IP Library Granted Patent US 12,223,306
Granted Patent B2
US 12,223,306 · App. 17/731,661 · Granted Feb 11, 2025

Secure device update by passing encryption and data together

Inventors: Piotr Wolnowski (Gdansk, PL); Pawel Raasz (Gdansk, PL)
Assignee: CARRIER FIRE & SECURITY EMEA BV
G06F8/65G06F21/44G06F21/572G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,223,306
App. No.
17/731,661
Granted
Feb 11, 2025
Kind
B2
Abstract

A method and system for updating firmware of a device. A method includes receiving a decryption engine for decrypting encrypted firmware, loading the decryption engine into a first memory of a device, and receiving the encrypted firmware. The method may include obtaining a pre-stored encryption key from a second memory of the device, wherein the second memory is a different type of memory than the first memory, and decrypting the encrypted firmware using the encryption key and the decryption engine, wherein the decryption of the encrypted firmware occurs in the first memory.

Claims (31)

1. A method of updating firmware of a device, the method comprising:

receiving in an update package an encrypted firmware and a decryption engine including a decryption algorithm for decrypting the encrypted firmware;

loading the decryption engine into a first memory of a device;

obtaining a pre-stored encryption key from a second memory of the device, wherein the second memory is a different type of memory than the first memory;

decrypting the encrypted firmware using the encryption key and the decryption engine, wherein the decryption of the encrypted firmware occurs in the first memory;

authenticating the decryption engine prior to receiving the encrypted firmware by comparing a digest stored in the device to a computed digest of the decryption engine;

wherein the authenticating comprises comparing, in the first memory, a first digest and a second digest, wherein the first digest is generated by a provider of the decryption algorithm, wherein the first digest is stored in the device and the first digest corresponds to the decryption algorithm and the second digest corresponds to an output of multiple XOR operations of selected bootloader code parts with the decryption algorithm.

2. The method of claim 1 , wherein the first memory is a random-access memory (RAM) and the second memory is a non-volatile memory (NVM).

3. The method of claim 1 , responsive to the authentication, executing the decryption engine to decrypt the encrypted firmware.

4. The method of claim 1 , further comprising implementing a second-encryption algorithm, wherein the second algorithm is different than the first algorithm.

5. The method of claim 1 , further comprising decrypting the encrypted firmware using the pre-stored key known only to the device and the manufacture.

6. The method of claim 5 , wherein the pre-stored key is programmed during manufacturing and is not transmitted over a network to be stored in the device.

7. The method of claim 1 , further comprising validating the decrypted encrypted firmware using cyclic redundancy check (CRC) prior to updating firmware in the second memory.

8. The method of claim 1 , wherein the device is a fire detector.

9. A system for updating firmware of a device, the device comprising:

a first memory of the device;

a second memory of the device configured with firmware, wherein the first memory is different than the second memory;

a processor, wherein the processor is configured to:

receive in an update package an encrypted firmware and a decryption engine including a decryption algorithm for decrypting the encrypted firmware;

load the decryption engine into the first memory of a device;

obtain a pre-stored encryption key from the second memory of the device, wherein the second memory is a different type of memory than the first memory; and

decrypting the encrypted firmware using the encryption key and the decryption engine, wherein the decryption of the encrypted firmware occurs in the first memory;

wherein the first memory is configured to authenticate the decryption engine prior to receiving the encrypted firmware by comparing a digest stored in the device to a computed digest of the decryption engine;

wherein the authentication comprises comparing, in the first memory, a first digest and a second digest, wherein the first digest is generated by a provider of the decryption algorithm, wherein the first digest is stored in the device and the first digest corresponds to the decryption algorithm and the second digest corresponds to an output of multiple XOR operations of selected bootloader code parts with the decryption algorithm.

10. The system of claim 9 , wherein the first memory is a random-access memory (RAM) and the second memory is a non-volatile memory (NVM).

11. The system of claim 9 , responsive to the authentication, executing the decryption engine to decrypt the encrypted firmware in the first memory.

12. The system of claim 9 , further comprising implementing a second-encryption algorithm, wherein the second algorithm is different than the first algorithm.

13. The system of claim 9 , wherein the first memory is configured to decrypt the encrypted firmware using the pre-stored key known only to the device and the manufacture.

14. The system of claim 13 , wherein the second memory stores the pre-stored key and is programmed during manufacturing.

15. The system of claim 9 , further comprising validating the decrypted encrypted firmware using cyclic redundancy check (CRC) prior to updating firmware in the second memory.

16. The system of claim 9 , wherein the device is a fire detector.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2025
From: CARRIER CORPORATION; CARRIER GLOBAL CORPORATION; CARRIER FIRE & SECURITY EMEA; CARRIER FIRE & SECURITY, LLC; CARRIER CANADA CORPORATION; CLIMATE, CONTROLS & SECURITY ARGENTINA S.A.; KIDDE IP HOLDINGS , INC.; KIDDE LTD.; KIDDE PRODUCTS LTD.; CARRIER TRANSICOLD AUSTRIA GMBH; CARRIER TRANSICOLD FRANCE SCS
To: KIDDE FIRE PROTECTION, LLC
Reel/Frame 072829/0383 →
SECURITY INTEREST Recorded May 28, 2025
From: KIDDE FIRE PROTECTION, LLC; WALTER KIDDE PORTABLE EQUIPMENT INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 071436/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2025
From: CARRIER GLOBAL CORPORATION; CARRIER CORPORATION; CARRIER FIRE & SECURITY EMEA; CARRIER FIRE & SECURITY, LLC; CARRIER CANADA CORPORATION; CLIMATE, CONTROLS & SECURITY ARGENTINA S.A.; KIDDE IP HOLDINGS, INC.; KIDDE LTD.; KIDDE PRODUCTS LTD.; CARRIER TRANSICOLD AUSTRIA GMBH; CARRIER TRANSICOLD FRANCE SCS
To: KIDDE FIRE PROTECTION, LLC
Reel/Frame 070518/0387 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: WOLNOWSKI, PIOTR; RAASZ, PAWEL
To: CARRIER FIRE & SECURITY POLSKA SP. Z O.O.
Reel/Frame 066856/0757 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: CARRIER FIRE & SECURITY POLSKA SP. Z O.O
To: CARRIER FIRE & SECURITY EMEA BV
Reel/Frame 066856/0802 →
Continuity (2)
Provisional Application 63180736 · Apr 28, 2021
Related Publication 20220350590A1 · Nov 3, 2022
References Cited (25)
US 6970565B1 · Rindsberg · 2005 [cited by examiner]
US 7330978B1 · Harrington · 2008 [cited by examiner]
US 7904706B2 · Lambert et al. · 2011 [cited by applicant]
US 8213612B2 · Kaabouch et al. · 2012 [cited by applicant]
US 8214654B1 · Wyatt · 2012 [cited by examiner]
US 9652755B2 · Deierling et al. · 2017 [cited by applicant]
US 10838705B2 · Riedl et al. · 2020 [cited by applicant]
US 20060005046A1 · Hars · 2006 [cited by applicant]
US 20100008510A1 · Zayas · 2010 [cited by applicant]
US 20110138377A1 · Allen · 2011 [cited by examiner]
US 20130111455A1 · Li · 2013 [cited by examiner]
US 20180373848A1 · Lafortune · 2018 [cited by examiner]
US 20190236280A1 · Sheng · 2019 [cited by examiner]
US 20200210168A1 · Farrell et al. · 2020 [cited by applicant]
US 20210056834A1 · Wolff · 2021 [cited by examiner]
US 20210058249A1 · Jeon · 2021 [cited by examiner]
CN 108418893A · 2018 [cited by applicant]
EP 2711858B1 · 2015 [cited by applicant]
EP 2568639B1 · 2018 [cited by applicant]
EP 3362931B1 · 2020 [cited by applicant]
WO 2020042778A1 · 2020 [cited by applicant]
D. K. Nilsson and U. E. Larson, “Secure Firmware Updates over the Air in Intelligent Vehicles,” ICC Workshops—2008 IEEE International Conference on Communications Workshops, Beijing, China, 2008, pp. 380-384. (Year: 200… [cited by examiner]
Kaplan, B., “RAM is Key: Extracting Disk ENcryption Keys From Volatile Memory,” May 2007, Carnegie Mellon University, Thesis Report, pp. 1-29. [cited by applicant]
ST Life.Augmented, “Introduction to STM32 microcontrollers security,” AN5156, Rev. 5, Nov. 2020, pp. 1-55, www.st.com. [cited by applicant]
Texas Instruments, “Secure In-Field Firmware Updaes for MSP MCUs,” Application Report, SLAA682, Nov. 2015, pp. 1-13. [cited by applicant]