Firmware Verification Control for Image Processing Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing image processing apparatuses struggle to efficiently verify firmware across multiple stages, leading to prolonged activation times regardless of security settings validity.
Innovation Solution
An image processing apparatus is designed with one or more storages to hold first and second firmware, along with a verification program. The apparatus includes controllers that determine verification enablement based on security settings and use the successfully verified first firmware to verify the second firmware when valid settings are applied.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware verification is performed for all stages (Boot firmware and Main firmware), then security reliability is improved, but activation time increases
Solution Approach 1:
The patent implements dynamic verification control where the controller determines whether to perform verification of Boot firmware and/or Main firmware based on setting information. This allows the verification process to adapt between different security modes (e.g., full verification when security settings require it, reduced verification when time constraints exist), resolving the contradiction between maintaining high security reliability and reducing activation time.
Solution Approach 2:
The patent changes the verification parameter (verification scope) based on setting information. By modifying which firmware stages are verified (all stages vs. selective stages) according to security settings, the system can adjust the balance between security reliability and activation time without compromising the core security function when needed.
2Reliability
If verification processing is performed regardless of security settings, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent performs preliminary determination of verification enablement based on setting information before actually executing verification processing. The controller first checks whether verification of Boot firmware and/or Main firmware is enabled according to security settings, and only then proceeds with the verification. This preliminary action simplifies the overall processing logic by avoiding unnecessary verification steps and reducing the complexity of the verification processing path.
Solution Approach 2:
The verification processing complexity is dynamically adjusted based on setting information. When security settings indicate that verification is not required, the controller skips verification steps, thereby reducing processing complexity. When security settings require verification, the full verification path is executed. This dynamic approach allows the system to maintain high security reliability when needed while reducing complexity in lower-security modes.
Data Source
AI summary
An image processing apparatus includes: one or more storages, each of which stores first firmware, second firmware differing from the first firmware, and a verification program used to verify presence or absence of falsification of the first firmware; and one or more controllers, each of which determines whether verification of at least the first firmware or the second firmware is enabled based on setting information set according to a security setting on the image processing apparatus. The one or more controllers verify presence or absence of falsification of the second firmware by the first firmware, which has been successfully verified by the verification program, in the case where the setting information is valid, and it is determined that the verification of the second firmware is enabled.


