Segmented Verification Storage for Third-Party Firmware Reloading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face inefficiencies in integrating third-party customized firmware or software into electronic devices due to the need for re-signing at the manufacturer after delivery, complicating the development process and hindering multi-vendor cooperation.

Innovation Solution

A data integrity protection method that involves storing verification information in separate storage areas within the device, allowing for secure boot of third-party customized firmware or software without returning to the manufacturer, by using digital signatures and secure boot policies tailored to the integrator's requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If firmware or software is customized by a third-party integrator after device delivery, then the firmware or software can be adapted to service requirements, but the device must be returned to the original manufacturer for re-signing, making the process complex and reducing integration development efficiency

Engineering Contradiction:
Improvecustomization capabilityVSAvoidintegration development efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The verification information storage is segmented into multiple storage areas: a first storage area storing verification information signed by the original manufacturer, and a second storage area storing verification information signed by the third-party integrator. This segmentation allows the system to independently verify firmware from different sources without requiring return to the manufacturer, thus resolving the contradiction between customization capability and integration efficiency.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If firmware or software is customized by a third-party integrator, then service requirements can be met, but the device needs to be returned to the manufacturer for re-signing, increasing process complexity

Engineering Contradiction:
Improvecustomization capabilityVSAvoidintegration process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The verification information storage is segmented into multiple storage areas: a first storage area storing verification information signed by the original manufacturer, and a second storage area storing verification information signed by the third-party integrator. This segmentation allows the system to independently verify firmware from different sources without requiring return to the manufacturer, thus resolving the contradiction between customization capability and integration efficiency.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple vendors co-construct a system, then division of labor is refined and service requirements can be better met, but the firmware or software cannot be reloaded without returning to the original manufacturer

Engineering Contradiction:
Improvemulti-vendor cooperationVSAvoidfirmware reloading ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The verification information storage is segmented into multiple storage areas: a first storage area storing verification information signed by the original manufacturer, and a second storage area storing verification information signed by the third-party integrator. This segmentation allows the system to independently verify firmware from different sources without requiring return to the manufacturer, thus resolving the contradiction between customization capability and integration efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12400039B2Data integrity protection method and apparatus
Publication Date: 2025.08.26 HUAWEI TECH CO LTD
  • US12400039B2 patent drawing
  • US12400039B2 patent drawing
  • US12400039B2 patent drawing

AI summary

A data integrity protection method is applied to an electronic device, and the electronic device stores vendor data and first verification information. The first verification information is stored in a first storage area of the electronic device and is used to perform integrity verification on the vendor data. The method includes: First data is obtained. Digital signature is performed on the first data to generate second data and second verification information. The second data and the second verification information are stored, where the second verification information is stored in a second storage area of the electronic device. According to the data integrity protection method provided in this embodiment of this application, firmware or software customized by a third-party integrator is supported in being reloaded to a system for running, thereby simplifying a process and improving integrated development efficiency of an electronic device.