Vehicle Controller Secure Boot Recovery After Firmware Parity Errors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
When an error occurs in the parity bit of a firmware image during the secure boot process of a vehicle controller, the signature inspection fails, preventing the secure boot from being performed, and existing recovery methods are inadequate.
Innovation Solution
A method where a first vehicle controller performs a normal boot and recovers the firmware by internetworking with a second vehicle controller that has successfully completed secure boot, involving the storage of a new firmware image in a different region, verifying hash values, and obtaining a new certificate and private key from the second controller.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure boot is performed with signature inspection, then firmware integrity is protected, but the system cannot boot when parity bit error occurs in firmware image
Solution Approach 1:
The system performs preliminary actions by storing multiple firmware images (A, B, C) and their corresponding signatures in the flash memory before boot operation. When a firmware image suffers a parity bit error, the system can switch to another stored firmware image without requiring external intervention, thus maintaining boot capability while preserving security.
Solution Approach 2:
The patent prepares compensatory measures in advance by maintaining multiple firmware images and signatures in the flash memory. This cushioning mechanism ensures that when one firmware image becomes unusable due to parity bit errors, the system has pre-prepared alternative images to fall back on, preventing complete system failure.
2Ease of operation
If normal boot is performed without signature inspection, then the system can boot despite firmware errors, but firmware security protection is compromised
Solution Approach 1:
The system introduces an intermediary mechanism - a recovery mode that operates between secure boot and normal boot. In this mode, the system can load firmware images without signature verification to recover from errors, but maintains the ability to switch back to secure boot mode, thus mediating between security requirements and operational continuity.
3Ease of repair
If firmware recovery is performed by external intervention, then faulty firmware can be replaced, but system complexity and recovery time increase
Solution Approach 1:
The system implements self-service capability by automatically detecting parity bit errors in firmware images and switching to alternative stored firmware images without requiring external intervention. The microcontroller independently manages the recovery process by selecting valid firmware images from its own flash memory, reducing both complexity and recovery time.
Solution Approach 2:
The patent uses copying by maintaining multiple copies of firmware images (A, B, C) and their signatures within the same flash memory. When one copy becomes corrupted, the system can immediately use another copy, eliminating the need for external firmware sources and simplifying the recovery mechanism.
Data Source
AI summary
In a method and a system for controlling a secure boot of a vehicle controller, when a first vehicle controller performs a normal boot as an error occurs in a parity bit of a firmware image, in the process of performing the secure boot by vehicle controllers related to autonomous driving, the first vehicle controller recovers firmware by internetworking with a second vehicle controller that is successful in the secure boot to perform the secure boot thereafter. The method includes performing, by a first vehicle controller, a normal boot, when the error occurs in the parity bit of the firmware image related to the secure boot, and recovering, by the first vehicle controller, the firmware image by internetworking with the second vehicle controller that is successful in the secure boot.


