Session-Specific Access Codes for Secure Remote Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote management systems for factory automation devices face security threats due to unauthorized access when URL information for accessing control devices leaks to unintended third parties.

Innovation Solution

An information providing method and system that initiates a communication session between a control device and a server, issuing temporary access information unique to each session, which is notified to the terminal only upon successful connection, and includes an identification code for session verification, with the access information being invalidated after a predetermined time or upon service termination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access information (URL) for control device is provided to terminal, then terminal can access control device information, but access information may leak to unintended third parties causing unauthorized access

Engineering Contradiction:
Improveaccessibility of control device informationVSAvoidunauthorized access and information leakage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The server performs preliminary authentication of the terminal before issuing access information. This preliminary action ensures that only authorized terminals receive access information, preventing leakage to unintended third parties while maintaining ease of access for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access information is changed from a static URL to a dynamic, session-specific access code. Each terminal receives a unique access code that is valid only for its authenticated session, transforming the access mechanism from a permanent credential to a temporary, context-dependent identifier that cannot be reused by unauthorized parties.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If static URL is used for accessing control device, then access is simple and consistent, but security is compromised when URL leaks

Engineering Contradiction:
Improvesimplicity of access mechanismVSAvoidsecurity of access information
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Authentication is performed before access information is issued, establishing a secure foundation that allows the use of simple access codes without compromising security. The complexity of authentication is separated from the access mechanism itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access mechanism transitions from using a static URL to using dynamic access codes that are regenerated for each authentication session. This parameter change maintains simplicity for the end user while fundamentally improving security by making leaked access information useless to unauthorized parties.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If access information is issued to multiple terminals, then more users can access control device, but risk of information leakage increases

Engineering Contradiction:
Improvenumber of accessible terminalsVSAvoidprobability of unauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Instead of issuing the same access information to multiple terminals, the system segments access information by creating unique, terminal-specific access codes. Each terminal receives its own authenticated access code, allowing multiple users to access the control device while preventing any single terminal from accessing another terminal's data or gaining unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access information parameter is transformed from a shared, static URL to individual, dynamic access codes tied to each terminal's authentication session. This parameter change enables scalable multi-terminal access while maintaining security, as each terminal's access code is independent and cannot be used by other terminals.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11979404B2Information providing method, information providing system, and server
Publication Date: 2024.05.07 OMRON CORP
  • US11979404B2 patent drawing
  • US11979404B2 patent drawing
  • US11979404B2 patent drawing

AI summary

An information providing method includes (i) starting, by a control device, a communication session with a server in response to establishment of a communication connection with a terminal, and (ii) issuing, by the server, temporary access information for accessing a service in a manner that depends on the communication session. The access information is different for each communication session. The information providing method further includes (iii) notifying, by the control device, the access information to the terminal, and (iv) providing, by the server, target information collected from the control device to the terminal in response to access from the terminal based on the access information. Accordingly, the threat to security when providing information of the control device is reduced.