Secure Programming System for Programmable Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic circuit board assembly processes lack integrated solutions for secure programming and configuration of programmable devices, such as Flash memories and smart phones, which often require separate equipment and areas for programming, testing, and calibration, leading to inefficiencies and security concerns.
Innovation Solution
A secure programming system that individually encrypts and configures programmable devices with customized security keys, enabling secure operation by validating serial numbers and providing code signing facilities, and authenticating devices before and after programming to ensure only authorized components are used.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate programming equipment and areas are used for configuring programmable devices, then security control over device operation is improved, but manufacturing efficiency and productivity deteriorate due to separation from main production assembly lines
Solution Approach 1:
The patent merges the separate programming equipment and secure configuration processes into the main production assembly lines. The system integrates programming capabilities, security key generation, and device authentication directly into the manufacturing flow, allowing devices to be configured and secured during normal production without requiring separate dedicated areas or equipment.
Solution Approach 2:
The programming equipment is designed to perform multiple functions: it can program various types of programmable devices (Flash memories, microcontrollers, FPGAs), generate security keys, authenticate devices, and integrate with different production line systems. This multi-functional approach eliminates the need for separate specialized equipment for each function.
2Reliability
If separate programming equipment is used for customizable devices, then security configuration control is improved, but device complexity and system integration difficulty worsen
Solution Approach 1:
The system employs universal interfaces and protocols that can handle multiple device types (Flash memories, microcontrollers, FPGAs, smart phones) through a single integrated platform. The programming equipment can adapt to different device architectures and security requirements without requiring separate specialized systems for each device category.
Solution Approach 2:
The patent introduces an intermediary programming system that acts as a bridge between the main production assembly lines and the programmable devices. This intermediary handles the complex communication protocols, authentication sequences, and security key management, shielding the main production system from complexity while maintaining secure configuration capabilities.
3Productivity
If bulk manufacturing is performed on assembly lines, then productivity is improved, but security customization for individual devices deteriorates
Solution Approach 1:
The system enables each programmable device to be individually authenticated and configured with its own unique security keys during the bulk manufacturing process. Devices present their identification, receive customized security configurations, and are authenticated individually by the programming system, allowing mass production while maintaining per-device security customization.
Solution Approach 2:
Security keys and authentication credentials are generated and configured into devices during the manufacturing process before the devices leave the production line. This preliminary security setup ensures that each device is pre-configured with its unique security identity, enabling both bulk production efficiency and individual security customization.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A secure programming system and method for provisioning and programming a target payload into a programmable device mounted in a programmer. The programmable device can be authenticated before programming to verify the device is a valid device produced by a silicon vendor. The target payload can be programmed into the programmable device and linked with an authorized manufacturer. The programmable device can be verified after programming the target payload by verifying the silicon vendor and the authorized manufacturer.