Access permission decision based on a capacity value of the associated data transmission connection

By evaluating performance values of data transmission connections, the method effectively detects and prevents lateral movement attacks, enhancing access control and reducing unauthorized access.

WO2025113957A1PCT designated stage expired Publication Date: 2025-06-05SIEMENS AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/081681
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-27
Filing Date
2024-11-08
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing access control methods struggle to effectively detect and prevent lateral movement attacks, where attackers gain indirect access to well-protected target systems by using intermediate computers.

Method used

The method evaluates at least one performance value of the data transmission connection associated with the access, using criteria to determine permissible values, thereby distinguishing between intended and unintended access.

Benefits of technology

This approach enhances access control by detecting and preventing lateral movement attacks, reducing the risk of unauthorized access and misuse of access credentials.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024081681_05062025_PF_FP_ABST
    Figure EP2024081681_05062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for determining a decision about an access to a target system (R), comprising the steps of: - using (S3) at least one capacity value (LW) of a data transmission connection associated with the access, - evaluating (S4) the at least one capacity value (LW), whereby a result is provided, and - determining (S5) the decision based on the result. Additionally, the invention relates to a computer program product, a decision node (PDP), a target system (R) and a superordinate system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Access authorization decision based on a performance value of the associated data transmission connection

[0003] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identity are included.

[0004] BACKGROUND OF THE INVENTION

[0005] Field of the invention

[0006] The invention relates to a method for determining a decision regarding access to a target system. The invention also relates to a computer program product, a decision node, a target system, and a higher-level system.

[0007] Description of the state of the art

[0008] In practice, attacks on a target system are often not carried out directly, but rather via several intermediate computers taken over by the attacker. This is also referred to as "lateral movement." This type of attack strategy is often used by attackers to gain indirect access to target systems that are well-protected according to the current state of the art.

[0009] Context-aware access control is part of a Zero Trust security strategy. This is also known as context-based access control. This can reduce the risk of unauthorized access because, in addition to checking the authorization of the accessing user, other parameters such as the location and time of access can be considered. This includes the possibility of considering distance as context information. Note: The term "Context-Aware Access Control" is used for firewalls that consider application protocol information when filtering TCP / UDP packets, i.e., adapt data transmission based on the network context. This is not what is meant by context-based access control.

[0010] There are known approaches to detecting lateral movement in which authentication processes are analyzed using AI.

[0011] Fingerprinting is known to identify the device or the operating system used based on implementation-specific details of a network communication stack.

[0012] IBM Security Verify Access describes the supported attributes for context-based access control decisions. Among the numerous supported attributes is the "ipReputation" attribute, which evaluates the trustworthiness of the IP address used by the accessing party, e.g., whether the IP address belongs to a known command and control server or to an anonymous proxy.

[0013] The object of the invention is to provide a solution for improved access control.

[0014] SUMMARY OF THE INVENTION

[0015] The invention is based on the features of the independent claims. Advantageous developments and refinements are the subject of the dependent claims. Embodiments, possible applications, and advantages of the invention will become apparent from the following description and the drawings.

[0016] The invention relates to a method for determining a decision regarding access to a target system, comprising the steps of: using at least one performance value of a data transmission connection associated with the access, evaluating the at least one performance value, thereby providing a result, and determining the decision based on the result.

[0017] The performance of the data transmission connection associated with the access describes a property of the access, particularly of an access request, to the target system. The performance value can also be referred to as the performance value.

[0018] The data transmission connection assigned to the access takes place in particular via a data communications network. In a data communications network, e.g. Ethernet, WLAN, IP network, Profinet network, mobile radio network, a transmission of data packets of a data transmission connection takes place. For this purpose, network components such as routers, switches, base stations and / or gateways can be provided, via which data packets are transmitted to and from the target system. A data transmission connection can in particular be bidirectional, but it can also in principle be a unidirectional data transmission connection, which in one variant takes place via a data diode or a unidirectional gateway or a multicast data transmission connection or a broadcast data transmission connection.This can be, for example, a TCP data transfer connection, a UDP data transfer connection, a TLS data transfer connection, a DTLS data transfer connection, a QUIC data transfer connection, an HTTP data transfer connection, an HTTPS data transfer connection, an FTP data transfer connection, an IP multicast data transfer connection, a publish-subscribe data transfer connection, an RTP data transfer connection or a TSN data transfer connection.

[0019] The use of intermediate nodes within a data transmission connection typically influences at least one performance value. If an attacker accesses the target system via an unintended (unexpected) data transmission connection (in particular a communication path), this automatically leads to different (i.e., unintended and / or unexpected) characteristics of at least one performance value. This makes it possible to distinguish between intended, permissible access and access by an attacker. For this purpose, at least one criterion is defined for the at least one performance value, which determines what a permissible performance value is. During the evaluation, it is determined whether the at least one performance value is permissible. The permissibility of the at least one performance value is reflected in the result of the evaluation.The result of the evaluation provides a basis for determining access.

[0020] In other words, it is proposed to grant or deny access authorization (particularly in the case of access by a device to a target device) depending on at least one performance value of the data transmission connection of the access.

[0021] The invention offers the advantage of detecting accesses that occur within the framework of a "lateral movement." For this purpose, the context (through the at least one performance value) of an access is used to determine whether the access occurs in a permissible, plausible manner.

[0022] In summary, a further advantage of the invention is that, when deciding on access to a target system, at least one performance value (context parameter) of the data transmission connection is evaluated, and access is decided based on this. This reduces the possibility of misusing an access credential acquired by an attacker. In particular, lateral movement by an attacker across multiple jump hosts can be detected, prevented, or at least made more difficult.

[0023] When a real-time communications infrastructure is used as a data transmission link in an industrial environment, it can be used to make access control decisions. This can provide protection against remote attackers who do not achieve the performance levels expected from communications within the industrial environment.

[0024] In a further development of the invention, the method according to the invention comprises the further step:

[0025] - Receiving the access request, wherein the access request is configured to request access to the target system.

[0026] In a further development of the invention, the at least one performance value is designed as at least one quality of service value.

[0027] The Quality of Service value (also abbreviated as QoS value) describes the Quality of Service (also abbreviated as QoS) of the data transmission connection. "Quality of Service" can also be referred to as "quality of service." The Quality of Service value is generally measured by the performance of a data transmission connection and / or the quality of the data transmission connection.

[0028] The performance value or QoS value refers to the value of a performance parameter or QoS parameter. The QoS value is also referred to as a (QoS) performance value and / or QoS information. The performance value or QoS value is, in particular, the characteristic of the performance parameter or QoS attribute determined / obtained by measuring and / or querying.

[0029] A QoS parameter is also referred to below as QoS attribute and / or QoS-related attribute.

[0030] In general, "Quality of Service" (QoS) refers to the quality of a communication service from the user's perspective. That is, the extent to which the quality of the service matches their requirements. Formally, QoS is a set of quality requirements for the joint behavior or interaction of several objects. The performance of a data transmission connection can be characterized in particular by data transmission performance values ​​such as bandwidth, throughput, bit error rate, packet loss rate, latency, and jitter (deviation of the latency from its mean value). Performance values ​​can, in one variant, describe the QoS properties of a real-time data transmission connection.

[0031] In order to be able to measure such general user-related properties in relation to the performance of a data transmission connection, quality parameters are defined that describe these properties and are evaluated in the form of at least one performance value (and thus in particular at least one Quality of Service value) of the data transmission connection associated with the access within the meaning of the present invention. The data transmission performance value can in particular characterize the bandwidth, throughput, bit error rate, packet loss rate, latency or jitter, or a combination of individual, several or all of these elements. The at least one performance parameter (also performance value) and / or the at least one QoS parameter are in particular designed as:

[0032] - A quality parameter of a connection setup of the data transmission connection: o A percentage of failed connections, o A percentage of incorrect connections, and / or o A percentage of duplicate connections, o A percentage of slow connection setups, and / or a quality parameter for an existing connection of the data transmission connection: o Percentage of premature connection aborts, o A percentage of user data not transmitted, o A percentage of user data transmitted with errors, o A delay in a user data transmission, o A fluctuation in a delay in a user data transmission, o An effective bandwidth of transmitted user data, o A signal delay, o Fluctuations in the signal delay, o A proportion of interference in transmitted signals, and / or o An echo proportion.

[0033] In a further development of the invention, at least one performance criterion is used to evaluate the at least one performance value.

[0034] According to this embodiment, at least one criterion is defined for the at least one performance value, which determines what a permissible performance value is. During the evaluation, it is determined whether the at least one performance value is permissible, i.e. whether access to the target system is permissible if the determined performance value is present. The access can take place at the application level, e.g. to a web service or to a web application or to a service or to an application, whereas the performance value characterizes at least one QoS property of the data transmission at the network level, which is used for the access at the application level.In addition to authorization checks of the accessing, authenticated user during access, the network performance parameters of a data transmission path used for access are determined and checked.

[0035] A performance criterion or a QoS criterion refers to a permissible performance value or a permissible QoS value or a permissible QoS value range and thus a requirement for a performance parameter or QoS parameter.

[0036] The performance or QoS criterion can also be considered a minimum performance or QoS requirement and, in particular, specifies at least one threshold, in particular at least one minimum or maximum value, for the performance or QoS value. The performance or QoS criterion thus sets requirements for the performance or QoS value and thus for the data transmission connection and its performance. Access is therefore only possible if the access occurs in compliance with the performance criterion.

[0037] In a further development of the invention, the at least one performance criterion is based on a set of rules which contains rules for a permissible characteristic:

[0038] - at least one performance value and / or

[0039] - at least one first performance value in relation to at least one second performance value, wherein the at least one first performance value and the at least one second performance value are exhibited by the at least one performance value. In particular, a performance criterion or QoS criterion is thus based on a set of rules which prescribes rules for permissible characteristics of individual performance or QoS parameters and thus permissible performance or QoS values. Additionally or alternatively, the set of rules prescribes rules for permissible characteristics of several performance or QoS parameters in relation to one another. Example: A higher QoS value is accepted before a first QoS value if a second QoS value is also above a predefined limit, but not if the second QoS value is below the predefined limit.

[0040] In a further development of the invention, determining the decision comprises:

[0041] - Granting access,

[0042] - denying access, and / or

[0043] - granting access under restrictions.

[0044] In a further development of the invention, the method according to the invention comprises the following steps:

[0045] - receiving at least one performance value,

[0046] - retrieving at least one performance value and / or

[0047] - determining at least one performance value.

[0048] The at least one performance value is preferably determined at the application protocol level of the data transmission connection, in particular HTTP or SSH. It is also possible, particularly in a 5G mobile communications system, to query the at least one performance value via a Network Exposure Function (NEF).

[0049] In a further development of the invention, the at least one performance value was determined by analyzing the data transmission connection with regard to: a data transmission, at least one associated data packet, a latency, a jitter, a data throughput of a communication path used and / or an associated access credential.

[0050] In particular, the at least one performance value was determined as part of determining the at least one performance value of the previous embodiment; alternatively, it was determined by another unit.

[0051] According to this embodiment, the at least one performance value or the QoS value is determined implicitly by analyzing the data transmission occurring (in particular analyzing data packets that arrive as part of the data transmission).

[0052] However, it is also possible to explicitly conduct network performance tests to determine the performance value or QoS value, in particular by measuring latency, jitter, and / or data throughput. The performance value or QoS value is thus, in particular, a value for the latency, jitter, and / or data throughput of the data transmission connection.

[0053] It is also possible for the performance value or QoS value to specify that a real-time communication path, e.g. TSN, DetNet, Profinet IRT, 5G URLLC (Ultra-reliable Low-Latency Communication), is used as the data transmission connection. Furthermore, in the case of TSN communication (TSN: Time Sensitive Networking) or DetNet, it can be checked whether access is via a data transmission connection, in particular a communication path, which is reserved according to the performance or QoS parameters required for access authorization. In a further development of the invention, the at least one performance value is indicated by: an access credential, in particular: o an access token, o a JSON web token, o a verifiable credential, o a verifiable presentation and / or o a digital certificate.

[0054] In this variant, the access credential serves as proof of authorization for access. It confirms that the required performance values ​​for data transmission are met.

[0055] The invention also includes a computer program product comprising a computer program (also referred to as Policy Decision Point (PDP) software), wherein the computer program can be loaded into a memory device of a computing unit, wherein the steps of a method according to the invention are carried out with the computer program when the computer program is executed on the computing unit.

[0056] The invention further comprises a decision node (also referred to as a "Policy Decision Point" (PDP)) comprising the computer program product according to the invention, configured to execute the computer program, optionally comprising:

[0057] - a receiving unit configured to receive the at least one performance value.

[0058] The invention further comprises a target system (also referred to as receiver, target device and / or accessed system) comprising:

[0059] - a decision node (also referred to as a "Policy Decision Point" (PDP)) according to claim 11, and

[0060] - optionally a collector unit designed to determine and / or measure at least one performance value (also referred to as "Context Attribute Collector") and / or optionally an implementation node (also referred to as "Policy Enforcement Point" (PEP)).

[0061] The decision regarding access (as well as the determination of at least one performance value or QoS value) is primarily made by the target system itself and its decision nodes. Alternatively, the decision regarding access is made by an intermediate node belonging to the target system, e.g., a firewall or a security gateway.

[0062] It is also possible that the collector unit and / or the conversion node are located internally or externally of the target system.

[0063] The invention also comprises a higher-level system comprising:

[0064] - an inventive target system,

[0065] - an accessing system, trained to access the target system, and

[0066] - a network designed to support a data transmission connection between the target system and the accessing system.

[0067] The higher-level system is designed in particular as a system, in particular an industrial system, in particular an industrial automation system.

[0068] The accessing system is particularly designed to initiate access to the target system.

[0069] The invention can be applied in particular to real-time communication for transmitting control data, e.g., for communication between a virtualized automation function (e.g., a virtualized PLC running on an edge computing system) as the accessing system and a remote IO module as the target system connected to sensors and actuators. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] The special features and advantages of the invention will become apparent from the following explanations of several embodiments based on the schematic drawings.

[0071] It shows

[0072] Fig. 1 is a flow diagram of the method according to the invention,

[0073] Fig. 2 is a schematic representation of a higher-level system according to the invention and

[0074] Fig. 3 is a schematic representation of a higher-level system according to the invention designed as an industrial plant.

[0075] DETAILED DESCRIPTION OF THE INVENTION

[0076] Fig. 1 shows a flow diagram of the method according to the invention for determining a decision on access to a target system, with the steps:

[0077] Step S1: Optionally, receiving the access request, wherein the access request is configured to request access to the target system,

[0078] Step S2a: Optionally, receiving the at least one performance value, Step S2b: Optionally, retrieving the at least one

[0079] Performance value,

[0080] Step S2c: Optionally, determining the at least one performance value, Step S3: Using at least one performance value of a data transmission connection associated with the access, Step S4: Evaluating the at least one performance value, thereby providing a result, and

[0081] Step S5 : Determining the decision based on the result.

[0082] Fig. 2 shows a schematic representation of a higher-level system according to the invention, in particular a schematic access control model. When an accessing system Z (also accessing device Z) accesses a target system R (also a resource R), the access control decision made by a decision node PDP (also Policy Decision Point PDP) is implemented by an implementation node PEP (also Policy Enforcement Point PEP), i.e., access is permitted or denied. The decision node PDP (also Policy Decision Point PDP) uses, in addition to the information about the access itself (accessing system Z, target system R, access type), context information LW provided by a collector unit C (also Context Attribute Collector C), which describes the circumstances of the access.

[0083] According to the invention, at least one QoS value LW (= QoS information LW, characteristic LW of a QoS attribute; corresponds to the at least one performance value LW) of the access of the accessing system Z to the target system R or of the data transmission connection, also communication connection, used by the accessing system Z to access the target system R is used as context information LW.

[0084] The Context Attribute Collector C determines the QoS values ​​LW for the QoS parameters such as data throughput, jitter, and latency, in particular through a measurement and / or queries the QoS values ​​LW via a Network Exposure Function (NEF) of the communication network used. Fig. 3 shows a schematic representation of a higher-level system according to the invention, designed as an industrial plant, in particular an industrial automation system, which interacts with the real, physical world P via sensors S and actuators A.

[0085] For the control and monitoring of remote input / output modules (IO), in addition to a physical programmable logic controller (PLC), virtualized programmable logic controllers (vPLCs) are also provided. A virtualized programmable logic controller (vPLC) is available, in particular, in the form of a Linux container, a virtual machine, or a native program, which is executed on an edge computing cornpute platform.

[0086] Furthermore, an operator panel (HMI), also referred to as a "human-machine interface", is provided, which displays process data from a virtualized "supervisory control and data acquisition" component (SCADA), or via which an operator (user) can influence the technical process.

[0087] Furthermore, a driverless transport system vehicle (AGV), also referred to as an "automated guided vehicle", is shown, which is controlled by a controller (AGVC).

[0088] A production planning system (MES), also known as a manufacturing execution system, is also provided for the planning and execution of production tasks.

[0089] The transmission of monitoring and control data takes place using a wireless control network N, also referred to as a "wireless control network" N, e.g., a 5G SNPN network or an industrial WLAN infrastructure. However, a wired control network N can also be used, e.g., a regular Ethernet network or an Ethernet communication network N supporting "Time Sensitive Networking" (TSN). The functions vPLC, SCADA, MES, AGVC executed on the Edge Compute Platform E can also generally be referred to as virtualized automation functions (VAF), which can each be in the form of a Linux container, a virtual machine, a native program, a script-based program (e.g., JavaScript, Python), or as bytecode. The Edge Compute Node E can, for example,an IPC, a server cluster, a hyper-converged infrastructure, an edge cloud or an edge functionality integrated with a 5G mobile network, e.g. Multi-Access Edge Computing (MEC).

[0090] The individual components, e.g., a virtualized "Programmable Logic Controller" vPLC and a remote input / output module 10, communicate via the control network N and transmit control commands, e.g., for setting up a device configuration, for setting up security credentials, or for influencing an actuator A. Such access is only possible if the accessing party is authenticated and recognized as authorized. For this purpose, the components of the remote input / output module 10 (remote input / output module 10 itself or, alternatively, an intermediate node associated with the remote input / output module 10, e.g., a firewall or a security gateway) comprise a policy decision point and a policy enforcement point.

[0091] According to the invention, access, e.g. by a virtualized "Programmable Logic Controller" vPLC to a remote input / output module 10, is only permissible and thus possible if the access or the communication connection used for the access and the QoS values ​​determined for the communication connection used meet the specified minimum QoS requirements (=QoS criteria), e.g. with regard to latency or jitter. This reduces the possibility of misuse. The remote input / output module 10 comprises a Context Attribute Collector (see Fig. 2) which determines the QoS information (see Fig. 2) and makes it available to the Policy Decision Point (see Fig. 2) of the remote input / output module 10, so that the access control decision can also take into account the QoS information associated with the access.

[0092] Although the invention has been illustrated and described in detail by the embodiments, the invention is not limited by the disclosed examples and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.

Claims

Patent claims 1. Method for determining a decision on access to a target system (R), comprising the steps: - Using (S3) at least one performance value (LW) of a data transmission connection associated with the access, wherein the at least one performance value (LW) is configured as bandwidth and / or throughput and / or bit error rate and / or packet loss rate and / or latency and / or jitter and / or a quality parameter of a connection setup via the associated data transmission connection, - evaluating ((SS44)) the at least one performance value ((LLWW)), thereby providing a result, and - determining (S5) the decision based on the result.

2. The method according to claim 1, comprising the further step: - Receiving (S1) the access request, wherein the access request is designed to request access to the target system (R).

3. Method according to one of the preceding claims, wherein the at least one performance value (LW) is designed as at least one quality of service value.

4. Method according to one of the preceding claims, wherein at least one performance criterion is used to evaluate the at least one performance value (LW).

5. Method according to claim 4, where at least one performance criterion is based on a set of rules which contains rules for a permissible characteristic: - at least one performance value (LW) and / or - at least one first performance value in relation to at least one second performance value, wherein the at least one first performance value and the at least one second performance value are exhibited by the at least one performance value (LW). 6 . Method according to one of the preceding claims, wherein determining the decision comprises: - Granting access, - denial of access, and / or - granting access subject to restrictions. 7 . Method according to one of the preceding claims, with the further steps: - receiving (S2a) at least one performance value (LW), - retrieving (S2b) at least one performance value (LW) and / or - determining (S2c) at least one performance value (LW).

8. Method according to one of the preceding claims, wherein the at least one performance value (LW) was determined by analyzing the data transmission connection with regard to: - a data transfer, - at least one associated data packet, - a latency, - a jitter, - a data throughput - a communication path used and / or an associated access credential.

9. Method according to one of the preceding claims, wherein the at least one performance value (LW) is exhibited by: - an access credential, in particular: o an access token, o a JSON web token, o a verifiable credential, o a verifiable presentation and / or o a digital certificate.

10. A computer program product comprising a computer program, wherein the computer program is loadable into a memory device of a computing unit, wherein the steps of a method according to one of claims 1 to 9 are carried out with the computer program when the computer program is executed on the computing unit.

11. Decision node (PDP) comprising the computer program product according to claim 10, configured to execute the computer program, optionally comprising: - a receiving unit configured to receive the at least one performance value (LW).

12. Target system (R) comprising: - a decision node (PDP) according to claim 11, and - optionally a collector unit (C) designed to determine and / or measure at least one performance value (LW) and / or - optionally an implementation node (PEP).

13. Superior system comprising: - a target system (R) according to claim 12, - an accessing system (Z) designed to access the target system (R), and a network (N) designed to support a data transmission connection between the target system (R) and the accessing system (Z).

Citation Information

Patent Citations

  • Techniques of optimizing policies in an information management system

    US20070156670A1