Franking Machine Security Module Authorization Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Franking machines with complex security modules are underutilized, as existing solutions require direct connection to a specific data processing device for secured services, limiting the exploitation of security-related capacities and increasing certification costs.

Innovation Solution

A method where the security module verifies authorization for requested secured services before provision, allowing any data processing device to access secured services without a specific connection, enabling binding to users, groups, or procedural applications, and reducing storage needs by using customizable authorization criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the security module is connected to a specific data processing device for secured services, then the security module can provide secured services, but the utilization of security module capacities is limited and device complexity increases

Engineering Contradiction:
Improveutilization of security module capacitiesVSAvoidconnection requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security module is designed to provide secured services to multiple different data processing devices through a standardized interface, rather than being tied to a single device. This universal design allows the same security module to serve various functions and devices, thereby increasing its utilization and reducing the need for multiple specialized connections.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple different security modules are used for different certification requirements, then certification can be provided, but certification costs increase

Engineering Contradiction:
ImprovecertificationVSAvoidcertification cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

A single security module design is created that can fulfill multiple certification requirements through configurable authorization criteria, eliminating the need to manufacture and certify multiple different security module variants. This reduces certification costs while maintaining reliability across different applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security module uses configurable authorization criteria that can be adjusted to meet different certification requirements without changing the hardware or fundamental design. By changing parameters such as authorization rules and service types, the same module can be adapted for different purposes, reducing the need for multiple certified variants.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If the security module provides secured services without authorization verification, then service provision is simplified, but security and control are compromised

Engineering Contradiction:
Improveservice provisionVSAvoidauthorization control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs authorization verification before providing secured services, establishing control criteria in advance. This preliminary authorization check ensures that only authorized data processing devices can access secured services, maintaining security while keeping the service provision process simple through automated verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8682801B2Method and arrangement for provision of security relevant services via a security module of a franking machine
Publication Date: 2014.03.25 FRANCOTYP POSTALIA AG & CO KG
  • US8682801B2 patent drawing
  • US8682801B2 patent drawing
  • US8682801B2 patent drawing

AI summary

In a method and an arrangement for provision of at least one secured service via a security module of a franking machine for at least one procedure for data processing that is executed in a data processing device that can be connected with the franking machine, the procedure requests a secured first service from the security module in a request step; and the security module provides the first service in a provision step subsequent to the request step. The security module verifies an authorization to request the first service via the procedure in a verification step preceding the provision step.