Verfahren zur Integritätsprüfung von Linux-Dateisystembildern
Anmelder: Valeo Comfort and Driving Assistance 🇫🇷
Details
- Veröffentlichungs-Nr.
- EP4804065
- Anmeldetag
- 4. März 2025
- Veröffentlichung
- 9. September 2026
- Rechtsraum
- EP
- IPC
- G06F21/57
Abstract
The invention relates to a method (Mth) for integrity verification of Linux filesystem images (Fsl) of a Linux embedded system, wherein said method (Mth) comprises: (a) a cryptographic signing phase (Ph_S) comprising : - generating a unique signature (S<n>) for each Linux filesystem image (FsI<n>) of a filesystem (Fs); - appending it to each corresponding Linux filesystem images (FsI<n>); - adding a padding (Pa<n>) to align the appended unique signatures (S<n>) to a predetermined size or structure; - producing signed Linux filesystem images (FsIS<n>) by combining each Linux filesystem image (FsI<n>) with their respective unique signature (S<n>), and padding (Pa<n>); -(b) a building phase (Ph_Bd) comprising : - building an initRAMFs image (I_RAMFs) that comprises a security configuration file (fs<n>.conf) for each signed Linux filesystem images (FsIS<n>), a security configuration file (fs<n>.conf) comprising a public key (PBK) or certificate (CT) and a fixed offset of location (Off<n>) for their respective signatures (S<n>); - building a boot Image (I_Boot) that comprises said initRAMFs image (I_RAMFs) and a Linux kernel (K); - loading a secondary bootloader (SBL), an application bootloader (ABL), said boot-image (I_Boot), said initRAMFs image (I_RAMFs), said Linux filesystem images (FsIS<n>) and said Linux filesystem images (FsIS<n>) into a second memory (Mem1) of a target device (Dev) that comprises a primary bootloader (PBL); (c) a boot up phase (Ph_Bt) comprising : - executing said primary bootloader (PBL) so as to cryptographically verify the secondary bootloader (SBL); - executing said secondary bootloader (SBL) so as to cryptographically verify the application bootloader (ABL); - executing said application bootloader (ABL) so as to load the boot image (I_Boot) into a random access memory (RAM) of said target device (Dev), said boot image (I_Boot) comprising the initRAMFs image (I_RAMFs) and the Linux kernel (K); - starting the Linux kernel (K) so as to execute the initRAMFs image (I_RAMFs), said executing comprising : verifying sequentially each of said signed Linux filesystem images (FsIS<n>) and if the signature verification is successful, mounting the Linux filesystem images (FsI<n>) into said random access memory (RAM).
Anmelder
- Firma
- Valeo Comfort and Driving Assistance
- Land
- 🇫🇷 Frankreich
Valeo Comfort and Driving Assistance ist eine Sparte des französischen Automobilzulieferers Valeo für Fahrerassistenz- und Komfortsysteme. Das Patentportfolio konzentriert sich auf Fahrzeugtechnik sowie Optik- und Fototechnik, ergänzt um Nachrichtentechnik und Software. Anmeldungen reichen von 2001 bis 2025.
538 Patente in unserer Datenbank