Mobile Device Encrypted Blob Authentication for Equipment Controllers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current equipment service systems face challenges in securely authenticating and updating equipment controllers using mobile devices without incurring high costs or compromising security, as they lack control over the execution environment and are vulnerable to tampering attacks.

Innovation Solution

A mobile-based equipment service system that employs a remote server to securely manage and authenticate encrypted blobs using unique private keys, allowing mobile devices to facilitate secure communication between users and equipment controllers, even without internet connectivity, by encrypting firmware and headers with duration limits and verification processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based service tools are used to securely authenticate equipment controllers, then security and protection against reverse engineering are improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a software-based copy of hardware security functionality by implementing cryptographic authentication (public key infrastructure, digital signatures) in the mobile device and server system. This software copy replicates the security functions of expensive hardware tools without requiring physical hardware tokens, thereby maintaining security while reducing costs.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/hardware-based authentication system with a software-based cryptographic system. Instead of using physical hardware tools with embedded security chips, the system uses mobile devices with software-based public key cryptography to perform authentication, key exchange, and digital signing operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If mobile devices are used as service tools, then cost is reduced, but control over execution environment and security enforcement deteriorates

Engineering Contradiction:
ImprovecostVSAvoidsecurity control
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary between the mobile device and the equipment controller. The server acts as a trusted mediator that generates cryptographic key pairs, distributes public keys to controllers, verifies authentication proofs, and manages the security-critical operations that the mobile device cannot perform independently. This intermediary architecture enables mobile devices to function securely despite lacking controlled execution environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security setup by pre-installing cryptographic authentication mechanisms in the equipment controllers and pre-distributing public keys through the server before field service operations begin. This preliminary configuration ensures that when mobile devices connect to controllers in the field, the security framework is already in place and operational.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If proprietary codes are made accessible for service operations, then ease of operation is improved, but vulnerability to tampering attacks increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidtampering attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing digital signatures and cryptographic authentication before any service operations occur. The controller verifies the mobile device's credentials and the server's authorization proofs before allowing access to proprietary codes or functions. This pre-authorization mechanism prevents unauthorized tampering while allowing legitimate service personnel easy access to needed information.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3396581B1Mobile-based equipment service system using encrypted code offloading
Publication Date: 2021.11.03 OTIS ELEVATOR CO
  • EP3396581B1 patent drawingFigure 1
  • EP3396581B1 patent drawingFigure 2

AI summary

A mobile-based equipment service system (20) includes a remote server (24), a mobile device (22), and at least one equipment controller (34, 36). The mobile device (22) includes a user interface (32), and is configured to send a user authentication message (50), initiated by a user via the user interface, to the remote server (24). The remote server (24) is configured to verify the user via the user authentication message (50) and once verified, send an encrypted blob (52) to the mobile device (22) in response to the user authentication message (50). At least one equipment controller (34, 36) is configured to receive and decrypt the encrypted blob (52) from the mobile device (22).