Secure Firmware Transfer and Burning Control System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the manufacturing and distribution of smart devices and IoT products, software and firmware are vulnerable to theft and reverse engineering, leading to loss of competitive advantage and potential customer data breaches, necessitating robust protection mechanisms.

Innovation Solution

A control system and method for secure manufacturing involving dual encryption processes: initial encryption during transfer and secondary encryption upon chip burning, utilizing asymmetric key pairs for secure verification and decryption, ensuring only authorized access and use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware is transferred without encryption, then the transfer process is simple and fast, but the firmware can be stolen during transfer

Engineering Contradiction:
Improvefirmware security during transferVSAvoidencryption process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by encrypting the firmware before transfer and verifying the encrypted firmware before burning to chip. This pre-prepared security mechanism ensures that even if the firmware is intercepted during transfer, it cannot be read or stolen, thus resolving the contradiction between transfer simplicity and security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism between the transfer process and the burning process. The verification module acts as a mediator that checks the encrypted firmware's validity before allowing it to be burned to the chip, adding a security layer without directly complicating the main transfer operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firmware is burned to chip without encryption, then the manufacturing process is simple, but the firmware can be stolen after burning

Engineering Contradiction:
Improvefirmware security after burningVSAvoiddual encryption process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by encrypting the firmware before burning to chip and maintaining the encrypted state in the chip. This pre-established encryption ensures that even after the burning process, the firmware remains protected against theft and reverse engineering, resolving the contradiction between manufacturing simplicity and post-burning security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by implementing encryption before the burning process, which prevents potential future theft or cracking of the firmware. This proactive security measure counteracts the risk of firmware stealing before it can occur, rather than reacting after security breaches happen.

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If no encryption verification is performed, then the manufacturing process is fast, but unauthorized copying and cracking can occur

Engineering Contradiction:
Improvemanufacturing speedVSAvoidprotection against illegal copying
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing encryption and verification before the burning process. This pre-computed security mechanism allows the manufacturing process to maintain high speed while ensuring that the firmware is protected against unauthorized copying and cracking, as the security measures are already in place before production begins.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If encryption keys are stored openly, then the key management is simple, but the encryption security is compromised

Engineering Contradiction:
Improveencryption key securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the extraction principle by separating the encryption keys from the firmware and storing them in a secure, isolated location (secure element or hardware security module). This extraction ensures that even if the firmware is stolen or the chip is reverse engineered, the keys remain protected and cannot be used to decrypt the firmware, thus resolving the contradiction between key management simplicity and encryption security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11455379B2Control system and method thereof for secure manufacturing
Publication Date: 2022.09.27 ECOLUX TECH CO LTD
  • US11455379B2 patent drawing
  • US11455379B2 patent drawing
  • US11455379B2 patent drawing

AI summary

A control system and method thereof for secure manufacturing, comprising a source end, a verification end, and a production end. Providing a source file, the source end encrypting and signing the source file to generate a transfer file and to generate an authorization information simultaneously, the transfer file being transferred to the production end, and the authorization information being transferred to the verification end. After the production end is authorized by the verification end, the transfer file is verified and decrypted, and can be re-encrypted or not re-encrypted to be written into a product or to generate a product.