Control program delivery system and method therefor

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing air conditioning systems face the risk of unauthorized use of control programs due to pre-written programs in outdoor and indoor machine control units, which can be illegally duplicated and used.

Innovation Solution

A control program delivery system that uses encrypted authentication information stored in non-rewritable storage, where the system authenticates the control device's authority before allowing the control program to be executed, preventing unauthorized use by writing the program into rewritable storage only if authentication is successful, and optionally using a repeater device for secure communication and customized program generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If control programs are pre-written into control units at the factory, then assembly work in the field is simplified, but the control programs can be illegally duplicated and used

Engineering Contradiction:
Improveassembly workVSAvoidunauthorized use prevention
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-installing authentication information (first authentication information) into the control device at the factory before the control program is delivered. This allows the control program to be written into the control unit only after successful authentication, preventing illegal duplication while enabling field assembly. The authentication mechanism is prepared in advance but the actual program writing occurs conditionally after verification.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If control programs are delivered from server to control device, then unauthorized duplication is prevented, but the system complexity increases

Engineering Contradiction:
Improveunauthorized use preventionVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an authentication information storage unit as an intermediary component between the control program storage unit and the execution unit. This intermediary stores first authentication information that must be verified before the control program can be written or executed. The authentication information acts as a mediator that controls access to the control program, preventing unauthorized duplication while maintaining a manageable system structure through clear separation of authentication and program execution functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication information is stored in non-rewritable storage, then duplication of authentication key is prevented, but the storage cannot be updated

Engineering Contradiction:
Improveauthentication key securityVSAvoidstorage flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the storage system into two distinct parts: a first authentication information storage unit with non-rewritable characteristics for storing authentication keys, and a second control program storage unit that is rewritable for storing and updating control programs. This segmentation allows the authentication information to remain secure and immutable while the control programs can be updated independently, resolving the contradiction between security and flexibility by assigning different storage characteristics to different functional requirements.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3139299B1Control program delivery system and method therefor
Publication Date: 2020.04.29 MITSUBISHI HEAVY IND LTD
  • EP3139299B1 patent drawingFigure 1
  • EP3139299B1 patent drawingFigure 2
  • EP3139299B1 patent drawingFigure 3

AI summary

A control program delivery system (1), wherein an outdoor machine (10) transmits a first authentication key written in a non-rewritable first storage device to a repeater device (3). The repeater device (3), having a second authentication key, transmits the first authentication key and the second authentication key to a server (5). The server (5) authenticates the first authentication key and the second authentication key, and, upon confirming that due authority is possessed, transmits a control program to the repeater device (3). The repeater device (3) transmits the control program to the outdoor machine (10). The outdoor machine (10) writes the received control program into a rewritable second storage device and places the program in an executable state. The control program delivered from the server (5) includes a step for authenticating the first authentication key at program run time and a step for permitting execution of the program only when the first authentication key is authenticated. It is thereby made possible to reduce the risk of an unauthorized use of the control program.