Secure IC Update Circuit with Write-Protected Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT devices and similar systems with tightly-integrated chip sets are vulnerable to undesirable modifications and attacks, particularly due to their ability to be reconfigured externally, which can compromise their operational security and integrity.

Innovation Solution

The implementation of secure update mechanisms for integrated circuits, involving circuit arrangements that allow an application circuit to access an external network while a non-volatile configuration memory is write-protected, and a reset-boot circuit that resets and boots the application circuit, disabling external network access for updates, ensuring the resilience of the recovery image.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the configuration memory is made writable to enable updates, then the device can receive OTA updates, but the device becomes vulnerable to unauthorized modifications and attacks

Engineering Contradiction:
Improveupdate capabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The memory system is segmented into secure configuration memory (protected from writes) and updateable storage areas. The configuration memory is divided into read-only configuration data and separate update targets, allowing updates without compromising the integrity of protected configuration regions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure boot loader and verification mechanism act as intermediaries between the external update source and the configuration memory. These intermediaries validate update authenticity and control the write process, preventing direct unauthorized writes to protected memory regions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If external network access is enabled for device management, then OTA updates can be deployed, but the communication stack becomes a target for attacks

Engineering Contradiction:
Improveremote management capabilityVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The verification and validation functions are extracted from the vulnerable communication stack and placed in the secure boot loader that operates with restricted network access. This separates the update reception function from the critical verification function, protecting the latter from network-based attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If the device allows reconfiguration through internal ports, then functionality can be extended, but unintended alterations may occur

Engineering Contradiction:
Improvefunctional reconfigurabilityVSAvoidconfiguration integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Configuration data is signed and verified in advance by a trusted authority before being loaded into the device. The secure boot loader performs preliminary verification of configuration integrity before applying any reconfiguration, preventing unintended alterations from occurring during runtime.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12265626B2Apparatuses and methods with secure configuration update
Publication Date: 2025.04.01 NXP BV
  • US12265626B2 patent drawing
  • US12265626B2 patent drawing
  • US12265626B2 patent drawing

AI summary

One example securely updates an integrated circuit to mitigate undesirable modifications and this involves an application circuit accessing an external network while a (e.g., nonvolatile) program memory is write protected; and a reset-boot circuit resetting and booting the application circuit while access to the external network is disabled, and causing an update for the application circuit. In response to an indication that an update is downloaded for installation, the downloaded update is installed in the memory while access to the external network is disabled, and execution of the reset mode is permitted after the update is installed. Also, a retrieval module may download, in response to an indication that an update is not downloaded, an update provided via the external network while the memory is write-protected and thereby permitting execution of the reset mode after the update is downloaded.