Embedded Processing System Authentication for Assembly Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing control systems for complex assemblies, such as gas turbine engines, often provide users with overly broad access, leading to unauthorized access and misuse.
Innovation Solution
An embedded processing system with processing circuitry and memory that utilizes encrypted user credential files to authenticate users, allowing access only to authorized tasks and logging unauthorized attempts, with features like digital signing and secure access levels for maintenance, repair, and testing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are provided with broad access to the control system, then ease of operation is improved, but security and reliability deteriorate due to unauthorized access and misuse
Solution Approach 1:
The patent segments user access into distinct levels (e.g., operator level, maintenance level, engineer level) with progressively broader permissions. Each level is clearly defined and isolated, allowing users to access only the functions appropriate to their role. This segmentation resolves the contradiction by providing ease of operation for authorized users while maintaining security through granular access control.
Solution Approach 2:
The system performs preliminary authentication and authorization checks before granting access to any control functions. User credentials are verified against stored authentication data in advance, and the system determines the appropriate access level before allowing operation. This preliminary action ensures security is maintained while enabling smooth operation for authenticated users.
2Reliability
If access control measures are implemented, then security is improved, but device complexity increases due to authentication processes
Solution Approach 1:
The control system incorporates universal authentication mechanisms that serve multiple functions: user identification, authorization determination, session management, and audit logging. By making the authentication subsystem multi-functional, the patent reduces overall system complexity while maintaining robust security. The same authentication infrastructure supports various access levels and control functions without requiring separate mechanisms for each.
Solution Approach 2:
The system automatically manages authentication and authorization without requiring external intervention. The control system independently verifies user credentials, determines access levels, enforces permissions, and logs security events. This self-service approach to security management reduces operational complexity and eliminates the need for manual security administration, offsetting the initial complexity of implementing authentication measures.
3Reliability
If user credentials are stored and verified, then unauthorized access is prevented, but loss of time occurs during authentication processes
Solution Approach 1:
The system performs authentication and authorization checks in advance, before users attempt to access controlled functions. By verifying credentials upfront and establishing session permissions beforehand, the system eliminates the need for repeated authentication during normal operation. This preliminary action ensures access control security while minimizing time loss, as users experience smooth operation once authenticated.
Solution Approach 2:
The authentication process is designed to be continuous and seamless for authorized users. Once a user is authenticated and their access level determined, the system maintains this authorization state throughout their session without requiring repeated verification. This continuity allows users to perform multiple operations without time loss from repeated authentication, while security is maintained through persistent session management and permission checks.
Data Source
AI summary
An embedded processing system and access combination includes processing circuitry, a memory system, and a plurality of user credential files. The user credential files include an encrypted user identifier, and an encrypted list of authorized task roles the particular user would have within the embedded processing system. Expected credentials from the user credential files are stored in the memory system. The processing system is programmed to receive a user credential file from a user, and compare expected credentials within the memory system to identify if the user is an authorized user. The processing system is programmed to allow access to an authorized user and deny access to an unauthorized user and determine what task roles are authorized for the authorized user, and deny access for the authorized user to other tasks. A method and an assembly are also disclosed.


