Head-End Software Update Delivery for IoT Peripherals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for updating software on peripheral devices connected to set-top boxes, IoT hubs, or gateways often require user involvement, are insecure, or necessitate expensive secure chipsets, leading to delays and security risks, especially for devices that cannot directly connect to the Internet.

Innovation Solution

Utilizing a head-end infrastructure like a set-top box or IoT hub as a secure entry-point to deliver software updates to peripheral devices through secure protocols, such as HTTPS or TFTP, ensuring encrypted and integrity-checked updates can be sent over existing network infrastructure, eliminating the need for direct Internet connectivity and expensive secure chipsets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If peripheral devices connect directly to the Internet for software updates, then update speed and autonomy are improved, but security risks and cost of secure chipsets increase

Engineering Contradiction:
Improveupdate speedVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a set-top box as an intermediary device between the peripheral device and the update server. The set-top box has a secure chipset that verifies update authenticity before delivery, eliminating the need for expensive secure chipsets in peripheral devices while maintaining security. This mediator approach allows fast updates through direct connection while centralizing security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If peripheral devices use expensive secure chipsets for secure updates, then security is improved, but device cost increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the security functions (secure chipset, cryptographic verification, update authentication) from the peripheral device into the set-top box. This consolidation allows peripheral devices to be manufactured without expensive secure chipsets, reducing costs, while the set-top box maintains centralized security controls for all connected devices.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If manual update processes are used for peripheral devices, then security control is improved, but user involvement and complexity increase

Engineering Contradiction:
Improvesecurity controlVSAvoiduser involvement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements an automated update system where the peripheral device autonomously receives update notifications from the set-top box, downloads updates, verifies authenticity, and installs updates without user intervention. The set-top box manages the entire update process automatically, eliminating manual USB connections and technical user involvement while maintaining security through cryptographic verification.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If interoperability testing is performed before deployment, then compatibility is improved, but time to market increases

Engineering Contradiction:
ImprovecompatibilityVSAvoidtime to market
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs interoperability verification as a preliminary action during the software update delivery process. Before deploying updates to peripheral devices, the set-top box validates update compatibility and authenticity. This allows early deployment of peripheral devices with basic functionality while ensuring compatibility through pre-deployment verification, reducing time to market without sacrificing compatibility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11681515B2Method of delivering and updating software on peripheral devices connected to set-top boxes, IoT-hubs, or gateways
Publication Date: 2023.06.20 ARRIS ENTERPRISES LLC
  • US11681515B2 patent drawing
  • US11681515B2 patent drawing
  • US11681515B2 patent drawing

AI summary

Disclosed are an apparatus and method for securely delivering and updating software on a peripheral device in an area network. Software for a peripheral device is obtained from an entity responsible for the functionality of the peripheral device. The software is validated for functionality and integrity, and it is then encrypted at the headend of a network infrastructure which securely delivers the software to a processor responsible for controlling the interface of the area network. The processor decrypts the validated software, and it delivers the validated software to a peripheral device on the area network. The validated software is executed on the peripheral device, such that the peripheral device executes an authentic version of the software from the entity responsible for the functionality of the peripheral device.