Controller Software Installation via Encrypted Memory Card

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In production sites where programmable controllers are used, there is a challenge in preventing unauthorized installation of software since no personal computer is allowed, and communication lines are not provided for software installation.

Innovation Solution

A control apparatus that uses a recording medium with stored additional software, software identification information, and encrypted information, where the recording medium identification information is used as a key to decrypt and verify the software, ensuring only authorized software installations are allowed by comparing decrypted and stored software identification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software installation is performed through communication line from Internet, then software installation convenience is improved, but security against unauthorized installation deteriorates

Engineering Contradiction:
Improvesoftware installation convenienceVSAvoidsecurity against unauthorized installation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A recording medium (memory card) is introduced as an intermediary carrier for software distribution. The memory card stores encrypted software that can only be decrypted and installed by the target control apparatus using its unique identification information as a decryption key. This intermediary mechanism enables secure software installation without requiring communication lines or personal computers at the installation site.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of software from unencrypted to encrypted form during distribution. The software is stored in encrypted state on the recording medium and only transformed to its functional state after verification and decryption by the target apparatus. This parameter change (encrypted ↔ decrypted) ensures that unauthorized parties cannot use or modify the software during distribution and installation.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If personal computer is brought in for software installation, then software installation capability is improved, but site security rules are violated

Engineering Contradiction:
Improvesoftware installation capabilityVSAvoidviolation of site security rules
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the software installation capability from the personal computer environment and embeds it directly into the control apparatus. The control apparatus itself performs the decryption and installation operations using its built-in processing capabilities and stored identification information, eliminating the need to introduce external personal computers into the controlled environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The control apparatus performs software installation autonomously using its own resources. The apparatus reads its unique identification information from its built-in storage, uses this information to decrypt the software on the recording medium, and installs the software without requiring external assistance from personal computers or communication infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If encrypted information verification is implemented, then security against unauthorized installation is improved, but installation process complexity increases

Engineering Contradiction:
Improvesecurity against unauthorized installationVSAvoidinstallation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control apparatus pre-stores its unique identification information in its built-in storage before the software installation process begins. This preliminary preparation allows the apparatus to immediately verify the encrypted software by decrypting it with its pre-stored identification information, streamlining the installation process and reducing the perceived complexity during actual installation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10187379B2Control apparatus and control apparatus system
Publication Date: 2019.01.22 OMRON CORP
  • US10187379B2 patent drawing
  • US10187379B2 patent drawing
  • US10187379B2 patent drawing

AI summary

Unauthorized installation of software is prevented even at a production site at which software cannot be installed through a communication line. The memory card stores: additional software including a software ID; a recording medium ID; and encrypted information generated by encrypting the software ID, using the recording medium ID as a key. The controller performs the steps of: obtaining the encrypted information from the memory card; obtaining the recording medium ID from the memory card; obtaining the software ID by decrypting the encrypted information, using the recording medium ID as a key; obtaining the software ID from the additional software, comparing the decrypted software ID and the software ID obtained from the additional software; and storing the additional software in the storage when the comparison is successful.