Secure Software Update Installation via Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face security challenges during software updates, as they are often used by end-users and manufacturers lack control over update modules, risking system coherence and privilege escalation.

Innovation Solution

A method involving an electronic device that receives a software update module with an indication value, verifies its authenticity and integrity, compares update information with reference data, and installs only authorized parts, ensuring only approved resources are used by the updated application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software update modules are received and installed without strict verification, then the device can be updated quickly and easily, but the system coherence and security are compromised, allowing privilege escalation

Engineering Contradiction:
Improveease of update installationVSAvoidsystem coherence and security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by performing verification of the software update module against reference information stored in the device before installation occurs. The processor compares update information with authorized reference data to ensure the update is legitimate and safe, preventing privilege escalation while maintaining ease of operation through automated verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a verification mechanism that acts as a mediator between the received update module and the installation process. The processor serves as this intermediary, comparing update information with reference information and only allowing installation if the comparison succeeds, thus ensuring system coherence without complicating the user experience

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manufacturers have control over software update modules, then system security and coherence are maintained, but the flexibility and adaptability of the update process is reduced

Engineering Contradiction:
Improvesystem security and coherenceVSAvoidflexibility of update process
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies self-service by enabling the device to autonomously verify update modules against its own stored reference information. The device performs the verification itself without requiring manufacturer intervention or control during the update process, maintaining security while allowing flexible, user-initiated updates from any authorized source

Inventive Principle:
Principle #25Self-service

3Reliability

If update information is encrypted, then the integrity and security of the update is improved, but the complexity of the installation process increases due to decryption requirements

Engineering Contradiction:
Improveupdate integrity and securityVSAvoidcomplexity of installation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing decryption of the encrypted update information before the verification and installation processes. The processor decrypts the update module using stored cryptographic keys, allowing the subsequent verification with reference information to proceed with standard comparison operations, thus managing complexity through staged processing

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240403433A1Method for secure installation of a software update
Publication Date: 2024.12.05 STMICROELECTRONICS INT NV
  • US20240403433A1 patent drawing
  • US20240403433A1 patent drawing
  • US20240403433A1 patent drawing

AI summary

An electronic device receives data including an application update module for an application program, the application update including a first part, the first part including first update information and an indication value. A processor of the electronic device then compares the first update information with reference information associated with the indication value and stored in a memory of the electronic device. The processor then installs a second part of the application update module when the first update information corresponds to the reference information, thereby producing an updated application program.