Certificate-Based Apparatus Control Without VPN Complexity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT and IIoT platforms face security and complexity challenges in information and communication technology networking and data transmission, often requiring high technical effort for secure data transmission via VPNs.

Innovation Solution

A method and communication apparatus that verifies identifiers and encryption keys using certificates to ensure secure data transmission without the need for VPNs, involving steps of verification, decryption, and authorization checks to generate and send control commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN is used for secure data transmission, then security is improved, but device complexity and hardware/software requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidtechnical complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security verification functionality from the VPN protocol suite, implementing only the necessary certificate-based authentication and encryption key verification. This selective extraction maintains security while eliminating unnecessary VPN complexity and reducing hardware/software requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a certificate-based intermediary mechanism that mediates between communication devices. Instead of requiring full VPN infrastructure, devices use certificates as trusted intermediaries to verify identities and establish secure communication, simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VPN is used for secure data transmission, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary certificate verification and encryption key validation before actual data transmission begins. By pre-establishing trust through certificate checks and verifying encryption keys in advance, the system automates security setup procedures, making operation easier while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If certificate verification and encryption key validation are performed, then security is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs certificate verification and encryption key validation as preliminary actions before data transmission. By completing these security checks in advance rather than during data transfer, the system minimizes the impact on processing time while ensuring security requirements are met.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250279900A1Method for controlling an apparatus, method for transmitting operating data of an apparatus, communication apparatus for use in such methods, computer program, computer-readable medium and data carrier signal
Publication Date: 2025.09.04 UMH SYST GMBH
  • US20250279900A1 patent drawing
  • US20250279900A1 patent drawing
  • US20250279900A1 patent drawing

AI summary

The invention relates to a method for controlling an apparatus (10), whereina communication apparatus (12) is connected to the apparatus (10);in a step S1, the communication apparatus (12) receives a plaintext and a signature from a sender apparatus (14);in a step S2, the communication apparatus (12) verifies a first identifier (ID1), which is assigned to the sender apparatus (14), and a first encryption key (CS1) using a valid first certificate (Z1) and aborts the method if the result of this verification is negative;in a step S3, the communication apparatus (12) verifies the received signature and the received plaintext using the first encryption key (CS1) and aborts the method if the result of this verification is negative;in a step S4, the communication apparatus (12) checks whether a control instruction for the apparatus (10) is contained in the plaintext, and aborts the method if the result of this check is negative;in a step S5, the communication apparatus (12) checks whether an authorization for the control instruction is assigned to the first encryption key (CS1) and/or the first identifier (ID1), and aborts the method if the result of this check is negative;in a step S6, the communication apparatus (12) generates a control command for the apparatus (10) using the control instruction contained in the recovered plaintext; andin a step S7, the communication apparatus (12) sends the control command to the apparatus (10), whereby the apparatus (10) is controlled.This enables a secure information technological and communication technological networking and data transmission between the sender apparatus (14) and the apparatus (12).