RELIABLE EMBEDDED SOFTWARE DISTRIBUTION SYSTEM AND METHOD
Patent Information
- Authority / Receiving Office
- TR · TR
- Patent Type
- Patents
- Current Assignee / Owner
- ROKETSAN ROKET SANAYI & TICARET ANONIM SIRKETI
- Filing Date
- 2023-12-20
- Publication Date
- 2026-06-22
Smart Images

Figure 00000008_0000 
Figure 00000008_0001
Abstract
Description
1 TARIFF RELIABLE EMBEDDED SOFTWARE DISTRIBUTION SYSTEM AND METHOD The technical field to which the invention relates: The invention allows for the confidentiality and integrity of embedded software / firmware to be maintained until it is deployed to the target environment. It relates to the embedded software distribution system and method that provides protection up to that point. 5 The invention specifically concerns the platform for deploying embedded software / firmware. This relates to storing files in encrypted form within the file system. State of the art: When software / firmware developed for embedded systems is deployed to the embedded system, the relevant Since remote access to the system is not possible, on-site deployment is required. Therefore, 10 Deployment requirements, which can vary depending on the embedded system, are relevant to the system. When physically nearby, it is greeted by scripts specifically developed for the system. Embedded After the software / firmware reaches the distribution platform, it is applied to the system on the platform. Software distribution is carried out by running specially designed scripts. At this point 15 used for transferring software / firmware to the distribution platform The electronic environment and the distribution platform it is located on cause a security vulnerability. It is possible. The invention, which is the subject of application number “CN218068848”, in the prior art. by protecting the confidentiality of the software on an embedded system where it is distributed It is related. The invention involves 20 units of persistent memory on the embedded system after the software is distributed. It aims to protect the software found. Therefore, during the distribution process... It does not offer a solution regarding the security of the software. The invention, which is the subject of application number “CN101950344”, in the prior art. It is particularly concerned with encryption and decryption methods of embedded software programs. Illegal or malicious modification of software programs or software programs 25 An embedded software program encrypts and decrypts files to prevent them from being read from memory. This method is related to the fact that this system ensures the confidentiality of embedded software from the beginning of the deployment process. 2 a guarantee that it will be preserved until the end and that records related to this process will be kept. It does not offer a solution. The previous technique involved secure software for platforms communicating over a network. There are systems built to facilitate transmission. However, embedded The compiled file or files of the software are encrypted and stored in a secure storage environment. 5 the acquisition, ensuring its protection in encrypted form until it is distributed to the target, and remotely capable of deploying embedded software to embedded systems that are inaccessible. A system not included in the previous technique. In conclusion, due to the negative aspects described above and the current solutions, the subject matter... Due to its inadequacy, there is a need for a new technology in the relevant technical field. 10 It is heard. Brief Description and Objectives of the Invention The invention allows for the confidentiality and integrity of embedded software / firmware to be maintained until it is deployed to the target environment. It is related to its protection. The main purpose of the invention is to enable different operating systems and various electronic infrastructures. 15 embedded systems that use complex dependencies Its purpose is to ensure the secure distribution of software / firmware. Another purpose of the invention is to enable access to different embedded systems. This this allows access to different embedded systems, which are specifically developed for these systems. This eliminates the need for access with different scripts and provides this access to embedded systems 20 It standardizes for this purpose. Another purpose of the invention is to facilitate the distribution of embedded software / firmware. This ensures that the files are stored encrypted within the platform's file system. The use of encrypted software / firmware files in distribution is only permitted for those with access authorization. This can be done with the correct key provided to the person. 25 Another objective of the invention is to provide the user with the relevant embedded data in proportion to the rights granted to them. After the software / firmware deployment process to the target environment has been successfully completed The embedded software / firmware will not be accessible again from the platform. Its purpose is to ensure its deletion. 3 Explanation of the Figures: FIGURE 1: Downloading, encrypting, and authorizing access to embedded software / firmware. The flow showing the transfer of the key to the owner. FIGURE 2: Embedded software / firmware after the person with access receives the key Flowchart 5 shows how to deploy to the embedded system. Reference numbers: 110. Interface component 120. Secure file server 130. Adaptive module 140. Platform file system 10 150. Management module 160. Secure communication tool 170. Person authorized to access 180. Communication module 190. Embedded system (Target environment) 15 Detailed Description of the Invention The invention creates a complex system using different operating systems and various electronic infrastructures. secure deployment of software / firmware for embedded systems with dependencies It is a system and method that provides this. The system / method described in the invention enables the distribution of embedded software / firmware in 2020. The data is stored encrypted in the file system of the platform that will be implementing it. Encrypted software / firmware files may only be used in distribution by authorized personnel. This can be done with the correct key transmitted to the operator. By decrypting the code, the key is sent to the operator. The relevant embedded software / firmware, to the extent of the given right, uses the appropriate communication module to target. 4 transferring to the environment and deleting embedded software / firmware from the platform file system The process is completed with this. According to the system / method of the invention, the person who has access rights in the first step (170) embedded secure file server (120) via an interface component (110) It makes a software / firmware request. Then this request is sent from the secure file server. (120) is transmitted to the adaptive module (130). Through the adaptive module (130) the relevant Software / firmware files are retrieved, encrypted and saved to the platform file system (140). and is sent to the management module (150) to request the key. Then the management The key is sent to the secure communication device (160) via module (150) and access The person with the authority (170) can send this key via secure communication device (160) 10 images. Then the person with access rights uses the key they obtained in the previous step. via interface component (110) to the adaptive module (130) key setup request It is found. Thanks to the key, the encrypted software adapter in the platform file system (140) module (130) receives and the adapter module (130) decrypts the encrypted software / firmware After making it available for distribution, unencrypted software / firmware can communicate from here 15 The communication module (180) is transferred to the embedded system (target). (190) enables the transfer of the environment and the adapter after the loading job is completed. The installation result is transferred from the module (130) to the interface component (110). Embedded after the software / firmware is deployed to the embedded system (target environment) (190) the software / firmware in question will be disabled from the platform in a way that will prevent further access. It is deleted. In addition, depending on the system / method that is the subject of the invention, the embedded software / firmware is also embedded. The authority to upload to the system (target medium) is granted to the person who has access rights (170) It can be given in limited numbers. All steps of the distribution flow are managed by the management module (150). It is recorded and monitored. The interface component of the system / method in question (110) These can be smart devices such as computers, tablets, and phones. The secure communication tool (160) is 25 It can be an encrypted or unencrypted phone, computer, or tablet.
Claims
REQUESTS 1. The confidentiality and integrity of the embedded software are maintained until it is deployed to the target environment. It is an embedded software distribution system that provides protection; its feature is: - The person with access authorization (170) through an interface component (110) The embedded software / firmware requests at least one secure file. 5 server (120), - Embedded software / firmware request transferred from secure file server (120) As a result, it retrieves, encrypts, and distributes the relevant software / firmware files to the platform. transmit to the file system (140) and request the key from the administration at least one adapter module (130) that transfers to module (150), 10 - The software / firmware from the adaptive module (130) is saved and At least one platform file system that is recalled when requested (140), - The relevant software / firmware files via the adaptive module (130) By encrypting it, you have the authority to access the software / firmware in question. At least one administrator who enables the generation of the key code for the person to access it. 15 module (150), - Authorized to access the key transferred via the management module (150) at least one secure communication device that enables the person (170) to view it. (160), - The person with access rights can use the key obtained in the previous step to access interface 20. It requested key setup via component (110), encrypted At least one adapter that decrypts the software / firmware and makes it distributable. module (130), - Enables the transfer of the software to the embedded system (target environment) (190) and After the loading process is complete, the adaptive module (130) and from there to interface 25 at least one communication module that transmits the installation result to component (110) (180) is to include. 6 2. Maintaining the confidentiality and integrity of the embedded software dependent on Claim 1 in the target environment. It is an embedded software distribution system that ensures its protection until it is deployed. feature; - Interface component (110) for smart devices such as computers, tablets, and phones That is. 5 3. Maintaining the confidentiality and integrity of the embedded software dependent on Claim 1 in the target environment. It is an embedded software distribution system that ensures its protection until it is deployed. feature; - Secure communication device (160) encrypted / unencrypted phone, computer or It is a tablet. 10 4. The confidentiality and integrity of the embedded software are maintained until it is deployed to the target environment. It is an embedded software deployment method that provides protection; its feature is: - The person with access authorization (170) through an interface component (110) Request embedded software / firmware from secure file server (120) its presence, 15 - Embedded software / firmware request from secure file server (120) Transmission to the adaptive module (130), - The relevant software / firmware files via the adaptive module (130) the acquisition, encryption and saving to the platform file system (140) and 20 - Key to secure communication device (160) via management module (150) sending, - The key transmitted to the person with access authorization (170) is secure communication Viewing via the vehicle (160), - The person with access rights can access interface 25 using the key obtained in the previous step. via component (110) to request key installation of the adaptive module (130) being, 7 - Encrypted software in the platform file system (140) thanks to the key the arrival of the adapter module (130) and the encryption of the adapter module (130) After decrypting the software / firmware and making it distributable, the password-free version... Transfer of software / firmware from here to communication module (180), - Through the communication module (180), the software is sent to the embedded system (target 5 (190) transfer / upload, - After the loading process is complete, it goes to the adaptive module (130), and from there to Steps for transferring the installation result to the interface component (110) It includes.
5. This is the embedded software deployment method in Claim 4, and its characteristic is; 10 - Distribution of embedded software / firmware to the embedded system (target environment) (190) After this happens, the software / firmware in question will be removed from the platform again. The process involves deleting the file in a way that makes it inaccessible.
6. This is the embedded software deployment method described in claim 4, and its characteristics are: - All steps of the distribution flow are recorded by the management module (150) 15 It means being monitored and tracked.