Embedded Security Command Extraction for Remote Device Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security technologies struggle to efficiently manage and update security rights and privileges on remote electronic devices without administrator presence, leading to logistical issues and potential unauthorized access.

Innovation Solution

A method and system for receiving a command with a data portion that extracts a security rights modification command set, allowing for secure session initiation and execution, enabling modification of security parameters without other commands being executed, and automatically closing the session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrator physically visits each device to modify security settings, then security changes can be made, but time consumption and logistical complexity increase significantly

Engineering Contradiction:
Improvesecurity settings modificationVSAvoidtime for security updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by allowing security settings to be modified automatically through embedded commands that execute without administrator presence. The electronic device itself performs the security configuration changes by processing the embedded commands locally, eliminating the need for administrator intervention and dramatically reducing update time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Embedded commands act as intermediaries between the administrator's intent and the device's security configuration. The commands encapsulate the necessary security modifications and transfer them to the device, which then executes them automatically. This intermediary mechanism enables remote security updates without requiring the administrator to physically visit each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If administrator password is distributed to multiple administrators for remote access, then remote security management becomes possible, but security risk increases due to more people knowing the password

Engineering Contradiction:
Improveremote security managementVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The invention extracts the administrator password from the security management process entirely. Instead of requiring password-based authentication, the system uses embedded commands that contain self-contained security modification instructions. These commands can be executed automatically without any password input, eliminating the security risk associated with password distribution while maintaining ease of remote operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The embedded commands enable the device to perform security modifications autonomously without requiring administrator authentication. The commands are designed to execute automatically when received, eliminating the need for password-based access control and thereby removing the security vulnerability of distributed password knowledge while maintaining operational ease.

Inventive Principle:
Principle #25Self-service

3Productivity

If security commands are executed without secure session, then command execution is simpler, but device is vulnerable to malware attacks during execution

Engineering Contradiction:
Improvecommand execution speedVSAvoidmalware attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system establishes a secure session before executing security commands and maintains it throughout the execution process. This preliminary security measure ensures that the device is protected against malware attacks during the vulnerable window when security settings are being modified. The secure session is set up in advance and remains active throughout the entire command execution, providing continuous protection without significantly impacting execution speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8380988B2Embedded self-contained security commands
Publication Date: 2013.02.19 KINGSTON DIGITAL INC
  • US8380988B2 patent drawing
  • US8380988B2 patent drawing
  • US8380988B2 patent drawing

AI summary

A set of commands is provided to a system for execution in order to modify a security related aspect of the system. The system executes the set of commands absent an intervening command being executed, for example by receiving a first command comprising a data portion, extracting a security rights modification command set comprising commands for initiating a secure session and for closing the secure session, and automatically executing the security rights modification command set with a processor, absent other security rights commands being executed. Initiating the secure session may comprise authentication, and the security rights modification command set may provide for security parameters modifiable only during a secure session.