Secure Programming Authentication Relay for Private Key Gaps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure programming systems are inconvenient when the original equipment manufacturer fails to provide the private key, leading to inefficiencies in the burning operation and process.

Innovation Solution

A method is introduced where the first authentication module acts as a root authentication module, authorizing a second authentication module to issue certificates, enabling secure and flexible classification of authentication modules based on product categories, using a hierarchical system with encryption and verification processes to ensure secure programming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the original equipment manufacturer provides the private key through a paired public key process, then the private key is protected and securely transmitted, but the burning operation becomes very inconvenient when the original equipment manufacturer fails to provide the private key

Engineering Contradiction:
Improveprivate key protectionVSAvoidburning operation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to both the original equipment manufacturer and the burning center. This mediator enables the burning center to verify the authenticity of the private key and perform burning operations without direct provision of the private key by the manufacturer, thus maintaining security while improving operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a digital certificate that copies and verifies the identity and authority of the original equipment manufacturer. Instead of directly transmitting the private key, the system uses a certified copy (digital certificate) that proves the authenticity of the key pair, allowing the burning center to operate independently while maintaining the security guarantees provided by the manufacturer's private key.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If a hierarchical authentication system is implemented with certificate signing, then security is enhanced and flexibility in classifying authentication modules is improved, but the system complexity increases

Engineering Contradiction:
Improveauthentication module classification flexibilityVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct hierarchical levels: a root certificate authority, intermediate certificate authorities, and end-entity certificates. This segmentation allows different authentication modules to be classified and managed separately based on product categories or methods, providing flexibility while organizing the complexity into manageable, standardized segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal certificate structure that can serve multiple authentication purposes and product categories. The hierarchical certificate system provides a multi-functional framework where the same authentication infrastructure supports different types of programmable devices, authentication methods, and product classifications, reducing the need for separate systems for each category.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12587390B2Method of operating secure programming system
Publication Date: 2026.03.24 DEDIPROG TECH
  • US12587390B2 patent drawing
  • US12587390B2 patent drawing
  • US12587390B2 patent drawing

AI summary

A method of operating a secure programming system is provided. The method can use the first authentication module as the root authentication module to authorize the second authentication module of the program burning system when the first authentication module fails to provide the private key. In this way, the second authentication module obtains the second certificate composed of the second digital signature and becomes the first relay authentication module authorized by the first authentication module to issue certificates on behalf of the first authentication module, so that the program burning system can perform burning operations and process operations. Therefore, the method of the present disclosure can not only achieve the purpose of signing the same certificate in a more secure manner, but also help the first authentication module to be more flexible in classifying the second authentication module according to different product application categories or methods.