Secure Storage Authentication for Multi-Provider Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of service provision models, where multiple service providers from different industries collaborate, poses challenges in ensuring secure and responsible service delivery, particularly in integrating information and communication technology (ICT) with other sectors like automotive, where safety and security are paramount.

Innovation Solution

A control system comprising an authentication apparatus and a control apparatus with a secure storage unit, which authenticates service providers and records authenticated information, enabling secure control of services and demarcation of responsibility across multiple providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple service providers are integrated into a single control system, then service versatility and functionality are improved, but system complexity and security management difficulty increase

Engineering Contradiction:
Improveservice versatilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system is segmented into distinct functional modules: authentication apparatus for security verification, secure storage unit for credential management, and control apparatus for service execution. This segmentation allows multiple service providers to be integrated while maintaining manageable system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication apparatus acts as an intermediary between service providers and the control system. This mediator verifies credentials from multiple providers centrally, enabling service versatility without proportionally increasing the complexity of each individual service integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is stored in a centralized secure storage unit, then service security and reliability are improved, but the risk of centralized failure and loss of information increases

Engineering Contradiction:
Improveservice securityVSAvoidrisk of centralized failure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The secure storage unit implements local quality through access control mechanisms where different service providers have restricted access only to their specific authentication information. This localization of access rights enhances security while reducing the impact of potential failures to specific service modules rather than the entire system.

Inventive Principle:
Principle #3Local quality

3Reliability

If separate authentication is performed for each service provider, then responsibility demarcation and security control are improved, but authentication processing time and system overhead increase

Engineering Contradiction:
Improveresponsibility demarcationVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials are verified in advance by the authentication apparatus before service access is granted. This preliminary authentication action establishes responsibility demarcation upfront, allowing subsequent service operations to proceed without repeated authentication delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10733272B2Control apparatus, authentication apparatus, control system, and control method
Publication Date: 2020.08.04 SONY GROUP CORP
  • US10733272B2 patent drawing
  • US10733272B2 patent drawing
  • US10733272B2 patent drawing

AI summary

There is provided a control apparatus including a secure storage unit and a processing unit that controls a control target on a basis of authenticated information that is stored in the secure storage unit and the authentication information is authenticated by an authentication apparatus. The processing unit controls the control target by controlling execution of an application.