Secure Headless Device Restore via Link Layer Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for restoring headless electronic devices, such as network cameras, lack secure and convenient mechanisms to ensure authorized access and initialization to factory default settings, potentially allowing unauthorized access and data hijacking.

Innovation Solution

A method and device that utilize an authorization device connected via Ethernet to initiate a restore process through low-level link layer packets, ensuring secure authorization and encryption of restore messages, using a controller with non-volatile storage and Ethernet communication, and optionally power over Ethernet, to verify and execute the restore operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a physical restore button is provided on the headless device, then the device can be restored to factory default settings, but the device becomes vulnerable to unauthorized access and hijacking

Engineering Contradiction:
Improverestore operationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

An authorization device is introduced as an intermediary between the operator and the headless device. The authorization device receives restore requests, verifies authorization credentials, and only then transmits the restore initiation signal to the headless device. This mediator prevents unauthorized direct access while maintaining convenient restore functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Authorization verification is performed in advance before the restore operation is executed. The authorization device checks credentials and validates the operator's right to perform restore before sending the initiation signal, preventing unauthorized access at the earliest possible stage.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If physical locks are added to protect the restore button, then unauthorized access is prevented, but the device complexity and durability requirements increase

Engineering Contradiction:
Improveunauthorized accessVSAvoiddevice structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Instead of modifying the headless device with physical locks or protective structures, an external authorization device serves as a mediator that handles security verification. This approach prevents unauthorized access without increasing the complexity or durability requirements of the headless device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Physical protection mechanisms (locks, covers, buttons) are replaced with an electronic/digital authorization system. The authorization device uses cryptographic verification and digital credentials instead of mechanical barriers, reducing physical complexity while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If smart card authentication is used for restore, then security is improved, but the ease of operation and accessibility are reduced

Engineering Contradiction:
Improveunauthorized accessVSAvoidrestore operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The authorization device is designed to support multiple authentication methods including smart cards, PIN codes, biometric authentication, or other credential types. This multi-functional approach maintains high security while improving accessibility and ease of operation by accommodating different user preferences and scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If the restore button is made accessible without physical protection, then ease of operation is maximized, but security against hijacking is compromised

Engineering Contradiction:
Improverestore operationVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authorization device acts as a mandatory intermediary that all restore operations must pass through. Even though the restore functionality remains easily accessible, the intermediary verifies authorization before allowing the operation, thus maintaining both ease of operation and device security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3291121B1Restore of headless electronic device
Publication Date: 2022.04.20 AXIS
  • EP3291121B1 patent drawingFigure 1~2
  • EP3291121B1 patent drawingFigure 3~4

AI summary

There is provided a method for restoring a setting on a network connected device. By using the method an increased security is achieved. The method comprises receiving an initiation signal representing a request to restore the setting on the device; transmitting a request for authorization to restore the setting to an authorization device arranged as an adjacent node on the network by transmitting the request for authorization over a link layer protocol, wherein the request is transmitted in response to the received initiation signal; receiving an encrypted restore authorization response from the authorization device in response to the request for authorization; decrypting, if encrypted, the received restore authorization message; verifying the restore authorization message; and restoring the settings on the network connected device if the restore authorization message was verified.