Segmented Firmware Update Packets with Device-Specific Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for updating computer programs, such as firmware, via a network are vulnerable to malware injection as attackers can intercept and manipulate data packets, potentially infecting multiple devices if security mechanisms are overcome.
Innovation Solution
A method where each electronic device receives a unique data packet containing a computer program and a key specific to that device, ensuring the program can only be processed if the key matches the device, thereby preventing unauthorized processing and reducing the risk of widespread malware infection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a single data packet is used for updating multiple electronic devices, then the update process is simplified and more efficient, but the security risk increases as attackers can intercept and manipulate the packet to infect multiple devices
Solution Approach 1:
The patent divides a single universal update packet into multiple device-specific segmented packets. Each packet contains the same computer program but is encrypted with a unique key tailored to a specific electronic device. This segmentation maintains update efficiency while eliminating the security vulnerability of universal packets, as attackers would need to compromise multiple device-specific encryption keys rather than a single universal key.
Solution Approach 2:
The patent applies local quality by making each data packet customized for its target device through device-specific encryption keys. While the computer program content remains the same across all packets, the encryption layer is locally adapted to each device's unique key, providing targeted security that prevents widespread infection while maintaining efficient distributed update delivery.
2Reliability
If strong encryption is used to secure data packets against manipulation, then security is improved, but if the encryption is overcome, attackers can infect large numbers of devices simultaneously
Solution Approach 1:
The patent segments the security approach by using individual encryption keys for each device rather than a single strong encryption scheme for all devices. This creates multiple independent security layers, where compromising one device's key does not endanger other devices. The segmentation transforms a single point of failure into multiple isolated security zones.
Solution Approach 2:
The patent changes the security parameter from using one strong encryption key for all devices to using multiple weak individual encryption keys, one per device. This parameter change ensures that the security breach of one device does not propagate to others, as each device operates in an independent security context with its own key.
3Object-affected harmful factors
If device-specific keys are used for each data packet, then security against widespread infection is improved, but the complexity of generating and managing multiple data packets increases
Solution Approach 1:
The patent applies universality by using a single computer program that serves all electronic devices, which is then encrypted with different keys for distribution. This multi-functional approach allows the same core update content to be securely delivered to multiple devices through a standardized process, reducing the complexity of creating entirely different update packages for each device while maintaining device-specific security.
Data Source
Figure 1a~1b
Figure 2a
Figure 2b
AI summary
Embodiments of the present invention include processing a computer program or computer program part contained in a data packet on an electronic device only if the data packet contains a key adapted to the electronic device and/or to a key associated with the electronic device, wherein the data packet is a data packet from a plurality of data packets, wherein each of the data packets from the plurality of data packets contains the computer program or computer program part and a key, wherein the computer program or computer program part contained in the data packets is the same for all data packets and is intended for processing on a plurality of electronic devices.wherein the electronic device is one electronic device from the multitude of electronic devices and wherein the key contained in each data packet is adapted only to one of the electronic devices and/or to a key assigned to one of the electronic devices, but to no other of the electronic devices and/or to no key assigned to any other of the electronic devices.