Secure Software Update Installation via Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices face security challenges during software updates, as they are often used by end-users and manufacturers lack control over update modules, risking system coherence and privilege escalation.
Innovation Solution
A method involving an electronic device that receives a software update module with an indication value, verifies its authenticity and integrity, compares update information with reference data, and installs only authorized parts, ensuring only approved resources are used by the updated application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software update modules are received and installed without strict verification, then the device can be updated quickly and easily, but the system coherence and security are compromised, allowing privilege escalation
Solution Approach 1:
The patent applies preliminary action by performing verification of the software update module against reference information stored in the device before installation occurs. The processor compares update information with authorized reference data to ensure the update is legitimate and safe, preventing privilege escalation while maintaining ease of operation through automated verification
Solution Approach 2:
The patent uses an intermediary approach by introducing a verification mechanism that acts as a mediator between the received update module and the installation process. The processor serves as this intermediary, comparing update information with reference information and only allowing installation if the comparison succeeds, thus ensuring system coherence without complicating the user experience
2Reliability
If manufacturers have control over software update modules, then system security and coherence are maintained, but the flexibility and adaptability of the update process is reduced
Solution Approach 1:
The patent applies self-service by enabling the device to autonomously verify update modules against its own stored reference information. The device performs the verification itself without requiring manufacturer intervention or control during the update process, maintaining security while allowing flexible, user-initiated updates from any authorized source
3Reliability
If update information is encrypted, then the integrity and security of the update is improved, but the complexity of the installation process increases due to decryption requirements
Solution Approach 1:
The patent applies preliminary action by performing decryption of the encrypted update information before the verification and installation processes. The processor decrypts the update module using stored cryptographic keys, allowing the subsequent verification with reference information to proceed with standard comparison operations, thus managing complexity through staged processing
Data Source
AI summary
An electronic device receives data including an application update module for an application program, the application update including a first part, the first part including first update information and an indication value. A processor of the electronic device then compares the first update information with reference information associated with the indication value and stored in a memory of the electronic device. The processor then installs a second part of the application update module when the first update information corresponds to the reference information, thereby producing an updated application program.


