Offline Authorization Verification Using Smart Card Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authorization systems, such as Kerberos, are limited to online scenarios, making it difficult for service technicians to obtain and verify authorization approvals for administrative tasks in offline situations, particularly in distributed structures like power distribution networks, where devices may not have access to online authentication services.
Innovation Solution
A method for generating and verifying authorization approvals on-the-fly, using a smart card or USB stick, which stores both the identity certificate and authorization approval, linked cryptographically, allowing offline verification with a limited validity period to ensure quick revocation of access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Kerberos online authentication service is used, then authorization verification can be performed with centralized control, but service technicians cannot obtain authorization approvals in offline situations
Solution Approach 1:
The authorization approval is segmented into multiple components: identity certificate, authorization certificate, and public key infrastructure elements. These segmented components are stored on a portable storage medium (smart card or USB stick), enabling the service technician to carry and present authorization credentials offline without requiring continuous connection to the centralized Kerberos server.
Solution Approach 2:
A portable storage medium (smart card or USB stick) acts as an intermediary between the service technician and the device to be administered. This intermediary stores and transports the authorization credentials, enabling offline verification while maintaining the security model of centralized authorization issuance.
2Ease of operation
If long-term identity certificates are used, then service technicians have continuous access capability, but rapid revocation of access rights becomes difficult
Solution Approach 1:
The authorization system implements dynamic authorization certificates with defined validity periods. The authorization certificate includes temporal constraints that automatically limit its lifespan, enabling rapid revocation by simply allowing the certificate to expire rather than requiring active revocation procedures. This dynamic approach maintains continuous access capability during the validity period while enabling quick termination when needed.
Solution Approach 2:
The authorization certificate is structured with periodic validity (time-limited authorization). This periodic nature allows the system to grant access for specific time intervals corresponding to task completion, automatically revoking access after the specified period without requiring manual intervention.
3Reliability
If authorization approvals are generated on-the-fly for specific tasks, then authorization can be tied to specific actions and identity, but the system complexity increases
Solution Approach 1:
The authorization approval is generated in advance as part of the work plan creation process. The planning utility creates the intervention plan and generates the corresponding authorization certificate before the service technician executes the tasks. This preliminary generation of authorization tied to specific tasks and identities provides precise authorization control without requiring complex real-time authorization decision-making during task execution.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables service technicians to perform tasks with short-term authorization grants tied to specific actions and identity, ensuring rapid revocation of access without affecting the identity certificate, supporting both online and offline scenarios and emergency service situations.
Implementation Method 1
the signed authorization approval is stored on the same storage medium that the service technician carries or can carry with him or her as the identity certificate... the signed authorization approval can be queried online and is cryptographically linked to the identity certificate
Data Source
Figure 1
AI summary
The invention solves the problem of providing a method for producing, allocating and checking authorization approvals which are necessary for tasks which are predefined by an engagement schedule to be performed by a service technician by means of actions which are defined by the tasks on a piece of equipment or a component of a distributed structure. The present invention solves this problem by permitting flying generation and distribution of authorization approvals for service technicians, as a function of necessary actions or measures which are to be performed in the form of tasks as part of an engagement schedule which is contained or recorded in a work schedule.