Attribute-Based Encryption for Secure Vehicle Firmware Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure remote update technologies for vehicle-mounted devices fail to mandatorily detect and ensure the identity and status prerequisites of vehicles, leading to potential update failures and security threats due to non-mandatory and inflexible detection methods.

Innovation Solution

Implementing a device update method using attribute-based encryption, where a server generates an access policy based on the attribute set of a vehicle, encrypts the update package, and only allows vehicles with matching attribute keys to decrypt and apply the updates, ensuring mandatory prerequisite detection and secure updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional remote update methods are used, then update efficiency is improved, but update security deteriorates due to lack of mandatory identity and status verification

Engineering Contradiction:
Improveupdate efficiencyVSAvoidupdate security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary identity and status verification by embedding access policies into update packages before distribution. The to-be-updated device checks these policies in advance to determine whether it meets update prerequisites, preventing unauthorized or incompatible updates from being applied.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces attribute-based encryption parameters (identity attributes and status attributes) to transform the update verification process. Instead of simple authentication, the system uses cryptographic parameters to enforce mandatory detection of device identity and status, ensuring both security and compatibility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If attribute-based encryption is implemented, then update security is improved, but device complexity increases due to additional verification mechanisms

Engineering Contradiction:
Improveupdate securityVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention merges identity verification and status verification into a unified attribute-based encryption framework. Both verification aspects are combined into single cryptographic operations during update package decryption, reducing the number of separate verification steps and simplifying the overall process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an access policy as an intermediary element that mediates between the update server and the to-be-updated device. The access policy contains embedded verification rules that automatically check device attributes without requiring complex manual verification procedures, thus reducing operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If mandatory identity and status detection is implemented, then update accuracy is improved, but update process time increases

Engineering Contradiction:
Improveupdate accuracyVSAvoidupdate process time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs mandatory identity and status detection as a preliminary step during the update package download phase. By completing verification before the actual update installation, the system ensures update accuracy while minimizing the time impact on the critical installation process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention replaces manual or sequential verification mechanisms with automated cryptographic verification based on attribute-based encryption. This substitution enables parallel processing of multiple verification checks, significantly reducing the time required for mandatory detection while maintaining high update accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3883212B1Device upgrade method and related device
Publication Date: 2023.02.22 HUAWEI TECH CO LTD
  • EP3883212B1 patent drawingFigure 1
  • EP3883212B1 patent drawingFigure 2
  • EP3883212B1 patent drawingFigure 3

AI summary

Embodiments of the present invention disclose a device update method and a related device. The device update method and the related device may be specifically applied to a smart vehicle and an unmanned vehicle, to ensure update security of a vehicle-mounted device inside the vehicle. The method includes: generating, by a server, an access policy for a to-be-updated device based on an attribute set of the to-be-updated device; encrypting, by the server, a target update package according to the access policy, to generate a ciphertext of the target update package; and sending, by the server, the ciphertext of the target update package to the to-be-updated device. The ciphertext of the target update package is used by the to-be-updated device to perform decryption based on one or more attribute keys corresponding to the attribute set to obtain the target update package. This application may be applied to a plurality of technical fields such as a smart home and smart driving, to ensure secure and efficient update of a home device or a vehicle-mounted device.