Firmware Verification and Automatic Recovery in Image Processors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Image forming apparatuses face significant downtime due to firmware tampering, which existing recovery techniques are not effectively addressing, especially since high-performance firmware requires large capacity storage, increasing costs and making automatic recovery during firmware updates challenging.

Innovation Solution

An image processing apparatus with a first verification unit to validate the common parts of firmware and a restoration unit to automatically restore the common parts using non-active firmware, minimizing downtime and reducing storage costs by utilizing existing, valid firmware for recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware verification is performed to prevent tampering, then security is improved, but apparatus downtime increases when firmware is compromised

Engineering Contradiction:
Improvefirmware securityVSAvoidapparatus downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent stores multiple versions of firmware (current firmware and previous firmware) in advance within the apparatus. When tampering is detected, the system can immediately switch to the previous firmware version without waiting for recovery operations, thereby reducing downtime while maintaining security through verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables automatic recovery of the firmware system by switching from the compromised current firmware to the intact previous firmware version. This recovery mechanism restores the apparatus to a known good state without requiring manual intervention or external repair equipment.

Inventive Principle:
Principle #34Discarding and recovering

2Loss of time

If automatic firmware recovery function is added, then downtime is reduced, but device complexity increases

Engineering Contradiction:
Improvefirmware recovery timeVSAvoidfirmware management complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent combines the firmware verification function and firmware recovery function into a unified system. The same firmware storage area that stores multiple versions also serves as the recovery mechanism, eliminating the need for separate recovery hardware or complex external recovery procedures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The apparatus performs self-diagnosis and self-recovery by automatically detecting firmware tampering and switching to the previous valid version without external intervention. The system manages its own firmware lifecycle, reducing the need for complex external management systems.

Inventive Principle:
Principle #25Self-service

3Ease of repair

If multiple firmware versions are stored for recovery, then recovery capability is improved, but storage capacity requirements increase

Engineering Contradiction:
Improvefirmware recovery capabilityVSAvoidstorage capacity
Core Design Contradiction:
Ease of repairVSQuantity of substance

Solution Approach 1:

The patent segments the firmware storage into distinct areas for different firmware versions (current firmware and previous firmware). This segmentation allows the system to store only the necessary previous version without requiring excessive storage capacity, as each version is stored as a discrete, manageable unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a strategy where the current firmware can be discarded (replaced) with the previous firmware version when tampering is detected. This approach requires storing only one previous version rather than multiple versions, significantly reducing the total storage capacity requirement while maintaining effective recovery capability.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS11106797B2Data processing apparatus, image processing apparatus and method for verifying and restoring operating system in activation mode
Publication Date: 2021.08.31 CANON KK
  • US11106797B2 patent drawing
  • US11106797B2 patent drawing
  • US11106797B2 patent drawing

AI summary

Provided is a data processing apparatus including: a storage unit that stores a first operating system (OS), a first application program executed after the first OS, a second OS, and a second application program executed after the second OS; and at least one processor configured to, in a first activation mode, verify the first OS, execute the first OS, and then execute the first application program, and, in a second activation mode, verify the second OS, execute the second OS, and then execute the second application program, in which the at least one processor is further configured to restore the first OS, in a case where it is determined on the verification of the first OS that the first OS is not valid, with use of the second OS.