Elevator Control System Cloud Security via Cryptoprocessor
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional elevator and escalator systems face limitations in scalability and maintenance due to local software updates and hardware resource constraints, requiring manual intervention and potential hardware upgrades to incorporate new functionalities.
Innovation Solution
A communication device with a microprocessor, cryptoprocessor, and memory that enables encrypted data communication between core controllers and a cloud server, allowing non-core functionalities to be relocated, thereby simplifying controller design, enhancing security, and enabling remote updates and upgrades without impacting local hardware resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If control functionalities are moved or relocated from the core controller to another entity, then device complexity and hardware resource requirements are reduced, but security and integrity of communication may be compromised
Solution Approach 1:
The patent introduces a communication device as an intermediary component positioned between the core controller and the cloud server. This communication device includes a cryptoprocessor that handles encryption and decryption operations, acting as a security mediator that protects the core controller while enabling cloud connectivity. The cryptoprocessor specifically protects encryption keys and performs cryptographic operations, ensuring that the core controller remains simple while communication security is maintained through this intermediate security layer.
2Reliability
If manual software updates are performed on local control boards, then system reliability is maintained, but productivity and ease of operation deteriorate due to manual intervention requirements
Solution Approach 1:
The patent implements a self-service update mechanism where the communication device automatically receives, decrypts, and installs software updates from the cloud server without requiring manual intervention. The system autonomously manages the software lifecycle by having the communication device fetch updates, decrypt them using stored keys, and install them on the core controller, thereby maintaining reliability through automated controlled updates while significantly improving productivity by eliminating manual service personnel involvement.
3Reliability
If encryption is implemented for data communication between core controllers and cloud servers, then security is improved, but device complexity increases due to additional cryptographic components
Solution Approach 1:
The patent extracts the cryptographic functionality from the core controller and places it in a dedicated cryptoprocessor within the communication device. This separation allows the core controller to remain simple while the cryptoprocessor handles all encryption and decryption operations. The cryptoprocessor is specifically designed to protect encryption keys and perform cryptographic operations, thereby providing strong data security without significantly increasing the complexity of the core control system.
Data Source
Figure 1
Figure 2
AI summary
Communication apparatus comprising: a communication device (1) with at least one microprocessor (101); at least one cryptoprocessor (102); and memory (103) having instructions stored thereon that, when executed by the at least one microprocessor and the at least one cryptoprocessor, cause the communication device to at least one of: Receive from the cloud (5) encrypted data that is configured to control at least core operations associated with an elevator or escalator device (34, 35, 36), decrypt the data, and distribute the data over at least one data connection between the communication device (1) and at least one core controller (24) associated with said elevator or escalator device (34, 35, 36) to said at least one core controller (24) to be used by said core controller (24) to control at least core operations associated with said elevator or escalator device (34, 35, 36), or receive control feedback data over at least one data connection between the communication device (1) and at least one core controller (24) associated with an elevator or escalator device (34, 35, 36) to said at least one core controller (1), encrypt the data, and send the encrypted data to the cloud (5). Encrypting the data which is communicated between the communication devices allows to maintain the security level obtained with conventionally controlled elevator and escalator devices even when control over non-core functionalities are moved or relocated to remote devices or into the cloud in general.