Intermediary Access Control Device for Legacy IT Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT systems face security compromises due to users remaining permanently logged in with their passwords across multiple systems, making it difficult to implement additional authentication measures without software adjustments, especially in older systems or those with data exchange, which can lead to instability or liability issues.
Innovation Solution
A device with a computing unit and operating units that receive and transmit electrical signals, utilizing an electromagnetic access message to generate a switching signal for activating signal transmission, allowing secure access without software changes, featuring a token-based authentication system for easy and secure operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software modifications are made to implement additional authentication methods, then access security is improved, but system stability deteriorates and complexity increases
Solution Approach 1:
The patent introduces an intermediary authentication device positioned between the user and the IT system. This device intercepts and validates authentication credentials (passwords, tokens, biometric data) before allowing communication with the IT system, thereby improving security without modifying the IT system's software architecture.
Solution Approach 2:
The authentication function is segmented from the IT system into a separate, standalone authentication device. This segmentation allows the IT system to remain unchanged while security capabilities are enhanced through the independent authentication module, reducing complexity and avoiding software integration issues.
2Reliability
If software modifications are made to support new authentication methods, then access security is improved, but system stability deteriorates
Solution Approach 1:
The authentication device acts as a mediator that handles all authentication processing externally. By positioning this intermediary between the user and the IT system, the patent enables enhanced security through multiple authentication factors without introducing software changes that could destabilize the IT system's operation.
Solution Approach 2:
The authentication functionality is extracted from the IT system and implemented in a separate device. This extraction ensures that the IT system's operational stability is maintained while security is improved through the independent authentication mechanism that operates parallel to the main system.
3Ease of operation
If password-based authentication is used across multiple IT systems, then ease of operation is improved, but access security deteriorates
Solution Approach 1:
The authentication device provides universal authentication capabilities that work across multiple IT systems through a single interface. Users authenticate once through the device using multiple factors (password, token, biometric), and the device manages authentication for various systems, maintaining ease of operation while enhancing security through multi-factor verification.
Solution Approach 2:
The authentication device serves as a universal intermediary that standardizes the authentication process across different IT systems. It maintains the simple user interaction of single-point login while internally implementing enhanced security measures, thus resolving the contradiction between operational simplicity and security robustness.
Data Source
Figure 1~2
AI summary
The invention relates to an access control in the form of an apparatus. The apparatus can be used to unlock a device, wherein the device has a computation unit and at least one operator control unit that is electrically connectable to the computation unit, wherein the apparatus has a first reception unit for receiving electrical signals from the at least one operator control unit, a transmission unit for transmitting the electrical signals to the computation unit, a second reception unit for receiving at least one access message transmitted by means of an electromagnetic signal, an authorisation unit for generating a switching signal if the result of the check on the access message is that unlocking of the device is permitted by means of the access message, and an unlocking unit for unlocking a transmission of electrical signals from the first reception unit to the transmission unit on the basis of the switching signal. The invention and the developments thereof can be used, inter alia, in security-critical installations, such as a computer centre, a substation of an energy supplier, in production installations or in a hospital.