Intermediary Access Control Device for Legacy IT Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IT systems face security compromises due to users remaining permanently logged in with their passwords across multiple systems, making it difficult to implement additional authentication measures without software adjustments, especially in older systems or those with data exchange, which can lead to instability or liability issues.

Innovation Solution

A device with a computing unit and operating units that receive and transmit electrical signals, utilizing an electromagnetic access message to generate a switching signal for activating signal transmission, allowing secure access without software changes, featuring a token-based authentication system for easy and secure operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software modifications are made to implement additional authentication methods, then access security is improved, but system stability deteriorates and complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidsoftware modification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication device positioned between the user and the IT system. This device intercepts and validates authentication credentials (passwords, tokens, biometric data) before allowing communication with the IT system, thereby improving security without modifying the IT system's software architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication function is segmented from the IT system into a separate, standalone authentication device. This segmentation allows the IT system to remain unchanged while security capabilities are enhanced through the independent authentication module, reducing complexity and avoiding software integration issues.

Inventive Principle:
Principle #1Segmentation

2Reliability

If software modifications are made to support new authentication methods, then access security is improved, but system stability deteriorates

Engineering Contradiction:
Improveaccess securityVSAvoidsystem operation stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The authentication device acts as a mediator that handles all authentication processing externally. By positioning this intermediary between the user and the IT system, the patent enables enhanced security through multiple authentication factors without introducing software changes that could destabilize the IT system's operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication functionality is extracted from the IT system and implemented in a separate device. This extraction ensures that the IT system's operational stability is maintained while security is improved through the independent authentication mechanism that operates parallel to the main system.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If password-based authentication is used across multiple IT systems, then ease of operation is improved, but access security deteriorates

Engineering Contradiction:
Improvelogin simplicityVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication device provides universal authentication capabilities that work across multiple IT systems through a single interface. Users authenticate once through the device using multiple factors (password, token, biometric), and the device manages authentication for various systems, maintaining ease of operation while enhancing security through multi-factor verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication device serves as a universal intermediary that standardizes the authentication process across different IT systems. It maintains the simple user interaction of single-point login while internally implementing enhanced security measures, thus resolving the contradiction between operational simplicity and security robustness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3417394B1Access control
Publication Date: 2024.04.17 SIEMENS AG
  • EP3417394B1 patent drawingFigure 1~2

AI summary

The invention relates to an access control in the form of an apparatus. The apparatus can be used to unlock a device, wherein the device has a computation unit and at least one operator control unit that is electrically connectable to the computation unit, wherein the apparatus has a first reception unit for receiving electrical signals from the at least one operator control unit, a transmission unit for transmitting the electrical signals to the computation unit, a second reception unit for receiving at least one access message transmitted by means of an electromagnetic signal, an authorisation unit for generating a switching signal if the result of the check on the access message is that unlocking of the device is permitted by means of the access message, and an unlocking unit for unlocking a transmission of electrical signals from the first reception unit to the transmission unit on the basis of the switching signal. The invention and the developments thereof can be used, inter alia, in security-critical installations, such as a computer centre, a substation of an energy supplier, in production installations or in a hospital.