Secure Device Programming System with Hardware Security Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device programming systems lack integration of secure programming capabilities within main production assembly lines, leading to separate equipment for programming, testing, and calibration, which complicates secure configuration and operation of devices like Flash memories, FPGAs, and IoT devices.
Innovation Solution
A secure programming system that uses a hardware security module and security interop layer to individually encrypt and program programmable devices with customized security keys, allowing for secure configuration and operation of devices by synchronizing with a host system to reduce data load and enhance security performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate programming equipment is used for customization, then device security and individual configuration capability are improved, but production complexity and time are worsened
Solution Approach 1:
The patent merges the programming function with the production assembly line by integrating a programming unit into the main production line. This allows customization and security configuration to be performed during normal production operations, eliminating the need for separate programming equipment while maintaining device security through individual encryption of payloads.
Solution Approach 2:
The system performs preliminary security configuration by encrypting payloads with device-specific keys before programming. The programming unit receives pre-prepared encrypted payloads that contain security configurations, allowing security to be established in advance without requiring complex real-time security operations during production.
2Adaptability or versatility
If separate programming equipment is used, then individual device configuration is improved, but productivity and production time are worsened
Solution Approach 1:
The programming unit is integrated into the main production assembly line, combining programming operations with existing production workflows. This allows individual device configuration to be performed inline during production, eliminating the need for separate programming steps and maintaining production efficiency.
Solution Approach 2:
The system introduces a programming unit as an intermediary component within the production line that handles customization operations. This intermediary unit processes individual device configurations using encrypted payloads, enabling adaptability without disrupting the main production flow.
3Reliability
If security configuration is performed separately, then security control is improved, but ease of operation and integration are worsened
Solution Approach 1:
The programming unit serves as an intermediary that handles security configuration operations, shielding the main production system from security complexity. It receives encrypted payloads, manages device-specific keys, and performs programming operations, making security control accessible without complicating integration into the production line.
Solution Approach 2:
The system implements self-service security configuration where the programming unit autonomously handles encryption and programming operations using pre-provided encrypted payloads. This reduces the operational burden on the main production system while maintaining strong security control through device-specific cryptographic keys.
Data Source
AI summary
A secure programming system and method for provisioning and programming a target payload into a programmable device mounted in a programmer. The programmable devices are provisioned with a job package created by a user on a host system and deployed on a device programmer. The secure programming system supports a hardware security module on the host system that can be accessed remotely from the device programmer using coordinated sets of template and mechanism dictionaries linked to a security API coupled to the hardware security module.


