Authenticated Firmware Update via Replacement Part

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for performing firmware updates on IoT and fog devices, especially those using low-bandwidth technologies like LoRa, face challenges due to unreliable network links, leading to potential device inactivation and the need for reliable, secure, and identifiable networks for task accomplishment.

Innovation Solution

A method and apparatus for authenticated firmware updates, including upgrades or downgrades, are implemented concurrently with a field update of a component coupled to the device, using a replacement part with a microcontroller unit, trusted execute environment, and storage, ensuring device verification, authentication, and firmware version verification before updating, with mechanisms to restore the device to its original configuration and allow partial updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If over-the-air firmware updates are performed using low-bandwidth technologies like LoRa, then device connectivity is maintained, but update reliability deteriorates due to unreliable network links

Engineering Contradiction:
Improvefirmware update reliabilityVSAvoidupdate mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the cloud server and IoT devices. The gateway receives firmware updates from the cloud, verifies their authenticity, stores them locally, and manages the update process for connected devices. This intermediary approach resolves the contradiction by providing a reliable update mechanism that doesn't depend on continuous cloud connectivity, thereby improving update reliability while keeping the device update mechanism relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary verification of firmware authenticity and device authorization before the actual update process. The gateway verifies firmware signatures and checks device update eligibility in advance, storing verified firmware locally. This preliminary action ensures that when updates are deployed, they are reliable and authorized, resolving the contradiction between update reliability and mechanism complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authenticated firmware updates are implemented with verification mechanisms, then security is improved, but processing time increases due to multiple verification steps

Engineering Contradiction:
Improvefirmware securityVSAvoidupdate processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs firmware authentication and device authorization verification in advance, before the actual firmware update is executed. The gateway verifies firmware signatures and stores authenticated firmware locally, and checks device update eligibility beforehand. This preliminary verification approach improves security while reducing the time required during the actual update process, as the heavy verification work is done beforehand.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service mechanisms where devices automatically verify their authorization status and firmware authenticity without requiring manual intervention. The gateway automatically manages firmware verification, device authorization checks, and update deployment, reducing both processing time and human involvement while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If complete firmware updates are performed, then device functionality is ensured, but network bandwidth consumption increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent enables incremental or partial firmware updates where only specific components or modules of the firmware are updated rather than the entire firmware image. The gateway manages segmented update packages and can apply updates in stages, ensuring device functionality is maintained while significantly reducing the bandwidth consumption compared to complete firmware replacements.

Inventive Principle:
Principle #1Segmentation

4Productivity

If firmware updates are performed in the field, then device availability is maintained, but risk of device inactivation increases due to update failures

Engineering Contradiction:
Improvedevice availabilityVSAvoidupdate success rate
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements backup mechanisms and rollback capabilities before performing firmware updates. The gateway stores backup firmware images and maintains the ability to revert to previous versions if updates fail. This beforehand cushioning approach allows field updates to proceed while mitigating the risk of device inactivation, as failed updates can be recovered without leaving devices in a non-functional state.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The gateway acts as an intermediary that manages the risk of field updates by verifying firmware authenticity, managing update deployment, and providing rollback capabilities. This intermediary layer protects devices from potentially harmful or faulty firmware updates while enabling field updates to proceed, thereby maintaining device availability while improving update success rates through controlled verification and management processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11669322B2Firmware upgrade method and apparatus
Publication Date: 2023.06.06 INTEL CORP
  • US11669322B2 patent drawing
  • US11669322B2 patent drawing
  • US11669322B2 patent drawing

AI summary

A method and apparatus are disclosed for performing authenticated firmware updates of a fog or IoT device, which happens concurrent with a field update of a component coupled to the device, such as a battery.