Remote Field Device Split Communications for Secure Firmware Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote field devices in buildings often lack timely firmware updates and security enhancements due to limited network connectivity and infrequent site visits, leading to stagnation and potential security and functional issues.
Innovation Solution
Implementing split communications in remote field devices to establish separate channels for owner operations and manufacturer control functions, using distinct credentials for each, allowing manufacturer-controlled updates without requiring owner interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If owner credentials are used for all device access, then ease of operation is improved, but device security deteriorates due to inability to separate manufacturer update functions from owner access functions
Solution Approach 1:
The patent divides the credential system into separate owner credentials and manufacturer credentials, creating distinct access channels. This segmentation allows owner operations and manufacturer updates to coexist without interference, improving both ease of operation for owners and security for manufacturer-controlled functions.
Solution Approach 2:
The patent introduces a credential verification intermediary mechanism that checks whether incoming credentials match the expected owner or manufacturer credential set. This intermediary layer ensures proper authorization while maintaining clear separation between operational and update functions.
2Reliability
If remote field devices are isolated from network for security, then device security is improved, but firmware updates and configuration changes become difficult
Solution Approach 1:
The patent segments communication into two independent channels: one for owner operations requiring owner credentials, and another for manufacturer updates requiring manufacturer credentials. This allows devices to remain network-isolated for security while still accepting authorized manufacturer updates through the dedicated channel.
Solution Approach 2:
The credential verification mechanism acts as an intermediary that mediates between the isolated device and external update sources. It verifies manufacturer credentials before allowing updates, enabling secure firmware updates without compromising the device's network isolation and security posture.
3Reliability
If manufacturer control functions require separate credentials from owner functions, then device security is improved, but device complexity increases
Solution Approach 1:
The patent implements segmentation by maintaining separate credential stores for owner and manufacturer functions. While this increases structural complexity, it provides clear security boundaries and prevents credential confusion, ultimately improving reliability.
Solution Approach 2:
The patent manages complexity by changing the parameter of credential storage organization. Instead of a single credential set, the system uses distinct credential parameters (owner credentials vs. manufacturer credentials) that are verified differently based on the operation type, making security management more systematic.
Data Source
AI summary
Disclosed herein are apparatuses and methods for performing manufacturer control functions on a remote field device. In one example, a mobile device can transmit, to a remote field device, a connection request including credentials related to performing a manufacturer control function the remote field device. The remote field device can verify the credentials with stored manufacturer credentials that are stored in the one or more memories for performing the manufacturer control function, where the stored manufacturer credentials are different from stored owner credentials stored in the one or more memories for accessing other functions of the remote field device. Based on verifying the credentials, a connection between the remote field device and the mobile device can be established to allow initiating, by the mobile device, the manufacturer control function on the remote field device.


