Multiple Authorization Modules for Secure Product Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating secure product identifiers in distributed or complex environments are inefficient and lack secure verification processes, particularly in maintaining audit and recall capabilities.

Innovation Solution

A system utilizing multiple authorization modules connected in parallel or series, where authorization is obtained by combining configuration data with security tokens, such as digital signatures, to ensure secure product identification and verification across production runs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single verification server is used for authentication, then the system is simple to manage, but the authentication speed and system reliability deteriorate in distributed environments

Engineering Contradiction:
Improveverification system structureVSAvoidauthentication speed
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The verification system is segmented into multiple independent authorization modules distributed across different locations. Each module can independently verify product identifiers, eliminating the single-point bottleneck and enabling parallel verification operations that significantly improve authentication speed while maintaining system manageability through modular architecture

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple authorization modules are used for verification, then the authentication security and reliability improve, but the system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthorization system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization system is divided into multiple independent modules that can be deployed distributedly. Each module maintains its own verification capabilities, allowing the system to achieve high reliability through redundancy and distribution while managing complexity through standardized module interfaces and configurations

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each authorization module is designed as a universal, multi-functional unit capable of verifying different product identifiers and configuration data using the same cryptographic protocols. This universality allows multiple modules to be deployed without proportionally increasing operational complexity, as they all follow the same verification patterns and can interchangeably serve various verification needs

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If configuration data is digitally signed by multiple modules, then the product identifier security improves, but the processing time increases

Engineering Contradiction:
Improveproduct identifier securityVSAvoidauthorization processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Configuration data is digitally signed by authorization modules in advance, before the actual product identification and verification process. This preliminary signing ensures that the configuration data is already authenticated and secured, allowing downstream verification to proceed rapidly without repeated cryptographic operations, thus improving security while minimizing processing time delays

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10917245B2Multiple authorization modules for secure production and verification
Publication Date: 2021.02.09 INEXTO SA
  • US10917245B2 patent drawing
  • US10917245B2 patent drawing
  • US10917245B2 patent drawing

AI summary

The invention relates to a system of obtaining authorization where there are multiple authorization modules. When an authorization is provided by a module, it is combined with a security token, digital signature or encryption identifying which module provided the authorization. To obtain a full authorization, multiple authorization modules may be required and these modules can be connected in parallel and or in series with each other.