Management Apparatus for Secure Measurement Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely and efficiently transmitting measurement information from measurement apparatuses to service providing apparatuses across different networks, requiring secure authentication and encryption while reducing communication load and preventing data manipulation.

Innovation Solution

A transfer system that includes a management apparatus generating seed information and user keys, which are used to securely transmit measurement information from measurement apparatuses to service providing apparatuses via different networks, employing cryptographic functions and network configurations to ensure authentication and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If measurement information is transmitted across different networks to service providing apparatus, then data accessibility and service capability are improved, but communication load and security risks increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidcommunication load
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent introduces a management apparatus as an intermediary between measurement apparatuses and service providing apparatuses. This intermediary generates and manages user keys, seeds, and authentication information, enabling secure data transmission across networks without requiring direct complex authentication between all parties. The management apparatus reduces communication load by pre-generating authentication credentials that can be reused.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management apparatus performs preliminary actions by generating user keys, seeds, and authentication information before actual measurement data transmission occurs. This pre-establishment of security credentials reduces the communication overhead during actual data transfer, as the authentication framework is already in place rather than being negotiated for each transmission.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If measurement information is transmitted across public networks, then service providing capability is improved, but security and data integrity are compromised

Engineering Contradiction:
Improveservice providing capabilityVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The management apparatus acts as a trusted intermediary that generates authentication information and user keys. This intermediary ensures data integrity by creating cryptographic credentials that verify the authenticity of measurement information transmitted over public networks, preventing manipulation while enabling broad service access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent employs cryptographic parameters including user keys, seeds, and authentication information that transform the security properties of transmitted data. These parameter changes ensure that even though data travels over public networks, the cryptographic protection maintains data integrity and prevents unauthorized modification.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If authentication and encryption are implemented for secure transmission, then data security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management apparatus consolidates the complexity of authentication and encryption operations into a single intermediary system. Rather than each measurement apparatus or service providing apparatus implementing complex cryptographic protocols independently, the management apparatus generates and manages all security credentials, simplifying the overall system architecture while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management apparatus provides universal security services to multiple measurement apparatuses and service providing apparatuses. By implementing authentication and encryption management in a single multi-functional system rather than duplicating these capabilities across all devices, the patent reduces overall device complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If user keys and authentication information are generated and transmitted, then secure communication is enabled, but initial communication load and setup time increase

Engineering Contradiction:
Improvesecure communicationVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The management apparatus performs preliminary generation of user keys, seeds, and authentication information before actual measurement data transmission begins. This advance preparation of security credentials enables secure communication to be established quickly once the preliminary setup is complete, as the authentication framework is already in place rather than being negotiated for each transmission session.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10516535B2Management apparatus, measurement apparatus, service providing apparatus, computer program product, transfer system, and transfer method
Publication Date: 2019.12.24 KK TOSHIBA
  • US10516535B2 patent drawing
  • US10516535B2 patent drawing
  • US10516535B2 patent drawing

AI summary

A management apparatus according to an embodiment is connected to a measurement apparatus deployed for each user via a first network. The management apparatus is connected to a service providing apparatus via a second network. The management apparatus includes a first communication device, a second communication device and one or more first processors. The first processors generate seed information using a service providing apparatus identifier. The first processors generate a user key using a measurement apparatus individual key, and the seed information. The first communication device transmits the generated seed information to the measurement apparatus via the first network. The second communication device transmits the generated user key to the service providing apparatus via the second network.