Control Device Dual Maintenance Mode Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control devices, such as robots and NC machine tools, require reliable management of storage content for operation, but existing systems lack robust security measures for updating and maintaining this content, especially in maintenance modes with varying levels of access.

Innovation Solution

A control device with a nonvolatile storage unit, a control calculation unit, and dual security management units that use hardware keys for permission checks in one mode and security codes in another, allowing for secure updates and restricted access in different maintenance modes without complicating operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware key is used for security check in maintenance mode, then security reliability is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The maintenance mode is segmented into two distinct levels: first maintenance mode requiring hardware key authentication for high-security operations, and second maintenance mode using simple password authentication for routine operations. This segmentation allows the system to apply appropriate security measures only where needed, improving security reliability without unnecessarily increasing device complexity across all operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts the security check method based on the selected maintenance mode. When first maintenance mode is selected, hardware key authentication is activated; when second maintenance mode is selected, simple password authentication is used. This dynamic adaptation allows the system to maintain high security when needed while preserving ease of operation for routine tasks.

Inventive Principle:
Principle #15Dynamics

2Reliability

If a hardware key is used for security check in maintenance mode, then security reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The maintenance mode is segmented into two distinct levels: first maintenance mode requiring hardware key authentication for high-security operations, and second maintenance mode using simple password authentication for routine operations. This segmentation allows the system to apply appropriate security measures only where needed, improving security reliability without unnecessarily increasing device complexity across all operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts the security check method based on the selected maintenance mode. When first maintenance mode is selected, hardware key authentication is activated; when second maintenance mode is selected, simple password authentication is used. This dynamic adaptation allows the system to maintain high security when needed while preserving ease of operation for routine tasks.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If security check is conducted without hardware key in second maintenance mode, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Different security measures are applied to different maintenance modes based on their specific requirements. The first maintenance mode, which handles critical security-sensitive operations, uses strong hardware key authentication. The second maintenance mode, used for routine operations, uses simpler password authentication. This local differentiation ensures that security reliability is optimized for each specific operational context without over-securing all operations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the security check method based on the selected maintenance mode. When first maintenance mode is selected, hardware key authentication is activated; when second maintenance mode is selected, simple password authentication is used. This dynamic adaptation allows the system to maintain high security when needed while preserving ease of operation for routine tasks.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If dual maintenance modes are provided, then adaptability is improved, but device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The maintenance mode is segmented into two distinct levels: first maintenance mode requiring hardware key authentication for high-security operations, and second maintenance mode using simple password authentication for routine operations. This segmentation allows the system to apply appropriate security measures only where needed, improving security reliability without unnecessarily increasing device complexity across all operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control device is designed to handle multiple maintenance modes and authentication methods within a single unified system. The security check unit can switch between hardware key authentication and password authentication based on the selected maintenance mode, providing multi-functionality without requiring separate systems for each operation type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9709970B2Control device, security management system, and security management method
Publication Date: 2017.07.18 YASKAWA DENKI KK
  • US9709970B2 patent drawing
  • US9709970B2 patent drawing
  • US9709970B2 patent drawing

AI summary

A central processing unit of a control device includes: a control calculation unit that performs calculation on the basis of storage content of a nonvolatile storage unit and controls a machine; an update unit that accepts operation input in a first maintenance mode or a second maintenance mode, which has a narrower operable range than the first maintenance mode, and updates the storage content of the nonvolatile storage unit in accordance with the operation input; a security management unit that determines permission or prohibition of the operation input in the first maintenance mode with the use of a hardware key; and a security management unit that determines permission or prohibition of the operation input in the second maintenance mode without the use of the hardware key.