IoT Terminal Upgrade via Surveillance Device Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional IoT device upgrades are time-consuming and laborious, requiring physical interfaces and are not feasible for large-scale deployments, while over-the-air (OTA) upgrades face security risks due to potential interference and tampering.
Innovation Solution
A method involving a hierarchical and distributed two-way verification mechanism, where a server initiates OTA upgrades through a surveillance device, ensuring secure communication by encrypting upgrade files and identification information, and each terminal device verifies the integrity of the upgrade files, reducing the number of two-way connections needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional wired upgrade method is used, then upgrade security is maintained through physical connection, but upgrade process becomes time-consuming and laborious requiring on-site cable connection
Solution Approach 1:
The patent replaces the mechanical wired connection system with a wireless communication system. The upgrade file transmission is achieved through wireless signals between the server and terminal device, eliminating the need for physical cable connections while maintaining secure transmission through encryption algorithms.
Solution Approach 2:
The patent introduces a wireless communication module as an intermediary between the server and terminal device. This intermediary enables secure file transmission by establishing an encrypted communication channel, allowing upgrades without physical connection while preserving security through the intermediary's encryption functions.
2Productivity
If OTA upgrade technology is used, then upgrade speed and convenience are improved, but security risks increase due to potential interference and tampering
Solution Approach 1:
The patent applies preliminary anti-action by implementing encryption algorithms before the upgrade file transmission. The server encrypts the upgrade file and verification code beforehand, and the terminal device verifies these encrypted elements upon receipt, preventing tampering and interference during the OTA upgrade process.
Solution Approach 2:
The patent implements a feedback mechanism where the terminal device sends verification results back to the server. The server provides upgrade files and verification codes, and the terminal device feedbacks whether the verification passed, creating a closed-loop security system that maintains reliability while enabling wireless upgrades.
3Reliability
If server directly communicates with each terminal device, then secure two-way verification is achieved, but the number of connections increases significantly in large-scale IoT deployments
Solution Approach 1:
The patent segments the verification process into two independent parts: the upgrade file itself and the verification code. This segmentation allows the server to transmit both elements separately to the terminal device, which then performs local verification, reducing the need for continuous server-terminal connections while maintaining security.
Solution Approach 2:
The patent enables the terminal device to perform self-verification by providing it with both the upgrade file and verification code. The terminal device independently verifies the upgrade file using the verification code without requiring real-time server connection, allowing secure upgrades in large-scale deployments with minimal server-terminal connections.
Data Source
AI summary
The present disclosure provides a method for upgrading an Internet of Things (IoT) terminal device and an electronic device thereof. The method includes: determining a surveillance device and performing two-way verification with the surveillance device; sending, in response to successful two-way verification, a first upgrade instruction to at least one of the surveillance device and the terminal device, wherein a server communicates with the terminal device via the surveillance device, and the first upgrade instruction includes an encrypted upgrade file, encrypted server identification information, and an encrypted first check value.


