Secure Software Update Mixing Pre-Registered Content
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security modules in decentralized systems, such as those used in Pay-TV and banking applications, face vulnerabilities during software updates due to the risk of malicious decryption of update messages, which can reveal sensitive security information, leading to potential security leaks and the dilemma of whether to apply patches or not.
Innovation Solution
A secure method for updating software in security modules involves forming a second program block by mixing a first updating block with pre-registered content specific to each module's memory zone, ensuring that even if the message is deciphered, the original block's relation is obscured, and using encryption keys for secure transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If update messages are transmitted in decentralized security modules, then software can be updated to fix security leaks, but the messages become vulnerable to malicious decryption that reveals security information
Solution Approach 1:
The patent applies preliminary action by pre-registering content in the security module's memory before the update process. This pre-registered content is then mixed with the update block during transmission, creating a protective mechanism that obscures the update content from malicious decryption attempts while ensuring reliable updates can still be applied.
Solution Approach 2:
The patent uses an intermediary approach by introducing a mixing mechanism that combines the update block with pre-registered content. This intermediary process transforms the update message into a protected form that maintains its functionality while hiding its true content from potential attackers, thus resolving the contradiction between update reliability and security vulnerability.
2Object-affected harmful factors
If encryption keys are used to protect update messages, then security is improved, but the complexity of the update system increases
Solution Approach 1:
The patent applies self-service by having each security module use its own pre-registered content for mixing with the update block. This eliminates the need for complex centralized key management systems, as each module independently protects its own updates using its unique pre-registered content, thereby improving security without significantly increasing system complexity.
3Productivity
If the same update message is sent to all security modules, then transmission efficiency is improved, but individual module security requirements may not be met
Solution Approach 1:
The patent applies universality by creating a single update block that can be universally transmitted to all security modules while maintaining individual security requirements. The mixing mechanism allows the same update content to be adapted to each module's unique pre-registered content, enabling efficient bulk transmission while preserving individual module security characteristics.
Data Source
AI summary
Transmission method of a message containing a program block that avoids the consequences of a possible malicious decryption of this message is proposed. This is achieved through a secure method to update software embedded in a security module, comprising formation of a first updating program block, determination of a target memory zone of said security module, determination, through said security module, of a pre-registered content in said target memory zone, formation of a second program block obtained by the mixing of all or a part of the pre-registered content with the first program block, transmission of the second program block to the security module, reception of the second block by the security module, reading of the target memory zone, obtaining and writing in the target memory zone of the first block by the inverse mixing of all or part of the second block and of the target memory zone content.

