ECU Software Manifest Validation for Secure Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for validating software and calibration files in vehicle electronic control units (ECUs) are insecure, allowing malicious files to be executed due to a window of opportunity between writing presence patterns and integrity checks, and do not ensure all files are properly flashed before allowing execution.

Innovation Solution

A system and method that uses programming manifests with flags in ECU memory to verify the presence and validity of software and calibration files by setting flags after each flash, ensuring all files are properly flashed before allowing the operating software to execute, employing a bootloader that checks these flags upon reset.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If presence patterns are written before integrity check, then validation process can proceed, but security vulnerability exists allowing malicious files to be executed

Engineering Contradiction:
Improvesoftware validation reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by writing the presence pattern immediately after flashing each file, rather than after all files are flashed. This early validation marker is written before the integrity check occurs, but the bootloader waits to validate until all files are present, eliminating the security window where malicious files could be injected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses feedback by having the bootloader check for the presence pattern of the last file flashed before allowing execution. This feedback mechanism ensures that the flashing process completed successfully and that all files are present and valid, preventing execution with malicious software.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If bootloader checks only the last file for presence pattern, then validation is simple, but cannot detect malicious files in previous files

Engineering Contradiction:
Improvevalidation simplicityVSAvoidfile validation completeness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the validation process by requiring presence patterns in every file, not just the last file. Each file contains its own validation marker, allowing the bootloader to verify each segment independently. This ensures that if any single file is malicious or corrupted, it will be detected.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If presence patterns are moved in fixed memory increments, then flexibility is improved, but bootloader compatibility is lost

Engineering Contradiction:
Improvememory layout flexibilityVSAvoidbootloader compatibility
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by having each file contain its own presence pattern embedded within it, rather than relying on external markers or fixed memory positions. The bootloader simply searches for these self-contained patterns, making the system adaptable to different memory layouts without requiring bootloader reconfiguration.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8930710B2Using a manifest to record presence of valid software and calibration
Publication Date: 2015.01.06 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US8930710B2 patent drawing
  • US8930710B2 patent drawing
  • US8930710B2 patent drawing

AI summary

A system and method for verifying that operating software and calibration files are present and valid after a bootloader flashes the files into the memory on a vehicle ECU before allowing the operating software to execute. The ECU memory defines a memory segment for the operating software and the calibration files. A software manifest is provided in a memory slot before the operating software segment in the memory. Likewise, a calibration manifest is provided in a memory slot before the calibration segment in the ECU memory. After the software has been flashed into the ECU memory, a software flag is set in the software manifest memory slot and each time a calibration file is flashed, a calibration flag for the particular calibration file is set in the calibration manifest.