Control Device Access Authorization with Encrypted Verification Backup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing control devices for machines and systems face challenges in securely managing access data, particularly for service employees, as access authorizations often remain unchanged, leading to security vulnerabilities and complications when service employees leave their positions, and current solutions are either inconvenient or impractical.
Innovation Solution
A method where a control device receives and stores encrypted verification data from a computer network, updates access authorizations by retaining old data for backup, and only allows access when the provided data matches current or old authorizations, using asymmetric encryption to ensure secure access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access data remains unchanged during the entire service life of the machine or system, then service employees can reliably access the control device, but security vulnerabilities increase and access control becomes compromised when employees leave
Solution Approach 1:
The patent implements dynamic access data that is periodically updated through encrypted transmissions from a remote server. The control device automatically receives and applies updates to access authorizations, transforming the static access control system into a dynamic one that adapts to changing security requirements while maintaining reliable access for authorized personnel
Solution Approach 2:
The control device autonomously manages access data updates by automatically receiving encrypted transmissions, validating the updates through cryptographic verification, and applying changes without requiring manual intervention. This self-service mechanism ensures continuous security updates while maintaining system reliability
2Object-affected harmful factors
If access data is frequently updated, then security is improved, but network dependency increases and access may be disrupted if the network link is disturbed
Solution Approach 1:
The system performs preliminary actions by maintaining a local copy of access data and implementing a update buffer mechanism. When network updates are unavailable, the control device continues to function using stored access data, and updates are applied once network connectivity is restored, ensuring uninterrupted access reliability
Solution Approach 2:
The patent implements cushioning mechanisms through encrypted backup storage of access data and cryptographic verification buffers. These pre-established safeguards allow the system to withstand network disturbances by validating and applying updates only when cryptographic verification succeeds, preventing access disruptions
3Adaptability or versatility
If service employees have continuous access to update access data, then access control flexibility is improved, but security risk increases if employees leave or credentials are compromised
Solution Approach 1:
The patent extracts the access data management function from local human operators and transfers it to a remote server that periodically transmits encrypted updates. This separation removes the security risk associated with continuous local access by service employees while maintaining flexibility through automated updates that can be applied at any time
Solution Approach 2:
The system introduces an intermediary encrypted transmission mechanism between the remote server and control device. This intermediary layer uses cryptographic protocols to securely transfer access data updates, enabling flexible access control management while eliminating direct human access risks through automated secure communication
4Ease of manufacture
If access data is transmitted in plain text for ease of updating, then update simplicity is improved, but security is compromised during transmission and storage
Solution Approach 1:
The patent replaces plain text transmission with cryptographic encryption mechanisms. The system uses asymmetric encryption where the control device holds private keys and verifies updates using public keys, substituting the simple but insecure mechanical approach of plain text with a more complex but secure cryptographic system that maintains update simplicity through automated verification
Solution Approach 2:
The system employs composite security mechanisms by combining encrypted transmission, cryptographic verification, and secure storage protocols. This composite approach integrates multiple security layers that work together to protect access data during transmission and storage while maintaining the simplicity of automated updates through unified cryptographic validation
Data Source
AI summary
A control device of a machine or system data compares access data with a current access authorization. If there is a match, access to user data stored in the control device is permitted. The control device occasionally accepts encrypted verification data from an external computer via a network and stores them encrypted or unencrypted as current verification data, with the current access authorization being derived from the unencrypted current verification data. Verification data already stored in the control device as current verification data when the verification data are accepted are retained as old verification data, while older verification data are overwritten. The accepted access data are compared with an old access authorization derived from the old verification data. An operator can access the user data only if there is a match with the old access authorization.


