Server-Based Debug Authorization for Low-Cost Embedded Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low-cost embedded systems face challenges in implementing effective access restriction against illegal debugging, as existing security measures are costly and difficult to integrate.

Innovation Solution

An information processing apparatus that includes a first circuit configured to request a server to determine whether debug or software changes are possible in response to external access, utilizing a ROM monitor and system soft to create a debug permission request message, verify debug licenses, and restrict debug access based on server authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a low-cost embedded system is used, then cost is reduced, but security against illegal debugging deteriorates

Engineering Contradiction:
ImprovecostVSAvoidsecurity against illegal debugging
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary component that handles debug authorization externally. The embedded system itself remains low-cost without complex internal security hardware, while the server provides centralized security management. This mediator approach allows the embedded system to achieve security functionality through external authorization services rather than expensive internal security modules.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the complex security verification functionality from the embedded system and places it in an external server. By taking out the authorization logic from the cost-constrained embedded device and relocating it to a more capable server environment, the system maintains low cost while achieving reliable security through external validation of debug permissions.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If effective access restriction function is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess restriction functionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server acts as an intermediary that handles the complexity of access restriction logic externally. The embedded system only needs to implement simple client-side functionality to communicate with the server, while the server manages the complex authorization decisions, license verification, and security policies. This distributes complexity away from the embedded device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security functionality into separate components: a lightweight client in the embedded system and a comprehensive server-side authorization service. This segmentation allows the embedded system to maintain simplicity while the server handles the complex access restriction logic, license management, and security verification in a distributed architecture.

Inventive Principle:
Principle #1Segmentation

3Reliability

If debug authorization is centralized on server, then security is improved, but system complexity increases

Engineering Contradiction:
Improvedebug authorizationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server serves as a centralized intermediary for all debug authorization requests. The embedded system implements a simple client that communicates authorization requests to the server and executes returned commands. This centralized mediation improves security through uniform policy enforcement while managing system complexity through clear separation of authorization logic in the server versus simple client execution in the embedded system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11418505B2Information processing apparatus, system and method
Publication Date: 2022.08.16 KK TOSHIBA
  • US11418505B2 patent drawing
  • US11418505B2 patent drawing
  • US11418505B2 patent drawing

AI summary

According to one embodiment, an information processing apparatus is applied to an embedded system in an electric device and includes a first circuit. The first circuit is configured to request a server different from the information processing apparatus to determine whether a debug or software change is possible in response to external access.