Secure Firmware Installation via Bypass Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electronic devices, pre-installed firmware cannot be trusted, leading to potential malicious firmware installation issues where the firmware may ignore updates but report successful installation, compromising device security and functionality.

Innovation Solution

Enabling a firmware update mode that bypasses the device's control logic, allowing a host computer to directly write trusted firmware to the device's storage medium, ensuring secure installation and operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the device uses its current firmware to install new firmware, then the installation process can be performed using existing control logic, but the malicious firmware may ignore updates while reporting successful installation

Engineering Contradiction:
Improvefirmware installation processVSAvoidfirmware update reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a host computer as an intermediary that directly writes firmware to the device's storage medium, bypassing the device's current firmware control logic. This mediator approach ensures that firmware installation is not controlled by potentially malicious existing firmware, thereby preventing the scenario where malicious firmware ignores updates while reporting success. The host computer acts as a trusted third party that can reliably install firmware without being influenced by the device's current firmware state.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a communication channel is enabled to allow direct firmware access, then trusted firmware can be installed by bypassing control logic, but the device must be in a specific update mode

Engineering Contradiction:
Improvefirmware trustworthinessVSAvoidfirmware update mode management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic communication channel that is enabled only when the device is in a specific firmware update mode. This dynamic approach allows the system to switch between normal operation (where the device controls firmware access) and update mode (where the host computer can directly access firmware storage). The mode switching mechanism manages the complexity by confining direct access capability to a controlled state rather than being permanently enabled, thus balancing reliability with complexity.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the host computer directly writes firmware to storage medium, then secure installation is ensured, but the device loses normal control during the process

Engineering Contradiction:
Improvefirmware installation securityVSAvoiddevice control during update
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the firmware installation process into distinct phases: normal operation mode where the device maintains full control, and firmware update mode where direct host access is enabled. During the actual firmware writing operation, the device's normal control is temporarily suspended in favor of host-controlled direct storage access. This segmentation allows the system to maintain ease of operation during normal use while enabling secure installation during updates, as the control transition is confined to a specific operational phase rather than continuously affecting device functionality.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10678529B1Secure device firmware installation
Publication Date: 2020.06.09 AMAZON TECH INC
  • US10678529B1 patent drawing
  • US10678529B1 patent drawing
  • US10678529B1 patent drawing

AI summary

Technologies are provided for bypassing control logic of an electronic device and writing a trusted firmware to a storage location of the device. The device can comprise a bypass communication channel that, when enabled, allows a connected host computer to access a storage medium and/or onboard memory of the device without using the device's control logic. A device controller can be configured to receive a firmware update mode command from a connected host computer and to enable the bypass communication channel. In at least some embodiments, the controller is configured to reject the update mode command unless it is received as part of an initial communication from the host computer during a boot sequence of the electronic device. In a different or further embodiment, the controller is configured to determine that the command is authorized before enabling the bypass communication channel.