Segmented Firmware Update Packets with Device-Specific Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for updating computer programs, such as firmware, via a network are vulnerable to malware injection as attackers can intercept and manipulate data packets, potentially infecting multiple devices if security mechanisms are overcome.

Innovation Solution

A method where each electronic device receives a unique data packet containing a computer program and a key specific to that device, ensuring the program can only be processed if the key matches the device, thereby preventing unauthorized processing and reducing the risk of widespread malware infection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single data packet is used for updating multiple electronic devices, then the update process is simplified and more efficient, but the security risk increases as attackers can intercept and manipulate the packet to infect multiple devices

Engineering Contradiction:
Improveupdate efficiencyVSAvoidmalware infection risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent divides a single universal update packet into multiple device-specific segmented packets. Each packet contains the same computer program but is encrypted with a unique key tailored to a specific electronic device. This segmentation maintains update efficiency while eliminating the security vulnerability of universal packets, as attackers would need to compromise multiple device-specific encryption keys rather than a single universal key.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making each data packet customized for its target device through device-specific encryption keys. While the computer program content remains the same across all packets, the encryption layer is locally adapted to each device's unique key, providing targeted security that prevents widespread infection while maintaining efficient distributed update delivery.

Inventive Principle:
Principle #3Local quality

2Reliability

If strong encryption is used to secure data packets against manipulation, then security is improved, but if the encryption is overcome, attackers can infect large numbers of devices simultaneously

Engineering Contradiction:
Improvedata packet securityVSAvoidlarge-scale malware distribution
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security approach by using individual encryption keys for each device rather than a single strong encryption scheme for all devices. This creates multiple independent security layers, where compromising one device's key does not endanger other devices. The segmentation transforms a single point of failure into multiple isolated security zones.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security parameter from using one strong encryption key for all devices to using multiple weak individual encryption keys, one per device. This parameter change ensures that the security breach of one device does not propagate to others, as each device operates in an independent security context with its own key.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If device-specific keys are used for each data packet, then security against widespread infection is improved, but the complexity of generating and managing multiple data packets increases

Engineering Contradiction:
Improvemalware injection preventionVSAvoiddata packet generation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by using a single computer program that serves all electronic devices, which is then encrypted with different keys for distribution. This multi-functional approach allows the same core update content to be securely delivered to multiple devices through a standardized process, reducing the complexity of creating entirely different update packages for each device while maintaining device-specific security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2442251B9Individual updating of computer programs
Publication Date: 2016.10.05 KOBIL SYST
  • EP2442251B9 patent drawingFigure 1a~1b
  • EP2442251B9 patent drawingFigure 2a
  • EP2442251B9 patent drawingFigure 2b

AI summary

Embodiments of the present invention include processing a computer program or computer program part contained in a data packet on an electronic device only if the data packet contains a key adapted to the electronic device and/or to a key associated with the electronic device, wherein the data packet is a data packet from a plurality of data packets, wherein each of the data packets from the plurality of data packets contains the computer program or computer program part and a key, wherein the computer program or computer program part contained in the data packets is the same for all data packets and is intended for processing on a plurality of electronic devices.wherein the electronic device is one electronic device from the multitude of electronic devices and wherein the key contained in each data packet is adapted only to one of the electronic devices and/or to a key assigned to one of the electronic devices, but to no other of the electronic devices and/or to no key assigned to any other of the electronic devices.