Software Version Management via Security Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hackers exploit vulnerabilities in software to avoid payment for communications services by using unapproved cellular communications systems, necessitating a method to prevent downgrading to out-of-date software versions.

Innovation Solution

The use of security certificates, such as hardware and common configuration certificates, to verify and authenticate software versions on devices, ensuring only proper and updated versions are executed, thereby preventing unauthorized usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software is updated to fix security vulnerabilities, then security is improved, but device complexity increases due to version management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidversion management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by embedding version criteria and security requirements into the certificate structure before software installation. The version criteria are predetermined and built into the certificate, allowing automatic verification without complex runtime management systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses certificates as an intermediary mechanism between the software and the device's security system. The certificate contains version criteria and acts as a mediator that automatically verifies software legitimacy, simplifying the version management process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If certificate verification is implemented to prevent software downgrading, then security is improved, but ease of operation deteriorates due to additional authentication steps

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware execution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies self-service by making the certificate verification process automatic and transparent to the user. The system itself performs the verification of version criteria against the certificate without requiring user intervention, maintaining ease of operation while ensuring security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The verification logic is prepared in advance within the certificate structure, allowing the system to automatically enforce version requirements without requiring users to manually check or configure security settings during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9256728B2Method, apparatus, and computer program product for managing software versions
Publication Date: 2016.02.09 NOKIA TECHNOLOGIES OY
  • US9256728B2 patent drawing
  • US9256728B2 patent drawing
  • US9256728B2 patent drawing

AI summary

An apparatus for managing software versions may include a processor. The processor may be configured to determine whether a security identifier of a first security certificate matches a trusted security identifier. In this regard, the first security certificate may include software version criteria. The processor may also be configured to determine whether a software version of a software application satisfies software version criteria of the first security certificate. The processor may be configured to make this determination in response to determining that the security identifier of the first certificate matches the trusted security identifier. Further, the processor may also be configured to permit execution of the software application, in response to determining that the software version satisfies the software version criteria. Associated methods and computer program products may also be provided.