Auditor-Based Workstation Authentication for Secure Process Start

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack secure and centralized monitoring capabilities for technical devices and systems, especially in distributed networks, and fail to ensure the authenticity of device components and data transmission, leading to potential damage from malware and incorrect configurations.

Innovation Solution

A system comprising a workstation, detection device, control device, and auditor device, where the auditor device, potentially a hardware security module (HSM), monitors and authenticates system components, ensuring secure data transmission and process integrity by querying and verifying IDs, and using cryptographic means to secure transactions and information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized monitoring is implemented to check system components and data transmission, then security and reliability are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvesystem securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an auditor device as an intermediary component that independently monitors system components, data transmission, and configuration. This auditor acts as a mediator between the system controller and external monitoring entities, providing centralized security checks without requiring complex integration into existing system architecture. The auditor device receives information from system components and verifies their authenticity, thereby improving reliability while maintaining manageable system complexity through clear separation of monitoring functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication of system components is performed to prevent malware damage, then system reliability is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improveprotection against malwareVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication by having system components present their identifiers and configuration information to the auditor device before executing critical operations. The auditor verifies the authenticity of components, checks configuration correctness, and validates data transmission integrity in advance. This preliminary verification ensures that only authenticated and properly configured components can perform work processes, preventing malware execution while minimizing time loss by performing checks before rather than during critical operations.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If detailed configuration checks are performed on system components, then measurement precision of system state is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improveconfiguration verification accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the monitoring function into distinct modular components within the auditor device, including separate modules for verifying component identifiers, checking configuration information, validating data transmission, and assessing component readiness. Each module handles a specific aspect of verification independently, allowing detailed and precise configuration checks without creating a monolithic complex system. This segmentation enables high measurement precision in configuration verification while keeping the overall device complexity manageable through clear functional separation and independent verification of each system component's identifier, configuration, and operational status.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3671379B1Authentication system and authentication method for performing a work process on an object
Publication Date: 2023.07.26 FRANCOTYP POSTALIA AG & CO KG
  • EP3671379B1 patent drawingFigure 1
  • EP3671379B1 patent drawingFigure 2

AI summary

The invention relates to a system (1) and a method for carrying out a work process on an object (3), wherein the system comprises at least one workstation (11), a detection device (5), a control device (7) and an auditor device (9), and the auditor device is configured to query and check configuration information from the detection device and to forward a result of the check to the control device, which processes this result and, depending on it, starts the work process or not.