Remote Field Device Split Communications for Secure Firmware Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote field devices in buildings often lack timely firmware updates and security enhancements due to limited network connectivity and infrequent site visits, leading to stagnation and potential security and functional issues.

Innovation Solution

Implementing split communications in remote field devices to establish separate channels for owner operations and manufacturer control functions, using distinct credentials for each, allowing manufacturer-controlled updates without requiring owner interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If owner credentials are used for all device access, then ease of operation is improved, but device security deteriorates due to inability to separate manufacturer update functions from owner access functions

Engineering Contradiction:
Improveease of operationVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the credential system into separate owner credentials and manufacturer credentials, creating distinct access channels. This segmentation allows owner operations and manufacturer updates to coexist without interference, improving both ease of operation for owners and security for manufacturer-controlled functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a credential verification intermediary mechanism that checks whether incoming credentials match the expected owner or manufacturer credential set. This intermediary layer ensures proper authorization while maintaining clear separation between operational and update functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If remote field devices are isolated from network for security, then device security is improved, but firmware updates and configuration changes become difficult

Engineering Contradiction:
Improvedevice securityVSAvoidfirmware update capability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments communication into two independent channels: one for owner operations requiring owner credentials, and another for manufacturer updates requiring manufacturer credentials. This allows devices to remain network-isolated for security while still accepting authorized manufacturer updates through the dedicated channel.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The credential verification mechanism acts as an intermediary that mediates between the isolated device and external update sources. It verifies manufacturer credentials before allowing updates, enabling secure firmware updates without compromising the device's network isolation and security posture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manufacturer control functions require separate credentials from owner functions, then device security is improved, but device complexity increases

Engineering Contradiction:
Improvedevice securityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements segmentation by maintaining separate credential stores for owner and manufacturer functions. While this increases structural complexity, it provides clear security boundaries and prevents credential confusion, ultimately improving reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent manages complexity by changing the parameter of credential storage organization. Instead of a single credential set, the system uses distinct credential parameters (owner credentials vs. manufacturer credentials) that are verified differently based on the operation type, making security management more systematic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250254518A1Split communications for updating remote field devices
Publication Date: 2025.08.07 TYCO FIRE & SECURITY GMBH
  • US20250254518A1 patent drawing
  • US20250254518A1 patent drawing
  • US20250254518A1 patent drawing

AI summary

Disclosed herein are apparatuses and methods for performing manufacturer control functions on a remote field device. In one example, a mobile device can transmit, to a remote field device, a connection request including credentials related to performing a manufacturer control function the remote field device. The remote field device can verify the credentials with stored manufacturer credentials that are stored in the one or more memories for performing the manufacturer control function, where the stored manufacturer credentials are different from stored owner credentials stored in the one or more memories for accessing other functions of the remote field device. Based on verifying the credentials, a connection between the remote field device and the mobile device can be established to allow initiating, by the mobile device, the manufacturer control function on the remote field device.