Supervisory Controller Firmware Upgrade via Secure Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-controller systems in industrial plants lack the capability to upgrade firmware onsite, leading to costly transportation and security vulnerabilities due to the lack of secure protocols for updating firmware, which can result in errors and unauthorized access.

Innovation Solution

Establishing secure communication channels, such as RS485, UART, I2C, SPI, or CAN, between a supervisory controller and associated controllers to facilitate firmware updates, using identifiers to ensure correct firmware delivery and authentication, and entering bootloader modes for secure data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware is updated by shipping controllers back to factory, then firmware can be upgraded, but transportation costs and man power are significantly wasted

Engineering Contradiction:
Improvefirmware upgrade capabilityVSAvoidtransportation cost and man power
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

A communication interface is introduced as an intermediary between the host computer and the controller, enabling firmware updates to be performed remotely at the installation site. This eliminates the need to physically transport controllers to the factory, thereby saving transportation costs and man power while maintaining firmware upgrade capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If existing communication protocols are used for firmware update, then data can be transmitted, but security against unauthorized commands or interception is insufficient

Engineering Contradiction:
Improvedata transmissionVSAvoidunauthorized access and interception
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Authentication procedures are performed preliminarily before firmware update data is transmitted. The host computer and controller verify each other's identities using authentication information, preventing unauthorized commands or interception. This preliminary security measure ensures that only authenticated devices can communicate and update firmware, countering potential security threats before they occur.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If entire firmware is replaced during update, then firmware can be updated, but errors may occur and system functionality may be compromised

Engineering Contradiction:
Improvefirmware updateVSAvoidupdate error risk
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication interface is configured in advance to receive firmware update data and transfer it to the appropriate destination within the controller. This preliminary setup ensures that updates are applied correctly and systematically, reducing the risk of errors that could compromise system functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates confirmation mechanisms where the controller provides feedback to the host computer regarding the status of firmware updates. This feedback loop allows for verification that updates were applied correctly, enabling error detection and correction while maintaining system functionality.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11210081B2Configuring firmware for a target device
Publication Date: 2021.12.28 CARRIER CORP
  • US11210081B2 patent drawing
  • US11210081B2 patent drawing
  • US11210081B2 patent drawing

AI summary

Aspects of the invention are directed towards systems for upgrading the firmware of one or more controllers in a system. One or more embodiments of the invention describe receiving an upgraded firmware for the supervisory controller and one or more associated controllers by the supervisory controller via a first interface. The supervisory controller identifies whether the firmware update is for the supervisory controller or for one or more associated controllers based on an identifier. The firmware update is transmitted to the supervisory controller and/or the one or more associated controllers based on the identification via a second interface.