Gateway-Accessible Memory Partitioning for Secure Firmware Restoration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing control systems for electronically controlled vehicles face safety concerns due to potential software alterations in electronic control apparatuses, which can lead to abnormal operations and lack of secure access to restoration firmware, risking unauthorized use.
Innovation Solution
A memory system with separate storage regions for normal and Shadow-MBR firmware, where the Shadow-MBR region is inaccessible during normal operations but accessible via authentication, stores special and diagnosis firmware for restoration, ensuring secure distribution and use only during restoration modes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of repair
If restoration firmware is stored in an accessible storage region, then restoration operations can be performed, but the firmware may be abused during normal operations
Solution Approach 1:
The storage device is divided into multiple storage regions: a first storage region accessible during normal operations and a second storage region inaccessible during normal operations. Restoration firmware is specifically stored in the second storage region, separating it from normally accessible firmware. This segmentation ensures that restoration firmware cannot be abused during normal operations while remaining accessible when needed for restoration.
2Reliability
If separate storage regions are used for normal and restoration firmware, then security is improved, but device complexity increases
Solution Approach 1:
The storage device is divided into multiple storage regions: a first storage region accessible during normal operations and a second storage region inaccessible during normal operations. Restoration firmware is specifically stored in the second storage region, separating it from normally accessible firmware. This segmentation ensures that restoration firmware cannot be abused during normal operations while remaining accessible when needed for restoration.
3Ease of operation
If all firmware is stored in one accessible region, then access is simple, but unauthorized use of restoration firmware becomes possible
Solution Approach 1:
The storage device is divided into multiple storage regions: a first storage region accessible during normal operations and a second storage region inaccessible during normal operations. Restoration firmware is specifically stored in the second storage region, separating it from normally accessible firmware. This segmentation ensures that restoration firmware cannot be abused during normal operations while remaining accessible when needed for restoration.
Solution Approach 2:
The system performs preliminary authentication to determine whether to access the second storage region. The controller is configured to transmit firmware from the second storage region only when specific authentication is successful, preventing unauthorized access before it can occur.
Data Source
AI summary
A memory system comprising a first storage region which stores first firmware corresponding to an external first electronic control apparatus; a second storage region which stores second firmware corresponding to an external gateway and third firmware corresponding to the first electronic control apparatus; and a controller configured to transmit the second firmware and the third firmware to the gateway on the basis of a first command received from the gateway, and transmit the first firmware to the gateway on the basis of a second command received from the gateway.


