Portable Terminal Locking System Isolating Authentication Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management systems for vehicles and facilities lack robust security measures, particularly when multiple users share access across different time zones, as authentication information is vulnerable to leakage when stored on a server managed by a third party.

Innovation Solution

A locking and unlocking system that includes a portable terminal and a server, where the portable terminal requests authentication information from a server managed by a different organization, reducing the risk of information leakage by using a dedicated security policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication information is stored on a server managed by a third party, then user convenience for shared access is improved, but security against information leakage deteriorates

Engineering Contradiction:
Improveuser convenience for shared accessVSAvoidsecurity against information leakage
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the authentication process into two distinct components: a first server that provides convenient access management and a second server that securely stores authentication information. This segmentation allows the first server to handle user reservations and access requests while the second server maintains security by storing authentication credentials, thus resolving the contradiction between convenience and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The portable terminal acts as an intermediary between the first server and the second server. It receives authentication information requests from the first server, forwards them to the second server, and relays the authentication results back. This intermediary role prevents direct exposure of authentication information to the first server while maintaining the convenience of access management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single server manages both reservation service and authentication information, then system complexity is reduced, but security risk increases

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system divides the server infrastructure into two separate servers: a first server dedicated to reservation services and a second server dedicated to authentication information storage. This segmentation reduces security risk by isolating sensitive authentication data from the reservation management system, while the overall system complexity remains manageable through clear functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication information storage function is extracted from the reservation service server and placed in a dedicated second server. This extraction removes the security vulnerability of having authentication information embedded in the reservation system, while the reservation service continues to operate independently through the portable terminal interface.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11380149B2Locking and unlocking system, portable terminal capable of communicating with server, locking and unlocking method executed by portable terminal, and non-transitory storage medium storing program
Publication Date: 2022.07.05 TOYOTA JIDOSHA KK
  • US11380149B2 patent drawing
  • US11380149B2 patent drawing
  • US11380149B2 patent drawing

AI summary

A locking and unlocking system includes a portable terminal and a server. The portable terminal includes a service providing unit, a first sending unit, and a first receiving unit. The service providing unit provides a use reservation service for a vehicle or facilities by communicating with another server. The first sending unit sends a first signal to the server in response to a request from the service providing unit. The first signal requests authentication information used for locking and unlocking. The first receiving unit receives the authentication information from the server. The server includes a second receiving unit and a second sending unit. The second sending unit sends a second signal including the authentication information to the portable terminal when the second receiving unit receives the first signal.