Secure IC Update Circuit with Write-Protected Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT devices and similar systems with tightly-integrated chip sets are vulnerable to undesirable modifications and attacks, particularly due to their ability to be reconfigured externally, which can compromise their operational security and integrity.
Innovation Solution
The implementation of secure update mechanisms for integrated circuits, involving circuit arrangements that allow an application circuit to access an external network while a non-volatile configuration memory is write-protected, and a reset-boot circuit that resets and boots the application circuit, disabling external network access for updates, ensuring the resilience of the recovery image.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the configuration memory is made writable to enable updates, then the device can receive OTA updates, but the device becomes vulnerable to unauthorized modifications and attacks
Solution Approach 1:
The memory system is segmented into secure configuration memory (protected from writes) and updateable storage areas. The configuration memory is divided into read-only configuration data and separate update targets, allowing updates without compromising the integrity of protected configuration regions.
Solution Approach 2:
A secure boot loader and verification mechanism act as intermediaries between the external update source and the configuration memory. These intermediaries validate update authenticity and control the write process, preventing direct unauthorized writes to protected memory regions.
2Ease of operation
If external network access is enabled for device management, then OTA updates can be deployed, but the communication stack becomes a target for attacks
Solution Approach 1:
The verification and validation functions are extracted from the vulnerable communication stack and placed in the secure boot loader that operates with restricted network access. This separates the update reception function from the critical verification function, protecting the latter from network-based attacks.
3Adaptability or versatility
If the device allows reconfiguration through internal ports, then functionality can be extended, but unintended alterations may occur
Solution Approach 1:
Configuration data is signed and verified in advance by a trusted authority before being loaded into the device. The secure boot loader performs preliminary verification of configuration integrity before applying any reconfiguration, preventing unintended alterations from occurring during runtime.
Data Source
AI summary
One example securely updates an integrated circuit to mitigate undesirable modifications and this involves an application circuit accessing an external network while a (e.g., nonvolatile) program memory is write protected; and a reset-boot circuit resetting and booting the application circuit while access to the external network is disabled, and causing an update for the application circuit. In response to an indication that an update is downloaded for installation, the downloaded update is installed in the memory while access to the external network is disabled, and execution of the reset mode is permitted after the update is installed. Also, a retrieval module may download, in response to an indication that an update is not downloaded, an update provided via the external network while the memory is write-protected and thereby permitting execution of the reset mode after the update is downloaded.


