Portable Certificate Management Apparatus for Secure Device Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In installations without a communication connection to a registration authority or certification authority, the frequent visits required for certificate updating and management are inefficient, as they necessitate multiple trips by service engineers to check and install new operative certificates.

Innovation Solution

A computer apparatus that establishes a connection with a device to transmit a certificate valid for a first time period, receives a further certificate request for a second time period, and breaks the connection, allowing for subsequent retrieval of the new certificate from the certification authority, thereby reducing the need for direct communication with the certification authority and minimizing on-site visits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If the device is directly connected to the certification authority for certificate updates, then certificate management can be automated, but the device must remain connected to public networks which compromises security

Engineering Contradiction:
Improvecertificate management automationVSAvoidsecurity risk from public network connection
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The portable computer acts as an intermediary between the certification authority and the device. It establishes a temporary connection to the certification authority to download certificates, then transmits them to the device through a separate coupling process, eliminating the need for the device to directly connect to public networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The certificate management process is segmented into distinct phases: (1) The portable computer connects to the certification authority to obtain certificates, (2) The portable computer couples to the device to transmit certificates, (3) The connection is broken after transmission. This segmentation allows automated certificate management while maintaining security by decoupling the device from public networks.

Inventive Principle:
Principle #1Segmentation

2Reliability

If service engineers visit the installation frequently for certificate updates, then certificates can be kept current, but the number of visits and time required increases

Engineering Contradiction:
Improvecertificate validityVSAvoidservice engineer visit time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device is enabled to autonomously generate certificate requests and receive certificates through the portable computer without requiring service engineer intervention for each update. The system performs self-service certificate management by allowing the device to initiate certificate requests and receive updates through the intermediary portable computer.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The portable computer retrieves certificates from the certification authority in advance before coupling to the device. This preliminary action allows certificates to be prepared and ready for transmission, reducing the time required during actual device updates and minimizing the need for frequent service engineer visits.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If the connection between the computer apparatus and the device remains established for multiple operations, then multiple certificates can be transmitted in one session, but the connection remains open longer potentially exposing security risks

Engineering Contradiction:
Improvecertificate transmission efficiencyVSAvoidsecurity exposure from prolonged connection
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system uses periodic, time-limited coupling sessions between the portable computer and the device. Each coupling establishes a temporary connection for certificate transmission, then the connection is broken. This periodic action allows multiple certificates to be transmitted in organized sessions while limiting exposure time by systematically closing connections after each transmission cycle.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10680832B2Computer apparatus for transmitting a certificate to a device in an installation
Publication Date: 2020.06.09 SIEMENS SCHWEIZ AG
  • US10680832B2 patent drawing

AI summary

A computer apparatus for transmitting a certificate to a device in an installation is provided. The computer apparatus has a coupling unit for establishing and breaking a connection between the computer apparatus and the device, a processing unit for transmitting a certificate to the device by means of the established connection, wherein the certificate is valid for a first time period and is issued by a certification authority based on a certificate request, and a receiving unit for receiving a further certificate request from the device by means of the established connection, wherein the further certificate request is designed to request a certificate for a second time period, wherein the coupling unit is designed to break the connection after the certificate is transmitted and the further certificate request is received.