IP Library Granted Patent US 11,853,743
Granted Patent B2
US 11,853,743 · App. 17/643,295 · Granted Dec 26, 2023

Safe modular upgrades

Inventors: Peter Hartley (Cambridge, GB); Philip Michaelson-Yeates (Ely, GB); Jonathan Williams (Cambridge, GB); Hugo Fiennes (Palo Alto, CA); Tejas Patil (Cambridge, GB); Joseph Birr-Pixton (Cambridge, GB)
Assignee: KORE Wireless Group, Inc.
G06F8/656G06F8/658G06F21/572
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,853,743
App. No.
17/643,295
Granted
Dec 26, 2023
Kind
B2
Abstract

An Internet of Things (IoT) device is deployed with embedded software that may comprise multiple components. After deployment, updated versions of one or more components of the embedded software may become available. The IoT device maintains a manifest of the installed components. Periodically, the IoT device requests an updated copy of the manifest from an upgrade server. The installed manifest and the updated manifest are compared to determine if updated versions of any components are available. If so, the IoT device requests only the components to be updated. Prior to beginning the copying of the upgraded components, an upgrade flag is set. The IoT device then begins copying the received components into memory, replaces the manifest with the updated manifest, and clears the upgrade flag.

Claims (76)

1. A method comprising:

accessing, by one or more processors, a local manifest that identifies a first module, a first local hash of the first module, a second module, a second local hash of the second module, a first memory region for the first module, and a second memory region for the second module;

accessing, by the one or more processors, a remote manifest that identifies the first module, a first remote hash of the first module, the second module, and a second remote hash of the second module;

determining that the first local hash is different from the first remote hash;

determining that the second local hash is equal to the second remote hash; and

receiving, over a network, the first module without receiving the second module.

2. The method of claim 1 , further comprising:

multiplexing, on a single connection, multiple data streams comprising a first data stream for communication by an application and a second data stream for receiving the first module.

3. The method of claim 1 , further comprising:

decrypting the received first module;

generating a hash of the received first module; and

comparing the generated hash to the first remote hash to verify the received first module.

4. The method of claim 1 , further comprising:

transmitting, over the network, the local manifest; and

receiving, over the network, the remote manifest.

5. The method of claim 1 , wherein the first module of the local manifest is an application module.

6. The method of claim 1 , wherein the first module of the local manifest is a kernel module.

7. The method of claim 1 , wherein:

the local manifest further identifies a third module;

the remote manifest further identifies the third module; and

the method further comprises:

receiving, over the network, the third module;

validating the received first module;

validating the received third module; and

installing the received first module and the received third module based on the validating of the received first module and the received third module.

8. A system comprising:

one or more computer processors; and

one or more computer-readable mediums storing instructions that, when executed by the one or more computer processors, cause the system to perform operations comprising:

accessing a local manifest that identifies a first module, a first local hash of the first module, a second module, a second local hash of the second module, a first memory region for the first module, and a second memory region for the second module;

accessing a remote manifest that identifies the first module, a first remote hash of the first module, the second module, and a second remote hash of the second module;

determining that the first local hash is different from the first remote hash;

determining that the second local hash is equal to the second remote hash; and

receiving, over a network, the first module without receiving the second module.

9. The system of claim 8 , wherein the operations further comprise:

multiplexing, on a single connection, multiple data streams comprising a first data stream for communication by an application and a second data stream for receiving the first module.

10. The system of claim 8 , wherein the operations further comprise:

decrypting the received first module;

generating a hash of the received first module; and

comparing the generated hash to the first remote hash to verify the received first module.

11. The system of claim 8 , wherein the operations further comprise:

transmitting, over the network, the local manifest; and

receiving, over the network, the remote manifest.

12. The system of claim 8 , wherein:

the local manifest further identifies a third module;

the remote manifest further identifies the third module; and

the operations further comprise:

receiving, over the network, the third module;

validating the received first module;

validating the received third module; and

installing the received first module and the received third module based on the validating of the received first module and the received third module.

13. A non-transitory computer-readable medium storing instructions that, when executed by one or more computer processors of one or more computing devices, cause the one or more computing devices to perform operations comprising:

accessing a local manifest that identifies a first module, a first local hash of the first module, a second module, a second local hash of the second module, a first memory region for the first module, and a second memory region for the second module;

accessing a remote manifest that identifies the first module, a first remote hash of the first module, the second module, and a second remote hash of the second module;

determining that the first local hash is different from the first remote hash;

determining that the second local hash is equal to the second remote hash; and

receiving, over a network, the first module without receiving the second module.

14. The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:

multiplexing, on a single connection, multiple data streams comprising a first data stream for communication by an application and a second data stream for receiving the first module.

15. The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:

decrypting the received first module;

generating a hash of the received first module; and

comparing the generated hash to the first remote hash to verify the received first module.

16. The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:

transmitting, over the network, the local manifest; and

receiving, over the network, the remote manifest.

17. The non-transitory computer-readable medium of claim 13 , wherein the first module of the local manifest is an application module.

18. The system of claim 8 , wherein the first module of the local manifest is an application module.

19. The non-transitory computer-readable medium of claim 13 , wherein:

the local manifest further identifies a third module;

the remote manifest further identifies the third module; and

the operations further comprise:

receiving, over the network, the third module;

validating the received first module;

validating the received third module; and

installing the received first module and the received third module based on the validating of the received first module and the received third module.

20. The non-transitory computer-readable medium of claim 13 , wherein the first module of the local manifest is a kernel module.

Assignments (7)
SECURITY INTEREST Recorded Jul 22, 2026
From: KORE WIRLESS GROUP INC.; KORE WIRELESS INC.
To: WHITEHORSE CAPITAL ORIGINATION, LLC
Reel/Frame 075362/0959 →
SECURITY INTEREST Recorded Jul 21, 2026
From: WHITEHORSE CAPITAL MANAGEMENT, LLC
To: KORE WIRELESS GROUP INC.
Reel/Frame 075348/0522 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: TWILIO INC.
To: KORE WIRELESS GROUP INC.
Reel/Frame 065772/0805 →
SECURITY INTEREST Recorded Nov 15, 2023
From: KORE WIRELESS GROUP INC.
To: WHITEHORSE CAPITAL MANAGEMENT, LLC
Reel/Frame 065574/0807 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2023
From: TWILIO INC.
To: KORE WIRELESS GROUP, INC.
Reel/Frame 071393/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2023
From: TWILIO INC.
To: KORE WIRELESS GROUP, INC.
Reel/Frame 063896/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2022
From: HARTLEY, PETER; MICHAELSON-YEATES, PHILIP; WILLIAMS, JONATHAN; FIENNES, HUGO; PATIL, TEJAS; BIRR-PIXTON, JOSEPH
To: TWILIO INC.
Reel/Frame 058584/0253 →
Continuity (1)
Related Publication 20230176857A1 · Jun 8, 2023
Cited By (1)
US 12,210,865