Dual-Processor Secure Patch Loading for WWAN Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
WWAN communication devices are vulnerable to malicious modifications and attacks, as attackers can block the loading of security patches, leading to increased insecurity and risk of denial of service attacks or device damage.
Innovation Solution
A dual-processor architecture is implemented in WWAN communication devices, where a trusted embedded processor ensures the loading of patches independently of an untrusted application processor, using a patch end signal to prevent attackers from blocking patch updates and ensuring secure firmware updates by encrypting and signing patches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single processor architecture is used in WWAN communication devices, then the device complexity is reduced, but the security and reliability of patch loading is compromised as attackers can block patch loading
Solution Approach 1:
The patent divides the processor into two independent parts: a trusted embedded processor (first processor) and an untrusted application processor (second processor). The first processor independently handles patch loading and verification, while the second processor runs applications. This segmentation ensures that even if the application processor is compromised, the patch loading security remains intact, resolving the contradiction between security and complexity.
Solution Approach 2:
The trusted embedded processor acts as an intermediary between the patch source and the application processor. It receives patches, verifies their authenticity, and loads them independently of the application processor's actions. This intermediary mechanism protects against malicious modifications while maintaining a relatively simple overall architecture.
2Ease of operation
If patch end signal is used to control patch processing, then the ease of operation is improved, but the reliability is reduced as attackers can send fake signals to block patch loading
Solution Approach 1:
The patent implements a feedback mechanism where the trusted embedded processor continuously monitors patch loading status and can independently verify patches before applying them. The patch end signal is generated and validated by the trusted processor, ensuring that only legitimate signals control patch processing. This feedback loop prevents attackers from injecting fake signals while maintaining operational simplicity.
3Adaptability or versatility
If software updates are provided while devices are in the field, then the adaptability is improved, but the vulnerability to malicious modifications increases
Solution Approach 1:
The patent performs preliminary verification of patches before they are applied. The trusted embedded processor verifies patch authenticity and integrity in advance, checking digital signatures and hash values. Only verified patches are loaded and applied by the first processor. This preliminary action ensures that adaptive updates can be provided in the field without introducing malicious modifications, as all patches are pre-validated by the trusted processor.
Data Source
AI summary
The present invention relates methods for patching WWAN (Wireless Wide Area Network) communication devices and corresponding WWAN communication devices, integrated circuit chips and computer-readable media. The WWAN communication device includes a first processor, a second processor and a memory. The first processor is arranged to process patches updating software running on the WWAN communication device. The second processor is arranged to provide a first set of the patches to the first processor. The memory stores a second set of the patches to be processed by the first processor. The second processor is further arranged to send a patch end signal to the first processor, the patch end signal causing the first processor to stop processing of patches provided by the second processor. The first processor is further arranged to process the patches stored in the memory independently of the patch end signal.


