Secure OTA Firmware Updates for Vehicle Components
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Vehicle components often require re-configuration due to software errors or corruption, which can lead to dangerous situations if not updated promptly, especially in autonomous vehicles where malware can cause crashes or injuries.
Innovation Solution
Implementing secure over-the-air (SOTA) updates that allow for wireless transmission of firmware updates to vehicle components, with cryptographic measurements to authenticate the updates and ensure their authenticity before execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firmware updates are transmitted locally or via memory stick, then security is maintained through controlled access, but update speed and convenience are reduced
Solution Approach 1:
The patent introduces a telematics control unit as an intermediary between the wireless communication system and the vehicle's control units. This intermediary receives firmware updates wirelessly, verifies their authenticity using cryptographic measurements, and then distributes them to the appropriate control units. This resolves the contradiction by enabling fast wireless transmission while maintaining security through the intermediary's verification process.
2Manufacturing precision
If firmware updates are performed manually at dealers, then update accuracy is ensured through professional verification, but time loss and operational disruption increase
Solution Approach 1:
The patent implements a self-service firmware update system where the vehicle's telematics control unit automatically receives, verifies, and installs firmware updates without requiring dealer intervention. The system performs automatic authenticity verification using cryptographic measurements and can install updates during normal vehicle operation or during scheduled maintenance, eliminating the need for specialized dealer equipment and reducing vehicle downtime significantly.
3Ease of operation
If wireless firmware transmission is implemented, then update convenience and speed are improved, but security risks from unauthorized updates increase
Solution Approach 1:
The patent implements preliminary action by performing cryptographic authenticity verification of firmware updates before they are installed or executed. The telematics control unit verifies digital signatures and cryptographic measurements of the received firmware against authorized values before allowing installation. This preliminary verification ensures that only authenticated, unauthorized-free updates are installed, eliminating security risks while maintaining the convenience of wireless updates.
4Reliability
If cryptographic verification is performed on all firmware updates, then security against malware is improved, but processing time and computational load increase
Solution Approach 1:
The patent applies partial verification action by performing cryptographic verification selectively on critical firmware components and updates. The telematics control unit prioritizes verification of safety-critical and security-critical firmware, while using lighter verification methods for non-critical updates. This approach maintains strong malware protection for essential systems while reducing overall verification time and computational load on the vehicle's processing resources.
Data Source
AI summary
Executable code is part of an over-the-air (OTA) update received by, for example, a computing device in a vehicle. In one example, the update is a secure over-the-air (SOTA) update of software that is stored in firmware of a vehicle component (e.g., firmware stored in memory of a storage device or a boot device that are mounted in a vehicle).


