Method, system, host for securely executing a control application
By using software containers and host-specific verification components to generate verification flags in industrial automation systems, and combining this with registration component verification certificates, the problem of complex control application configuration is solved, enabling a simple, low-cost, and fault-safe configuration process.
Patent Information
- Application Number
- CN202310331532.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-03-31
- Filing Date
- 2023-03-30
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2043-03-30
AI Technical Summary
In industrial automation systems, existing technologies struggle to achieve simple and fault-safe configuration of control applications, especially in the case of OPC UA server applications, where configuration is complex, error-prone, and requires a high degree of manual intervention.
By using a software container to provide the control application and utilizing a host-specific verification component to calculate verification flags, combined with the initial application certificate and registration component verification, a device configuration certificate and application authority certificate are generated, thus achieving an automated secure configuration process.
It enables simple, low-cost, and fault-safe configuration of control applications, reduces manual intervention, and improves the reliability and efficiency of the configuration process.
Smart Images

Figure CN116894235B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to methods and systems for securely executing control applications, as well as host systems, particularly those providing automation functions within industrial automation systems. The systems and host systems are configured to execute the methods according to the invention. Background Technology
[0002] Industrial automation systems typically comprise a large number of automated devices connected to the Internet via industrial communication networks, and are used to control or regulate facilities, machines, or equipment within the scope of production or process automation. Due to the time-critical framework of industrial automation systems, real-time communication protocols (such as PROFINET, PROFIBUS, real-time Ethernet, or Time-Sensitive Networking (TSN)) are primarily used for communication between automated devices. In particular, control services or applications are automatically and distributed according to load to currently available hosts or virtual machines within the industrial automation system.
[0003] WO 2020 / 182627 A1 describes a method for monitoring the integrity of an industrial cyber-physical system, wherein measurement data detected by various sensors of the cyber-physical system and / or control data determined for various actuators of the cyber-physical system are provided or intercepted. Furthermore, at least one measurement data association parameter is determined between the measurement data detected by the various sensors, and / or at least one control data association parameter is determined between the control data determined for the various actuators. The at least one measurement data association parameter is compared with a measurement data association reference, and / or the at least one control data association parameter is compared with a control data association reference. Based on the comparison, the integrity of the cyber-physical system to be monitored is evaluated.
[0004] An earlier European patent application, application number 21197157.7, relates to a method for creating a certificate for securely providing a service to a service recipient via a process control component within a process control environment. Here, at least one server component is associated with the service, formed by a process control component that can be loaded into and implemented within the process control environment. At least one proxy component, comprising a subnet of the process control environment, accepts requests from the service recipient. A central directory service component manages valid addressing information within the subnet for the server components' internal endpoint addresses and associated external endpoint addresses, and transmits this information to the proxy components. The server components register using their internal endpoint addresses. An internal directory service, obtaining the necessary information about the external and associated internal endpoint addresses from a local directory service, generates a certificate required for subsequent encrypted communication, the certificate having the determined associated external endpoint address, and transmits the certificate to the server components so that the service recipient can use the certificate to establish an encrypted connection to the server components.
[0005] A method for securely providing services via a central provider on a device, to be executed upon retrieval by a service recipient, is known from an earlier European patent application, application number 22152226.1. Here, at least one server component is associated with the service, the server component being formed by a process control component that can be loaded into and executed within a process control environment. A clearly identifiable, operable mechanism provides the service to the device. The service, upon provision, is accompanied by a unique service certificate assigned to the service mechanism, which is inextricably linked to and clearly identifies the service mechanism. Furthermore, an equally unique device certificate, associated with the service certificate, is generated and transmitted to the device. The device proves itself to the service using the device certificate, and the service verifies the device certificate using the service certificate. Thus, the device obtains authorization to transmit protected information from the application mechanism certificate, necessary for further execution of the service provision, to a reset.
[0006] Especially in the case of OPC UA server applications, there are user-side requirements that go beyond simply providing a connection between the client and server and verifying the trustworthiness of the control application. This verification should be implemented with low overhead and without additional expertise during construction and operation. Here, given the foreseeable future volume of control applications to be provided and configured, manageable complexity is crucial. Furthermore, according to current practices, a relatively high degree of manual configuration is still always required. This is time-consuming and error-prone. Summary of the Invention
[0007] The present invention aims to provide a method for securely executing a control application, the method enabling simple and fault-safe configuration of the control application, and to propose a device suitable for executing the method.
[0008] According to the invention, this objective is achieved by a method having the features described in claim 1, a system having the features described in claim 11, and a host having the features described in claim 12. Advantageous improvements are described in the dependent claims.
[0009] According to the method for securely executing control applications according to the invention, the control applications are provided by means of software-implemented containers, which can be loaded into and executed in a container runtime environment set on a host. The verification component of the respective host calculates verification flags based on host-specific characteristics and characteristics of the respective control applications. The initial application certificate and verification flags of the control application are transmitted to the registration component. The initial application certificate can be, in particular, an initial device identifier (IDevID) generated according to IEEE 802.1 AR.
[0010] The verification flag can be signed with low overhead, for example, by means of a signing key associated with the host's initial device certificate. Advantageously, the initial application certificate is securely provided either by the provider of the respective control application or through an application store. To meet high security requirements, the verification flag and the initial application certificate preferably each include a public identifier, via which the verification flag and the initial application certificate are linked to each other.
[0011] According to the present invention, the registration component verifies the verification flag and the initial application certificate. If the verification result is positive, the registration component creates a device configuration certificate and an application authority certificate and transmits them to the host. The link between the application authority certificate and the control application is authorized using the device configuration certificate. The execution authorization of the container providing the control application on the host is granted via the application authority certificate. In particular, the link between the application authority certificate and the control application enables the provisioning and / or configuration of the application authority certificate for the authorization function of the control application.
[0012] This invention enables the creation of device configuration certificates independently of the corresponding control application provider or through an app store. Therefore, a ticket generator on the provider or app store side is unnecessary. In particular, the provisioning and configuration process is significantly simplified so that control application providers and / or app store operators no longer need to prepare device configuration certificates and app agency certificates for a large number of possible application and device variants.
[0013] According to a preferred embodiment of the invention, the host verifies the registration component using a verification flag. This allows the registration component to compare the description included in the initial application certificate with the features calculated via the verification flag. Specifically, if the description included in the initial application certificate matches the compared features, the registration component confirms that the verification flag and the initial application certificate are valid. This enables valid and reliable verification of the verification flag and the initial application certificate.
[0014] The initial application certificate and / or application authority certificate can include, for example, licensing information that defines the scope of functionality of the control application. Therefore, the licensed functions of the control application can be enabled flexibly and tamper-proofly. Furthermore, the verification flag, device configuration certificate, or application authority certificate is preferably stored in the host's certificate storage. This enables a particularly reliable implementation of the invention.
[0015] The system configuration according to the invention is for executing the method corresponding to those previously stated and includes at least one host and a registration component. The host is designed to provide control applications via software-implemented containers, each capable of being loaded into and executed within a container runtime environment hosted on the host. Furthermore, the host includes a verification component designed to calculate verification flags based on host-specific characteristics and characteristics of the respective control application. The host is additionally designed to transmit the initial application certificate and verification flags of the control application to the registration component.
[0016] The registration component of the system according to the invention is designed to verify the verification flag and the initial application certificate, and, if the verification result is positive, to create a device configuration certificate and an application authority certificate and transmit them to the host. Furthermore, the host is additionally designed to authorize the link between the application authority certificate and the control application by means of the device configuration certificate, and to authorize the execution of the container providing the control application via the application authority certificate.
[0017] The host according to the invention is suitable for the aforementioned system and is designed to provide control applications by means of software-implemented containers, which can be loaded into and executed in a container runtime environment set on the host. The host includes a verification component designed to calculate verification flags via host-specific features and via features of the respective control applications.
[0018] The host according to the invention is also designed to transmit the initial application certificate and verification flag of the control application to the registration component. Furthermore, the host is additionally designed to authorize the link between the application authority certificate generated by the registration component and the control application by means of a device configuration certificate generated by the registration component, and to authorize the execution of the container providing the control application by means of the application authority certificate. Attached Figure Description
[0019] The invention will now be explained in more detail with reference to the accompanying drawings and an embodiment. The drawings show...
[0020] Appendix Figure 1 The system shown has multiple hosts, an app store, and registration components for providing control applications. Detailed Implementation
[0021] The system shown in the accompanying drawings includes multiple hosts 101-102, an application store 200, and a registration component 103. In the current embodiment, hosts 101-102 and registration component 103 are comprised of a subnet protected by a firewall system, which is associated with the industrial automation system. The protected subnet is connected to the application store 200 via a wide area network 300, which in particular provides internet communication connectivity.
[0022] In the current embodiment, host units 101-102 implement the functions of automation equipment, such as operation and monitoring stations, programmable logic controllers, RFID readers, or systems for machine image processing. In addition to host units 101-102 and registration unit 103, the protected subnet of the industrial automation system can also include network infrastructure devices such as switches or routers. These network infrastructure devices are specifically used to connect programmable logic controllers, input / output units (I / O modules), or operation and monitoring stations.
[0023] A programmable logic controller (PLC) may include, for example, a communication module, a central unit, and at least one input / output unit. The input / output unit is used to exchange control and measurement variables between the PLC and the machine or device controlled by the PLC. The central unit is particularly configured to derive appropriate control variables from the detected measurement variables. In principle, the input / output unit can also be configured as distributed peripheral modules located remotely from the PLC.
[0024] Hosts 101-102 are configured and designed to provide control applications 113, 123 via software containers, which can be loaded into and executed in container runtime environments 112, 122 installed on host operating systems 111, 121. Specifically, control applications 113, 123 implement functions of automated devices, such as control and monitoring functions, or other time-critical services, associated with machines or devices 110, 120 connected to hosts 101-102.
[0025] Application store 200 includes an image repository 210 for providing stored images 201 for software containers. In this way, the stored images 201 for software containers can be retrieved by a large number of users. Alternatively, the stored images 201 can also be provided directly through the provider of the corresponding control application. In principle, application store 200 can be configured as a storage and provisioning system capable of being read or written by a large number of users.
[0026] The software containers used to control applications 113 and 123 can be migrated from hosts 101 and 102 with container runtime environments 112 and 122 to another host 102 and 101 with container runtime environments 122 and 112, respectively, to execute there, or simultaneously execute on multiple hosts 102 and 101 with container runtime environments 122 and 112. The software containers are preferably configured and designed to run in isolation from other software containers or groups of containers, such as Pods, within their respective host operating systems 111 and 121 within their container runtime environments. Advantageously, the software containers use the kernel of the host operating system 111 and 121, respectively, along with other software containers running on their respective hosts 101 and 102. In principle, other microvirtualization designs, such as snapshots, can also be used instead of Docker containers for software containers.
[0027] In the current embodiment, container runtime environments 112 and 122 are container engines that create, delete, or link virtual resources. Here, in addition to software containers, virtual resources also include virtual communication networks and connections associated with those virtual communication networks. Specifically, container runtime environments 112 and 122 may include a Docker engine or Snap Core running on the respective automated devices 101-102.
[0028] To control the secure execution of applications, the corresponding hosts 101 and 102 are configured such that the verification components 114 and 124 of the ticket generators of the respective hosts 101 and 102 calculate tickets or verification flags 116 and 126 respectively, based on host-specific characteristics and characteristics of the corresponding control applications 113 and 123. Preferably, the verification flags 116 and 126 are signed using a signing key associated with the initial device certificate of the respective hosts 101 and 102.
[0029] By associating verification components 114 and 124 with the corresponding hosts 101 and 102, and not with the application store 200, the secure use of side-loaded applications is particularly simplified. Furthermore, the application store 200 is relieved of the burden of creating verification flags 116 and 126. Verification components 114 and 124 are retrieved after the installation of control applications 113 and 123, respectively, collecting the information required for creating verification flags 116 and 126. Verification flags 116 and 126 are preferably based on OPC Foundation Specification Part 21 in their composition, but may also differ from it.
[0030] The respective hosts 101 and 102 log in to the registration component 103 via a secure connection, such as a secure connection according to Part 21 of the OPC Foundation specification, using verification flags 116 and 126, and initiate the application software provisioning. For this purpose, the verification flags 116 and 126 of the respective control applications 113 and 123, and the initial application certificate 202, are transmitted to the registration component 103. Specifically, the respective hosts 101 and 102 verify themselves against the registration component 103 using verification flags 116 and 126.
[0031] In the current embodiment, the initial application certificate 202 is an initial device identifier (IDevID) generated according to IEEE 802.1AR provided by the application store 200. Alternatively, the initial application certificate 202 can also be provided by the provider of the respective control applications 113, 123. Verification flags 116, 126 and the initial application certificate 202 each include a public identifier, and the verification flags and the initial application certificate are linked to each other via said public identifier. Such a public identifier can be, for example, a product instance URI.
[0032] Registration component 103 verifies verification flags 116 and 126 and the initial application certificate 202. Here, registration component 103 compares the description included in the initial application certificate 202 with the features used to calculate verification flags 116 and 126. If the description included in the initial application certificate 202 matches the compared features, registration component 103 confirms that verification flags 116 and 126 and the initial application certificate 202 are valid. If the verification result is positive, registration component 103 creates a device configuration certificate 131 and an application authority certificate 132 and transmits them to the corresponding hosts 101 and 102.
[0033] The linking of application authority certificate 132 with the corresponding control applications 113, 123 is authorized by device configuration certificate 131. By linking application authority certificate 132 with the corresponding control applications 113, 123, the authentication function of control applications 113, 123 is provided or configured by application authority certificate 132. This allows the execution authorization of containers providing the corresponding control applications 113, 123 on the corresponding hosts 101, 102 to be granted via application authority certificate 132.
[0034] Application authority certificate 132 and device configuration certificate 131 are in a trust relationship with each other. Due to this trust relationship, the corresponding control applications 113, 123 trust registration component 103 or device configuration certificate 131 and allow the transfer or use of application authority certificate 132. Specifically, the manual establishment of authorization issued through registration component 103 is eliminated by means of authorization via device configuration certificate 131. The aforementioned trust relationship is based on the described provisioning process, wherein the initial application certificate 202 and verification flags 116, 126 are used for mutual authentication.
[0035] Verification flags 116, 126, device configuration certificate 131, and / or application authority certificate 132 are preferably stored in the certificate storage 115, 125 of the respective hosts 101, 102. In particular, the initial application certificate 202 or application authority certificate 132 may include licensing information that defines the functional scope of the respective control applications 113, 123.
Claims
1. A method for securely executing control applications, wherein, The control applications (113, 123) are provided using software-implemented containers, which are respectively capable of being loaded into and executed within container runtime environments (111, 112) set up on the host (101, 102). The corresponding verification components (114, 124) of the host calculate verification flags (116, 126) respectively via host-specific features and via features of the corresponding control application. The initial application certificate (202) of the control application and the verification flag are transmitted to the registration component (103). The registration component verifies the verification flag and the initial application certificate, and if the verification result is positive, the registration component creates a device configuration certificate (131) and an application authority certificate (132) and transmits the device configuration certificate and the application authority certificate to the host. The device configuration certificate authorizes the link between the application authority certificate and the control application. The application authority certificate authorizes the container providing the control application to perform operations on the host.
2. The method according to claim 1, in, The verification flags (116, 126) are signed using a signing key associated with the initial device certificate of the host (101, 102).
3. The method according to claim 1 or 2, in, The initial application certificate (202) is provided by the provider of the respective control application or by the application store (200).
4. The method according to claim 1 or 2, in, The verification flag and the initial application certificate each include a public identifier, and the verification flag and the initial application certificate are linked to each other via the public identifier.
5. The method according to claim 1 or 2, in, By linking the application authority certificate to the control application, the authentication function of the control application is supplied and / or the application authority certificate is configured.
6. The method according to claim 1 or 2, in, The host verifies the registered component using the verification flag, wherein the registered component is compared for consistency with the description included in the initial application certificate and the features used to calculate the verification flag.
7. The method according to claim 6, in, If the description included in the initial application certificate matches the characteristics being compared, the registration component confirms that the verification flag and the initial application certificate are valid.
8. The method according to claim 1 or 2, in, The verification flags (116, 126), the device configuration certificate (131), and / or the application authority certificate (132) are stored in the certificate storage (115, 125) of the host (101, 102).
9. The method according to claim 1 or 2, in, The initial application certificate (202) is an initial device identifier generated according to IEEE 802.1 AR.
10. The method according to claim 1 or 2, in, The initial application certificate (202) and / or the application authority certificate (132) include licensing information that limits the functionality of the control application (113, 123).
11. A system for performing the method according to any one of claims 1 to 10, wherein The system includes at least one host (101, 102) and a registration component (103). The host is designed to provide control applications (113, 123) via software-implemented containers, which can be loaded into and executed within container runtime environments (111, 112) set up on the host. The host includes verification components (114, 124) designed to calculate verification flags (116, 126) via host-specific features and via features of the corresponding control application. The host is additionally designed to transmit the initial application certificate (202) of the control application and the verification flag to the registration component. The registration component is designed to verify the verification flag and the initial application certificate, and if the verification result is positive, to create a device configuration certificate (131) and an application authority certificate (132) and transmit the device configuration certificate and the application authority certificate to the host. The host is additionally designed to authorize the link between the application authority certificate and the control application by means of the device configuration certificate, and to authorize the execution of the container providing the control application on the host by means of the application authority certificate.
12. A host for use in the system according to claim 11, wherein The hosts (101, 102) are designed to provide control applications (113, 123) via software-implemented containers, which are respectively capable of being loaded into and executed within container runtime environments (111, 112) set up on the hosts. The host includes verification components (114, 124) designed to calculate verification flags (116, 126) via host-specific features and via features of the corresponding control application. The host is additionally designed to transmit the initial application certificate (202) of the control application and the verification flag to the registration component (103). The host is additionally designed to authorize the linking of the application authority certificate (132) generated by the registration component with the control application by means of the device configuration certificate (131) generated by the registration component, and to authorize the execution of the container providing the control application by means of the application authority certificate.
Citation Information
Patent Citations
Method and system for monitoring the integrity of an automation system
WO2020182627A1
Self-checking method and device based on local certificate, equipment and storage medium
CN110300096A
Trusted application processing method based on multiple containers and related equipment
CN110532766A