Client Device Service Key Activation Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for securing maintenance and service functions on devices, such as medical products, face challenges in ensuring only authorized and trained personnel can perform tasks, as existing authorization methods are costly and complex, requiring continuous online links and increased computing capacity, and are not feasible for all devices.

Innovation Solution

A client device with a storage unit for service keys, each defining device functions and allocated to a password, receives a password from a server, compares it with stored keys, and activates the corresponding function, using a processing unit to verify digital signatures, ensuring only the manufacturer can generate service keys, and deactivating them after a specified period.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a permanent on-line link with the manufacturer is established to provide continuous authorization, then the reliability of authorization is improved, but the device complexity and computing capacity requirements increase

Engineering Contradiction:
Improveauthorization reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-storing multiple service keys in the client device before authorization is needed. Each service key is paired with a password and defines specific functions that can be activated. When authorization is required, the client simply compares the received password with the pre-stored service keys locally, eliminating the need for continuous online connection while maintaining secure authorization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating local copies of authorization data (service keys) in the client device. Instead of maintaining a live connection to the manufacturer's server for authorization verification, the client stores encrypted copies of service keys that can be independently verified against received passwords, reducing dependency on continuous online communication.

Inventive Principle:
Principle #26Copying

2Reliability

If complicated authorization information items are processed to ensure proper training and authorization, then the security and reliability of maintenance operations are improved, but the device complexity and processing requirements increase

Engineering Contradiction:
Improvemaintenance authorization reliabilityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the authorization system into discrete service keys, each defining specific functions and associated with unique passwords. This segmentation allows the complex authorization process to be broken down into simple comparisons between received passwords and pre-stored service key-password pairs, reducing processing complexity while maintaining comprehensive authorization control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses disposable service keys that are pre-stored in the client device and activated once with the corresponding password. These service keys are designed to be simple, fixed-structure authorization tokens that can be easily compared and deactivated after use, avoiding the need for complex continuous verification processes while ensuring proper authorization for maintenance operations.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If service keys are stored in advance in the client device, then the ease of operation is improved, but the security risk of storing authorization data increases

Engineering Contradiction:
Improveauthorization easeVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism using encrypted service keys and password-based verification. The service keys are stored in an encrypted form in the client device, and authorization is achieved through comparison with received passwords rather than direct use of stored credentials. This intermediary layer of encryption and verification maintains ease of operation while significantly reducing security risks associated with storing authorization data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10284546B2Client device and server device for the secured activation of functions of a client
Publication Date: 2019.05.07 SIEMENS AG
  • US10284546B2 patent drawing

AI summary

A client device for the secured activation of functions of a client, a server device for providing a password for the client device, and corresponding methods. The client device has a storage unit for storing a plurality of service keys, each service key defining at least one function of the client and being allocated to a password, a receiving unit for receiving a password from a server, and a processing unit for comparing the plurality of service keys with the received password, for selecting the service key to which the received password is allocated, and for activating at least one function of the client which is contained in the selected service key.