Secure Autorun Program Update via USB Re-enumeration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing portable electronic devices, such as USB keys, lack a secure method for updating their autorun programs, which are typically protected by passwords or cryptographic means but do not allow for program modifications.

Innovation Solution

Incorporating secure means for modifying the autorun program on the device, including identification as a ROM reader and rewritable non-volatile memory, with authentication and encryption to ensure secure updates, and compatibility with various host stations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the autorun program is protected by password or cryptographic means, then security is improved, but the program cannot be modified

Engineering Contradiction:
ImprovesecurityVSAvoidprogram modifiability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the program storage into two distinct zones: a first memory zone for storing the original protected autorun program with full security protections, and a second memory zone for storing updated versions. This segmentation allows the original secure program to remain immutable while enabling safe updates in the second zone, thus resolving the contradiction between security and modifiability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication and verification steps before allowing program modification. The secure means authenticate the updating operation and verify the integrity of the new program version before writing it to the second memory zone. This preliminary action ensures that security protocols are maintained even as the program is being updated.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the entity re-enumerates as a rewritable memory reader to allow program modification, then program update capability is improved, but compatibility with host stations that do not support re-enumeration deteriorates

Engineering Contradiction:
Improveprogram update capabilityVSAvoidhost station compatibility
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements dynamic re-enumeration where the portable entity changes its USB device class identification based on the operation required. During normal operation, it presents as a ROM reader for security. During update operations, it re-enumerates as a rewritable memory reader to accept program updates. This dynamic switching resolves the contradiction by allowing both secure operation and update capability without requiring permanent changes to host compatibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the USB device parameters (specifically the device class and interface descriptors) during the update process. By modifying these identification parameters, the entity can present different functional interfaces to the host station - a read-only interface for normal operation and a writable interface for updates - thus achieving both compatibility and update capability.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If authentication and verification means are added to the secure means, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary secure means layer that handles authentication and verification operations. This secure means acts as a mediator between the host station and the program memory zones, managing cryptographic operations, authentication checks, and integrity verification. By centralizing these security functions in a dedicated secure means module, the overall system architecture remains manageable despite the added security complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2048576B2Secure method for updating a program that runs automatically and portable electronic device implementing same
Publication Date: 2015.01.07 OBERTHUR TECH SA
  • EP2048576B2 patent drawingFigure 1~4
  • EP2048576B2 patent drawingFigure 2A
  • EP2048576B2 patent drawingFigure 2B

AI summary

The entity has an universal serial bus (USB)interface for connecting the entity with a host station e.g. mobile phone. A rewritable non-volatile memory e.g. EPROM, conserves an autorun program adapted to be executed automatically on the host station, on a connection between the entity and the host station. A secured unit is formed of a drive program, a controller, a memory zone, a memory and a remote station i.e. remote server, for modifying the program. An independent claim is also included for a method for updating an autorun program of a portable electronic entity.