Authentication Proving Device for People Conveyor Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems for people conveyor control systems, such as elevators and escalators, face challenges in securely restricting access to authorized personnel for maintenance operations, as passwords and encryption keys can be easily compromised when stored on external PC-based devices, and memory cards can lead to unauthorized access if lost.

Innovation Solution

An access control system utilizing an authentication proving device with a central processor unit and read-protected memory, which communicates directly or indirectly with the conveyor control system to perform verification calculations and send verification signals, ensuring secure access by using dongle devices or smartcards that prevent unauthorized access through hardware-based protection and asymmetric encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are used for restricting access to the conveyor control system, then access control is implemented, but the passwords can be easily compromised when stored on external PC-based devices

Engineering Contradiction:
Improveaccess control securityVSAvoidpassword compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication data from external PC-based devices and stores it exclusively in protected memory within the conveyor control system itself. This extraction eliminates the vulnerability of storing passwords on external devices that can be easily accessed by unauthorized persons, while maintaining the access control functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where authentication data is stored in protected memory and accessed through controlled interfaces. This intermediary layer prevents direct access to passwords while enabling legitimate authentication, thus resolving the contradiction between security and accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If memory cards are used for granting access, then access control is simplified, but unauthorized access occurs if the memory card is lost

Engineering Contradiction:
Improveaccess control convenienceVSAvoidunauthorized access prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the authentication data storage with the conveyor control system's protected memory rather than using separate memory cards. This combination ensures that authentication credentials remain securely integrated within the controlled system, preventing unauthorized access even if external media are lost or compromised.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts authentication functionality from removable memory cards and embeds it within the controlled system's protected memory. This extraction eliminates the security risk of lost memory cards while maintaining ease of operation through structured access control.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encryption keys are stored in PC-based external devices, then access control is implemented, but severe data safety problems occur due to easy reading of keys

Engineering Contradiction:
Improveaccess control functionalityVSAvoiddata safety vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces protected memory as an intermediary between the encryption keys and external access points. This intermediary structure allows authentication to proceed while preventing direct reading of encryption keys from external devices, thus resolving the data safety vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts encryption keys from external PC-based devices and stores them exclusively in protected memory within the conveyor control system. This extraction eliminates the vulnerability of key storage on external devices while maintaining encryption-based access control functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If simple passwords are used for access control, then ease of operation is improved, but protection of proprietary control software is insufficient

Engineering Contradiction:
Improvepassword usabilityVSAvoidsoftware protection strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameter of authentication from simple passwords to structured authentication data stored in protected memory. This parameter change maintains ease of operation through controlled access interfaces while significantly strengthening software protection through secure storage and controlled retrieval mechanisms.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2368229B1Access control system and access control method for a people conveyor control system
Publication Date: 2019.09.11 OTIS ELEVATOR CO
  • EP2368229B1 patent drawingFigure 1
  • EP2368229B1 patent drawingFigure 2
  • EP2368229B1 patent drawingFigure 3

AI summary

Disclosed is an access control system for a people conveyor control system (10), comprising an authentication prooving device (14; 16; 20) adapted to communicate - directly or indirectly via at least one further device - with a people conveyor control system (10); said authentication prooving device (14; 16; 20) having a central processor unit and a read protected memory being protected from read and write access by external applications; said authentication prooving device (14; 16; 20) storing in its read protected memory program code to carry out a verification procedure in response to a verification request from said people conveyor control system (10), and to send a verification signal to said people conveyor control system (10); said people conveyor control system (10) in response to receipt of said verification signal selectively allowing or denying access to specific sections of said people conveyor control system and/or to specific functions implemented in said people conveyor control system (10).