In-Vehicle Firmware Update Control with Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In in-vehicle networks, ensuring the proper update of firmware across terminals connected through a network bus is challenging due to security vulnerabilities and the lack of comprehensive security measures, which can lead to improper update recognition and failure in updating functions or countermeasures against vulnerabilities.

Innovation Solution

An update control apparatus with first and second communication circuits and a processor that receives update data from a server, transmits it to terminals, and verifies the update result using verification data, such as message authentication codes or digital signatures, to ensure proper firmware updates, and manages the state of the vehicle based on update success or failure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If firmware updates are transmitted through an in-vehicle network without comprehensive security measures, then update speed and ease of operation are improved, but security reliability deteriorates due to potential improper update recognition and vulnerability

Engineering Contradiction:
Improvefirmware update processVSAvoidupdate security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The update control apparatus performs preliminary verification of update results before considering the update successful. It receives update results from terminals and verifies them against expected values in advance of finalizing the update process, preventing improper update recognition from compromising system security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where terminals report update results back to the update control apparatus, which then verifies these results against predetermined expected values. This closed-loop feedback ensures that updates are properly recognized and security is maintained while allowing easy update operations.

Inventive Principle:
Principle #23Feedback

2Reliability

If verification mechanisms are added to ensure proper firmware updates, then security reliability is improved, but device complexity increases due to additional communication circuits and verification processes

Engineering Contradiction:
Improveupdate verificationVSAvoidupdate control apparatus structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The update control apparatus integrates multiple functions into a single device: it manages firmware distribution, receives update results from terminals, verifies update outcomes against expected values, and controls the overall update process. This multi-functionality reduces the need for separate specialized components, limiting the increase in device complexity while maintaining high reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The update control apparatus serves as an intermediary between the external server and the in-vehicle terminals. It receives firmware from the server, distributes it to terminals, and verifies update results before confirming successful updates. This intermediary role centralizes the verification logic in a single component rather than requiring complex verification mechanisms in each terminal, thus improving reliability without proportionally increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10360018B2Update control apparatus, software update system, and update control method
Publication Date: 2019.07.23 KK TOSHIBA
  • US10360018B2 patent drawing
  • US10360018B2 patent drawing
  • US10360018B2 patent drawing

AI summary

According to an embodiment, an update control apparatus is to control update of software in a terminal connected to a network. The update control apparatus includes a first communication circuit, a second communication circuit, and a processor. The first communication circuit is configured to communicate with a server located outside the network. The second communication circuit is configured to communicate with the terminal through the network. The processor is configured to: receive update data to update the software from the server using the first communication circuit; transmit the update data to the terminal, as well as receive an update result indicating whether update of the software has succeeded, together with verification data, from the terminal using the second communication circuit; and verify, using the verification data, whether the update result is proper data.