Security technology module

By integrating module lists and OPC-UA servers in the control system, the equipment in the technical modules is automatically identified and managed, and the complexity of device identity and certificate management is solved, improving the security and reliability of the facility.

CN120266433APending Publication Date: 2025-07-04SIEMENS AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380081014.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-06-21
Filing Date
2023-11-22
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, the identity and originality of the equipment in the technical module cannot be effectively verified, there is a risk that the equipment will be manipulated or replaced, and the certificate update and management are complex, which affects the safety and reliability of the facility.

Method used

Through a computer-implemented module list that integrates technical modules in the control system, device information is saved to achieve identity and originality checks, interact with OPC-UA server, automatically evaluate the validity of the certificate, and manage the certificate through the certification authority to ensure the legality and security of the device identity.

Benefits of technology

It realizes automatic identification and security management of equipment in the technical module, reduces the risk of equipment being manipulated, simplifies the certificate update process, and improves the safety and reliability of the facilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120266433A_ABST
    Figure CN120266433A_ABST
Patent Text Reader

Abstract

The invention relates to a method for generating operator control and monitoring and / or automation by means of a control system (16) for a technical installation, in particular a processing or process installation, comprising: a) integrating a technical module (1) into the control system (16), the technical module (1) having a plurality of technical installations (2, 3, 4, 5a, 5b, 5c, 6), the technical installations (2, 3, 4, 5a, 5b, 5c, 6) being integrated into the control system (16), the technical installations (2, 3, 4, 5a, 5b, 5c, 6) being integrated into the control system (16); the control system (16) retrieves information from a computer-implemented module list (9) of the technical module (1) and stores the information in a computer-implemented control system list (30) of the control system (16), said information being designed to identify the technical devices (2, 3, 4, 5a, 5b, 5c, 6) of the technical module (1); b) generating operator control and monitoring and / or automation for the technical installation taking into account the information relating to the technical module (1) stored in the computer-implemented control system list (30).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a module for generating operator control and monitoring and / or automation by means of a control system for a technical facility. In addition, the present invention relates to a control system for a technical facility, in particular a process or processing facility. Furthermore, the present invention relates to a technical module having a plurality of technical devices and a computer-implemented module inventory, which is designed to be integrated into a control system for a technical facility, in particular a process or processing facility. Background Art

[0002] Especially in the pharmaceutical industry and the specialty chemicals industry, high demands are placed on the operator of a technical facility to be able to quickly respond to changing market demands. Modular facilities enable the facility operator to significantly shorten the so-called "Time to Market" and to quickly respond to changing market conditions through low-cost facility retrofits. The facility operator can build a pool of modular units (such as process units) for this purpose, by means of which the facility operator can assemble a specific facility through so-called orchestration. If the facility is to be retrofitted, individual modules or complete units are removed and replaced with other, for example, better-performing modules or complete units.

[0003] In this context, a "technical module" or "complete unit" is understood to be a part of a technical facility that can be integrated as an independent unit into the central engineering system of the control system of the technical facility. A module has a wider scope than a single measurement point or technical device. A "module" can also be interpreted as a sub-facility of a technical facility having a complete process technology structure, which includes a plurality of technical devices (such as tanks), which in turn contain a plurality of measurement points (such as valves, monitors, regulators, engines, etc.).

[0004] A method of how to create a modular technical facility by means of self-descriptive information of modules is described in the document WO 2016 / 074730 A1. This method is based on the self-descriptive information of individual modules available online.

[0005] Due to the "black box" approach of technical modules, the internal structure of the installed technical devices remains hidden to the user - in the case of modules for process facilities, the interaction with the module is limited to process connections and interfaces for orchestration.

[0006] Inside the module and for the required external interactions, it is recommended to use secure communication (e.g., by using OPC UA). This means that the individual installed devices require corresponding certificates. According to common security recommendations, these certificates should be issued and signed by a trusted Certificate Authority (CA), and should not be self-signed (i.e., issued and signed by the individual device itself).

[0007] Based on the "black box" method, users usually cannot check the identity and originality of the technical devices installed inside the module. Therefore, for example, it may be unsafe to install a manipulated device inside the module, which may cause damage in the working environment during the operation of the module.

[0008] If the manufacturer of the technical module has issued the certificates required for secure communication for the installed devices through its trusted Certificate Authority and distributed them to the devices, then only by using the same Certificate Authority and thus only with the participation of the manufacturer can the regular update of these certificates (recommended for security reasons) be achieved during the operation of the module at the user's location. Even when replacing a device, the replacement device should be equipped with the certificates necessary for secure communication after corresponding checks. However, in most cases, there is no connection between the working environment and the manufacturer.

[0009] Devices installed inside a technical module (such as industrial computers, programmable logic controllers, sensors, actuators, human-machine interfaces, peripherals, etc.) often have a secure digital identity in the form of a so-called "Initial Device Identifier" (IDevID), which is transmitted to the device by the manufacturer during the manufacturing process of the module. According to the standard IEEE 802.1AR, this "Initial Device Identifier" includes a secret key securely stored in the device. In addition, it includes an attached IDevID certificate (represented by an X.509 certificate and mainly containing the attached public key) and an attached certificate chain. Here, as the trust anchor of the manufacturer, the certificate chain includes the certificate of the Certification Authority (CA) that issued the IDevID certificate and the certificates of all higher-level Intermediate CAs up to the Root CA.

[0010] By verifying a secure digital identity (which is often referred to as Proof of Originality in English), it is possible to use a suitable method (in the simplest case, for example, using a TLS handshake (TLS Handshake)) to check whether the corresponding device is the original device, that is, whether its ID, its public key that matches the private key securely stored in the device, and other data all originate from the IDevID certificate.

[0011] Even if it is assumed that the manufacturer of the manufacturing technology module itself has checked the identity / originality of individual devices according to its IDevID, there is still a risk of undetected and unauthorized replacement or manipulation of the automation technology devices located within the technology module, either on the transportation route to the original place of use of the technology module, within the scope of commissioning / integration at the user's location, or during operation at the user's location.

[0012] This problem becomes acute because generally, for users, it is unknown which devices are exactly installed within the technology module. For example, if a device belonging to a specific manufacturer's product line is recalled (e.g., due to a root certification authority compromise), then the user may not necessarily associate this information with the technology module in which such a device is installed and operated by them.

[0013] According to the current state of the art, the manufacturer / OEM that processes the technology module and installs various devices within the module may have the manufacturer / OEM-PKI (including the so-called issuing certification authority) issue the necessary application-specific certificates (which are particularly necessary for OPC UA communication) and convey them to the devices. This ensures secure communication between the installed devices using these certificates. Since the expiration date of these certificates (in accordance with general recommendations, it is preferably at most two months) may expire before commissioning or during the operation of the technology module in the corresponding working environment, there should be a possibility to update the certificates (in advance, for example, two weeks before their expiration). Summary of the Invention

[0014] The object of the present invention is to provide a simple and more secure method for generating operator control and monitoring for a technical facility including a technology module.

[0015] This object is achieved by a method for generating operator control, monitoring and / or automation by means of a control system for a technical installation, in particular a processing or process installation, as claimed in claim 1. In addition, this object is achieved by a control system for a technical installation, in particular a process or processing installation, as claimed in claim 7. Furthermore, this object is achieved by a technical module as claimed in claim 8, which technical module has a plurality of technical devices and a computer-implemented module list and is designed to be integrated into a control system for a technical installation, in particular a process or processing installation.

[0016] A method for generating operator control, monitoring and / or automation by means of a control system for a technical installation, in particular a processing or process installation, according to the invention comprises the following method steps:

[0017] a) integrating a technical module into the control system, wherein the technical module has a plurality of technical devices, and wherein, within the scope of the integration, the control system retrieves information from the computer-implemented module list of the technical module and stores the information in a computer-implemented control system list of the control system, the information being designed to identify the technical devices of the technical module;

[0018] b) generating operator control, monitoring and / or automation for the technical installation taking into account the information of the technical module stored in the computer-implemented control system list.

[0019] A "technical module" is understood to be an independent technical unit that can be integrated into a higher-level control level. Such a technical module can, for example, be a collection of a plurality of measuring points or a larger facility part of an industrial installation. However, the technical module does not have to originate from the field of industrial installations, but can also be, for example, an engine module of a motor vehicle, a ship or a similar installation.

[0020] In this context, a "control system" is understood to be a computer-aided technical system that includes functions for operator control and monitoring and for controlling a technical processing or production installation. In the present case, the control system includes sensors for determining measured values and various actuators. In addition, the control system includes so-called near-process or processing components for actuating the actuators or the sensors. Furthermore, the control system includes, but is not limited to, engineering means for the visualization of the technical installation. Additionally, the term "control system" can also be interpreted as other computing units for more complex regulation and systems for data storage and processing.

[0021] "Automation" is understood as the autonomous (automatic) acquisition and influencing of physical variables by means of technical means of a control system. Here, machines, facilities or other devices are usually enabled to work autonomously. Automation includes at least the parameterization of components of technical facilities and the interaction of components with other components.

[0022] According to the invention, information is stored in a computer-implemented module inventory, which is designed to identify the technical devices of a technical module. In the context of integrating a technical module into a control system, the control system reads this information from the module inventory of the technical module via a suitable interface (e.g., an OPC-UA server implemented on the technical module) and transfers it to the control system inventory of the control system. In combination with the retrieved information, the control system generates an operator control and monitoring, i.e., visualization, which the operator can use for operator control and monitoring of technical facilities, in particular technical modules. Alternatively or (usually) additionally, the control system also generates automation for the technical facilities, where the information received regarding the individual technical devices of the technical module is also taken into account here.

[0023] Preferably, this information includes certificates based on which the identification and originality check or identity check of the corresponding device can be implemented. Here, the identity check or originality check can be implemented in the interaction with the corresponding technical device. The control system can automatically evaluate the validity of these certificates and, when one of the certificates is invalid, exclude the technical module from the operator control and monitoring or automation of the technical facilities.

[0024] The certificates can have been issued by a certification body of the manufacturer of the technical module. However, the technical module can also have its own certification body, which has issued certificates for identifying individual technical devices.

[0025] Particularly preferably, this information includes a certificate chain for the technical device, where the certificate chain respectively includes the certification body that has issued the corresponding certificate for the corresponding technical device and the certificates of all higher-level certification bodies. If a certificate for the technical module has been issued by a certification body within the module, the corresponding certificate chain can be transmitted to the control system so that it can perform a certificate verification in accordance with RFC5280.

[0026] In this preferred case, the control system or the certification body of the technical facility obtains the certificates for the devices installed in the technical module via a suitable interface. In this case, the cost of transmitting the so-called "Root CA" certificate without integrity protection to the communication partner of the technical module is eliminated because the same certification body is used.

[0027] Preferably, this information includes the respective firmware version, serial number, update requirements for the operating software, manufacturer name, device series, IP address, MAC address, time points of originality checks, and / or time points of manual identification of the respective technical devices.

[0028] Furthermore, this object is achieved by a control system for a technical facility, in particular a process or processing facility, which is designed to carry out the method according to any one of the preceding claims.

[0029] In addition, this object is achieved by a technical module which includes a plurality of technical devices and a computer-implemented module list, and which is designed to be integrated into a control system for a technical facility, in particular a process or processing facility. The technical module is characterized in that information is stored in the computer-implemented module list of the technical module, and this information is designed to identify the technical devices of the technical module by means of the control system.

[0030] Preferably, this information includes certificates, based on which (and their attached private keys or secrets securely stored in the respective technical devices and matching the public keys stored in the respective certificates), the identification of the respective devices can be achieved. Usually, the identity check / originality check is not achieved solely by examining the certificates. It generally also includes the following steps, in which the respective device verifies its private key that matches the public key contained in the certificate. The control system can automatically evaluate the validity of these certificates, and when one of the certificates is invalid, the technical module is excluded from the operator control and monitoring or automation for the technical facility.

[0031] The certificates can have been issued by a certification body of the manufacturer of the technical module. However, the technical module can also have its own certification body which has issued certificates for identifying individual technical devices.

[0032] Particularly preferably, this information includes a certificate chain for the technical devices, where each certificate chain includes the certification body that has issued the respective certificate for the respective technical device and the certificates of all higher-level certification bodies.

[0033] Preferably, this information includes the so-called certificate revocation registers for the technical devices, which are each issued by the certification body that has issued the respective certificate for the respective technical device. Here, the certificate revocation register includes the certificates that have been revoked (i.e., declared invalid) by the respective certification body.

[0034] Within the scope of a preferred refinement of the technical module, this information meets the structural and substantial requirements of VDI / VDE / NAMUR guideline 2658 as of the filing date of this patent application. This mainly means that in addition to the identity information related to the technical devices installed in the technical module, this information also has the following components:

[0035] - Facility images (in standard format), which are provided by the control system for the operator to control and monitor the technical equipment contained in the technology module and visualized by the operator station client of the control system;

[0036] - Interface description of the technology module for cooperation with other facility parts of the technical facility to achieve operator control, monitoring, and automation of the technology module. In addition to process values and alarms, it can also include so-called services;

[0037] - Structural description of the technology module, for example, various process technology fields such as buffer tanks, reactors, agitators, etc. The facility images and interfaces are then correspondingly mapped onto the structural description - for example, the facility image of the agitator provides signals for the operator to control the agitator.

[0038] Within the scope of the present invention, information identifying the structural extension known under the name "ModuleType Package" according to the VDI / VDE / NAMUR guideline 2658. This can include the following information:

[0039] - Manufacturer (e.g., Siemens)

[0040] - Equipment series (e.g., S7-1500 CPU)

[0041] - Equipment ID, e.g., serial number (e.g., XYZ)

[0042] - Hardware version (e.g., 10007)

[0043] - Firmware version (e.g., R29.44.53_00.00.00.00)

[0044] - IP address (e.g., 172.27.232.44)

[0045] - MAC address (e.g., 28:63:36:8D:C4:2A)

[0046] - IDevID certificate (if any) (e.g., stored as a CER / DER file)

[0047] - The LDevID certificate (if any), such as a device-specific LDevID general certificate or various application-specific LDevID-App certificates, where in the working environment (more precisely, by the Public Key Infrastructure (PKI) running within the module or within the working environment, i.e., the technical infrastructure, or by a similar service), certificates are issued for different purposes for the device, and the certificates are automatically (e.g., by using standardized mechanisms such as OPC UA GDS Push / Pull or protocols such as the Certificate Management Protocol (CMP)) or manually conveyed to the device. In this case, a single PKI component (such as a registration authority or a local registration service capable of taking over its role, such as the OPC UA Global Discovery Server, for example) can be located within and / or outside the technical module and be run by the facility operator / appropriate service provider.

[0048] - “Proof of Originality” (PoO) (e.g., 08:32 on December 28, 2022), as the time point of the so-called originality check, which generally particularly includes the verification of the IDevID certificate, its identity, and originality of the device, and can be achieved with / without user support, where it shows, for example, a mandatory step within the scope of so-called Secure Device Onboarding.

[0049] - “Identification” (e.g., 09:33 on December 28, 2022), as the time point of identifying the device, which can be achieved, for example, by scanning a QR code printed on the device housing (e.g., by an authorized user). Within the scope of this process, device data can be read and presented to the user, who can then compare it with the available information. Here, it is worth noting that within the scope of identification, although the device can assert its identity, it cannot verify its identity (as in the originality check described above). Therefore, from the perspective of Cyber Security, this option lacks a strong foundation. For security reasons, for existing or legacy devices, it is strongly recommended to implement or even enforce identification at least once with user support.

[0050] Preferably, the technical module has a computer-implemented registration service, which is designed to determine information related to the technical device within the technical module based on a manual request or automatically or event-controlled at a specific time point and save the information in a computer-implemented module inventory.

[0051] In addition to the above identity checks, the computer-implemented registration service can also include other suitable and, if necessary, configurable check steps. For example, a specific comparison of the technical data / characteristics of a device with those of a reference device can be implemented both for debugging and during device replacement at runtime. The registration process can be triggered automatically (e.g., by an installed device using a suitable discovery method such as mDNS or using pre-configured address data to find the registration service) or induced by the user.

[0052] The registration service can also determine information related to a technical device within a technical module based on a manual request, based on replacing one of the technical devices, or automatically or event-controlled at a specific point in time, perform an identity check or originality check of the device, and save the information related to the technical device together with the status of the identity check / originality check and / or the corresponding identifier in a computer-implemented module list.

[0053] Particularly preferably, the registration service is designed to, by replacing one of the technical devices, induce the following actions in a technical module: determine information related to the technical device and save the information in a computer-implemented module list. Therefore, the incentive to call the registration service can be to identify and correspondingly report a device replacement during the operation of a technical module or technical facility, where the replacement device installed in the technical module should be correspondingly registered. If it is determined here (e.g., within the scope of initial debugging or device replacement) that the IDevID certificate of the installed device is invalid and / or has expired, the user is correspondingly notified or the corresponding policy is taken into account when triggering other suitable actions. If the identity check is successfully performed based on the IDevID certificate of the installed device, all devices together with their checked certificates are received into the module list. Description of the Drawings

[0054] In connection with the description of the embodiments below, the features, characteristics, and advantages of the present invention described above and the ways and means of implementing it can be more clearly and definitely understood, where these embodiments are described in more detail in connection with the accompanying drawings. In the drawings:

[0055] Figure 1 A technical module according to the present invention is schematically shown;

[0056] Figure 2 An object model of the technical module is shown; and

[0057] Figure 3 A control system according to the present invention is schematically shown. Detailed Description of the Embodiments

[0058] In Figure 1The technical module 1 is shown, which includes a server 2, a visualization device 3, an automation device 4, peripheral devices 5a, 5b, 5c and a plurality of sensors as well as actuators 6. In addition, the technical module 1 has connectors 7a, 7b, which are used to connect (e.g., process-technologically) to other technical modules or to components of technical facilities such as process plants. Further, the technical module 1 has an interface 8.

[0059] The technical module 1 can be connected via the interface 8 to a higher-level control level, such as a control system (see Figure 3 ). The interface 8 can for example include an OPC UA server, which can be used for software integration of the technical module 1 into the control system.

[0060] In the technical module 1, for example in the server 2, the module inventory 9 is computer-implemented. Information is stored in the module inventory 9 of the technical module 1, which is designed to enable the control system to identify the technical devices 2, 3, 4, 5a, 5b, 6 of the technical module 1.

[0061] This information meets the structural and substantial requirements of VDI / VDE / NAMUR guideline 2658 as of the filing date of this patent application. In Figure 2 an object model of the information related to the technical module 1 is shown. According to guideline VDI / VDE / NAMUR 2658, the description 10 of the technical module 1 includes a plant image 11, an interface 12 and a general structural layout 13 of the technical module 1.

[0062] Additionally, the description includes an inventory 14 of the technical devices 2, 3, 4, 5a, 5b, 6 of the technical module 1. The inventory 14 includes registers 15 of all the devices 2, 3, 4, 5a, 5b, 6 contained within the technical module 1, which can identify the technical devices 2, 3, 4, 5a, 5b, 6 of the technical module 1 in the control system connected to the technical module 1.

[0063] In Figure 3 a control system 16 is schematically shown, which is used for operator control and monitoring of a technical facility designed as a process plant. The control system 16 includes an operator station server 17 and an operator station client 18. The operator station server 17 and the operator station client 18 are interconnected via a terminal bus 19 and optionally connected to other non-shown components of the control system 16, such as an archive server.

[0064] For the purpose of operator control and monitoring, a user or operator can access the operator station server 17 via the operator station client 18 by means of the terminal bus 19. The terminal bus 19 can for example be designed as Industrial Ethernet, but is not limited thereto.

[0065] The operator station server 17 has an OPC UA server 21 and a device interface 20 connected to the facility bus 22. The operator station server 17 is connected to and can communicate with the automation device 23 and other components of the process technology facility (such as the peripheral facility 24) via the device interface 20. These other components are located outside the technology module 1. The technology module 1 is (detachably) connected to the other components 24 of the technology facility via the process connection piece 7b. The facility bus 22 can be designed, for example, as an industrial Ethernet, but is not limited thereto.

[0066] On the operator station server 17, there are also a visualization service 25, a process image 26, an orchestration service 27, and a certificate monitoring service 28. Snapshots of the (signal) states of the connected devices 24 and / or applications are respectively saved in the process image 26. The orchestration service 27 is designed to integrate the technology module 1 (software) into the operator control, monitoring, and automation of the technology facility. In other words, the orchestration service 27 performs orchestration, that is, the control of the technology module 1 and the coordination of the technology module 1 with the technology (process technology) facility. For orchestration, in this case, the process image 26 via the operator station server 17 and the OPC UA server 21 is read and written by the orchestration service 27 to the process values and services of the technology module 1. Via the operator station client 18, higher-level operator control and monitoring are performed by the operator, and in the operator station client, the visualization of the facility image necessary for operator control and monitoring is realized both for the technology module 1 and for the remaining part of the (process) technology facility. The certificate monitoring service 28 monitors the validity of the certificates of the technical devices 2, 3, 4, 5a, 5b, 5c, 6 of the technology module 1, which will be explored in more detail below. Additionally, the technology facility also has a certification authority 29 and a control system inventory 30.

[0067] The visualization service 25 integrated in the operator station server 17 initiates the transmission of visualization information to the operator station client 18. The operator station client 18 is in turn designed to display, in particular, the visualization of the facility image and the hierarchy, that is, a graphical presentation, for the operator to control and monitor the process facility.

[0068] As previously clarified, in the technology module 1, the module inventory 9 is computer-implemented. Information is saved in the module inventory 9 of the technology module 1, and this information is designed to enable the control system to identify the technical devices 2, 3, 4, 5a, 5b, 6 of the technology module 1. Additionally, the technology module 1 has a computer-implemented registration service 31, a certificate management service 32, a monitoring service 33, and a module certification authority 34 integrated within the technology module.

[0069] The registration service 31 is designed to determine and check or verify the identities of the technical devices 2, 3, 4, 5a, 5b, 6 present in the technology module. This is achieved, for example, based on their IDevID certificates. The certificates can, for example, be IDevID manufacturer certificates issued by the manufacturer of the technology module 1 or LDevID - OEM certificates issued by the OEM. The identities of the technical devices 2, 3, 4, 5a, 5b, 6 together with their certificates are stored by the registration service 31 in the module inventory 9. In addition to the above identity checks, the registration service can also perform other suitable and, if necessary, configurable check steps. For example, during commissioning and during device replacement at runtime, a specific comparison of the technical data / characteristics of the technical devices 2, 3, 4, 5a, 5b, 6 with a reference device can be performed. At runtime, the role of the reference device takes over, for example, the corresponding originally installed device to be replaced.

[0070] During this process, the registration process can be triggered automatically. For example, this is achieved by the installed device determining the registration service 31, for example using a suitable discovery method (such as mDNS), or using pre - configured address data and transmitting the identification data to it. Alternatively, the process can also be triggered by the user or by other processes.

[0071] Another trigger event for calling the registration service 31 can be a device replacement detected by the monitoring service 33 and correspondingly reported during the operation of the technology module 1, where the replacement device integrated into the technology module 1 should be registered correspondingly. If it is found here (for example, during initial commissioning or during device replacement) that the IDevID certificates of the installed technical devices 2, 3, 4, 5a, 5b, 5c, 6 are invalid and / or expired, the user is correspondingly notified or the corresponding policy is taken into account when triggering another appropriate action. If the identity check is successfully performed based on the IDevID certificates of the installed technical devices 2, 3, 4, 5a, 5b, 5c, 6, all the technical devices 2, 3, 4, 5a, 5b, 5c, 6 together with their checked certificates are included in the module inventory 9.

[0072] The module list 9 represents an overview of the technical devices 2, 3, 4, 5a, 5b, 5c, 6 installed in the technical module 1 together with their IDevID or LDevID certificates (wherein the LDevID certificate can include on the one hand the so-called device-specific LDevID general certificate and on the other hand the so-called application-specific LDevID-App certificate). During the entire life cycle of the technical module 1, after its first creation, the module list 9 is supplemented by the certificates (issued at the user's place during the OEM's assembly of the complete unit and during commissioning / orchestration) and is always kept up-to-date. In addition to the device-specific data and certificates, the status of the last identity check is also recorded in the module list 9. For example, here, the identity check performed by the OEM is called "Proof of Initial Device Identity", and the check performed by the user or in the user's working environment during the orchestration process is called "Proof of Locally-Significant OEM Device Identity".

[0073] The certificate management service 32 is particularly responsible for issuing module-specific or working environment-specific LDevID general certificates. Here, the certificate is applied for from the internal certification authority 34 installed in the technical module or from the certification authority 29 of the technical facility integrating the technical module 1. Additionally, this service is also responsible for triggering certificate updates or revocations for the technical devices 2, 3, 4, 5a, 5b, 5c, 6 based on the monitoring status reported by the monitoring service 33 and simultaneously reporting the updated / revoked certificates to the module list 9.

[0074] In order to be able to issue device-specific and application-specific certificates, a certification authority 34 (optionally including other attached certification services) is provided in the technical module 1 and a suitable interface is provided via the OPC UA interface 8 through which the technical module 1 can be integrated into the corresponding working environment (and in particular into the public key infrastructure running in this working environment). In a preferred case, the above-mentioned interface 8 is activated by establishing a certificate-based trust relationship between the registration service 31 and the certification authority 29 of the user's working environment. During the process of orchestrating the technical module 1, the trust relationship can be established at the user's place. It is worth noting here that each technical module 1 usually has at least one certificate-based communication relationship with a device external to the technical module 1.

[0075] If a certificate for the technical module 1 for ensuring this communication relationship has been issued by the internal certification authority 34, the corresponding certificate chain (including the root certification authority certificate protected by integrity) should be transmitted to the communication partner of the technical module 1 so that it can perform certificate verification in accordance with RFC5280.

[0076] Alternatively, certificates for the technical devices 2, 3, 4, 5a, 5b, 5c, 6 to be installed in the technical module are obtained from the user's certification authority 29 via the above-mentioned interface 8. In this case, there is no need to transmit the root certification authority certificates to the communication partner in an integrity-protected manner, since they utilize the same public key infrastructure.

[0077] Since the identity check on the individual installed technical devices 2, 3, 4, 5a, 5b, 5c, 6 is successfully performed with the aid of the registration service 31, the manufacturer / OEM of the assembled and successfully tested technical module (more precisely, the issuing certification authority operating it securely) can issue a module-specific IDevID or LDevID certificate for the technical module 1. Here, the application for this certificate is realized by using the certificate management service 32, taking into account the entries in the module inventory 9 and the status captured by the monitoring service 33.

[0078] Once the monitoring service 33 reports unacceptable changes that would have a negative impact on the trustworthiness of the technical module 1 according to the current policy, the above-mentioned module-specific IDevID or LDevID certificate is revoked (in consultation with the user if necessary). When other devices installed in the corresponding working environment communicate with the technical module 1, the above-mentioned module-specific certificate is checked as part of an additional check. In this way, it is possible to prevent (immediately if necessary) the proven untrusted technical module 1 from communicating with other devices in the technical facility to prevent damage.

[0079] The "private key" for the above-mentioned module-specific IDevID or LDevID certificate is stored in the hardware or software security element of the technical devices 2, 3, 4, 5a, 5b, 5c, 6 installed in the technical module 1. The same security element that has been used by one of the technical devices 2, 3, 4, 5a, 5b, 5c, 6 storing the private key is also used by the entire technical module 1 to securely store the private key. In this case, during the replacement of a device at runtime, if the check is successfully performed with the aid of the registration service 31, a key pair is regenerated and a certificate is applied for not only for the corresponding technical device 2, 3, 4, 5a, 5b, 5c, 6, but also additionally for the entire technical module 1. Alternatively, the above-mentioned "private key" can be stored in a separate and securely installed hardware or software security element within the technical module 1.

[0080] Localize the services 31, 32, 33 of the described technology module 1 on a suitable component / device (such as an IoT device). Here, while it is possible to use the already installed technology devices 2, 3, 4, 5a, 5b, 5c, 6 for other purposes as platforms for the above-mentioned services 31, 32, 33, in particular, in terms of network security and availability, it has proven reasonable to use a dedicated device as a platform for these services 31, 32, 33 and install the device within the technology module 1, or provide the device in the corresponding working environment via one or more suitable interfaces.

Claims

1. A method for generating operator control, monitoring, and / or automation by means of a control system (16) for a technical facility, in particular a processing or process facility, the method comprising: a) integrating a technical module (1) into the control system (16), wherein the technical module (1) has a plurality of technical devices (2, 3, 4, 5a, 5b, 5c, 6), and wherein, during the integration, the control system (16) retrieves information from a computer-implemented module list (9) of the technical module (1) and stores the information in a computer-implemented control system list (30) of the control system (16), the information being designed to identify the technical devices (2, 3, 4, 5a, 5b, 5c, 6) of the technical module (1); b) generating the operator control, monitoring, and / or automation for the technical facility taking into account the information related to the technical module (1) stored in the computer-implemented control system list (30).

2. The method according to claim 1, wherein, The information includes certificates based on which the identification and originality check or identity check of the corresponding technical devices (2, 3, 4, 5a, 5b, 5c, 6) can be performed.

3. The method according to claim 2, wherein, The control system (16) automatically evaluates the validity of the certificates, and if one of the certificates is invalid, excludes the technical module (1) from the operator control, monitoring, or automation of the technical facility.

4. The method according to claim 2 or 3, wherein The certificates have been issued by a certification body of the manufacturer of the technical module (1).

5. The method according to any one of claims 2 to 4, wherein The information includes a certificate chain for the technical devices (2, 3, 4, 5a, 5b, 5c, 6), the certificate chain respectively including certificates from the certification bodies (29, 34) that have issued the corresponding certificates for the respective technical devices (2, 3, 4, 5a, 5b, 5c, 6) and from all higher-level certification bodies (29, 34).

6. The method according to any one of the preceding claims, wherein, The information includes the respective firmware versions, serial numbers, update requirements for the operating software, names of manufacturers, device series, IP addresses, MAC addresses, time points of originality checks, and / or time points of manually performed identification of the respective technical devices (2, 3, 4, 5a, 5b, 5c, 6).

7. A control system (16) for a technical facility, in particular a process or processing facility, the control system being designed to perform the method according to any one of the preceding claims.

8. A technical module (1) comprising a plurality of technical devices (2, 3, 4, 5a, 5b, 5c, 6) and a computer-implemented module list (9), the technical module (1) being designed to be integrated into a control system (16) for a technical facility, in particular a process or processing facility, characterized in that information is stored in the computer-implemented module list (9) of the technical module (1), the information being designed to identify the technical devices (2, 3, 4, 5a, 5b, 5c, 6) of the technical module (1) by means of the control system (16).

9. The technical module (1) according to claim 8, wherein, The information includes a certificate based on which the identification and originality check or identity check of the corresponding technical devices (2, 3, 4, 5a, 5b, 5c, 6) can be performed.

10. The technical module (1) according to claim 9, wherein, The certificate has been issued by the certification bodies (29, 34) of the manufacturer of the technical module (1).

11. The technical module (1) according to claim 9 or 10, wherein, The information includes a certificate chain for the technical devices (2, 3, 4, 5a, 5b, 5c, 6), which respectively includes the certificates from the certification bodies (29, 34) that have issued the corresponding certificates for the corresponding technical devices (2, 3, 4, 5a, 5b, 5c, 6) and the certificates from all higher-level certification bodies.

12. The technical module (1) according to any one of claims 8 to 11, wherein, The information includes the corresponding firmware versions, serial numbers, update requirements for the operating software, names of manufacturers, device series, IP addresses, MAC addresses, time points of the originality check, and / or time points of manually performing the identification of the corresponding technical devices (2, 3, 4, 5a, 5b, 5c, 6).

13. The technical module (1) according to any one of claims 8 to 12, wherein, The information meets the structural and substantial requirements of VDI / VDE / NAMUR guideline 2658 as of the filing date of this patent application.

14. The technical module (1) according to any one of claims 8 to 13, wherein, The technical module has a computer-implemented registration service (31) which is designed to determine, based on a manual request or automatically at a specific time point, information about the technical devices (2, 3, 4, 5a, 5b, 5c, 6) within the technical module (1) and save the information in the computer-implemented module list (9).

15. The technical module (1) according to claim 14, wherein, The registration service (31) is designed such that when one of the technical devices (2, 3, 4, 5a, 5b, 5c, 6) is replaced in the technical module (1), the registration service is triggered to determine information about the technical devices (2, 3, 4, 5a, 5b, 5c, 6) and save the information in the computer-implemented module list (9).

Citation Information

Patent Citations

  • Method for planning the production of a product and production module having self-description information

    WO2016074730A1