Control Device for Secure External Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network-connected and internet-connected devices are vulnerable to unauthorized access due to their connectivity and outdated firmware or software, which compromises their security without reducing their convenience.

Innovation Solution

A control system and method that uses a control device with processor circuitry and switches to manage access through communication networks, operating in a default access-denied mode until user authorization is verified, providing an approval code for temporary access to external devices via ports, and optionally updating firmware or software to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network-connected devices are made accessible via communication networks, then user convenience is improved, but security vulnerability increases due to hacking risks

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and authorization actions before enabling network access. The control device receives authentication credentials from the user in advance, verifies them against stored credentials, and only then activates the switches to enable port connectivity. This ensures that access is granted only after proper verification, preventing unauthorized access while maintaining convenience for authorized users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The control device acts as an intermediary between the network and the external device. It includes a control device with processor circuitry, switches, and ports that mediates all access requests. The control device receives authentication credentials, processes them through processor circuitry, and controls the switches to either connect or disconnect the port based on authentication results. This intermediary layer blocks unauthorized access while allowing convenient access for authenticated users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access control mechanisms are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The access control system is segmented into distinct functional components: authentication credential storage, processor circuitry for verification, switches for physical connection control, and ports for network interface. Each component has a specific function, making the overall system manageable despite its complexity. The segmentation allows the system to provide robust security through multiple layers without requiring a monolithic complex design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control device performs self-service authentication by storing credentials locally and verifying user-provided credentials against stored ones using its processor circuitry. The system automatically controls the switches based on verification results without requiring external intervention. This self-service capability reduces operational complexity while maintaining strong security through automated authentication and access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10250607B2Control systems and methods for providing user access to external devices via communications networks
Publication Date: 2019.04.02 PM INVESTIGATIONS
  • US10250607B2 patent drawing
  • US10250607B2 patent drawing
  • US10250607B2 patent drawing

AI summary

Control systems and methods for providing a user with access to an external device via a communication network are provided, in which the external device is connected to a first port having lines including at least one power line and at least one data line, first and second of the lines being connected to a first switch and a second switch, respectively, of a first set of switches. A representative method includes: operating in an access-denied mode, in which one of the first set of switches is open to electrically disable the first port; receiving access request information requesting access to communicate with the external device; determining whether the user is authorized access; if the user is authorized access, providing the user an approval code; and in response to receiving login information and the approval code from the user, operating in the access-approved mode, in which the first port is enabled for a predetermined time period.