Secure Usage Index Provision for Automation Billing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in securely collecting and storing usage data for pay-per-use models in the automation business, balancing the need for transparent billing with the protection of sensitive production data from unauthorized access and modification, while ensuring the integrity and usability of performance indicators for both the invoice issuer and user.

Innovation Solution

An apparatus and method involving a key generator to produce symmetric keys for encrypting measurement values, transmitting encrypted performance indicators with a key index, and using a pseudorandom number generator to manage key generation, ensuring secure and granular data release, particularly in the context of billing disputes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If usage data is collected and stored transparently for billing purposes, then billing accuracy is improved, but data security and protection from unauthorized access deteriorates

Engineering Contradiction:
Improvebilling accuracyVSAvoidunauthorized access to data
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

A trustworthy third party (cloud server) is introduced as an intermediary to collect, store, and process usage data. This mediator operates with limited access rights, collecting only necessary data for billing while maintaining security through controlled access architecture, thus resolving the contradiction between transparent billing and data protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different levels of data access and processing are implemented locally at different system levels. The machine controller performs local data evaluation and only transmits necessary aggregated data to the cloud, while sensitive raw data remains protected at the source, enabling billing accuracy without full data exposure

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If data encryption is implemented to protect sensitive information, then data security is improved, but access restrictions and complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidaccess restriction complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system performs self-service encryption where the machine controller automatically encrypts data before transmission using keys derived from the trust relationship. The cloud server automatically decrypts and processes data without requiring manual intervention, reducing operational complexity while maintaining strong security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Encryption parameters and key management are dynamically adjusted based on the trust relationship and data sensitivity levels. The system changes encryption strength and access controls adaptively, providing strong protection where needed while maintaining ease of access for authorized operations

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If access rights are restricted to protect trade secrets, then data protection is improved, but billing verification capability deteriorates

Engineering Contradiction:
Improvetrade secret protectionVSAvoidbilling verification
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

Data access rights are segmented into different levels: the cloud server receives encrypted aggregated data for billing verification, while raw sensitive data remains protected at the machine level. This segmentation allows billing verification without exposing trade secrets, resolving the contradiction between protection and verification capability

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240070593A1Apparatus, system, and method for the access-restricted provision of a time-dependent usage index for a device
Publication Date: 2024.02.29 SIEMENS AG
  • US20240070593A1 patent drawing
  • US20240070593A1 patent drawing
  • US20240070593A1 patent drawing

AI summary

The disclosure relates to a method and a corresponding apparatus for allowing the introduction of pay-per-use models in the renting out of components in automation business. The challenge and the success in the introduction of pay-per-use models include appropriately addressing the conflict of interest between the protection of sensitive production data and the need to collect as much of the production data as possible for use as usage-relevant billing data. Therefore, a method is proposed that securely protects the data used and nevertheless allows the data to be reconstructed at a later time in the event of contentious questions.