Mobile Device ROM Update Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for mobile devices do not adequately protect against data destruction or disclosure when the device is lost, as binding the SIM card to the device does not prevent data access or reset if the SIM card is lost or destroyed.

Innovation Solution

A method and apparatus for controlling updates to mobile devices by checking and encrypting ROM installation packages, using user and SIM card data to verify the integrity of updates, and terminating installations if errors or unauthorized access are detected, while ensuring updates are only performed when the screen is unlocked, thereby binding the device to the user and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the SIM card is bound to the device for security, then data protection is improved, but the device becomes unusable if the SIM card is lost or destroyed

Engineering Contradiction:
Improvedata protectionVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security binding is segmented into two independent components: SIM card binding and device binding. The device maintains its own independent binding to the user account through check data stored in its memory, separate from SIM card binding. This allows the device to remain usable even if the SIM card is lost, while still maintaining security through the device's own binding mechanism.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If ROM installation packages are allowed without verification, then device updates are simplified, but unauthorized access and data destruction risks increase

Engineering Contradiction:
Improveupdate simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of ROM installation packages by checking digital signatures and validating binding information before allowing installation. This preliminary security check ensures that only authorized updates from the original device owner can be installed, preventing unauthorized access and data destruction while maintaining a relatively simple update process for legitimate packages.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9392441B2Method and apparatus for controlling updates to a mobile device
Publication Date: 2016.07.12 SPREADTRUM COMMUNICATION (SHANGHAI) CO LTD
  • US9392441B2 patent drawing
  • US9392441B2 patent drawing

AI summary

The present invention discloses a method and apparatus for controlling updates to a mobile device consisting of checking a ROM installation package and storing the check data, or encrypting a ROM installation package and storing said encrypted ROM installation package. The stored check data is used to check a ROM installation package or to decrypt a stored encrypted ROM installation package when updating a mobile device. If it is verified to be correct or to be decryptable, the verified or decrypted ROM installation package is installed. If it is verified to have errors or to be undecryptable, the installation of the ROM installation package is terminated. The present invention reduces the risks associated with the destruction or disclosure of data when mobile devices are lost.