Software Parameterization via Digital Signature Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for changing parameters in technical systems are often complex, inflexible, and costly, particularly when requiring online connections or multiple hardware components, which can lead to delays and inefficiencies, especially in remote or specialized environments like ships or submarines.

Innovation Solution

A computer-aided parameterization method involving a software package with a digital signature, which includes a test program and external digital information, allows for flexible parameter setting by verifying signatures and adhering to predefined rules, enabling authorized changes without the need for additional signatures or complex hardware setups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary interfaces with authorization requirements are implemented to prevent unauthorized parameter changes, then security is improved, but device complexity and implementation effort increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical hardware authorization systems with a software-based digital signature verification mechanism. Instead of using multiple independent hardware components with separate authorization definitions, the system uses cryptographic digital signatures to authenticate parameter change requests, significantly reducing hardware complexity while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a universal parameter change authorization system that can handle multiple authorization scenarios through a single software-based digital signature mechanism. This single system replaces the need for multiple specialized hardware interfaces, allowing the same infrastructure to serve different authorization levels and parameter types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple independent hardware components are installed to limit parameter change to certain authorities, then security is improved, but device complexity and costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple independent hardware authorization components into a single unified software-based authorization system. Instead of installing separate hardware components for different authorities, the system combines all authorization logic into one software module that uses digital signature verification to handle various authorization levels, reducing both hardware count and system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses digital signature certificates as cryptographic copies of authorization credentials. Instead of requiring physical hardware tokens for each authority, the system creates software-based cryptographic representations of authorization rights that can be verified without the original hardware components, reducing hardware requirements while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If online connection is required to check and confirm parameter changes, then security is improved, but productivity and response time decrease

Engineering Contradiction:
ImprovesecurityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs authorization verification in advance by checking digital signatures before parameter changes are applied. The system validates the cryptographic authenticity of parameter change requests locally using pre-stored public keys, eliminating the need for real-time online connections during the actual parameter change operation, thus improving response time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service parameter changes by allowing authorized users to perform parameter modifications locally without requiring real-time online verification. The digital signature mechanism allows the system to autonomously verify authorization credentials without external intervention, enabling parameter changes in offline environments like ships or submarines.

Inventive Principle:
Principle #25Self-service

4Reliability

If online connection is required to check and confirm parameter changes, then security is improved, but ease of operation decreases

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service parameter modification capability where authorized users can directly change parameters using locally stored digital signature credentials. The system automatically verifies authorization without requiring external online confirmation, making the operation as simple as local file operations while maintaining security through cryptographic verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11669641B2Method for the computer-aided parameterization of a technical system
Publication Date: 2023.06.06 SIEMENS AG
  • US11669641B2 patent drawing

AI summary

The invention relates to a method for the computer-aided parameterisation of a technical system (1) in which the technical system (1) is used to store a software package (SP) that is signed with a first digital signature (SIG1) and comprises a test program (PM). The technical system (1) checks the validity of the first digital signature (SIG1). If the first digital signature (SIG1) is valid, the software package (SP) is installed on the technical system (1), wherein during the installation the test program (PM) checks whether a number of rules (RU), at least some of which are stored in the test program (PM), are observed by external digital information (DA) coming from outside the software package (SP). If there is a number of conditions (CO) comprising observance of the number of rules (RU) by the external digital information (DA), parameter setting is performed in the technical system (1) by means of the external digital information (DA) and otherwise the method is terminated.