Certificate-Based Apparatus Control Without VPN Complexity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT and IIoT platforms face security and complexity challenges in information and communication technology networking and data transmission, often requiring high technical effort for secure data transmission via VPNs.
Innovation Solution
A method and communication apparatus that verifies identifiers and encryption keys using certificates to ensure secure data transmission without the need for VPNs, involving steps of verification, decryption, and authorization checks to generate and send control commands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN is used for secure data transmission, then security is improved, but device complexity and hardware/software requirements increase
Solution Approach 1:
The patent extracts the essential security verification functionality from the VPN protocol suite, implementing only the necessary certificate-based authentication and encryption key verification. This selective extraction maintains security while eliminating unnecessary VPN complexity and reducing hardware/software requirements.
Solution Approach 2:
The patent introduces a certificate-based intermediary mechanism that mediates between communication devices. Instead of requiring full VPN infrastructure, devices use certificates as trusted intermediaries to verify identities and establish secure communication, simplifying the overall system architecture.
2Reliability
If VPN is used for secure data transmission, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements preliminary certificate verification and encryption key validation before actual data transmission begins. By pre-establishing trust through certificate checks and verifying encryption keys in advance, the system automates security setup procedures, making operation easier while maintaining high security standards.
3Reliability
If certificate verification and encryption key validation are performed, then security is improved, but processing time increases
Solution Approach 1:
The patent performs certificate verification and encryption key validation as preliminary actions before data transmission. By completing these security checks in advance rather than during data transfer, the system minimizes the impact on processing time while ensuring security requirements are met.
Data Source
AI summary
The invention relates to a method for controlling an apparatus (10), whereina communication apparatus (12) is connected to the apparatus (10);in a step S1, the communication apparatus (12) receives a plaintext and a signature from a sender apparatus (14);in a step S2, the communication apparatus (12) verifies a first identifier (ID1), which is assigned to the sender apparatus (14), and a first encryption key (CS1) using a valid first certificate (Z1) and aborts the method if the result of this verification is negative;in a step S3, the communication apparatus (12) verifies the received signature and the received plaintext using the first encryption key (CS1) and aborts the method if the result of this verification is negative;in a step S4, the communication apparatus (12) checks whether a control instruction for the apparatus (10) is contained in the plaintext, and aborts the method if the result of this check is negative;in a step S5, the communication apparatus (12) checks whether an authorization for the control instruction is assigned to the first encryption key (CS1) and/or the first identifier (ID1), and aborts the method if the result of this check is negative;in a step S6, the communication apparatus (12) generates a control command for the apparatus (10) using the control instruction contained in the recovered plaintext; andin a step S7, the communication apparatus (12) sends the control command to the apparatus (10), whereby the apparatus (10) is controlled.This enables a secure information technological and communication technological networking and data transmission between the sender apparatus (14) and the apparatus (12).


