Centralized Update Service for Passive Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for updating passive network connected devices in isolated networks are inefficient, costly, and prone to errors due to the need for manual intervention and lack of scalability, especially for large entities managing multiple devices across different geographical areas.

Innovation Solution

A scalable distributed computing and network architecture utilizing a centralized update service (CUS) that issues a single command to securely update multiple passive devices across isolated networks, leveraging intermediary agents and proxy agents to navigate network obstacles and ensure secure communication, while generating a trust score for firmware files based on feedback from test devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual update methods are used for passive devices in isolated networks, then update control and security are maintained, but update efficiency and scalability deteriorate

Engineering Contradiction:
Improveupdate controlVSAvoidupdate efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the isolated network containing passive devices and the external network. The gateway receives update commands from external sources, authenticates them, and forwards them to passive devices within the isolated network. This mediator approach maintains security boundaries while enabling automated updates without manual intervention, resolving the contradiction between controlled updates and update efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If controller devices are deployed in each isolated network for updates, then local update capability is achieved, but deployment cost and complexity increase

Engineering Contradiction:
Improvelocal update capabilityVSAvoiddeployment complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The gateway device is designed to perform multiple functions: it acts as a network router, an update server, an authentication authority, and a communication bridge between isolated and external networks. By consolidating these functions into a single multi-functional device, the patent eliminates the need for separate controller devices in each isolated network, reducing deployment complexity while maintaining local update capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If firmware updates are pushed to passive devices, then software currency is improved, but security risks from untrusted firmware increase

Engineering Contradiction:
Improvesoftware currencyVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The gateway device performs preliminary authentication and verification of firmware updates before they are pushed to passive devices. It validates digital signatures, checks firmware integrity, and authenticates the gateway itself against trusted certificates stored in passive devices. This preliminary security check ensures that only authenticated and trusted firmware reaches passive devices, eliminating security risks while maintaining software currency.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If automated update systems are implemented across multiple isolated networks, then scalability is improved, but network security and isolation requirements become more difficult to maintain

Engineering Contradiction:
ImprovescalabilityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent maintains network isolation by segmenting the update architecture: each isolated network retains its security boundary, and gateways are deployed at the boundary layers. The gateway architecture allows automated update management across multiple isolated networks while preserving their security isolation, as each gateway handles only its local isolated network's updates and communicates securely with external networks. This segmented approach enables scalability without compromising network security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12088577B2Systems and methods of remotely updating a multitude of IP connected devices
Publication Date: 2024.09.10 VIAKOO INC
  • US12088577B2 patent drawing
  • US12088577B2 patent drawing
  • US12088577B2 patent drawing

AI summary

Various embodiments of the present disclosure include a scalable distributed computing and network system that is configured to install, update or revoke certificates in a multitude of passive devices in many isolated networks. Various embodiments may include a processor in a computing device associating a certificate profile with one or more passive devices in a plurality of passive devices in one or more isolated networks, generating a certificate signing request (CSR) message for each of the associated passive devices, sending the generated CSR messages to a certificate authority, receiving digital certificates from the certificate authority, and sending the received digital certificates to their respective associated passive devices.