Vehicle Software Integrity Verification via Hash Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software in vehicle electronic control units can be maliciously altered during updates or resets, compromising their functionality and integrity.

Innovation Solution

A method and system utilizing a trusted platform module and integrity verification module to compare hash values of software, ensuring the software's integrity by generating and verifying confirmation values, thereby preventing unauthorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software of electronic control units is updated or reset, then the software can be upgraded or reconfigured, but the software may be maliciously altered and compromise functionality

Engineering Contradiction:
Improvesoftware update capabilityVSAvoidsoftware integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by measuring the software hash value before update and storing it in the trusted platform module. This preliminary measurement and storage of the original software state enables subsequent verification to detect any malicious alterations during the update process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by comparing the current software hash value with the stored original hash value after update. This feedback mechanism allows the system to detect and alert about malicious changes in software integrity following the update operation.

Inventive Principle:
Principle #23Feedback

2Reliability

If hash value measurement and comparison is performed, then software integrity can be verified, but additional security components and processing are required

Engineering Contradiction:
Improvesoftware integrity verificationVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted platform module as an intermediary component that performs the hash measurement and storage functions. This intermediary module simplifies the overall system architecture by centralizing the security-critical functions in a dedicated component rather than distributing them across multiple complex subsystems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the software hash value and stores it in the trusted platform module for later comparison. This copying mechanism enables integrity verification without requiring continuous complex processing, as the stored hash copy can be directly compared with the current software hash when needed.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8327153B2Method and system for verifying software platform of vehicle
Publication Date: 2012.12.04 ELECTRONICS & TELECOMM RES INST
  • US8327153B2 patent drawing
  • US8327153B2 patent drawing
  • US8327153B2 patent drawing

AI summary

A system for verifying a software platform of a vehicle including at least one electronic control unit receives a first final confirmation value corresponding to a hash value of software measured in the electronic control unit from an integrated security apparatus inside the vehicle and extends a hash value of normally operated software received from a software manufacturer of the electronic control unit to generate a second final confirmation value. Next, the system verifies the software platform of the vehicle based on results obtained by comparing the first final confirmation value with the second final confirmation value.