Secure Operation Approval via Signatory Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public or cloud-based management solutions for SCADA systems and other managed devices are vulnerable to unauthorized access, compromising security and risking high-risk assets due to insecure configurations.

Innovation Solution

A system and method for secure approval of operations requested by a device management system, utilizing a managed device with an authorization key and a management module that communicates with a signatory module to enable authorization of operation requests, ensuring only authorized operations are performed by the managed device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public or cloud-based management solutions are used for managing devices, then ease of operation and remote access are improved, but security and reliability deteriorate due to vulnerability to unauthorized access and insecure configurations

Engineering Contradiction:
Improveremote accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the management architecture into distinct components: a cloud-based management module for ease of operation, a local signatory module for security approval, and managed devices. This segmentation allows public cloud access while maintaining local security control through the signatory module that approves or rejects operations before they reach managed devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The signatory module acts as an intermediary between the cloud-based management module and managed devices. It receives operation requests from the cloud, applies security policies and authorization keys, and only forwards approved operations to managed devices. This intermediary layer enables public cloud access while filtering out unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If on-premises management solutions are used to improve security, then security and reliability are improved, but ease of operation and remote access capability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidremote access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges the advantages of both cloud-based and on-premises solutions by combining the remote access capability of cloud management with the security of local control. The management module resides in the cloud for ease of operation, while the signatory module with authorization keys remains on-premises for security, creating a hybrid architecture that achieves both goals simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If authorization mechanisms are added to secure operations, then security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The signatory module performs preliminary authorization actions before operations are executed on managed devices. Authorization keys and security policies are pre-configured in the signatory module, which automatically approves or rejects operations based on these pre-established criteria. This preliminary action eliminates the need for complex real-time authorization processing on managed devices themselves.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The signatory module operates autonomously using pre-configured authorization keys and security policies to automatically approve or reject operations without requiring manual intervention or complex processing on managed devices. This self-service mechanism simplifies the overall system by handling security decisions centrally rather than requiring complex local authorization logic on each device.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240297792A1System and method for secure approval of operations requested by a device management system
Publication Date: 2024.09.05 SEMTECH CORP
  • US20240297792A1 patent drawing
  • US20240297792A1 patent drawing
  • US20240297792A1 patent drawing

AI summary

There is provided a system and method for secure approval of operations requested by a device management system. The system includes a managed device configured to provide wireless device access, the managed device having information indicative of an authorization key associated therewith and a management module configured to manage access to the managed device, the management module configured to communicate with a signatory module. The system further includes a signatory module configured to receive an authorization request associated with the operation, the signatory module further configured to enable authorization of the operation through the association of the authorization key with the operation. Upon receipt of an authorized operation request that includes information indicative of the operation and the authorization key, the managed device responsive to the authorized operation request upon verification of the authorization key.