Secure Software Installation via Region Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for installing secure software in devices with partitioned non-volatile memory are cumbersome, requiring special tools and increasing development costs, as they necessitate the OEM to handle all secure software installations, which is impractical for manufacturers dealing with diverse batches and constrained resources.
Innovation Solution
A method where target software is initially installed in a less secure region and verified using standard tools, then the region is updated to a more secure status, allowing non-secure installation tools to be used without the need for dedicated secure-installation tooling, thereby simplifying the process and reducing costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If secure software is installed directly in a more secure region using standard tools, then security is compromised, but if installed in a less secure region first, then installation becomes simpler
Solution Approach 1:
The patent applies preliminary action by first installing the secure software image in a less secure region using standard installation tools, then subsequently migrating it to the secure region after verification. This preliminary installation step simplifies the overall process while maintaining security through the two-stage approach.
Solution Approach 2:
The less secure region acts as an intermediary medium during the installation process. Standard installation tools install the software image in this intermediate location, which then serves as a temporary holding area before the final migration to the secure region, enabling the use of conventional tools without compromising security.
2Reliability
If OEM handles all secure software installations, then security is maintained, but device complexity and development costs increase
Solution Approach 1:
The system enables self-service installation by allowing standard installation tools to install secure software images in the less secure region autonomously. The access control circuitry automatically verifies the software and performs the migration to the secure region, eliminating the need for OEM-specific manual installation processes.
Solution Approach 2:
The patent makes the installation process universal by enabling standard installation tools to handle secure software installation through the two-stage process. This multi-functional approach allows the same tools to install both secure and non-secure software, eliminating the need for specialized OEM installation procedures.
3Reliability
If verification is performed before region update, then security is ensured, but installation time increases
Solution Approach 1:
Verification is performed as a preliminary action before the region update occurs. The access control circuitry verifies the software image in the less secure region before migrating it to the secure region, ensuring security is maintained while the process remains efficient through automated verification.
Data Source
AI summary
A software installation method is provided for a device comprising non-volatile memory 10 and access control circuitry 6 to control access to the non-volatile memory based on region defining data 7 defining whether a given region of the non-volatile memory is a less secure region or a more secure region, with greater access restriction imposed on access to a more secure region than to a less secure region. The method comprises installing target software 40 in a target region of the non-volatile memory 10 defined by the region defining data as a less secure region; verifying the target software; and at least when verification of the target software is successful, and after installation of the target software, updating the region defining data 7 to change the target region from a less secure region to a more secure region.


