Secure Technology Module

The control system with a module inventory and identity verification method addresses the challenge of authenticating devices in modular installations, ensuring secure and reliable operation by validating device identities and certificates.

JP2025541689AActive Publication Date: 2025-12-23SIEMENS AG
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025529977
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-06-21
Filing Date
2023-11-22
Publication Date
2025-12-23
Estimated Expiration
2043-11-22

AI Technical Summary

Technical Problem

The existing methods for operating and monitoring technical installations with modular equipment face challenges in verifying the identity and authenticity of devices within the modules, particularly due to the 'black box' approach, which limits user inspection and exposes the system to risks of tampering and unauthorized device replacements.

Method used

A control system and method that integrates a computer-implemented module inventory to store and manage device-specific information, including certificates and identity checks, to ensure secure operation and monitoring of technical installations by verifying the authenticity of devices through a certificate validation process.

Benefits of technology

Ensures reliable operation and monitoring of technical installations by automatically validating device identities and certificates, preventing unauthorized devices from being integrated and maintaining secure communication within the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025541689000001_ABST
    Figure 2025541689000001_ABST
Patent Text Reader

Abstract

A method is proposed for operating and monitoring and / or generating automation by means of a control system (16) for a technological installation, in particular a manufacturing or processing installation, comprising: a) incorporating a technological module (1) into the control system (16), the technological module (1) having a plurality of technological devices (2, 3, 4, 5a, 5b, 5c, 6), the control system (16) retrieving information within the framework of the incorporation of a computer-implemented module inventory (9) of the technological module (1) and storing it in a computer-implemented control system inventory (30) of the control system (16), the information being configured for ID identification of the technological devices (2, 3, 4, 5a, 5b, 5c, 6) of the technological module (1); and b) generating operation and monitoring and / or automation for the technological installation taking into account the information of the technological module (1) stored in the computer-implemented control system inventory (30).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for operating and monitoring and / or automating a technical installation by means of a control system for the technical installation, and more particularly to a control system for a technical installation, in particular a processing or manufacturing installation.Furthermore, the present invention relates to a technical module having a plurality of technical devices and a computer-implemented module inventory, and adapted to be integrated into a control system for the technical installation, in particular a processing or manufacturing installation.

[0002] Particularly in the pharmaceutical and specialty chemical industries, there are high demands on operators of technical equipment to be able to react quickly to changing market requirements. Modular equipment allows equipment operators to significantly shorten the so-called "time to market" and to quickly react to changing market conditions by retrofitting the equipment at low cost. For this purpose, equipment operators can create pools of modular units (e.g., process units), which can be used to create specific equipment through so-called orchestration. If an equipment needs to be rebuilt, individual modules or package units are removed and replaced with other, e.g., more efficient, modules or package units.

[0003] A technological module or package unit is understood in this context to be a part of a technological installation that can be integrated as a closed unit into the central engineering part of the control system of the technological installation. A module is broader than an individual measuring point or technological device. A module can also mean a sub-installation of a technological installation that contains several technological devices (e.g. tanks) that in turn contain a complete process technological structure that contains several measuring points (e.g. valves, monitors, controllers, motors, etc.).

[0004] WO 2016 / 074730 describes a method for how modular technical installations can be created using self-descriptive information of modules, which is based on the self-descriptive information of the individual modules available online.

[0005] The "black box" approach of technical modules means that the internal structure with the installed technical devices remains hidden to the user, meaning that interaction with the module is limited to the processing connections and interfaces for orchestration (in the case of modules for processing equipment).

[0006] It is recommended to use secure communication (for example using OPC UA) both within the module and for any necessary interaction with the outside world. This means that the respective embedded devices require corresponding certificates. These certificates should be issued and signed by a trusted Certificate Authority (CA) and not self-signed (i.e. not issued and signed by the respective devices themselves), in accordance with current security recommendations.

[0007] Based on the "black box" approach, the user usually cannot inspect the identity and originality of the technical devices incorporated into the module, and therefore cannot verify, for example, whether the module contains manipulated devices that may cause damage in the environment in which the module is used when it is in operation.

[0008] If the manufacturer of a technical module uses a trusted certificate authority to issue and assign the certificates required for secure communication to installed devices, the periodic renewal of these certificates (recommended for security reasons) can only be carried out using the same certificate authority and thus with the involvement of the manufacturer while the module is in operation at the user. In the case of a device replacement, it is also desirable that the replaced device, after appropriate testing, is equipped with the certificates required for secure communication. However, in many cases, there is no connection between the environment and the manufacturer.

[0009] Devices installed in a technological module (e.g., industrial PCs, PLCs, sensors, actuators, HMIs, peripheral devices) often have a secure digital ID identifier in the form of a so-called "Initial Device ID Identifier (IDevID)", which is transmitted to the device by the manufacturer during module production. This type of "Initial Device ID Identifier" contains a private key securely stored on the device in accordance with the IEEE 802.1AR standard. Furthermore, the IDevID certificate corresponding to this private key (represented by an X.509 certificate and containing, among other things, the associated public key) also contains a corresponding certificate chain. Here, the certificate chain contains, as a trust anchor for the manufacturer, the certificate of the certification authority (CA) that issued the IDevID certificate, as well as the certificates of all intermediate CAs up to the root CA.

[0010] Validation of a secure digital identity identifier (often referred to as Proof of Originality) allows each device to be verified using appropriate methods (most simply, a TLS handshake, for example) to determine whether it is the original device, whose identity and its public key are derived from a private key securely stored on the device and other data in the IDevID certificate.

[0011] Even if the manufacturer of the technological module itself checks the identity / authenticity of each device based on the IDevID, there is still a risk that the automated technological devices present in the technological module may be subject to unknown and unauthorized replacement or tampering during the transport of the technological module to its specific place of use, during the initiation of operation / connection by the user, and even during operation at the user.

[0012] These problems are exacerbated by the fact that users generally do not know which devices are exactly embedded in a technology module. For example, when a device belonging to a product family from a given manufacturer is called out (e.g., based on a Root CA compromise), the user does not necessarily associate that information with the running technology module in which the device is embedded.

[0013] According to the current state of the art, a manufacturer / OEM that produces a technology module and integrates various devices within this module can issue the necessary application-specific certificates (in particular those required for OPC UA communication) from the Manufacturer / OEM PKI (including a so-called Issuing CA) and provide them to the devices. This ensures that secure communication between the integrated devices is possible using these certificates. Since the validity period of these certificates (preferably a maximum of two months according to previous recommendations) can expire before or during the operation of the technology module in the respective environment, means should be provided to renew the certificates (early, for example, two weeks before their validity period).

[0014] The problem underlying the present invention is to provide a simple and reliable method for generating control and monitoring for technical installations with reference to technical modules.

[0015] The above-mentioned problem is solved by a method for operating and monitoring and / or automating by means of a control system for a technical installation, in particular a processing or manufacturing installation, according to claim 1. The above-mentioned problem is further solved by a control system for a technical installation, in particular a processing or manufacturing installation, according to claim 7. The above-mentioned problem is further solved by a technical module having a plurality of technical devices and a computer-implemented module inventory, and which is adapted to be integrated into a control system for a technical installation, in particular a processing or manufacturing installation, according to claim 8.

[0016] A method for operating and monitoring and / or automating a technical installation, in particular a manufacturing or processing installation, by means of a control system, comprising: a) incorporating a technical module into a control system, the technical module having a plurality of technical devices, the control system retrieving information within the framework of the incorporation of a computer-implemented module inventory of the technical module and storing it in a computer-implemented control system inventory of the control system, the information being configured for ID identification of the technical devices of the technical module; b) To generate operation and monitoring and / or automation for technical installations, taking into account the information of technical modules stored in the computer-implemented control system inventory; Includes.

[0017] A technical module is understood to be a closed technical unit that can be integrated into a higher control level. Such a technical module can be, for example, an assembly of several measuring stations or a larger part of an industrial installation. However, the technical module does not necessarily have to originate from the field of industrial installations, but can also be, for example, an engine module of a car, a ship, etc.

[0018] In this context, a control system is understood to be a computer-assisted technical system that includes functions for operating, monitoring, and controlling a technical manufacturing or production facility. The control system here includes sensors and various actuators that calculate measured values. The control system also includes so-called process-related or production-related components that are used to control the actuators or sensors. Furthermore, the control system particularly includes means for visualizing and engineering the technical facility. The term control system is also intended to include additional computing units for more complex control, as well as systems for data storage and data processing.

[0019] Automation is understood to mean the autonomous (automated) detection and action on physical quantities by means of technical means of a control system, usually making machines, installations or other devices capable of working autonomously. Automation includes at least the parameterization of components of a technical installation and their interaction with other components.

[0020] According to the invention, information configured for the identification of the technical devices of a technical module is stored in a computer-implemented module inventory. During integration of the technical module into a control system, this information is retrieved by the control system from the module inventory of the technical module via a suitable interface, e.g., an OPC UA server implemented in the technical module, and transmitted to the control system inventory of the control system. The control system takes into account the retrieved information and generates operation and monitoring, i.e., visualizations that an operator can use to operate and monitor the technical installation, in particular the technical module. Alternatively, or (usually) additionally, the control system also generates automation for the technical installation, taking into account the received information about the individual technical devices of the technical module.

[0021] Preferably, the information includes certificates that allow identification and identity or authenticity checks of each device, where the identity or authenticity checks can be performed in interaction with the respective technical device. The control system can automatically evaluate the validity of the certificates here, and if one of the certificates is invalid, the technical module can be excluded from operation and monitoring, or can be excluded from automation of the technical installation.

[0022] The certificates can be issued by the certification authority of the manufacturer of the technology module, but it is also possible for the technology module to have its own certification authority that issues identity certificates to individual technology devices.

[0023] Particularly preferably, the information comprises a certificate chain for the technical device, each containing the certificate of the certificate authority that issued the respective certificate for the technical device and the certificates of all superior certificate authorities. If the certificates of the technical module are issued by a module internal certificate authority, the corresponding certificate chain can be transmitted to the control system in order to enable a certificate validation in accordance with RFC5280.

[0024] In the preferred case described above, certificates for devices integrated into the technical module are obtained via a suitable interface from the certification authority of the management system or the certification authority of the technical installation, which saves the costs of integrity-protected transmission of so-called "root CA" certificates to the communication partners of the technical module, since these certificates utilize the same certification authority.

[0025] The information preferably includes the respective firmware version, serial number, operating software update request, manufacturer name, device family, IP address, MAC address, time of authenticity check, and / or time of manual ID identification performed by the respective technical device.

[0026] The above object is further achieved by a control system for a technical installation, in particular a control system for a processing or manufacturing installation, which is adapted to carry out a method according to one of the preceding claims.

[0027] Furthermore, the above-mentioned object is achieved by a technological module having a plurality of technological devices and a computer-implemented module inventory and adapted to be integrated into a control system for a technological installation, in particular a processing or manufacturing installation, characterized in that the computer-implemented module inventory of the technological module stores information adapted by the control system for identification of the technological devices of the technological module.

[0028] Preferably, the information includes a certificate enabling the identification of each device (and a private key corresponding to the public key stored in the certificate and securely stored in the respective technical device). Identity / authenticity checks are usually performed solely by verifying the certificates. This verification usually also includes a step of proving that the respective device recognizes the private key corresponding to the public key contained in the certificate. The control system can automatically evaluate the validity of the certificates and, if any of the certificates are invalid, can exclude the technical module from operation and monitoring or from automation of the technical installation.

[0029] The certificates can be issued by the certification authority of the manufacturer of the technology module, although the technology module may also have its own certification authority that issues identity certificates to individual technology devices.

[0030] Particularly preferably, the information includes certificate chains for the technical devices, each of which includes the certificate of the certification authority that issued each certificate for the respective technical device and the certificates of all superior certification authorities.

[0031] Preferably, the information comprises so-called certificate blocklists for the technical devices, each issued by the certificate authority that issued the respective certificate for that technical device, where the certificate blocklist comprises the revoked certificates of the respective certificate authority, i.e. the revoked certificates.

[0032] In the framework of a preferred development of the technical module, the information meets the structural and content requirements of VDI / VDE / NAMUR guideline 2658 at the time of filing of this patent application. This means, inter alia, that in addition to the ID identification information relating to the technical devices integrated in the technical module, the information is stored in each of the following components: - installation images (in a standardized format) provided for operating and monitoring the technical devices included in the technical modules by the control system and visualized by the operator station client of the control system; - interface descriptions of the technological modules for operation, monitoring and automation of the technological modules in combination with other parts of the technological installation, which may contain process values ​​and alarms as well as so-called services; -Structural description of technological modules, e.g., structural description of various processing technological areas, such as buffer tanks, reactors, mixers, etc.; In this case, the installation image and the interface are mapped accordingly to the structural description, and the signals for controlling the mixer are presented to the operator, for example, via the installation image of the mixer.

[0033] The structure here, already known under the name "module type package" in accordance with VDI / VDE / NAMUR guideline 2658, is extended in the framework of the present invention by information indicating the identification. The method can include the following information: - manufacturer (e.g. Siemens); -Device family (e.g. S7-1500CPU); -Device ID, e.g. serial number (e.g. XYZ); - hardware version (e.g. 10007); -Firmware version (e.g. R29.44.53_00.00.00.00); -IP address (e.g. 172.27.232.44); -MAC address (e.g. 28:63:36:8D:C4:2A); -IDevID certificate (if present) (e.g. saved as a CER / DER file); - LDevID certificates (if any), e.g. device-specific LDevID genetic certificates or various application-specific LDevID application certificates, issued in the environment of use (more precisely, from a Public Key Infrastructure (PKI) or equivalent service for various purposes for devices run within the module or within the environment of use, i.e. within the technical installation) and applied to the device automatically (e.g. using standardized mechanisms such as OPC UA GDS Push-Pull or using protocols such as the Certificate Management Protocol (CMP)) or manually. In this case, the individual PKI components (e.g. registration authorities or local registration services, whose role can be taken over by the OPC UA Global Discovery Server) can be located inside the technical module and / or outside it and can be operated by the installation operator / appropriate service provider; - "Proof of Originality", abbreviated as "PoO" (e.g. 08:32, 28.12.2022), as a point of authenticity check, in particular to verify the IDevID certificate of the device, and thus its identity / authenticity, and which can be performed with or without user assistance (this is, for example, an essential step in the so-called secure device onboarding framework); - "ID verification" (e.g., 09:33, 28.12.2022) as a point of device identification, which can be achieved, for example, by scanning (e.g., by an authorized user) a QR code printed on the device's casing. Within this process, device data can be read out, presented to the user, and compared with subsequently available information. It is important to note that in this context, a device can assert its identity but cannot verify it (similar to the proof of authenticity described above). This option is therefore considered unfounded from a cybersecurity perspective. For existing or older devices, it is highly recommended from a security perspective to at least enable user-assisted identification, or even to implement mandatory identification.

[0034] Preferably, the technology module has a computer-implemented registration service configured to calculate and store information about technology devices in the technology module in a computer-implemented module inventory based on a manual request, automatically at predetermined times, or event-controlled.

[0035] In addition to the identity checks described above, the computer-implemented registration service may include further appropriate, possibly configurable, check steps. For example, a predetermined comparison of the device's technical data / characteristics with a reference device may be performed both at startup and during runtime device replacement. The registration process may be initiated automatically (e.g., by the embedded device discovering the registration service) or may be triggered by the user, for example by discovering the registration service using an appropriate mDNS-like discovery method or by using pre-configured address data.

[0036] The registration service may also, based on a manual request, based on replacement of one of the technical devices, or automatically at a predetermined time or under event control, calculate information about the technical device in the technical module, perform an identity or authenticity check on the device, and store information about the technical device together with the identity / authenticity check status and / or a corresponding flag in a computer-implemented module inventory.

[0037] Particularly preferably, the registration service is configured to trigger, by replacing one of the technical devices in the technical module, that information about the technical device be calculated and stored in the computer-implemented module inventory. Thus, the trigger for calling the registration service can be a device replacement that is recognized and accordingly reported during the runtime of the technical module or technical installation, in which case a replacement device integrated into the technical module should be registered accordingly. Here, if it is determined (e.g., during initial startup or device replacement) that an integrated device has an invalid and / or expired IDevID certificate, the user is accordingly notified or a corresponding policy is taken into account when another appropriate action is triggered. If the identity check based on the IDevID certificate of the integrated device proceeds successfully, all devices are included in the module inventory together with their verified certificate.

[0038] The above-mentioned characteristics, features and advantages of the present invention and how they are achieved will be more clearly and distinctly understood in connection with the following description of the embodiments, which is set forth in more detail in connection with the accompanying drawings. [Brief explanation of the drawings]

[0039] [Figure 1] 1 is a schematic diagram showing a technology module according to the present invention; [Figure 2] FIG. 2 illustrates an object model for a technology module. [Figure 3] 1 is a schematic diagram illustrating a control system according to the present invention;

[0040] 1 shows a technological module 1, which includes a server 2, a visualization device 3, an automation device 4, peripheral devices 5a, 5b, 5c, and a number of sensors and actuators 6. The technological module 1 also has connections 7a, 7b for (e.g., process-technical) connection to other technological modules or components of a technological installation, for example a processing installation. Furthermore, the technological module 1 has an interface 8.

[0041] Via the interface 8, the technical module 1 can be connected to a higher control level, such as a control system (see FIG. 3 ), which can include, for example, an OPC UA server that can be used for software integration of the technical module 1 into the control system.

[0042] In the technical module 1, for example in the server 2, a module inventory 9 is computer-implemented. The module inventory 9 of the technical module 1 stores information generated by the control system for the identification of the technical devices 2, 3, 4, 5a, 5b, 6 of the technical module 1.

[0043] The information meets the structural and content requirements of the VDI / VDE / NAMUR guideline 2658, which is prior at the time of filing the present patent application. An object model of the information relating to a technical module 1 is shown in Figure 2. According to the guideline VDI / VDE / NAMUR 2658, the description 10 of a technical module 1 comprises an installation image 11, an interface 12 and a coarse structural structure 13 of the technical module 1.

[0044] Additionally, the description herein includes an inventory record 14 of the technical devices 2, 3, 4, 5a, 5b, 6 of the technical module 1. The inventory record 14 includes a list 15 of all devices 2, 3, 4, 5a, 5b, 6 contained in the technical module 1, said list 15 enabling identification of the technical devices 2, 3, 4, 5a, 5b, 6 of the technical module 1 in a control system connected to the technical module 1.

[0045] 3 shows a schematic representation of a control system 16 for operating and monitoring a technical installation configured as a processing facility. The control system 16 includes an operator station server 17 and an operator station client 18. The operator station server 17 and the operator station client 18 are connected to each other via a terminal bus 19 and, optionally, to other components of the control system 16, not shown, such as an archive server.

[0046] A user or operator can access the operator station server 17 for the purpose of operating and monitoring the operator station clients 18 using a terminal bus 19. The terminal bus 19 can be configured as, for example, but not limited to, an industrial Ethernet.

[0047] The operator station server 17 has a device interface 20 and an OPC UA server 21, which are connected to an installation bus 22. Via the device interface 20, the operator station server 17 is connected to and can communicate with automation devices 23 and other components of the process technology installation, such as peripheral devices 24. These other components are external to the technology module 1. The technology module 1 is (removably) connected to the other components 24 of the technology installation via a process connection 7b. The installation bus 22 can be configured as, for example, but not limited to, an Industrial Ethernet.

[0048] The operator station server 17 further comprises a visualization service 25, a process mapping 26, an orchestration service 27, and a certificate monitoring service 28. The process mapping 26 stores a single instantaneous record of the (signal) states of the connected devices 24 and / or applications. The orchestration service 27 is configured to incorporate the technical modules 1 (on the software side) into operation and monitoring and to automate the technical installation. In other words, the orchestration service 27 performs orchestration, i.e., the drive control of the technical modules 1 and their coordination with the technical (method-technical) installation. For orchestration, the process values ​​and services of the technical modules 1 are read and written by the orchestration service 27 via the process mapping 26 of the operator station server 17 and the OPC UA server 21. Higher-level operation and monitoring by an operator is performed via the operator station client 18. In the operator station client 18, the installation images required for operation and monitoring are visualized for the technical modules 1 and for the rest of the (method-technical) installation. The certificate monitoring service 28 monitors the validity of the certificates of the technical devices 2, 3, 4, 5a, 5b, 5c, 6 of the technical module 1, as will be explained in more detail below. The technical installation further comprises a certificate authority 29 and a control system inventory 30.

[0049] A visualization service 25 integrated in the operator station server 17 initiates the transmission of visualization information to the operator station client 18. The operator station client 18 is further configured to display visualizations, i.e., in particular graphical representations of facility images and hierarchies, for operating and monitoring the processing facility.

[0050] As already mentioned above, the technological module 1 comprises a computer-implemented module inventory 9. The module inventory 9 of the technological module 1 stores information configured by the control system for the identification of the technological devices 2, 3, 4, 5a, 5b, 6 of the technological module 1. The technological module 1 further comprises a computer-implemented registration service 31, a certificate management service 32, a monitoring service 33 and a module certification authority 34 integrated in the technological module.

[0051] The registration service 31 is configured to calculate and verify or validate the identity of the technical devices 2, 3, 4, 5a, 5b, 6 installed in the technical module. This is done, for example, based on their DevID certificates. These may be, for example, IDevID manufacturer certificates issued by the manufacturer of the technical module 1 or LDevID-OEM certificates issued by the OEM. The identities of the technical devices 2, 3, 4, 5a, 5b, 6, including their certificates, are stored in the module inverter 9 by the registration service 31. In addition to the above-mentioned identity check, the registration service can perform further appropriate, possibly configurable, check steps. For example, it can perform a predefined comparison of the technical data / technical characteristics of the technical devices 2, 3, 4, 5a, 5b, 6 with a reference device, both at the start of operation and when a device is replaced. Note that the role of the reference device is assumed, for example, by the original device to be replaced during runtime.

[0052] In this case, the registration process can be triggered automatically, for example by the embedded device determining the registration service 31, for example using a suitable discovery method, for example DNS, or using pre-configured address data, and transmitting this ID identification data to itself. Alternatively, the process can also be triggered by a user or another process.

[0053] Another trigger for calling the registration service 31 may be a device replacement during runtime of the technical module 1, which is recognized by the monitoring service 33 and accordingly left alone, in which case it is desirable for a replacement device integrated into the technical module 1 to be registered accordingly. In this case, if it is determined (for example in the framework of initial startup or device replacement) that an integrated technical device 2, 3, 4, 5a, 5b, 5c, 6 has an invalid and / or expired IDevID certificate, the user is informed accordingly or a corresponding policy is taken into account when another appropriate action is triggered. Once the identity check based on the IDevID certificates of the integrated technical devices 2, 3, 4, 5a, 5b, 5c, 6 has proceeded successfully, all technical devices 2, 3, 4, 5a, 5b, 5c, 6 are included in the module inventory 9, including their checked certificates.

[0054] The module inventory 9 represents an overview of the technical devices 2, 3, 4, 5a, 5b, 5c, 6 integrated into the technical module 1 together with their IDevID or LDevID certificates (which may include LDevID certificates on the one hand and so-called application-specific LDevID application certificates on the other hand). The module inventory 9 is issued with certificates (issued by the OEM when assembling the package unit and by the user at start-up / orchestration) after the initial design and throughout the entire lifecycle of the technical module 1, and is kept up to date. In addition to device-specific data and certificates, the module inventory 9 also stores the state of the last identity check. For example, an identity check performed by the OEM is called "Proof of Initial Device Identity", while a check performed by the user or in the context of an orchestration in the user's environment is called "Proof of Locally-Significant OEM Device Identity".

[0055] The certificate monitoring service 32 is in particular authorized to roll out module-specific or usage environment-specific LDevID generic certificates, which are requested either from an internal certificate authority 34 embedded in the technology module or from a certificate authority 29 of the technology installation embedded in the technology module 1. Furthermore, this service is also authorized to trigger the renewal or revocation of certificates for the technology devices 2, 3, 4, 5a, 5b, 5c, 6 according to the monitoring status notified by the monitoring service 33, and to notify the module inventory 9 of renewed or revoked certificates.

[0056] To enable the rollout of device-specific and application-specific certificates, the technology module 1 is provided with a suitable interface with a certificate authority 34 (possibly together with other authentication services belonging to it) and an OPC UA interface 8, via which the technology module 1 can be integrated into the respective environment of use (in particular into the public key infrastructure operating in this environment of use). In a preferred case, the aforementioned interface 8 is activated by establishing a certificate-based trust relationship between the registration service 31 and the certificate authority 29 of the user's environment of use. The establishment of the trust relationship can take place within the framework of the orchestration of the technology module 1 at the user. It is important to note here that each technology module 1 usually has at least one certificate-based communication relationship to a device external to the technology module 1.

[0057] If the technology module 1 certificates used to protect these communication relationships are issued by an internal certificate authority 34, the corresponding certificate chain, including the integrity-protected root CA certificate, must be transmitted to the technology module 1 communication partners to enable a certificate validation check in accordance with RFC5280.

[0058] Alternatively, the certificates for the technical devices 2, 3, 4, 5a, 5b, 5c, 6 integrated in the technical module are obtained from the user's certificate authority 29 via the above-mentioned interface 8. In this case, the costs for the integrity-protected transmission of the root CA certificate to the communication partner are saved, since the same public key infrastructure is used.

[0059] The technical module 1 is made up of devices 2, 3, 4, 5a, 5b, 5c, 6 and is executed by a registration service 31 that has successfully verified (more precisely from a securely operating Issuing CA) and is able to issue module-specific IDevID or LDevID certificates based on appropriate identity verification of each embedded technical device 2, 3, 4, 5a, 5b, 5c, 6. In this case, the certificate request is made using a certificate management service 32, taking into account the entries in the module inventory 9 and the status detected by a monitoring service 33.

[0060] As soon as the monitoring service 33 notifies of an unacceptable change that negatively affects the trustworthiness of the technical module 1 described herein, the aforementioned module-specific IDevID or LDevID certificate (possibly transmitted in a user interaction) is revoked. If other devices integrated in the respective environment of use communicate with the technical module 1, the aforementioned module-specific certificate is checked within the framework of an additional check. In this way, it is possible to prevent (in cases requiring immediate action) a less trusted technical module 1 from communicating with other devices in the technical installation and possibly causing damage.

[0061] The "private keys" for the module-specific IDevID or LDevID certificates mentioned above are stored in a hardware or software secure element of the technological devices 2, 3, 4, 5a, 5b, 5c, 6 integrated into the technological module 1. The same secure element already used by one technological device 2, 3, 4, 5a, 5b, 5c, 6 in which the private key is stored is also used by the entire technological module 1 for secure storage of the private key. In this case, in the event of a device exchange during runtime and a check is performed by the registration service 31, a new key pair is generated and a certificate is requested not only for each technological device 2, 3, 4, 5a, 5b, 5c, 6 but also for the entire technological module 1 in addition. Alternatively, the "private keys" mentioned above may be stored in a hardware or software secure element separately and securely integrated into the technological module 1.

[0062] The above-mentioned services 31, 32, 33 of the technological module 1 are located in suitable components / devices, such as IoT devices, etc. In this case, it is certainly possible to use technological devices 2, 3, 4, 5a, 5b, 5c, 6 that are already integrated and used for other purposes as a platform for the above-mentioned services 31, 32, 33. However, in particular from the viewpoint of cybersecurity and availability, it proves advantageous to use dedicated devices as a platform for these services 31, 32, 33, which are integrated into the technological module 1 or which are provided via one or more suitable interfaces appropriate in the respective environment of use.

Claims

1. A method for operating and monitoring and / or automating a technical installation (16) by means of a control system (16) for a technical installation, in particular a manufacturing or processing installation, comprising: a) incorporating a technological module (1) into the control system (16), the technological module (1) comprising a number of technological devices (2, 3, 4, 5a, 5b, 5c, 6), the control system (16) retrieving information within the framework of the incorporation of a computer-implemented module inventory (9) of the technological module (1) and storing it in a computer-implemented control system inventory (30) of the control system (16), the information being configured for ID identification of the technological devices (2, 3, 4, 5a, 5b, 5c, 6) of the technological module (1); b) generating operation and monitoring and / or automation for said technical installations taking into account the information of said technical modules (1) stored in said computer-implemented control system inventory (30); A method comprising:

2. 2. The method of claim 1, wherein said information comprises a certificate based on which an identification and authenticity or identity check of each technical device (2, 3, 4, 5a, 5b, 5c, 6) can be performed.

3. 3. The method according to claim 2, wherein the control system (16) automatically evaluates the validity of the certificates and, if one of the certificates is invalid, the technical module (1) is excluded from operation and monitoring or automation for the technical installation.

4. 4. The method according to claim 2 or 3, wherein the certificate is issued by a certification authority of the manufacturer of the technological module (1).

5. 5. The method according to claim 2, wherein the information includes a certificate chain for each of the technical devices, the certificate chain including a certificate of a certification authority that issued each certificate for each of the technical devices and certificates of all higher-level certification authorities.

6. 6. The method according to claim 1, wherein the information includes the respective firmware version, serial number, operating software update request, manufacturer name, device family, IP address, MAC address, time of authenticity check, and / or time of manually performed ID identification of each technical device (2, 3, 4, 5a, 5b, 5c, 6).

7. A control system (16) for a technical installation, in particular a processing or manufacturing installation, comprising: configured to carry out the method according to any one of claims 1 to 6, Control system (16).

8. a control system (16) for a technical installation, in particular a processing or manufacturing installation, comprising a plurality of technical devices (2, 3, 4, 5a, 5b, 5c, 6) and a computer-implemented module inventory (9); In the technology module (1), The computer-implemented module inventory (9) of the technology module (1) stores information configured for identification of the technology devices (2, 3, 4, 5a, 5b, 5c, 6) of the technology module (1) by the control system (16). A technological module (1).

9. 9. The technological module (1) according to claim 8, wherein said information comprises a certificate based on which an identification and authenticity or identity check of each technological device (2, 3, 4, 5a, 5b, 5c, 6) can be performed.

10. 10. The technological module (1) according to claim 9, wherein the certificate is issued by a certificate authority (29, 34) of the manufacturer of the technological module (1).

11. 11. The technical module (1) according to claim 9 or 10, wherein the information comprises certificate chains for the technical devices (2, 3, 4, 5a, 5b, 5c, 6), each of the certificate chains comprising a certificate of a certification authority (29, 34) that issued each certificate for each technical device (2, 3, 4, 5a, 5b, 5c, 6) and certificates of all superior certification authorities.

12. 12. The technical module (1) according to any one of claims 8 to 11, wherein the information comprises the respective firmware version, serial number, operating software update request, manufacturer name, device family, IP address, MAC address, time of authenticity check and / or time of manually performed ID identification of each technical device (2, 3, 4, 5a, 5b, 5c, 6).

13. 13. The technical module (1) according to any one of claims 8 to 12, wherein the information meets the structural and content requirements of the VDI / VDE / NAMUR guideline 2658, which is prior at the time of filing the present patent application.

14. The technology module (1) has a computer-implemented registration service (31) configured to calculate and store information about the technology devices (2, 3, 4, 5a, 5b, 5c, 6) in the computer-implemented module inventory (9) based on a manual request or automatically at a predetermined point in time within the technology module (1), Technological module (1) according to any one of claims 8 to 13.

15. 15. The technology module (1) according to claim 14, wherein the registration service (31) is configured such that replacement of one of the technology devices (2, 3, 4, 5a, 5b, 5c, 6) triggers in the technology module (1) the calculation of information about the technology device (2, 3, 4, 5a, 5b, 5c, 6) and its storage in the computer-implemented module inventory (9).

Citation Information

Patent Citations

  • Cryptographic certificates for an industrial controller

    EP3700160A1

  • Automated public key infrastructure initialization

    JP2020022165A

  • Security system for use in implementing highly-versatile field device and communication network in control and automation system

    JP2022046423A

  • Authenticated backplane access

    US20190236313A1

  • Single authentication portal for diverse industrial network protocols across multiple OSI layers

    US20190245856A1