Centralized Secure Instrument Configuration Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional networked systems, such as test and measurement systems, face difficulties in securely configuring multiple devices due to the need for manual, error-prone, and time-consuming processes for credential setup and validation, especially when changes are made or third-party credential mechanisms are involved, leading to burdensome updates and complexity.

Innovation Solution

A centralized Secure Instrument Configuration (SIC) server automates the secure configuration of networked devices, enabling remote secure communications by managing credentials and authentication data across all devices from a central point, simplifying the process and reducing user error.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stand-alone configuration interfaces are used on each networked device, then secure connections can be established between devices, but the configuration process becomes difficult, error-prone, and time-consuming

Engineering Contradiction:
Improvesecure connection establishmentVSAvoidconfiguration process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A centralized configuration server is introduced as an intermediary between networked devices. The server stores credential information and authentication data, and automatically distributes it to devices. This eliminates the need for manual configuration on each device while maintaining secure connection establishment through automated credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple configuration tasks into a single centralized operation. Instead of accessing each device individually to configure credentials and authentication, the user performs all configuration through one centralized interface, which then automatically propagates settings across the entire networked system.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If manual configuration is performed on each device, then credentials and authentication data can be set, but the process is time-consuming and error-prone

Engineering Contradiction:
Improvecredential configurationVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The centralized configuration server pre-generates credential information and authentication data before devices need them. When a device joins the network or needs reconfiguration, the credentials are already prepared and can be automatically distributed, eliminating the time-consuming manual configuration process while ensuring reliable credential setup.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If third-party credential mechanisms are implemented independently on each instrument, then credential validation can be performed, but the burden on each instrument increases and updates become complicated

Engineering Contradiction:
Improvecredential validationVSAvoidinstrument complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex third-party credential validation mechanism from individual instruments and consolidates it into the centralized configuration server. The server handles all communication with third-party services, while instruments simply receive pre-configured credentials. This reduces instrument complexity while maintaining reliable credential validation through the centralized authority.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11956274B1System and method for implementing a secure configuration of controllers and instruments in a networked system
Publication Date: 2024.04.09 KEYSIGHT TECHNOLOGIES INC
  • US11956274B1 patent drawing
  • US11956274B1 patent drawing

AI summary

A system and method are provided for implementing a secure configuration of a networked system for secure communications, the networked system including at least one instrument for performing corresponding tasks and at least one controller for controlling functions of the at least one instrument. The method includes providing a secure instrument configuration (SIC); displaying status provided by the SIC server identifying the controller and the instruments to a user via a user interface; writing controller secure configuration information from the SIC server to the controller through a software agent on the controller, the controller secure configuration information including authentication data for the instruments, and/or credentials of the one controller acceptable by the one instruments for identifying the controller; and communicating with the controller to initiate implementation of the secure configuration. The controller establishes a secure connection with the instruments using the controller secure configuration information.