Control Device Access Authorization with Encrypted Verification Backup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing control devices for machines and systems face challenges in securely managing access data, particularly for service employees, as access authorizations often remain unchanged, leading to security vulnerabilities and complications when service employees leave their positions, and current solutions are either inconvenient or impractical.

Innovation Solution

A method where a control device receives and stores encrypted verification data from a computer network, updates access authorizations by retaining old data for backup, and only allows access when the provided data matches current or old authorizations, using asymmetric encryption to ensure secure access management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access data remains unchanged during the entire service life of the machine or system, then service employees can reliably access the control device, but security vulnerabilities increase and access control becomes compromised when employees leave

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access data that is periodically updated through encrypted transmissions from a remote server. The control device automatically receives and applies updates to access authorizations, transforming the static access control system into a dynamic one that adapts to changing security requirements while maintaining reliable access for authorized personnel

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The control device autonomously manages access data updates by automatically receiving encrypted transmissions, validating the updates through cryptographic verification, and applying changes without requiring manual intervention. This self-service mechanism ensures continuous security updates while maintaining system reliability

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If access data is frequently updated, then security is improved, but network dependency increases and access may be disrupted if the network link is disturbed

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidaccess reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system performs preliminary actions by maintaining a local copy of access data and implementing a update buffer mechanism. When network updates are unavailable, the control device continues to function using stored access data, and updates are applied once network connectivity is restored, ensuring uninterrupted access reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements cushioning mechanisms through encrypted backup storage of access data and cryptographic verification buffers. These pre-established safeguards allow the system to withstand network disturbances by validating and applying updates only when cryptographic verification succeeds, preventing access disruptions

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Adaptability or versatility

If service employees have continuous access to update access data, then access control flexibility is improved, but security risk increases if employees leave or credentials are compromised

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the access data management function from local human operators and transfers it to a remote server that periodically transmits encrypted updates. This separation removes the security risk associated with continuous local access by service employees while maintaining flexibility through automated updates that can be applied at any time

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces an intermediary encrypted transmission mechanism between the remote server and control device. This intermediary layer uses cryptographic protocols to securely transfer access data updates, enabling flexible access control management while eliminating direct human access risks through automated secure communication

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of manufacture

If access data is transmitted in plain text for ease of updating, then update simplicity is improved, but security is compromised during transmission and storage

Engineering Contradiction:
Improveupdate simplicityVSAvoidtransmission security
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent replaces plain text transmission with cryptographic encryption mechanisms. The system uses asymmetric encryption where the control device holds private keys and verifies updates using public keys, substituting the simple but insecure mechanical approach of plain text with a more complex but secure cryptographic system that maintains update simplicity through automated verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system employs composite security mechanisms by combining encrypted transmission, cryptographic verification, and secure storage protocols. This composite approach integrates multiple security layers that work together to protect access data during transmission and storage while maintaining the simplicity of automated updates through unified cryptographic validation

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS11182495B2Secure management of access data for control devices
Publication Date: 2021.11.23 SIEMENS AG
  • US11182495B2 patent drawing
  • US11182495B2 patent drawing
  • US11182495B2 patent drawing

AI summary

A control device of a machine or system data compares access data with a current access authorization. If there is a match, access to user data stored in the control device is permitted. The control device occasionally accepts encrypted verification data from an external computer via a network and stores them encrypted or unencrypted as current verification data, with the current access authorization being derived from the unencrypted current verification data. Verification data already stored in the control device as current verification data when the verification data are accepted are retained as old verification data, while older verification data are overwritten. The accepted access data are compared with an old access authorization derived from the old verification data. An operator can access the user data only if there is a match with the old access authorization.