Appliance Boot Loader Access Control Using Remote Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial appliances with external communication ports, such as RJ45 connections, are vulnerable to unauthorized access, posing a security risk in public or shared environments where users may attempt to tamper with or update firmware without proper authorization.

Innovation Solution

Implementing a system with a wireless communication module that connects to a remote server to regulate access to the appliance's boot loader segment, requiring owner approval before allowing access, thereby preventing unauthorized manipulation of the operating software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If an external communication port (RJ45) is provided for firmware updates, then ease of repair and software updates are improved, but security vulnerability increases allowing unauthorized access

Engineering Contradiction:
Improvefirmware update capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authorization system between the external communication port and the boot loader. When an update request is received, the system sends a notification to a remote server which verifies authorization credentials before granting access. This intermediary layer allows legitimate firmware updates while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization verification before allowing access to the boot loader. The notification is sent to the remote server in advance of the actual firmware update process, and access is granted only after receiving authorization confirmation. This preliminary check prevents unauthorized users from directly accessing the boot loader.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If public access to RJ45 port is allowed for convenience, then ease of operation is improved, but reliability decreases due to tampering risks

Engineering Contradiction:
Improveaccessibility for updatesVSAvoidsystem integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The remote server acts as a mediator that receives update requests from users and verifies their authorization status before allowing communication with the boot loader. This maintains ease of operation by accepting public requests while ensuring reliability through centralized authorization verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where the remote server responds to update requests with authorization decisions. The controller receives feedback from the server indicating whether the requested access should be permitted or denied, enabling dynamic control over port accessibility based on verified credentials.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If boot loader access is restricted to prevent tampering, then security is improved, but ease of repair worsens requiring complex authorization procedures

Engineering Contradiction:
Improvetampering preventionVSAvoidauthorized update process
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The remote server serves as an automated intermediary that handles authorization verification for authorized personnel. While physical access to the port remains restricted, the intermediary system streamlines the authorization process for legitimate users, maintaining security without unduly complicating the repair process for authorized technicians.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11985502B2System and method for seeking owner authorization for an appliance to enter a boot loader for a software update
Publication Date: 2024.05.14 HAIER US APPLIANCE SOLUTIONS INC
  • US11985502B2 patent drawing
  • US11985502B2 patent drawing
  • US11985502B2 patent drawing

AI summary

An appliance includes an external communication port, such as an RJ45 port, and a wireless communication module in wireless communication with a remote server through an external network. In addition, a controller includes a boot loader segment and is configured to receive a request to access the boot loader segment of the controller, transmit a notification of the request to the remote server using the wireless communication module, receive an access determination from the remote server, e.g., such as an access authorization or denial from an owner, and regulate access to the boot loader segment based at least in part on the access determination.