FOTA Update Synchronization in Mesh Lighting Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firmware updates over-the-air (FOTA) in building technology, particularly lighting installations, face challenges with maintaining downward compatibility and ensuring reliable updates in mesh networks, where failures can lead to devices becoming non-communicative.
Innovation Solution
A method where a server transmits a firmware update image to devices in a mesh network, with a timeout period to confirm receipt and initiate the update, allowing devices to boot with the new firmware and revert to a golden copy if not activated, ensuring synchronization and reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If firmware update is performed over-the-air in mesh networks, then update convenience and automation are improved, but reliability deteriorates due to potential communication failures and loss of downward compatibility
Solution Approach 1:
The patent applies preliminary action by having devices save the firmware update image in their memory before the actual update is triggered. This allows the update to be prepared in advance but not executed immediately, enabling the system to maintain current operational firmware while having the new firmware ready. The update is then activated systematically across the mesh network, and if failures occur, devices can revert to the previously saved golden copy, thus maintaining reliability while achieving automation.
2Productivity
If firmware update is triggered simultaneously across all devices, then update speed is improved, but reliability deteriorates due to synchronization issues and communication failures
Solution Approach 1:
The patent applies segmentation by dividing the firmware update process into distinct phases: first saving the update image, then triggering the copy to internal memory, and finally activating the update. This segmented approach allows the system to monitor each phase separately and abort the process at any stage if communication failures or synchronization issues are detected, thereby maintaining reliability while still achieving efficient updates.
Solution Approach 2:
The patent implements feedback mechanisms where devices send status information back to the system about their update progress and success. This feedback allows the system to monitor the update process across the mesh network, detect communication failures, and trigger abort conditions when necessary. The feedback loop ensures that updates are performed reliably by allowing the system to respond to actual device states rather than assuming uniform progress.
3Reliability
If timeout period for update confirmation is extended, then reliability is improved by allowing more time for successful updates, but productivity deteriorates due to longer waiting times
Solution Approach 1:
The patent applies dynamics by making the timeout period adjustable rather than fixed. The system can adapt the timeout duration based on network conditions, device responses, and update progress. This dynamic approach allows the system to extend the timeout when communication is slow or devices are processing updates, improving reliability. Conversely, when updates proceed quickly, the timeout remains short, maintaining productivity. The dynamic timeout works in conjunction with the segmented update process to balance reliability and efficiency.
Data Source
Figure 1
AI summary
The invention relates to a firmware over-the-air (FOTA) method for updating building services installations, in particular lighting services installations, comprising multiple devices which are connected to a server as a mesh network, the method comprising the following steps: storing a firmware update image sent by the server in a storage unit of each device, and triggering the copying of the firmware update from the storage unit into an internal storage unit of a microcontroller of each of the devices by means of a trigger request outputted by the server, wherein the server, within a predefined time period (Timeout) after the trigger command is outputted, uses responses from the devices to check whether each device has received the firmware update image and the trigger command, and the copying only takes place after the predefined time period has passed.