Server-Controlled Security Management for Franking Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current franking machines lack comprehensive security measures for data storage and processing, particularly in remote services, which can lead to vulnerabilities in postage calculation, print head protection, and data exchange security.

Innovation Solution

A server-controlled security management system that utilizes a remote data center to store and process security data sets with associated security categories, determining storage locations and security protocols for data exchange, and establishing logical communication channels to ensure secure data transfer and storage within or outside the postal security device (PSD) of the franking system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security measures are implemented for data storage and processing in franking machines, then security against manipulation and fraud is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity against manipulation and fraudVSAvoidcomplexity of security management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote data center as an intermediary that handles security data storage and management externally. The franking machine communicates with this external security infrastructure rather than containing all security functions internally, thereby improving security reliability while avoiding the complexity of implementing comprehensive local security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security management system is segmented into multiple components: a security module within the franking machine for local security operations, a remote data center for centralized security data storage, and a communication interface for data exchange. This segmentation allows each component to be optimized independently, improving overall security without proportionally increasing complexity.

Inventive Principle:
Principle #1Segmentation

2Speed

If security data are stored locally in the franking machine, then response time for security operations is improved, but vulnerability to local manipulation increases

Engineering Contradiction:
Improveresponse time for security operationsVSAvoidrisk of local manipulation
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements a nested security architecture where a security module is embedded within the franking machine to provide fast local response, while this entire system is nested within a broader remote security infrastructure. The security module handles immediate local security operations quickly, while critical security data are stored remotely to protect against local manipulation attempts.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If remote data center services are used for security management, then security data protection is improved, but communication overhead and latency increase

Engineering Contradiction:
Improvesecurity data protectionVSAvoidcommunication overhead and latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing secure communication channels and authenticating sessions before actual security data exchanges occur. Security protocols are pre-configured and validated, so that when remote data center services are accessed, the communication overhead is minimized because the foundation for secure exchange is already in place.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If security categories and policies are implemented for data sets, then granular security control is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvegranular security controlVSAvoidcomplexity of security policy management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security category system where a small set of standardized security categories can be applied to multiple different types of security data. This multi-functional approach allows granular security control across diverse data types without requiring separate complex policies for each data type, thereby reducing overall system complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7996884B2Method and arrangement for server-controlled security management of services to be performed by an electronic system
Publication Date: 2011.08.09 FRANCOTYP POSTALIA AG & CO KG
  • US7996884B2 patent drawing
  • US7996884B2 patent drawing
  • US7996884B2 patent drawing

AI summary

An arrangement for providing data in the context of security management for a franking system has a remote data center at which a list of data sets is stored the data sets containing security information as well as information regarding associated security policies, appertaining at least to security measures and the location of their storage in the franking system. A method for server-controlled security management of performable services in an electronic system includes the steps of receiving a request for a desired service, determining a security feature to be selected and generating a data set corresponding thereto, selecting a logical channel and transferring to data set via that channel establishing the service end, and waiting for receipt of a further service request or for the ending of the communication connection.