Centralized Update Service for Passive Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for updating passive network connected devices in isolated networks are inefficient, costly, and prone to errors due to the need for manual intervention and lack of scalability, especially for large entities managing multiple devices across different geographical areas.
Innovation Solution
A scalable distributed computing and network architecture utilizing a centralized update service (CUS) that issues a single command to securely update multiple passive devices across isolated networks, leveraging intermediary agents and proxy agents to navigate network obstacles and ensure secure communication, while generating a trust score for firmware files based on feedback from test devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual update methods are used for passive devices in isolated networks, then update control and security are maintained, but update efficiency and scalability deteriorate
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the isolated network containing passive devices and the external network. The gateway receives update commands from external sources, authenticates them, and forwards them to passive devices within the isolated network. This mediator approach maintains security boundaries while enabling automated updates without manual intervention, resolving the contradiction between controlled updates and update efficiency.
2Ease of operation
If controller devices are deployed in each isolated network for updates, then local update capability is achieved, but deployment cost and complexity increase
Solution Approach 1:
The gateway device is designed to perform multiple functions: it acts as a network router, an update server, an authentication authority, and a communication bridge between isolated and external networks. By consolidating these functions into a single multi-functional device, the patent eliminates the need for separate controller devices in each isolated network, reducing deployment complexity while maintaining local update capability.
3Reliability
If firmware updates are pushed to passive devices, then software currency is improved, but security risks from untrusted firmware increase
Solution Approach 1:
The gateway device performs preliminary authentication and verification of firmware updates before they are pushed to passive devices. It validates digital signatures, checks firmware integrity, and authenticates the gateway itself against trusted certificates stored in passive devices. This preliminary security check ensures that only authenticated and trusted firmware reaches passive devices, eliminating security risks while maintaining software currency.
4Productivity
If automated update systems are implemented across multiple isolated networks, then scalability is improved, but network security and isolation requirements become more difficult to maintain
Solution Approach 1:
The patent maintains network isolation by segmenting the update architecture: each isolated network retains its security boundary, and gateways are deployed at the boundary layers. The gateway architecture allows automated update management across multiple isolated networks while preserving their security isolation, as each gateway handles only its local isolated network's updates and communicates securely with external networks. This segmented approach enables scalability without compromising network security.
Data Source
AI summary
Various embodiments of the present disclosure include a scalable distributed computing and network system that is configured to install, update or revoke certificates in a multitude of passive devices in many isolated networks. Various embodiments may include a processor in a computing device associating a certificate profile with one or more passive devices in a plurality of passive devices in one or more isolated networks, generating a certificate signing request (CSR) message for each of the associated passive devices, sending the generated CSR messages to a certificate authority, receiving digital certificates from the certificate authority, and sending the received digital certificates to their respective associated passive devices.


