Secure Removable Device Registration via Pre-Certified Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industrial electrical systems, the need for timely replacement of faulty devices is hindered by the requirement for high security permissions during registration, which is often unavailable due to the geographical dispersion of devices and the unavailability of system administrators, posing a security risk if maintenance operators with lower privileges intervene.
Innovation Solution
A method utilizing security certificates specific to each removable device, associated with a trusted certification authority, allows maintenance operators to register new devices without high security permissions, ensuring secure enrollment and maintaining IT security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If high security permissions are required for device registration, then system security is improved, but device replacement speed and maintenance efficiency deteriorate
Solution Approach 1:
The patent segments the registration process into two distinct phases: a secure certification phase that verifies device authenticity through security certificates, and a simplified enrollment phase that uses pre-shared keys for quick registration. This segmentation allows system administrators to certify devices securely in advance, while maintenance operators can perform rapid replacements without requiring high security permissions, thus resolving the contradiction between security and replacement speed.
Solution Approach 2:
The patent implements preliminary action by requiring system administrators to certify devices with security certificates before they are installed in the field. This pre-certification creates a trusted foundation that enables maintenance operators to subsequently register replaced devices using simplified procedures with pre-shared keys, eliminating the need for administrators to be present during urgent replacements while maintaining security guarantees.
2Reliability
If system administrator presence is required for registration, then security is maintained, but response time to failures increases
Solution Approach 1:
The patent introduces pre-shared keys as an intermediary mechanism that bridges the gap between security requirements and operational efficiency. These pre-shared keys are securely distributed to maintenance operators in advance, enabling them to register replaced devices without real-time administrator involvement. The intermediary mechanism maintains security by ensuring that only authorized operators with valid pre-shared keys can perform registration, while eliminating the time loss associated with administrator availability.
3Productivity
If maintenance operators with lower privileges perform registration, then replacement speed improves, but system security risk increases
Solution Approach 1:
The patent changes the security parameters available to maintenance operators by providing them with pre-shared keys instead of requiring full administrator credentials. This parameter change enables operators to perform registration operations with limited but sufficient privileges - they can register devices using their pre-shared keys without having access to higher security functions. This resolves the contradiction by optimizing the security parameter for the specific task of device registration, allowing fast replacement while maintaining appropriate security controls.
Data Source
Figure 1~2
Figure 3
AI summary
This secure registration process for a removable electrical device includes steps consisting of: a) after the installation of a new removable electrical device in an electrical system to replace a defective removable electrical device, acquiring (112) a first safety certificate for the new device, this first certificate being signed by an authority known to the system; b) verifying (114) the authenticity of the first acquired safety certificate, this verification being carried out by the electronic control module; c) generating a second safety certificate for the new removable electrical device, including a key generated by the electronic control unit of the new device; d) obtaining (126) a signature of the second safety certificate from a trusted certification authority, the new device then being registered in the system only if this signature is obtained.