An OTA update (over-the-air update) refers to the remote updating of connected controllers, data loggers, gateways, or other devices. Software or firmware components are transferred and installed via a network connection. This normally eliminates the need for an on-site service visit.
OTA Updates at a Glance
- OTA updates allow individual devices or an entire device fleet to be updated remotely.
- Before installation, the device should verify the compatibility, integrity, and origin of the update package.
- Recovery mechanisms can prevent a faulty update from permanently disabling the device.
- In energy management, OTA updates can fix errors, close security vulnerabilities, and expand functionality.
How Does an OTA Update Work?
A central update system provides an approved software or firmware package for selected devices. Depending on the system architecture, the device retrieves the update independently, or the installation is initiated centrally. Distribution can be limited to an individual project, tested with a pilot group, or gradually rolled out across a larger device fleet.
The controller downloads the package via an available network connection. Before installation, the device checks whether the intended version is compatible with the installed hardware and the current software version. Checksums are primarily used to detect transmission errors and unintended modifications. Digital signatures can additionally confirm the origin and integrity of the package.
Installation may only begin after the package has been transferred completely and successfully verified. Depending on the scope of the update, individual services or the entire device may need to restart. The controller should then report its status, installed version, and update result to the central system. An additional functional check can verify that communication, data acquisition, and local control functions are operating correctly again.
Where Are OTA Updates Used in Energy Management?
OTA updates can correct software errors, update security components, and extend existing functions. They can also provide new or revised communication interfaces for inverters, energy meters, battery storage systems, and other devices.
Project-specific software components can also be adapted on controllers with active control functions. These may include communication processes or local EMS functions. Each update must remain compatible with the technical and operational requirements of the respective site.
Security, Failure Protection, and Technical Requirements
Update packages and transmission paths must be protected against manipulation and unauthorized access. Suitable measures can include encrypted connections, secure device authentication, digitally signed packages, and defined access rights.
An interrupted download must not damage the existing software. The update package can be discarded or the transfer can be resumed later. However, installation may only begin after the package has been transferred completely and successfully verified.
If an installation fails, a rollback to the previous functional version should be possible. Devices with redundant system partitions, also known as A/B partitions, can install the new version separately from the existing version. If the update fails, the device can restart from the previous partition.
Controllers performing active control tasks have additional requirements. Critical control and safety functions must not fail in an uncontrolled manner during an update. Depending on the project, maintenance windows, safe fallback values, local fallback mechanisms, or redundant functions may be required.
An OTA update must be distinguished from remote configuration. Remote configuration normally changes operating parameters such as limits or operating times. An OTA update modifies software or firmware components. However, new configuration files may still form part of an update package.
OTA Updates with EcoPhi
EcoPhi can update controllers and data loggers remotely. This allows software components, device integrations, communication functions, or project-specific control logic to be adapted without visiting every site.
This can reduce the effort required for maintenance and further development, particularly for internationally distributed systems. The timing, approval process, update scope, and potential operational interruptions must be coordinated with the individual project. The specific implementation depends on the hardware used, the available network connection, and the criticality of local control functions.
Conclusion
OTA updates enable connected devices to be updated remotely. Reliable implementation requires protected transmission paths, verified update packages, clear status messages, and suitable recovery mechanisms.
Frequently Asked Questions About OTA Updates
Does an OTA update require an internet connection?
The device requires an accessible network connection to the update system. This can be established via Ethernet, Wi-Fi, cellular connectivity, a private network, or the internet.
What happens if the download is interrupted?
An interrupted download can be discarded or resumed later. The package may only be installed after it has been transferred completely and successfully verified.
Is an OTA update the same as remote configuration?
No. Remote configuration normally changes operating parameters. An OTA update modifies the device’s software or firmware components.
Can OTA updates be installed automatically?
Automatic installation is technically possible. However, approvals, maintenance windows, and potential effects on plant operation should be considered for devices with control-related functions.
