A secure system for automated control of devices
A decentralized smart device control system with multi-layer authentication and peer-to-peer redundancy addresses network congestion and security vulnerabilities, ensuring reliable operation and scalability in diverse environments.
Patent Information
- Application Number
- PCT/IN2025/051400
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-30
- Filing Date
- 2025-08-30
- Publication Date
- 2026-03-05
AI Technical Summary
Existing smart device control systems face limitations such as network congestion, instability, security vulnerabilities, and single-point failures, leading to inefficiencies and potential system failures, particularly in environments with intermittent connectivity.
A decentralized, modular control system with a master control unit and zone control units that utilize multi-layer authentication, peer-to-peer redundancy, and local data storage to ensure secure, reliable operation with or without internet connectivity, featuring GSM/OTP verification and hardware token encryption.
The system provides robust, scalable, and secure control of multiple devices, maintaining operation during network outages and reducing reliance on constant internet connectivity, with enhanced security and scalability across various environments.
Smart Images

Figure IN2025051400_05032026_PF_FP_ABST
Abstract
Description
[0001] “A SECURE SYSTEM FOR AUTOMATED CONTROL OF DEVICES”
[0002] FIELD OF THE INVENTION:
[0003] The present invention relates to automated control of electrical and electronic devices, and more particularly to secure decentralised automation systems with advanced control capabilities.
[0004] BACKGROUND OF THE INVENTION:
[0005] Nowadays, smart devices are becoming increasingly popular. With advancements in the Internet of Things, the use of smart devices has continuously grown. Smart control of these devices allows users to manage their equipment and instruments locally and remotely. Generally, current smart systems adopt a single control mode. Users configure these control systems and manage smart device settings using mobile terminals. In these systems, multiple devices are connected to an internet router and communicate with their cloud servers via internet to execute local user-generated commands.
[0006] However, as the number of smart devices in an intelligent domestic system increases, the router becomes overburdened. This leads to limitations in communication range, increased instability of internet connections, and overall inefficiency. Unstable internet connections further complicate device operation, making the user experience cumbersome and inefficient. Additionally, these systems have inherent security vulnerabilities and reduced scalability.
[0007] The Chinese Patent Application CN105577495A to Zhang Na teaches a control method and device for smart home devices. In this system, each device is instructed by setting commands generated according to the identifiers and the target working states of the smart devices to achieve corresponding target working states. The generated setting commands are simultaneously sent to the corresponding devices, enabling remote control of the equipment. However, when a user needs to use a particular device, they must identify it from a list of devices, which can lead to controlling the wrong device. This makes operating the system and devices complicated and prone to user errors.
[0008] The United States Patent US10119714B2 to Waseem Amer teaches controlling IR-enabled appliances via networked device. The system controls a plurality of appliances. However, limitations of the system in automated controlling for internet unavailability or the central server failure becomes problematics.
[0009] The Chinese Patent Application CN 103744411 A to Xu Xiaoqing and others describes a smart controller with central learning logic and appliance control. The controller includes protocol with centralized control on the remote server. The controller relies on a single controller for decision making. However, secure remote access without reliance on cloud systems is not described. Hence, intelligent local and offline operable arbitration system is required.
[0010] Traditionally, the smart systems are architectured around a single controller or central hub, that becomes a single point of failure in the event of hardware malfunction, connectivity loss, or cyberattack. If the internet is unavailable or the central server fails, the entire automation framework often becomes non-functional, leaves the user without control over essential systems like lighting, HVAC, safety alarms, or industrial actuators. In said smart system, a single controller referred to as a central hub is employed to manage all device communications and cloud synchronization. In the situation of the hub malfunctions or the internet becomes unstable, the entire automation ecosystem, including essential services like lighting, HVAC, or security systems, becomes non-functional. This limitation is observed across Wi-Fi, or similar mesh protocols for coordinating multiple smart devices. Also, creates the risk of unauthorized access, especially in sensitive or mission-critical environments.
[0011] Moreover, these architectures frequently overburden the local router, as numerous devices attempt to maintain cloud sessions, leading to network congestion. Communication latency, especially for time-critical commands, is further exacerbated when commands must be routed through remote servers even for local control. These shortcomings are particularly problematic in real-world scenarios such as large homes, remote industrial setups, medical or similar installations or agricultural installations with intermittent connectivity.
[0012] Additionally, the reliance on cloud-based user authentication exposes the system to external hacking threats, data leaks, and privacy violations, particularly in sensitive environments such as medical facilities, defense sites, or critical industrial infrastructure. However, said systems rarely offer adequate offline functionality, and fail to provide secure fallback control methods in remote or low- connectivity areas.
[0013] Notably, prior systems fail to create a peer-to-peer redundancy in a local zone. In such systems, failure of a single controller often cascades to complete system failure, however, a distributed multilayer peer-to-peer based redundant system allows zones to autonomously recover before escalating the control to a central hub, a second layer of redundancy and reduces the chances of a complete failure of the system.
[0014] The control systems disclosed in the prior art includes prototype-level tools and centralized architectures without addressing critical aspects of system resilience, user privacy, or decentralized intelligence. Hence, a modular, decentralized, and privacy-first smart device control ecosystem that operates intelligently with or without cloud connectivity is required.
[0015] Accordingly, there is a need of a secure system for automated control of devices that enhances security by isolating and pre authentication of internet communication to a single master controller in an environment with improved scalability. Further, there is a need of the secure system that provides robust and scalable control, and efficient management of multiple smart devices in home, office or industrial environments or within a local network of devices.
[0016] SUMMARY OF THE INVENTION:
[0017] The present invention discloses a secure and automated system for controlling devices for continuous, reliable, and secure operation in a wide variety of environments, including residential, commercial, industrial, agricultural, and critical infrastructure applications. The system includes a master control unit comprising a master controller, a multi-layer authenticator, and a master communication module. The master control unit receives control commands from one or more input interfaces or from decentralized control units. The master control unit authenticates the commands using at least two different authentication mechanisms in a normal operating mode and coordinates the decentralized control units and output devices in a failsafe operating mode. The master communication module isolates internet access to the master control unit to reduce the risk of unauthorized access to the decentralized zone control units.
[0018] All device control logs, UIDs, and user data remains stored locally in the master control unit and zone control units, with external synchronization being optional and user-initiated through the master control unit. The master control unit and zone control unit further include a local logic edge engine, that executes stored automation rules and scene profiles, routines without the need of internet connectivity.
[0019] The multi-layer authentication system incorporates GSM or one-time password (OTP) verification, cloud token validation, and hardware token generation using embedded encryption, thereby providing robust access control for both local and remote operations. The system further comprises a plurality of the control units, each associated with a respective control zone.
[0020] Each decentralized zone control unit also incorporates a primary controller configured to process input commands, generate output trigger signals, and transmit the signals to output devices in the corresponding zone. Each decentralized control unit stores a zone-specific device registry and operates autonomously when disconnected from the master control unit. Each decentralized control unit acts as a temporary master controller in the failure status of the master control unit, thereby maintaining continuity of automation operations.
[0021] Each control unit also incorporates a failover logic module configured to transfer control to another decentralized control unit in a redundancy mode or to the master control unit in the fail-safe mode, in the event of a fault, ensuring that device control is not interrupted by localized failures. The failover logic module of a decentralized zone control unit reassigns control to a peer zone control unit within the same control zone by transfer of synchronization beat prior to escalation to the master control unit.
[0022] An input control unit is configured to interface with a wide variety of input sources, including physical sensors, digital interface devices, mobile applications, remote control devices, and voice-controlled interfaces. The cloud server integrates with third-party voice assistants or application programming interfaces (APIs) for remote control of devices.
[0023] The input control unit encrypts input data before transmission to either the master control unit or a decentralized control unit, thereby enhancing data integrity and security. Physical sensors may include motion, temperature, light, vibration, gas, smoke, door, rain, or CO2 sensors, while digital interfaces may include touch panels, push buttons, keypads, rotary encoders, RF or IR remotes, gesture sensors, RFID readers, fingerprint sensors, emergency buttons, NFC tags, and display modules.
[0024] An output control unit is configured to receive encrypted control signals, decrypt them, validate their authenticity, and actuate corresponding output devices. Output devices may include lighting equipment, HVAC systems, motors, actuators, curtain controls, geysers, or infrared transmitters. The output control unit may also feature a load monitoring module to measure energy parameters such as voltage, current, and power consumption, and to log these for performance tracking or energy management.
[0025] The system communicates via a communication network including at least one of a proprietary wireless protocol, Bluetooth, Wi-Fi, Zigbee, GSM, or a wired connection, or combinations thereof. A key feature of the invention is its capability to operate seamlessly in both internet-connected and offline modes.
[0026] In the connected mode, the system may integrate with cloud services for remote monitoring, data backup, and integration with third-party APIs or voice assistants. In the offline mode, the system continues to operate autonomously using stored rules and scene profiles, with control maintained through peer-to-peer communication between decentralized control units or direct intervention by the master control unit in the event of a network or device failure.
[0027] The system of the present invention has high reliability through redundancy and automatic failover between control units, ensuring uninterrupted operation during faults or network outages. The system offers enhanced security via multilayer authentication and end-to-end encryption between devices over the prior art. This system of the present invention has better scalability for deployment in diverse environments, from small residential networks to large industrial installations. It is noted that there is a reduced dependency on constant internet connectivity, enabling autonomous local operation even in remote or low- connectivity areas in the present invention.
[0028] Now, a method for secure automated control of devices using a distributed control system includes following steps: receiving, at an input control unit, input signals from at least one of a physical sensor, digital interface, mobile application, remote-control device, or voice- controlled interface; encrypting the input signals and transmitting corresponding control commands to a master control unit or a decentralized zone control unit; authenticating the control commands using multi-layer authentication including at least two of cloud-based one-time password validation, GSM-based OTP validation, or hardware-token-based encryption; processing the authenticated commands at a primary controller of a decentralized zone control unit to generate output trigger signals; transmitting the output trigger signals to an output control unit; decrypting and validating the output trigger signals at the output control unit; actuating one or more output devices selected from lighting devices, HVAC units, motors, actuators, curtain controls, geysers, or infrared transmitters; and performing redundancy failover by reassigning control to a peer decentralized control unit or escalating control to the master control unit upon detection of a fault or failure. The system of the present invention offers versatility in supporting a wide range of input devices, sensors, output devices, and communication protocols. A person skilled in the art will appreciate that the modularity of the system of the present invention allows easy installation, expansion, and integration with existing systems without compromising performance or security and comprehensive monitoring and control for real-time status feedback, troubleshooting, and energy management.
[0029] In essence, the present invention delivers a modular, decentralized, and privacy-focused smart control ecosystem that remains functional under adverse network conditions, offers robust access control, and supports flexible deployment for varied automation needs.
[0030] BRIEF DESCRIPTION OF DRAWINGS:
[0031] The objectives and advantages of the present invention will become apparent from the following description read in accordance with the accompanying drawings wherein,
[0032] FIG. 1 shows a schematic of a secure system for automated control of devices in accordance with the present invention;
[0033] FIG. 1A shows a more detailed schematic of the secure system for automated control of devices in accordance with the present invention of FIG. 1 ;
[0034] FIG. 2 shows a schematic of a nth zone of the secure system for automated control of devices of FIG. 1 ; FIG. 2A shows a detailed schematic of the nth zone of the secure system for automated control of devices of FIG. 1 ;
[0035] FIG. 2B shows a step wise execution in the nth zone of the secure system for automated control of devices of FIG. 1 ;
[0036] FIG. 3 shows an input interface to an input control unit of the nth zone of the secure system for automated control of devices in accordance with the present invention of FIG.2;
[0037] FIG. 3A shows a step wise execution of monitoring and controlling of the input trigger by the input control unit of zone control of the secure system for automated control of devices of FIG. 2;
[0038] FIG. 4 shows an output interface to an output control unit of control zone of the secure system for automated control of devices of FIG.2;
[0039] FIG. 4A shows a step wise execution to the output control unit of control zone of the secure system for automated control of devices in accordance with the present invention of FIG. 2;
[0040] FIG. 5 shows a step wise execution of master control of the secure system for automated control of devices in accordance with the present invention of FIG. 1 ; and
[0041] FIG. 6 shows a stepwise execution of operational cycle of the secure system for automated control of devices in accordance with the present invention of FIG. 1.
[0042] DESCRIPTION OF THE INVENTION: References in the specification to "one embodiment" or "an embodiment" means that a particular feature, structure, characteristic, or function described in connection with the embodiment is included in at least one embodiment of the invention. The appearances of the phrase “in one embodiment” in various places in the specification are not necessarily all referring to the same embodiment.
[0043] References in the specification to “preferred embodiment” means that a particular feature, structure, characteristic, or function described in detail thereby omitting known constructions and functions for clear description of the present invention.
[0044] The foregoing description of specific embodiments of the present invention has been presented for purposes of illustration and description. They are not intended to be exhaustive or to limit the present invention to the precise forms disclosed and obviously many modifications and variations are possible in light of the above teaching.
[0045] In general aspect, the present invention is a system for controlled automation of electrical, electromechanical devices and or different appliances. The system of the present invention is installed on a site, for example, home, office, agricultural or industrial environment. The system of the present invention provides automated control of output devices according to the input signals from the input units or external triggers. The system of the present invention provides secure device control and access control, and fault-tolerant operation across a broad range of infrastructure environments including, but not limited to, residential, commercial, industrial, agricultural, medical, and other similar infrastructure. The system of present invention works as a decentralized, interconnection of devices in home, office, or industrial environments by real time monitoring and controlling of multiple devices with enhanced security. Advantageously, the system of present invention provides redundancy for continuous operation of devices and optimizes communication network management even in cases of no internet, intermittent or even full internet communication.
[0046] Referring to FIG. 1, a secure system for automated control of devices (100) by real time monitoring of the input and output devices, hereinafter, referred to as the system (100) is described herein. The system (100) includes a master control (108) and a plurality of zones (110). A user (106) operates the system (100) via an input interface (104). The input interface (104) is for example, a mobile phone, laptop, tablet, or a like
[0047] The master control (108) is primary gateway responsible to provide secured access for central monitoring, and controls a control zone (110) in case of failure of all zone control units and also via the cloud infra structure (116).
[0048] Further, the control zone (110) includes a plurality of zones, a first zone (110-1), a second zone (110-2), and a nth zone (110-n). The first zone (110-1) serves as the primary interface between an input device (104) and the output devices (120) in the first zone.
[0049] It is noted that in accordance with the present invention, the control zone defines a primary control of the system (100). The first zone (110-1) serves as the primary interface between an input device (104) and the output units (120) in the first zone. The second zone (110-2) serves as the primary interface between an input device (104) and the output devices (120) in the second zone. The nth zone (110- n) serves as the primary interface between an input device (104) and the output devices (120) in the nth zone. The output unit (120) includes plurality of the output units (120). The output units (120) are for example, lights, fans, IR blasters or alike within the same zone. The user (106) communicates with the system (100) via a communication module (128). The communication module (128) is for example, a wireless communication, like WiFi, Bluetooth, GSM, LAN or cloud interface. The communication module (128) also provides operational active mode of the system (100) even in the absence of internet connectivity.
[0050] Now referring to FIG. 1A, a more detailed schematic of the secure system (100) is described herein. The system (100) includes the master control (108), and the plurality of control zones (110) such as the first zone (110-1), the second zone (110-1), ... and the nth zone (110-n). The master control (108) includes a master controller (125), an authenticator (112), a master output control module (122), a master local database (124), and a master communication module (128).
[0051] Further, each zone (110-n) includes an input unit (104) and an output unit (120) respectively coupled to that zone. The master controller (125) is configured on the master control (108) to coordinate control of the zones (110) in a failsafe mode of the system (100). In the failsafe mode of the system (100), an edge logic engine is implemented on the master controller (125) to control, process, analyze, and generate decision triggers for autonomous operation during failover conditions. The master communication module (128) interfaces the master controller (125) with the plurality of zones (110), that monitors all active zone during normal operation of the system. The master controller (125) may be, for example, a microcontroller or an equivalent processing device.
[0052] The master communication module (128) is, for example, a wireless communication like internet, Bluetooth, ZigBee, GSM, RF communication and a like. It is noted that the cloud infrastructure unit (116) stores and retrieves data from the primary local database through the master control (108). The cloud infrastructure unit (116) includes a GSM API (Global System for Mobile Communications Application Programming Interface), API hardware and an API adapter.
[0053] The cloud infrastructure unit (116) includes a remote server and a server OS running on it, or it may utilize third-party service providers like Amazon Web Services (AWS) or Google Cloud Platform (GCP). The third-party service provider companies provide the necessary operating system to run the software designed for managing the remote connectivity of the system (100). The cloud infrastructure (116) also facilitates backing up user data, ensuring that it can be restored when needed.
[0054] Furthermore, the cloud infrastructure (116) handles remote operations after authenticating the user (106) to control the system (100). Additionally, it provides one-way access to third-party APIs or voice assistants to operate devices based on user configurations. This integration with cloud services ensures reliable data storage, backup, and remote operation capabilities, enhancing the overall functionality and security of the control system.
[0055] According to the preferred embodiment of the present invention, the authenticator (112) includes a first authentication module (113), a second authentication module (114), and a third authentication module (115). The user (106) accesses the system (100) via the input interface (104). The authenticator (112) is configured on master controller (125) to authenticate the user (106), that secures via a multi-layered security system.
[0056] The first authentication module (113) provides a first secrecy level. In the first secrecy level, the first authentication module (113) provides authentication by an OTP authentication. The first authentication module (113) is configured on the cloud infrastructure (116), that provides cloud data access securely as a first security level. In the first security level, a cloud token validation provides authentication by the authenticator (112) to the user. In the preferred embodiments, the first secrecy level provides only limited data visualization and basic system access, without granting full device control.
[0057] In the second secrecy level, the second authentication module (114) provides authentication by a GSM based OTP authentication generated by the GSM module in the second authentication module (114) The GSM module is implemented within the master control (108), that ensures secure OTP generation and validation directly on the local system hardware. The second authentication module (114) secures identity & verification of the user (106) before access to the system (100) and provides access controls via cloud-connected interfaces (116). The second authentication module (114) authenticates and validates the user and network by GSM OTP.
[0058] The user (106) accesses the mobile app (or web interface) outside the local network, the system requests authentication via the cloud infrastructure (116). The cloud infrastructure (116) verifies the user's credentials (UID) and device identity by One-Time Password (OTP) generation. The user receives the OTP on the user interface (104) via SMS message. Accordingly, the first authentication module
[0059] (113) accesses a session token. The session token provides subsequent authenticated communication between the user interface (104) and the cloud infrastructure (116). The session token is valid, till session expires.
[0060] Next, the second authentication module (114) is configured on the master controller (125), that provides user registration. The second authentication module
[0061] (114) provides a second secrecy level. The second authentication module (114) includes a login module, a registration module, and a user input selection module.
[0062] It is noted that the input unit (104) stores and retrieves data from the master local database (124) through the master controller (125). The users (106) need to be registered with the system (100). Also, the registration module is configured for registration of the user (106) in the system. After registration, the users (106) enter the appropriate credentials and login to the system (100) through the login module.
[0063] Further, the second authentication module (114) validates the GSM OTP entered by the user on a remote console against the GSM OTP generated using the GSM module from the second authentication module (114) and accordingly, allows the users (106) to access the system interface unit (104). The master local database (124) stores an input / output device UIDs, UID registry, scene data, settings and logs, batch information, and configurations securely.
[0064] The third authentication module (115) provides a third secrecy level. In the third secrecy level, the third authentication module (115) generates hardware token by embedded encryption. In the preferred embodiments, the third secrecy level is provided by a local AES- hardware based encryption engine that secures a private key known only to the user, thereby providing the highest level of local authentication.
[0065] According to preferred embodiment of the present invention, a local logic engine is configured on the master controller (125), that executes automation, fallback, and logic functions locally in normal operating mode of the system (100). Normally, the master controller (125) monitors the respective zones (110-n) of the control zones (110). A redundancy & failover control engine is configured on the master controller (125), that switches normal operating mode of the master controller (125) to a failsafe operating mode of the system (100). A redundancy and failover control engine are configured on the master controller (125), that switches normal operating mode of the master controller (125) to a failsafe operating mode of the system (100).
[0066] Also in the preferred embodiment, the local logic engine is updated through secure over-the-air (OTA) mechanisms, that enables continuous improvement, security patching, and feature expansion without reliance on constant cloud connectivity.
[0067] Further, the master output control module (122) is configured on the master controller (125) that directly operates the output unit (120) for failsafe output triggers. The master output control module (122) controls respective output unit (120) in failure condition of the respective zone (110-n) of the control zone (110)). Also, a mode orchestration engine is configured on the master controller (125) to manage and control stored scene profiles or multi-device triggers. The local logic engine further supports secure OTA updates delivered via the master communication module (128), to ensure new rules, bug fixes, or policies addition to the system (100) without compromising privacy or local autonomy.
[0068] Referring now to FIG. 2, a schematic of the nth zone (110-n) of the system (100) is illustrated. The nth zone (110-n) includes an input control unit (204), a plurality of control units (208) and an output control unit (220).
[0069] In the present invention, the input control unit (204) receives data from the input interfaces (104) in first operating mode, processes and sends corresponding commands to the plurality of control units (208) within the same zone. The plurality of the control units (208) includes a first control unit (208-1), a second control unit (208-2), and nth control unit (208-n).
[0070] The plurality of control units (208) operates in a distributed redundancy mode, wherein each control unit (208) takes over the processing functions of another control unit (208) in case of local failure such as power failure or alike. In such case, the plurality of the control unit (208) provides a peer-to-peer multimaster operation within the same zone.
[0071] Accordingly, the first control unit (208-1) couples to the input control unit (204), processes the received data, generates corresponding commands, and sends these commands to the output control unit (220). The output control unit (220) interfaces to the output units (120) of the same zone. The output unis (120) are, for example, lightening devices, HVAC (Heating, Ventilation, and Air Conditioning) devices, fans, motors, rotary devices, Geysers, actuators or the like.
[0072] Next, the second control unit (208-2) couples to the the input control unit (204), processes the received data, generates corresponding commands, and sends these commands to the output control unit (220). Also, the zone control unit (208) receives encrypted commands from the master control (108) or directly from the local input control units (104). The zone control unit (208) triggers respective outputs unit (120).
[0073] The output control unit (220) interfaces to the output units (120) of the same zone. The nth control unit (208-n) couples to the the input control unit (204), processes the received data, generates corresponding commands, and sends these commands to the output control unit (220). The output control unit (220) interfaces to the output units (120) of the same zone.
[0074] Also, each decentralized control unit (208) stores a zone-specific device registry, that includes a unique identifier (UIDs) of associated devices, and validates UID authenticity before accepting or executing any control command, and is configured to operate autonomously even when the control unit (208) gets disconnected from the master control unit (108).
[0075] Now referring to FIG. 2A, detailed schematics of the nth zone is described herein. The nth zone (110) includes the input control unit (204), the plurality of control units (208) and the output control unit (220) connected to the output devices of the same zone. Further, the plurality of control units (208) includes the first control unit (208-1), the second control unit (208-2), and the nth control unit (208-n). It is to be noted that, the first control unit (208-1), the second control unit (208-2), and the nth control unit (208-n) are in peer-to-peer communication.
[0076] According to preferred embodiment of the present invention, the nth control unit includes a primary authentication unit (212), a primary data base (224), a primary communication unit (228) and a primary nth control (216).
[0077] The primary authentication unit (212) receives commands from the primary communication unit (228) for both incoming signals from input control unit (204) and outgoing signals intended for output control unit (220). The primary authentication unit (212) authenticates the unique identifiers (UIDs) and verifies the legitimacy of the associated devices before allowing further processing or transmission of the signals. The primary authentication unit (212) also provides UID locking interface and device authentication for onboarding.
[0078] The primary authentication unit (212) locks every output unit (120) to the system (100), that prevents rogue devices, ensures only authenticated UIDs enter. Each output device (120) is assigned a unique identifier (UID), which is locked and stored securely in the primary database (224) of the zone control unit (208). Any attempt to add a new device requires authentication and approval of the new UID through the master control (108), that ensures only authorized devices are enrolled into the system.
[0079] The primary control (216) accesses the primary database (224) to retrieve relevant data when an input signal is received. It is noted that irrespective to the selected algorithm and the available data, the control module generates different sets of output data. This output data is then transferred to the respective output unit (120) for execution.
[0080] The primary control (216) is configured on the nth control unit (208-n) to generate output trigger packet. The primary control (216) includes a primary controller (225), a processing module (230), a command generation module (232), a command parser module (234), a command validator module (236). The primary control (216) also includes a redundancy assignment module (238), a failover detection & control logic (240), an action logger (242), and a fault detector (244).
[0081] The processing module (230) is configured on the primary controller (225) to process inputs, triggers, and local automation functions. The command generation module (232) is configured on the primary controller (225) to generate and route commands to the appropriate output interfaces. The command validator module (236) is configured on the primary controller (225) to ensure the validity and freshness of commands before execution. The redundancy assignment module (238) is configured on the primary controller (225) to assign primary or backup control roles to controllers within the zone. The failover detection and control logic (240) are configured on the primary controller (225) to initiate takeover signals in case of failure of the active control unit within the zone, and may escalate control to the master control (108) if peer-level redundancy is unavailable.
[0082] The primary control (216) analyses, controls and transfers the controlled output signal commands to the output control unit (220). The output control unit (220) generates the request to operate the output unit (120) of respective zone. In the failsafe mode of the system (100), an edge logic engine is implemented on the master controller (125) to control, process, analyze, and generate decision triggers for autonomous operation during failover conditions. In the present invention, the redundancy and failover control are also distributed such that the primary control (216) provides peer-to-peer takeover in the event of local zone level failures before escalation to the master control (108), that provides a multi-master multi-layer redundancy architecture.
[0083] The output control unit (220) interfaces to the output units (120) of the respective zone. The output unis (120) are, for example, lightening devices, HVAC (Heating, Ventilation, and Air Conditioning) devices, fans, motors, rotary devices, Geysers, actuators and the like. The output control unit (220) receives the control signal from the primary control (216). Advantageously, the output control unit (220) transfers a status update feedback signal to the nth control unit (208-n), that maintains system integrity and allows for monitoring and troubleshooting. It is noted that the primary communication unit (228) utilizes an RF communication protocol. In the present invention, the primary communication unit (228) provides a wireless communication between a plurality of input units, a primary control (216), the authentication unit (212) and the output unit (120). The wireless communication is, for example, proprietary wireless RF protocol. It is to be noted that the authentication unit (212) & the primary communication unit (228) operate on different wireless communications. The wireless communication is, for example, the internet, Bluetooth, Wi-Fi, cloud interface, and similar technologies.
[0084] Now referring to FIG. 2B, a step wise execution of the nth control of the control zone (110) in the normal operating mode of the system (100) is described herein.
[0085] Initially, in a step (254), the nth control unit (208-n) of the nth zone is activated. The primary controller (225) initializes all communication interfaces, such as RF, BLE, and wired communication, and loads the local UID table and configuration data for the respective control from the primary database (224), if available.
[0086] Next, in a step (258), the nth control unit (208-n) of the nth zone monitors incoming packets, including activity commands from the master control (108), input activity commands from connected active input control units (204), and peer message commands from other zone control units (208) within the same control zone (110). In a step (262), the primary authentication unit (212) validates the source of each message. The authentication validates the origin is from a registered zone control unit (208) in the same control zone (110), confirms authentication from a paired input control unit (205), and validates the control zone designation (110-n).
[0087] Next, in a step (266), the command validator module (236) validates the command, and the primary controller (225) decrypts the incoming data packet using the local encryption module. If decryption fails, the command validator module (236) discards the command packet and logs an error for the respective input control unit (204).
[0088] In a next step (270), the primary authentication unit (212) identifies the target UID of the input control unit (204) or the output device (120) by comparing the received details with the records stored in the primary database (224). The input control unit (204) processes the received data, generates corresponding commands, and sends these commands to the zone control units (208).
[0089] Finally, in step (274), the primary controller (225) transmits the validated output commands to the output control unit (220) for execution within the same zone (110).
[0090] Further in the zone (110-1), if the first control unit (208-1) becomes unresponsive, the redundancy mode of the system (100) gets active. In the redundancy mode of the system (100), the control from the first control unit (208- 1) is transferred to the next peered control unit in same zone (110-1), such as the second control unit (208-2) or the third control unit (208-3), and so on. The active control (208-n) of the same zone, accordingly operates the output control unit (220) and respective associated output units (120). The redundancy is controlled via a periodic synchronization beat exchanged between peer control units (208) within the same zone (110). If the control unit (208- n) fails to transmit its synchronization beat within a predefined window, that the function control, the control unit (208- n) is automatically reassigned to a peer unit before escalation to the master control (108).
[0091] Further, if the second zone control unit (208-2) also becomes unresponsive, control is transferred to the third zone control unit (208-3), and this process continues in sequence.
[0092] If all zone control units (208) within a control zone (110) are unresponsive or fail, the fail-safe mode of the system get activates. In the fail-safe mode, the master control (108) gets activates. In this condition, the master control (108) directly operates the output control unit (220) and the output devices (120) of the failed zone to maintain uninterrupted system operation.
[0093] Also, the present invention ensures that internet access is strictly isolated to the master control (108). The decentralized control units (208) never directly connect to the internet, thereby prevents unauthorized access. All data remains within the user’s zone premises, ensuring a privacy-enabled system that is completely under the user’s control.
[0094] Now referring to FIG. 3, an input unit interface to the input control unit (204) of the system (100) is described herein. The input control unit (204) receives the input from the plurality of input devices through the input interfaces (104). The input interfaces (104) include a first interface unit (104-A), a second interface unit (104-B), a third interface unit (104-C), and a fourth interface unit (104-D).
[0095] The input interface (104) provides facility of operating the system (100) in the first mode, the second mode, the third mode and the fourth mode to generate an input trigger signal. The first interface unit (104-A) is, for example, a mobile, tab or laptop for accessing the system (100) by the user (106) via a master communication module (128) or a primary communication unit (228). In the first mode, the system (100) is accessible via the first interface unit (104-A).
[0096] The second interface unit (104-B) is, for example, a remote interface device to operate the input or output device without network. In the second mode, the system (100) operates through the second interface unit (104-B).
[0097] The third interface unit (104-C), is for example, voice assistant, Amazon Alexa, Google Home etc. The third interface unit (104-C) provides instructions to and from the primary interface (104-C) through the primary communication unit (228). In the third mode, the system (100) operates according to voice commands through the third interface unit (104-C).
[0098] The fourth interface unit (104-D) further includes a physical sensor unit (304) and a digital interface unit (308). The physical sensor unit (304) includes a plurality of sensors is, for example a motion sensor (PSI) (PIR, mmWave, ultrasonic), temperature sensors (PS2), light sensors (PS3), sound sensors (PS4), vibration sensors (PS5), pressure sensors (PS6), CO2 sensors (PS7), gas sensors (PS8), rain sensors (PS9), smoke sensors (PS 10), door sensors (PS 11), or alike.
[0099] The digital interface unit (308) includes a plurality of interface unit. The plurality of interface unit is, for example, touch panels (Dll), push buttons (DI2), key pads (DI3), rotary encoders (DI4), RF remote controls (DI5), IR remote receivers (DI6), voice interfaces (DI7), gesture sensors (DI8), fingerprint sensors (DI9), emergency buttons (DUO), fire alarm (Dll 1), NFC tags (DI12), TFT display (Dll 3), RFID card readers (DI 14), or a like. Each sensor / interface delivers a signal to the input controller (316). The physical sensor unit (304) and a digital interface unit (308) processes and transfers the signal from respective input interface to the primary control (208).
[0100] The input control unit (204) is first point of data acquisition, also detects user interactions or environmental inputs and securely communicates received data to the primary control (216) for further processing and action.
[0101] The input control unit (204) includes an input unit controller (316), an input interface module (324), an input analyses engine (328), and an input command generation module (332). The input control unit (204) also includes an input encryption module (336), an input pairing module / interface (340) and feedback synchronization module (344) and an input memory (314).
[0102] The input unit controller (316) is, for example, a microcontroller. The input unit controller (316) is configured on the input control unit (204) to receive input from a physical sensor unit (304) and a digital interface unit (308) to process and transfer the input trigger signal from respective input interface to the control unit (208) of nth zone (110-n).
[0103] Also, input interface module (324), the input analyze engine (328), the command generation module (332), the input encryption module (336), the input pairing module / interface (340) and feedback synchronization module (344) are configured on the input controller (316) for providing secrecy. The input pairing module (340) is configured on the input unit controller (316) for initial secure pairing with nth control unit (208-n) of the nth zone (110-n). The input control unit (204) facilitates acquisition of signals from multiple input devices in parallel. The first input storage (314) is an input event logger Logs last N input events locally for diagnostics and also stores the thresholds and presets for data comparison on the controller level.
[0104] Now referring to FIG 3A, a step wise execution of real time monitoring and controlling the input trigger command by the input control unit (204) is described herein.
[0105] Initially, in a step (354), the inbuilt power supply activates the input control unit (204). Next, in a step (358), the input interface module (324) is configured on the input controller (316) to receive the input trigger signal from the physical sensor unit (304) or digital interface unit (308). Next, in a next step (362), If no input trigger is detected, the system remains idle and no signal is transmitted to the primary control (208). Next, in a next step (366), input trigger detection, the input analyse engine (328) processes the input data by debounce, analog thresholding, and pattern recognition. Accordingly, the input analyse engine (328) analyzes type, context, and behavior of input and applies zone-specific logic. In a next step (370), a command generation module (332) is configured on input controller (316) to generate a contextual command to translate processed input into actionable control packets for example, switch is in ‘ON’ state, report motion, request scene and a like. Also, the input encryption module (336) is configured on input controller (316) to encrypt the generated command received from a command generation module (332). The input encryption module (336) also encrypts outgoing commands for secure transmission. In a next step (374), the input pairing module (340) is configured on input controller (316), that combines device UID and zone information to each command and transmits the encrypted command over a proprietary wireless (or wired) protocol to its assigned primary control (208). Also manages pairing, zone assignment, and synchronization with primary control (208). In a next step (378), the feedback and synchronization module (344) receive optionally response from the master control unit (108) like ‘ACK’, ‘Fail’. ‘Retry’. Also, the feedback and synchronization module (344) activates respective local LED, buzzer, or haptic module to confirm input success, resumes monitoring inputs for next event by continuing the step (358).
[0106] FIG. 4 shows an output interface to the output control unit (220) of nth zone (110-n) of the control zone (110) is described herein. The output control unit (220) receives the control signal from the primary control (216). The output control unit (220) provides the final actuator interface for the system (100). The output control unit (220) is interfaced and coupled with the plurality of the output devices (120). The output devices include a first output device (404), a second output device (408), a third output device (412) and a like nth output device (416). The output device is, for example as lights, fans, HVAC systems, curtains, or valves, and are capable of status feedback and self-monitoring. Also, each output unit (120) is assigned a unique device UID and configured to receive respective output trigger command packets
[0107] The output control unit (220) includes an output unit controller (422), an UID address resolver module (428), an output decryption module (432), and an authentication validation module (436). Also, the output control unit (220) includes a command interpretation (440) module, an execution engine (442), a feedback synchronization module (446) and a load monitor module (450).
[0108] The output control unit (220) includes the output unit controller (422). The output unit controller (422) is, for example, a microcontroller. The output unit controller (422) controls a single or multi-channel outputs, also monitors output load.
[0109] The UID address resolver module (428) is configured on the output unit controller (422), that compares and matches incoming command to this device’s unique ID stored in the primary database (224). The output decryption module (432) is configured on the output unit controller (422), to decrypt encrypted output triggered command packets before execution. The authentication validation module (436) is configured on the output unit controller (422), that validates source authenticity from a control zone (110) master control (108) or primary control (216). The command interpretation (440) is configured on the output unit controller (422), that parses decrypted commands, for example a toggle, dim, set level, IR trigger. The action execution engine (442) is configured on the output unit controller (422), that executes operations via actuation interfaces, for example, relays, dimmers, motors, or IR. The feedback synchronization module (446) is configured on the output unit controller (422), accepts direct commands from the master control (108) in case of failure of the all-zone controller in (110).
[0110] The output control unit (220) executes, processes, transmits the output trigger commands received from the nth control unit (208) of the Zone (110) or the primary master control (108). The output devices, for example lights, fans, HVAC systems, curtains, or valves, are configured with unique identifiers (UIDs) and are capable of status feedback and self-monitoring The load monitoring module (450) tracks energy metrics like current, voltage, or power and also stores the current log event in local storage database (448) present on the output control unit (220) and send the event to the primary database (224).
[0111] Now referring to FIG. 4A, a step wise execution of controlling the output devices by the output control unit (220) is described herein. Initially, in step (454), the output control unit (220) receives the output trigger command from the control unit (208). The UID address resolver module (428) validates the command by comparing it with the unique ID stored in the primary database (224). Next, in a decryption step (458), the output unit controller (422) transfers output command packet to the output decryption module (432). The output decryption module (432) decrypts output command packet command by local encryption keys. The authentication validation module (436) is configured on the output unit controller (422), that validates source authenticity from a zone control (110), master control or primary control (108). Next, in a command interpretation step (462), the command interpretation (440) parses decrypted commands in the respective output triggers like ‘ON’, ‘OFF’, ‘brightness’, ‘speed level’, ‘IR trigger code’, ‘motor operation command’. Next, in a step of (464), the action execution engine (442) operates the respective operations via actuation interfaces. Next, in a step of monitoring the output command (468), the feedback synchronization module (446) optionally accepts direct commands to execute fail safe operation from the master control (108). The fail-safe operation mode of the system (100) activates in case of failure of the respective control unit of the zone (110).
[0112] Referring to FIG. 5, a step wise execution of the master control (108) of the system (100) of the present invention is described herein. In the present invention, the master control (108) is a central monitoring unit and core intelligence of the system (100).
[0113] Initially, in a step (504), the master control (108) activates and operates as a central monitoring and security unit of a secure system (100), the master control (108) initializes the master communication module (128) and communication interfaces, including RF, GSM, Wi-Fi, and Bluetooth, and uploads stored policy and state data from the master local database (124). Next, in a step (508), the master controller (125) monitors all control units (208) of zones (110) and supervises redundancy mode of the system in a failover condition of the control units (208). The master controller (125) monitors sync beats from all zone control units. Absence of multiple sync beats triggers redundancy reassignment within the zone, and only upon exhaustion of all peer units does the system enter master-controlled fail-safe mode.
[0114] Next, in step (512) the master controller (125) authenticates remote access requests from the first authentication module (113), the second authentication module (114), and the third authentication module (115). Next, in a step (516) the master controller (125) decrypts authenticated request data. Next in a step (520), the master controller (125) identifies the target UID, device, and zone (110-n) from records stored in the master local database (124). Next in a step (524), the master controller (125) operates in fail safe mode of the system (100). In the failsafe mode, the master controller (125) applies stored policy and logic to determine whether to forward the command to the active z control unit (208). In the failure situation of all the control units (208) in a respective zone, the master controller (125) itself, accordingly, controls the output control unit (220) of respective zone. Next, in a step (528), the master controller (125) generates control commands for the output control unit (220) of the affected zone (110-n). In a next step (532), the master controller (125) encrypts the generated commands for secure transmission. Next in a step (536), the master controller (125) rejects invalid feedback and processes valid status feedback from the output control unit (220). And in a next step (540), the master controller (125) updates logs and system state in the master local database (124).
[0115] Now, a method for secure automated control of devices using a distributed control system is described hereinafter. The said method includes following steps: i) receiving, at an input control unit (204), input signals from at least one of a physical sensor, digital interface, mobile application, remote-control device, or voice-controlled interface; ii) encrypting the input signals and transmitting corresponding control commands to a master control unit (108) or a decentralized zone control unit (208); iii) authenticating the control commands using multi-layer authentication including at least two of cloud-based one-time password validation, GSM-based OTP validation, or hardware-token-based encryption; iv) processing the authenticated commands at a primary controller (225) of a decentralized zone control unit (208) to generate output trigger signals; v) transmitting the output trigger signals to an output control unit (220); vi) decrypting and validating the output trigger signals at the output control unit (220); vii) actuating one or more output devices (120) selected from lighting devices, HVAC units, motors, actuators, curtain controls, geysers, or infrared transmitters; and viii) performing redundancy failover by reassigning control to a peer decentralized control unit (208) or escalating control to the master control unit (108) upon detection of a fault or failure.
[0116] Now referring to FIGS. 1, 1A, 2, 2A,2B, 2C,3, 3B, 4,4B, 5A, and 6 an operational flow of the system (100) is described herein.
[0117] Initially, the user (106) accesses the system (100) via the mobile application or web interface (104-A) outside the local network, and initiates authentication via the cloud infrastructure (116). The cloud infrastructure (116) verifies the user’s credentials (UID) and device identity by generates a one-time password (OTP) delivery to the user interface (104-A) via SMS. The first authentication module
[0118] (113) receives the OTP response and obtains a session token for subsequent authenticated communication between the user interface (104-A) and the cloud infrastructure (116) until the session expires. The second authentication module
[0119] (114), configured on the master controller (125), provides the second secrecy level by handling user registration and login, including validating the GSM / OTP against records stored in the master local database (124). The master local database (124) securely stores input / output device UIDs, UID registry, scene data, settings, logs, batch information, and configurations. The third authentication module (115) provides the third secrecy level by generating a hardware token using embedded encryption to secure local network sessions and device-level integrity. According to successful completion of three authentication layers, the master control (108) initializes the access to the system (100). Activates the system (100) in normal mode to functions and initiates the control zone (110) operations.
[0120] In a step (604), the system (100) operates in the normal mode of operation and activates the control zone (110) operations. In a step (608), the input control unit (204) receives inputs, that are user commands or sensor inputs. The input control unit (204) processes and encrypts the data, and further transmits encrypted data exclusively to one or more control units (208) within the respective zone (110- n). Next, in a step (612), the control unit (208) performs primary zone level authentication and validation. The validation verifies the command origination from an authorized and paired input control unit (204) and ensures packet integrity by local encryption and authentication modules. Next, in a step (616), the primary controller (225) of the active control unit (208) of the respective zone decrypts the command payload. Next, in a step (620), the primary controller (225) identifies the target UID and device, generates the output trigger command, and stores the transaction in the respective primary database (224). Next, in a step (624), the output control unit (220) transmits the output commands to the output devices (120) of the respective zone for execution. Next, in a step (628), the control unit (208) monitors the output devices (120) and analyzes feedback signals and input signals to verify proper execution during normal mode. Next, in a step (632), for a device fault or acknowledgment detection by the fault detector module (244), the system (100) operates in the redundancy mode. In the redundancy mode, the control unit (208) attempts to reassign control to another active control unit (208) within the same zone. For example, in redundancy mode 1, if a fault is detected in the first control unit (208-1) such that it becomes non-responsive and fails to transmit its synchronised beat within a specified timeframe, the control is transferred to another active control unit (208-2). If (208-2) is subsequently fails, the control is reassigned to (208-3), and this process continues sequentially. Next, in step (634), if all control units (208) in a zone (110-n) are in failure status and stops sending an active synchronization beat to the master controller (108), the system (100) operates in the second fail-safe mode. In the second failsafe mode, the master control (108) controls the affected failure zone and sends direct commands to the output control unit (220) via the feedback synchronization module (446), maintains the operation until at least one zone control unit (208) is restored and activates.
[0121] EXAMPLES:
[0122] The performance of the system (100) is described below using specific exemplary details.
[0123] Example 1:
[0124] In this example, the system (100) was installed in a home. The system (100) has operated electrical devices in the three zones (110-1), (110-2) and (110-3). Each zone included multiple input units (104), such as touch panels, motion detectors, and mobile app access points. The input units (104) interacted with the plurality of control units (208). The control unit (208-n) has controlled and operated the output units (220). The output units were lights, fans, IR controllers, and smart switches.
[0125] In normal operation mode of the system (100), the user (106) was at home, used the mobile app or local interfaces (104-A) to control appliances directly. The operating commands were processed by the control unit (208- n) without the need for additional authentication because in-home control was secured through encrypted local communication (Wi-Fi, Bluetooth, RF, or wired network).
[0126] In the zone (110-1), three control units such as first control unit (208-1), the second control unit (208-2) and the third control unit (208-3) were in peer-to-peer communication. Each input unit (104) sent an encrypted, UID-tagged command to the control unit (208-1), that processed, analyzed and controlled the logic for generating the respective output unit (120) activation commands in the same zone (110-1). The output activation commands with the schedule conditions were transferred to the respective output units (220) in the same zone (110-1). The respective output units (120) performed the actions like, switching lights ON, adjusting fans, operating curtains. The output control unit (220) sent a feedback status report the respective control unit (208-1).
[0127] Next, due to hardware failure of the first control unit (208-1), the first control unit (208-1) was failed. Now, the system (100) operated in the redundancy operation mode. In the redundancy mode, the control of the first control unit (208- 1) has transferred to the second control unit (208-2) in the same zone (110-1). The said transition was without the user intervention.
[0128] Further, the second control unit (208-2) was failed due to communication disruption. The control of the second control unit (208-2) has transferred to the third control unit (208-3) in the same zone (110-1). Furthermore, the third control unit (208-3) was failed due to power loss.
[0129] Next, the system (100) was operated in the fail-safe mode, as the last active control unit (208-3) of the zone (110-1) was failed. In the fail-safe mode, the master control (208) gets activated and controls the output units (120) of the zone (110-1). The user (106) has accessed the system (100) via his mobile application as he went outside the zone (110). The user sent a request to access the control zone (110), the home, remotely via the cloud interface (116) and the master control (108). For remote access, the master control initiated a GSM-based OTP authentication processed by the authenticator (112) through its built-in SIM card. An OTP is sent to users (106) registered mobile number. After OTP authentication, the master control (108) receives the user’s temporary secure access to the system (100). When a new device was introduced in zone (110-1), its unique UID was authenticated via the master control (108) before being added to the zone database (224). The UID authentication prevented addition of unauthorized output without explicit user approval.
[0130] Accordingly, the master control (108) has controlled all the output units (120) in all zones (110-n), even if the control units (208-n) were offline. It is to be noted, the master control (108) has not interacted to the respective input unit (104) or the logic configured on the respective primary control (216). However, the user (106) retained the ability to ‘turn devices ON / OFF’, to adjust settings of lights, fans, curtains, etc., or to trigger emergency scenes or override outputs.
[0131] Example 2:
[0132] The performance of the system (100) installed in the Agriculture Field Control with Multi-Layer Redundancy
[0133] In this example, the system (100) was installed in an agriculture field. The performance of the system (100) installed in the agriculture field control in redundancy operating mode is discussed.
[0134] The control zone was the agriculture farm (110) included the first zone (110- 1), a second zone (110-2) and a third zone (110-3). The first zone (110 -1) was a drip and sprinkler zone. The system (100) automatically triggered irrigation in the first zone (110-1) when the soil moisture level dropped below a set threshold, and combined with time-based scheduling to optimize water usage.
[0135] The second zone (110-2) was a greenhouse environmental management zone. In the second zone (110-2), the control unit (208-n) continuously monitored temperature and humidity through sensors connected to the input control unit (204). As the temperature exceeded a preset threshold limit, the system (100) activated fans and water misting outputs to stabilize conditions.
[0136] The third zone (110 -3) was a perimeter security & lighting zone. The motion sensors triggered perimeter lights or activated alarms, that prevented trespassing after sunset.
[0137] Each zone (110 -n) has received the parameters from the input units (104), like soil moisture sensors, temperature / humidity sensors, light sensors, motion detectors, and manual override switches. All actions were processed locally by the respective control unit (208-n), that ensured fast response times and no dependence on internet connectivity.
[0138] Next, due to hardware failure of the first control unit (208-1), the first control unit (208-1) was failed. Now, the system (100) operates in the redundancy operation mode. In the redundancy mode, the control of the first control unit (208- 1) has transferred to the second control unit (208-2) in the same zone (110-1).
[0139] Further, the second control unit (208-2) was failed due to communication disruption. The control of the second control unit (208-2) has transferred to the third control unit (208-3) in the same zone (110-1). However, the user (106) controlled all irrigation outputs directly via the master control (208), through the user’s mobile phone, whether he was on-site or at remote location.
[0140] The master control initiated a GSM-based OTP authentication processed by the authenticator (112) through its built-in SIM card. An OTP is sent to users (106) registered mobile number. Aster OTP authentication, the master control (108) receives the user’s temporary secure access to the system (100). The user (106) has activated water pumps, opened or closed solenoid valves, and monitored system logs directly from the master control (208).
[0141] Additionally, during emergencies like power failure in the Greenhouse Zone, the master control (208) has controlled the outputs units (120), that maintained critical operations, such as fan activation or venting without sensor input.
[0142] The system (100) facilitated offline operation as the system (100) automated farm activities without internet. The system (100) has stored every event logging in the master local database (124) and primary data base (224), such as every action, override, or failure is logged for audits and compliance. The system (100) provided energy monitoring by tracking pump and motor energy usage to optimize power consumption. Also, the system (100) provided secured access to the user. The authenticator (112) ensured GSM OTP validity only for authorized personnel to changes remotely.
[0143] The system (100) has automated multi zones, such as (110-1), (110-2) and (110-3), that respectively managed irrigation, greenhouse, and security separately. As the first control unit (208-1) was failed due to hardware loss, the system (100) has provided dual redundancy control, and no system of respective zine was down observed during control unit failure situation. The system (100) has provided secured access to the user from remote location via GSM OTP authentication. And the user operated the zone from any location securely. The system (100) provided fail-safe output operation. As the master control (208) has controlled the pumps and motors still work during failures of the primary control (116). The system is inherently privacy-enabled, wherein all control and data remain local to the user, and external connectivity is optional, restricted, and authenticated through the master control (108). This ensures the user retains complete control of the system at all times.
[0144] Advantageously, the system (100) provides robust stable, secured, verified, scalable, versatile and centralized control of operating the output devices. The system (100) advantageously reduces internet dependency and efficient local network management. Further, the system (100) has consistent performance even if in the situation of failure of network connectivity and power failure. Also, the system (100) advantageously controls with or without internet communication network. The system (100) facilitates to adjust and set working modes according to working periods of the appliance automatically according to user habits without human intervention.
[0145] Further, the system (100) advantageously allows easy and user-friendly installation. Also, the system is economical as it provides scalable accessibility of connecting devices. The comprehensive monitoring and command structure ensures that the system (100) operates efficiently, responds promptly to user commands, and maintains a high level of reliability and security in a closed network without the need of internet. The system is configured for deployment in at least one of residential, office, agricultural, industrial, or medical automation domains without modification of the underlying architecture.
[0146] The embodiments were chosen and described in order to best explain the principles of the present invention and its practical application, to thereby enable others, skilled in the art to best utilize the present invention and various embodiments with various modifications as are suited to the particular use contemplated.
[0147] It is understood that various omission and substitutions of equivalents are contemplated as circumstance may suggest or render expedient, but such are intended to cover the application or implementation without departing from the scope of the present invention.
Claims
CLAIMS:I claim:
1. A secure system for automated control of devices (100) comprising: a master control unit (108) having a master controller (125), a multi-layer authenticator (112), and a master communication module (128), the master control unit (108) being configured to receive control commands from one or more input interfaces or decentralized a control units (208-n), authenticate the commands using at least two different authentication mechanisms in a normal operating mode and coordinate the decentralized control units (208) and output units (120) in a failsafe operating mode; a plurality of the decentralized control units (208), each associated with a respective control zone (110), each decentralized zone control unit (208) having a primary controller (225) configured to process input commands, generate output trigger signals, and transmit the signals to output devices in the corresponding zone, and a failover logic module configured to transfer control to another decentralized zone control unit (208) in a redundancy mode or the master control unit (108) in a failsafe mode upon detection of a fault and failure of all the zone control units (208); an input control unit (204) configured to receive input from at least one of a physical sensor, a digital interface, a mobile application, a remote-control device, or a voice-controlled interface, encrypt the input, and transmit corresponding control commands to the master control unit (108) or a decentralized control unit(208);an output control unit (220) configured to receive and decrypt output commands, validate their authenticity, and actuate corresponding output devices (120); a communication network including at least one of a proprietary wireless protocol, Bluetooth, Wi-Fi, Zigbee, GSM, or a wired connection; and an internet-connected mode and offline modes of operation wherein the system (100) maintains control of the output devices (120) through peer-to-peer communication between decentralized control units (208) or direct intervention by the master control unit (108) in the event of a network or device failures.
2. The secure system for automated control of devices (100) as claimed in claim 1, wherein the multi-layer authenticator (112) includes a first authentication module (113) for GSM or one-time password (OTP) verification, a second authentication module (114) for cloud token validation, and a third authentication module (115) comprising a local hardware-based AES encryption engine storing a secure key for final device-level authentication for hardware token generation using embedded encryption.
3. The secure system for automated control of devices (100) as claimed in claim 1, wherein the master control unit (108) is configured to store user credentials, device identifiers, configuration data, and control logs in a secure local database and optionally synchronize the data with a cloud server.
4. The secure system for automated control of devices (100) as claimed in claim 1, wherein each decentralized control unit (208) stores a zone-specific device registry and is configured to operate autonomously when disconnected from the master control unit (108).
5. The secure system for automated control of devices (100) as claimed in claim 1, wherein at least one decentralized control unit (208) being further configured to act as a temporary master controller in the fail status of the master control unit (108), thereby maintaining continuity of automation operations.
6. The secure system for automated control of devices (100) as claimed in claim 1, wherein the failover logic module of a decentralized zone control unit (208) is configured to reassign control to a peer zone control unit (208) within the same control zone (110) by transfer of synchronization beat prior to escalation to the master control unit (108).
7. The secure system for automated control of devices (100) as claimed in claim 1, wherein the input control unit (204) further includes an input pairing module for secure initial pairing with the master control unit (108) or a decentralized control unit (208), and an input encryption module (336) for encrypting outgoing control commands using device- specific keys.
8. The secure system for automated control of devices (100) as claimed in claim 1, wherein the physical / environmental sensors include at least one of: motion sensors, temperature sensors, light sensors, vibration sensors, gas sensors, smoke sensors, door sensors, rain sensors, or CO2 sensors.
9. The secure system for automated control of devices (100) as claimed in claim 1, wherein the digital interface includes at least one of: a touch panel, push button, keypad, rotary encoder, RF remote, IR receiver, gesture sensor, RFID reader, fingerprint sensor, emergency button, NFC tag, or TFT display.
10. The secure system for automated control of devices (100) as claimed in claim 1, wherein the output control unit (220) further includes a load monitoring module (450) configured to measure voltage, current, and power consumption for each output device (120).
11. The secure system for automated control of devices (100) as claimed in claim 1, wherein the output devices (120) have at least one of: lighting devices, HVAC units, motors, actuators, curtain controls, geysers, infrared transmitters, electromechanical devices.
12. The secure system for automated control of devices (100) as claimed in claim 1, wherein the output devices (120) being assigned a unique identifier (UID) and manufacturing batch number stored in the nth control unit (208), and wherein addition of a new device requires authentication of its UID and batch number by the master control (108), thereby preventing unauthorized or cloned devices from being registered.
13. The secure system for automated control of devices (100) as claimed in claim 1, wherein the master control unit (108) is configured to directly control the output control unit (220) and thereby the output devices (120) in a control zone (110), when all corresponding decentralized zone control units (208) are unresponsive in the failsafe redundancy mode.
14. The secure system for automated control of devices (100) as claimed in claim 1, wherein communication between the master control unit (108) and decentralized control units (208) employ end-to-end encryption with device-level authentication.
15. The secure system for automated control of devices (100) as claimed in claim 1, wherein the communication between the input control units (204) and control unit (208) to the output control unit (220) being in end-to-end encryption with device level authentication.
16. The secure system for automated control of devices (100) as claimed in claim 1, wherein the communication between the cloud or local level mobile or any server level communication employ end-to-end encryption with device-level authentication between input, control, and output units.
17. The secure system for automated control of devices (100) as claimed in claim 1, wherein the master control unit (108) and zone control unit (208) further includes a local logic edge engine configured to execute stored automation rules and scene profiles, routines without the need of internet connectivity.
18. The secure system for automated control of devices (100) as claimed in claim 1, wherein all device control logs, UIDs, and user data remain stored locally in the master control unit (108) and zone control units (208), with external synchronization being optional and user-initiated through the master control unit (108).
19. The secure system for automated control of devices (100) as claimed in claim 1, wherein the master communication module (128) is configured to isolate internetaccess to the master control unit (108) to reduce the risk of unauthorized access to the decentralized zone control units (208).
20. The secure system for automated control of devices (100) as claimed in claim 1, wherein the cloud server (116) is further configured to integrate with third-party voice assistants or application programming interfaces (APIs) for remote control of devices.
21. A method for secure automated control of devices using a distributed control system as claimed in claim 1, the method comprising: i) receiving, at an input control unit (204), input signals from at least one of a physical sensor, digital interface, mobile application, remote-control device, or voice-controlled interface; ii) encrypting the input signals and transmitting corresponding control commands to a master control unit (108) or a decentralized zone control unit (208); iii) authenticating the control commands using multi-layer authentication including at least two of cloud-based one-time password validation, GSM-based OTP validation, or hardware-token-based encryption; iv) processing the authenticated commands at a primary controller (225) of a decentralized zone control unit (208) to generate output trigger signals; v) transmitting the output trigger signals to an output control unit (220); vi) decrypting and validating the output trigger signals at the output control unit (220);vii) actuating one or more output devices (120) selected from lighting devices, HVAC units, motors, actuators, curtain controls, geysers, or infrared transmitters; and viii) performing redundancy failover by reassigning control to a peer decentralized control unit (208) or escalating control to the master control unit (108) upon detection of a fault or failure.
Citation Information
Patent Citations
Redundant Automation System
US20150095690A1
Multi-Level User Device Authentication System for Internet of Things (IOT)
US20180183779A1
Industrial control system redundant communication / control modules authentication
US20180343125A1