METHOD AND SYSTEM FOR GRANTING ACCESS RIGHTS TO CONTROL APPLICATIONS OF AN INDUSTRIAL AUTOMATION SYSTEM
Patent Information
- Application Number
- DE502023002264
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-03-25
- Filing Date
- 2023-02-27
- Publication Date
- 2025-12-04
- Estimated Expiration
- 2043-02-27
Description
[0001] The present invention relates to a method for granting access rights to control applications of an industrial automation system and to a system suitable for carrying out the method.
[0002] Industrial automation systems typically comprise a multitude of automation devices interconnected via an industrial communication network and serve to control or regulate plants, machines, or equipment within the context of manufacturing or process automation. Due to time-critical conditions in industrial automation systems, real-time communication protocols such as PROFINET, PROFIBUS, Real-Time Ethernet, or Time-Sensitive Networking (TSN) are predominantly used for communication between automation devices. In particular, control services or applications can be automatically and load-dependently distributed across currently available hosts or virtual machines within an industrial automation system.
[0003] WO 2021 / 104632 A1 concerns a method for capturing data packets originating from a first container within a cluster of containers. Each container is assigned multiple network interfaces for transmitting data packets. As soon as a first connection for transmitting data packets via a first network interface assigned to the first container is detected, an identifier assigned to the first container is inserted into a data stream associated with that first connection. The inserted identifier allows the first container to be identified for capturing data packets originating from it.
[0004] The earlier European patent application with application number 21212849.0 describes a method for providing control applications, in which the control applications are provided by means of sequence control components that can be loaded into and executed in a sequence control environment created by a server. Control applications requiring specific safety authorizations are each assigned a designation as a safety-critical control application. For each control application designated as a safety-critical control application, at least one execution condition is defined for the selected safety authorizations. During the execution of the sequence control components for the control applications, the sequence control environment monitors for the occurrence of each respective execution condition.The execution of the process control components is terminated upon the occurrence of the respective process condition.
[0005] US Patent 2019 / 182295 A1 discloses a method for granting access rights to control applications, in which the control applications are provided by means of software containers that are loaded into and executed in a container runtime environment installed on a host operating system. The control applications are monitored and configured by means of an application management system. Data traffic from the control applications to target devices or applications is authorized after successful authentication by a web proxy using an access key embedded in the data traffic.
[0006] Industrial automation systems contain numerous control applications that require authentication with other systems or system components. A common problem with existing, especially older, control applications or third-party control applications is that they often do not support the authentication methods required by the target systems. This typically results in the control applications having to be extensively adapted to the required authentication methods, or authentication being disabled altogether. Token-based methods are also not a solution, as such methods generally do not identify the component accessing a target system.
[0007] The present invention is based on the objective of creating a method for granting access rights to control applications which enables access to any target devices or applications in industrial automation systems, independent of an authentication method directly supported by the respective control application, and of specifying a suitable device for carrying out the method.
[0008] This problem is solved according to the invention by a method with the features specified in claim 1 and by a system with the features specified in claim 10. Advantageous embodiments are specified in the dependent claims.
[0009] According to the inventive method for granting access rights to control applications of an industrial automation system, first control applications are provided by means of software containers, which are loaded into and executed in a container runtime environment installed on a host operating system. The first control applications are monitored and configured by means of an application management system. Furthermore, the first control applications are authenticated by means of the application management system. Second control applications are executed directly on a host operating system and cryptographically authenticated. In particular, neither the first nor the second control applications have or perform any authentication functions.
[0010] According to the invention, the software containers for the first control applications can be migrated from one automation device with a container runtime environment to another automation device with a container runtime environment for execution there, or can be executed simultaneously on several automation devices with container runtime environments. Furthermore, the application management system detects the creation, deletion, or modification of the software containers and registers the software containers with their respective execution status. The creation, deletion, or modification of the software containers each includes the allocation or release of resources in the respective automation device with a container runtime environment. In this way, the first control applications can be consistently orchestrated by the application management system and authorized with regard to their data traffic.
[0011] According to the invention, data traffic from the first and second control applications to target devices or applications is authorized after successful authentication by means of an access key inserted into the data traffic, which is valid at least temporarily. Advantageously, the access keys are inserted into the respective data traffic by an associated injector component that is separate from the first and second control applications. In this process, the first and second control applications are authenticated against their respective associated injector components. Furthermore, the data traffic is preferably authorized only for trusted first and second control applications that are provided via a trusted channel or by a trusted instance.
[0012] In contrast to prior art approaches, which primarily secure communication links cryptographically and can, in principle, be used by any application, the present invention identifies trusted control applications in order to authorize access to critical resources. In particular, it is not necessary for the control applications themselves to include or provide authentication functions.
[0013] Advantageously, the second control applications are cryptographically authenticated using digital signatures, processing process identifiers, or operating system-level authentication. Root keys for authentication can be transferred to the respective automation device during commissioning processes on which the second control applications are installed. For successful authentication of a second control application, such a root key is required on the respective automation device. The root keys can, for example, be continuously exchanged during operation of the automation devices, so that even stringent security requirements can be met with the present invention.
[0014] According to a further embodiment of the present invention, the first and second control applications are installed on automation devices that are encompassed by a secure subnetwork assigned to the industrial automation system. In this case, access to the first and second control applications from outside the secure subnetwork is only possible after authorization by the application management system. This ensures secure interaction of the first and second control applications, particularly with cloud computing systems.
[0015] Furthermore, it can be advantageously provided that the first and second control applications are authenticated against an injector component associated with the application management system for access to a cloud computing system outside the secured subnet. After successful authentication, the injector component associated with the application management system inserts at least temporarily valid access keys into the data traffic of the first and second control applications to the cloud computing system. Access to the cloud computing system by the first and second control applications is then securely and efficiently authorized using these access keys.
[0016] The system according to the invention is provided for carrying out a method as described above and comprises several automation devices designed and configured to provide first control applications by means of software containers that can be loaded into and executed in a container runtime environment installed on a host operating system. Furthermore, selected automation devices are designed and configured to execute second control applications directly on a host operating system and to authenticate them cryptographically.
[0017] Furthermore, the system according to the invention comprises an application management system designed and configured to monitor, configure, and authenticate the first control applications. The system is also designed and configured to authorize data traffic from the first and second control applications to target devices or applications after successful authentication, using an access key that is at least temporarily valid and embedded in the data traffic.
[0018] The present invention is explained in more detail below using an exemplary embodiment with reference to the drawing. It shows the Figurein system with multiple automation devices, an application management system, and a cloud computing system.
[0019] The system depicted in the figure comprises several automation devices 101-103, an application management system 200, and a cloud computing system 301. The automation devices 101-103 and the application management system 200 are encompassed by a secure subnetwork 100, which is assigned to an industrial automation system. The secure subnetwork 100 is connected to the cloud computing system 301 via a wide area network 300, which in particular provides internet communication connections. Preferably, a firewall system is provided for the secure subnetwork 100, which may, for example, be integrated into the application management system 200. The cloud computing system 301 comprises at least one server through which IT infrastructure, such as storage space, computing power, or application software, is provided as a service, in particular for the automation devices 101-103 or for the application management system 200.
[0020] Automation devices 101-103 can include, for example, operator and monitoring stations, programmable logic controllers (PLCs), RFID readers, or machine vision systems. In addition to automation devices 101-103, network infrastructure devices such as switches or routers can also be included in the secure subnetwork 100. Network infrastructure devices are used in particular to connect programmable logic controllers, input / output units (I / O modules), or operator and monitoring stations of the industrial automation system.
[0021] Programmable logic controllers (PLCs) comprise, for example, a communication module, a central processing unit (CPU), and at least one input / output unit. Input / output units facilitate the exchange of control and measurement variables between PLCs and the machines or devices controlled by them (110, 120, 130). The CPUs are specifically designed to determine suitable control variables from acquired measurement variables. Input / output units can also be configured as decentralized peripheral modules located remotely from a PLC.
[0022] The automation devices 101-103 are designed and configured to provide initial control applications 113, 123 by means of software containers that can be loaded into and executed in a container runtime environment 112, 122 installed on a host operating system 111, 121. The initial control applications 113, 123 can, in particular, implement functions of automation devices, such as control and monitoring functions, or other time-critical services.
[0023] In the present embodiment, the first control applications 113, 123 are monitored and configured by means of the application management system 200. The application management system 200 detects the creation, deletion, or modification of software containers and registers the software containers with their respective execution status. The creation, deletion, or modification of the software containers specifically includes the allocation or release of resources in the respective automation device 101-102 with container runtime environment 112, 122.
[0024] Furthermore, the application management system 200 includes an image repository 213 for providing storage images for the software containers. Alternatively or additionally, the storage images for the software containers can be retrieved from a storage and deployment system accessible to a large number of users for reading and writing, such as Docker Hub or another container registry.
[0025] In particular, the software containers for the first control applications 113, 123 can each be migrated from one automation device 101, 102 with container runtime environment 112, 122 to another automation device 102, 101 with container runtime environment 122, 112 for execution there, or executed simultaneously on several automation devices 101-103 with container runtime environment 112, 122. Preferably, each software container is designed and configured to run in isolation from other software containers or container groups, e.g., pods, within the container runtime environment on the respective host operating system 111, 121. Advantageously, the software containers, together with other software containers running on the respective automation device, utilize a kernel of the host operating system 111, 121.In principle, alternatives to Docker containers for software containers can also be used for micro-virtualization concepts such as Snaps.
[0026] In the present embodiment, the container runtime environment is a container engine that creates, deletes, and links virtual resources. These virtual resources include not only software containers but also virtual communication networks and their associated connections. Specifically, the container runtime environment can include a Docker Engine or a Snap Core running on the respective automation device 101-102.
[0027] Furthermore, the automation devices 101-102 are designed and configured to execute secondary control applications 114, 124 directly on the respective host operating systems 111, 121 and to cryptographically authenticate them. The primary control applications 113, 123, on the other hand, are authenticated by means of the application management system 200. In particular, the primary 113, 123 and the secondary 114, 124 control applications do not have or perform authentication functions.
[0028] The second control applications 114, 124 can be cryptographically authenticated, for example, by means of digital signatures, processing process identifiers, or operating system-level authentication. In the present embodiment, a root key is required on the respective automation device 101-102 for successful authentication of a second control application 114, 124. Preferably, the root keys 14 are transferred to the automation device 101, 102 during a commissioning process of the respective automation device 101-102, on which at least one second control application 114, 124 is installed, and stored there in a key repository 115, 125. The root keys 14 can, for example, be transferred to the automation devices 101-102 by the application management system 200. Advantageously, the root keys 14 are continuously exchanged during operation of the automation devices 101-102.
[0029] Data traffic 11 from the first and second control applications to target devices 103 or their respective target applications is authorized after successful authentication by means of an access key 12 inserted into the data traffic 11, which is valid at least temporarily. This data traffic 11 is authorized only for trusted first control applications 113-114 and second control applications 123-124, which are provided via a trusted path or by a trusted instance, in particular by the application management system 200. The access keys 12 are inserted into the respective data traffic 11 by an associated injector component 201-202, which is separate from the first control applications 113 and the second control applications 114 and 124. The first 113, 123 and the second control applications 114, 124 are authenticated against their respective assigned injector components 201-202.
[0030] In addition to an application management component 211, the application management system 200 in the present embodiment includes an injector component 212. This injector component 212 ensures that access to the first 113, 123 and the second control applications 114, 124 from outside the secured subnetwork 100 is only possible after authorization by the application management system 200. For this purpose, the application management system 200 inserts access keys 32 into access requests from the cloud computing system 301, thereby authorizing access to the first 113, 123 and the second control applications 114, 124.
[0031] Specifically, the first and second control applications are authenticated to the injector component 212 of the application management system 200 for access to the cloud computing system 301 outside the secured subnetwork 100. Furthermore, after successful authentication, the injector component 212 of the application management system 200 inserts at least temporarily valid access keys 12 into the data traffic 11 of the first and second control applications to the cloud computing system 301. These access keys 12 authorize the access of the first and second control applications to the cloud computing system 301.
Claims
1. Method for enabling access rights to control applications of an industrial automation system, in which - first control applications (113, 123) are provided by means of software containers, which are loaded into a container runtime environment (112, 122) installed on a host operating system (111, 121) and executed there, - the software containers for the first control applications can be migrated onto another automation device with container runtime environment for execution there by an automation device with container runtime environment and / or executed simultaneously on several automation devices with container runtime environment, - the first control applications are monitored and configured by means of an application management system (200), - the application management system detects an application, a deletion and / or a change in the software container and registers the software container with its respective execution status, and in which the application, the deletion and / or the change in the software container comprises in each case an allocation or release of resources in the respective automation device with container runtime environment, - the first control applications are authenticated by means of the application management system, - second control applications (114, 124) are executed directly on a host operating system (111, 121) and are authenticated cryptographically, - data traffic (11) in the first and second control applications to target devices (103, 301) and / or applications are authorized following successful authentication in each case by means of an at least temporarily valid access key (12) which is inserted into the data traffic.
2. Method according to claim 1, in which the data traffic (11) is authorized for only trusted first (113, 123) and second control applications (114, 124), which are provided by way of a trusted approach and / or by a trusted entity (200).
3. Method according to one of claims 1 or 2, in which the access keys (12) are each inserted into the respective data traffic (11) by an assigned injector component (201, 202, 212) which is separated from the first (113, 123) and the second control applications (114, 124), and in which the first and the second control applications are authenticated with respect to the respective assigned injector component.
4. Method according to one of claims 1 to 3, in which the second control applications are cryptographically authenticated by means of digital signatures, calculation process identifiers and / or on the operating system side.
5. Method according to claim 4, in which root keys (14) for authentication during commissioning processes of automation devices (101-102), on which the second control applications (114, 124) are installed, are transferred to the respective automation device and in which a root key is required on the respective automation device for a successful authentication of a second control application in each case.
6. Method according to claim 5, in which the root keys are continuously replaced in each case during operation of the automation devices.
7. Method according to one of claims 1 to 6, in which the first and the second control applications in each case do not have and / or perceive authentication functions.
8. Method according to one of claims 1 to 7, in which the first and the second control applications are installed on automation devices (101-102) which are included in a protected subnetwork (100) which is assigned to the industrial automation system, and in which access to the first and the second control applications is carried out from outside of the protected subnetwork only following authorization by the application management system (200).
9. Method according to claim 8, in which the first (113, 123) and the second control applications (114, 124) are authenticated with respect to an injector component (212) assigned to the application management system (200) for access to a Cloud computing system (301) outside of the protected subnetwork (100), in which, following successful authentication, the injector component assigned to the application management system inserts in each case at least temporarily valid access keys (12) in data traffic (11) of the first and the second control applications to the cloud computing system, and in which the access of the first and the second control applications to the Cloud computing system is authorized by means of these access keys.
10. System for implementing a method according to one of claims 1 to 9 with - a number of automation devices (101-102) which are designed and configured to provide first control applications (113, 123) by means of software containers, which can be loaded into a container runtime environment (112, 122) installed on a host operating system (111, 121) and executed there, wherein selected automation devices are designed and configured to execute second control applications (114, 124) directly on a host operating system and to authenticate the same cryptographically, - an application management system (200), which is designed and configured to monitor, configure and authenticate the first control applications, - wherein the software container for the first control applications can be migrated onto another automation device with container runtime environment for execution there in each case by an automation device with container runtime environment and / or can be simultaneously executed on several automation devices with container runtime environment, - wherein the application management system is designed and configured to detect an application, a deletion and / or a change in the software container and to register the software container with its respective execution status, wherein the application, the deletion and / or the change in the software container comprises in each case an allocation or release of resources in the respective automation device with container runtime environment, - wherein the system is designed and configured to authorize data traffic (11) of the first and second control applications to target devices (103, 301) and / or control applications following successful authentication in each case by means of an at least temporarily valid access key (12) inserted into the data traffic.