Secure Remote Access to Industrial Control Systems Using Hardware-Based Authentication
The system addresses the need for secure remote access to industrial control systems by employing hardware-based authentication methods, including smart cards and managed appliances, to enforce layered security and policy management, thereby reducing cybersecurity risks and operational costs.
Patent Information
- Application Number
- JP2022573446
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-05-29
- Filing Date
- 2021-05-31
- Publication Date
- 2026-01-07
- Estimated Expiration
- 2041-05-31
AI Technical Summary
There is an increasing need for secure remote access to industrial control systems to mitigate cyber attack vectors in digitized and interconnected critical control networks, such as those of electric utility companies, while ensuring robust authentication and authorization.
A system and method for secure remote access using hardware-based authentication, including secure user authentication, secure interactive and machine-to-machine remote access, and remote access services, utilizing smart cards with biometric and multi-factor authentication, and a managed remote access appliance with virtual machines, to enforce layered security and policy management.
The solution provides strong authentication and enhanced safeguards, significantly reducing cybersecurity risks and operational costs by preventing credential theft and ensuring secure, auditable remote access to industrial control systems.
Smart Images

Figure 0007795480000001 
Figure 0007795480000002
Abstract
Description
[Technical Field]
[0001] The present invention relates to a system and method for secure remote access to industrial control systems using hardware-based authentication. [Background technology]
[0002] There is an increasing need for employees and vendors to remotely access industrial control systems for monitoring, troubleshooting, and maintenance. As critical control networks become more digitized and interconnected, secure remote access is necessary to reduce the risk of cyber attack vectors for critical industrial control networks, such as those of electric utility companies. Summary of the Invention [Means for solving the problem]
[0003] A system for secure remote access to industrial control systems, such as those of a power utility, using hardware-based authentication is provided, the system including secure user authentication, secure interactive remote access or secure machine-to-machine remote access or communication, and remote access services.
[0004] Also provided is a method for secure remote access to an industrial control system, the method including the steps of providing a system for secure remote access to an industrial control system using hardware-based authentication, performing secure user authentication, providing secure interactive remote access or secure machine-to-machine remote access or communication, and providing a remote access service. [Brief explanation of the drawings]
[0005] [Figure 1] 1 is a schematic diagram of a system for secure remote access to an industrial control system. [Figure 2]1 is an end-user authentication flow diagram for a system for secure remote access to industrial control systems. DETAILED DESCRIPTION OF THE INVENTION
[0006] A system and method for secure remote access to industrial control systems using hardware-based authentication is provided, including secure user authentication, secure interactive remote access or secure machine-to-machine remote access or communication, and remote access services.
[0007] Secure user authentication is provided by secure two-factor authentication (2FA) or secure three-factor authentication (3FA) based on smart cards in a plastic ID card form factor with contact and contactless interfaces. Secure two-factor user authentication requires possession of a smart card and knowledge of the corresponding personal identification number (PIN). Three-factor authentication also performs biometric authentication, which is the confirmation of a biological characteristic, including, but not limited to, a retina scan, iris scan, fingerprint scan, finger vein scan, facial recognition, voice recognition, handprint recognition, and ear recognition. This authentication allows for multi-stage verification of session authorization via third-party verification. Four-factor authentication (4FA) can employ an additional factor: location. Distributed keys and credentials secured within the smart card hardware provide secure key management and storage, enabling identity proofing and authentication at the NIST IAL3 and AAL3 levels, according to guidelines provided by the National Institute of Standards and Technology in NIST Special Publication 800-63-3. An example of a suitable smart card is Tyfone's SideCard®.
[0008] Secure interactive remote access can be provided through a secure, hardened, stateless software appliance. A managed remote access appliance (RAA) with virtual machines and software is used to initiate remote access to an industrial plant uniformly from any remote access workstation, which can be dedicated, managed, or unmanaged. The appliance's underlying virtual machine provides a controlled environment that can be managed by policy, even when invoked from an unmanaged workstation. The appliance can be used solely with smart card credentials. Local authentication credentials to the appliance are separate from certificate-based remote access authentication to the plant network, both of which are stored on the smart card. Secure interactive remote access can be provided through secure machine-to-machine remote access or communication.
[0009] Remote access services may include, but are not limited to, technical cybersecurity control services that automate security policies and processes for user and token lifecycle management, software configuration management, access control and authentication using layered security, and remote access audit trails. Layered security can allow two or more individuals to be involved in authorizing scheduled and unscheduled remote access to an industrial plant, and audit logs provide an additional level of control in the security policies of plants that wish to enable secure remote access to their plant infrastructure.
[0010] Smart cards can be equipped with hardware endpoint security technology, including ISO 7816 contact interfaces, ISO 14443A contactless interfaces, and Bluetooth (BLE) interfaces, providing the flexibility to be used for omnichannel security for digital transactions alongside physical transactions across mobile and non-mobile devices. Platform-agnostic low-level interface specifications and platform-specific high-level API libraries are available for smart cards, which can optionally interoperate with digital security platforms for identity and transactions, providing layered, step-up security that supports all NIST assurance levels, including the highest in the industry, without compromising convenience and ease of use. Smart cards enable organizations to implement decentralized user authentication in a convenient and familiar form factor, providing strong authentication and enhanced safeguards, significantly reducing cybersecurity risks and operational costs.
[0011] The smart card's Secure Element (SE) provides the highest level of built-in tamper resistance, secure storage, and hardware encryption. The Secure Element allows for the storage of credentials, cryptographic keys, and X.509 certificates, making them impossible for hackers to extract. The Secure Element stores the PIN and 2048-bit RSA private key along with the associated X.509 certificate. The PIN resides in the Secure Element's EEPROM (Electrically Erasable Programmable Read-Only) as a PIN object and cannot be extracted. The PIN cannot be stolen. Once the old PIN is known, it can be changed. The private key resides in the Secure Element's EEPROM as a PrivateKey object and cannot be extracted. The private key can be deleted, and once the PIN is known, a new one can be created. The private key cannot be stolen. The Secure Element is NIST FIPS 140-2 certified and tamper-proof. The private key is used to sign transactions. Access to the Secure Element in the smart card is granted only after successful authentication using the PIN. The maximum number of incorrect PIN entries is limited. If the maximum number of PIN entries exceeds a set value, the card will be blocked and will need to be reconfigured by an administrator, for example using a personalization kiosk, before it can be used by the user.
[0012] Three types of smart cards can be provided depending on the individual's role in the system, including administrator, supervisor, and remote user. All three types of cards are provided with a client user certificate generated on the secure element. Smart cards can communicate with other devices using a contact interface, such as a smart card reader, or a contactless interface, such as Bluetooth (BLE) or radio frequency identification (RFID).
[0013] The remote access service enables management of remote access authorization and policies and layered security controls along with user, smart card token, and appliance (virtual machine and software) status. The remote access service implements technical cybersecurity controls to manage and audit interactive remote access. The supervisor mobile application implements layered security controls for remote access authorization and access control, with two-factor authentication using smart cards performed on mobile devices. The administrator mobile tablet application implements layered security controls for remote access authorization and access control, with two-factor authentication using smart cards performed on mobile tablet devices.
[0014] Remote access services are responsible for storing user plant information and validating access requests using data exchange over a mutually authenticated Transport Layer Security (TLS) channel, as well as technical cybersecurity control services. Security controls follow the guidelines of the National Institute of Standards and Technology document "NIST SP800-53 rev.4." Technical cybersecurity control services may include, but are not limited to, account management, access control, information flow enforcement, failed login control, system use notification, concurrent session control, session termination, authorized actions without identification or authentication, security attributes and transmission, remote access, auditable events, audit records and storage capacity, audit review and analysis, audit reporting, time stamps, non-repudiation, identification and authentication, denial of service protection, transmission integrity and confidentiality, use of cryptography, public key infrastructure certificates, protection of stored information, virtualization technologies, malicious code protection, software and information integrity control, information entry restrictions, and protection against malware.
[0015] The account management system can include three types of roles: administrator, supervisor, and at least one end user. Administrators can create, modify, or delete other administrators, supervisors, and end users. Administrators can also create access schedules for end users, which must be authorized by a supervisor. Supervisors have the privilege to grant or deny access to workstations to users. End users can have scheduled or unscheduled access to workstations. Individual identities are established using smart cards protected by localized PINs. For access control, administrators have the access to configure plants, users, and workstations and associate users with plants and workstations. Administrators also have access to provisioning tools used to create users and provide smart cards to users. Supervisors have access to authorization requests through the supervisor application and have the privilege to grant or deny scheduled or unscheduled access requests. End users can access workstations if access is scheduled or can request unscheduled access. End users do not have access to administrator and supervisor tools. Supervisors do not have access to administrator and end user tools.
[0016] Certain actions may be permitted without identification or authentication. In supervisor and administrator applications, users of the application can view notifications; however, they cannot perform actions on notifications until the user is authenticated using a smart card and PIN. A session is created upon successful login and terminated upon logout. Multiple concurrent sessions may be possible. System usage notifications are sent to supervisors informing them of end-user logins, logouts, and workstation access. In the event of a failed login, access to the private key in the secure element of the smart card is protected by a PIN. If an incorrect PIN is entered, the user is prompted to re-enter the PIN. There is a maximum limit on the number of incorrect PIN attempts. If the maximum number of PIN attempts exceeds a set value, the card is blocked. The smart card will need to be reconfigured by an administrator, for example, using a personalization kiosk, before it can be used by the user.
[0017] Remote access to workstations can be scheduled or unscheduled. However, access to workstations requires prior authorization by a supervisor. Auditable events and audit record content include all transaction events securely stored in a database, with storage capacity limited only by the size allocated to the database server. Time stamps are stored according to Coordinated Universal Time (UTC). Non-repudiation is achieved through digital signatures in the RSA cryptosystem, and transaction information is stored in the database for auditing. For identification and authentication, an administrator physically identifies an individual at the time of provisioning and then assigns a smart card to the user. During authentication, the user must provide a PIN for the smart card. Authentication occurs over a mutually authenticated TLS channel, where the user and server certificates are verified.
[0018] In a specific embodiment, cryptographic standards in accordance with Federal Information Processing Standards Publication 140-2 (FIPS 140-2), entitled "Security Requirements for Cryptographic Modules," are used. For public key infrastructure certificates, a valid certification authority (CA) must provide user certificates. RSA (2048-bit key) X.509 certificates are used as user certificates. Virtualization technology requires a remote access appliance (RAA) operating in kiosk mode. Malicious code protection is achieved through application integrity checking. For sensitive data entry, information entry restrictions are designed using a randomized software PIN pad. This protects the system from keylogging and screen scraping.
[0019] A simple high-level architectural diagram of one embodiment of secure remote access to industrial control systems in a single plant network is shown in Figure 1. This diagram provides a high-level overview of the system, with key elements and data flows. The system provides a secure, distributed, and auditable approach to remote access without interfering with existing software technologies, such as session monitoring software and legacy remote access. While the description pertains to a single industrial plant, the underlying architecture can be used for multiple industrial plants. In a multi-plant deployment, the u4ia Digital Security Platform would operate collaboratively across all plants, and each plant would have its own independent u4ia instance for fault tolerance.
[0020] According to certain exemplary embodiments, the key elements of secure remote access to the industrial control system 10 of FIG. 1 include a remote access (RA) device 102, which may be a laptop configured with appropriate software and communicates with cloud computing 104 over the Internet; a remote access physical or logical boundary network or screened subnetwork known in computer security as a demilitarized zone (DMZ) 112, such as a collection of servers and software such as those offered by Tyfone's SideAssure; and a plant control network 120. The remote access DMZ 112 includes a secure virtual private network (VPN) end endpoint 114, a secure jump host 116, and an authentication appliance: a u4ia server 118. The plant control network 120 includes a personalization kiosk 126, which may be a laptop configured with software used to issue and manage SideCard devices; at least one engineering workstation 124, which is a target computer in the client network to which remote access is provided; and a Windows Active Directory domain controller 122, which mediates logon and policy access for users and machines in the plant control network. In this description, an engineering workstation is an example of a control system component. In another embodiment, the control system component may include, but is not limited to, a security workstation, a human-machine interface (HMI), a supervisory workstation, a log server, a historian, or any control system component capable of utilizing a group policy structure. Also, the control system component may be any Incident Command System (ICS) component for machine-to-machine communication, including, but not limited to, a programmable logic controller (PLC) to human-machine interface (HMI) or PLC-to-PLC communication.
[0021] In the illustrated embodiment, Internet access 104 with appropriate bandwidth and latency characteristics enters the plant management network 108 from the remote access (RA) device 102 through a firewall 106. The plant management network 108 can be connected to the remote access DMZ 112 network by direct connection or through a firewall gateway 110. If through a firewall gateway, rules must be configured as needed to allow necessary ingress and egress to the remote access DMZ 112. The remote access DMZ 112 can be connected to the plant control network through the firewall gateway 110, with rules configured as needed to allow ingress and egress from the DMZ to specific engineering workstations 124. Because the plant operator is ultimately responsible for plant network security, the plant operator typically maintains control of all firewalls and network monitoring. The plant control network 120 is isolated from other networks and, specifically, does not include a path to the Internet for either inbound or outbound traffic.
[0022] An end-user authorization flow diagram for a system and method for secure remote access to an industrial control system 20 is shown in Figure 2 for scheduled user access to a workstation. According to this exemplary embodiment, a system for secure remote access to an industrial control system using hardware-based authentication includes secure user authentication originating from a secure user with a SideCard 200, secure interactive remote access 210, and remote access services 220.
[0023] In step 1, a secure user 200 with a side card inserts the smart card (side card) into a card reader and enters a PIN (201). A remote access appliance (RAA) virtual machine for secure interactive remote access 210 is opened, which verifies the PIN and requests a certificate (202) in step 2. In step 3, the smart card provides a user certificate to the remote access appliance for secure interactive remote access 210 (203). Using the user certificate and the certificate of the remote access service (RAS) 220, a mutually authenticated TLS channel is established in step 4 (211). The remote access service 220 comprises a server containing plant information and the u4ia digital security platform.
[0024] In step 5, the secure interactive remote access appliance (RAA) 210 sends the user credentials to the remote access service (RAS) 220 (212). In step 6, the remote access service 220 verifies the user credentials and sends a user information object to the secure interactive remote access 210 (213). In step 7, the secure interactive remote access 210 sends a request for plant and workstation details to the remote access service 220 (214). In step 8, the remote access service 220 sends the plant and workstation details to the secure interactive remote access 210 (215). In step 9, the secure interactive remote access 210 sends a scheduled workstation access request to the remote access service 220 (216). In step 10, the remote access service 220 checks the rules associated with the end user and workstation based on the access time and determines that the access is scheduled (217).
[0025] A scheduled request does not require plant supervisor approval. In step 11, secure interactive remote access 210 connects to a virtual private network (VPN), then to a remote desktop protocol (RDP) gateway, and finally to an engineering workstation (218) within plant control network 230. If the request was unscheduled, plant supervisor approval would be required to access the workstation.
[0026] The systems and methods provided herein, including secure user authentication, secure interactive or machine-to-machine remote access or communication, and remote access services for secure remote access to industrial control systems using hardware-based authentication, implement many important and advantageous attributes. Distributed Secure Element (DSE) physical tokens connected via contact or contactless interfaces prevent mass theft and remote credential harvesting and enable loss recognition, allowing lost or stolen access cards to be easily located by users. Layered defenses are provided by strong cryptography and routing traffic through multiple checkpoints, requiring asymmetric (NIST LOA3) strong cryptographic authentication, with the highest level of NIST 800-63 Authenticator Assurance Level (AAL) enabled, Level 3.
[0027] The provided system and method for secure remote access to industrial control systems is a comprehensive solution that implements industry best practices for complete solutions for control systems and mitigates host (user device) compromise by utilizing a stateless guest operating system, guest integrity validation, and a hardened guest operating system. Access control lists are used to filter inbound traffic and limit outbound traffic, and access control is granted independently on a per-session basis, either by design or by design. The network is monitored, traffic is logged, and traffic flows are audited. Remote Desktop Protocol (RDP) shadowing and forced session termination are also possible. The provided system and method for secure remote access utilizes a virtual private network (VPN) and is easily integrated into existing architectures.
[0028] Example By way of example and not limitation, examples of the presented systems and methods for secure remote access to industrial control systems using hardware-based authentication may include secure user authentication, secure interactive remote access or secure machine-to-machine remote access or communication, and remote access services.
[0029] 1. The end user inserts their smart card into a card reader that has a Remote Access Appliance (RAA) virtual machine open. This is a Windows kiosk virtual machine that the end user uses to access workstations within the plant. 2. The user enters the smart card's personal identification number (PIN) and the remote access appliance sends a "Verify PIN" request to the smart card. 3. The smart card verifies the user's PIN. 4. If the entered PIN is incorrect, the user will be asked to re-enter the PIN. There is a limit to the maximum number of incorrect PIN attempts. If the maximum number of PIN attempts exceeds a set value, the card will be blocked and will need to be reconfigured by an administrator, for example using a personalization kiosk, to be usable by the user. 5. If the entered PIN is correct, the remote access appliance prompts the smart card for user certificate details. 6. The smart card provides the user certificate to the remote access appliance. Note that this certificate only contains information about the public key. 7. A mutually authenticated TLS channel is established using the user's certificate and the certificate of the Remote Access Service (RAS), which is a server containing plant information and the u4ia Digital Security Platform. 8. The Remote Access Appliance (RAA) sends the user credentials to the Remote Access Service (RAS). 9. The remote access service validates the user certificate with the issuer certificate. 10. If the user certificate is valid, the user information is sent to the remote access appliance. 11. The remote access appliance sends a request to the remote access service to obtain information about the plant and workstations. 12. The Remote Access Service sends plant and workstation information to the Remote Access Appliance. 13. The end user selects the workstation to which they require access. The remote access appliance sends this request to the remote access service. 14. The remote access service checks the policies associated with the end user and workstation based on the time of access to determine whether it is unscheduled or scheduled access. 15. Scheduled requests do not require plant supervisor approval. The remote access appliance connects to a virtual private network (VPN), then to a remote desktop protocol (RDP) gateway, and finally to the workstation. Access to the virtual private network, remote desktop protocol gateway, and workstation requires a smart card. The user's PIN is automatically entered by the remote access appliance. 16. If the request is unscheduled, access to the workstation shall require authorization from the plant supervisor. The remote access appliance shall initiate steps to query the remote access service for status on the access request. 17. Remote access service identifies supervisors associated with the plant. 18. The remote access service will send a push notification to the plant supervisor with the access request details and challenge. 19. The Remote Access Service will create a digital receipt for the access request. 20. The supervisor will click on the notification. 21. The Supervisor application opens and the supervisor is prompted to enter the card's Token Serial Number (TSN). Note that if the smart card is already paired with the supervisor's mobile device, the TSN will be entered automatically. The Supervisor application is a mobile application used to authorize access to workstations within the plant. 22. The supervisor turns on the smart card. 23. The supervisor's device connects to the smart card using a Bluetooth (BLE) connection. 24. The supervisor application will initialize the Group Identifiers (GIDS) applet in the smart card. 25. The supervisor enters the PIN. 26. The supervisor application sends a PIN verification request to the smart card. 27. If the entered PIN is incorrect, the user will be prompted to re-enter the PIN. The maximum number of incorrect PIN attempts is limited. If the maximum number of PIN attempts exceeds a set value, the card will be blocked and will need to be reconfigured by an administrator, for example using a personalization kiosk, to be usable by the user. 28. If the entered PIN is correct, the supervisor application prompts the smart card for user certificate details. 29. The smart card provides the supervisor application with a user certificate. Note that this certificate only contains information about the public key. 30. A mutually authenticated TLS channel is established between the supervisor application and the remote access service using the supervisor's certificate and the remote access service's certificate. 31. The supervisor application retrieves the transaction details from the notification. 32. Additional data about the transaction is obtained by the supervisor application from the remote access service. 33. Please note that the supervisor application must sign the transaction whether the supervisor accepts or rejects the access request. The transaction information to be signed and the challenge are hashed using Secure Hash Algorithm 256-bit (SHA256) and sent to the smart card for digital signing. 34. The smart card signs the hashed transaction and challenge using its RSA 2048-bit private key and sends it to the supervisor. 35. The supervisor application sends the signature to the remote access service for verification. 36. The remote access service uses the digital receipt to verify the digital signature (to obtain the transaction information and challenge). 37. If the verification is successful, a success message is sent to the supervisor application. 38. If the validation fails, an error message is sent to the supervisor application. 39. Verification results will be updated in the digital receipt and maintained for audit and reporting purposes. 40. A remote access appliance querying a remote access service for status regarding an access request may receive the following response: Approved: This indicates that the request for access to the workstation has been approved by a supervisor. Pending: This indicates that the request for access to the workstation has not yet been approved by a supervisor. Denied: The supervisor denied the access request. Expired: The access request has expired. Failed: Validation failed.
[0030] Accordingly, in a first embodiment, a system for secure remote access to an industrial control system using hardware-based authentication is provided, the system comprising: Secure user authentication and Secure interactive remote access or secure machine-to-machine remote access or communication; Remote access services and Includes.
[0031] According to a first embodiment, secure user authentication includes two-factor authentication (2FA) or three-factor authentication (3FA) based on a smart card. According to first and subsequent embodiments, secure user authentication can include possession of a smart card, knowledge of a corresponding personal identification number (PIN), and optionally biometric authentication. According to first and subsequent embodiments, the smart card includes a secure element (SE) that stores credentials, cryptographic keys, and X.509 certificates. Also, according to first and subsequent embodiments, smart cards for administrators, supervisors, and end users have different functions.
[0032] According to a first embodiment and subsequent embodiments, the secure interactive remote access comprises a managed remote access appliance (RAA) including a virtual machine and software. According to the first embodiment and subsequent embodiments, the managed remote access appliance (RAA) can be used with only a smart card credential.
[0033] According to the first and subsequent embodiments, the remote access service includes technical cybersecurity control services that automate security policies and processes related to user and token lifecycle management, software configuration management, access control and authorization using layered security, and remote access audit trails. According to the first and subsequent embodiments, the remote access service can include management of users, smart card tokens, remote access appliance (RAA) status, remote access authorizations and policies, and layered security controls.
[0034] In a second embodiment, a method for securely remotely accessing an industrial control system is provided, the method comprising: providing a system for secure remote access to an industrial control system using hardware-based authentication; performing secure user authentication; providing secure interactive remote access or secure machine-to-machine remote access or communication; providing a remote access service; Includes.
[0035] According to a second embodiment, performing secure user authentication includes providing two-factor authentication (2FA) or three-factor authentication (3FA) requiring possession of a smart card, a personal identification number (PIN), and optionally biometric authentication. According to the second and subsequent embodiments, providing secure interactive remote access includes authorizing the smart card PIN with a remote access appliance (RAA) including a virtual machine and software.
[0036] According to the second and subsequent embodiments, providing the remote access service includes providing account management for administrator, supervisor, and at least one end-user role. According to the second and subsequent embodiments, providing the remote access service may include providing non-repudiation by using a digital signature scheme of the RSA cryptosystem. According to the second and subsequent embodiments, providing the remote access service may include providing an auditable record by securely storing all transaction events in a database.
[0037] According to the second and subsequent embodiments, providing the remote access service includes limiting the number of incorrect PIN entries. According to the second and subsequent embodiments, providing the remote access service includes sending system usage notifications to a supervisor informing the supervisor of end user logins, logouts, and workstation accesses.
[0038] According to the second and subsequent embodiments, providing the remote access service may include providing an identification and authorization process. According to the second and subsequent embodiments, providing the remote access service may include requesting a supervisor to authorize user access to the workstation.
[0039] While the systems and methods for secure remote access to industrial control systems using hardware-based authentication, including secure user authentication, secure interactive remote access or secure machine-to-machine remote access or communication, and remote access services, are described in connection with various exemplary embodiments, it should be understood that the embodiments described herein are merely exemplary, and that those skilled in the art can make variations and modifications without departing from the spirit and scope of the embodiments. All such variations and modifications are intended to be included within the scope of such embodiments.
[0040] Furthermore, all disclosed embodiments are not necessarily alternatives, as various embodiments may be combined to provide the desired result. Accordingly, the systems and methods for secure remote access to industrial control systems using hardware-based authentication, including secure user authentication, secure interactive remote access or secure machine-to-machine remote access or communication, and remote access services, are not intended to be limited to any single embodiment, but rather to be construed in breadth and scope in accordance with the recitation of the following claims.
Claims
1. 1. A system for secure remote access to an industrial control system using hardware-based authentication, comprising: A smart card for distributed secure user authentication, the smart card storing local authentication credentials to a Remote Access Appliance (RAA) and certificate-based remote access authentication to a plant network, the local authentication credentials to the Remote Access Appliance (RAA) being separate from the certificate-based remote access authentication to the plant network, the secure user authentication comprising possession of the smart card and knowledge of a corresponding personal identification number (PIN), the smart cards for administrators, supervisors, and end users each having different functions; A managed remote access appliance (RAA) for secure interactive remote access or secure machine-to-machine remote access or communication, the managed remote access appliance (RAA) being usable only with a smart card credential; a remote access service including a server configured to verify a user certificate, the remote access service being separate from the plant network; A system including:
2. The system for secure remote access to industrial control systems of claim 1 , wherein the secure user authentication comprises smart card-based two-factor authentication (2FA) or three-factor authentication (3FA).
3. The system for secure remote access to industrial control systems of claim 1 , wherein the secure user authentication further comprises biometric authentication.
4. 2. The system for secure remote access to an industrial control system of claim 1, wherein the remote access services include technical cybersecurity control services that automate security policies and processes for user and token lifecycle management, software configuration management, access control and authorization using layered security, and remote access audit trails.
5. 10. The system for secure remote access to an industrial control system of claim 1, wherein the remote access services include management of users, smartcard tokens, and remote access appliance (RAA) states.
6. The system for secure remote access to industrial control systems of claim 1 , wherein the remote access services include management of remote access authorization and policies and layered security controls.
7. A method for securely remotely accessing an industrial control system of an industrial plant, comprising: providing a system for distributed, secure, remote access to said industrial control systems using hardware-based authentication; performing distributed secure user authentication using a smart card, the smart card storing local authentication credentials to a Remote Access Appliance (RAA) and certificate-based remote access authentication to a plant network, the local authentication credentials to the Remote Access Appliance (RAA) being separate from the certificate-based remote access authentication to the plant network, the secure user authentication comprising possession of the smart card and knowledge of a corresponding personal identification number (PIN), the smart cards for administrators, supervisors, and end users each having different capabilities; providing secure interactive or machine-to-machine remote access or communication via a managed remote access appliance (RAA), said remote access appliance (RAA) being capable of being used only with a smartcard credential; providing a remote access service to a plant control network including workstations for the industrial plant, the plant control network being isolated from other networks and not including a path for input / output traffic to the Internet, the remote access service being configured to validate user credentials and being isolated from the plant network; A method comprising:
8. 8. The method for secure remote access to an industrial control system of claim 7, wherein the step of performing secure user authentication further comprises biometric authentication.
9. 8. The method for secure remote access to an industrial control system of claim 7, wherein the step of providing secure interactive remote access includes authorizing a smart card PIN with a remote access appliance (RAA) including a virtual machine and software.
10. 8. The method for secure remote access to industrial control systems of claim 7, wherein the step of providing remote access services includes the step of providing non-repudiation by using a digital signature scheme of the RSA cryptosystem.
11. 8. The method for securely remotely accessing an industrial control system of claim 7, wherein the step of providing a remote access service includes the step of providing an auditable record by securely storing all transaction events in a database.
12. 8. The method for securely remotely accessing an industrial control system of claim 7, wherein the step of providing remote access services includes the step of sending system usage notifications to a supervisor informing the supervisor of end-user logins, logouts, and workstation accesses.
13. 8. The method for secure remote access to an industrial control system of claim 7, wherein the step of providing a remote access service includes the step of requesting a supervisor to authorize user access to a workstation.
14. 8. The method for secure remote access to an industrial control system of claim 7, wherein the step of providing a remote access service includes the step of providing an identification and authorization process.
15. The system for secure remote access to an industrial control system of claim 2, wherein the smart card includes a secure element (SE) that stores credentials, cryptographic keys, and X.509 certificates.
16. The step of providing the remote access service includes limiting the number of incorrect PIN entries; providing the remote access services includes providing account management for administrator, supervisor, and at least one end-user role; 10. The method for secure remote access to an industrial control system of claim 9.
Citation Information
Patent Citations
Secure remote access system
JP2005235159A
Approval control method, approval control system, and approval control program related to remote operation
JP2017091304A
Industrial machinery system and control method for industrial machinery
JP2018523252A
Remote asset management services for industrial assets
US20150074749A1