Removable Media Access Control Using Device Group Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data access control systems in factory automation settings face security concerns due to the risk of removable storage media being stolen, as they often rely on user-friendly but insecure authentication methods that may not always ensure data access is restricted to authorized devices.

Innovation Solution

A control system that verifies the serial numbers and model codes of devices before allowing access to data stored on removable storage media, ensuring that only authorized devices can access the data by using a concealed logic reader and a support device to manage the verification process, thereby enhancing security without compromising user-friendliness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control through individual authentication using host devices authorized beforehand is implemented, then security is improved, but user-friendliness deteriorates because the media may not always be inserted in the authorized host devices

Engineering Contradiction:
ImprovesecurityVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system is segmented into two independent verification methods: (1) host device authorization verification, and (2) device group consistency verification. This segmentation allows the system to flexibly apply appropriate verification levels based on the situation, maintaining security while improving usability when the storage medium is used across multiple authorized devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial verification by allowing access when either host device authorization OR device group consistency is confirmed. This partial action approach prevents excessive authentication barriers while maintaining adequate security through alternative verification paths.

Inventive Principle:
Principle #16Partial or excessive action

2Ease of operation

If removable storage media are made easily accessible for data storage and retrieval, then user-friendliness is improved, but security deteriorates due to the risk of theft and unauthorized access

Engineering Contradiction:
Improveuser-friendlinessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces an intermediary verification mechanism (device group information comparison) that acts as a mediator between the storage medium and the access request. This intermediary layer verifies whether the requesting device belongs to the authorized device group by comparing device group IDs, providing security without directly restricting user access to the storage medium.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The storage medium itself performs self-verification by storing device group information and actively comparing it with the requesting device's group information. This self-service authentication mechanism enables the medium to autonomously determine whether to grant access, reducing reliance on external authorization systems while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3940470B1Control system, control method, and control device for controlling access to data in a device group
Publication Date: 2024.09.25 OMRON CORP
  • EP3940470B1 patent drawingFigure 1
  • EP3940470B1 patent drawingFigure 2
  • EP3940470B1 patent drawingFigure 3

AI summary

Provided is a technology directed to enhancing the level of security while ensuring user-friendliness in data accesses to removable storage media. A control system (1) is equipped with a PLC (100) included in a plurality of devices and configured to receive, in a removable manner, a data-storable memory card (300), and one or a plurality of units (200) included in the plurality of devices. Each of members of the plurality of devices and the memory card (300) retains, in a storage region, a list containing relevant information associated with each of the members, and verifies, using a verifying unit, the relevant information of each of other members included in the list retained in the storage region against the relevant information of each of the other members obtained from each of the other members. The PLC (100) is enabled to access the data stored in memory card (300) when a result of verification obtained by the verifying unit of each of the other members but the PLC (100) satisfies a predetermined condition.