Centralized Update Service for Isolated Network Firmware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for updating software on passive network connected devices in isolated networks are cumbersome, inefficient, and costly, particularly for larger entities managing numerous devices across multiple isolated networks.
Innovation Solution
A scalable distributed computing and network architecture that includes a Centralized Update Service (CUS) computing device, proxy agents, and intermediary agents, enabling secure, efficient, and scalable software updates across multiple isolated networks with a single command.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual controller installation and physical device access is used for software updates, then update security is maintained, but update time and cost increase significantly
Solution Approach 1:
The patent introduces a centralized update service as an intermediary between the corporate network and isolated network devices. This service uses proxy agents deployed within isolated networks to mediate firmware distribution, allowing automated updates without requiring physical device access while maintaining security through controlled communication channels.
Solution Approach 2:
The system segments the update delivery mechanism into multiple components: a centralized update service for coordination, proxy agents for local network communication, and intermediary agents for secure data transfer. This segmentation enables parallel update operations across multiple devices simultaneously, reducing total update time while maintaining security protocols.
2Ease of manufacture
If manual controller installation is used for each device, then firmware distribution control is precise, but operational complexity increases
Solution Approach 1:
The centralized update service automatically discovers devices within isolated networks, retrieves their firmware requirements, and distributes appropriate updates without manual intervention. The proxy agents autonomously manage local network communication, eliminating the need for operators to manually configure each device while maintaining precise control over firmware distribution.
Solution Approach 2:
The centralized update service provides universal functionality across diverse device types and isolated network configurations. A single service instance can manage updates for multiple devices with different firmware requirements, replacing the need for separate manual update procedures for each device type.
3Reliability
If physical access to each device is required for updates, then security risks are minimized, but scalability is limited
Solution Approach 1:
Proxy agents act as intermediaries within isolated networks, enabling secure automated communication between the centralized update service and devices without requiring physical access. This intermediary layer maintains security by controlling and monitoring all update-related communications while enabling scalable automated operations.
Solution Approach 2:
The patent replaces the mechanical approach of physical device access with electronic communication through proxy agents and intermediary agents. This substitution eliminates the need for physical presence at each device while maintaining security through authenticated, monitored digital communication channels, thereby enabling scalable updates across numerous devices.
Data Source
AI summary
Various embodiments of the present disclosure include a scalable distributed computing and network system that is configured to update multitude of passive devices in many isolated networks. The system may include a centralized update service (CUS) computing device that receives a firmware file, generates a firmware profile, identifies passive devices that include outdated firmware, select one of the identified passive devices as a test device, and send the firmware file to the test device through intermediates and proxy agents. The CUS computing device receives feedback from the test device, generates a trust score for the firmware file based on the received feedback, and determine whether to send the firmware file to the other identified passive devices based on the generated trust score.


