Secure Firmware Update Console for Multi-Chip Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic apparatuses require separate update tools and data transmission paths for each integrated circuit chip, leading to information security vulnerabilities if one chip lacks a secure update engine.
Innovation Solution
An electronic apparatus with a secure firmware update console in one integrated circuit chip that performs verification and update procedures for multiple non-volatile memory chips, using a spare data storage space and common buses like SPI and I2C for secure firmware updates across all chips, even if they don't have a secure update engine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate update tools and data transmission paths are used for each integrated circuit chip, then each chip can be updated independently, but information security vulnerabilities arise if one chip lacks a secure update engine
Solution Approach 1:
The first integrated circuit chip is designed with a universal secure firmware update console that can update firmware for multiple different integrated circuit chips (first chip, second chip, third chip) through a unified interface. This single console performs verification and update operations for all chips, eliminating the need for separate update tools for each chip while maintaining security standards.
Solution Approach 2:
The spare data storage space in the first non-volatile memory chip serves as an intermediary for storing firmware update data before verification and execution. This intermediary storage mechanism allows secure temporary holding of update data, enabling the secure firmware update console to verify and execute updates across multiple chips without exposing security vulnerabilities.
2Productivity
If multiple separate firmware update processes are performed for different integrated circuit chips, then each chip's firmware can be updated, but the update process becomes complex and time-consuming
Solution Approach 1:
Multiple separate firmware update processes are merged into a single unified update operation. The secure firmware update console in the first integrated circuit chip handles verification and execution of firmware updates for all integrated circuit chips simultaneously through a common data transmission path, significantly reducing the time required compared to sequential separate updates.
Solution Approach 2:
Firmware update data is pre-loaded into the spare data storage space of the first non-volatile memory chip before verification and execution. This preliminary action allows the update data to be readily available in a secure intermediate location, enabling faster verification and execution processes across multiple chips without repeated data retrieval operations.
3Reliability
If each integrated circuit chip is provided with its own secure update engine, then each chip achieves secure firmware update, but the overall system complexity increases
Solution Approach 1:
Instead of providing separate secure update engines in each integrated circuit chip, a single universal secure firmware update console is implemented in the first integrated circuit chip. This console performs verification and update operations for all chips in the system, reducing overall system complexity while maintaining secure update capabilities across all integrated circuit chips.
Data Source
AI summary
An electronic apparatus and a secure firmware update method thereof are provided. The electronic apparatus includes a first integrated circuit chip, a first non-volatile memory chip, a second integrated circuit chip and a second non-volatile memory chip. The first integrated circuit chip includes a secure firmware update console, and the first non-volatile memory chip includes a spare data storage space. The first non-volatile memory chip and the second non-volatile memory chip store a first firmware code of the first integrated circuit chip and a second firmware code of the second integrated circuit chip, respectively. Firmware code update data are transferred to and stored in the spare data storage space. The secure firmware update console performs a firmware update procedure by writing the firmware code update data into the second non-volatile memory chip to overwrite the second firmware code after passing a verification procedure on the firmware code update data.


