Software Update System Address Translation for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software update systems for IoT devices face challenges in ensuring the confidentiality and integrity of software updates, particularly due to limited processing power and memory resources in IoT CPUs, which makes them vulnerable to theft, piracy, and reverse engineering.
Innovation Solution
A software update system that includes an update software generation device and a CPU, where the update software generation device translates stored addresses, register numbers, operand addresses, and data values in the update software, making it impossible to use the software as is, even if it is stolen, and the CPU performs inverse translation to restore the original software for updating purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and decryption processing is performed on the update software, then confidentiality and integrity are ensured, but processing power and memory resources are consumed
Solution Approach 1:
The patent creates a translated copy of the update software with modified stored addresses, register numbers, operand addresses, and data values. This translated copy is what is actually transmitted and installed, while the original untranslated software remains on the developer's side. The CPU includes translation processing units that can translate between the original and translated formats, eliminating the need for encryption/decryption while maintaining security.
Solution Approach 2:
The patent systematically changes multiple parameters of the update software including stored addresses, register numbers, operand addresses, and data values to create a translated version. These parameter transformations make the software unintelligible to unauthorized users while preserving functionality for authorized devices with the appropriate translation processing units.
2Reliability
If high-performance CPU is used to perform verification and decryption processing, then security is improved, but cost increases
Solution Approach 1:
Instead of using high-performance CPUs for security processing, the patent creates a translated copy of the software that can be processed by standard low-power IoT CPUs. The translation processing units handle the security functions, allowing cost-effective manufacturing while maintaining security against theft and piracy.
Solution Approach 2:
The patent enables the use of inexpensive, low-power CPUs for IoT devices by shifting the computational burden to the software translation layer. This allows manufacturers to use affordable hardware components while still providing secure software updates, significantly reducing manufacturing costs.
3Power
If update software is transmitted in plain text, then processing resources are saved, but theft and piracy become easier
Solution Approach 1:
The patent transmits a translated copy of the update software in a modified format with changed addresses and values. This translated version appears as plain text during transmission, saving processing resources, but is only intelligible to devices with the corresponding translation processing units, thereby preventing theft and piracy.
Solution Approach 2:
Instead of encrypting the software to prevent theft, the patent inverts the approach by translating the software into a format that is intentionally difficult to understand and use without the proper translation processing units. This inversion makes the software appear as plain text (saving processing resources) while simultaneously protecting it from unauthorized use.
Data Source
AI summary
It is an object of the present disclosure to provide a software update system and a software update method capable of safely performing an update at a low cost while saving resources. A software update system according to the present disclosure includes an update software generation device and a CPU, the update software generation device includes a stored address translation unit that translates a stored address stored in a memory on the CPU allocated per at least one instruction code of an assembler code or a machine language code of update software into a different stored address from a normal stored address, and the CPU includes a stored address inverse translation unit that returns the different stored address resulting from the translation by the stored address translation unit to the normal stored address.


