IP Library › Granted Patent US 12,265,626
Granted Patent B2
US 12,265,626 · App. 17/830,197 · Granted Apr 1, 2025

Apparatuses and methods with secure configuration update

Inventors: Marcel Medwed (Graz, AT); Ventzislav Nikov (Haasrode, BE); Tobias Schneider (Graz, AT)
Assignee: NXP B.V.
G06F21/575G06F8/65G06F21/572G11C13/0059G11C16/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,626
App. No.
17/830,197
Granted
Apr 1, 2025
Kind
B2
Abstract

One example securely updates an integrated circuit to mitigate undesirable modifications and this involves an application circuit accessing an external network while a (e.g., nonvolatile) program memory is write protected; and a reset-boot circuit resetting and booting the application circuit while access to the external network is disabled, and causing an update for the application circuit. In response to an indication that an update is downloaded for installation, the downloaded update is installed in the memory while access to the external network is disabled, and execution of the reset mode is permitted after the update is installed. Also, a retrieval module may download, in response to an indication that an update is not downloaded, an update provided via the external network while the memory is write-protected and thereby permitting execution of the reset mode after the update is downloaded.

Claims (48)

1. An apparatus comprising:

an application-specific circuit to receive, while a nonvolatile memory circuit which has a programmed configuration is in a write-protection state and while access to an external network data-access circuit is enabled, an indication that an update corresponding to a change in the configuration is appropriate;

a reset-and-boot circuit to, in response to the indication, execute reset and boot the application-specific circuit while access to an external network data-access circuit is disabled, and, in response to the indication, to cause the application-specific circuit to operate consistent with an updated configuration which overrides the configuration previously programmed into the nonvolatile memory circuit;

a recovery circuit including

a circuit-based install module to cause, in response to an indication that an update is downloaded for installation, the downloaded update to be installed in the nonvolatile memory circuit while access to the external network data-access circuit is disabled, and to permit execution of the reset mode after the update is installed, and

a circuit-based retrieval module to download, in response to an indication that an update is not downloaded for installation, an update provided via the external network data-access circuit while the nonvolatile memory circuit is in the write-protection state, and to permit execution of the reset mode after the update is downloaded.

2. The apparatus of claim 1 , wherein the reset-and-boot circuit is further to disable the write-protection state and, in response to a reset action by the reset-and-boot circuit, the write-protection state is no longer enabled.

3. The apparatus of claim 1 , wherein the reset-and-boot circuit is to remove the nonvolatile memory circuit from the write-protection state by initiating a reset mode for the apparatus, and wherein, while the downloaded update is installed in the nonvolatile memory circuit.

4. The apparatus of claim 1 , wherein the circuit-based install module is further to conduct an internal check on whether the update is already downloaded for installation.

5. The apparatus of claim 1 , wherein the circuit-based retrieval module is further to enable access to external data and then to request an update from an external server and, in response to a communication from the external server, download the update provided via the external network data-access circuit.

6. The apparatus of claim 1 , wherein the nonvolatile memory circuit further includes a flash memory circuit, and wherein programmed configuration includes a resilient recovery image.

7. The apparatus of claim 1 , further including a system-on-chip (SoC) circuit including the application-specific circuit, the reset-and-boot circuit and the recovery circuit.

8. The apparatus of claim 1 , further including at least one Internet of Thing (IoT) device including circuitry to enable the IoT device to communicate over a broadband network.

9. The apparatus of claim 1 , further including communications circuitry to enable the apparatus device to communicate over a network.

10. The apparatus of claim 1 , further including an integrated circuit of which the application-specific circuit, the reset-and-boot circuit and the recovery circuit form a part, wherein the nonvolatile memory circuit includes

an external memory circuit situated external to the integrated circuit, including a resilient recovery image, and controlled by using a XOM mode which allows fetching access but not read-and/or-write access, in combination with a write-protection mode, and

an internal memory circuit, as part of the integrated circuit, including a first use-case region having a use-case image containing code for functional operation of the IC and including a second use-case region having a use-case image containing code for functional operation of the IC, the first and second use-case regions to be operably controlled by using a write-lock mode and the XOM mode,

wherein the resilient recovery image is updated by:

booting the resilient recovery image from the external memory circuit while the external memory circuit is in the write-protection state and while access to the external network data-access circuit is enabled,

downloading and validating the update as an update resilient recovery image to the second use-case region, and

rebooting into the update resilient recovery image while the external memory circuit is not in the write-protection state and while access to the external network data-access circuit is disabled and, based on whether the reboot is deemed successful, install the update resilient recovery image as a replacement for the resilient recovery image in the external memory circuit or reboot into the resilient recovery image in the external memory circuit to permit for another attempt in updating the resilient recovery image.

11. The apparatus of claim 10 , wherein the integrated circuit is to transfer, in response to the reboot being deemed successful, a copy of the use-case image from the first use-case region to the second use-case region.

12. The apparatus of claim 10 , wherein the use-case image containing code for functional operation of the IC in the second use-case region is a copy of the resilient recovery image.

13. The apparatus of claim 1 , further including an integrated circuit (IC) of which the application-specific circuit, the reset-and-boot circuit and the recovery circuit form a part, wherein the nonvolatile memory circuit includes an internal flash memory circuit as part of the integrated circuit, and the internal flash memory circuit including a first use-case region having a use-case image containing code for functional operation of the IC and having a resilient recovery image, and including a second use-case region also having a use-case image containing code for functional operation of the IC and having a resilient recovery image, the first and second use-case regions to be operably controlled by using a write-lock mode and an XOM mode which allows fetching access but not read-and/or-write access, in combination with a write-protection mode, wherein the resilient recovery image is updated by tracking versions of the use-case image containing code for functional operation of the IC and having a resilient recovery image in each of the first and second use-case regions.

14. The apparatus of claim 1 , further including an integrated circuit of which the application-specific circuit, the reset-and-boot circuit and the recovery circuit form a part, wherein the nonvolatile memory circuit includes

an external flash memory circuit situated external to the integrated circuit, including a resilient recovery image, and controlled by using a XOM mode which allows fetching access but not read-and/or-write access, in combination with a write-protection mode, and

an internal flash memory circuit, as part of the integrated circuit, including an SBL (secondary bootloader) region having an SBL which is combinable with a recent copy of the resilient recovery image, having a first use-case region, and including a second use-case region, the SBL region and the first and second use-case regions being operably controllable by using a write-lock mode and the XOM mode,

wherein the resilient recovery image is updated by:

booting the resilient recovery image from a copy in the first use-case region of the internal flash memory circuit while the nonvolatile memory circuit is in the write-protection state and while access to the external network data-access circuit is enabled,

downloading and validating the update as an update resilient recovery image to the external flash memory circuit, and

rebooting into the update resilient recovery image while the nonvolatile memory circuit is not in the write-protection state and while access to the external network data-access circuit is disabled and, based on whether the reboot is deemed successful, install the update resilient recovery image as a replacement first use-case region of the internal flash memory circuit and, if there is an indication of a failed update, reboot into the resilient recovery image in the external flash memory circuit to permit for another attempt in updating the resilient recovery image.

15. A method comprising:

storing a programmed configuration in a nonvolatile memory circuit of an integrated circuit;

operating an application-specific circuit, while the nonvolatile memory circuit is in a write-protection state and while access to an external network data-access circuit is enabled, consistent with the configuration programmed into the nonvolatile memory circuit and receive an indication that an update corresponding to a change in the configuration is appropriate;

executing a reset-and-boot circuit to, in response to the indication, execute reset and boot the application-specific circuit while access to an external network data-access circuit is disabled, and in response to the indication, to cause the application-specific circuit to operate consistent with an updated configuration which overrides the configuration previously programmed into the nonvolatile memory circuit; via a recovery circuit,

causing, in response to an indication that an update is downloaded for installation, the downloaded update to be installed in the nonvolatile memory circuit while access to the external network data-access circuit is disabled, and to permit execution of the reset mode after the update is installed, and

downloading, in response to an indication that an update is not downloaded for installation, an update provided via the external network data-access circuit while the nonvolatile memory circuit is in the write-protection state, and thereby permitting execution of the reset mode after the update is downloaded.

16. The method of claim 15 , wherein the nonvolatile memory circuit includes an external memory circuit situated external to the integrated circuit, including a resilient recovery image, and controlled by using a first mode which allows fetching access but not read-and/or-write access, in combination with a second, write-protection mode.

17. The method of claim 16 , wherein the nonvolatile memory circuit includes an internal memory circuit, as part of the integrated circuit, including a first use-case region having a use-case image containing code for functional operation of the IC and including a second use-case region having a use-case image containing code for functional operation of the IC, the first and second use-case regions to be operably controlled by using a write-lock mode.

18. The method of claim 17 , wherein at least one of the internal memory circuit and the external memory circuit is a flash-type memory circuit, and the use-case image containing code for functional operation of the IC in the second use-case region is a copy of the resilient recovery image.

19. The method of claim 15 , wherein the method further comprises removing the nonvolatile memory circuit from the write protection state by initiating a reset mode.

20. A non-transient computer storage medium containing instructions to be executed by a computer processor for carrying out a method including a set of steps comprising:

storing a programmed configuration in a nonvolatile memory circuit of an integrated circuit;

operating an application-specific circuit, while the nonvolatile memory circuit is in a write-protection state and while access to an external network data-access circuit is enabled, consistent with the configuration programmed into the nonvolatile memory circuit and receive an indication that an update corresponding to a change in the configuration is appropriate;

executing a reset-and-boot circuit to, in response to the indication, execute reset and boot the application-specific circuit while access to an external network data-access circuit is disabled, and, in response to the indication, to cause the application-specific circuit to operate consistent with an updated configuration which overrides the configuration previously programmed into the nonvolatile memory circuit;

via a recovery circuit,

causing, in response to an indication that an update is downloaded for installation, the downloaded update to be installed in the nonvolatile memory circuit while access to the external network data-access circuit is disabled, and to permit execution of the reset mode after the update is installed, and

downloading, in response to an indication that an update is not downloaded for installation, an update provided via the external network data-access circuit while the nonvolatile memory circuit is in the write-protection state, and thereby permitting execution of the reset mode after the update is downloaded.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2022
From: MEDWED, MARCEL; NIKOV, VENTZISLAV; SCHNEIDER, TOBIAS
To: NXP B.V.
Reel/Frame 060076/0494 →
Continuity (1)
Related Publication 20230395110A1 · Dec 7, 2023
References Cited (65)
US 7555775B2 · Smith · 2009 [cited by applicant]
US 7900249B2 · Burcham et al. · 2011 [cited by applicant]
US 8359646B2 · Suffern et al. · 2013 [cited by applicant]
US 8489922B2 · Matthew · 2013 [cited by applicant]
US 8839435B1 · King · 2014 [cited by applicant]
US 8869138B2 · Bandakka · 2014 [cited by applicant]
US 8892928B2 · Maciocco · 2014 [cited by applicant]
US 8909930B2 · Winslow et al. · 2014 [cited by applicant]
US 9300642B2 · Weis et al. · 2016 [cited by applicant]
US 9722904B2 · Liu et al. · 2017 [cited by applicant]
US 10680887B2 · Pallas et al. · 2020 [cited by applicant]
US 10809944B1 · Ostrikov et al. · 2020 [cited by applicant]
US 20030084337A1 · Simionescu et al. · 2003 [cited by applicant]
US 20040076043A1 · Boals et al. · 2004 [cited by applicant]
US 20040255167A1 · Knight · 2004 [cited by applicant]
US 20040268116A1 · Vasisht · 2004 [cited by applicant]
US 20050055595A1 · Frazer · 2005 [cited by examiner]
US 20050132179A1 · Glaum · 2005 [cited by examiner]
US 20070002730A1 · Lu et al. · 2007 [cited by applicant]
US 20070050426A1 · Dubal · 2007 [cited by examiner]
US 20070118646A1 · Gassoway · 2007 [cited by examiner]
US 20070150524A1 · Eker · 2007 [cited by examiner]
US 20090006827A1 · Rothman · 2009 [cited by examiner]
US 20100082932A1 · Rothman · 2010 [cited by examiner]
US 20100180130A1 · Stahl et al. · 2010 [cited by applicant]
US 20100191950A1 · Lin et al. · 2010 [cited by applicant]
US 20100248707A1 · Hoffner et al. · 2010 [cited by applicant]
US 20130097711A1 · Basavapatna et al. · 2013 [cited by applicant]
US 20130276128A1 · Konetski · 2013 [cited by examiner]
US 20140250290A1 · Stahl et al. · 2014 [cited by applicant]
US 20140310510A1 · Potlapally et al. · 2014 [cited by applicant]
US 20150067402A1 · Lee et al. · 2015 [cited by applicant]
US 20150381651A1 · Lietz et al. · 2015 [cited by applicant]
US 20160070656A1 · Babu · 2016 [cited by examiner]
US 20160110550A1 · Kakii · 2016 [cited by applicant]
US 20170032126A1 · Koike · 2017 [cited by examiner]
US 20170310703A1 · Ackerman et al. · 2017 [cited by applicant]
US 20180019880A1 · Wu et al. · 2018 [cited by applicant]
US 20180096154A1 · Shivanna · 2018 [cited by examiner]
US 20180165455A1 · Liguori et al. · 2018 [cited by applicant]
US 20190349356A1 · McElwee et al. · 2019 [cited by applicant]
US 20200034541A1 · Ballard · 2020 [cited by examiner]
US 20200184089A1 · Ponsini · 2020 [cited by applicant]
US 20200210204A1 · Arora · 2020 [cited by examiner]
US 20200257518A1 · Liedtke · 2020 [cited by examiner]
US 20200305000A1 · Obaidi · 2020 [cited by applicant]
US 20210133362A1 · Medwed et al. · 2021 [cited by applicant]
US 20230198775A1 · Liu · 2023 [cited by examiner]
US 20240311489A1 · Jin · 2024 [cited by examiner]
EP 0999673B1 · 2004 [cited by applicant]
EP 3444720B1 · 2020 [cited by examiner]
TW 200428196A · 2004 [cited by applicant]
WO 2013188830A1 · 2013 [cited by applicant]
WO 2016020640A1 · 2016 [cited by applicant]
WO 20160999839A1 · 2016 [cited by applicant]
WO WO2020172061A1 · 2020 [cited by examiner]
Yao, Jiewen, and Vincent Zimmer. “Building secure firmware.” Apress: New York, NY, USA (2020): 67-184. (Year: 2020). [cited by examiner]
Yao, Jiewen, and Vincent Zimmer. “A Tour Beyond BIOS-Capsule Update and Recovery in EDK II.” Intel whitepaper (2016). (Year: 2016). [cited by examiner]
Cooper, David, et al. “BIOS protection guidelines.” NIST Special Publication 800.2011 (2011). (Year: 2011). [cited by examiner]
Mahmoud Ammar and Bruno Crispo, Verify&Revive: Secure detection and recovery of compromised low-end embedded devices, ACSAC '20: Annual Computer Security Applications Conference, Virtual Event / Austin, TX, USA, Dec. 7-… [cited by applicant]
TCG CyRes Working Group, Cyber Resilient Module and Building Block Requirements: Specification. Version 1.0, Rev. 0.08, Cyber Resilient Technologies, Oct. 19, 2020, 67 pgs. https://trustedcomputinggroup.org/work-groups/… [cited by applicant]
Manuel Huber, Stefan Hristozov, Simon Ott, Vasil Sarafov, and Marcus Peinado, The Lazarus Effect: Healing Compromised Devices in the Internet of Small Things, Asia CCS '20: The 15th ACM Asia Conference on Computer and C… [cited by applicant]
Alexandru Radovici, Ioana Culic, Daniel Rosner, and Flavia Oprea, A Model for the Remote Deployment, update, and safe recovery for commercial sensor-based loT systems, Sensors 20 (2020), No. 16, pp. 1-34. [cited by applicant]
Meng Xu, Manuel Huber, Zhichuang Sun, Paul England, Marcus Peinado, Sangho Lee, Andrey Marochko, Dennis Mattoon, Rob Spiger, and Stefan Thom, Dominance as a new trusted computing primitive for the internet of things, 20… [cited by applicant]
Medwed, Marcel et al.; “Cyber Resilience for Self-Monitoring IoT Devices”; 2021 IEEE International Conference on Cyber Security and Resilience (CSR); Jul. 26-28, 2021, Rhodes, Greece; DOI: 10.1109/CSR51186.2021.9527995. [cited by applicant]