Offline Control Device Startup via Multi-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for commissioning and managing offline control devices lack robust security measures, particularly in ensuring that only authorized individuals or devices can access and manage these devices without an internet connection.

Innovation Solution

A method utilizing multi-factor/ID authentication, where a terminal is equipped with a management control unit and implements a multi-factor authentication algorithm, using a first security code stored on a transponder and a second security code generated by the terminal manufacturer, stored on a mobile device, to validate and authorize access, ensuring secure communication and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented in offline control devices, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent factors: a first security code stored on a secure element within the terminal, a second security code stored on a separate mobile device, and a multi-factor authentication algorithm executed by the control unit. This segmentation allows each component to be optimized independently while collectively providing robust security without requiring the entire system to become uniformly complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first security code is pre-stored in the terminal's secure element during manufacturing, and the second security code is pre-distributed to the user's mobile device before the terminal is activated. This preliminary action ensures that both authentication factors are already in place before the terminal needs to authenticate, streamlining the authentication process and reducing the complexity of real-time code generation and distribution.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If offline authentication is implemented without internet connection, then independence from internet is improved, but security validation capability deteriorates

Engineering Contradiction:
Improveindependence from internetVSAvoidsecurity validation capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The terminal performs self-authentication by executing the multi-factor authentication algorithm locally using the first security code from its secure element and the second security code from the mobile device. The control unit validates the authentication result without requiring external verification, enabling the system to maintain high security validation capability while operating completely offline and independently from internet connections.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4176361B1Method and system for starting up or managing an offline control device
Publication Date: 2024.05.01 HAEFELE TECHNOLOGY SOLUTIONS GMBH & CO KG
  • EP4176361B1 patent drawingFigure 1

AI summary

A method according to the invention for starting up and managing an offline control device (2), which comprises a management control unit (3) and a terminal (4) activating the management control unit (3), by means of a multi-factor/ID authentication comprises the following method steps for initial start-up of the control device (2): - implementing a multi-factor/ID authentication algorithm (6) in the terminal (4), - delivering the terminal (4), in a factory state, and a first storage medium (7), in which a storage medium ID and a first security code (5) are stored in a forgery-proof and globally unique manner, to a customer, - delivering a second security code (22), generated on the basis of the first security code (5), to a second storage medium (8) of the customer, - a user positioning the first and the second storage medium (7, 8) at the location of the terminal (4) and the terminal (4) reading the storage medium ID and the first and second security codes (5, 22) and checking offline, by means of the multi-factor authentication algorithm (6) of the terminal (4), whether the first and second security codes (5, 22) read are valid with each other, - following a positive multi-factor authentication check, storing the storage medium ID as authorisation ID and the first security code (5) in the terminal (4), and - terminating the initial start-up mode.