Secure Over-the-Air Firmware Upgrade via Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded devices face security vulnerabilities during over-the-air firmware upgrades, as malicious parties can access or alter the firmware, compromising its integrity and authenticity.
Innovation Solution
A system that encrypts firmware upgrades using a firmware key and a session key, digitally signs them, and transmits them securely over a controlled channel, ensuring only authorized devices can decrypt and update the firmware, using a server and controller device to manage encryption and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If firmware upgrade is transmitted over-the-air wirelessly, then embedded devices can receive firmware updates without physical connection, but the firmware becomes susceptible to security vulnerabilities including unauthorized access and alteration
Solution Approach 1:
The patent applies preliminary action by encrypting the firmware with a firmware key before transmission, and pre-establishing key encryption keys in both the server and embedded device before the firmware update process begins. This ensures that security measures are in place before the actual firmware transmission occurs, preventing unauthorized access and alteration during over-the-air updates.
Solution Approach 2:
The patent introduces encryption keys as intermediaries between the server and embedded device. The firmware key encrypts the firmware, while key encryption keys protect the firmware key during transmission. These cryptographic intermediaries enable secure communication over wireless channels without requiring physical connection, thus resolving the contradiction between ease of operation and firmware integrity.
2Reliability
If firmware is encrypted and digitally signed, then security and authentication are improved, but the complexity of the firmware update system increases
Solution Approach 1:
The patent reduces system complexity by pre-establishing key encryption keys in both the server and embedded device before the firmware update process. This preliminary setup eliminates the need for complex key exchange protocols during the actual update, simplifying the overall system while maintaining strong authentication and encryption capabilities.
Solution Approach 2:
The embedded device autonomously decrypts the firmware key using its pre-stored key encryption key, and then decrypts the firmware using the decrypted firmware key. This self-service approach eliminates the need for complex external key management systems, reducing overall system complexity while ensuring reliable firmware authentication and security.
Data Source
AI summary
Methods, systems, devices, and apparatuses for securely providing an over-the-air firmware upgrade. The system includes an embedded device configured to receive the firmware upgrade. The system includes a server having a memory configured to store a first key encryption key, the firmware upgrade and a firmware key and having a processor coupled to the memory. The processor is configured to obtain the firmware upgrade, the firmware key and the first key encryption key. The processor is configured to encrypt the firmware upgrade using the firmware key. The processor is configured to encrypt the firmware key with the first key encryption key and transmit the encrypted firmware upgrade and the encrypted firmware key to the embedded device.


