Method, control entity and computer program product for controlling access to structured data or functions of an industrial automation device
By assigning multiple security and user levels to data or functions, and combining this with system-level control entities, the issues of flexibility and confidentiality in access authorization within industrial automation devices are resolved, enabling reliable access control over data and functions.
Patent Information
- Application Number
- CN202480024882.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-04-11
- Filing Date
- 2024-03-05
- Publication Date
- 2025-11-11
AI Technical Summary
Existing technologies in industrial automation devices are insufficient in flexibly and reliably adjusting access authorization according to the needs of different users and the confidentiality levels of different data, especially in terms of sensitivity classification and access control in data streams.
By assigning multiple security levels to data or functions and user levels to users or technical entities, access authorization is defined in a matrix manner. Combined with the automatic control of access by the system-level control entity (gatekeeper), it is ensured that users or technical entities can only access and operate data or functions that match their authorization level.
It enables flexible and reliable access control to data and functions in industrial automation devices, ensures data confidentiality throughout the process, simplifies authorization adjustments, and can automatically derive and enforce access permissions.
Smart Images

Figure CN120937007A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for accessing structured data or functions of an industrial automation device by controlling a higher-level concept according to claim 1, a control entity for accessing structured data or functions of an industrial automation device by controlling a higher-level concept according to claim 11, and a computer program product for accessing structured data or functions of an industrial automation device by controlling a higher-level concept according to claim 12. Background Technology
[0002] With the rise of edge computing in automation fields (such as manufacturing and buildings), a large amount of data is generated and is automatically transmitted to local (device-side), on-premises (field), and cloud (e.g., internet) hosted databases. For certain sensitive applications, such as in the medical and defense industries, customers need to enforce strict access control policies throughout the data flow. This invention relates to configuring and implementing such data classification policies in industrial automation devices, particularly in industrial edge and cloud computing systems / infrastructure.
[0003] As a representative implementation of the classification level, the following sensitivity levels (also known as confidentiality levels) are used here as an example:
[0004] 0 - Unlimited;
[0005] 1. Restriction (Internal only);
[0006] 2. Confidential; and
[0007] 3- Strictly confidential.
[0008] It should be noted that this scale is only provided as an example or standard specification. This invention can be easily extended to incorporate user-defined or configurable sensitive scales or confidentiality levels. In hierarchical data models, such as typical asset / aspect / variable structures, this classification scheme can be constructed as a tree structure.
[0009] In existing technologies, database technology enables access and authorization to each database. Databases are typically structured as semantic data models to represent hierarchical asset structures.
[0010] Access control is known to be implemented in database technologies in the present technology. Most modern databases (such as PostgreSQL, MongoDB, InfluxDB, etc.) come with an integrated Database Management System (DBMS) that provides access control policies and tools. While the underlying data structures provided in the database (such as sub-databases, resources, buckets, tags, data points, shards, etc.) depend on their specific implementation, the DBMS generally provides and manages user access authorization for these structures. Many implementations also support integration with enterprise directories through the standard LDAP interface (Lightweight Directory Access Protocol interface). Additional security features such as authorization tokens and TLS / SSL encryption (Transport Layer Security / Secure Sockets Layer Encryption) are standard features of such databases. However, these features primarily target user access control to regulate who can access which data; they do not address the security or sensitivity classification of the data structures themselves.
[0011] The enterprise classification levels for corporate documents are well-known. Enterprise software such as the Microsoft Office suite may support enterprise-specific sensitivity or classification levels. Within an enterprise, MS Office's "Information Protection" feature can assign an enterprise-specific sensitivity or confidentiality level to the current document (such as Word, Excel, PowerPoint, etc.). In this case, the data itself acquires a "sensitivity classification," but because the document is primarily used locally and for temporary sharing, comprehensive data access management based on this sensitivity classification may not be possible, and the assigned classification is tied to the corresponding document. Therefore, the classified authorization or restrictions associated with the document apply to any use of that (only) document and are binding and consistent on all users of that document. Conversely, the extent to which an enterprise can effectively control the flow of sensitive data depends crucially on employee adherence to established confidentiality policies; that is, employees not only need to correctly classify documents but also need to know and enforce the regulations under which sensitive documents can be forwarded.
[0012] In the industrial sector, access control is also known to exist in Supervisory Control and Data Access (SCADA) systems. Typically, SCADA systems provide user management tools to authorize which users can access the system with what permissions. For example, in Siemens WinCC, it is possible to assign login access permissions and function / operation permissions to each user, such as... Figure 1 The table is shown below.
[0013] In the paper US 2015 / 0205977 A1, Rundle et al., in their "Data Security Based on Isolation Zones," proposed centralizing data in specific storage structures ("isolation zones") and assigning each isolation zone a category. Users must have the same or a higher category to access the data in the corresponding storage structure.
[0014] Schulz's "Computer system and method for controlling access to digital data of a device" disclosed in EP 3 515 035 A1 discloses a method that assigns attribute information to a user and access information to digital data, wherein when a user accesses data, the user's attribute information is compared with the corresponding access information.
[0015] The paper “Access Control: Principles and Practices” by Sandhu et al. (IEEE Communications Journal, IEEE Service Center, Piscatave, USA, Vol. 32, No. 9, September 1, 1994, pp. 40-48) discloses a role-based access control concept in which multiple rules (“policies”) must be satisfied simultaneously when accessing data. Summary of the Invention
[0016] Therefore, the purpose of this invention is to more reliably control access to data in industrial environments and to flexibly adjust access authorization according to the needs of different users and the confidentiality level of different data.
[0017] In the scheme described in this invention, files, data streams, or data objects (such as variables, assets, functions, and applications), referred to simply as data, can be categorized according to their required level of protection. This data categorization is considered throughout the application, which may encompass multiple devices and organizational units, thereby allowing users to access and manipulate (e.g., read and write) data objects of a specific category only based on their authorization level. Typical user interactions requiring management include:
[0018] - Display (read) assets / aspects / variables, especially the data related to them;
[0019] - Edit (write) assets / aspects / variables, especially the data associated with them;
[0020] - Export and import, backup and restore.
[0021] The core of a classification system lies in controlling the data or "assets" themselves. This concept applies to systems that lack traditional (personal-oriented) user management as well as systems that manage human or non-technical users ("users"). Access management for specific categories must be linked to the system's user management; a user ("user") generally refers to an entity that uses or accesses data, functionality, or a broader "asset," and can also be an (external) device, service, or other "data recipient." While typical examples involve human users or general personnel assigned to authorized roles or similar attributes, this invention is generally applicable to data recipients, interfaces, or APIs. Administrators can specify which categories and interactions each user (broadly defined) can access (or, alternatively, all users belonging to a defined group) can perform.
[0022] This objective is achieved by the method of claim 1, the control entity of claim 11, and the computer program product of claim 12.
[0023] Here, a method for controlling access to structured data or functions of industrial automation devices is proposed, wherein access to data or functions is controlled. Specifically, data or functions are assigned a specific security level from multiple security levels (0, ..., 3), and users or technical entities are assigned user levels from a certain number of user levels. Preferably, access authorization is specified for multiple or each security level (0, ..., 3) and for multiple or each user level in a matrix manner. The access authorization specifies the restrictions on access to data or functions belonging to the corresponding security level (0, ..., 3) by the user or technical entity of the corresponding user level, and based on the specified restrictions, the user or technical entity of the corresponding user level controls access to the data or functions belonging to the corresponding security level (0, ..., 3). Thus, user or machine access and authorization are controlled by the security classification of the data or data structure or function itself, providing a comprehensive scheme to automatically determine the authorization for known users or technical entities to access and modify specific data or data structures or functions.
[0024] This objective is also achieved through a control entity (also known as a gatekeeper or system-level gatekeeper) for controlling access to structured data or functions of industrial automation devices. This control entity includes an input interface for receiving data to be accessed, or an API (Application Programming Interface) or similar interface for accessing functions. The control entity is configured to control access to data or functions according to any of the methods described above, and includes an output interface for accessing the data or functions. This enables the realization of the advantages discussed in the aforementioned methods.
[0025] Furthermore, this objective is also achieved by a computer program product for controlling access to structured data or functions of an industrial automation device, the computer program product being designed to implement any of the methods described in the claims when executed on a computer.
[0026] This method or control entity is particularly preferred for industrial edge devices that can access (confidential) data from industrial automation equipment and simultaneously have interfaces for connecting to public networks (the Internet, the cloud). The control entity described in this document can also supplement existing firewalls by controlling access to data based on content (rather than just port). Industrial edge devices (“Edge Devices”) are typically equipped with runtime environments for software containers (such as so-called Docker containers) and managed by management systems (such as Kubernetes). Industrial applications are then encapsulated and run in their respective runtime environments. The method, apparatus, or service according to the invention (hereinafter referred to as the control entity) can preferably be encapsulated in a separate container and / or run in a separate runtime environment, controlling the data flow of associated adjacent containers. Software containers assigned to other containers or applications to implement a service are sometimes also referred to as sidecar containers.
[0027] Other advantageous embodiments of the method of the invention are set forth in the dependent claims. The features and advantages described herein also apply to the apparatus and the computer program product of the invention. Advantageous embodiments can be implemented individually or in reasonable combinations.
[0028] In one advantageous implementation, at least "read authorization" and "read and write authorization" are distinguished in the access method, i.e., in the data operation method. Therefore, this method is compatible with existing access control methods.
[0029] In cases where no access information is available for a given combination of security level and user level, it is preferable to deny access or take other predefined measures. This eliminates the need for administrators to manually fill in every possible combination of user level and security level, which avoids unnecessary work, especially when using a matrix-like recording method.
[0030] By means of the present invention, it is advantageously possible to subsequently change restrictions associated with confidentiality levels and / or user levels, wherein the restrictions on subsequent access to the relevant data are changed. This greatly simplifies the overall adjustment of authorization or restrictions.
[0031] A key advantage of this invention is that it can classify data directly, or it can first assign categories to variables or data sources and then automatically assign them to all data generated or derived from the values of those variables or data sources. It can also advantageously assign categories to data types and automatically assign them to all data of that type. Furthermore, it enables inheritance of derived structures, data types, or similar content, wherein data or data types or data structures generated from combinations of individual data or data types or data structures, if each of which has an independent category, inherit the most stringent category as a whole.
[0032] Preferably, access to data belonging to the corresponding security level is controlled by user control at the appropriate user level of the external interface of the component associated with the data-containing automation device, particularly via network interface, other data interface, or software for the user interface (BuB - Operation and Monitoring; "HMI" - Human-Machine Interface). Thus, the internal data flow within the device or associated automation device ("domain") is not interfered with by control, while data is protected by controlling external access, such as access to other devices, other programs, network access, access to operation and monitoring equipment, or similar access.
[0033] User class assignments can be made to users who are "technical users" in the sense of devices, applications, or interfaces, and can originate from internal use management systems. Alternatively, external identity and access management systems (IAM) such as corporate directories (Lightweight Directory Access Protocol LDAP) or Active Directory known in network management can be used. User class classification schemes can also be derived from enterprise systems (such as MS Office) and subsequently associated with authorization. Attached Figure Description
[0034] The present invention will be described with reference to the accompanying drawings.
[0035] The diagram shows:
[0036] Figure 1 The illustration shows, in the prior art, taking a SCADA system as an example, how users are assigned to user groups and the authorization or restrictions assigned thereto.
[0037] Figure 2 The classification of data or data structures according to the present invention is shown, with confidentiality levels, assigned user levels and corresponding restrictions. Detailed Implementation
[0038] exist Figure 1The table illustrates classic authorization rules in the prior art. In industrial applications, such as SCADA systems (SCADA = Monitoring, Control and Data Access), access control is known to exist. Generally, SCADA systems provide user management tools to authorize which users are allowed access to the system with what permissions. In known SCADA systems like Siemens WinCC, it is possible to assign login, access, and function / operation permissions to each user, such as... Figure 1 As shown in the table. However, these authorizations are implemented only at the general system functionality level and are not combined with the concepts of sensitivity level classification or confidentiality level classification of the underlying data structures.
[0039] Figure 2 The top row of the authorization matrix displays security levels 0, ..., 4. These security levels can be directly assigned to the data, data structures, or data sources that need protection. Of course, system functions (such as storage, printing, sending, login, etc.) can also be considered as data or data operations in a broader sense. Access to or use of these system functions is controlled and can be categorized. Figure 2 The table shown illustrates an example of how user roles (left column) are used as user levels, and how permitted interactions / actions are assigned according to confidentiality levels (following columns), with corresponding restrictions (e.g., hidden – read-only, read and write) marked within the matrix cells. Of course, information can also be displayed or stored in other forms besides matrices, such as as XML (Extensible Markup Language) files with appropriate tags.
[0040] To configure the classification hierarchy of the data structure, a web-based user interface is preferably implemented. After input, the classification hierarchy is inherited in the asset hierarchy structure.
[0041] Furthermore, the subtrees of a data model cannot have a lower (i.e., more lenient) classification hierarchy than their parent elements.
[0042] Subsequently, data access is automatically enforced at the system level by a control entity called a "gatekeeper." This entity simply compares the current user's access / authorization level for a given operation (e.g., read / write) with the confidentiality or sensitivity classification of the relevant data structure. When returning query results to the user, if the required authorization or confidentiality level of the data structure is higher than that of the current user (Benutzer / Nutzer / User) or user group, the data structure will be directly filtered out. The gatekeeper can also easily prevent users from modifying read-only data.
[0043] In summary, the present invention has the following main features:
[0044] • Confidentiality classification or sensitivity classification is stored as an inherent attribute of each asset / variable / object (generally: data).
[0045] • User management (referring to the management of authorization for users, devices, services or other entities that access data) is specifically implemented to map access authorization to data category access authorization.
[0046] • The system-level control entity or "gatekeeper" is responsible for regulating or controlling the distribution of data to users or other data receivers through the following methods:
[0047] • Check authorization before releasing data to users;
[0048] • When querying the database, use filters that are adjusted based on the relevant user's authorization or restrictions; and
[0049] • Check user authorization before allowing changes to the data.
[0050] Although the above implementation requires configuring authorization mapping relationships specifically for each category (see...) Figure 2 (as shown in the table), but it can also be integrated with existing enterprise directories and classification systems.
[0051] Therefore, this classification system is not (must be) user-based (referring to an individual) in the traditional sense. Based on the classification, control should be exercised over whether data can be processed in a certain function or similar situation, or whether it is allowed to be transmitted via an interface. Thus, control over data flow and interface / function access is achieved.
[0052] The connection to the user (individual) exists because the user interface (such as an HMI - Human-Machine Interface) also implements the data flow that needs to be controlled. This process is similar to all other interfaces, for example:
[0053] - Variable X has a category Y. This data can only be used in read-only mode via the cloud interface.
[0054] - Variable X has a category Y. This data is only allowed to be accessed by user Z in read-only mode via the user interface.
[0055] Therefore, there are no dedicated functions for (human) users in this system; "HMI" or other access methods are merely one of many interfaces that allow data flow and must be controlled. If a product is not managed by a "human" user, this approach remains essentially unchanged. The key is to implement access control over data, data sources, functions, interfaces, applications, or other assets, which can be enforced by human users or technical entities, the latter being devices, applications, interfaces, functions, or other entities.
[0056] The significant difference between this invention and existing similar technologies lies in the fact that user access and authorization are automatically derived and enforced based on the confidentiality level classification inherent in the data structure itself. This ensures the confidentiality of data throughout the entire data flow.
[0057] contrast:
[0058] • Database technology provides comprehensive user management and access control tools, but the underlying data structure usually does not include specific confidentiality level classifications unless they are implemented manually or by the user.
[0059] Similarly, SCADA / WinCC systems typically support user management and system function authorization, but are not directly linked to the concept of underlying security level classification of available data structures. Furthermore, WinCC only restricts access to the overall system functions, lacking selective control within functions. Likewise, WinCC only allows or prohibits access to the entire data structure; in contrast, this invention enables selective control over which data is accessible.
[0060] • Enterprise-level classification tools, such as Microsoft Office's "Information Protection" feature, can classify each document by its level of confidentiality, but access control for highly sensitive documents relies on employees strictly enforcing and adhering to confidentiality and data sharing policies.
[0061] In short, according to the present invention, user access, authorization, and permitted operations are controlled by the confidentiality level classification of the data structure itself. Therefore, a comprehensive measure is provided to automatically determine the access and modification authorization of a known user to a given data structure – at the system level, the "system-level gatekeeper" (abbreviated as Gatekeeper, a control entity; a computer program / program product for access control) simply compares the user's authorization level for the desired operation (e.g., read / write) in the user class with the data's sensitivity level classification or confidentiality level classification.
Claims
1. A method for controlling access to structured data or functions of an industrial automation device. in, Access to the data or functions is controlled. Its features are, The data or function is assigned a classification with a specific security level (0, ..., 3) derived from multiple security levels (0, ..., 3). To assign user levels to users or technical entities, which are derived from a certain number of user levels. Preferably, access authorization is specified in a matrix for multiple or each of the security levels (0, ..., 3) and for multiple or each of the user levels. The access authorization specifies the restrictions on access to the data or functions belonging to the corresponding security level (0, ..., 3) by the user or technical entity of the corresponding user level. According to the restrictions stipulated in the relevant regulations, access to the data or functions belonging to the corresponding security level (0, ..., 3) is controlled by the user or technical entity belonging to the corresponding user level.
2. The method according to claim 1, characterized in that, In the case of access authorization, at least a distinction should be made between "read" authorization, which is a permitted operation for the data, and "read and write" authorization.
3. The method according to any one of the preceding claims, characterized in that, Access is denied if no access authorization is available for a specific combination of confidentiality level (0, ..., 3) and user level.
4. The method according to any one of the preceding claims, characterized in that, The restrictions associated with the confidentiality level (0, ..., 3) and / or user level will then be changed, wherein the restrictions are changed for subsequent access to the relevant data or functions.
5. The method according to any one of the preceding claims, characterized in that, The confidentiality level (0, ..., 3) is assigned to the variable or data source and automatically assigned to all data generated or derived from the value of the variable or data source.
6. The method according to any one of the preceding claims, characterized in that, The confidentiality level (0, ..., 3) is assigned to the data type and automatically assigned to all data of that type.
7. The method according to any one of the preceding claims, characterized in that, The corresponding security level (0, ..., 3) is stored together with the corresponding data.
8. The method according to claim 7, characterized in that, The confidentiality level (0, ..., 3) is stored as metadata along with the dataset or data stream, preferably placed before the dataset or data stream.
9. The method according to any one of the preceding claims, characterized in that, A combination of data or data types or data structures generated from individual data or data types or data structures, each having its own security level (0, ..., 3), inherits the most stringent security level among the security levels (0, ..., 3).
10. The method according to any one of the preceding claims, characterized in that, Access to the data, which is associated with the corresponding security level (0, ..., 3), is controlled by the user at the corresponding user level of the external interface of the component of the automated device having the data, particularly via a network interface, other data interface, or software for the user interface.
11. A control entity for controlling access to structured data or functions of an industrial automation device. Its features are, The control entity includes an input interface for receiving the data to be accessed or an access interface for accessing functions, the access interface being particularly an API. The control entity is designed to control access to the data or function according to any of the foregoing methods, and The control entity includes an output interface for accessing the data or the function.
12. A computer program product for controlling access to structured data or functions of industrial automation devices, characterized in that, The computer program product is configured to perform the method according to any one of claims 1 to 10 when the computer program product is executed on a computer.
Citation Information
Patent Citations
Computer system and method for controlling access to digital data of a device
EP3515035A1
Compartment-based data security
US20150205977A1