Communication Control Device for Secure Social Infrastructure Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Social infrastructure devices, such as monitoring cameras, face challenges in maintaining data security due to the difficulty in frequently replacing equipment and the risk of malware attacks, especially since they often lack the resources for encryption processes.

Innovation Solution

A communication system with client-side and server-side communication control devices that encrypt and decrypt data using SSL/TLS protocols, leveraging IC cards for authentication and key management, allowing secure data transmission without requiring hardware changes to the existing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption processes are implemented to protect data security, then security level is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvedata securityVSAvoidencryption process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a communication control device as an intermediary between the monitoring camera and the server. This mediator handles all encryption and decryption operations, allowing the monitoring camera to transmit data in plain text without requiring encryption capabilities. The communication control device establishes secure SSL/TLS connections with both the camera and the server, effectively mediating the security requirements while keeping the original devices simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If equipment is replaced with more secure models, then security level is improved, but maintenance cost and operational disruption increase

Engineering Contradiction:
Improvesecurity levelVSAvoidequipment replacement difficulty
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent implements security measures in advance by deploying communication control devices before any potential security incidents occur. These devices pre-establish secure communication channels and authentication mechanisms (including certificate-based authentication) so that existing monitoring cameras can immediately benefit from enhanced security without requiring modifications or replacements. The security infrastructure is prepared beforehand and transparently applied to all connected devices.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication mechanisms are added to existing devices, then security level is improved, but device complexity and resource usage increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the monitoring cameras and concentrates it in the communication control device. The communication control device manages certificate storage, authentication verification, and session management, while the monitoring cameras simply transmit data without any authentication processing. This extraction allows existing cameras to maintain their simplicity while the system as a whole achieves strong authentication capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3913851B1Communication control device and communication system
Publication Date: 2024.02.28 KK TOSHIBA
  • EP3913851B1 patent drawingFigure 1
  • EP3913851B1 patent drawingFigure 2
  • EP3913851B1 patent drawingFigure 3~4

AI summary

According to an embodiment, a communication control device includes a communication interface, a controller, and a memory. The communication interface communicates with a first device and a device connected via a network communication network. The controller configured to transmit, to a second communication control device connected between a second device and a network communication network, information obtained by encrypting information transmitted from the first device to the second device, and transmit, to the first device, information obtained by decrypting information transmitted from the second device to the first device, using a common key determined by a mutual authentication process with the second communication control device using a secret key and a client certificate issued by a private authentication authority. The memory stores analysis information of a communication amount of data communication carried out via the communication interface. The controller transmits log information to a device management server at an execution time set based on the analysis information of the communication amount stored in the memory.