System and method for authenticating industrial automation components

By introducing EEPROM for component authentication in industrial automation systems, the authentication challenges of firmware, microprocessors, and microcontrollers are solved, thereby improving system security and management efficiency.

CN115857381BActive Publication Date: 2026-01-02ROCKWELL AUTOMATION TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211103470.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-09-27
Filing Date
2022-09-09
Publication Date
2026-01-02
Estimated Expiration
2042-09-09

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively certify industrial automation components lacking firmware, microprocessors, and microcontrollers, leaving industrial automation systems exposed to unknown risks.

Method used

Introducing electrically erasable programmable read-only memory (EEPROM) into components of industrial automation systems to store identification information and authenticate them via backplane switches ensures the legitimacy of the components.

Benefits of technology

It enables the authentication of components lacking firmware, microprocessors, and microcontrollers, improving system security and management efficiency, and providing verification of component legitimacy and system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115857381B_ABST
    Figure CN115857381B_ABST
Patent Text Reader

Abstract

The present invention relates to systems and methods for authenticating industrial automation components. A first component of an industrial automation system includes an electrically erasable programmable read-only memory (EEPROM) storing data identifying the first component. The data identifying the first component is read from the EEPROM by a second component communicatively coupled with the first component to authenticate the first component. The first component lacks a processor and a microcontroller, and does not run firmware.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates generally to authenticating industrial automation components. More specifically, the present disclosure relates to authenticating industrial automation components in an input / output (I / O) system without using firmware, microprocessors, or microcontrollers. BACKGROUND

[0002] Industrial automation systems can be used to provide automated control over one or more actuators. Controllers can output regulated power signals to actuators to control movement of the actuators. Input / output (I / O) systems can facilitate communication with controllers and other devices within an industrial automation system. To reduce costs, owners of industrial automation systems can obtain components for their industrial automation systems from un-authorized sources. These components can include counterfeit components, stolen components, cloned components, refurbished components made from one or more retired or previously used components, malicious (e.g., malware) or components that attempt to modify functionality of the components, such that use of these components can pose unknown risks to the industrial automation system. For components that run firmware and / or have microcontrollers or microprocessors, authentication certificates can be used in conjunction with the firmware, microcontrollers, and / or microprocessors to perform an authentication process that authenticates components used within the industrial automation system. However, such authentication processes can not be applicable to components that lack firmware, microcontrollers, and / or microprocessors. Accordingly, there is a need for methods of authenticating components that lack firmware, microcontrollers, and / or microprocessors.

[0003] This section is intended to introduce the reader to various aspects of art that can be related to various aspects of the present disclosure that are described and / or claimed below. This discussion is believed to be helpful in providing the reader with background information to facilitate a better understanding of the various aspects of the present disclosure. Accordingly, it should be understood that these statements are to be read in this light, and not as admissions of prior art. SUMMARY

[0004] In one embodiment, an input / output (I / O) system of an industrial automation system includes a rail, a first backplane switch coupled to the rail, a network adapter base coupled to the first backplane switch, a second backplane switch coupled to the rail and arranged adjacent to the first backplane switch, and an I / O bank. The network adapter base includes a first electrically erasable programmable read only memory (EEPROM) storing first data identifying the network adapter base. The first backplane switch reads the first data from the first EEPROM to authenticate the network adapter base. The I / O bank includes an I / O base coupled to the second backplane switch, an I / O component coupled to the I / O base, and a terminal block coupled to the I / O base. The I / O base includes a second EEPROM storing second data identifying the I / O base. The second backplane switch reads the second data from the second EEPROM to authenticate the I / O base. The I / O component performs an industrial automation input / output function associated with a component of the industrial automation system. The terminal block is communicatively coupled to the component of the industrial automation system, wherein the terminal block includes a third EEPROM storing third data identifying the terminal block, wherein the I / O component reads the third data from the third EEPROM to authenticate the terminal block.

[0005] In another embodiment, a first component of an industrial automation system includes an electrically erasable programmable read only memory (EEPROM) storing data identifying the first component. The data identifying the first component is read from the EEPROM by a second component communicatively coupled to the first component to authenticate the first component. The first component lacks a processor and a microcontroller, and does not run firmware.

[0006] In yet another embodiment, a method includes detecting that an industrial automation component has been connected to an input / output (I / O) system of an industrial automation system, wherein the industrial automation component includes an electrically erasable programmable read only memory (EEPROM) storing data identifying the component, wherein the component lacks a processor and a microcontroller, and wherein the component does not run firmware; reading the data from the EEPROM; and authenticating the industrial automation component. BRIEF DESCRIPTION OF DRAWINGS

[0007] These and other features, aspects, and advantages of the present embodiments will become better understood when the following detailed description is read with reference to the accompanying drawings in which like characters represent like parts throughout the drawings, wherein:

[0008] Figure 1 is a schematic diagram of an industrial automation system according to embodiments presented herein;

[0009] Figure 2 is a schematic diagram of an industrial automation system according to embodiments presented herein Figure 1schematic diagram of a modular input / output (I / O) system of an industrial automation system;

[0010] Figure 3 is a perspective view of an embodiment of an I / O system in accordance with the embodiments presented herein; Figure 2 is a perspective view of an embodiment of an I / O system in accordance with the embodiments presented herein;

[0011] Figure 4 is a schematic diagram of a network adapter utilizing a "rail master base" style network adapter base in accordance with the embodiments presented herein;

[0012] Figure 5 is a schematic diagram of an I / O group utilizing a "four I / O base" style I / O base in accordance with the embodiments presented herein;

[0013] Figure 6 is a flowchart of a process for authenticating an industrial automation component coupled to an I / O system in accordance with the embodiments presented herein; Figure 2 and Figure 3 is a flowchart of an industrial automation component without firmware, microprocessor, or microcontroller for an I / O system in accordance with the embodiments presented herein; and

[0014] Figure 7 is a flowchart of a process for authenticating an industrial automation component in accordance with the embodiments presented herein. DETAILED DESCRIPTION

[0015] One or more specific embodiments will be described below. In an effort to provide a concise description of these embodiments, all features of an actual implementation can not be described in the specification. It should be appreciated that in the development of any such actual implementation, as in any engineering or design project, numerous implementation-specific decisions must be made to achieve the developers' specific goals, such as compliance with system-related and business-related constraints, which can vary from one implementation to another. Moreover, it should be appreciated that such a development effort might be complex and time consuming, but would nevertheless be a routine undertaking of design, fabrication, and manufacture for those of ordinary skill having the benefit of this disclosure.

[0016] When introducing elements of various embodiments of the present disclosure, the articles "a," "an," "the," and "said" are intended to mean that there are one or more of the elements. The terms "comprising," "including," and "having" are intended to be inclusive and mean that there can be additional elements other than the listed elements.

[0017] The disclosed technology includes components of an input / output (I / O) system of an industrial automation system that lack firmware, microprocessors, and microcontrollers, but have an electrically erasable programmable read-only memory (EEPROM) that stores identification information. For example, such components can include network adapter bases, I / O bases, base expander components, terminal blocks, and other industrial automation components. When such components are connected to the I / O system, or when they are powered on, existing devices of the I / O system such as backplane switches and / or I / O components can be configured to read the identification information from the EEPROM to authenticate the components. In some implementations, the identification information stored on the EEPROM can be encrypted, in which case reading the identification information from the EEPROM can involve cryptographic operations to decrypt the identification information. Further, in some implementations, the identification information can be provided to a software application or client device to verify the identity of the components. If the components pass authentication, they can be used normally. However, if the components fail authentication, a warning message / notification can be generated, and / or aspects of the industrial automation system can be disabled. The identification information can also be used to build a model of the industrial automation system to suggest modifications to the setup, provide installation and / or setup instructions, provide guidance to solve problems, confirm configurations, etc. Further, the identification information can be used for remote inventory and / or asset management.

[0018] By way of introduction, Figure 1 is a schematic diagram of an industrial automation system 10. As shown, the industrial automation system 10 includes a controller 12 and an actuator 14 (e.g., a motor (M)). The industrial automation system 10 can also include or be coupled to a power source 16. The power source 16 can include a generator, a battery (or other power storage device), or an external power grid. Although Figure 1 The controller 12 shown in FIG. 1 is a standalone controller 12, but in more complex industrial automation systems 10, one or more controllers 12 can be combined with other components in a motor control center (MCC) to control multiple actuators. In the present implementation, the controller 12 includes a user interface 18 such as a human-machine interface (HMI) and a control system 20, which can include a memory 22 and a processor 24.

[0019] The control system 20 can be programmed (e.g., via computer readable code or instructions stored on the memory 22 and configured to be executed by the processor 24) to provide signals for driving the motor 14. In certain embodiments, the control system 20 can be programmed according to a particular configuration required for a particular application. For example, the control system 20 can be programmed to respond to external inputs such as reference signals, alarms, command / status signals, etc. The external inputs can come from one or more relays or other electronic devices (e.g., sensors 26). The programming of the control system 20 can be accomplished by software configurations or firmware code that can be loaded onto the internal memory 22 of the control system 20 or programmed via the user interface 18 of the controller 12. The control system 20 can respond to a defined set of operating parameters. The settings of the various operating parameters determine the operating characteristics of the controller 12. For example, the various operating parameters can determine the speed or torque of the motor 14 or can determine how the controller 12 responds to various external inputs (e.g., from the sensors 26). Thus, the operating parameters can be used to map control variables within the controller 12 or other devices communicatively coupled to the controller 12. For example, these variables can include speed presets, feedback types and values, computational gains and variables, algorithm adjustments, status and feedback variables, control programming of programmable logic controllers (PLCs), etc.

[0020] In some embodiments, the controller 12 can be communicatively coupled to one or more sensors 26 for detecting operating temperatures, voltages, currents, pressures, flow rates, etc. within the industrial automation system 10. With feedback data from the sensors 26, the control system 20 can keep detailed track of various conditions under which the industrial automation system 10 can operate. For example, the feedback data can include conditions such as actual motor speed, voltage, frequency, power quality, alarm conditions, etc.

[0021] Figure 2 is for Figure 1A schematic diagram of a modular input / output (I / O) system 100 of an industrial automation system is shown. As shown, the modular I / O system 100 includes a network adapter 102 that communicates with a controller 12 (e.g., a programmable logic controller or PLC) via a network 104 (e.g., an Ethernet / IP network or other industrial automation network) such that the network adapter 102 receives data from the controller 12, sends data to the controller 12, and otherwise communicates with the controller 12. The network adapter 102 includes a network adapter base 106, a network adapter component 108 (e.g., a network adapter module), a network connector 110, and a power connector 112. In some embodiments, the network adapter 102 can also include a power conditioning circuit 114. The network adapter base 106 can be mounted (e.g., permanently or removably coupled) to a rail or a board 116. The network adapter component 108 can be removably coupled to the network adapter base 106 and include communication circuitry for communicating with the controller 12 via the network connector 110 and the network 104 and / or with other I / O groups 118 coupled to the rail or board 116. Thus, the network adapter component 108 can be configured to manage communications within the I / O system (e.g., between the network adapter 102 and various other I / O groups 118) and / or between the I / O system 100 and various other components of the industrial automation system, e.g., including the controller 12. The power connector 112 can be configured to receive power from a power source (which can or can not be the same power source 16 as shown Figure 1 In embodiments having the power conditioning circuit 114, the power conditioning circuit 114 can be configured to condition power received via the power connector 112 from the power source 16 by amplifying the power signal, attenuating the power signal, stepping up or stepping down the power signal, inverting the power signal, applying one or more filters to the power signal, converting a direct current (DC) power signal to an alternating current (AC) power, converting an AC power signal to a DC power, and the like.

[0022] Each of one or more other I / O groups 118 may include an I / O base 120, an I / O component 122 (e.g., an I / O module), and a terminal block 124 (e.g., a removable terminal block or "RTB"). The I / O base 120 may also be mounted (e.g., permanently or removably coupled) to a rail or board 116. The other I / O groups 118 may be sequentially communicatively coupled to each other via a multi-contact connector 126 and coupled to a network adapter 102 to form a backplane 128, enabling communication with the controller 12 and with one or more other I / O devices 132 via I / O wiring 136. The I / O component 122 may be removably coupled to the I / O base 120, enabling communication between the I / O component 122 and the controller 12 via the backplane 128. I / O component 122 may be configured to perform one or more dedicated industrial automation input / output functions, such as DC input, DC output, AC input, AC output, analog input and / or output, resistance temperature detector (RTD) and / or thermocouple input, control actuator output signals, etc. Terminal block 124 may include cage clips, spring clips, push-in terminals, threaded terminals, or other wiring connectors 130 configured to couple to field wiring associated with field I / O devices 132 (e.g., sensors, flow meters, switches, probes, thermocouples, RTDs, encoders, actuators, etc.) associated with a process or machine controlled by controller 12. In some embodiments, terminal block 124 may be a separate structure assembled and coupled to I / O base 120. In other embodiments, terminal block 124 may be integrated into I / O base 120. Depending on the specific configuration suitable for the field device wiring connector 130, different implementations / configurations of the terminal block 124 can be achieved (e.g., with different common terminals, ground connections, voltage supply terminals, etc.). The terminal block 124 of the I / O group 118 may also include a power connector 112 to supply power from a power source (which may or may not be present). Figure 1The same power source 16 shown receives power to I / O group 118 and / or I / O devices 132 (e.g., sensors, actuators, etc.) communicatively coupled to I / O group 118. Each mounted I / O component 122 communicates with a field device wiring connector 130 of the same I / O base 120 to which the I / O component 122 is physically coupled. Input / output data is provided between the field devices 132 connected to the respective I / O base 120 via backplane 128 and network adapter component 108 and the controller 12. In some embodiments, network adapter 102 and I / O group 118 may be coupled to rails or boards 116 via their respective backplane switches (BPS) 134 (sometimes referred to as bus interface modules (BIM)), which facilitate electrical connections between various components of backplane 128 (e.g., network adapter 102, I / O group 118, rails 116, etc.). In some embodiments, the multi-contact connector 126 and the backplane switch 128 may be different components. In other embodiments, the functions of the multi-contact connector 126 and the backplane switch 128 may be performed by the same component.

[0023] like Figure 2 As shown, backplane 128 sequentially couples the network adapter 102 and the circuitry of adjacent I / O groups 118 in series or sequentially via connectors 126 and / or backplane switches 134 of backplane 128. For example, the backplane switches 134 of each I / O group 118 and adapter 102 use a backplane data communication protocol to establish the aforementioned backplane circuitry 128.

[0024] Figure 3 yes Figure 2 A perspective view of an implementation of the I / O system 100. Figure 2 As illustrated, the I / O system 100 includes a network adapter 102 and two I / O groups 118. The network adapter 102 includes a network adapter base 106 (e.g., a rail-mounted main base), a network adapter component 108, a power conditioning component 114, a power connector 112 (e.g., a removable terminal block), one or more network connectors 110, and a backplane switch 134 (hidden). The I / O group 118 includes an I / O base 120 (e.g., a quad I / O base), I / O components 122, a removable terminal block 124 with wiring connectors 130, and a backplane switch 134. As shown, the removable terminal block 124 can be configured, as indicated by element 200, to support a single I / O component 122, or as indicated by element 202, to support a dual configuration of two I / O components 122.

[0025] like Figure 3As shown, the I / O system 100 also includes a base expansion component 204 (e.g., a base expansion module or "BEM") that is coupled to the rail or plate 116 and can be used to facilitate the addition of one or more additional I / O groups 118 to the I / O system 100. Thus, the base expansion component 204 can be configured with one or more connectors for communicatively coupling one or more additional I / O groups 118 to the I / O group 118 coupled to the rail or plate 116.

[0026] To reduce costs, owners of industrial automation systems can attempt to use components in their industrial automation systems that are procured from un-authorized sources. Such components can be counterfeit components, stolen components, cloned components, refurbished components made from one or more retired or previously used components, components that have been maliciously (e.g., with malware) modified, or modified in an attempt to improve or otherwise modify the performance of the component. Such components can be obtained at a second-hand market, from un-authorized distributors, at a gray market, etc. For components that run firmware and / or have a microcontroller or microprocessor, an authentication certificate can be used in conjunction with the firmware, microcontroller, and / or microprocessor to perform an authentication process that authenticates the components used within the industrial automation system. However, for components that lack firmware, microcontrollers, and / or microprocessors, such a process can not be feasible. The presently disclosed technology includes equipping industrial automation components that lack firmware, microcontrollers, and / or microprocessors with a redundant secure memory device, such as a secure or capable secure electrically erasable programmable read-only memory (EEPROM), that stores identification information that can be read and used to authenticate the industrial automation component. Although the term EEPROM is used hereinafter, it should be understood that whenever the term EEPROM is used, the associated component can be any secure memory device. For example, in the present embodiment, the network adapter base 106, the I / O base 120, the terminal block 124, and the base expansion component 204 can each be equipped with a pair of single-wire or single-pin EEPROMs that store identification information that is read by the bus interface component or backplane switch 134 upon command, at start-up, at shut-down, when a component is installed, when a component is removed, etc., to authenticate the network adapter base 106, the I / O base 120, the terminal block 124, and / or the base expansion component 204. In some embodiments, an encrypted token or secret string is stored on the EEPROM along with the identification information and used to verify the identification information stored on the EEPROM.

[0027] Figure 4is a schematic diagram of a network adapter 102 utilizing a "rail master base" style network adapter base 106. As shown, the network adapter base 106 includes a pair of redundant EEPROMs 206 (e.g., EEPROM 0 and EEPROM 1) communicatively coupled to the backplane switch 134. As previously described, the EEPROMs 206 can be single pin or single wire EEPROMs 206 such that all data stored on the EEPROMs 206 can be read by the backplane switch 134 via a single wire or pin, thereby leaving other pins of the backplane switch 134 available for connection to other components. For example, the EEPROMs 206 can store identification data including, for example, vendor ID, device type, product code, version, serial number, product name, catalog number, date of manufacture, warranty number, etc. In some embodiments, the data stored on the EEPROMs 206 can be encrypted, while in other embodiments, the data stored on the EEPROMs 206 can not be encrypted. Thus, when the network adapter base 106 equipped with a pair of redundant EEPROMs 206 is installed on a rail or board 116, the network adapter base 106 is communicatively coupled to one or more backplane switches 134. Thus, the one or more backplane switches 134 are communicatively coupled to the wiring or pins of the EEPROMs 206 and can read the identification information and token from the EEPROMs 206 and authenticate the network adapter base 106. Having a pair of redundant EEPROMs 206 provides the system with higher fault tolerance such that if one of the EEPROMs 206 fails, the backplane switch 134 can still read the identification information from the remaining EEPROM 206 and authenticate the network adapter base 106. Once the network adapter base 106 is authenticated, the I / O system 100 can utilize the network adapter base 106 to function as planned. However, if the network adapter base 106 is not authenticated, the I / O system 100 can refuse to function with the network adapter base 106, can display a warning, can notify someone or some party (e.g., a manager, supervisor, compliance officer, manufacturer, distributor, etc.) that an authorized device was installed, the I / O system 100 can be disabled for a period of time, etc.

[0028] As Figure 4As shown, the terminal block 124 can also be equipped with an EEPROM 206. In installing the network adapter 102, because the terminal block 124 is not directly connected to the backplane switch 134, and thus the backplane switch 134 is not directly communicatively coupled to the EEPROM 206 of the terminal block 124, the network adapter component 108 can act as an intermediary component and read the identification information and / or token from the EEPROM 206, which can then pass the identification information and / or token to the backplane switch 134 for authentication. As with the authentication process described above for the network adapter base 106, if the terminal block 124 is authenticated, the I / O system 100 can utilize the terminal block 124 as planned. However, if the terminal block 124 is not authenticated, the I / O system 100 can refuse to utilize the terminal block 124, can display a warning, can notify someone or some party (e.g., a manager, supervisor, compliance officer, manufacturer, distributor, etc.) that an unauthorized device was installed, the I / O system 100 can be completely or partially disabled for a period of time, etc.

[0029] In the present embodiment, the identification information and token stored on the EEPROM 206 can be placed on the EEPROM 206 by the manufacturer of the respective device prior to shipment of the device. However, embodiments are also contemplated in which the identification information and / or token is stored on the EEPROM 206 by a distributor, retailer, service provider, customer, or combination thereof.

[0030] Figure 5 is a schematic diagram of an I / O bank 118 utilizing a "four I / O base" style I / O base 120. As shown, the I / O base 120 includes a pair of redundant EEPROMs 206 (e.g., EEPROM 0 and EEPROM 1) that are in communication with the backplane switch 134 via the network adapter 102. As shown, the I / O base 120 includes a pair of I / O modules 122 (e.g., I / O module 0 and I / O module 1) that are in communication with the backplane switch 134 via the network adapter 102. As shown, the I / O base 120 includes a pair of terminal blocks 124 (e.g., terminal block 0 and terminal block 1) that are in communication with the backplane switch 134 via the network adapter 102. Figure 5The EEPROM 206 is represented by a single block 206 that includes a "0" representing EEPROM 0 and a "1" representing EEPROM 1. The EEPROM 206 is communicatively coupled to the backplane switch 134. As previously described, the EEPROM 206 can be a single pin or single wire EEPROM 206 such that all data stored on the EEPROM 206 can be read by the backplane switch 134 via a single wire or pin. The EEPROM 206 can store identification data such as, for example, a vendor ID, a device type, a product code, a version, a serial number, a product name, a catalog number, a manufacture date, a warranty number, etc. The data stored on the EEPROM 206 can or can not be encrypted. When the I / O base 120 equipped with a pair of redundant EEPROMs 206 is installed on a rail, the I / O base 120 is communicatively coupled to one or more backplane switches 134 such that the one or more backplane switches 134 are communicatively coupled to the wiring or pins of the EEPROMs 206. Thus, the backplane switch 134 reads the identification information and / or token from the EEPROM 206 and authenticates the I / O base 120. As described above, if one of the EEPROMs 206 fails, the backplane switch 134 can still read the identification information from the remaining EEPROM 206 and authenticate the I / O base 120. Once the I / O base 120 is authenticated, the I / O system 100 can utilize the network I / O base 120 to function as planned. However, if the I / O base 120 is not authenticated, the I / O system 100 can refuse to function with the I / O base 120, can display a warning, can notify someone or some party that an authorized device was installed, the I / O system 100 can be completely or partially disabled for a period of time, etc.

[0031] As Figure 5As shown, the terminal block 124 can also be equipped with an EEPROM 206. Because the terminal block 124 is not connected to the backplane switch 134, the backplane switch 134 is not communicatively coupled to the EEPROM 206 of the terminal block 124 when the I / O bank 118 is installed. Thus, the I / O component 122 can act as an intermediary component and read the identification information and / or token from the EEPROM 206, and then it can pass the identification information and / or token for authentication. For example, the identification information can be passed to the backplane switch 134, the network adapter 102, a software application, a computing device, or some combination thereof for authentication. As with the authentication process described above, if the terminal block 124 passes authentication, the I / O system 100 can function as planned with the terminal block 124. However, if the terminal block 124 fails authentication, the I / O system 100 can refuse to function with the terminal block 124, can display a warning, can notify someone or some party (e.g., a manager, supervisor, compliance officer, manufacturer, distributor, etc.) that an unauthorized device was installed, the I / O system 100 can be completely or partially disabled for a period of time, etc.

[0032] Figure 6 is a flowchart for authenticating an industrial automation component without using firmware, microprocessors, or microcontrollers coupled to the I / O system 100. As previously described, the network adapter base 106, the I / O base 120, the base expansion component 204, and / or the removable terminal block 124 can each be equipped with one or more EEPROMs 206 that store identification information. In some embodiments, an encrypted token or secret string is stored on the EEPROM with the identification information, and the encrypted token or secret string is used to validate the identification information stored on the EEPROM. For example, the EEPROM 206 can store identification data including, for example, a vendor ID, a device type, a product code, a version, a serial number, a product name, a catalog number, a manufacturing date, a warranty number, etc. In some embodiments, the identification information stored on the EEPROM 206 can be encrypted, while in other embodiments, the identification information stored on the EEPROM 206 can not be encrypted.

[0033] Because the network adapter chassis 106, the I / O chassis 120, and the chassis expansion component 204 are communicatively coupled to the backplane switch 134, the backplane switch 134 can read the identification information and / or tokens from the EEPROMs 206 of the network adapter chassis 106, the I / O chassis 120, and the chassis expansion component 204. The backplane switch 134 relays the identification of the network adapter chassis 106, the I / O chassis 120, and / or the chassis expansion component 204, as well as the identification of the backplane switch 134, to the network adapter 102, which communicates the identification information and / or tokens to a software application and / or a client device 300 via a wired network connection, a wireless network connection, and / or the Internet. The software application and / or the client device 300 can be located locally to the industrial automation system (e.g., a human-machine interface or HMI of the industrial automation system, or a nearby computing device in communication with the industrial automation system), or can be disposed remotely from the industrial automation system (e.g., in a data center, at a facility operated by a manufacturer, distributor, retailer, service provider, etc.). The software application and / or the client device 300 confirms the identification information and authenticates the network adapter chassis 106, the I / O chassis 120, and the chassis expansion component 204, and authenticates all devices, or determines that one or more of the network adapter chassis 106, the I / O chassis 120, and the chassis expansion component 204 fails authentication. The software application and / or the client device 300 relays the authentication status of each component back to the network adapter 102 and the backplane switch 134.

[0034] Because the removable terminal block 124 is not communicatively coupled to the backplane switch 134, the network adapter component 108 and / or the I / O component 122 read the identification information and / or tokens from the EEPROM 206 of the removable terminal block 124 and relay the identification of the removable terminal block 124, as well as the identification of the network adapter component 108 and / or the I / O component 122, directly to the software application and / or the client device 300 via a wired network connection, a wireless network connection, and / or the Internet. The software application and / or the client device 300 confirms the identification information and / or tokens and authenticates the removable terminal block 124 and authenticates all devices, or determines that one or more of the removable terminal block 124 fails authentication. The software application and / or the client device 300 relays the authentication status of each component back to the I / O component 122.

[0035] In some embodiments, providing the installed components' identification to the software application and / or client device 300 can facilitate more efficient remote inventory and / or asset management. For example, when the identification of the components of the industrial automation system are provided to the software application and / or client device 300 for authentication, the information received for the various components can be stored in a database or table. While the present disclosure relates to industrial automation components that lack firmware, microprocessors, and / or microcontrollers, it should be appreciated that the identification information and / or tokens can be provided by industrial automation components that are equipped with firmware, microprocessors, and / or microcontrollers. Thus, the software can create a model of the industrial automation system and its components and maintain the model over time. Further, the received information can be used to compare the model of the industrial automation system to the physical industrial automation system to verify the configuration (e.g., single vs. dual configuration for I / O components and removable terminal blocks, etc.). Along these lines, the received information and / or model can be used to suggest adjustments to the configuration, settings, parameters, etc. to improve the way the industrial automation system works. For example, the information can be used to suggest updating or automatically updating SerDes (Serial Deserializer) parameters (e.g., pre-emphasis, amplitude, etc.) based on the type of base being used and whether a base extension component is being used. Similarly, when problems arise, such data can be used during the resolution of the problem for developing maintenance / service schedules, assisting with setup, installation, and configuration, etc. For example, the data can be used to determine whether various industrial automation components are installed correctly and, if not, one or more actions that can be taken to install the incorrectly installed industrial automation components correctly. Further, the data can be sent to manufacturers, distributors, service providers, managers, supervisors, or other interested parties to provide a better understanding of the way the industrial automation components are being used, the way the industrial automation system is implemented, the way the industrial automation components work, and other valuable information.

[0036] Figure 7is a flowchart of a process 400 for authenticating an industrial automation component. In particular, the process 400 can be used to authenticate an industrial automation component that lacks firmware, a microprocessor, and / or a microcontroller and is installed in an I / O system of an industrial automation system. Such components can include, for example, a network adapter base, an I / O base, a base expansion component, a removable terminal block, etc. At block 402, an indication is received that a component has been installed and / or powered on. As previously discussed, the component can be equipped with one or more one-wire or one-pin EEPROMs that store identification information (e.g., vendor ID, device type, product code, version, serial number, product name, catalog number, date of manufacture, warranty number, etc.). In some embodiments, an encrypted token or secret string can also be stored on the EEPROM and used to verify the identification information. Although the present embodiment is directed to components that lack firmware, a microprocessor, and / or a microcontroller of an I / O system of an industrial automation system, it should be understood that similar techniques can be used for other components that lack firmware, a microprocessor, and / or a microcontroller in other parts of an industrial automation system.

[0037] At block 404, the identification information and / or token is read from the first EEPROM. As previously discussed, the EEPROM can be a one-pin or one-wire EEPROM such that all data stored on the EEPROM can be read via a single wire or pin, leaving other pins of the component available for connection to other components. If the first EEPROM is part of a network adapter base, an I / O base, and / or a base expansion component, the first EEPROM can be read by a backplane switch of the I / O system. However, if the first EEPROM is part of a removable terminal block, the first EEPROM can be read by an I / O component of the I / O system.

[0038] At box 406, identification information and / or a token are read from the second EEPROM. Similar to the first EEPROM, if the second EEPROM is part of a network adapter base, I / O base, and / or base extension, it can be read by a backplane switch of the I / O system; if it is part of a removable terminal block, it can be read by an I / O component of the I / O system. As previously discussed, using two EEPROMs provides greater fault tolerance, ensuring that if one EEPROM fails, identification information can still be read from the remaining EEPROMs to authenticate the component. In some embodiments, as an initial step in authenticating the component, data read from multiple EEPROMs can be compared. However, it should be understood that implementations of industrial automation components with a single EEPROM or two or more EEPROMs are envisioned. For example, in some embodiments, industrial automation components may be equipped with 3, 4, 5, 6, 7, 8, 9, 10, or more EEPROMs. Therefore, box 406 can be removed or additional boxes added based on the number of EEPROMs used.

[0039] At box 408, cryptographic operations can be performed. For example, if the identification information and / or token stored on the EEPROM are encrypted, the cryptographic operations can be used to decrypt information read from the EEPROM. For example, asymmetric cryptography can be used to encrypt and / or decrypt the identification information and / or token on the EEPROM. For example, the identification information can be encrypted using a public key. In such an implementation, the identification information can be decrypted using a provided private key. Furthermore, in some implementations, the encrypted identification information can be read from the EEPROM, decrypted, and then re-encrypted before being transmitted for authentication.

[0040] At box 410, identification information and / or tokens read from one or more EEPROMs can be transmitted to software applications and / or client devices for authentication. For example, as per [reference to...] Figure 6If described, the one or more EEPROMs can be read by the backplane switch of the I / O system, then transmitted to the network adapter, which passes the identification information and / or token to the software application and / or client device via a wired network connection, a wireless network connection, and / or the Internet. However, if the industrial automation component is a removable terminal block, the one or more EEPROMs can be read by the I / O component of the I / O system and passed directly to the software application and / or client device via a wired network connection, a wireless network connection, and / or the Internet. The software application and / or client device determines whether the identification information and / or token read from the plurality of EEPROMs match and checks the identification information against its own records to authenticate the industrial automation component. In some embodiments, a token or secret string stored on the EEPROM along with the identification information is used to validate the identification information stored on the EEPROM. In some embodiments, the software application and / or client device can check to determine whether the provided identification information and / or token match known information for a given class of product. That is, if the identification information is trustworthy and there is nothing suspicious about the identification information (e.g., mismatched configuration, serial number, etc.), the industrial automation component is authenticated. However, in other embodiments, the software application and / or client device can tie the identification information to a specific product or instantiation of a product before authenticating the industrial automation component. In yet other embodiments, the identification information can include or be stored with a certificate to verify the authenticity of the industrial automation component. Thus, the authentication process performed by the software application and / or client device can be any process from a range of authentication processes that encompass a range of strictness. In some embodiments, the process used can be selected and / or customized by the customer, manufacturer, distributor, service provider, etc. In other embodiments, the authentication can be performed by the I / O system (e.g., via the network adapter) without the need to transmit the identification information outside of the I / O system.

[0041] At block 412, the I / O system receives an indication from the software application and / or client device indicating whether the industrial automation component passed authentication. Once the component has passed authentication, the I / O system can utilize the component to work as planned. However, if the component did not pass authentication, the I / O system can refuse to utilize the component to work, can display a warning notification, can notify someone or some party (e.g., a manager, supervisor, compliance officer, manufacturer, distributor, etc.) that an unauthorized device was installed, the I / O system can be completely or partially disabled for a period of time, etc.

[0042] The disclosed technology includes components of input / output (I / O) systems of industrial automation systems that lack firmware, microprocessors, and microcontrollers but have electrically erasable programmable read-only memories (EEPROMs) that store identification information. For example, such components can include network adapter bases, I / O bases, base expander components, terminal blocks, and other industrial automation components. When such components are connected to an I / O system, or upon power-up, existing devices of the I / O system such as backplane switches and / or I / O components can be configured to read the identification information from the EEPROMs to authenticate the components. In some implementations, the identification information stored on the EEPROMs can be encrypted, in which case reading the identification information from the EEPROMs can involve a cryptographic operation to decrypt the identification information. Further, in some implementations, the identification information can be provided to a software application or client device to verify the identity of the components. If the components pass authentication, they can be used normally. However, if the components fail authentication, a warning message / notification can be generated, and / or aspects of the industrial automation system can be disabled. The identification information can also be used to build a model of the industrial automation system to suggest modifications to the setup, provide installation and / or setup instructions, provide guidance to solve problems, confirm configurations, etc. Further, the identification information can be used for remote inventory and / or asset management.

[0043] While only certain features of the disclosure have been illustrated and described, many modifications and changes will occur to those skilled in the art. Therefore, it is to be understood that the application herein disclosed is intended to cover all such modifications and changes as fall within the true spirit of the embodiments described herein.

[0044] The technology presented and claimed herein was made available to the public, in particular, the specific exemplification of subject matter and applications hereof, which is set forth in the remainder of the patent document are presented for purposes of illustration and description. They are not intended to exhaustively categorize every possible implementation and configuration of this technology.

Claims

1. An input / output (I / O) system of an industrial automation system, comprising: a rail or a board; a first backplane switch coupled to the rail or the board; a network adapter base coupled to the first backplane switch, wherein the network adapter base includes a first pair of electrically erasable programmable read-only memories (EEPROMs), wherein each EEPROM of the first pair of EEPROMs stores first data identifying the network adapter base, wherein the first backplane switch is configured to read the first data from at least one EEPROM of the first pair of EEPROMs to authenticate the network adapter base; a second backplane switch coupled to the rail, wherein the second backplane switch is arranged adjacent to the first backplane switch; and an I / O group, comprising: an I / O base coupled to the second backplane switch, wherein the I / O base includes a second pair of EEPROMs, wherein each EEPROM of the second pair of EEPROMs stores second data identifying the I / O base, wherein the second backplane switch is configured to read the second data from at least one EEPROM of the second pair of EEPROMs to authenticate the I / O base; an I / O component coupled to the I / O base and configured to perform an industrial automation input / output function associated with a component of the industrial automation system; and a terminal block coupled to the I / O base and configured to communicatively couple to a component of the industrial automation system, wherein the terminal block includes a third pair of EEPROMs, wherein each EEPROM of the third pair of EEPROMs stores third data identifying the terminal block, wherein the I / O component is configured to read the third data from at least one EEPROM of the third pair of EEPROMs to authenticate the terminal block, wherein the network adapter base, the I / O base, and the terminal block each lack a processor and a microcontroller and do not run firmware.

2. The I / O system of claim 1, comprising: a third backplane switch coupled to the rail, wherein the third backplane switch is arranged adjacent to the second backplane switch; and a second I / O group, comprising: a second I / O base coupled to the third backplane switch, wherein the second I / O base lacks a processor and a microcontroller and does not run firmware, wherein the second I / O base includes a fourth pair of EEPROMs, wherein each EEPROM of the fourth pair of EEPROMs stores fourth data identifying the second I / O base, wherein the third backplane switch is configured to read the fourth data from at least one EEPROM of the fourth pair of EEPROMs to authenticate the second I / O base; a second I / O component coupled to the second I / O base and configured to perform a second industrial automation input / output function associated with a second component of the industrial automation system; and a second terminal block coupled to the second I / O base and configured to communicatively couple to a second component of the industrial automation system, wherein the second terminal block lacks a processor and a microcontroller and does not run firmware, wherein the second terminal block includes a fifth pair of EEPROMs, wherein each EEPROM of the fifth pair of EEPROMs stores fifth data identifying the second terminal block, wherein the second I / O component is configured to read the fifth data from at least one EEPROM of the fifth pair of EEPROMs to authenticate the second terminal block.

3. The I / O system of claim 2, wherein, the network adapter base includes a sixth pair of EEPROMs, wherein each EEPROM of the sixth pair of EEPROMs stores the first data identifying the network adapter base, wherein the second backplane switch is configured to read the first data from at least one EEPROM of the sixth pair of EEPROMs to authenticate the network adapter base.

4. The I / O system of claim 3, wherein, the I / O base includes a seventh pair of EEPROMs, wherein each EEPROM of the seventh pair of EEPROMs stores the second data identifying the I / O base, wherein the second backplane switch is configured to read the second data from at least one EEPROM of the seventh pair of EEPROMs to authenticate the I / O base.

5. The I / O system of claim 4, comprising: a fourth backplane switch coupled to the rail, wherein the fourth backplane switch is arranged adjacent to the third backplane switch; and a base expander component coupled to the fourth backplane switch and configured to receive an additional I / O group, wherein the base expander component lacks a processor and a microcontroller and does not run firmware, wherein the base expander component includes an eighth pair of EEPROMs, wherein each EEPROM of the eighth pair of EEPROMs stores eighth data identifying the base expander component, wherein the fourth backplane switch is configured to read the eighth data from at least one EEPROM of the eighth pair of EEPROMs to authenticate the base expander component.

6. The I / O system of claim 1, wherein, the network adapter base is part of a rail master base, and wherein the I / O group includes four I / O bases.

Citation Information

Patent Citations

  • Authenticated backplane access

    CN110083129A

  • System and method for authentication for transceivers

    US20150039894A1