Optical Code Authentication for Secure Device Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for configuring devices in security-relevant facilities lack effective methods to ensure that only authorized devices can configure other devices, potentially allowing unauthorized access.

Innovation Solution

A method where a first device displays a code, which is detected by a second device using an optical sensor. The second device then authenticates itself to a server, sends a representation of the code to the server, and the server authorizes the configuration of the first device based on the representation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are configured to be authorized in advance to prevent configuration by unauthorized persons, then security is improved, but device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an optical code as an intermediary authentication element that bridges the first device and the second device. The optical code displays authentication information that can be captured by the second device's optical sensor, eliminating the need for complex direct device-to-device authentication protocols while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces complex electronic authentication mechanisms with an optical-based authentication system. Instead of using sophisticated cryptographic handshakes or physical security modules, the system uses optical code generation and detection, which are simpler to implement and verify while providing equivalent security functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If optical code authentication is implemented to verify device identity, then security is enhanced, but ease of operation decreases due to additional authentication steps

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The first device automatically generates and displays the optical code without requiring user intervention. The authentication process is self-initiated by the devices themselves, reducing the operational burden on users while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The optical code is generated and displayed in advance before the actual configuration operation. This preliminary authentication preparation allows the second device to capture and verify the code before the configuration process begins, streamlining the overall operation flow.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This method ensures that only authorized devices can configure other devices by verifying the identity of the second device through the server, thereby enhancing security in security-relevant facilities.

Implementation Method 1

detecting, by a second device, the code by means of an optical sensor

Methodology Applied
Scientific EffectOptical detection: Light

Data Source

PatentUS20250150452A1System for establishing a communication connection between a first device and a server via a network and method for authorizing a configuration of a first device by a second device
Publication Date: 2025.05.08 WAGO VERW GMBH
  • US20250150452A1 patent drawing
  • US20250150452A1 patent drawing
  • US20250150452A1 patent drawing

AI summary

Provided is a method for authorizing a configuring of a first device by a second device and a system for establishing a communication connection between a first device and a server over a network. A first message is sent over a network to a server, the first message comprising first information regarding an identity of the first device. The server sends a second message over the network to the first device. The first device derives a first code from the second message. The first device displays the first code. A second device detects the first code via an optical sensor and authenticates the second device to the server The server authenticates an identity of the second device. The second device sends a representation of the first code to the server. The server authorizes a configuring of the first device by the second device based on the representation.