Control systems for technical facilities where certificate management is performed
The control system addresses the inefficiency in certificate revocation by implementing an automatic revocation service, ensuring immediate and secure certificate updates within the system, thus minimizing delays and misuse risks.
Patent Information
- Application Number
- JP2022543030
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-01-14
- Filing Date
- 2021-01-13
- Publication Date
- 2026-01-14
- Estimated Expiration
- 2041-01-13
AI Technical Summary
Existing control systems for technical facilities are unable to efficiently and instantly revoke certificates when communication links between components become unnecessary, leading to potential misuse due to delays in the revocation process.
A control system with a computer-implemented revocation service that automatically initiates certificate revocation based on event control, minimizing delays by monitoring and processing revocation requests directly or indirectly via a registration service.
The solution ensures immediate and efficient certificate revocation, reducing the risk of misuse by maintaining up-to-date knowledge of revoked certificates within the system, thereby enhancing security and reducing the need for external communication.
Smart Images

Figure 0007798769000001
Abstract
Description
[Technical Field]
[0001] The present invention relates to a control system for a technical facility, in particular a control system for a manufacturing or process facility, with the features of claim 1, which control system is configured and arranged to initiate the issuing and revoking of certificates for components of the technical facility as part of the certificate management. Furthermore, the present invention relates to a method as claimed in claim 4.
[0002] As part of the certificate management of an industrial installation, it must be possible not only to issue but also to revoke certificates. The revocation of certificates used by installation components takes place in particular when these are taken out of operation and when they are replaced (or replaced by other components), and this can be done while the installation is in operation. In this case, the certificates used are invalidated by revocation. Otherwise certificates could potentially be misused, for example by using a device that has been illegally copied and removed to communicate using this certificate (possibly in another part of the installation).
[0003] In the context of modular automation, the ability to initiate the revocation of specific certificates as needed is also essential, since a module can be combined with various other modules in various projects, and this module is generally assigned a project-specific certificate that is required for communication with the other modules in the context of the respective projects. As soon as the use of a module in the context of a particular project is no longer necessary (i.e., it should be blocked), it is desirable to revoke all project-specific certificates assigned to this module in the context of this project in order to eliminate certificate misuse.
[0004] Depending on the circumstances, upon revocation of an activatable certificate, either by the establishment component itself or by an authorized (management) instance, a revocation request (in English: Revokation Request) is submitted to the Certification Authority (CA for short) that issued this certificate. This kind of revocation request is a component of well-known certificate management protocols, such as CMP according to RFC 4210, and is supported by certification authorities, for example by the so-called EJBCA / PrimeKey CA. For other certification authorities supporting protocols that do not have revocation requests as a message type within their scope, the revocation can be sent as manually directly at the CA (e.g. via its web front-end), or by an application (for example, by being initiated by a Registration Authority (RA)). It can be realized.
[0005] If communication links between individual components of a facility suddenly turn out to be no longer necessary and, from a security perspective, one wishes to block these communication links by revoking the certificates used, "instant" certificate revocation is not possible in previously known control systems. The revocation process is traditionally initiated by the user directly at the certificate authority or via another central instance, for example, via a registration service. Here, the need for certificate revocation is first identified, and then the revocation is manually initiated. For organizational and technical reasons, a significant delay may result between these two events.
[0006] The problem underlying the present invention is to provide a control system for technical facilities that implements certificate management in which certificates are revoked more efficiently.
[0007] This problem is solved by a control system for a technical installation with the features of claim 1. Furthermore, this problem is solved by a method according to claim 4. Advantageous developments are described in the dependent claims.
[0008] In a control system of the type mentioned at the beginning, this problem is solved according to the invention in that the control system comprises a computer-implemented revocation service that is configured and set up to automatically initiate the revocation of certificates under event control.
[0009] In the context of this specification, a control system is understood to be a computer-assisted technical system that includes functions for displaying, operating, and controlling a technical system, such as a manufacturing or production facility. In this case, the control system includes sensors for determining measured values as well as various actuators. Furthermore, the control system also includes so-called process-related or production-related components that serve to control these actuators or sensors. Furthermore, the control system particularly includes means for visualizing and engineering the technical facility. Additionally, the term control system also includes further computing units for more complex control, as well as systems for data storage and data processing.
[0010] The technical installation can be an installation in the process industry sector, such as a chemical, pharmaceutical or petrochemical installation, or an installation in the food and luxury goods sector. This also includes any installation in the manufacturing industry sector, such as a factory where cars or any kind of goods are manufactured. The technical installation suitable for carrying out the method according to the invention can also belong to the energy generation sector. Wind turbines, solar power plants or power plants for energy generation are also included in the term technical installation.
[0011] A component can be an individual sensor or actuator of a technical installation, but a component can also be a collection of several sensors and / or actuators, for example a motor, a reactor, a pump or a valve system.
[0012] A certificate is understood to be a digital data set that acknowledges a specified characteristic (in this case of a machine, device, application, etc.), the authenticity and integrity of which can be verified, typically cryptographically.
[0013] Due to the event-controlled and fully automatic revocation triggered by the process control system, the certificates to be revoked can be revoked with as immediate effect as possible.The technical features of the present invention allow delays in the revocation process to be efficiently minimized, thereby improving the overall certificate management of the control systems of technical facilities.
[0014] As an event, any state change in the technical installation comes into consideration. According to one advantageous development of the invention, a change in the communication links between the individual components of the technical installation constitutes such an event.
[0015] Advantageously, the revocation service of the control system is configured and arranged to initiate the revocation of a certificate by submitting a revocation request to the certification authority, wherein the revocation service is configured and arranged to monitor or have the processing of the revocation request monitored, meaning that the revocation service itself, i.e. directly, or has it monitored via a separate service, i.e. indirectly, in particular via a registration service.
[0016] A certification authority is also called an "Issuing CA (Certification Authority)". This kind of "Issuing CA" is generally always online and issues certificates to various applicants based on the certificate requests that come in, signing them with its own unique "Issuing CA" certificate. The authenticity of an "Issuing CA" is guaranteed in that its own unique "Issuing CA" certificate is signed by the certificate of a trusted root certification authority (also called "Root CA") located in a secure environment. It should be noted here that a "Root CA" is offline most of the time and is activated or switched on only when it needs to issue a certificate for its own "Issuing CA", observing the strictest security measures. A "Root CA" can reside outside the technical facilities.
[0017] As part of the revocation service's monitoring of revocation requests, it may issue new queries to the CA in case of delays in processing the revocation request (known in this context as "polling"). This process is described, for example, in the RFC4210 standard (RFC = Request for Comments), which describes the specification of the Certificate Management Protocol (CMP).
[0018] According to one particularly preferred development of the invention, the control system is configured and arranged to announce the revocation of a certificate in the control system after it has been carried out, in particular in the form of a block list. The immediate revocation of a certificate as already described above and the subsequent propagation of a message about the revocation in the control system ensure that all components of the technical installation are always up-to-date with regard to issued certificates, thereby significantly reducing the risk of certificate misuse. This announcement allows for constant knowledge of all revoked certificates related to the installation.
[0019] In cases where a block list is used, announcement of revoked certificates can be made by the Certificate Authority. Such entries in the block list can be digitally signed by the Certificate Authority to ensure the authenticity of the entries. This prevents, among other things, the block list from being updated by users (e.g., project engineers) or the intelligent service itself, thereby reducing the risk of abuse.
[0020] The use of an enterprise-wide blocklist allows ad-hoc control over which certificates issued by project-specific CAs are permitted and which are not. If a certificate is found to be unpermitted for a particular (engineering) project, a revocation process can be initiated as described above.
[0021] The above-mentioned problem is further solved by a method according to claim 4, which comprises the following steps: a) initiating the issuance of a certificate to a component of the technical facility by a control system of the technical facility; b) automatically initiating the revocation of the certificate by a computer-implemented revocation service in the technical facility's control system in response to a particular event; Includes.
[0022] For the explanation of the method claims and the attendant advantages, please refer to the above description of the control system according to the invention.
[0023] According to one advantageous development of the method according to the invention, a change in the communication links between the components of the technical installation constitutes an event that triggers the automatic initiation of a certificate revocation.
[0024] Preferably, the revocation service submits revocation requests to the certificate authority to initiate the revocation of the certificate, and the revocation service monitors the processing of the revocation requests.
[0025] Particularly preferably, after the revocation of a certificate has taken place, this revocation is announced in the control system, this announcement being made in particular in the form of a block list.
[0026] The foregoing characteristics, features and advantages of the present invention, as well as the manner in which they are achieved, will be more clearly and emphatically understood by reference to the following detailed description of the preferred embodiments taken in conjunction with the drawings. [Brief explanation of the drawings]
[0027] [Figure 1] 1 shows a part of a control system according to the invention for a technical facility configured as a process technology facility;
[0028] The drawing shows part of a control system 1 according to the invention for a technology facility configured as a process technology facility. The control system 1 comprises an operation system server or operator station server 2 and associated operator station clients 3. The operator station server 2 and the operator station clients 3 are connected to each other via a terminal bus 4 and to further components of the control system 1, which are not shown, such as an engineering system server or a process data archive.
[0029] A user or operator accesses the operator station server 2 for operation and monitoring purposes using an operator station client 3 via a terminal bus 4. The terminal bus 4 may be configured as, for example, but not limited to, an industrial Ethernet.
[0030] The operator station server 2 has a device interface 5 connected to a facility bus 6, via which the operator station server 2 can communicate with (external) devices 7. In this case, the connected devices 7 can alternatively be applications, in particular web applications. According to the invention, any number of devices and / or applications 7 can be connected to the operator station server 2. The facility bus 6 can be configured as, for example but not limited to, an industrial Ethernet. The devices 7 themselves can be further connected to any number of subsystems (not shown).
[0031] The operator station server 2 incorporates a visualization service 8, via which the transmission of (visualization) data to the operator station client 3 can take place. Furthermore, the operator station server 2 has a process image 9, a process data archive 10, and a so-called "User Profile and Selection Service (UPSS)" 11. The process image 9 of the operator station server 2 stores instantaneous records of the (signal) states of the devices and / or applications 7 connected to the operator station server 2 via the device interfaces 5. Already-experienced (signal) states are stored in the process data archive 10 for archiving purposes. The "User Profile and Selection Service" 11 forms a database in which the user profiles and personal settings of operators of the process technology facility are stored. These can also be accessed by other operators.
[0032] The control system 1 further includes a registration authority 12 and a certification authority 13, which are connected to the operator station server 2 and the operator station client 3 via a terminal bus 4. The registration authority 12 is configured to accept and forward authentication requests to the certification authority 13, which is responsible for issuing certificates.
[0033] If a device 7 wants to log in to the control system 1 and use its functions in connection with one particular engineering project, the device 7 needs a valid certificate. In a first step I, the device 7 queries the authentication service 14 of the operator station server 2. In a second step II, the authentication service 14 accesses a block list 15 stored in the user profile and selection service 11. This block list 15, or in a database 16 of the user profile and selection service 11, contains revoked certificates ("Certificate Revocation List") associated with the process technology facility at the time the block list 15 is accessed.
[0034] If the certificate to be requested in connection with the engineering project authorizes the device 7, i.e. in particular if this certificate is not listed in the blocklist 15 as a revoked certificate, the corresponding certificate request is forwarded in a third step III to the registration authority 12, which itself further forwards this certificate request in a fourth step IV to the certification authority 13. The certificate issued by the certification authority 13 is then transmitted by the registration authority 12 to the requesting device 7 (step V).
[0035] Now, if a specific event occurs, such as a change in a communication link within the process technology facility, a specific certificate can become invalid and must therefore be revoked. A revocation request is initiated by the revocation service 17 of the operator station server 2 and transmitted to the registration authority 12. This revocation request is initiated fully automatically, without any direct action by a project engineer or operator of the process technology facility. The certification authority 13 then declares the certificate in question invalid and stores this information in a block list 15 stored at the certification authority 13. The updated block list 15 is then transmitted by the registration authority 12 to the database 16 of the user profile and selection service 11.
[0036] In this case, the event-controlled fetching of the block list 15 from the certification authority 13 via the registration authority 12 can be realized in various ways. In the simplest case, a trigger can be configured in the certification authority 13 which causes the block list 15 stored locally at the certification authority 13 to be replaced with an updated block list 15 immediately after a certificate is revoked. The storage location of the block list 15 in the certification authority 13 can be monitored by the registration authority 12 (e.g. by a corresponding intelligent service), so that any updates can be immediately identified and the updated block list 15 can be immediately communicated to the user profile and selection service 11 of the operator station server 2. If several operator station servers 2 are used, the databases 16 can be collated by a "mirroring" service 18 between the individual operator station servers 2 to increase the availability of the block list 15.
[0037] Through an interface 19 that is graphically mapped by the visualization service 8 to the operator station client 3, the operator / project engineer can predefine new / revised events, which can then be supplied by the management service 20 of the user profile and selection service 11 to the revocation service 17 for future automatic revocation of certificates.
[0038] The above-mentioned technical features make it possible to eliminate delays in the revocation process, and in accordance with the principle of minimum, which has a very high priority in relation to industrial security, any device 7 is only granted access to the latest blocklist 15 that it actually needs. Since the technical functions required for this purpose are integrated "as process technology" into the control system 1, no further communication paths "outside the control system 1" are required for revocation management, in addition to the communication paths already established around the control system 1.
[0039] A further advantage with regard to security is that no special configuration is required in the network (e.g. no opening of ports which poses a high security risk) since access to the block list 15 is required. The control system 1 described is highly suitable for modularized facilities where process technology facility parts are dynamically added or removed.
Claims
1. A control system (1) for a technical facility, configured and set up to initiate the issuance and revocation of certificates for communications between components (7) of the technical facility as part of certificate management, The control system (1) includes a computer-implemented revocation service (17) configured and configured to automatically initiate event-controlled revocation of certificates; A change in a communication link between components (7) of the technical facility without the replacement or removal of a single component (7) constitutes an event that triggers the initiation of a revocation of the certificate; The information of the revoked certificate is stored in a block list (15), When a request for certificate is made, the control system (1) determines whether the requested certificate is not on the block list (15). A control system (1) for technical facilities, characterized in that:
2. the revocation service (17) is configured and configured to initiate the revocation of a certificate by submitting a revocation request to the certification authority (13); said cancellation service (17) being configured and arranged to monitor or cause to be monitored the processing of said cancellation requests; A control system (1) according to claim 1.
3. 3. The control system (1) according to claim 1 or 2, configured and set to announce in the control system (1) after revocation of a certificate, said announcement being made in the form of said block list (15).
4. a) initiating the issuance of certificates for communications between components of a technical facility by a control system (1) of said technical facility; b) automatically initiating the revocation of the certificate by a computer-implemented revocation service (17) of the control system (1) of the technical facility in response to a specific event, wherein a change in a communication link between components (7) of the technical facility without a component (7) being replaced or removed constitutes an event that triggers the automatic initiation of the revocation of the certificate; c) storing the information of the revoked certificate in a block list (15); Including, The step of starting includes determining whether the requested certificate is not on the block list (15). method.
5. The revocation service (17) submits a revocation request to the certification authority (13) to initiate the revocation of the certificate; said cancellation service (17) monitors or causes to be monitored the processing of said cancellation requests; The method of claim 4.
6. 6. The method according to claim 4 or 5, wherein after the revocation of a certificate has taken place, the revocation is announced in the control system (1), the announcement being in the form of the block list (15).