Gateway-Accessible Memory Partitioning for Secure Firmware Restoration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing control systems for electronically controlled vehicles face safety concerns due to potential software alterations in electronic control apparatuses, which can lead to abnormal operations and lack of secure access to restoration firmware, risking unauthorized use.

Innovation Solution

A memory system with separate storage regions for normal and Shadow-MBR firmware, where the Shadow-MBR region is inaccessible during normal operations but accessible via authentication, stores special and diagnosis firmware for restoration, ensuring secure distribution and use only during restoration modes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If restoration firmware is stored in an accessible storage region, then restoration operations can be performed, but the firmware may be abused during normal operations

Engineering Contradiction:
Improverestoration operation capabilityVSAvoidsecurity of restoration firmware
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The storage device is divided into multiple storage regions: a first storage region accessible during normal operations and a second storage region inaccessible during normal operations. Restoration firmware is specifically stored in the second storage region, separating it from normally accessible firmware. This segmentation ensures that restoration firmware cannot be abused during normal operations while remaining accessible when needed for restoration.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate storage regions are used for normal and restoration firmware, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity of restoration firmwareVSAvoidstorage structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage device is divided into multiple storage regions: a first storage region accessible during normal operations and a second storage region inaccessible during normal operations. Restoration firmware is specifically stored in the second storage region, separating it from normally accessible firmware. This segmentation ensures that restoration firmware cannot be abused during normal operations while remaining accessible when needed for restoration.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If all firmware is stored in one accessible region, then access is simple, but unauthorized use of restoration firmware becomes possible

Engineering Contradiction:
Improvefirmware access simplicityVSAvoidunauthorized restoration firmware use
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The storage device is divided into multiple storage regions: a first storage region accessible during normal operations and a second storage region inaccessible during normal operations. Restoration firmware is specifically stored in the second storage region, separating it from normally accessible firmware. This segmentation ensures that restoration firmware cannot be abused during normal operations while remaining accessible when needed for restoration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication to determine whether to access the second storage region. The controller is configured to transmit firmware from the second storage region only when specific authentication is successful, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11494104B2Memory system with accessible storage region to gateway
Publication Date: 2022.11.08 KIOXIA CORP
  • US11494104B2 patent drawing
  • US11494104B2 patent drawing
  • US11494104B2 patent drawing

AI summary

A memory system comprising a first storage region which stores first firmware corresponding to an external first electronic control apparatus; a second storage region which stores second firmware corresponding to an external gateway and third firmware corresponding to the first electronic control apparatus; and a controller configured to transmit the second firmware and the third firmware to the gateway on the basis of a first command received from the gateway, and transmit the first firmware to the gateway on the basis of a second command received from the gateway.