Vehicle Component Software Update Protection via Credential Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of GNU General Purpose License software in electronic control units of road vehicles can lead to unpredictable functionality if uncertified replacement software is installed, as it may not be validated for the intended environment.
Innovation Solution
A system and method that involves a back office portal generating a signed update mode record, which is verified by a component in the vehicle. Upon verification, the component erases valid credentials, performs an irreversible action, enters a software update mode, updates the software, and exits the mode, rejecting requests that rely on the erased credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user-initiated software updates are allowed in vehicles, then adaptability and user control are improved, but system reliability and security deteriorate due to potential unpredictable behavior from uncertified replacement software
Solution Approach 1:
The system performs preliminary actions by erasing credentials and executing irreversible actions before allowing software updates. This ensures that once an update is initiated, the component cannot revert to its original state or interact with the vehicle system using old credentials, preventing unpredictable behavior from uncertified software.
Solution Approach 2:
The patent extracts the credentials that establish component validity from the vehicle system before allowing updates. By removing these credentials and preventing their reuse, the system separates the update capability from the original security authentication mechanism, allowing updated software to operate without access to original system resources.
2Object-affected harmful factors
If credentials are erased to prevent unauthorized access, then security is improved, but the component can no longer perform its intended function, worsening operational capability
Solution Approach 1:
The system erases credentials and performs irreversible actions as preliminary steps before allowing software updates. This ensures that the component transitions to a state where it can only operate with the updated software, preventing unauthorized access while maintaining operational capability through the updated version.
Solution Approach 2:
The patent changes the operational parameters of the component by erasing credentials and executing irreversible actions. This transforms the component from a state where it uses original credentials for authentication to a state where it operates with updated software and new security parameters, resolving the contradiction between security and functionality.
3Reliability
If an irreversible action is performed to prevent credential reuse, then security against unpredictable behavior is improved, but device complexity increases due to additional security mechanisms
Solution Approach 1:
The patent extracts and removes credentials from the component using an irreversible action. This simple yet effective mechanism prevents credential reuse without requiring complex security verification systems, maintaining reliability while minimizing added complexity.
Solution Approach 2:
The system uses disposable credentials that are erased after a single use to enable software updates. This approach provides strong security protection against unpredictable behavior without requiring complex long-term security management, as the credentials are designed to be short-lived and single-use only.
Data Source
AI summary
A system includes a vehicle external to a back office portal. The back office portal is operational to generate a signed update mode record. The vehicle has multiple devices and a component. The component is in communication with the devices, and operational to receive the signed update mode record, verify that the signed update mode record is from the back office portal and was created for the component, erase credentials within the component that establish the component as valid to the plurality of devices in response to the verification of the signed update mode record, perform an irreversible action within the component, enter a software update mode, exit the software update mode, and reject each request from the plurality of devices to the component that relies on the credentials that were erased from the component.


