Automated Security Profile Generation for Target Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual process of creating security information for configuring target devices is slow and prone to inaccuracies, leading to inefficient deployment of computer software code and potential security issues.

Innovation Solution

A method for generating security profiles for target devices, involving obtaining a base security profile, assigning configurable security parameters with specific values, and outputting different security profiles for various deployment phases, such as development, testing, and production.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual process is used to create security information for each deployment phase, then security officer can configure security parameters, but the process becomes slow and prone to inaccuracies

Engineering Contradiction:
Improveaccuracy of security informationVSAvoidspeed of deployment
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by creating a master security profile that contains all necessary security parameters before deployment phases begin. This master profile serves as a pre-configured template that can be automatically replicated and adapted for different deployment phases (development, testing, production), eliminating the need for manual reconfiguration and reducing errors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements copying by automatically generating phase-specific security profiles from the master security profile. The system creates copies of the master profile for each deployment phase and automatically populates them with appropriate values based on phase-specific rules, eliminating manual copying and reducing inaccuracies.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If security officer manually configures each security parameter, then security information can be created, but human resource is needed to diagnose incorrect configurations

Engineering Contradiction:
Improveflexibility in security configurationVSAvoidtime for diagnosis and correction
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies feedback by implementing automatic validation mechanisms that check security profile configurations against defined rules and requirements. The system provides feedback on configuration errors and automatically corrects them, eliminating the need for manual diagnosis and reducing time loss.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements self-service by enabling the system to automatically configure, validate, and correct security profiles without human intervention. The automated system serves itself by detecting and fixing configuration errors, eliminating the need for human resource to diagnose and correct issues.

Inventive Principle:
Principle #25Self-service

3Reliability

If different security information is used for each deployment phase, then security requirements are met, but manual creation leads to inefficiency

Engineering Contradiction:
Improvesecurity complianceVSAvoidcomplexity of security management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a master security profile that serves multiple deployment phases (development, testing, production) simultaneously. This single master profile can be automatically adapted to generate phase-specific security profiles, reducing the complexity of managing separate security configurations for each phase while maintaining security compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements parameter changes by automatically modifying security profile parameters based on the deployment phase. The system changes specific parameters (such as certificate validity periods, key strengths, or access permissions) automatically when generating profiles for different phases, maintaining security compliance without manual intervention.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3555791B1Programming target devices
Publication Date: 2025.05.21 SECURE THINGZ
  • EP3555791B1 patent drawingFigure 1
  • EP3555791B1 patent drawingFigure 2
  • EP3555791B1 patent drawingFigure 3

AI summary

A method of providing a security profile for programming at least one target device, the method implemented on a computing device and comprising:obtaining a base security profile, the base security profile defining at least one security parameter having a configurable value, generating a first security profile from the base security profile in response to receiving input from a user via an input device of the computing device, wherein generating the first security profile comprises, for each of the at least one security parameter, assigning the security parameter with a value of a first set of values by: (i) retrieving the value of the first set of values from a first data storage location coupled to the computing device and setting the configurable value of the security parameter using the retrieved value, or (ii) associating the security parameter with an instruction to obtain the value of the first set of values and set the configurable value of the security parameter using the obtained value, the instruction selected from one or more instructions;generating a second security profile from the base security profile in response to receiving further input from a user via said input device, wherein generating the second security profile comprises, for each of the at least one security parameter, assigning the security parameter with a value of a second set of values by: (i) retrieving the value of the second set of values from a second data storage location coupled to the computing device and setting the configurable value of the security parameter using the retrieved value, or (ii) associating the security parameter with an instruction to obtain the value of the second set of values and set the configurable value of the security parameter using the obtained value, the instruction selected from said one or more instructions, wherein the second set of values are different to the first set of values; outputting, the first security profile for programming at least one target device for use by a first type of user; and outputting the second security profile for programming at least one target device for use by a second type of user different to the first type of user.