Temporally Restricted Authorization for Secure Program Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for testing programs in electronic devices fail to ensure secure and authentic testing environments, risking exposure of sensitive functions and information due to potential errors in programs granted trust access, and often require separate testing devices, increasing costs and security risks.

Innovation Solution

A method involving digitally signed and encrypted authorization messages transmitted via wireless communication, where the digital signature is verified and decrypted within the device, granting temporally restricted access to ensure the message is intended for the specific device, allowing secure and authentic testing without compromising security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a program is granted authorization to use functions requiring trust for testing purposes, then the program can be tested in an authentic device environment, but the device risks exposure of sensitive functions and information due to potential errors in the program

Engineering Contradiction:
Improvetesting reliabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the authorization temporal and revocable rather than static. The authorization granted to the test program is time-limited and can be revoked, allowing the system to adapt the security level dynamically during the testing process. This resolves the contradiction by enabling authentic testing while limiting the window of security risk through temporal constraints on authorization.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of authorization from permanent to temporal. By introducing a time parameter to the authorization mechanism, the system allows programs to be tested in authentic environments while the authorization automatically expires after a specified period, thereby reducing the security risk associated with potential program errors.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If trust level of the entire device is lowered for testing duration, then program can be tested extensively, but the device becomes vulnerable to unauthorized access and confidential information exposure

Engineering Contradiction:
Improvetesting capabilityVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by granting authorization to a specific program for specific functions rather than lowering the trust level of the entire device. The authorization is localized to the test program and specific time period, allowing extensive testing capability while maintaining high security levels for the rest of the device system.

Inventive Principle:
Principle #3Local quality

3Reliability

If separate testing devices are used, then security risks are reduced, but testing costs increase and authentic environment is compromised

Engineering Contradiction:
Improvesecurity safetyVSAvoidtesting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the authorization mechanism into distinct components: the authorization message itself, the verification process, and the temporal constraints. This allows the system to maintain security through structured authorization management while using a single authentic device for testing, avoiding the need for separate testing devices and reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7287161B2Method and system for testing a program, and a device
Publication Date: 2007.10.23 GULA CONSULTING LLC
  • US7287161B2 patent drawing
  • US7287161B2 patent drawing
  • US7287161B2 patent drawing

AI summary

The present invention relates to a method and system for testing programs. In the method, authorization to use is determined for a program. In the method, a grant message of authorization is produced to grant temporally restricted authorization to use for the program, it is verified that the grant message of authorization is suitable to be utilized only in the device and the verified grant message of authorization is transmitted to the device. In the device the verification is checked, the authorization to use transmitted in the grant message of authorization is determined, and authorization to use according to the grant message of authorization are given for the program to be tested, if the checking shows that the grant message of authorization is intended for the device. The invention also relates to a device in which the method is applied.