Secure Process Logging With Object-Linked Audit Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a secure system and method to log process steps in a work process that changes an object's state, ensuring the link between log data and the product is secure and cannot be falsified, particularly for the entire life cycle of the object or product.

Innovation Solution

A system comprising a work station, an acquisition device, and an auditor device, where an identification element is assigned to the object, and the acquisition device outputs information to the auditor device for secure assignment to the object, utilizing cryptographic security and Hardware Security Modules (HSMs) to ensure data integrity and protection against manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a simple logging system is used to record process steps, then the system complexity is low and ease of operation is high, but the security and reliability of the link between log data and product is insufficient

Engineering Contradiction:
Improvesecurity of link between log data and productVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into distinct functional modules: work station for process execution, acquisition device for data collection, and auditor device for secure logging. Each component has a specific responsibility, creating a segmented architecture that enhances security while maintaining manageable complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The auditor device acts as an intermediary between the acquisition device and the log storage system. It receives acquisition information, assigns it to identification elements, and stores it in a secure manner, thereby mediating the data flow and ensuring security without requiring the work station to directly manage secure logging operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic security and HSMs are implemented to protect data integrity, then the reliability and protection against manipulation are enhanced, but the device complexity and computational requirements increase

Engineering Contradiction:
Improvedata integrity and protection against manipulationVSAvoidcomplexity of security implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The auditor device autonomously performs cryptographic operations including generating digital signatures for log entries and verifying the integrity of acquisition information. The system self-manages security functions without requiring external intervention, with the HSM automatically handling key management and cryptographic processing, thereby reducing operational complexity despite the advanced security measures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Cryptographic keys are generated and stored in the HSM before the logging process begins. Digital signatures are created in advance for each log entry before storage, and the auditor device pre-configures security parameters. This preliminary preparation of security mechanisms simplifies the actual logging operation while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12032357B2System and method for logging process steps
Publication Date: 2024.07.09 FRANCOTYP POSTALIA AG & CO KG
  • US12032357B2 patent drawing
  • US12032357B2 patent drawing

AI summary

A system and a method for executing a work process on an object are provided, the system includes at least one work station, an acquisition device and an auditor device. The system and method can be used to log process steps of a work process.