Appliance Port Security via Remote Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial appliances with external service ports, such as RJ45 connections, are vulnerable to unauthorized access and tampering, particularly in public or shared environments where financial transactions are involved, necessitating a secure authentication mechanism to regulate access to operating software.

Innovation Solution

Incorporating a wireless communication module and controller that receives a secure unlock command from a remote server, allowing authorized access to the external communication port for maintenance or software updates, while locking the port to prevent unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an external service port (RJ45 connection) is provided on the appliance for programming and data collection, then ease of operation for authorized users is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveaccess to operating softwareVSAvoidunauthorized access and tampering
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a remote server as an intermediary between authorized users and the appliance's external service port. The server authenticates users before granting access credentials, acting as a mediator that enables legitimate access while blocking unauthorized attempts. This resolves the contradiction by adding a security layer that doesn't prevent authorized operation but filters out malicious access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and credential verification before allowing access to the external service port. The remote server checks user credentials in advance and only provides access tokens to authenticated users. This preliminary security check ensures that the service port remains accessible to authorized users while preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If the external service port is locked to prevent unauthorized access, then security is improved, but ease of operation for authorized maintenance deteriorates

Engineering Contradiction:
Improveappliance tamperingVSAvoidsoftware updates and maintenance
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The external service port's access state is made dynamic rather than static. The port can be locked or unlocked based on real-time authentication results from the remote server. Authorized users receive dynamic credentials that temporarily enable access, while unauthorized users encounter locked ports. This dynamic approach maintains security while enabling maintenance operations when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where the remote server continuously monitors access attempts to the external service port. When authentication fails, the system provides feedback by denying access and alerting administrators. When authentication succeeds, feedback enables the port for authorized operations. This feedback mechanism ensures security is maintained without preventing legitimate maintenance.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If authentication mechanisms are implemented for the external service port, then security against unauthorized usage is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidaccess control system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The complex authentication and credential management functionality is extracted from the appliance itself and placed on a remote server. The appliance only needs to implement simple credential verification and port locking/unlocking, while the heavy lifting of user management, authentication, and security policy enforcement is performed externally. This extraction reduces the appliance's complexity while maintaining strong security through the remote server.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11947714B2System and method for authorizing appliance access
Publication Date: 2024.04.02 HAIER US APPLIANCE SOLUTIONS INC
  • US11947714B2 patent drawing
  • US11947714B2 patent drawing
  • US11947714B2 patent drawing

AI summary

An appliance includes an external communication port, such as an RJ45 port, and a wireless communication module in wireless communication with a remote server through an external network. A controller is configured to receive, using the wireless communication module, a secure unlock command from a remote server, the secure unlock command being generated when a remote service device transmits appliance identification data to the remote server, and unlock the external communication port to permit the remote service device to access operating software through the external communication port.