Mobile Device Encrypted Blob Authentication for Equipment Controllers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current equipment service systems face challenges in securely authenticating and updating equipment controllers using mobile devices without incurring high costs or compromising security, as they lack control over the execution environment and are vulnerable to tampering attacks.
Innovation Solution
A mobile-based equipment service system that employs a remote server to securely manage and authenticate encrypted blobs using unique private keys, allowing mobile devices to facilitate secure communication between users and equipment controllers, even without internet connectivity, by encrypting firmware and headers with duration limits and verification processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based service tools are used to securely authenticate equipment controllers, then security and protection against reverse engineering are improved, but cost increases
Solution Approach 1:
The patent creates a software-based copy of hardware security functionality by implementing cryptographic authentication (public key infrastructure, digital signatures) in the mobile device and server system. This software copy replicates the security functions of expensive hardware tools without requiring physical hardware tokens, thereby maintaining security while reducing costs.
Solution Approach 2:
The patent replaces the mechanical/hardware-based authentication system with a software-based cryptographic system. Instead of using physical hardware tools with embedded security chips, the system uses mobile devices with software-based public key cryptography to perform authentication, key exchange, and digital signing operations.
2Ease of manufacture
If mobile devices are used as service tools, then cost is reduced, but control over execution environment and security enforcement deteriorates
Solution Approach 1:
The patent introduces a server as an intermediary between the mobile device and the equipment controller. The server acts as a trusted mediator that generates cryptographic key pairs, distributes public keys to controllers, verifies authentication proofs, and manages the security-critical operations that the mobile device cannot perform independently. This intermediary architecture enables mobile devices to function securely despite lacking controlled execution environments.
Solution Approach 2:
The system performs preliminary security setup by pre-installing cryptographic authentication mechanisms in the equipment controllers and pre-distributing public keys through the server before field service operations begin. This preliminary configuration ensures that when mobile devices connect to controllers in the field, the security framework is already in place and operational.
3Ease of operation
If proprietary codes are made accessible for service operations, then ease of operation is improved, but vulnerability to tampering attacks increases
Solution Approach 1:
The patent applies preliminary anti-action by implementing digital signatures and cryptographic authentication before any service operations occur. The controller verifies the mobile device's credentials and the server's authorization proofs before allowing access to proprietary codes or functions. This pre-authorization mechanism prevents unauthorized tampering while allowing legitimate service personnel easy access to needed information.
Data Source
Figure 1
Figure 2
AI summary
A mobile-based equipment service system (20) includes a remote server (24), a mobile device (22), and at least one equipment controller (34, 36). The mobile device (22) includes a user interface (32), and is configured to send a user authentication message (50), initiated by a user via the user interface, to the remote server (24). The remote server (24) is configured to verify the user via the user authentication message (50) and once verified, send an encrypted blob (52) to the mobile device (22) in response to the user authentication message (50). At least one equipment controller (34, 36) is configured to receive and decrypt the encrypted blob (52) from the mobile device (22).