Wireless Device Code Update Verification via Security Subsystem
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The communications subsystem in wireless devices lacks the processing power and resources to autonomously verify the trustworthiness of updates, making it vulnerable to corrupted or malicious code, and existing methods for remote updates are exposed to security risks due to the need for additional code portions that can cause conflicts and compatibility issues.
Innovation Solution
A method where the applications subsystem verifies the credibility and integrity of code updates using robust cryptographic methods and a one-way register indicator to ensure the trust state, allowing the communications subsystem to receive trusted updates without performing security processes, thus simplifying operations and avoiding conflicts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the communications subsystem performs autonomous verification of updates, then security against malicious code is improved, but device complexity and resource requirements increase
Solution Approach 1:
The patent introduces a security subsystem as an intermediary component that performs verification of communications subsystem updates. This separate security subsystem contains the cryptographic code and data space needed for verification, rather than requiring the communications subsystem to have these capabilities directly. The security subsystem acts as a mediator that the communications subsystem can trust to verify updates autonomously without the communications subsystem needing full verification capabilities.
Solution Approach 2:
The device is divided into separate functional subsystems: a communications subsystem that receives updates and a security subsystem that verifies them. This segmentation allows each subsystem to be optimized for its specific function while sharing resources through the common security verification mechanism. The security subsystem is a distinct code portion that can serve multiple subsystems.
2Reliability
If multiple code portions with security capabilities are included in the wireless device, then verification capability is improved, but conflicts and compatibility issues increase
Solution Approach 1:
The security subsystem is designed as a universal, shared resource that can verify updates for multiple different code portions including the communications subsystem, applications subsystem, and other components. Rather than having duplicate security verification code in each subsystem, there is one security subsystem that serves all subsystems, eliminating conflicts while maintaining verification capability across the entire device.
3Extent of automation
If the communications subsystem includes flash management and cryptographic capabilities, then autonomous update verification is improved, but resource consumption and implementation issues increase
Solution Approach 1:
The security subsystem serves itself and other subsystems by providing shared verification capabilities. The security subsystem manages its own resources and provides services to multiple clients (communications subsystem, applications subsystem, etc.) without each client needing to have its own complete set of cryptographic and flash management capabilities. This self-service model reduces overall resource consumption while maintaining autonomous verification capability.
Data Source
AI summary
In one embodiment, the present invention includes a method to initiate updating of a second portion of a system if a value indicates that the system is in a trusted state. In such an embodiment, a first portion of the system may validate updated code before the second portion of the system is updated. In one such embodiment, the first portion may be an applications portion and the second portion may be a communications portion of a wireless device.


