Control system for a technical facility and method for removing one or more certificates
By implementing certificate services in the control system of technical facilities and checking and removing unnecessary certificates in certificate memory, the problem of overfilling and searching in certificate management is solved, and the efficient utilization and performance improvement of certificate memory is achieved.
Patent Information
- Application Number
- CN202211329066.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-10-29
- Filing Date
- 2022-10-27
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2042-10-27
AI Technical Summary
In the control system of prior art facilities, certificate management has problems of overfilling and inefficient search efficiency, resulting in performance damage and unnecessary occupation of storage space.
By implementing certificate service on components of the control system, check whether there are multiple certificates in the certificate memory that are different from each other's valid time periods, and initiate the removal of the earliest ending certificate, ensuring that only the latest ending certificate is retained.
It realizes that there is only a unique special certificate in the certificate memory of the facility components, improves the efficiency and storage utilization of certificate management, and avoids performance damage and excessive consumption of storage space.
Smart Images

Figure CN116074010B_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a control system for a technical installation, in particular a process or production installation. The invention also relates to a method for removing one or more certificates. Furthermore, the invention relates to the use of a control system for operating a technical installation. Background Art
[0002] Due to increasing protection requirements (through the increasing use of open IT standards and protocols) and the requirements of IEC 62443 as the leading industrial security standard, communication connections in control systems of technical installations must increasingly be secured, i.e. adequately protected against unauthorized access.
[0003] Adequate protection can include, in particular (depending on the results of a so-called threat and risk analysis (TRA)), encryption and / or authentication of the transmitted data. Corresponding encryption and authentication mechanisms are usually components of secure communication protocols (e.g., TLS, OPC UA, for example). The use of secure communication protocols presupposes that the communication participants have digital certificates.
[0004] For example, certificates used in an operating environment (i.e., for example, an industrial plant) for secure communication or user authentication are often referred to as so-called "operational certificates" (OC in English). For security reasons, it is recommended to use a dedicated operational certificate for each communication protocol used. This means that if an installation component uses, for example, OPC UA for securing one communication relationship and TLS for securing another communication relationship, the component requires an OPC UA certificate and a TLS certificate (for TLS server or TLS client authentication) in each case. If the number of installation components and thus the number of required operational certificates is small, the certificates can be manually imported into the installation components.
[0005] As the number of plant components involved in secure communication relationships and requiring multiple certificates increases, it is meaningful to automate the issuance of operation certificates (based on certificate requests (CR) generated by the plant components) and the distribution of the issued certificates to the components. Such automated certificate management usually requires a so-called public key infrastructure (PKI), which should exist in the corresponding operating environment (e.g. industrial plant).
[0006] Therefore, in order to enable the facility component to optimally "understand" the components of the public key infrastructure used, a common certificate management protocol is always implemented in the component, i.e., for example, the "Certificate Management Protocol (CMP)" according to RFC 4210 or according to the "Lightweight CMP Profile". The use of such a protocol makes it possible to distinguish various scenarios (i.e., for example, an initial request for an operating certificate for a specific purpose or a request for an update of an already existing operating certificate for a specific purpose). In addition, such a protocol is suitable for requesting different types of certificates, since in most cases it is recommended that, before requesting an application-specific operating certificate, a facility component is configured with a facility-bound client certificate (Customer Device Certificate, abbreviated: CDC), which binds the component to the customer facility (such as an employee certificate binds the employee to the enterprise), and the client certificate is then used as the basis for requesting an operating certificate.
[0007] Certificates and the associated private keys should be updated regularly (e.g. every two years) according to current assumptions / recommendations (e.g. from NIST). In the context of automated certificate management, this means that the installation component requests an update from the certificate authority (CA) that issued the certificate to be updated, e.g. by transmitting the certificate request to the certificate authority (RA). To this end, the installation component should be able to check whether the current time is between the times "valid from" and "valid until" listed in the certificate.
[0008] Due to possible connection problems and the risk of timeouts, certificate renewal is usually requested in advance (e.g., a few weeks before the certificate expires) or performed manually by the user (via an administrative user interface). The result of a certificate renewal is represented by a certificate, which is usually distinguished from the original certificate by a different public key and / or a different validity period. The basic certificate content (in particular the values of the certificate attributes "Applicant", "Issuer", "Serial Number", "Key Usage Purpose", "Extended Key Usage Purpose") remains unchanged.
[0009] The certificates are usually stored in the certificate memory (Certificate Store in English) of the corresponding installation component, more precisely in the subdirectory "Own". Therefore, after a successful update, there are at least two (almost) identical and overlapping certificates in the "Own" directory, which can be used for the same purpose. In the case of repeated manual initiation of certificate updates by the user for test purposes, or in the case that an installation component does not obtain the requested certificate within a preconfigured time period due to technical problems (such as connection problems) and thus repeatedly requests an update (possibly multiple times), it is even possible to store multiple identical, overlapping certificates under "Own", which are distinguished from each other only by different validity periods and different public keys.
[0010] This can have a disadvantageous effect as described below: If a plant component searches its certificate memory (under "Own") for a certificate for a specific purpose (e.g. "Key Usage" or "Extended Key Usage"), for example to sign data packets that are to be transmitted to other plant components or to authenticate itself relative to other plant components, the plant component finds more than one certificate that matches this specific purpose. The search for this certificate must or can take a lot of time and impair the performance of the plant component. In addition, the certificate memory of the plant component is thus unnecessarily overfilled. It must be taken into account that most Industrial Internet of Things devices (e.g. so-called industrial edge devices) have very limited storage space. For this reason in particular, only the necessary certificates should be stored in the certificate memory of such a device.
[0011] Furthermore, it is often mistakenly assumed that the process for renewing a certificate also includes or involves the revocation of an existing certificate by default. However, this is usually not the case. For example, the so-called Certificate Management Protocol (CMP) according to RFC 4210 defines two different message or request types for requesting a certificate renewal or certificate revocation (Key Update Request, KUR, or Revocation Request, RR) together with the associated response types (Key Update Response, KUP, or Revocation Response, RP), which are not in direct relation to one another. Revocation requests are also not explicitly provided in the context of certificate management using the so-called OPC UA Global Discovery Server (GDS) according to the OPC UA specification.
[0012] If the procedure for updating certificates includes by default the immediate revocation of existing certificates, this has the effect that an existing certificate, for which an installation component has requested an update, is immediately revoked after the issuance of a "successor" by the responsible issuing certificate authority (issuing CA), i.e. is set to the certificate revocation list (certificate revocation list, CRL) of the issuing CA. If the "successor" is therefore delivered to the relevant installation component (usually via a registration authority (RA)) with a certain delay, as is often the case in industrial environments, it can therefore happen that the certificate stored in the certificate memory of the relevant installation component is already invalid (because it is listed on the CRL of the issuing CA), but the installation component does not yet have the updated certificate.
[0013] As a result, a component can "unknowingly" use a revoked and therefore no longer valid certificate in the context of secure communication, which is "noticed" by its communication partner during the revocation status check in the context of certificate verification. The communication partner can therefore reject the communication process, which can lead to a communication interruption and thus endanger the normal operation and availability of the industrial facility.
[0014] EP 3 258 662 A1 discloses a method for registering an intelligent electrical device with a certification body.
[0015] US 5 745 574 A discloses a security infrastructure having a plurality of certification authorities. Summary of the invention
[0016] The invention is based on the object of specifying a control system for a technical installation which enables improved certificate management for components of the technical installation.
[0017] The object is achieved by a control system for a technical installation, in particular a process or production installation, having the features of the invention. The object is also achieved by a method for removing one or more certificates from a certificate memory of a component of a control system for an installation component, in particular a production or process installation, having the features of the invention. The object is also achieved by the use of the control system according to the invention. Advantageous developments emerge from the various embodiments.
[0018] According to the invention, a control system for a technical installation has at least one component on which a certificate service is computer-implemented, wherein the certificate service involves a method for checking a certificate memory associated with the component or other components: whether two or more certificates are stored in the certificate memory, which certificates each differ from one another only in terms of their validity period, and in the case where such two or more certificates are determined during the check, initiating the revocation and removal of one or more certificates whose validity period expires earliest from the certificate memory, so that only the certificate with the validity period that expires latest remains stored in the certificate memory.
[0019] A technical installation can be an installation from the process industry, for example an installation from the chemical, pharmaceutical, petrochemical industry, or an installation from the food and beverage industry. This also includes any installation from the production industry, in which, for example, all types of vehicles or articles are produced. A technical installation suitable for carrying out the method according to the invention can also come from the field of energy production. Wind turbines, solar installations or power plants for generating energy are likewise included in the term "technical installation".
[0020] In this context, a control system is understood to be a computer-aided technical facility that includes functions for displaying, operating and controlling a technical manufacturing or production facility. A control system can also include sensors for determining measured values and various actuators. In addition, a control system can include so-called process- or production-related components for driving actuators or sensors. In addition, a control system can have, in particular, mechanisms for visualizing technical facilities and for engineering design. The term control system also includes other computing units for complex regulation and systems for data storage and processing.
[0021] A certificate is understood to be a digital data set that confirms certain properties, in this case of a machine, a device, an application, etc. The authenticity and integrity of a certificate can usually be verified by means of cryptographic methods.
[0022] In principle, the certificate service can be implemented on every component of the control system that is designed for this purpose. The certificate service is designed not only to monitor the certificate memory of the component on which the certificate service is implemented, but rather to monitor every arbitrary component of the control system if it is associated with a certificate memory. The certificate memory can be implemented directly on the respective component or the respective component can be associated with a certificate memory located on another component.
[0023] The certificate service can consist of multiple sub-services, which can be implemented on a single component, but can also be implemented on different components of the control system. For example, the first sub-service of the certificate service can fulfill the function of checking the certificate memory, while the second sub-service initiates the revocation of the relevant certificate and the third sub-service initiates the removal of the certificate.
[0024] The control system according to the invention ensures in a particularly advantageous manner that at every arbitrary point in time there is a unique, dedicated, and exactly one certificate for a specific use purpose in the certificate memory of the facility component. As a result, it is not necessary to find the "best matching" certificate from a large number of identical certificates when necessary. The time required for the search is also superfluous. In addition, this helps to optimally utilize the certificate memory of the facility component and not overload it. The certificate service can be designed to store one or more certificates that have been revoked and removed from the certificate memory in an archive of the control system and / or in a cloud-based environment in order to achieve traceability of certificate revocation. In particular, in the context of audit trails, it is of interest to know which certificates have been removed from the certificate memory. Here, it is advantageously possible to additionally store information about the reasons, at which point in time, by which service, or from which certificate memory of which component the relevant certificate was removed.
[0025] In the scope of an advantageous improved form of the present invention, the certificate service is designed to initiate the removal of the certificate only when it confirms the revocation of the certificate. This ensures that the certificate is removed only when the certificate is proven to be invalid, that is, revoked. Here, the confirmation of the revocation of the certificate can represent an explicit revocation message from the certification authority responsible for the revocation. Here, the revocation message is sent directly from the certification authority to the certificate service that has requested the revocation. Alternatively or additionally, the confirmation of the revoked certificate can represent a revocation list, which is issued by the certification authority responsible for the revocation after the certificate is revoked, and the revocation list lists the revoked certificates and other certificates revoked by the certification authority. Here, the certificate service does not directly notify the revocation of the certificate, but indirectly notifies the revocation of the certificate via the distribution of the revocation list. The provision can be achieved in the following way: the revocation list is distributed in an appropriate manner and method or directly to the components of the control system or to a location (such as a revocation list distribution point, PKI agent, LRA or RA) that is regularly accessed to obtain / upload an updated revocation list.
[0026] The certification service is preferably designed to initiate the revocation of one or more certificates by making a revocation request directly to the certification authority responsible for certificate revocation. The certification service hereby automatically (i.e. independently of an external request) undertakes the revocation request. However, the certification service can also be designed to initiate the revocation of one or more certificates by a corresponding request to an operator of the control system. By confirming the revocation to the operator request, an additional intermediate step is used, which can ensure that the certificate revocation should also actually be carried out. This is an additional control routine, which can be necessary in specific cases (high safety relevance).
[0027] The component or components on which the certificate service or a subservice of the certificate service is implemented can be, for example, an engineering station server, an automation device, a field device, a programmable logic controller, a switch, a machine tool, an edge component, an operator station server or an operator station client.
[0028] At present, an "engineering station server" is understood to be a server that is designed to create, manage, archive and document various hardware and software projects for control systems of technical installations. With the help of special software design tools (engineering tool sets) and pre-made modules and plans, the interaction of control technology devices and devices of technical installations can be planned and managed with the help of an engineering station server. An example of this is the SIMATIC Management Server from Siemens.
[0029] At present, an "operator server" is understood to be a server that centrally detects and makes available to users the data of the operating and monitoring system and usually the alarms and measured value archives of the control system of the technical installation. The operator server usually establishes a communication connection with the automation system of the technical installation and forwards the data of the technical installation to so-called clients, which are used to operate and monitor the operation of the individual functional elements of the technical installation. The operator server can have a client function in order to access the data (archives, messages, tags, variables) of other operator servers.
[0030] Thus, the image of the technical facility operation on the operator station server can be combined with the variables of other operator station servers (server-server communication). The operator station server can be, but is not limited to, a SIMATIC PCS7 industrial workstation server of Siemens.
[0031] The automation device serves to realize automation and can be, for example, a programmable logic controller which represents a superordinate control function for a subordinate programmable logic controller.
[0032] The certification service is designed to classify the event as a security event and store a corresponding message in an archive of the control system and / or in a cloud-based environment, if two or more such certificates are detected during the check, or if there is an explicit revocation message from the certification authority responsible for the revocation, or if there is a revocation list issued after the revocation of the certificate, or in the case of the revocation of the certificate. The archive or cloud-based environment can be, for example, a so-called SIEM system (Security Information and Event Management), in which all security-related information / data of the technical installation are stored.
[0033] The object is also achieved by a method for removing one or more certificates from a certificate memory of a component of a control system for a technical installation, in particular a production or process installation, the method comprising:
[0034] a) a computer-implemented certificate service checks on a component of the control system or another component to determine whether two or more certificates are stored in the certificate memory, which certificates differ from one another only in terms of their validity period,
[0035] b) In the event that two or more such certificates are determined during the check, the certificate service initiates the revocation and removal of one or more certificates whose validity period expires earliest from the certificate memory, so that only the certificate with the latest validity period remains stored in the certificate memory.
[0036] The certification service can initiate the revocation of one or more certificates by submitting a revocation request directly to the certification authority responsible for revoking certificates.
[0037] Certificate Services initiates the removal of a certificate only if it confirms the revocation of the certificate.
[0038] The confirmation of certificate revocation can mean an explicit revocation message from the certification authority responsible for revoking the certificate or a revocation list issued by the certification authority responsible for revoking after the certificate is revoked, and the revocation list lists the revoked certificate and other certificates revoked by the certification authority.
[0039] The certification service can initiate the revocation of one or more certificates by making a revocation request directly to the certification authority responsible for certificate revocation or by a corresponding request to the operator of the control system.
[0040] Furthermore, the object is achieved by the use of a control system as described above for the operation of a technical installation, in particular a process or production installation. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The above characteristics, features and advantages of the present invention and the ways and methods of achieving them are explained in more detail below based on the description of the embodiments in conjunction with the accompanying drawings. The accompanying drawings show:
[0042] Figure 1 A sketch showing the principle of the method according to the invention according to the first aspect; and
[0043] Figure 2 A schematic diagram of the principle of the method according to the invention according to the second aspect is shown. DETAILED DESCRIPTION
[0044] exist Figure 1 Schematically shows a method according to the invention according to a first aspect. A component 1 has a certificate memory 2, which is part of a control system for a technical installation and is, for example, a control device, a switch, an operator station client or an edge device. A first certificate 3 is stored in the certificate memory. For example, the first certificate 3 can be a TLS server / client certificate or an OPC UA server / client certificate.
[0045] In a first step I, the operator of the technical installation applies for the renewal of the first certificate 3. The application for renewal of the first certificate 3 can also be made automatically by the component 1 itself (step I'). The renewal request can be submitted directly to the certification authority 4, which is responsible for issuing and revoking certificates in the technical installation. Figure 1 In , the operator directly sends the request to the certification authority 4. Component 1 sends its request to the registration authority 5, which forwards the update request to the certification authority 4 (after verifying the identity of component 1, which will not be discussed further here).
[0046] After checking the certificate update request, the certification authority 4 transmits the new second certificate 6 to the component 1. This is done either manually via an operator (step II) or automatically via the registration authority 5 (step II'). The second certificate 6 is stored in the certificate memory 2 of the component 1 (step III). The first certificate 3 and the second certificate are issued for the same component 1 for the same purpose and differ only in their validity period. Therefore, after step III, two certificates 3, 6 are present in the certificate memory 2, which certificates differ from each other only in their validity period.
[0047] The control system of the technical installation comprises a computer-implemented certificate service 7 (so-called "Certificate Overlap Watchdog"), which checks the certificate storage 2: whether two or more certificates 3, 6 are stored in the certificate storage 2, which certificates each differ from one another only in their validity period (step IV). In the present exemplary embodiment, there are two such certificates 3, 6. The certificate service 7 then immediately generates a message, in particular a security event message (for example "Certificate Overlap Detected" (step V)).
[0048] The certificate service 7 has a subservice 8, which initiates the revocation of the first certificate 2 based on the generation of the message (step VI). This can be done by automatically and directly submitting a revocation request for the first certificate 2 to the certification authority 4. The revocation request can be formed according to the "Internet X.509 Public Key Infrastructure Certificate Management Protocol (CMP)". Alternatively, a request to the operator of the control system can also be generated, which is presented to the operator in a visual manner, for example via an operator station client. The operator can thus manually initiate the revocation of the first certificate 2.
[0049] As soon as the revocation of the first certificate 3 has been verifiably completed (step VII), the subservice 8 of the certificate service 7 generates a message, in particular a security event message (e.g. "Revocation_Completed"). The certification authority 4 either provides this confirmation directly via a response to the revocation request (a so-called "revocation response"). Alternatively, the certificate service 7 obtains the confirmation indirectly via an updated revocation list 9, which the certification authority 4 generates and which is distributed in the control system and is also stored in the certificate memory 2 of the component 1. The first certificate 3 is listed on the revocation list 9 as a revoked certificate.
[0050] The subservice 8 of the certificate service 7 then removes the first certificate 3 from the certificate memory 2 of the component 1 (step VIII). After removal, the first certificate 3 is archived in an archive of the control system or in a cloud-based environment in order to be available for a subsequent audit trail.
[0051] Figure 2 A further use of the control system according to the invention or of the certificate service 7 comprised therein is shown. The second certificate 6 and the updated revocation list 9 are also present in the certificate memory 2 of the component 1 .
[0052] Component 1 establishes a communication connection to another component 10 of the control system (step IX). Component 1 uses its new second certificate 6 to establish a secure communication connection (e.g., within the scope of a handshake process). According to the current security plan, second certificate 6 is stored in certificate memory 11 of other component 10 (step X). The old first certificate 3 is still located in certificate memory 11, which other component 10 obtained within the scope of the past communication establishment.
[0053] The certificate service 7 also monitors the certificate memory 11 of the other components 10 and recognizes two duplicate certificates 3, 6 which differ only in their validity period (step XI). Figure 1 According to the method described in , the certificate service 7 generates a message, in particular a security event message (step XII), which then removes the redundant first certificate 3 from the certificate storage 11 of the other component 10 (and archives it in an archive / in a cloud-based environment).
[0054] Although the present invention has been illustrated and described in detail by means of preferred embodiments, the present invention is not restricted to the disclosed examples and other variants can be derived therefrom by a person skilled in the art without departing from the scope of protection of the present invention.
Claims
1. A control system for a technical installation, the control system having at least one component, on one or more of which a certificate service (7) is implemented by computer, wherein: The certificate service (7) is designed to: A certificate memory (2, 11) associated with the component or another component is checked to determine whether two or more certificates are stored in the certificate memory (2, 11), the certificates differing from one another only in terms of the validity period of the certificates, and In the event that two or more of the certificates are detected during the check, a revocation and removal of one or more certificates whose validity period expires earliest from the certificate memory (2, 11) is initiated, so that only the certificate with the latest validity period remains stored in the certificate memory (2, 11).
2. The control system according to claim 1, wherein: The technical facility is a process or production facility.
3. The control system according to claim 1 or 2, wherein: The certificate service (7) is designed to store one or more certificates which have been revoked and removed from the certificate memory (2, 11) in an archive of the control system and / or in a cloud-based environment in order to enable traceability of certificate revocations.
4. The control system according to claim 1 or 2, wherein: The certificate service (7) is designed to initiate the removal of the certificate only when the certificate service (7) confirms the revocation of the certificate.
5. The control system according to claim 4, wherein: Acknowledgment of the revocation of a certificate represents an explicit revocation message from the certification authority (4) responsible for the revocation.
6. The control system according to claim 4, wherein: The confirmation of the revocation of the certificate is expressed as a revocation list (9), which is issued by the certification authority (4) responsible for revocation after the revocation of the certificate and which lists the revoked certificate and other certificates revoked by the certification authority (4).
7. The control system according to claim 1 or 2, wherein: The certificate service (7) is designed to initiate the revocation of one or more certificates by submitting a revocation request directly to the certification authority (4) responsible for the revocation of certificates.
8. The control system according to claim 1 or 2, wherein: The certificate service (7) is designed to initiate the revocation of one or more certificates by a corresponding request to an operator of the control system.
9. The control system according to claim 1 or 2, wherein: The components represent automation devices, field devices, programmable logic controllers, switches, machine tools, edge components, operator station servers or operator station clients.
10. The control system according to claim 1 or 2, wherein: The certificate service (7) is designed to: in the event that two or more certificates are detected during the check, or when there is an explicit revocation message from the certification authority (4) responsible for the revocation, or when there is a revocation list (9) issued after the revocation of the certificate, or when the certificate is revoked, classify the event as a security event and store a corresponding message in an archive of the control system and / or in a cloud-based environment.
11. A method for removing one or more certificates from a certificate memory (2, 11) of a component of a control system for a technical installation, the method comprising: a) checking, by means of a computer-implemented certificate service (7) on the component or another component of the control system, whether two or more certificates are stored in the certificate memory (2, 11), which certificates differ from one another only in terms of the certificate validity period, b) in the event that two or more certificates are determined during the check, the certificate service (7) initiates the revocation and removal from the certificate memory (2, 11) of one or more certificates whose validity period expires earliest, so that only the certificate with the latest validity period remains stored in the certificate memory (2, 11).
12. The method according to claim 11, wherein: The technical facility is a manufacturing or process facility.
13. The method according to claim 11 or 12, wherein: The certificate service (7) stores the revoked certificates removed from the certificate memory (2, 11) in an archive of the control system and / or in a cloud-based environment in order to enable traceability of certificate revocations.
14. The method according to claim 11 or 12, wherein: When the certificate service (7) confirms the revocation of the certificate, the certificate service (7) initiates the removal of the certificate.
15. The method according to claim 11 or 12, wherein: Acknowledgement of certificate revocation represents an explicit revocation message from the certification authority (4) responsible for revoking the certificate.
16. The method according to claim 11 or 12, wherein: The confirmation of the revocation of the certificate is expressed as a revocation list (9), which is issued by the certification authority (4) responsible for revocation after the revocation of the certificate and which lists the revoked certificate and other certificates revoked by the certification authority (4).
17. The method according to claim 11 or 12, wherein: The certificate service (7) initiates the revocation of one or more certificates by making a revocation request directly to the certification authority (4) responsible for the revocation of certificates.
18. The method according to claim 11 or 12, wherein: The certificate service (7) initiates the revocation of one or more certificates by a corresponding request to an operator of the control system.
19. The method according to claim 11 or 12, wherein: The certificate service (7) classifies the event as a security event and stores a corresponding message in an archive of the control system and / or in a cloud-based environment if two or more of the certificates are detected during the check, or if there is an explicit revocation message from the certification authority (4) responsible for revocation, or if there is a revocation list (9) issued after the revocation of the certificate, or when a certificate is revoked.
Citation Information
Patent Citations
Secure efficient registration of industrial intelligent electronic devices
EP3258662A1
Security infrastructure for electronic transactions
US5745574A
Certificate management method and certificate management device based on P2P (peer-to-peer)
CN102868709A
Vehicle Segment Certificate Management Using Short-Lived, Unlinked Certificate Schemes
US20080232595A1