ECU Software Manifest Validation for Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for validating software and calibration files in vehicle electronic control units (ECUs) are insecure, allowing malicious files to be executed due to a window of opportunity between writing presence patterns and integrity checks, and do not ensure all files are properly flashed before allowing execution.
Innovation Solution
A system and method that uses programming manifests with flags in ECU memory to verify the presence and validity of software and calibration files by setting flags after each flash, ensuring all files are properly flashed before allowing the operating software to execute, employing a bootloader that checks these flags upon reset.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If presence patterns are written before integrity check, then validation process can proceed, but security vulnerability exists allowing malicious files to be executed
Solution Approach 1:
The patent applies preliminary action by writing the presence pattern immediately after flashing each file, rather than after all files are flashed. This early validation marker is written before the integrity check occurs, but the bootloader waits to validate until all files are present, eliminating the security window where malicious files could be injected.
Solution Approach 2:
The patent uses feedback by having the bootloader check for the presence pattern of the last file flashed before allowing execution. This feedback mechanism ensures that the flashing process completed successfully and that all files are present and valid, preventing execution with malicious software.
2Ease of operation
If bootloader checks only the last file for presence pattern, then validation is simple, but cannot detect malicious files in previous files
Solution Approach 1:
The patent segments the validation process by requiring presence patterns in every file, not just the last file. Each file contains its own validation marker, allowing the bootloader to verify each segment independently. This ensures that if any single file is malicious or corrupted, it will be detected.
3Adaptability or versatility
If presence patterns are moved in fixed memory increments, then flexibility is improved, but bootloader compatibility is lost
Solution Approach 1:
The patent applies self-service by having each file contain its own presence pattern embedded within it, rather than relying on external markers or fixed memory positions. The bootloader simply searches for these self-contained patterns, making the system adaptable to different memory layouts without requiring bootloader reconfiguration.
Data Source
AI summary
A system and method for verifying that operating software and calibration files are present and valid after a bootloader flashes the files into the memory on a vehicle ECU before allowing the operating software to execute. The ECU memory defines a memory segment for the operating software and the calibration files. A software manifest is provided in a memory slot before the operating software segment in the memory. Likewise, a calibration manifest is provided in a memory slot before the calibration segment in the ECU memory. After the software has been flashed into the ECU memory, a software flag is set in the software manifest memory slot and each time a calibration file is flashed, a calibration flag for the particular calibration file is set in the calibration manifest.


