IP Library Granted Patent US 10,701,084
Granted Patent B2
US 10,701,084 · App. 16/130,566 · Granted Jun 30, 2020

Reliable and secure firmware update with a dynamic validation for internet of things (IoT) devices

Inventor: Oleksii Surdu (Broadlands, VA)
Assignee: GBS Laboratories, LLC
H04L63/123G06F8/654G06F21/105G06F21/572G06F21/602H04L67/34G06F11/1451G06F11/1469G06F2201/805G06F2221/0797
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,701,084
App. No.
16/130,566
Granted
Jun 30, 2020
Kind
B2
Abstract

A computing system for a secure and reliable firmware update through a verification process, dynamic validation and continuous monitoring for error or failure and speedy correction of Internet of Things (IoT) device operability. The invention uses a Trusted Execution Environment (TEE) for hardware-based isolation of the firmware update, validation and continuous monitoring services. The isolation is performed by hardware System on a Chip (SoC) Security Extensions such as ARM TrustZone or similar technologies on other hardware platforms. The invention therefore comprises Firmware Update Service (FUS), System Validation Service (SMS) and Continuous Monitoring Service (CMS) running in the TEE with dedicated memory and storage, thus providing a trusted configuration management functionality for the operating system (OS) code and applications on IoT devices. Services running in the TEE use both direct (hardware level) and indirect (software agents inside main execution environment (MEE)) methods of control of the MEE. Embodiments of the invention apply all updates to a staging (new) execution environment (SEE) without changing of the MEE.

Claims (13)

1. A system to securely perform a firmware update on a computing system, the system comprising:

a computer system firmware update package comprising a new firmware for a Trusted Execution Environment (TEE),

a security extension to isolate the TEE; and

a firmware update system to run in the TEE,

wherein the TEE continues to operate normally while the firmware update system performs integrity, authenticity validation and management of the computer system firmware update package,

creates a Stage Trusted Execution Environment (STEE) to replace the TEE, copies the TEE into the STEE, applies the new firmware to the STEE, and

updates a boot configuration to start the STEE as the TEE, wherein the firmware update system validates the STEE after applying the new firmware and prior to updating the boot configuration to start the STEE as the TEE.

2. The system as claimed in claim 1 further comprising a Bootloader that validates the TEE each time when the computing system starts and loads the TEE after successful validation.

3. The system as claimed in claim 1 further comprising a Bootloader that detects a failed or damaged TEE and removes the TEE.

4. The system as claimed in claim 1 wherein the system comprises limited hardware resources.

5. The system as claimed in claim 1 wherein the firmware update system migrates a configuration of the TEE to the STEE.

6. The system as claimed in claim 1 wherein the TEE functions as a backup to the STEE.

7. The system as claimed in claim 1 further comprising restarting the device to boot the new TEE.

Assignments (1)
CHANGE OF NAME Recorded Dec 1, 2020
From: GBS LABORATORIES, LLC
To: INZERO TECHNOLOGIES, LLC
Reel/Frame 054555/0094 →
Continuity (2)
Continuation 15146157 · May 4, 2016
Related Publication 20190014128A1 · Jan 10, 2019
Cited By (1)
US 12,229,267