Duplex Module Encryption Blob Management for ROM Update Reliability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional information processing apparatuses with duplex systems face challenges in managing Blobs during ROM updates, leading to issues with encryption key retrieval due to hash value mismatches between primary and backup modules, resulting in decryption failures.
Innovation Solution
The apparatus includes primary and backup modules with a value storage unit, encryption information storage, and an update unit that calculates unique values for each module, allowing seamless encryption and decryption, and updates encryption information based on these values, ensuring decryption capabilities even during module updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a duplex system with primary and backup modules is implemented, then system reliability is improved, but management complexity of encryption information increases
Solution Approach 1:
The patent merges the management of encryption information for primary and backup modules into a unified structure. The Blob file contains encryption information that is jointly managed for both modules, eliminating the need to separately manage distinct encryption information sets. This reduces management complexity while preserving the reliability benefits of the duplex system.
Solution Approach 2:
The encryption information storage mechanism is designed to serve multiple functions: it supports both primary and backup modules universally, handles both normal operation and failure recovery scenarios, and manages both encryption and decryption operations through a single unified system. This multi-functionality reduces the overall complexity of managing encryption information across the duplex system.
2Adaptability or versatility
If ROM update is performed on primary or backup modules, then software functionality is improved, but decryption capability may be lost due to hash value mismatch
Solution Approach 1:
The patent performs preliminary actions during the update process by calculating and storing the hash value of the updated module within the Blob file before the actual update is complete. This preliminary preparation ensures that when the update is finalized, the hash value matching can proceed smoothly without losing decryption capability, thus maintaining reliability while enabling software updates.
Solution Approach 2:
The system implements feedback mechanisms where the hash value of the module is continuously verified and compared against the stored value in the Blob file. During updates, this feedback loop allows the system to detect changes and adjust the encryption information accordingly, ensuring that decryption capability is maintained even as software functionality evolves through updates.
3Object-affected harmful factors
If hash value verification is performed for security, then information security is improved, but operation complexity increases
Solution Approach 1:
The system implements self-service mechanisms where the hash value verification process is automatically performed by the system itself without requiring manual intervention. The Blob file structure enables the system to autonomously calculate, store, and verify hash values, maintaining high security standards while keeping operations simple and automated. This reduces operational complexity while preserving the security benefits of hash value verification.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An information processing apparatus, a software update method, and an image processing apparatus capable of encrypting and decrypting information using values uniquely calculated from booted primary modules or booted backup modules with less effort are disclosed. The information processing apparatus includes primary modules and the same kinds of backup modules, and includes a value storage unit storing values calculated from the modules, an encryption information storage unit storing information unique to the modules, an information decryption unit decrypting the information unique to the modules using the values in the value storage unit, and an encryption information update unit , when the module is updated, encrypting the information unique to the modules based on a value calculated from the each kind of the primary modules or the backup modules after the update.