Configurable Data Object Update System for Network Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data object update systems face challenges in efficiently updating digital identity data and other sensitive materials in network-enabled devices without requiring device recall, often resulting in operational disruptions and difficulties in supporting new data object types without downtime.
Innovation Solution
A flexible data object update system that allows configuration of authentication, authorization, and protection mechanisms, enabling secure and timely updates to network-enabled devices without disrupting existing operations, by using a data object generation system, update server, whitelist/blacklist manager, and configuration manager to manage and deliver downloadable data objects over networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional data object update systems are used to update digital identity data in network-enabled devices, then security and privacy are maintained, but device recall to service centers is required causing operational disruptions
Solution Approach 1:
The system separates the data object generation function from the update server. A data object generation system creates authorized data objects that are then distributed through the update server to devices in the field, eliminating the need for device recall while maintaining security through controlled generation and distribution channels.
Solution Approach 2:
The update server acts as an intermediary between the data object generation system and network-enabled devices. It receives authorized data objects from the generation system and delivers them to devices remotely, providing a secure middle layer that enables updates without device recall to service centers.
2Adaptability or versatility
If conventional update systems are used, then existing devices can be updated, but new data object types cannot be supported without system downtime
Solution Approach 1:
The system dynamically adapts to new data object types through the data object generation system, which can authorize and create new types of data objects without requiring system downtime. The update server dynamically receives and distributes these new data object types to devices as needed, enabling continuous operation while supporting versatility.
Solution Approach 2:
The data object generation system pre-authorizes new data objects and their types before distribution. This preliminary authorization allows the update server to immediately distribute new data object types to devices without waiting for system configuration or experiencing downtime, enabling continuous productivity while supporting new types.
3Reliability
If digital identity data is updated in deployed devices, then security is maintained, but devices must be recalled to service centers increasing loss of time
Solution Approach 1:
Network-enabled devices can autonomously receive and install updated data objects through the update server without requiring service center intervention. The system enables self-service updates where devices remain in the field, connecting remotely to receive security updates, thereby eliminating the time loss associated with device recall.
Solution Approach 2:
The update server provides a universal platform that can distribute various types of data objects to multiple devices simultaneously across the network. This multi-functional system handles different data object types and serves multiple devices through a single remote update mechanism, eliminating the need for individual device recalls to service centers.
Data Source
AI summary
A data object update system provides a flexible framework that can be used to upgrade, renew, replace or supplement data objects that are provisioned in a large base of network-enabled devices that been deployed in the field to end users. The system has the flexibility to configure, for example, the following items, based on different requirements received from network operators: which device key and/or certificate is to be used to authenticate request messages from network-enabled devices before a specific data object update request is accepted into the system; which device identifier is to be used to authorize data object update requests; which device identifier is to be used for generating device specific data objects; and which protection mechanism is to be used to secure the delivery of data objects to network-enabled devices.


