IP Library Granted Patent US 10,069,633
Granted Patent B2
US 10,069,633 · App. 15/717,925 · Granted Sep 4, 2018

Unified programming environment for programmable devices

Inventors: Rajeev Gulati (Sammamish, WA); David R. Christie (Woodinville, WA); Edwin R. Musch (Redmond, WA); Benjamin M. Deagen (Lynnwood, WA)
Assignee: Data I/O Corporation
H04L9/3263G06F8/61G06F9/4406H04L9/14H04L9/30G06F9/44G06F21/57G06F21/572G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,069,633
App. No.
15/717,925
Granted
Sep 4, 2018
Kind
B2
Abstract

A secure programming system can receive a job control package having a security kernel and a target payload of content for programming into a pre-defined set of trusted devices. A device programmer can install a security kernel on the trusted devices and reboot the trusted devices using the security kernel to validate the proper operation of the security kernel. The target payload can then be securely installed on the trusted devices and validated.

Claims (58)

1. A method of operation of a secure programming system comprising:

retrieving a job control package having a security kernel, an authentication list, and a target payload;

loading a programmable device into a programmer;

authenticating a device identifier of the programmable device by matching with an authentication identifier of the authentication list;

installing the security kernel in the programmable device based on the authentication of the device identifier;

rebooting the programmable device in the programmer to generate a validation code of the security kernel by activating the security kernel;

validating the security kernel of the programmable device by matching a signing code to the validation code; and

provisioning the programmable device with the target payload based on a successful validation of the security kernel.

2. The method as claimed in claim 1 , wherein rebooting the programmable device includes sending a reboot command to the programmable device mounted in the programmer.

3. The method as claimed in claim 1 , further comprising:

retrieving a silicon vendor device certificate from the programmable device;

extracting a silicon vendor public key from the target payload;

generating the validation code by authenticating the silicon vendor device certificate with the silicon vendor public key;

extracting an identification token from the silicon vendor device certificate, the identification token encrypted by the silicon vendor device public key; and

authenticating the identification token using a silicon vendor device private key.

4. An apparatus comprising:

a programming unit configured to retrieve a job control package having a security kernel, an authentication list, and a target payload and to authenticate a device identifier of a programmable device by matching with an authentication identifier of the authentication list;

a programmer of the programming unit configured to load a programmable device into the programmer, install the security kernel in the programmable device based on the authentication of the device identifier, reboot the programmable device in the programmer to generate a validation code of the security kernel by activating the security kernel, and provision the programmable device with the target payload based on a successful validation of the security kernel; and

a security controller of the programming unit configured to validate the security kernel of the programmable device by matching a signing code to the validation code retrieved from the security kernel after rebooting.

5. The apparatus as claimed in claim 4 , wherein the programmer is configured to send a reboot command to the programmable device mounted in the programmer.

6. The apparatus as claimed in claim 4 , wherein the programming unit includes:

the programmer configured to retrieve a silicon vendor device certificate from the programmable device; and

the security controller configured to extract a silicon vendor public key from the target payload, to generate the validation code by authenticating the silicon vendor device certificate with the silicon vendor public key, to extract an identification token from the silicon vendor device certificate, the identification token encrypted by the silicon vendor device public key, and to authenticate the identification token using a silicon vendor device private key.

7. The apparatus as claimed in claim 4 , wherein the programming unit includes:

the security controller configured to extract a firmware image from the target payload and to decrypt the firmware image; and

the programmer configured to copy the firmware image to the programmable device.

8. The apparatus as claimed in claim 4 , wherein the programming unit includes the security controller configured to calculate a device validation status based on a module list of the programmable device matching another module list of the target payload and configured to insert the device validation status into a validation report.

9. The apparatus as claimed in claim 4 , wherein:

the programming unit configured to retrieve the security kernel in an encrypted format in the job control package;

the security controller configured to decrypt the security kernel with a public key pre-loaded in a programming unit; and

the programmer configured to install the security kernel in an unencrypted format into the programmable device.

10. The apparatus as claimed in claim 4 , further comprising a hardware security module outside the programming unit configured to encrypt the security kernel with a programmer public key, an OEM public key, or a silicon vendor public key and to form the job control package with the security kernel in an encrypted format.

11. One or more non-transitory computer-readable media storing instructions that, when executed by one or more computing devices, cause:

retrieving a job control package having a security kernel and a target payload;

loading a programmable device into a programmer;

authenticating a device identifier of the programmable device by matching with an authentication identifier of the authentication list;

installing the security kernel in the programmable device based on the authentication of the device identifier;

rebooting the programmable device in the programmer to generate a validation code of the security kernel by activating the security kernel;

validating the security kernel of the programmable device by matching a signing code to the validation code; and

provisioning the programmable device with the target payload based on a successful validation of the security kernel.

12. The one or more non-transitory computer-readable media of claim 11 , wherein rebooting the programmable device includes sending a reboot command to the programmable device mounted in the programmer.

13. The one or more non-transitory computer-readable media of claim 11 , wherein the instruction when executed by the one or more computing devices, further cause:

retrieving a silicon vendor device certificate from the programmable device;

extracting a silicon vendor public key from the target payload;

generating the validation code by authenticating the silicon vendor device certificate with the silicon vendor public key;

extracting an identification token from the silicon vendor device certificate, the identification token encrypted by the silicon vendor device public key; and

authenticating the identification token using a silicon vendor device private key.

14. The one or more non-transitory computer-readable media of claim 11 , wherein provisioning the programmable device includes:

extracting a firmware image from the target payload;

decrypting the firmware image; and

copying the firmware image to the programmable device.

15. The one or more non-transitory computer-readable media of claim 11 , wherein the instruction when executed by the one or more computing devices, further cause:

calculating a device validation status based on a module list of the programmable device matching another module list of the target payload; and

inserting the device validation status into a validation report.

16. The one or more non-transitory computer-readable media of claim 11 , wherein retrieving the job control package includes:

retrieving the security kernel in an encrypted format in the job control package;

decrypting the security kernel with a public key pre-loaded in a programming unit; and

installing the security kernel in an unencrypted format into the programmable device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2017
From: GULATI, RAJEEV; CHRISTIE, DAVID R.; MUSCH, EDWIN R.; DEGAN, BENJAMIN M.
To: DATA I/O CORPORATION
Reel/Frame 043934/0374 →
Continuity (2)
Provisional Application 62401953 · Sep 30, 2016
Related Publication 20180097639A1 · Apr 5, 2018
Cited By (36)
US 12,193,636 US 12,193,766 US 12,207,817 US 12,226,151 US 12,226,166 US 12,232,729 US 12,239,320 US 12,256,995 US 12,295,674 US 12,303,159 US 12,310,586 US 12,318,152 US 12,329,467 US 12,376,855 US 12,383,115 US 12,396,806 US 12,433,508 US 12,458,351 US 12,500,948 US 12,514,584 US 12,521,191 US 12,549,622 US 12,572,661 US 12,574,254 US 12,574,255 US 12,574,434 US 12,575,855 US 12,582,457 US 12,587,390 US 12,648,789 US 12,653,628 US 12,657,304 US 12,672,922 US 12,688,028 US 12,708,427 US 12,730,894