directly to the appliance via various communication channels. Such approaches may simplify maintenance workflows and preserve the appliance's integrity through subsequent configurations and reconfigurations, improving operational reliability by reducing the likelihood of errors during maintenance or servicing.
[0006] Systems, methods, apparatuses, and techniques described in this specification may also reduce manufacturing complexity by eliminating the need to program each individual component on the production line. Instead, in some implementations, only the appliance's memory controller needs to be programmed with the appropriate configuration data. During the initial configuration process, the appliance's main controller may retrieve the configuration data from the memory controller, perform an integrity check to ensure its accuracy and completeness, and then automatically program the unconfigured components with the correct settings. By centralizing the programming process in this way, manufacturers can streamline production workflows, reduce the risk of introducing errors during component programming, and avoid the inadvertent delivery of misconfigured appliances to end users. Such techniques may not only simplify manufacturing processes but may also improve reliability and consistency across large-scale production operations.
[0007] Systems, methods, apparatuses, and techniques described in this specification may also reduce the need for manual servicing of appliances by facilitating automated self-correction. For example, when a component's configuration does not match the expected configuration of the appliance—such as after a component failure or replacement—the main controller may detect the inconsistency and evaluate the configurations of the matching components within the appliance. In response to the main controller determining that a sufficient number of components have matching configurations, the main controller may automatically reprogram the non-matching component based on the data from the matching components. By allowing the appliance to self-correct in certain failure scenarios, such automated processes can enhance uptime, reduce operational disruptions, and minimize the need for manual interventions.
[0008] In scenarios where the appliance cannot automatically reconfigure failed or replaced components, the main controller may rely on a recovery code generated by the appliance configuration platform. For example, a service technician or user may request the recovery code from the platform and input it into the appliance. In some implementations, the appliance itself may directly request the recovery code from the configuration platform. The main controller can then use the recovery code to program or reprogram the non-matching components, ensuring the appliance is restored to its intended configuration, even in severe failure scenarios. This approach provides a robust fallback mechanism for maintaining operational integrity and reliability, even in cases where automated self-correction is insufficient.
[0009] Furthermore, to ensure the appliance operates correctly during normal operation, the main controller may periodically perform integrity checks on the programmable components. As described previously, when discrepancies are detected, the main controller may attempt to resolve them by synchronizing the mismatched component with data from the memory controller or other trusted components. When automatic resolution is not possible, the appliance may halt operations to prevent unintended behavior and notify the user of the issue. In such scenarios, as described earlier, the user may be prompted to provide a recovery code or contact a service technician to restore the correct configuration. Such safeguards may further enhance operational reliability, minimize the risk of prolonged downtime, and ensure that configuration errors are promptly identified and addressed.
[0010] According to some examples, an appliance includes a main controller and one or more programmable components. The main controller is configured to receive data from each of one or more programmable components, compare the received data to determine whether the configuration of each of the one or more programmable components matches a configuration of the main controller, and enter an alternate operational mode in response to determining that the configuration of each of the one or more programmable components does not match the configuration of the main controller. The data is indicative of a configuration of each of the one or more programmable components.
[0011] In other features, the main controller is further configured to enter a normal operational mode in response to determining that the configuration of each of the one or more programmable components matches the configuration of the main controller. In other features, the one or more programmable components include a memory and the main controller is further configured to, in the alternate operational mode, determine whether a current operational cycle of the appliance is an initial operational cycle, and update the configuration of each of the one or more programmable components based on a configuration of the memory in response to determining that the current operational cycle of the appliance is the initial operational cycle.
[0012] In other features, the main controller is further configured to, in the alternate operational mode, determine whether a number of matching configurations of one or more programmable components and the main controller crosses a threshold and enter an automatic recovery mode in response to determining that the number of matching configurations crosses the threshold. In other features, the main controller is further configured to in the automatic recovery mode, determine whether the appliance is running and update a configuration of a non-matching programmable component based on the matching configuration in response to determining that the appliance is running.
[0013] In other features, the main controller is further configured to enter an assisted recovery mode in response to determining that the appliance is not running. In other features, the main controller is further configured to enter the assisted recovery mode in response to determining that the number of matching configurations does not cross the threshold. In other features, the main controller is further configured to, in the assisted recovery mode, receive a recovery code. The recovery code includes a payload. In other features, the recovery code includes a validation token and the main controller is further configured to verify an integrity of the payload based on the validation token.
[0014] In other features, the one or more programmable components include a memory. The main controller is further configured to retrieve a predefined configuration from the memory based on the payload and program a non-matching programmable component based on the predefined configuration. In other features, the main controller is further configured to program a non-matching programmable component based on the payload. In other features, the payload includes information defining a programmable component configuration. In other features, the one or more programmable components include a user interface and the main controller is configured to receive the recovery code from the user interface.
[0015] In other features, the appliance includes a communications interface configured to receive a recovery code from a user device and the main controller is configured to receive the recovery code from the communications interface.
[0016] Other examples provide a method that includes receiving, at a main controller of an appliance, data from each of one or more programmable components of the appliance, comparing, at the main controller, the received data to determine whether the configuration of each of the one or more programmable components matches a configuration of the main controller, and entering an alternate operational mode at the main controller in response to determining that the configuration of each of the one or more programmable components does not match the configuration of the main controller. The data is indicative of a configuration of each of the one or more programmable components.
[0017] In other features, the method includes entering a normal operational mode at the main controller in response to determining that the configuration of each of the one or more programmable components matches the configuration of the main controller. In other features, the method includes, in the alternate operational mode, determining, at the main controller, whether a current operational cycle of the appliance is an initial operational cycle, and updating the configuration of each of the one or more programmable components based on a configuration of a memory of the respective programmable component in response to determining that the current operational cycle is the initial operational cycle.
[0018] In other features, the method includes, in the alternate operational mode, determining, at the main controller, whether a number of matching configurations of one or more programmable components and the main controller crosses a threshold, and entering an automatic recovery mode at the main controller in response to determining that the number of matching configurations crosses the threshold. In other features, the method includes in the automatic recovery mode, determining, at the main controller, whether the appliance is running and updating a configuration of a non-matching programmable component based on the matching configuration in response to determining that the appliance is running.
[0019] In other features, the method includes entering an assisted recovery mode at the main controller in response to determining that the appliance is not running. In other features, the method includes entering the assisted recovery mode at the main controller in response to determining that the number of matching configurations does not cross the threshold. In other features, the method includes, in the assisted recovery mode, receiving a recovery code at the main controller. The recovery code includes a payload. In other features, the method includes verifying, at the main controller, an integrity of the payload based on a validation token included in the recovery code.
[0020] In other features, the method includes retrieving, via the main controller, a predefined configuration from a memory of the one or more programmable components based on the payload and programming, via the main controller, a non-matching programmable component based on the predefined configuration. In other features, the method includes programming, via the main controller, a non-matching programmable component based on the payload. In other features, the payload includes information defining a programmable component configuration.
[0021] In other features, the method includes receiving, at the main controller, a recovery code from a user interface. The one or more programmable components includes the user interface. In other features, the method includes receiving, at the main controller, the recovery code from a communications interface. The communications interface is configured to receive a recovery code from a user device.
[0022] According to some examples, a system includes an appliance, non-transitory computer-readable media storing instructions, and an electronic processor. The electronic processor is configured to execute the instructions to receive a unique identifier associated with an appliance, store the unique identifier at a data store, receive configuration information associated with the appliance, associate the configuration information with the unique identifier, store the configuration information at the data store, and generate a recovery code based on the configuration information associated with the unique identifier in response to receiving a request including an indication of the unique identifier. A main controller of the appliance is configured to program a programmable component of the appliance based on the recovery code.
[0023] In other features, the recovery code includes a payload. In other features, the recovery code includes a validation token. The main controller of the appliance is configured to verify an integrity of the payload based on the validation token. In other features, the main controller of the appliance is configured to retrieve a predefined configuration from a memory based on the payload and program a programmable component of the appliance based on the predefined configuration. In other features, the main controller of the appliance is configured to program a programmable component of the appliance based on the payload. In other features, the payload includes information defining a programmable component configuration.
[0024] Other examples provide a method that includes receiving, at an appliance configuration platform, a unique identifier associated with an appliance, storing, at the appliance configuration platform, the unique identifier at a data store, receiving, at the appliance configuration platform, the configuration information associated with the appliance, associating, at the appliance configuration platform, the configuration information with the unique identifier, storing, at the appliance configuration platform, the configuration information at the data store, generating, at the appliance configuration platform, a recovery code based on the configuration information associated with the unique identifier in response to receiving a request including an indication of the unique identifier, and programming, at a main controller of the appliance, a programmable component of the appliance based on the recovery code.
[0025] In other features, the recovery code includes a payload. In other features, the method includes verifying, at the main controller of the appliance, an integrity of the payload based on a validation token included in the recovery code. In other features, the method includes retrieving, at the main controller of the appliance, a predefined configuration from a memory based on the payload and programming, via the main controller of the appliance, a programmable component of the appliance based on the predefined configuration. In other features, the method includes programming, via the main controller of the appliance, a programmable component of the appliance based on the payload. In other features, the payload includes information defining a programmable component configuration.
[0026] Other examples, embodiments, features, and aspects will become apparent by consideration of the detailed description and accompanying drawings.BRIEF DESCRIPTION OF THE DRAWINGS
[0027] FIG. 1 is a block diagram of a system including a configurable appliance, according to some examples.
[0028] FIG. 2 is a front view of a configurable appliance, according to some examples.
[0029] FIG. 3 is a block diagram illustrating an interconnected hardware control system of an appliance, according to some examples.
[0030] FIG. 4 is a block diagram illustrating additional details associated with a main controller, according to some examples.
[0031] FIG. 5 is a block diagram illustrating additional details associated with a heating controller, according to some examples.
[0032] FIG. 6 is a block diagram illustrating additional details associated with a memory controller, according to some examples.
[0033] FIG. 7 is a block diagram illustrating additional details associated with a user interface, according to some examples.
[0034] FIG. 8 is a block diagram illustrating additional details associated with an appliance configuration platform, according to some examples.
[0035] FIG. 9 is a block diagram illustrating additional details associated with a user device, according to some examples.
[0036] FIG. 10 illustrates a message sequence chart illustrating interactions between components of a system, according to some examples.
[0037] FIG. 11 illustrates a recovery code, according to some examples.
[0038] FIGS. 12-15 present a flowchart of a process illustrating programming logic of a main controller, according to some examples.
[0039] In the drawings, reference numbers may be reused to identify similar and / or identical elements.DETAILED DESCRIPTION
[0040] FIG. 1 is a block diagram of a system 100 including a configurable appliance 102, according to some examples. In one example, the system 100 includes the configurable appliance 102, an appliance configuration platform 104, one or more user devices 106 (such as, for example, user devices 106-1 and 106-2), and a communications system 108. Although a single appliance 102, a single appliance configuration platform 104, two user devices 106, and a single communications system 108 is illustrated in the example of FIG. 1, other implementations of the system 100 include a different number of each appliance, platform, device, or system. Additionally, although these elements are illustrated as discrete, individual elements in FIG. 1, one or more of the elements may be combined into a single component and / or split across multiple components in certain configurations.
[0041] In various implementations, the appliance configuration platform 104 is implemented as a computing platform or as part of a computing platform. Examples of suitable computing platforms include on-premises servers, distributed systems, cloud infrastructures, and / or hybrid deployments that combine multiple deployment models. In some examples, the computing platforms are implemented as local servers, clusters of distributed servers, or components within scalable cloud computing environments. Suitable cloud technologies may include platform-as-a-service (PaaS) solutions, container orchestration systems (e.g., Kubernetes), serverless computing platforms, and / or managed hosting services. In various implementations, the computing platforms include dedicated bare-metal servers, content delivery networks (CDNs), and / or web hosting services, depending on the specific requirements of the application.
[0042] In some examples, the user devices 106 include one or more personal or mobile computing platforms that facilitate user interaction with components of the system 100. Examples of suitable platforms include personal computers (PCs) and / or workstations, as well as portable devices such as laptops, tablets, and / or smartphones. In various implementations, user devices 106 serve as access points for initiating, monitoring, or managing interactions with components of the system 100 and support various operating systems (e.g., Windows, macOS, iOS, Android) and interfaces. Various implementations of the user devices 106 include web browsers, standalone desktop applications, and / or mobile apps for connecting to and interacting with components of the system 100, such as the appliance 102 and / or the appliance configuration platform 104.
[0043] The configurable appliance 102, appliance configuration platform 104, and / or user devices 106 may communicate with one another via the communications system 108. Although the communications system 108 is illustrated as a single element in FIG. 1, the communications system 108 may be implemented as multiple systems. In various implementations, a component of the system 100 may use a different type of communications system depending on the corresponding component. For example, a user device 106 may communicate with the appliance 102 using a different communications system than the user device 106 uses to communicate with the appliance configuration platform 104. Similarly, the appliance configuration platform 104 may communicate with the appliance 102 using a different communications system than the appliance configuration platform 104 uses to communicate with a user device 106. In some examples, the components of the system 100 communicate via a shared or common communications system. It should be appreciated that the components of the system 100 may communicate over any combination of suitable communications systems, as may be appropriate for the particular application.
[0044] Thus, various implementations of the communications system 108 include any combination of diverse networks and technologies that support data transmission between components of the system 100. Examples of suitable networks include both wired and wireless communication systems. Wireless networks encompass a broad range of technologies, including wide-area networks such as cellular systems. Examples of suitable cellular systems include general packet radio service (GPRS) networks, time-division multiple access (TDMA) networks, code-division multiple access (CDMA) networks, global system for mobile communications (GSM) networks, enhanced data rates for GSM evolution (EDGE) networks, high-speed packet access (HSPA) networks, evolved high-speed packet access (HSPA+) networks, long-term evolution (LTE) networks, worldwide interoperability for microwave access (WiMAX) networks, fifth-generation mobile networks (5G), and similar technologies. Local wireless networks may include systems implemented based on IEEE 802.11 standards (e.g., Wi-Fi) or wireless application protocol (WAP). These networks may facilitate communication over varying distances and are suitable for both broad and localized connectivity needs.
[0045] In some examples, the communications system 108 includes a combination of short-range systems, wired communication systems, and other specialized networks. Suitable short-range systems may include Bluetooth systems, near-field communication (NFC) systems, Zigbee systems for low-power and low-data-rate applications, and ultra-wideband (UWB) systems for high-precision data transmission and location tracking. Wired communication systems may include those implemented according to serial communication protocols such as RS-232, RS-485, universal serial bus (USB), and universal asynchronous receiver-transmitter (UART). Additional examples of suitable wired and hybrid networks include optical networks for high-speed data transmission, local area networks (LANs) for localized connectivity, global communication networks such as the Internet for broader reach, and communication over power lines (PLC) to utilize existing electrical infrastructure.
[0046] In addition to facilitating direct digital communication between system components, the communications system 108 may also support human-assisted communication channels for customer service and technical support. For instance, in scenarios where an appliance 102 requires assistance with recovery or reconfiguration, a user or service technician may use a user device 106 to contact a support center—such as a manufacturer-operated customer service or technical support center—via the communications system 108. At the support center, personnel may access the appliance configuration platform 104, which may generate a recovery code in accordance with techniques described herein. The support center may then relay the recovery code back to the user, who can input it into the appliance 102 via techniques described herein. Such human-assisted support mechanisms provide an additional layer of accessibility, particularly in scenarios where direct digital recovery may not be possible or where user intervention may be required for verification and troubleshooting. By employing a suitable combination of these networks and technologies, the communications system 108 facilitates reliable and efficient data exchange between components of the system 100.
[0047] FIG. 2 is a front view of a configurable appliance 102, according to some examples. In the example of FIG. 2, the appliance 102 is implemented as a water heater. In other examples, the appliance 102 may be implemented as any other suitable appliance, including a tankless water heater. The appliance 102 may include a tank 202 for holding water, a rating plate 204 coupled to the tank 202, a user interface 206 for interacting with the appliance 102, and a communications interface 208 for communicating with other components of the system 100, such as via the communications system 108.
[0048] The tank 202 may include an outer shell, an inner shell, and an insulation layer positioned between the outer and inner shells. The outer shell may be constructed from a durable material, such as steel, to provide structural integrity. The inner shell may also include steel but may also incorporate a corrosion-resistant lining made of materials such as glass or polymer coatings to prevent degradation when containing a fluid such as water. The insulation layer may be constructed from materials that minimize heat transfer, such as fiberglass or polyurethane foam, to reduce heat loss from the tank to the surrounding environment.
[0049] The rating plate 204 may display operational and regulatory information for the appliance 102, such as a model identifier, a unique identifier (e.g., a serial number), the capacity of the tank 202, rated pressure capacity of the appliance 102, and / or other relevant details. In various implementations, the rating plate 204 includes a scannable feature 210, such as a QR code or barcode. The scannable feature 210 may allow a user device 106 to retrieve additional information about the appliance 102 or facilitate connection with the appliance 102 (e.g., via the communications system 108) for configuration and maintenance activities, as will be described in detail.
[0050] FIG. 3 is a block diagram illustrating an interconnected hardware control system of the appliance 102, according to some examples. As illustrated in FIG. 3, the appliance 102 may include a main controller 302, a heating controller 304, and a memory, such as, for example, a memory controller 306. The memory controller 306, user interface 206, and communications interface 208 may be connected to the main controller 302 via a common communication bus, such as the communication bus 308. The heating controller 304 may be connected to the main controller 302 via a dedicated communication link, such as a wire harness. Similarly, the heating controller 304 may be connected to the heating components 310 via a separate dedicated communication link, such as another wire harness.
[0051] FIG. 4 is a block diagram illustrating additional details associated with the main controller 302, according to some examples. The main controller 302 may include one or more electronic processors—such as an electronic processor 402—connected to non-transitory computer-readable storage media—such as storage 404—via a communication bus 406. The storage 404 may store instructions that, when executed by the electronic processor 402, cause the electronic processor 402 to perform various functions associated with the main controller 302, as described herein. For example, as will be describe in detail, these functions may include retrieving configuration data from the memory controller 306, coordinating communication between subsystems such as the user interface 206 and the heating controller 304, managing the overall operation of the appliance 102, managing communications with other components of the system 100, etc.
[0052] FIG. 5 is a block diagram illustrating additional details associated with the heating controller 304, according to some examples. The heating controller 304 may include one or more electronic processors—such as an electronic processor 502—connected to non-transitory computer-readable storage media—such as storage 504—via a communication bus 506. The storage 504 may store instructions that, when executed by the electronic processor 502, cause the electronic processor 502 to perform various functions associated with the heating controller 304, as described herein. These functions may include controlling the operation of the heating components 310, ensuring that the heating components 310 operate within the parameters provided by the main controller 302, etc.
[0053] FIG. 6 is a block diagram illustrating additional details associated with the memory controller 306, according to some examples. The memory controller 306 may include one or more electronic processors—such as an electronic processor 602—connected to non-transitory computer-readable storage media—such as storage 604—via a communication bus 606. The storage 604 may store instructions that, when executed by the electronic processor 602, cause the electronic processor 602 to perform various functions associated with the memory controller 306, as described herein. For example, as will be describe in detail, these functions may include managing configuration data for the appliance 102, as described in detail herein.
[0054] FIG. 7 is a block diagram illustrating additional details associated with the user interface 206, according to some examples. The user interface 206 may include one or more electronic processors—such as an electronic processor 702, one or more input devices—such as an input device 704, one or more output devices—such as an output device 706, and non-transitory computer-readable storage media—such as storage 708. The electronic processor 702, input device 704, output device 706, and storage 708 may be connected via a communication bus 710.
[0055] Examples of input devices 704 may include physical buttons, dials, or switches that allow a user to input commands or adjust settings. Examples of output devices 706 may include display screens, indicator lights, or audible alarms that provide feedback or information to the user. In various implementations, the input device 704 and output device 706 is combined into a single device, such as a touchscreen, which supports both user input and visual output. The touchscreen may allow users to adjust settings, view system status, or receive error notifications through an intuitive graphical interface.
[0056] The storage 708 may store instructions that, when executed by the electronic processor 702, cause the electronic processor 702 to perform various functions associated with the user interface 206, as described herein. These functions may include processing user input, updating display outputs, facilitating communication between the user interface 206 and other components of the appliance 102, such as the main controller 302, etc.
[0057] Returning to FIG. 3, the heating components 310 include components configured to heat water—such as the water contained in the tank 202—using one or more heat sources. Depending on the specific configuration of the appliance 102, the heat sources may include burners or combustors supplied by a fuel source (e.g., natural gas or propane), electrical resistance elements, a heat pump designed to transfer heat from ambient air or a building's water supply, and / or a combination thereof.
[0058] In configurations implemented with a combustor, the heating components 310 may include a burner assembly, a gas valve, a blower, and an igniter. The burner assembly may function as the central component for generating heat by burning fuel regulated by the gas valve. The gas valve, under the control of the heating controller 304, may adjust the flow of fuel, for example, based on commands from the main controller 302. The blower may ensure an adequate supply of combustion air, which is mixed with the fuel to promote efficient combustion. The igniter may initiate the combustion process by providing a spark or heat source for ignition. Thus, the heating controller 304 may command the heating components 310 to collectively function in a coordinated manner to deliver controlled and efficient heating.
[0059] In operation, the user may interact with the user interface 206 through the input device 704, such as a touchscreen that displays instructions, messages, performance data, and prompts for user input, or through other input devices like keypads or on-screen selection options. User inputs received via the user interface 206 may be transmitted to the main controller 302, which may process the inputs to manage the operation of the appliance 102. For example, the main controller 302 may control the heating controller 304 by transmitting configuration data, such as the appliance's fuel type or heating capacity, and / or operational commands based on the user inputs. The heating controller 304, in turn, may utilize this information to manage the heating components 310 according to the configuration and commands provided. This operation may be guided by software instructions stored in the storage 504. Additionally, the main controller 302 may relay data related to the configuration and operation of the appliance 102 to the user interface 206, allowing real-time feedback and information to be displayed to the user via the output device 706. Additional functionality of the appliance 102 (including its various components) is described herein with reference to the FIG.
[0060] FIG. 8 is a block diagram illustrating additional details associated with the appliance configuration platform 104, according to some examples. In the example of FIG. 8, the appliance configuration platform 104 includes system resources 802, a communications interface 804, and non-transitory computer-readable storage media, such as, for example, storage 806. In various implementations, system resources 802 includes one or more electronic processors and / or one or more graphics processing units for executing instructions stored in the storage 806, volatile computer memory, non-volatile computer memory, and / or one or more system buses interconnecting the components of the appliance configuration platform 104 (such as any of the previously described components). The communications interface 804 includes one or more components configured to facilitate communication via the communications system 108. For example, the communications interface 804 includes one or more transceivers and associated circuitry for handling data communications via the communications system 108.
[0061] In some examples, the storage 806 includes an appliance configuration application 808 and a data store 810. The appliance configuration application 808 may manage, process, and store configuration data for appliances within the system 100, for example, using the data store 810 as the primary repository for this information. The appliance configuration application 808 may handle tasks such as storing and retrieving configuration data to and from the data store 810, generating recovery codes for appliances in the system 100, and communicating with other components of the system 100.
[0062] The data store 810 may function as a structured repository, supporting the storage and retrieval of configuration data. Depending on the implementation, the data store 810 may be designed using various database architectures. Examples include relational database management systems (RDBMS) for highly structured data with predefined relationships or NoSQL databases for unstructured or semi-structured data requiring flexibility and scalability, among others. To ensure high availability and fault tolerance, the data store 810 may leverage distributed database architectures, incorporating features such as data replication, partitioning, and automatic failover. Furthermore, the data store 810 may support real-time data querying to enable immediate access to critical configuration information during maintenance, recovery, or diagnostics. Additional functionality of the appliance configuration application 808 and the data store 810 is described herein with reference to the FIG.
[0063] FIG. 9 is a block diagram illustrating additional details associated with a user device 106, according to some examples. In the example of FIG. 9, the user device 106 includes system resources 902, a communications interface 904, and non-transitory computer-readable storage media, such as, for example, storage 906. In various implementations, system resources 902 includes one or more electronic processors and / or one or more graphics processing units for executing instructions stored in the storage 906, volatile computer memory, non-volatile computer memory, and / or one or more system buses interconnecting the components of the user device 106 (such as any of the previously described components). The communications interface 904 includes one or more components configured to facilitate communication via the communications system 108. For example, the communications interface 904 includes one or more transceivers and associated circuitry for handling data communications via the communications system 108.
[0064] In various implementations, the storage 906 includes an appliance configuration application 908. The appliance configuration application 908 may be a dedicated software application for communicating with the appliance configuration application 808 and / or appliances of the system 100. In some examples, the storage 906 includes a communications application 910. The communications application 910 may be a general-purpose communication application, such as, for example, a web browser, messaging application, telephony application, teleconference or video conference application, etc., suitable for communicating with the appliance configuration application 808 and / or appliances of the system 100. Additional functionality of the appliance configuration application 908 and communications application 910 is described herein with reference to the FIG.
[0065] FIG. 10 illustrates a message sequence chart 1000 illustrating interactions between components of the system 100, according to some examples. In certain practical applications, appliances such as the appliance 102 may be manufactured as universal base units that are initially inoperable and require post-manufacturing programming to achieve their final configuration. This programming may be performed by a distributor, service technician, or end user to tailor the appliance 102 to specific operational requirements. To ensure traceability throughout its lifecycle, the appliance 102 may be associated with a unique identifier, such as a serial number.
[0066] In the example message sequence chart 1000, the unique identifier may be programmed into the appliance 102 during an initialization process (operation 1002). The unique identifier may serve as a reference for configuration, maintenance, and tracking and may be physically inscribed on the appliance 102, such as on the rating plate 204. Additionally, the unique identifier may be digitally stored within various programmable components of the appliance 102. For example, the unique identifier may be saved in the storage 404 of the main controller 302, the storage 504 of the heating controller 304, the storage 604 of the memory controller 306, and / or the storage 708 of the user interface 206.
[0067] In the example message sequence chart 1000, the unique identifier for the appliance 102 is also stored at the appliance configuration platform 104 (at operation 1004). For example, the appliance configuration application 808 may write the unique identifier to the data store 810, which serves as a centralized repository for tracking the appliance 102 and its associated configuration data. By maintaining this information in the data store 810, the appliance configuration platform 104 ensures that the unique identifier is consistently accessible throughout the lifecycle of the appliance 102, which may facilitate subsequent maintenance and recovery operations. The data store 810 may function as the source of truth for the system 100, supporting the reliable storage and retrieval of unique identifiers and associated configuration information.
[0068] After the appliance 102 is configured with the unique identifier, the appliance 102 may be shipped from the manufacturer to a distributor, end user, etc., where the appliance 102 may be programmed to its final configuration. For example, in the example message sequence chart 1000, the user device 106-1 can transmit configuration information to the appliance 102 (at operation 1006). For example, the appliance configuration application 908 and / or communications application 910 may establish a communications link with the memory controller 306 via the communications system 108, and the appliance configuration application 908 and / or the communications application 910 may transmit the configuration information to the memory controller 306 (for example, using NFC techniques).
[0069] In various implementations, the user device 106-1 scans the scannable feature 210 to retrieve information embedded within the scannable feature 210. This information may include the unique identifier of the appliance 102, network credentials for establishing a secure connection, and / or a URL directing the user device 106-1 to a configuration portal hosted by the main controller 302. Upon scanning the scannable feature 210, the user device 106-1 may use the embedded data to establish a communications link with the main controller 302 via the communications system 108 and transmit the configuration information to the main controller 302 via the communications link.
[0070] In some examples, the configuration information includes settings, operating instructions, control logic, software updates, firmware updates, and / or other forms of configuration information for the main controller 302, heating controller 304, memory controller 306, user interface 206, communications interface 208, and / or any other programmable components of the appliance 102. Settings may define high-level operational parameters of the heating components 310, such as, for example, fuel type (e.g., natural gas or propane), heating capacity (e.g., BTU input and / or output), and / or other attributes of the heating components 310.
[0071] Control logic may define rules, conditions, and operational parameters governing the interactions between the programmable components of the appliance 102. For example, control logic may regulate the air-to-fuel ratio managed by the heating controller 304, ensuring that the burner assembly operates within safe and efficient thresholds. This logic may also govern parameters such as the firing rate of the burner assembly, the operating rate of the blower, and the flow rate of fuel allowed by the gas valve. Additional control logic may specify ignition timing, combustion air adjustments, and exhaust gas management settings, ensuring coordinated operation of the heating components 310. Beyond combustion, control logic may also include safety protocols, such as shutting down the heating components 310 when abnormal pressure or temperature levels are detected, or calibrating temperature sensors to ensure accurate measurements.
[0072] Software updates may introduce new functionality or optimize existing operations. For example, software updates transmitted to the main controller302 may enhance its ability to coordinate with other programmable components, such as the memory controller 306 or user interface 206. Similarly, updates for the heating controller 304 may improve its control algorithms for the gas valve and blower, facilitating finer adjustments to the firing rate and airflow of the burner assembly, etc.
[0073] Firmware updates may modify the low-level hardware control functionality of the appliance 102. For instance, a firmware update for the memory controller 306 may improve its ability to store and retrieve configuration data, while a firmware update for the communications interface 208 may enhance its compatibility with newer communication protocols within the communications system 108.
[0074] In the example message sequence chart 1000, the appliance 102 may configure its components based on the received configuration information (at operation 1008). For example, the main controller 302 may apply updates or perform initial configuration for software stored in the storage 404 of the main controller 302, the storage 504 of the heating controller 304, the storage 604 of the memory controller 306, the storage 708 of the user interface 206, and / or other programmable components of the appliance 102. These actions may include modifying, replacing, and / or adding operational logic, adjusting parameter settings, or enabling / disabling functionality to align the appliance 102 with its intended configuration.
[0075] In various implementations, the main controller 302 may also apply firmware updates or execute initial configuration for the respective programmable components to enhance low-level hardware control. For example, a firmware update or initial configuration for the heating controller 304 may refine its ability to manage the gas valve and blower, ensuring precise adjustments to fuel flow and blower speed. Similarly, updates or initial configurations for the user interface 206 may introduce improvements to its graphical interface or input handling, while updates or initial configurations for the communications interface 208 may enhance compatibility with newer protocols supported by the communications system 108.
[0076] In some examples, the received configuration information may include detailed control logic or operating parameters. For example, the configuration may specify the firing rate for the burner assembly, the rate at which the blower operates, and the flow rate of fuel managed by the gas valve. These parameters may be used to update or configure the control logic executed by the heating controller 304, ensuring safe and efficient operation of the heating components 310. Additionally, the configuration information may include safety protocols, such as conditions for shutting down the heating components 310 in response to abnormal temperature or pressure readings, or calibration data for temperature sensors to ensure accurate measurements, etc. In some other examples, various instances of available configuration information sets may be stored within one or more of the storage 404, 504, 604, and 708, and the received configuration information may include a selection of a specific one of the available configuration information sets.
[0077] In the example message sequence chart 1000, the user device 106-1 may transmit the unique identifier of the appliance 102 along with the associated configuration information to the appliance configuration platform 104 (at operation 1010). For example, the appliance configuration application 908 and / or communications application 910 may communicate the unique identifier and configuration information to the appliance configuration application 808 via the communications system 108.
[0078] In the example message sequence chart 1000, the configuration information may be associated with the corresponding unique identifier at the appliance configuration platform 104 (at operation 1012). For example, the appliance configuration application 808 may retrieve the unique identifier stored in the data store 810, link the configuration information to the identifier, and store the updated configuration data within the data store 810. Thus, the appliance configuration platform 104 may ensure that the correct or intended configuration of the appliance 102 is maintained in the centralized repository (e.g., data store 810), which may function serves as the source of truth for the system 100. This association may facilitate the efficient tracking and management of configuration data throughout the lifecycle of the appliance 102, including during servicing, maintenance, or component replacement events.
[0079] Following configuration, the appliance 102 may be delivered to its end-use location for installation. For example, the appliance 102 may be integrated into a water system, enabling it to heat water received from the system and distribute the heated water back into the system. During the initial startup process at the installation site, the appliance 102 may perform additional initialization or configuration tasks (as described in detail with reference to the figures) for its programmable components, as necessary.
[0080] Over time, operational issues may arise that require servicing. For instance, one or more components of the appliance 102 may require repair or replacement. In some scenarios, a programmable component—such as the main controller 302, heating controller 304, memory controller 306, user interface 206, and / or communications interface 208—may fail due to physical damage, a loss of connectivity to the communication bus 308, or another malfunction. Additionally or alternatively, operational issues could necessitate replacing one or more programmable components with unconfigured replacement parts or components previously configured for another appliance.
[0081] When a component is replaced or fails, the main controller 302 may detect inconsistencies in the configuration data shared among the programmable components via the communication bus 308. This configuration mismatch may prevent the appliance 102 from functioning correctly or achieving optimal performance. To resolve the issue, the failed or replaced components may require reprogramming. In such cases, a service technician or end user may use a recovery code to restore the appliance 102 to its intended operational state.
[0082] In the example message sequence chart 1000, the appliance 102 may initiate a request for a recovery code (at operation 1014). In various implementations, the main controller 302 generates this request and communicates it through the user interface 206. For instance, the request may be displayed via a graphical user interface (GUI) on the output device 706, such as a display screen, or conveyed using alternative methods, including a predefined sequence of flashing indicator lights or a series of audible notifications. In various implementations, the main controller 302 transmits the recovery code request directly to a user device 106-2 via the communications system 108. This request may inform the user that the appliance 102 requires servicing and that a recovery code should be obtained from the appliance configuration platform 104.
[0083] To retrieve a recovery code from the appliance configuration platform 104, the user may provide the unique identifier associated with the appliance 102. As shown in the example message sequence chart 1000, the user device 106-2 may transmit the unique identifier of the appliance 102 to the appliance configuration platform 104 (at operation 1016). This transmission may be facilitated by the appliance configuration application 908 and / or the communications application 910 operating on the user device 106-2 over the communications system 110. Upon receiving the unique identifier, the appliance configuration platform 104 may process the request. For example, the appliance configuration application 808 may retrieve the configuration data for the appliance 102 from the data store 810 using the unique identifier as a reference. The appliance configuration application 808 may then generates a recovery code based on the retrieved configuration data (at operation 1018).
[0084] FIG. 11 illustrates a recovery code 1102, according to some examples. The recovery code 1102 may serve as a compact and secure representation of the correct configuration of the appliance 102, facilitating the reprogramming of programmable components following servicing or replacement. For example, the recovery code 1102 may include two primary components: a payload 1104 and a validation token 1106 (e.g., following the payload 1104 or before the payload 1104). The payload 1104 may include or encode information essential for restoring the configuration of the components of appliance 102. Depending on the implementation, the payload 1104 may directly include the configuration data of the appliance 102—such as, for example, settings, control logic, firmware parameters, etc.—or reference a predefined configuration stored within the appliance 102, specifying which subset of preprogrammed options should be activated and / or how the programmable components should be configured.
[0085] The validation token 1106 may ensure the integrity, completeness, and / or authenticity of the recovery code 1102. For example, the validation token 1106 may be implemented as a cyclic redundancy check (CRC), which calculates a short, fixed-length binary sequence from the payload 1104. The CRC value allows the main controller 302 to detect errors or corruption in the recovery code by comparing the recalculated value against the received token. In other implementations, the validation token 1106 includes a cryptographic hash, which generates a unique, fixed-length string of characters (known as a hash) from the payload 1104. Even a minor alteration in the payload 1104 results in a completely different hash value, ensuring robust integrity checks. Alternatively, the validation token 1106 may be a digital signature, created using a private cryptographic key associated with the appliance configuration platform 104. When received, the digital signature can be verified using a corresponding public key, ensuring both the integrity of the payload 1104 and its authenticity by confirming that it originated from a trusted source. In various implementations, the recovery code 1102 is encrypted—using, for example, the unique identifier of the appliance 102 or a key that corresponds to one held by the main controller 302—and can be decrypted by the appliance 102.
[0086] Returning to FIG. 10, in the example message sequence chart 1000, the appliance configuration platform 104 may transmit the recovery code 1102 to the user device 106-2 (at operation 1020). For example, the appliance configuration application 808 may deliver the recovery code 1102 to the appliance configuration application 908 and / or the communications application 910 of the user device 106-2 via the communications system 108. Upon receipt, the user may input the recovery code 1102 at the appliance 102 (at operation 1022). In various implementations, the user enters the recovery code 1102 through the input device 704 of the user interface 206, such as a touchscreen or keypad, and the main controller 302 retrieves the recovery code via the communication bus 308. In some examples, the user device 106-2 may transmits the recovery code 1102 directly to the main controller 302 over the communications system 108, facilitating seamless electronic input. In various implementations, the main controller 302 decrypts the recovery code 1102.
[0087] Once the recovery code 1102 is received, the main controller 302 may validate its integrity using the validation token 1106. For example, when the validation token 1106 is implemented as a CRC, the main controller recalculates the CRC value from the payload 1104 and compares it to the received validation token 1106 to ensure no errors or corruption occurred during transmission. When the validation token 1106 includes a cryptographic hash, the main controller 302 may perform a similar calculation, verifying that the hash matches the payload 1104 to detect any alterations. In implementations where the validation token 1106 includes a digital signature, the main controller 302 uses a public cryptographic key to authenticate the recovery code 1102, confirming its origin from the trusted appliance configuration platform 104.
[0088] Following successful validation, the main controller 302 may utilize the payload 1104 to configure the programmable components of the appliance 102. When the payload 1104 includes a direct representation of the configuration data, the main controller 302 applies the encoded settings, such as operating parameters, control logic, or firmware updates, to the corresponding programmable components. Alternatively, when the payload 1104 references a preprogrammed library of configurations stored locally, such as in the storage 404 of the main controller 302, the main controller 302 controller identifies the correct configuration subset specified by the payload and programs the programmable components accordingly. This process may ensure that the programmable components of the appliance 102 are restored to their intended operational state.
[0089] FIGS. 12-15 present a flowchart of a process 1200 illustrating programming logic of the main controller 302, according to some examples. It should be understood that the order of the steps disclosed in process 1200 could vary. Additional steps may also be added to the control sequence and not all of the steps may be required. The process 1200 may begin when the appliance 102 is powered on, which may occur, for instance, by connecting the appliance 102 to an electrical circuit, such as a 120-volt alternating current (AC) circuit. Upon power-up, the electrical system may supply electrical power to the various components of the appliance 102, such as, for example, the main controller 302, heating controller 304, memory controller 306, user interface 206, communications interface 208, communication bus 308, and / or heating components 310.
[0090] In the example process 1200, the main controller 302 may receive data from the programmable components of the appliance 102 (at block 1202). In various implementations, the main controller 302 retrieves this data via the communication bus 308 from components such as the memory controller 306, user interface 206, and / or communications interface 208. Additionally or alternatively, the main controller 302 may receive data from the heating controller 304 through a dedicated communication link. This data can include, for example, the unique identifier associated with the appliance 102, configuration information stored in the respective storage units of these components, status updates regarding their operational states, etc. In various implementations, the configuration data received from each component includes a unique identifier and configuration information.
[0091] In the example process 1200, the main controller 302 may compare the data received from the programmable components of the appliance 102 to reference data stored in its own storage 404 to determine whether the data matches (at block 1204). In response to the main controller 302 determining that all received data matches the stored reference data (“YES” at decision block 1206), the main controller 302 may enter a normal operational mode. For example, the main controller 302 may transmit configuration parameters to the heating controller 304 (at block 1208) via the dedicated communication link. A complete match at decision block 1206 may indicate that all programmable components of the appliance 102 are properly configured, allowing the appliance 102 to continue normal operation (at block 1210).
[0092] To maintain consistent operation, the main controller 302 may periodically re-evaluate data received from the components via the communication bus 308 and / or the dedicated communication link. For example, the main controller 302 may periodically perform checks to determine whether any component has failed, been replaced, or lost connectivity. Thus, the process 1200 may periodically (e.g., after a predetermined period of time has elapsed) loop back to block 1202, where the main controller 302 continues receiving data from the components.
[0093] In response to determining that the data from the components of the appliance 102 does not match the reference data stored in its storage 404 (“NO” at decision block 1206), the main controller 302 may enter an alternate operational mode. For example, the main controller 302 may evaluate whether the current operational cycle corresponds to the initial startup of the appliance 102 (at decision block 1212). A data mismatch at decision block 1206 may indicate that one or more components are unprogrammed, incorrectly programmed, disconnected, or otherwise faulty.
[0094] However, in various implementations, only the memory controller 306 is pre-programmed during the appliance's initial configuration (e.g., by the distributor or end user, as described at operation 1008 in message sequence chart 1000). The main controller 302 completes the programming of the remaining programmable components during the initial startup cycle, ensuring that the appliance 102 is fully configured for operation. Thus, one or more components being unprogrammed during the initial startup may be a normal condition but may necessitate the main controller 302 completing the programming of the components.
[0095] To evaluate whether the current operational cycle is the initial startup, the main controller 302 checks the status of configuration data within its storage 404. In various implementations, the absence of stored configuration data indicates that the appliance 102 is in its initial startup cycle. Alternatively, the main controller 302 may reference a specific flag within its storage 404. This flag may be set during initial configuration and cleared upon the successful completion of the initial startup cycle. When the flag remains uncleared, the main controller 302 determines that the current cycle is the initial startup.
[0096] In response to determining that the current operational cycle corresponds to the initial startup of the appliance 102 (“YES” at decision block 1212), the main controller 302 may initiate an initial startup configuration process. For example, in the process 1200, the main controller 302 evaluates the integrity of the memory controller 306 (at block 1214). This evaluation may involve analyzing the data received from the memory controller 306 to determine whether the configuration information it contains is complete and / or valid.
[0097] In response to the main controller 302 determining that the memory integrity is satisfactory (“YES” at decision block 1216), it may proceed to update the data across the remaining programmable components of the appliance 102 (at block 1218). For instance, the main controller 302 may write the configuration data retrieved from the memory controller 306 to its own storage 404 and transmit the same data to user interface 206, communications interface 208, and / or other relevant components. Each respective electronic processor associated with these components may write the received configuration data to its storage, ensuring consistency across the appliance's subsystems. Once the data update is complete, the process 1200 may return to block 1208, where the main controller 302 continues transmitting the configuration parameters to the heating controller 304 and resumes normal operations.
[0098] In response to determining that the memory integrity does not pass (“NO” at decision block 1216), the main controller 302 may generate a notification indicating the error (at block 1220). This condition may arise when the memory controller 306 was not correctly configured during the initial setup process (e.g., at operation 1008 of the message sequence chart 1000), became corrupted, and / or failed to communicate with the main controller 302 via the communication bus 308. For instance, the main controller 302 may issue a command to the user interface 206 to display an error message on the output device 706. Additionally or alternatively, the main controller 302 may send a command to the communications interface 208 to relay the notification to a connected user device 106-2 via the communication system 108.
[0099] In various implementations, the notification may include a message displayed on a graphical user interface, a specific sequence of flashing indicator lights, a series of audible alerts, etc. The notification may provide details about the nature of the error, such as a corruption in the memory controller 306, a communication failure with the main controller 302, an unconfigured state, etc. The notification may also indicate that further action is required, such as contacting the appliance configuration platform 104 for additional support.
[0100] In scenarios where the memory controller 306 or another component has failed, repairs may be necessary before proceeding. For example, a service technician or end user may need to replace the memory controller 306 or other malfunctioning components. Once the required repairs are complete, the main controller 302 can resume the configuration process by referencing the stored configuration data or a recovery code provided by the appliance configuration platform 104 to restore the appliance 102 to its intended operational state.
[0101] Once the memory controller 306 or another component has been installed, the process 1200 may proceed. In the example process 1200, the main controller 302 may generate a prompt for a recovery code (at block 1222). To convey this prompt, the main controller 302 may issue a command to the user interface 206, which then outputs the prompt via the output device 706. Additionally or alternatively, the main controller 302 may transmit a command to the communications interface 208, which may transmit the prompt to the user device 106-2 via the communication system 108.
[0102] The prompt may provide instructions for obtaining a recovery code from the appliance configuration platform 104. In various implementations, the user may retrieve the recovery code using an automated process, such as through a dedicated application or web portal, as previously described. In some examples, the prompt may include instructions for requesting the recovery code by contacting the manufacturer's customer service or support center.
[0103] Upon receiving a recovery code request, the appliance configuration platform 104 may request the unique identifier of the appliance 102 from the user or user device 106-2. As detailed earlier, this unique identifier may be programmed into the programmable components of the appliance 102 and may also be found on physical labels, such as the rating plate 204, or any other nameplates affixed to the appliance 102. In various implementations, the main controller 302 can command the user interface 206 to display or otherwise output the unique identifier via the output device 706, ensuring it is easily accessible to the user.
[0104] Once the unique identifier is provided to the appliance configuration platform 104, the appliance configuration platform 104 may generate or retrieve the configuration information specific to the appliance 102. This configuration information may be returned to the user as a recovery code (e.g., recovery code 1102), allowing the appliance 102 to restore its intended configuration and functionality.
[0105] In the example process 1200, the main controller 302 may receive the recovery code 1102 as an input (at block 1224). After obtaining the recovery code 1102, the user may provide it to the appliance 102 through various input mechanisms. For example, the user may enter the recovery code 1102 via the input device 704 of the user interface 206. The user interface 206 may then transmit the recovery code 1102 to the main controller 302 over the communication bus 308. Additionally or alternatively, the user device 106-2 may transmit the recovery code 1102 directly to the communications interface 208 via the communications system 108. In such implementations, the communications interface 208 forwards the recovery code 1102 to the main controller 302 using the communication bus 308.
[0106] Once the main controller 302 receives the recovery code 1102, it may validate the integrity of the recovery code 1102 to ensure accuracy and authenticity (at block 1226). This validation process may involve verifying the integrity of the validation token 1106, which is included in the recovery code 1102, to confirm that it has not been corrupted during transmission or incorrectly entered by the user. For example, the main controller 302 may recalculate the cyclic redundancy check (CRC) value embedded in the validation token 1106 and compare the recalculated value against the received value to detect transmission errors. In other implementations, the main controller 302 may calculate a cryptographic hash of the payload 1104 and validate it against the hash stored in the validation token 1106. In examples where the validation token 1106 includes a digital signature, the main controller 302 may authenticate the signature using a public cryptographic key, ensuring the recovery code 1102 originates from the trusted appliance configuration platform 104 and has not been altered.
[0107] Once the recovery code 1102 successfully passes the integrity checks (as applicable to the specific implementation), the main controller 302 may begin reconfiguring the appliance 102 in accordance with the encoded configuration data. In the example process 1200, in response to determining that the recovery code 1102 passes the integrity checks and is valid (“YES” at decision block 1228), the main controller 302 updates the configuration data across the programmable components of the appliance 102 to restore the original intended configuration of the appliance 102 (at block 1230). This process may include processing the payload 1104 of the recovery code 1102, which may contain either direct configuration data or a reference to a preprogrammed configuration stored within the appliance 102.
[0108] For recovery codes containing direct configuration data, the main controller 302 distributes the specific settings, operational parameters, control logic, firmware updates, and / or other encoded instructions to any or all programmable components, including itself. The main controller 302 writes the configuration data to its own storage 404 and / or transmits the data to other components, such as the memory controller 306, heating controller 304, user interface 206, and / or communications interface 208. Each programmable component may write the received data to its respective storage (e.g., storage 604, 504, or 708, etc.), thereby aligning its configuration with the original specifications of the appliance 102.
[0109] For recovery codes referencing a predefined configuration stored locally in the appliance 102, the main controller 302 identifies the appropriate configuration subset stored in its own storage 404 or retrieved from the memory controller 306 referenced by the recovery code 1102. Once identified, the main controller 302 programs its own storage 404 with the retrieved configuration and / or distributes the data to other programmable components to ensure configuration alignment across the appliance 102. Each component may update its configuration settings and operational parameters accordingly.
[0110] In response to determining that the recovery code 1102 does not pass the integrity checks and is deemed invalid (“NO” at decision block 1228), the main controller 302 may again generate a notification at block 1220. This notification may alert the that the recovery code is invalid, incorrectly entered, corrupted, etc.
[0111] By leveraging this recovery process, the main controller 302 may ensure synchronization and consistency of configuration data across all programmable components within the appliance 102. This approach may allow the appliance 102 to autonomously reconfigure its components while maintaining adherence to its original design specifications. Through the controlled distribution of recovery code 1102, the process prevents duplication or cloning of the appliance, ensuring the integrity and uniqueness of its configuration.
[0112] Furthermore, the recovery process facilitates the restoration of the appliance 102 to full operational status following service or maintenance events without requiring the delivery or installation of pre-programmed memory devices or other specialized replacement components. By streamlining servicing and reducing downtime, this approach may minimize logistical complexity and supports a more efficient and reliable maintenance process.
[0113] Returning to decision block 1212, in response to the main controller 302 determining that the current operational cycle is not the initial startup of the appliance 102 (“NO” at decision block 1212), the main controller 302 may evaluate whether a predetermined threshold number of components have matching data sets (at decision block 1232). The predetermined threshold may vary by implementation but may generally require a plurality of components to exhibit consistent or matching data. In some examples, the threshold is defined as a majority of components, such as about ½, ⅔, ¾, ⅘, 9 / 10, etc., of the total number of programmable components.
[0114] In response to the threshold not being met (“NO” at decision block 1232), the main controller 302 may generate a notification at block 1220 and enter a recovery mode to initiate a recovery process. This situation may arise due to significant data corruption across multiple components or the simultaneous replacement of several components during servicing of the appliance 102. In such scenarios, the main controller 302 may be unable to confidently identify the correct configuration from the available data and thus cannot proceed with automatic reconfiguration based on existing component data. The recovery process, leveraging the recovery code 1102, may ensure that the appliance 102 is restored to its original configuration, addressing the error condition and re-establishing operational consistency across all components.
[0115] In response to the threshold being met (“YES” at decision block 1232), the main controller302 may enter an automatic recovery mode to initiate an automatic recovery process using existing configuration data from operational components, beginning at decision block 1234. In the example process 1200, the main controller 302 determines whether the appliance 102 is currently running (at decision block 1234). A running state of the appliance 102 may indicate that the configuration of the components had been verified as correct at an earlier point during the current power cycle.
[0116] Under these conditions, the main controller 302 may proceed under the assumption that the matching configuration data represents the correct configuration and that one or more components have since become damaged, corrupted, or lost communication. Thus, automatic reconfiguration using the matching data may be appropriate. Accordingly, upon determining that the appliance 102 is running (“YES” at decision block 1234), the main controller 302 may generate a notification to provide a description of the error and / or indicate that the appliance 102 will attempt to automatically correct the error (at block 1236).
[0117] The main controller 302 may issue this notification through the user interface 206 and the communications interface 208. In various implementations, the main controller 302 sends a command to the user interface 206 to display a message on the output device 706, such as a screen or indicator lights, explaining the nature of the error and / or outlining the corrective action being attempted. Additionally, the main controller 302 may instruct the communications interface 208 to transmit the notification to a connected user device 106 via the communications system 108. This transmitted notification may include details about the error, the automatic recovery process being initiated, etc.
[0118] In the example process 1200, the main controller 302 may update the configuration data of non-matching components to align with the configuration data of matching components (at block 1238). This update process may include retrieving the verified configuration data from the matching components and transmitting it to the non-matching components via the communication bus 308 or dedicated communication links, such as those connecting the main controller 302 to the heating controller 304. The main controller 302 may coordinate these updates to re-establish consistent configurations across all components. For example, the data received at block 1202 may indicate that a plurality or majority of components (such as, for example, the main controller 302, memory controller 306, and user interface 206) have matching configuration data, but the configuration data from the memory controller 306 does not match the other components. The main controller 302 may then configure the non-matching component (such as, for example, the memory controller 306) to match the configuration data of the matching components.
[0119] In response to situations where automatic reconfiguration is not feasible—such as when components are damaged or communication with the components is disrupted due to a failure of the communication bus 308 or a dedicated communication link—the main controller 302 may allow the appliance 102 to continue operating under its current configuration. This operational state may be based on the assumption that the configuration was verified as correct at an earlier point in the current power cycle, prior to the detection of mismatched components. The appliance 102 may, therefore, continue its normal operation (at block 1208), even when certain non-matching components cannot be updated with the correct configuration data. This approach ensures that the appliance 102 remains functional while limiting disruptions caused by damaged or disconnected components.
[0120] In response to the main controller 302 determining that the appliance 102 is not operating (“NO” at decision block 1234), as may occur following a power cycling of the appliance 102, the main controller 302 may generate a prompt for the unique identifier of the appliance 102 (at block 1240). To convey this prompt, the main controller 302 may issue a command to the user interface 206, causing the output device 706 (e.g., a display screen or indicator lights) to present a message requesting the unique identifier. Additionally or alternatively, the main controller 302 may transmit a notification to the communications interface 208, which forwards the prompt to a connected user device 106-2 via the communications system 108. In various implementations, the notification includes instructions for locating the unique identifier, such as directing the user to consult the rating plate 204 or another decal affixed to the appliance 102.
[0121] In the example process 1200, the main controller 302 may receive the input unique identifier. For example, the unique identifier may be entered through the input device 704 of the user interface 206, such as a touchscreen or keypad, where the main controller 302 retrieves it via the communication bus 308. In some examples, the user transmits the unique identifier to the communications interface 208 using the user device 106-2 over the communications system 108. The communications interface 208 may forward the unique identifier to the main controller 302 via the communication bus 308. After the main controller 302 receives the unique identifier (at block 1242), it may compare the received unique identifier to the unique identifier portions of the matching configuration data from the matching components (at block 1244).
[0122] In response to the main controller 302 determining that the input unique identifier matches the unique identifier portions of the configuration data from the matching components (“YES” at decision block 1246), the main controller 302 may determine that the configuration data from the matching components represents the correct configuration for the appliance 102. Consequently, the main controller 302 may update the configuration data of non-matching components to align with the configuration data of the matching components (at block 1238). Following the update, the appliance 102 may resume normal operation (at block 1208). This approach may allow the main controller 302 to autonomously reconfigure the appliance 102 and restore correct operation without requiring the user to retrieve a recovery code from the appliance configuration platform 104.
[0123] In response to the main controller 302 determining that the input unique identifier does not match the unique identifier portions of the configuration data from the matching components (“NO” at decision block 1246), the main controller 302 may generate a notification (at block 1220). This notification may include an error message indicating that service of the appliance 102 may be required. Such a scenario may arise, for instance, when components from another appliance are transferred to the appliance 102, causing a mismatch between the unique identifier of the transferred components and the unique identifier of the appliance 102. This mismatch can result in an undesirable operating condition, such as incompatibility between the configuration of the transferred components and the configuration of the matching components.
[0124] To resolve this condition, the appliance 102 may request a recovery code corresponding to its unique identifier, which the main controller 302 can use to update all components with the correct configuration. In various implementations, the example process 1200 may iterate through the prompt for the unique identifier and the matching loop (e.g., block 1240 through block 1246) one or more additional times to address potential user input errors when entering the unique identifier.ADDITIONAL ENUMERATED EXAMPLES
[0125] The following paragraphs provide examples of systems, methods, and devices implemented in accordance with this specification.Example 1
[0126] An appliance, comprising: a main controller; and one or more programmable components; wherein the main controller is configured to: receive data from each of one or more programmable components, the data indicative of a configuration of each of the one or more programmable components, compare the received data to determine whether the configuration of each of the one or more programmable components matches a configuration of the main controller, and in response to determining that the configuration of each of the one or more programmable components does not match the configuration of the main controller, enter an alternate operational mode.Example 2
[0127] The appliance of example 1, wherein the main controller is further configured to: in response to determining that the configuration of each of the one or more programmable components matches the configuration of the main controller, enter a normal operational mode.Example 3
[0128] The appliance of example 1, wherein: the one or more programmable components include a memory; and the main controller is further configured to: in the alternate operational mode, determine whether a current operational cycle of the appliance is an initial operational cycle, and in response to determining that the current operational cycle of the appliance is the initial operational cycle, update the configuration of each of the one or more programmable components based on a configuration of the memory.Example 4
[0129] The appliance of example 1, wherein the main controller is further configured to: in the alternate operational mode, determine whether a number of matching configurations of one or more programmable components and the main controller crosses a threshold; and in response to determining that the number of matching configurations crosses the threshold, enter an automatic recovery mode.Example 5
[0130] The appliance of example 4, wherein the main controller is further configured to: in the automatic recovery mode, determine whether the appliance is running; and in response to determining that the appliance is running, update a configuration of a non-matching programmable component based on the matching configuration.Example 6
[0131] The appliance of example 5, wherein the main controller is further configured to: in response to determining that the appliance is not running, enter an assisted recovery mode.Example 7
[0132] The appliance of example 6, wherein the main controller is further configured to: in response to determining that the number of matching configurations does not cross the threshold, enter the assisted recovery mode.Example 8
[0133] The appliance of example 7, wherein the main controller is further configured to: in the assisted recovery mode, receive a recovery code, the recovery code including a payload.Example 9
[0134] The appliance of example 8, wherein: the recovery code includes a validation token; and the main controller is further configured to verify an integrity of the payload based on the validation token.Example 10
[0135] The appliance of example 8, wherein: the one or more programmable components include a memory; and the main controller is further configured to: retrieve a predefined configuration from the memory based on the payload, and program a non-matching programmable component based on the predefined configuration.Example 11
[0136] The appliance of example 8, wherein the main controller is further configured to program a non-matching programmable component based on the payload.Example 12
[0137] The appliance of example 11, wherein the payload includes information defining a programmable component configuration.Example 13
[0138] The appliance of example 8, wherein: the one or more programmable components include a user interface; and the main controller is configured to receive the recovery code from the user interface.Example 14
[0139] The appliance of example 8, further comprising: a communications interface configured to receive a recovery code from a user device; wherein the main controller is configured to receive the recovery code from the communications interface.Example 15
[0140] A method, comprising: receiving, at a main controller of an appliance, data from each of one or more programmable components of the appliance, the data indicative of a configuration of each of the one or more programmable components; comparing, at the main controller, the received data to determine whether the configuration of each of the one or more programmable components matches a configuration of the main controller; and in response to determining that the configuration of each of the one or more programmable components does not match the configuration of the main controller, entering an alternate operational mode at the main controller.Example 16
[0141] The method of example 15, further comprising: in response to determining that the configuration of each of the one or more programmable components matches the configuration of the main controller, entering a normal operational mode at the main controller.Example 17
[0142] The method of example 15, further comprising: in the alternate operational mode, determining, at the main controller, whether a current operational cycle of the appliance is an initial operational cycle; and in response to determining that the current operational cycle is the initial operational cycle, updating the configuration of each of the one or more programmable components based on a configuration of a memory of the respective programmable component.Example 18
[0143] The method of example 15, further comprising: in the alternate operational mode, determining, at the main controller, whether a number of matching configurations of one or more programmable components and the main controller crosses a threshold; and in response to determining that the number of matching configurations crosses the threshold, entering an automatic recovery mode at the main controller.Example 19
[0144] The method of example 18, further comprising: in the automatic recovery mode, determining, at the main controller, whether the appliance is running; and in response to determining that the appliance is running, updating a configuration of a non-matching programmable component based on the matching configuration.Example 20
[0145] The method of example 19, further comprising: in response to determining that the appliance is not running, entering an assisted recovery mode at the main controller.Example 21
[0146] The method of example 20, further comprising: in response to determining that the number of matching configurations does not cross the threshold, entering the assisted recovery mode at the main controller.Example 22
[0147] The method of example 21, further comprising: in the assisted recovery mode, receiving a recovery code at the main controller, the recovery code including a payload.Example 23
[0148] The method of example 22, further comprising: verifying, at the main controller, an integrity of the payload based on a validation token included in the recovery code.Example 24
[0149] The method of example 22, further comprising: retrieving, via the main controller, a predefined configuration from a memory of the one or more programmable components based on the payload; and programming, via the main controller, a non-matching programmable component based on the predefined configuration.Example 25
[0150] The method of example 22, further comprising: programming, via the main controller, a non-matching programmable component based on the payload.Example 26
[0151] The method of example 25, wherein the payload includes information defining a programmable component configuration.Example 27
[0152] The method of example 22, further comprising: receiving, at the main controller, a recovery code from a user interface; wherein the one or more programmable components includes the user interface.Example 28
[0153] The method of example 22, further comprising: receiving, at the main controller, the recovery code from a communications interface; wherein the communications interface is configured to receive a recovery code from a user device.Example 29
[0154] A system, comprising: an appliance; non-transitory computer-readable media storing instructions; and an electronic processor configured to execute the instructions to: receive a unique identifier associated with an appliance, store the unique identifier at a data store, receive configuration information associated with the appliance, associate the configuration information with the unique identifier, store the configuration information at the data store, and in response to receiving a request including an indication of the unique identifier, generate a recovery code based on the configuration information associated with the unique identifier; wherein a main controller of the appliance is configured to program a programmable component of the appliance based on the recovery code.Example 30
[0155] The system of example 29, wherein the recovery code includes a payload.Example 31
[0156] The system of example 30, wherein: the recovery code includes a validation token; and the main controller of the appliance is configured to verify an integrity of the payload based on the validation token.Example 32
[0157] The system of example 30, wherein the main controller of the appliance is configured to: retrieve a predefined configuration from a memory based on the payload; and program a programmable component of the appliance based on the predefined configuration.Example 33
[0158] The system of example 30, wherein the main controller of the appliance is configured to program a programmable component of the appliance based on the payload.Example 34
[0159] The system of example 33, wherein the payload includes information defining a programmable component configuration.Example 35
[0160] A method, comprising: receiving, at an appliance configuration platform, a unique identifier associated with an appliance; storing, at the appliance configuration platform, the unique identifier at a data store; receiving, at the appliance configuration platform, the configuration information associated with the appliance; associating, at the appliance configuration platform, the configuration information with the unique identifier; storing, at the appliance configuration platform, the configuration information at the data store; in response to receiving a request including an indication of the unique identifier, generating, at the appliance configuration platform, a recovery code based on the configuration information associated with the unique identifier; and programming, at a main controller of the appliance, a programmable component of the appliance based on the recovery code.Example 36
[0161] The method of example 35, wherein the recovery code includes a payload.Example 37
[0162] The method of example 36, further comprising: verifying, at the main controller of the appliance, an integrity of the payload based on a validation token included in the recovery code.Example 38
[0163] The method of example 36, further comprising: retrieving, at the main controller of the appliance, a predefined configuration from a memory based on the payload; and programming, via the main controller of the appliance, a programmable component of the appliance based on the predefined configuration.Example 39
[0164] The method of example 36, further comprising: programming, via the main controller of the appliance, a programmable component of the appliance based on the payload.Example 40
[0165] The method of example 39, wherein the payload includes information defining a programmable component configuration.
[0166] The foregoing description is merely illustrative in nature and does not limit the scope of the disclosure or its applications. The broad teachings of the disclosure may be implemented in many different ways. While the disclosure includes some particular examples, other modifications will become apparent upon a study of the drawings, the text of this specification, and the following claims. In the written description and the claims, one or more processes within any given method may be executed in a different order—or processes may be executed concurrently or in combination with each other—without altering the principles of this disclosure. Similarly, instructions stored in a non-transitory computer-readable medium may be executed in a different order—or concurrently—without altering the principles of this disclosure. Unless otherwise indicated, the numbering or other labeling of instructions or method steps is done for convenient reference and does not necessarily indicate a fixed sequencing or ordering.
[0167] It should also be noted that a plurality of hardware and software-based devices, as well as a plurality of different structural components may be utilized in various implementations. Aspects, features, and instances may include hardware, software, and electronic components or modules that, for purposes of discussion, may be illustrated and described as if the majority of the components were implemented solely in hardware. However, one of ordinary skill in the art, and based on a reading of this detailed description, would recognize that, in at least one instance, the electronic based aspects of the invention may be implemented in software (for example, stored on non-transitory computer-readable medium) executable by one or more processors. As a consequence, it should be noted that a plurality of hardware and software-based devices, as well as a plurality of different structural components may be utilized to implement the invention. For example, “control units” and “controllers” described in the specification can include one or more electronic processors, one or more memories including a non-transitory computer-readable medium, one or more input / output interfaces, and various connections (for example, a system bus) connecting the components.
[0168] Unless the context of their usage unambiguously indicates otherwise, the articles “a,”“an,” and “the” should not be interpreted to mean “only one.” Rather, these articles should be interpreted to mean “at least one” or “one or more.” Likewise, when the terms “the” or “said” are used to refer to a noun previously introduced by the indefinite article “a” or “an,” the terms “the” or “said” should similarly be interpreted to mean “at least one” or “one or more” unless the context of their usage unambiguously indicates otherwise.
[0169] It should also be understood that although certain drawings illustrate hardware and software located within particular devices, these depictions are for illustrative purposes only. In some embodiments, the illustrated components may be combined or divided into separate software, firmware, and / or hardware. For example, instead of being located within and performed by a single electronic processor, logic and processing may be distributed among multiple electronic processors. Regardless of how they are combined or divided, hardware and software components may be located on the same computing device or may be distributed among different computing devices connected by one or more networks or other suitable connections or links.
[0170] Thus, in the claims, if an apparatus or system is claimed, for example, as including an electronic processor or other element configured in a certain manner, for example, to make multiple determinations, the claim or claim element should be interpreted as meaning one or more electronic processors (or other element) where any one of the one or more electronic processors (or other element) is configured as claimed, for example, to make some or all of the multiple determinations collectively. To reiterate, those electronic processors and processing may be distributed.
[0171] Spatial and functional relationships between elements—such as modules—are described using terms such as (but not limited to) “connected,”“engaged,”“interfaced,” and / or “coupled.” Unless explicitly described as being “direct,” relationships between elements may be direct or include intervening elements. The phrase “at least one of A, B, and C” should be construed to indicate a logical relationship (A OR B OR C), where OR is a non-exclusive logical OR, and should not be construed to mean “at least one of A, at least one of B, and at least one of C.” The term “set” does not necessarily exclude the empty set. For example, the term “set” may have zero elements. The term “subset” does not necessarily require a proper subset. For example, a “subset” of set A may be coextensive with set A, or include elements of set A. Furthermore, the term “subset” does not necessarily exclude the empty set.
[0172] In the figures, the directions of arrows generally demonstrate the flow of information—such as data or instructions. The direction of an arrow does not imply that information is not being transmitted in the reverse direction. For example, when information is sent from a first element to a second element, the arrow may point from the first element to the second element. However, the second element may send requests for data to the first element, and / or acknowledgements of receipt of information to the first element. Furthermore, while the figures illustrate a number of components and / or steps, any one or more of the components and / or steps may be omitted or duplicated, as suitable for the application and setting.
[0173] Additionally, operations (such as processes, decisions, inputs, outputs, actions, messages, interactions, events, and / or any other operations) shown in the flowcharts and / or message sequence charts may be illustrated once each and in a particular order in the drawings. However, in various implementations, the operations may be reordered and / or repeated as may be suitable. In some examples, different operations may be performed in parallel, as may be appropriate.
[0174] The term computer-readable medium does not encompass transitory electrical or electromagnetic signals or electromagnetic signals propagating through a medium—such as on an electromagnetic carrier wave. The term “computer-readable medium” is considered tangible and non-transitory. The functional blocks, flowchart elements, and message sequence charts described above serve as software specifications that can be translated into computer programs by the routine work of a skilled technician or programmer.
Claims
1. An appliance, comprising:a main controller; andone or more programmable components;wherein the main controller is configured to:receive data from each of one or more programmable components, the data indicative of a configuration of each of the one or more programmable components,compare the received data to determine whether the configuration of each of the one or more programmable components matches a configuration of the main controller, andin response to determining that the configuration of each of the one or more programmable components does not match the configuration of the main controller, enter an alternate operational mode.
2. The appliance of claim 1, wherein the main controller is further configured to:in response to determining that the configuration of each of the one or more programmable components matches the configuration of the main controller, enter a normal operational mode.
3. The appliance of claim 1, wherein:the one or more programmable components include a memory; andthe main controller is further configured to:in the alternate operational mode, determine whether a current operational cycle of the appliance is an initial operational cycle, andin response to determining that the current operational cycle of the appliance is the initial operational cycle, update the configuration of each of the one or more programmable components based on a configuration of the memory.
4. The appliance of claim 1, wherein the main controller is further configured to:in the alternate operational mode, determine whether a number of matching configurations of one or more programmable components and the main controller crosses a threshold; andin response to determining that the number of matching configurations crosses the threshold, enter an automatic recovery mode.
5. The appliance of claim 4, wherein the main controller is further configured to:in the automatic recovery mode, determine whether the appliance is running; andin response to determining that the appliance is running, update a configuration of a non-matching programmable component based on the matching configuration.
6. The appliance of claim 5, wherein the main controller is further configured to:in response to determining that the appliance is not running, enter an assisted recovery mode.
7. The appliance of claim 6, wherein the main controller is further configured to:in response to determining that the number of matching configurations does not cross the threshold, enter the assisted recovery mode.
8. The appliance of claim 7, wherein the main controller is further configured to:in the assisted recovery mode, receive a recovery code, the recovery code including a payload.
9. The appliance of claim 8, wherein:the recovery code includes a validation token; andthe main controller is further configured to verify an integrity of the payload based on the validation token.
10. The appliance of claim 8, wherein:the one or more programmable components include a memory; andthe main controller is further configured to:retrieve a predefined configuration from the memory based on the payload, andprogram a non-matching programmable component based on the predefined configuration.
11. The appliance of claim 8, wherein the main controller is further configured to program a non-matching programmable component based on the payload.
12. The appliance of claim 11, wherein the payload includes information defining a programmable component configuration.
13. The appliance of claim 8, wherein:the one or more programmable components include a user interface; andthe main controller is configured to receive the recovery code from the user interface.
14. The appliance of claim 8, further comprising:a communications interface configured to receive a recovery code from a user device;wherein the main controller is configured to receive the recovery code from the communications interface.
15. A system, comprising:an appliance;non-transitory computer-readable media storing instructions; andan electronic processor configured to execute the instructions to:receive a unique identifier associated with an appliance,store the unique identifier at a data store,receive configuration information associated with the appliance,associate the configuration information with the unique identifier,store the configuration information at the data store, andin response to receiving a request including an indication of the unique identifier, generate a recovery code based on the configuration information associated with the unique identifier;wherein a main controller of the appliance is configured to program a programmable component of the appliance based on the recovery code.
16. The system of claim 15, wherein the recovery code includes a payload.
17. The system of claim 16, wherein:the recovery code includes a validation token; andthe main controller of the appliance is configured to verify an integrity of the payload based on the validation token.
18. The system of claim 16, wherein the main controller of the appliance is configured to:retrieve a predefined configuration from a memory based on the payload; andprogram a programmable component of the appliance based on the predefined configuration.
19. The system of claim 16, wherein the main controller of the appliance is configured to program a programmable component of the appliance based on the payload.
20. The system of claim 19, wherein the payload includes information defining a programmable component configuration.