Field Device Firmware Update via Cryptographic Signature Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial installations face challenges in securely updating field device firmware without disrupting measuring operations or introducing unauthorized, potentially harmful software that could compromise security or functionality.

Innovation Solution

A method for authorized firmware updating involves authentication testing using a private key and public key pair, ensuring only signed and approved software can replace existing firmware, with optional additional signing by the manufacturer for enhanced security, allowing partial or complete software updates while preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If firmware updates are allowed without authentication, then updating productivity is improved, but security reliability deteriorates

Engineering Contradiction:
Improvefirmware update speedVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing authentication testing of the firmware signature before allowing the update to proceed. The field device authenticates the signature of the updated firmware using a public key stored in its memory before executing or installing the new firmware. This preliminary authentication step ensures that only authorized firmware can be installed, resolving the contradiction by maintaining security reliability while still enabling updates through the pre-verification process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication testing is performed for all firmware updates, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a signature file as a mediator between the firmware update process and the authentication system. The signature file, which contains the cryptographic signature of the firmware, is authenticated separately from the firmware itself. This intermediary mechanism simplifies the authentication process by decoupling the verification of firmware integrity from the firmware installation, reducing device complexity while maintaining security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If old firmware is completely replaced by new firmware, then adaptability is improved, but risk of harmful factors increases

Engineering Contradiction:
Improvefirmware version adaptabilityVSAvoidrisk of unauthorized firmware
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing signature authentication as a preventive measure before firmware replacement occurs. The field device authenticates the signature of the incoming firmware using a public key stored in its memory before allowing the old firmware to be replaced. This preliminary security check prevents unauthorized or harmful firmware from being installed, thereby counteracting the potential harmful effects of complete firmware replacement while still enabling necessary updates for adaptability.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10402190B2Method for authorized updating of an automation technology field device
Publication Date: 2019.09.03 ENDRESS HAUSER CONDUCTA GMBH CO KG
  • US10402190B2 patent drawing

AI summary

The invention relates to a method for authorized updating of first operating software of a field device which is used in an automation technology installation, wherein an authentication test of second operating software for the field device is performed, which second operating software is signed by means of a first private key associated with the installation, wherein, within the scope of the authentication test, the signature, generated by the first private key, of the second operating software is authenticated by means of a first public key associated with the installation, and wherein, in the event that the authentication test has been performed successfully, the first operating software located on the field device is at least partially replaced by the second operating software.