Device Configuration Recovery via Operational Trust Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication devices face challenges in reliably updating software and configuration settings, as updates may introduce incompatibilities or impair device function, and there is a need for a mechanism to ensure the device can recover from operational failures and upgrade outdated factory versions.
Innovation Solution
The device is configured to store multiple copies of its configuration information and apply updates in a manner that allows automatic recovery if the update introduces issues. It sets a low trust level for new configuration information, allowing it to be used temporarily for booting, and then tests its operation to verify proper function before raising the trust level or reverting to previous configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the device applies software updates to improve functionality and security, then the device features and security are enhanced, but the device may experience operational failures or incompatibilities
Solution Approach 1:
The device performs preliminary actions by storing multiple copies of configuration information (current and previous versions) before applying updates. This allows the device to prepare recovery options in advance, ensuring that if an update fails, the device can revert to a known good state without loss of functionality.
Solution Approach 2:
The patent implements a trust level mechanism that acts as a cushion against update failures. By setting initial trust levels to 'low' and requiring verification through testing and remote communication before elevating to 'high' trust, the system buffers against potential incompatibilities and operational failures from unverified updates.
2Reliability
If the device stores multiple copies of configuration information to enable recovery, then the device can recover from update failures, but the device storage requirements increase
Solution Approach 1:
The configuration information is segmented into distinct versions (current and previous) stored in separate locations. This segmentation allows the device to maintain multiple copies without creating a monolithic storage structure, enabling selective restoration of specific configuration versions while managing storage efficiently.
Solution Approach 2:
The device implements a mechanism to discard outdated configuration copies after successful recovery or verification. The trust level system allows the device to temporarily retain multiple copies for verification purposes, then permanently discard the previous version once the current configuration is confirmed to work correctly, reducing long-term storage requirements.
3Reliability
If the device tests operation with new configuration information before full adoption, then the device can verify compatibility, but the update process time increases
Solution Approach 1:
The device performs partial verification by testing only critical functions with the new configuration information at low trust level before full adoption. Rather than exhaustive testing of all features, the system verifies essential operational compatibility, then elevates trust level if successful, balancing verification thoroughness with time efficiency.
Solution Approach 2:
The trust level mechanism provides continuous feedback during the update process. The device monitors operational status with the new configuration and communicates verification results to remote systems. This feedback loop allows the device to confirm compatibility incrementally, reducing overall verification time by stopping early if critical failures are detected.
4Reliability
If the device automatically reverts to previous configuration upon failure, then the device maintains continuous operation, but the user may not be aware of the update failure
Solution Approach 1:
The device implements feedback mechanisms to notify users of update failures despite automatic reversion. The system communicates with remote systems to report verification failures and can provide local notifications to users, ensuring awareness of update outcomes while maintaining operational continuity through automatic recovery.
Solution Approach 2:
The device performs self-service by automatically detecting update failures and reverting to previous configurations without user intervention. This self-healing capability maintains continuous operation, while complementary notification mechanisms inform users of the recovery action taken, balancing automation with user awareness.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer-storage media, for operational trust-based device auto-recovery. In some implementations, a device operates using first configuration information stored by the device. The device receives updated configuration information and stores the updated configuration information while maintaining storage of the first configuration information. The device sets itself to operate with the updated configuration information subject to a limitation, and the device is configured to revert to using the first configuration information if one or more predetermined conditions occur. The communication device then operates using the updated configuration information subject to the limitation.


