Remote Service Execution with Multi-Signature Change Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In plants, changing setting conditions or parameter values using remote service systems poses challenges in verifying the correctness of changes and ensuring security against malicious intrusions, as existing systems lack robust verification and authentication mechanisms.

Innovation Solution

A remote service system that employs a multi-signature verification process using a blockchain network to authenticate and encode instructions for changing facility settings, ensuring that only authorized changes are applied, and maintaining a high security level by using a dedicated communication circuit and data diode for secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote service system is used to change facility settings, then work efficiency is improved and on-site dispatch is reduced, but security risks from unauthorized access and malicious intrusions increase

Engineering Contradiction:
Improvework efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a remote service execution device as an intermediary between the remote service provider and the facility control system. This mediator verifies authentication information, validates change requests, and coordinates the execution of remote commands, thereby enabling efficient remote operation while maintaining security through controlled access procedures

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and verification actions before executing remote facility changes. The remote service execution device validates authentication information and verifies the legitimacy of change requests in advance, preventing unauthorized access and malicious intrusions before they can affect the facility

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If multi-signature verification process is implemented, then security level is improved and unauthorized access is prevented, but system complexity and processing time increase

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication and verification process is segmented into distinct functional modules: authentication information verification, change request validation, and command execution control. Each module handles a specific aspect of security verification, making the complex multi-signature process more manageable and maintainable while ensuring comprehensive security

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If multiple authentication layers are added to verify correctness of changes, then measurement precision of change verification is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improvechange verification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and verification actions before the actual facility changes are executed. By validating authentication information and verifying change requests in advance through the remote service execution device, the system ensures high verification accuracy while minimizing processing time during the actual change execution

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3726773B1Remote service system
Publication Date: 2023.03.15 MITSUBISHI POWER LTD
  • EP3726773B1 patent drawingFigure 1
  • EP3726773B1 patent drawingFigure 2
  • EP3726773B1 patent drawingFigure 3

AI summary

This remote service system is provided with: a first computer terminal that adds a first signature to control information representative of control content to be applied to an installation and then transmits the control information; and a second computer terminal that causes the control content represented by the control information to be applied with respect to the installation, wherein the first computer terminal and the second computer terminal are connected by a first communication network, and the second computer terminal and the installation are connected by a second communication network.