Mechanism
A firmware update originates with a deploying authority that publishes it as a governed observation. The governed observation carries the firmware version, the firmware content, the deploying authority's signature, and an applicability-scope specification identifying the devices eligible to receive the update. The same publication pattern serves governance-policy updates and skill-adapter updates; firmware updates follow it with the addition of a sandbox-evaluation operation at the receiver.
The governed observation propagates through the governed mesh by multi-hop relay and by mobile store-and-forward carriage, the latter allowing the update to reach regions of sparse or intermittent connectivity: an update emitted at an ingress point is carried by operating units traversing the sparse-connectivity region and rebroadcast upon entry into the signaling volume of a receiving device. Where the message is broadcast over lossy links, it may be carried under a forward-error-correction scheme so that a receiving device reconstructs the source message from any subset of encoded symbols exceeding a reconstruction threshold, regardless of which specific encoded symbols are received and without channel feedback or coordination with the transmitter.
At each receiving device, the governed observation is evaluated through the composite admissibility evaluator. The evaluator verifies the authority credential of the deploying authority, weighs the evidential weight assigned to that authority under the receiving device's authority taxonomy, and checks the consistency of the update with the receiving device's prior state. For a firmware update, the receiving device additionally evaluates the update in a sandboxed execution environment to verify that it does not violate governance-policy-defined safety, integrity, or capability-envelope properties. A firmware update that fails sandbox evaluation is not applied and is recorded in the receiving device's lineage field together with the sandbox-evaluation output.
On admission, the receiving device atomically transitions from the prior state to the updated state. A rollback mechanism enables reversion to the prior state upon detection of admission failure or upon receipt of a subsequent revocation governed observation. The update event and the device's transition between versions are recorded in the receiving device's lineage field.
Propagation and Admission
The deploying authority is the source of evidential weight, not a transport dependency: the mechanism does not require each receiving device to establish a connection to a centralized distribution server, to carry an out-of-band credential for such a server, or to depend on out-of-band connectivity infrastructure. Any path through the governed mesh that delivers the governed observation suffices, including paths that pass through relays the deploying authority does not control, because admission is decided by the credential the observation carries rather than by the path it traveled.
Propagation is hierarchical and scope-specific. A policy update issued by a higher-authority deploying authority supersedes a conflicting state established by a lower-authority deploying authority under the supersession semantics of the disclosure. The applicability-scope specification may name a geographic scope, a temporal scope, a device-class scope, or a combination, limiting application of the update to receiving devices within the specified scope.
Where forward-error-correction is used for disconnected broadcast, the scheme is selectable in accordance with signaling-medium characteristics. The disclosure contemplates, without limitation, rateless erasure codes such as Luby Transform, Raptor, and RaptorQ codes, fixed-rate erasure codes operated with a redundancy margin, repetition codes, network codes, timed re-broadcast schemes, and hybrids of these. The common property required of any such scheme is partial-receive-and-reconstruct: a receiving device reconstructs the source from any sufficient subset of encoded symbols.
Alternative Embodiments
A first embodiment carries the governed observation under a rateless erasure code such as a Luby Transform, Raptor, or RaptorQ code, allowing a receiving device to reconstruct the update from an unbounded sequence of encoded symbols once accumulation exceeds the reconstruction threshold. A second embodiment uses a fixed-rate erasure code operated with a redundancy margin sufficient to satisfy the partial-receive-and-reconstruct property within expected channel loss rates. A third embodiment uses repetition or timed re-broadcast so that a receiving device transiting the transmitter's signaling range captures at least one instance of each source block.
A fourth embodiment carries the update through mobile store-and-forward, in which operating units traverse a sparse-connectivity region and rebroadcast the update upon entry into the signaling volume of a receiving device. A fifth embodiment applies scope-specific propagation, in which the applicability-scope specification names a geographic, temporal, or device-class scope, or a combination, limiting application to receiving devices within that scope.
A sixth embodiment applies hierarchical propagation, in which a higher-authority update supersedes a conflicting state established by a lower-authority deploying authority under the supersession semantics of the disclosure. A seventh embodiment governs governance-policy updates by the same publication, propagation, admission, and lineage pattern as firmware, with the policy-application operation transitioning atomically between policy versions.
An eighth embodiment governs skill-adapter updates by the same pattern, with the addition of the adapter-sandboxing mechanism prior to adapter activation. A ninth embodiment subjects a firmware update to sandbox evaluation against governance-policy-defined safety, integrity, and capability-envelope properties before application, recording a failed evaluation in the lineage field together with the sandbox-evaluation output. A tenth embodiment provides rollback to the prior state upon detection of admission failure or upon receipt of a subsequent revocation governed observation.
Composition With Other Primitives
The mechanism composes with the governed-observation primitive at every layer: the update is published as a governed observation, it propagates as a governed observation, and the update event is recorded in the device's lineage field. The mechanism composes with the composite admissibility evaluator of the mesh: the same evaluator that gates ordinary observations also gates an incoming update, so an adversary who controls a relay can carry update traffic but cannot fabricate the authority credential it must carry to be admitted.
The mechanism composes with the confidence-governed actuation mechanism when the update is itself a governance-policy update, because the same publication, admission, and atomic-application pattern that supervises a firmware update also supervises a live policy transition, with rollback to the prior policy state on admission failure or revocation. The mechanism composes with the lineage primitive: a device's update history is a chain of recorded transition events, each recorded in the lineage field, and the chain is auditable by any party that holds the deploying authority's public credential.
Prior-Art Distinctions
The disclosure distinguishes the mechanism from prior centralized firmware-update mechanisms and prior centralized policy-distribution mechanisms. The mechanism does not require each receiving device to establish a connection to a centralized distribution server, does not require each receiving device to carry an out-of-band credential for a distribution server, and does not depend on out-of-band connectivity infrastructure for the propagation of updates. Any path through the governed mesh suffices for delivery, because admission is decided by the authority credential the governed observation carries rather than by the path it traveled.
The mechanism additionally supports propagation into regions of sparse or intermittent connectivity through mobile store-and-forward carriage: an update emitted at an ingress point is carried by operating units traversing the sparse-connectivity region and rebroadcast upon entry into the signaling volume of a receiving device in that region. Admission remains an act of the receiving device's own composite admissibility evaluator, and for a firmware update of its own sandbox evaluation, rather than an act of trust in the channel or the relay set that carried the update.
Disclosure Scope
The disclosure covers the mesh-distributed propagation of governance-policy updates, firmware updates, and skill-adapter updates as governed observations; the policy-publication, policy-propagation, policy-admission, policy-application, and policy-lineage operations; the sandbox-evaluation operation that gates firmware updates and the adapter-sandboxing operation that gates skill-adapter updates; the atomic transition between versions and the rollback mechanism on admission failure or revocation; the multi-hop relay and mobile store-and-forward carriage paths; hierarchical and scope-specific propagation; and the forward-error-correction schemes, including rateless erasure codes, by which an update may be carried over lossy disconnected broadcast.
This disclosure appears in U.S. Provisional Application No. 64/049,409, which situates this primitive among the spatial-mesh substrate cluster. The primitive is not limited to any particular device class. It applies to vehicles, drones, robots, sensors, industrial controllers, and any other field-deployed device that today depends on centralized over-the-air infrastructure to remain current.
The mechanism does not depend on an out-of-band distribution channel: the deploying authority supplies the evidential weight that admits an update, and any path through the governed mesh that delivers the governed observation, including a path through relays the deploying authority does not control, suffices. Each receiving device admits an update through its own composite admissibility evaluator, and a firmware update additionally through its own sandbox evaluation, so admission scales across a single receiving device and across many receiving devices uniformly.