eUICC Firmware Update Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firmware update methods for eUICC lack a defined security management mechanism, leading to potential tampering risks due to the absence of eligibility and integrity checks for update installation packages.

Innovation Solution

The proposed method involves an operating system delivery server and a subscription manager data preparation+ server that store and bind digest data with differential installation packages to specific eUICC identities, ensuring mutual authentication and verification of messages to ensure the integrity and eligibility of firmware updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If firmware update is performed without security management mechanism, then update process is simple and fast, but security risk increases due to potential tampering

Engineering Contradiction:
Improvefirmware update speedVSAvoidfirmware integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing security verification of the firmware update package before the actual update installation. The verification process checks the eligibility and integrity of the update package in advance, ensuring that only authenticated and untampered firmware is installed. This preliminary security check prevents potential security risks while maintaining a streamlined update process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security verification is performed on firmware update package, then firmware integrity is ensured, but update process complexity increases

Engineering Contradiction:
Improvefirmware integrityVSAvoidupdate process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the terminal device to autonomously perform security verification of the firmware update package using its own processing capabilities. The terminal device independently checks the eligibility and integrity of the update package without requiring external verification systems, thereby ensuring firmware integrity while avoiding the added complexity of external verification infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If eligibility and integrity checks are performed before firmware update, then security risk is reduced, but update time increases

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by performing selective verification of the firmware update package. Instead of comprehensive exhaustive checking, the system performs targeted eligibility and integrity checks on critical security parameters. This partial verification approach reduces security risks while minimizing the additional time required compared to complete verification processes.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3648487B1Method for updating firmware and related apparatus
Publication Date: 2022.06.01 HUAWEI TECH CO LTD
  • EP3648487B1 patent drawingFigure 1
  • EP3648487B1 patent drawingFigure 2
  • EP3648487B1 patent drawingFigure 3

AI summary

A firmware update method and a related apparatus are provided. The method includes: receiving a first message sent by an update server, where the first message includes first data and a signature of the first data; verifying the first message, and after the first message is successfully verified, obtaining digest data included in the first data, where the digest data includes digest information of a differential installation package between a first installation package and a second installation package, and the digest data further includes at least one of digest information of the first installation package or digest information of the second installation package; receiving a second message sent by the update server, where the second message includes the differential installation package; and verifying the digest data, and after the digest data is successfully verified, updating firmware of an eUICC based on the differential installation package; where the first installation package is an installation package corresponding to a current firmware version, and the second installation package is an installation package corresponding to an updated firmware version. Embodiments of this application can ensure security of an eUICC firmware update to some extent.