Control system for technical equipment with certificate management

By introducing an automatic revocation service and a blacklist into the control system, the problem of delayed certificate revocation for equipment components was solved, enabling instant certificate revocation and consistency of certificate status within the equipment, thereby improving the security and efficiency of equipment communication.

CN114981735BActive Publication Date: 2026-03-24SIEMENS AG
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-01-13
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In the existing technology, the revocation of certificates between device components cannot achieve an immediate effect, which may lead to the abuse of communication and the revocation process is delayed.

Method used

Design a computer-supported control system, including a revocation service, capable of automatically and event-drivenly initiating certificate revocation and ensuring certificate state consistency within the device through a prohibition list.

Benefits of technology

It enables immediate certificate revocation, reduces the risk of certificate abuse, and improves the security and efficiency of device communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114981735B_ABST
    Figure CN114981735B_ABST
Patent Text Reader

Abstract

The invention discloses a control system (1) for a technical device, in particular a manufacturing or process device, which is designed and configured to initiate the issuance and revocation of certificates for components (7) of the technical device in the context of a certificate management. According to the invention, the control system (1) is characterized in that the control system comprises a revocation service (17) executed by a computer, which is designed and configured to initiate the revocation of certificates in an event-driven and automated manner.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The invention discloses a control system for technical equipment, in particular manufacturing or process equipment, which is designed and arranged for initiating, in the context of certificate management, the issuance and revocation of certificates for components of the technical equipment, having the features according to the invention. Furthermore, the invention discloses a method according to the invention. BACKGROUND

[0002] In the context of certificate management of industrialized equipment not only certificates have to be issued, but also revocations have to be possible. In particular, the revocation of certificates applied by equipment components takes place at standstill of the equipment component and at its replacement (or substitution by other components) and can take place at operation of the equipment. Here, the applied certificate is invalidated by revocation. Otherwise the certificate can be misused, by for example employing a revoked and removed device in case of an application (in case in other equipment parts) of the certificate for communication.

[0003] In the context of modular automation it is absolutely necessary that the possibility exists to initiate the revocation of a certain certificate as required. This is because modules can be combined with various other modules in various projects and are here usually assigned project-specific certificates which are used for communication with other modules in the context of the respective project. As soon as a module is no longer required (and thus prevented) to be employed in the context of a certain project, all project-specific certificates assigned to the module in the context of the project should be revoked in order to exclude the misuse of the certificates.

[0004] Depending on the scenario, the revocation of a certificate can be initiated by the equipment component itself or by a right (management) entity, a Revokation Request being distributed to the Certification Authority (CA) which issued the certificate. Such a Revokation Request is a component of known certificate management protocols (for example CMP according to RFC 4210) and is supported by certification authorities, for example by the so-called EJBCA / PrimeKey CA. For certification authorities of other supporting protocols which do not have a Revokation Request as a message type in their scope, the revocation can be

[0005] - either manually, directly at the certification authority (for example via its web front end),

[0006] - or by an application (for example initiated by a Registration Authority (RA)).

[0007] If communication between the various components of a device suddenly proves unnecessary and, from a security perspective, should be blocked due to the revocation of the certificate in use, the revocation of the certificate cannot be achieved "immediately" in previously known control systems. Until now, the revocation process has been initiated by the user directly at the certification authority or via other central entities (such as a registration server). Here, the necessity of certificate revocation is first identified, and then the revocation is initiated manually. Here, due to organizational and technical reasons, a significant delay can occur between these two events. Summary of the Invention

[0008] The purpose of this invention is to provide a control system for a technical device that enables certificate management with valid revocation of certificates.

[0009] This objective is achieved by a control system for technical equipment having the features described in this invention. Furthermore, this objective is achieved by a method according to the invention. Advantageous improvements are given by embodiments.

[0010] According to the present invention, the purpose of a control system of the type described at the beginning is to include a revocation service executed by a computer, which is designed and configured to initiate the revocation of a certificate in an event-driven and automatic manner.

[0011] In the current context, a control system is understood as a computer-supported technical system that includes the functionality for displaying, operating, and managing technical systems (such as manufacturing or production equipment). In this context, a control system includes sensors for determining measured values ​​and various actuators. Furthermore, a control system includes so-called process-related or manufacturing-related components for driving actuators or sensors. In addition, a control system also provides mechanisms for visualizing technical equipment and for engineering design. Additionally, the concept of a control system can also be understood as additional computing units for complex calculations and systems for data storage and processing.

[0012] Technical equipment can be equipment from process industries, such as chemical, pharmaceutical, petrochemical, or food and beverage industries. This also includes every piece of equipment in manufacturing plants, such as those producing automobiles or all types of goods. Technical equipment suitable for performing the methods according to the invention can also originate from the power generation sector. Wind turbines, solar power equipment, or power plants used for power generation are also included in the concept of technical equipment.

[0013] A component can be any individual sensor or actuator of a technical device. A component can also be a combination of multiple sensors and / or actuators, such as a motor, reactor, pump, or valve system.

[0014] A certificate is understood as a digital dataset that verifies specific characteristics (in this case, a machine, device, application, or the like). The trustworthiness and integrity of a certificate can typically be verified using cryptographic methods.

[0015] Revocation can be initiated by the process control system in an event-driven and fully automated manner, enabling the revocation of certificates to be revoked as immediately as possible. The technical features according to the invention effectively minimize delays in the revocation process, thus improving certificate management of the control system for technical equipment overall.

[0016] Any change in state within the technical equipment can be considered an event. Within the scope of an advantageous improvement of the invention, a change in the communication links between the various components of the technical equipment represents such an event.

[0017] Advantageously, the revocation service of the control system is designed and configured to initiate the revocation of a certificate by issuing a revocation request to the certificate authority through the revocation service. Here, the revocation service is designed and configured to monitor, or be able to monitor, the processing of revocation requests. This means that the revocation service can self-monitor, i.e., directly, or indirectly, particularly through monitoring by a separate service, i.e., indirectly, especially through monitoring by the registration service.

[0018] Certification authorities are also known as "Certification Authorities (CAs)." Such CAs are typically always online and, based on incoming certificate requests, issue certificates to different applicants using their own CA certificates. The trustworthiness of a CA is thus ensured by having its own CA certificate signed by a trusted root CA (also known as a "root CA") located in a protected environment. It's important to note that root CAs are mostly offline and are only activated or connected under strict security measures when they are required to issue certificates for their respective CAs. Root CAs can also be located outside of technical facilities.

[0019] Within the scope of monitoring revocation requests through a revocation service, the revocation service can send new requests to the certification authority while delaying the processing of revocation requests (referred to herein as "polling"). This process is described, for example, in standard RFC 4210 (RFC = Request for Comments), which specifies the Certificate Management Protocol (CMP).

[0020] In a particularly preferred embodiment of the invention, the control system is designed and configured to publish the revocation within the control system after successful certificate revocation, specifically in the form of a prohibition list. By immediately revoking the certificate as previously described and immediately distributing the revocation message within the control system, all components of the technical equipment are always kept up-to-date with respect to the issued certificate, significantly reducing the risk of certificate abuse. This publication ensures that all revoked certificates are always available within the context of the equipment.

[0021] When a no-list is applied, the publication of revoked certificates can be achieved through a certification authority. Such entries on the no-list can be digitally signed by the certification authority to ensure their credibility. Furthermore, this avoids the possibility of the no-list being updated by users (e.g., designers) or the intelligent server itself, reducing the risk of abuse.

[0022] What can be provided by the ad-hoc list available across the entire equipment range is which certificates issued by project-specific certification bodies are reliable in that project context and which are not. If a certificate is proven to be unreliable in the context of the (engineering) project, then the revocation process can be initiated as described above.

[0023] Furthermore, the aforementioned objective is achieved by the method according to the present invention. The method includes the steps of:

[0024] a) The issuance of certificates to components of technical equipment is initiated through the control system of the technical equipment;

[0025] b) In response to a determined event, the revocation of the certificate is automatically initiated through a computer-executed revocation service of the control system of the technical equipment.

[0026] The description of the method and its related advantages are given by reference to the above-described embodiments of the control system according to the present invention.

[0027] In a favorable improvement of the method according to the invention, a change in the communication link between components of a technical device represents an event that triggers the automatic initiation of certificate revocation.

[0028] Preferably, the revocation service submits a revocation request to the certification authority in order to initiate the revocation of the certificate, wherein the revocation service monitors the processing of the revocation request.

[0029] Particularly preferably, the revocation is published within the control system after the certificate is successfully revoked, wherein the publication is specifically implemented in the form of a prohibition list. Attached Figure Description

[0030] Combine the following connectionsFigure 1 The detailed description of the embodiments clearly and understandably illustrates the above-mentioned features, characteristics, and advantages of the present invention, as well as the ways and methods of implementing them. Detailed Implementation

[0031] Figure 1 A portion of the control system 1 according to the present invention is shown as a device constructed as a method technique. The control system 1 includes an operating system server or operator station server 2 and associated operator station clients 3. The operator station server 2 and operator station clients 3 are interconnected via a terminal bus 4 and connected to other components of the control system 1 (not shown), such as an engineering system server or process data archive.

[0032] Users or operators access operator station server 2 in the context of operation and monitoring via operator station server 3 and terminal bus 4. Terminal bus 4 can be configured as industrial Ethernet without limitations.

[0033] Operator station server 2 has a device interface 5, which is connected to a device bus 6. This enables operator station server 2 to communicate with (external) devices 7. Alternatively, the connected device 7 can be an application, particularly a network application. Within the scope of this invention, any number of devices and / or applications 7 can be connected to operator station server 2. Device bus 6 can be configured as, for example, industrial Ethernet without limitation. On the other hand, device 7 can be connected to any number of subsystems (not shown).

[0034] A visualization server 8 is integrated into the operator station server 2, enabling the transmission of (visualized) data to the operator station client 3. Furthermore, the operator station server 2 includes a process image 9, a process data archive 10, and a so-called "User Configuration and Selection Service (UPSS)" 11. The process image 9 of the operator station server 2 stores a transient image of the (signal) status of devices and / or applications 7 connected to the operator station server 2 via device interface 5. Past (signal) statuses are stored in the process data archive 10 for archiving. The "User Configuration and Selection Service" 11 represents a database storing the application configurations and personal settings of the operators / users of the method technology equipment. It can also be accessed by other operators / users.

[0035] Furthermore, the control system 1 includes a registration authority 12 and a certification authority 13. They are connected to the operator station server 2 and the operator station client 3 via a terminal bus 4. The registration authority 12 is designed to receive certification applications and transmit them to the certification authority 13. The certification authority 13 is used to issue certificates.

[0036] If device 7 wants to register with control system 1 and use its functions within the context of a defined engineering project, it needs a valid certificate. In step I, device 7 requests authentication from operator station server 2's authentication server 14. In step II, authentication server 14 accesses a prohibited list 15 stored in user configuration and selection service 11. Revoked certificates (“certificate revocation list”) are stored in this prohibited list 15 or in the database 16 of user configuration and selection service 11 at the time of access to prohibited list 15, within the context of the method technology device.

[0037] If device 7 is entitled to the certificate to be applied for in the context of an engineering project, specifically if the certificate is not one of the certificates revoked from the prohibition list 15, then the corresponding certificate application is passed to the registration authority 12 in step III, which in turn passes the certificate application to the certification authority 13 in step IV. The certificate issued by the certification authority 13 is then passed to the applying device 7 via the registration authority 12 (step V).

[0038] If a specific event occurs (e.g., a change in communication within the method / technology equipment), the certificate can become invalid and must therefore be revoked. The revocation request is transmitted from the revocation service 17 of the operator station server 2 to the registration authority 12. Here, the revocation request is initiated automatically without the direct influence of the designer or operator of the method / technology equipment. The registration authority 13 then declares the certificate in question invalid and stores this information on a prohibition list 15 stored in the registration authority 13. Next, the updated prohibition list 15 is transmitted via the registration authority 12 to the database 16 of the user configuration and selection service 11.

[0039] Here, the prohibition list 15 can be obtained from the certification authority 13 via the registration authority 12 in an event-driven manner in various ways. In the simplest case, a trigger can be configured in the certification authority 13, which ensures that the prohibition list 15 stored locally in the certification authority 13 is immediately replaced by the updated prohibition list 15 after the certificate is revoked. The storage location of the prohibition list 15 in the certification authority 13 can be monitored by the registration authority 12 (e.g., through a corresponding smart server) to immediately identify each update and immediately transmit the updated prohibition list 15 to the user configuration and selection service 11 of the operator station server 2. To improve the availability of the prohibition list 15 when multiple operator station servers 2 are used, the database 16 can compare the "mirrors" 18 between the various operator station servers 2 using the server.

[0040] Through the interface 19, which is graphically constructed by the visualization server 8 on the operator station client 3, the operator / designer can pre-define new / modified events, which are provided by the management server 20, which is configured and selected by the user, to the revocation service 17 for automatic revocation of certificates thereafter.

[0041] The technical features described above eliminate delays in the revocation process. Furthermore, based on the principle of minimum requirements (which has a very high priority in industrial safety), each device 7 is only permitted to access the currently prohibited list 15 that is truly necessary. To this end, the necessary technical functions are "technically" integrated into the control system 1, thus eliminating the need for additional communication paths "outside the control system 1" for revocation management, in addition to those already existing within the environment of the control system 1.

[0042] Another advantage lies in the security aspect, namely that no special settings are required in the network for access to the prohibited list 15 (e.g., no ports need to be opened, which would pose a high security risk). The described control system 1 is well-suited for modular devices in which the device components of the method technology are dynamically added or removed.

Claims

1. A control system (1) for technical equipment, said technical equipment being manufacturing or process equipment, said control system being designed and configured to initiate the issuance and revocation of certificates for components (7) of said technical equipment within the scope of certificate management. Its features are, The control system (1) includes an operator station server (2) and associated operator station clients (3), which are interconnected via a terminal bus (4). The operator station server (2) includes a revocation service (17) executed by a computer. The revocation service is designed and configured to initiate the revocation of a certificate in an event-driven and automatic manner, wherein a change in the communication between the components (7) of the technical equipment in the absence of any component (7) being replaced or removed during the process represents an event that triggers the initiation of the revocation of the certificate. The control system is designed and configured to publish the revocation within the control system (1) after the certificate is successfully revoked. The publication is implemented in the form of a prohibition list (15). The publication of the revoked certificate can be implemented by a certification authority. The entries in the prohibition list can be digitally signed by the certification authority to ensure the credibility of the entries.

2. The control system (1) according to claim 1, wherein the revocation service (17) is designed and configured to initiate the revocation of the certificate by providing a revocation application to the certification body (13) through the revocation service (17), wherein, The revocation service (17) is designed and configured to monitor or be able to monitor the processing of the revocation request.

3. A method for issuing and revoking certificates for components of technical equipment, comprising: a) The issuance of a certificate to a component of the technical equipment is initiated through the control system (1) of the technical equipment; b) In response to a determined event, the revocation of the certificate is automatically initiated by the operator station server through a computer-executed revocation service (17) of the control system (1) of the technical equipment. The operator station server includes a computer-executed revocation service. The operator station server and the operator station client are interconnected via a terminal bus. A change in communication between the components (7) of the technical equipment, without any component (7) being replaced or removed during the process, indicates an event that triggers the automatic initiation of the revocation of the certificate. After a certificate is successfully revoked, the revocation is published in the control system (1). The publication is carried out in the form of a prohibition list (15). The publication of the revoked certificate can be carried out by a certification authority. The entries in the prohibition list can be digitally signed by the certification authority to ensure the credibility of the entries.

4. The method according to claim 3, wherein the revocation service (17) provides a revocation request to the certification authority (13) to initiate the revocation of the certificate, wherein, The revocation service (17) monitors or is able to monitor the processing of the revocation request.

Citation Information

Patent Citations

  • Method, device and system for raising network security

    CN103563291A

  • Mobile handset extension to a device

    US20100062770A1

  • Systems and methods for enhanced online certificate status protocol

    US20190260596A1