Method for issuing and obtaining certificates, devices, and computer program product

The automatic verification and issuance of certificates by a certificate management device simplifies the onboarding of industrial devices in IIoT networks, reducing errors and enhancing cyber security.

WO2025199940A1PCT designated stage Publication Date: 2025-10-02ABB (SCHWEIZ) AG +6
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/084782
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

The process of onboarding industrial devices in an IIoT network is complex and requires multiple engineers, leading to potential provisioning errors and increased vulnerability to cyber threats due to the use of IP-based networks.

Method used

A certificate management device automatically verifies and issues certificates to industrial devices based on broadcasted network address information, eliminating the need for human intervention and simplifying the onboarding process.

Benefits of technology

This approach reduces human effort, minimizes provisioning errors, and enhances cyber security by establishing secure communications without manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024084782_02102025_PF_FP_ABST
    Figure CN2024084782_02102025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of present disclosure relate a method for issuing a certificate for an industrial device. In the method, a certificate management device receives network address information broadcasted by an industrial device from the industrial device. The certificate management device transmits a request for a device identifier of the industrial device to the industrial device. The certificate management device receives the device identifier from the industrial device. The certificate management device verifies that the industrial device is trusted based on the device identifier. The certificate management device issues a certificate for establishing secure communications in the industrial network to the industrial device. In this way, the verification process is also implemented without human interference. As such, the industrial device can obtain a certificate for secure communications with other devices thereby reducing human efforts and potential provisioning errors.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD FOR ISSUING AND OBTAINING CERTIFICATES, DEVICES, AND COMPUTER PROGRAM PRODUCTFIELD

[0001] Embodiments of the present disclosure generally relate to the field of industrial network, and more particularly, to a method for issuing certificates and obtaining certificates an industrial device, a certificate management device and a computer program product.BACKGROUND

[0002] With the advent of new industrial revolution, the industrial network becomes a cornerstone for digital transformation, especially the Industrial Internet of Things (IIoT) . The technologies relating to IIoT offers new growth opportunities to improve operational efficiency. Nowadays, more and more production networks are adopting such technologies. Due to this trends, the traditional industrial systems in which the components are not connected via networks are now transformed into “Smart Factory” and “Smart Manufacturing” .

[0003] In order to implement the IIoT concept, all the industrial devices as components in the industrial system need to be connected to an industrial network during the establishment of such industrial system. As a result, during production process of the industrial system, the components in the industrial network may communicate with each other across the industrial network.SUMMARY

[0004] In view of the foregoing problems, example embodiments of the present disclosure propose solutions for allocating network addresses in the industrial network.

[0005] In a first aspect of the present disclosure, example embodiments of the present disclosure provide a method for issuing a certificate for an industrial device. In the method, a certificate management device receives network address information broadcasted by an industrial device from the industrial device. The certificate management device transmits a request for a device identifier of the industrial device to the industrial device. The certificate management device receives the device identifier from the industrial device. The  certificate management device verifies that the industrial device is trusted based on the device identifier. The certificate management device issues a certificate for establishing secure communications in the industrial network to the industrial device.

[0006] In a second aspect, example embodiments of the present disclosure provide a method for obtaining a certificate. In the method, an industrial device broadcasts network address information in an industrial network. The industrial device receives a request for a device identifier of the industrial device from a certificate management device in the industrial network. The industrial device transmits the device identifier to the certificate management device. The industrial device receives a certificate for establishing secure communications in the industrial network from a certificate management device.

[0007] In a third aspect, example embodiments of the present disclosure provide an electronic device. The electronic device comprises: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the device to perform the method in accordance with the first aspect or the second aspect of the present disclosure.

[0008] In a fourth aspect, example embodiments of the present disclosure provide a computer program product comprising computer readable instructions stored on a computer readable storage medium. When executed by a computer, the computer readable instructions cause the computer to perform the method in accordance with the first aspect or second aspect of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Through the following detailed descriptions with reference to the accompanying drawings, the above and other objectives, features and advantages of the example embodiments disclosed herein will become more comprehensible. In the drawings, several example embodiments disclosed herein will be illustrated in an exemplary and in a non-limiting manner, wherein:

[0010] Fig. 1 schematically illustrates a block diagram of an industrial system in which example embodiments of the present disclosure can be implemented;

[0011] Fig. 2A schematically illustrates a signaling diagram of an example procedure for issuing a certificate in accordance with embodiments of the present disclosure;

[0012] Fig. 2B schematically illustrates a signaling diagram of an example procedure for allocating a network address in accordance with embodiments of the present disclosure;

[0013] Figs. 3A-3C schematically illustrate schematic diagrams of example procedures for provisioning industrial devices in accordance with some embodiments of the present disclosure;

[0014] Fig. 4 schematically illustrates a schematic diagram of an example procedure for provisioning industrial device in accordance with some embodiments of the present disclosure;

[0015] Fig. 5 schematically illustrates a flowchart of a method for issuing a certificate at a certificate management device in accordance with embodiments of the present disclosure;

[0016] Fig. 6 schematically illustrates a flowchart of a method for obtaining a certificate at an industrial device in accordance with embodiments of the present disclosure; and

[0017] Fig. 7 schematically illustrates a schematic diagram of an electronic device for implementing a method in accordance with embodiments of the present disclosure.

[0018] Throughout the drawings, the same or similar reference numerals represent the same or similar element.DETAILED DESCRIPTION

[0019] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. The disclosure described herein can be implemented in various manners other than the ones described below.

[0020] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.

[0021] References in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not  necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the know circle of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.

[0022] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.

[0023] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and / or “including” , when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.

[0024] As described above, components in the IIoT-based industrial system are connected with industrial network. In the case that industrial products are connected to the global network, there are more demands for cost-effective and standard-based technology such as Ethernet and Transmission Control Protocol  / Internet Protocol (TCP / IP) . However, these IP-based networks are more vulnerable to cyberattacks. As a result, connecting the industrial system online imposes more threats of being attacked by malware, ransomware and viruses. Therefore, it is important to establish industrial cyber security architecture for the IIoT-based industrial systems.

[0025] Conventionally, Secure Device Identifiers (DevIDs) according to IEEE802.1AR are designed to be used as interoperable secure device authentication credentials with Extensible Authentication Protocol (EAP) and other industry standard authentication and provisioning protocols. In the related framework, each device in the industrial network may be configured with a DevID which incorporates a globally unique manufacturer  provided Initial Device Identifier (IDevID) , stored in a way that protects it from modification.

[0026] Although the IDevID-based architecture can provide secure network functions, the device onboarding process, which is the process to provision the devices with specific identifiers and network addresses in the industrial network, may be complex. For example, when a device is deployed in the industrial network for the first time, a field engineer may plug it in a mounting slot. Then, a network engineer may configure the device with IP followed by an application engineer configuring the applications of the device, and another engineer provisioning the device with redundancy configuration. In this process, more than one engineer is involved and may need to work in sequence. For industrial systems with multiple components, the onboarding process would be troublesome and engineers must be on standby for potential system failures.

[0027] In view of the above, a mechanism of zero touch provisioning is provided. In the mechanism, a certificate management device monitors the network address information broadcasted by the industrial devices in an industrial network. Once the certificate management device receives the network address information from a particular industrial device, the certificate management device automatically verifies the industrial device and issues a certificate for the industrial device when the industrial device is verified to be trusted.

[0028] According to the embodiments in accordance with the present disclosure, when an industrial device is deployed in the industrial system for the first time, the industrial device can obtain a certificate automatically without human interference, thereby reducing the human effort and avoiding provisioning errors that may be caused by personal negligence.

[0029] A framework in accordance with embodiments of the present disclosure will be described with reference to Figs. 1 to 7. Fig. 1 schematically illustrates a block diagram of an industrial system 100 in which example embodiments of the present disclosure can be implemented. The industrial system 100 may be a distributed control system (DCS) . The industrial system 100 may include an operation level and a processing level. The operation level may contain the functions for operation, process monitoring, archives and logs, trends and alarms. The processing level may contain open-and closed-loop control functions which are processed in the controllers which communicate with actuators and sensors in the field. Between the operation level and the processing level, there is also a network level  connecting the operation level and the processing level.

[0030] As illustrated in Fig. 1, the operation level of the industrial system 100 includes a configuration device 101. The configuration device 101 may also be referred to as an engineer station. The configuration device 101 is configured for configuration and commissioning of all automation functions. The network level includes the industrial bus 102 for connecting all the components in the system and assisting devices for supporting the bus and providing assisting functions. For example, the industrial bus 102 may be Profibus. The assisting device includes a network address server 103 for allocating network addresses to the industrial devices in the network. The network address server 103 may be a Dynamic Host Configuration Protocol (DHCP) server. The assisting devices may also include a certificate management device 104 for verifying industrial devices and issuing certificates to allow the verified industrial devices to establish secure communications in the network by means of the certificates.

[0031] Further, the network address server 103 and the certificate management device 104 may be configured by the configuration device 101 according to the current project. In the illustrated embodiment, the configuration device 101 distributes a configuration file 108 to the network address server 103. The configuration file 108 may indicate mapping of a network address to a registered industrial device. Similarly, the configuration device 101 distributes a configuration file 109 to the certificate management device 104. The configuration file 109 may indicate whether an industrial device is trusted.

[0032] Further, the processing level of the industrial system 100 may include field devices for providing a variety of processing functions in the field. For example, the field devices may include controllers, for example programmable logic controllers (PLCs) . The controllers may be modular and include a backplane and modular devices mounted on the backplane. As illustrated in Fig. 1, a backplane 105 is provided in the field and configured to provide power and network interface for industrial devices. The backplane 105 may include a power supply circuit and a memory for storing essential information for provisioning the mounted industrial devices. The backplane 105 includes 4 mounting slots 106-1, 106-2, 106-3, 106-4 (may also be separately or collectively referred to as the mounting slot 106) . The mounting slot 106-1 has a slot identifier of SLOT001 and is not occupied, i.e., no industrial device is mounted on the mounting slot 106-1. The mounting slot 106-2 has a slot identifier of SLOT002 and an industrial device 107-1 with a device ID of DEV001 is mounted on the mounting slot 106-2. The mounting slot 106-3 has a slot  identifier of SLOT003 and an industrial device 107-2 with a device ID of DEV002 is mounted on the mounting slot 106-3. The mounting slot 106-4 has a slot identifier of SLOT004 and an industrial device 107-3 (may also be referred to as the mounting slot 106 separately or collectively with the industrial device 107-1 and the industrial device 107-2) with a device ID of DEV003 is mounted on the mounting slot 106-4.

[0033] When the industrial device 107 is properly mounted in the mounting slot 106, the backplane 105 delivers power to the industrial device 107 and connects the industrial device 107 to the industrial bus 102. Once the industrial device 107 is in the network by means of the industrial bus 102, a provisioning process of the industrial device 107 may automatically start. In the process, the industrial device 107 may broadcast a discovery message in the network to announce its presence and search for one of the network address servers in the industrial network. When the network address server 103 receives the discovery message, the network address server 103 determines an available network address that can be assigned to the industrial device 107 and unicasts an offer message to notify the industrial device 107 about the available network address. When the industrial device 107 receives the offer message from the network address server 103, the industrial device 107 may determine to use the offered network address. Then, the industrial device 107 broadcasts a message to confirm the use of the offered network address from the network address server 103. When the network address server 103 receives the request message, the network address server 103 unicasts an acknowledgement message to the industrial device 107.

[0034] During the network address assigning process, since the request message to confirm the network address is broadcasted by the industrial device 107, the certificate management device 104 is also able to receive the request message. When the certificate management device 104 receives the request message, the certificate management device 104 is also be notified about the network address to be used by the industrial device 107. Thus, the certificate management device 104 is able to connect to the industrial device 107.

[0035] At this time point, the industrial device 107 needs a certificate for establishing secure communications with other industrial devices in the network which requires verification from the certificate management device 104. In this case, the certificate management device 104 automatically initiates a certificate issuing process once it receives the broadcasted message to confirm the network address from the industrial device 107. The certificate management device 104 connects to the industrial device 107 according to  the network address and transmits a request for the device identifier of the industrial device 107. When the certificate management device 104 receives the device identifier from the industrial device 107, the certificate management device 104 compares the received device identifier with the trusted device identifiers configured by the configuration file 109. If the certificate management device 104 determines the received device identifier is registered or recorded at the certificate management device 104, the certificate management device 104 verifies that the industrial device 107 is trusted. Then, the certificate management device 104 issues a certificate to the industrial device 107. To this point, the automatic certificate issuing process in accordance with the present disclosure is complete. The detailed procedures will be described hereinafter with reference to Figs. 2A-6.

[0036] Fig. 2A schematically illustrates a signaling diagram of an example procedure 200A for issuing certificates in accordance with embodiments of the present disclosure. For the purpose of discussion, the procedure 200A will be described in association with Fig. 1. The procedure 200A is implemented between an industrial device 201 and a certificate management device 203. For example, the certificate management device 203 may be corresponding to the certificate management device 104 in Fig. 1 and the industrial device 201 may be any one of the industrial device 107-1, 107-2 and 107-3.

[0037] As illustrated in Fig. 2A, at 202, the industrial device 201 broadcasts network address information 205 in the industrial network such that the devices monitoring such messages are able to receive the network address information. At 204, the certificate management device 203 receive network address information broadcasted by the industrial device 201. At 206, the certificate management device 203 transmits a request for a device identifier of the industrial device 201 to the industrial devic201. At 208, the industrial device 201 receives a request for a device identifier of the industrial device from the certificate management device 203 in the industrial network. At 210, the industrial device 201 transmits the device identifier to the certificate management device 203. At 212, the certificate management device 203 receives the device identifier from the industrial device. At 214, the certificate management device 203 verifies that the industrial device 201 is trusted based on the device identifier 225. At 216, the certificate management device 203 issues a certificate for establishing secure communications in the industrial network to the industrial device 201. At 218, the industrial device 201 receives a certificate for establishing secure communications in the industrial network from the certificate management device 203.

[0038] In the embodiments as illustrated in Fig. 2A, the certificate management device is configured to automatically initial a verification process once network address information is received from an industrial device. The verification process is also implemented without human interference. As such, the industrial device can obtain a certificate for secure communications with other devices thereby reducing human efforts and potential provisioning errors.

[0039] In addition to the automatic certificate issuing process, the network address allocation process can also be automated. Fig. 2B schematically illustrates a signaling diagram of an example procedure 200B for allocating a network address in accordance with embodiments of the present disclosure. For the purpose of discussion, the procedure 200B will be described in association with Fig. 1. The procedure 200B is implemented between an industrial device 201 and a network address server 207. For example, the network address server 207 may be corresponding to the certificate management device 104 in Fig. 1 and the industrial device 201 may be any one of the industrial device 107-1, 107-2 and 107-3.

[0040] At 220, the industrial device 201 obtains a slot identifier of the mounting slot in which it is mounted. For example, in the embodiment of as illustrated in Fig. 1, the industrial device being mounted on the mounting slot. At 222, the industrial device 201 broadcasts a discovery message 245 to search for network address servers configured to allocate network addresses. In this case, the discovery message 245 includes the slot identifier. At 224, the network address server 207 receives the discovery message 245 from the industrial device 201. At 226, the network address server 207 allocates a network address corresponding to the slot identifier to the industrial device. At 228, the network address server 207 transmits the allocated network address 255 to the industrial device 201. At 230, the industrial device 201 receives the allocated network address 255 which may be available for the industrial device 201 to use at the moment. At 232, the industrial device 201 broadcasts network address information 265 to the network address server 207 to notify the network address server 207 about the selected network address. At 234, the network address server 207 receives the network address information 265 from the industrial device 201. At 236, the network address server 207 transmits an acknowledgement 275 to confirm the receipt of the network address information. At 238, the industrial device 201 receives the network address server 207.

[0041] In the embodiment as illustrated in Fig. 2B, the network address server can  allocate network addresses for the industrial devices based on the slot identifier rather than the medium access control (MAC) address in the conventional case. In this way, the network address server needs not to be configured with mapping between unique MAC address of every industrial device and the network address provided by the network address server. As such, the configuration of the network address server is simplified. In the meantime, since the industrial device in the same slot will have the same network address, the process of replacement of defect industrial device is very smooth.

[0042] Fig. 3A schematically illustrates a schematic diagram of an example procedure 300A for configuration in accordance with some embodiments of the present disclosure. As illustrated in Fig. 3A, the industrial system may be a DCS system. The industrial system includes a configuration device 301. The configuration device 301 may also be referred to as an engineer station or an extended operation station. The configuration device 301 is configured for configuration and commissioning of all automation functions. The industrial system includes an industrial bus 302 for connecting all the components in the system and assisting devices for supporting the bus and providing assisting functions. The industrial bus 302 may be implemented according to Profibus. The assisting device includes a server for allocating network addresses for the industrial devices in the network. In the illustrated embodiment, the server is a DHCP server 303. The industrial system also includes a certificate management device 304 for verifying industrial devices and issuing certificates to allow the verified industrial devices to establish secure communications in the network.

[0043] The industrial system includes field devices for providing a variety of processing functions in the field. As illustrated in Fig. 3A, a backplane 305 is provided in the field and configured to provide power and network interface for industrial devices. In some example embodiments, the backplane 305 may include a power supply circuit and a memory for storing essential information for provisioning the mounted industrial devices. The backplane 305 includes 4 mounting slots 306-1, 306-2, 306-3, 306-4 (may also be separately or collectively referred to as the mounting slot 306) . The mounting slot 306-1 has a slot identifier of SLOT001. The mounting slot 306-2 has a slot identifier of SLOT002. The mounting slot 306-3 has a slot identifier of SLOT003. The mounting slot 306-4 has a slot identifier of SLOT004.

[0044] Before the production process of the industrial system starts, the DHCP server 303 and the certificate management device 304 are configured by the configuration device 301 according to the current project for providing corresponding functions. As illustrated, the  configuration device 301 distributes a configuration file 311 to the DHCP server 303. The configuration file 311 indicates a mapping of the IP addresses to the mounting slots. As illustrated, the configuration file 311 comprises a mapping table of the SLOT ID to IP addresses. In the mapping table, the slot identifier “SLOT ID001” is associated with the IP address “10.10.0.1” . The slot identifier “SLOT ID002” is associated with the IP address “10.10.0.2” . The slot identifier “SLOT ID003” is associated with the IP address “10.10.0.3” . The slot identifier “SLOT ID004” is associated with the IP address “10.10.0.4” . As a result, the DHCP server 303 is configured to allocate IP addresses according to the stored mapping table. For, example, when an industrial device (may also be referred to as DHCP client in this scenario) requires an IP address, the DHCP server 303 selects an IP address corresponding to the slot identifier indicated by the industrial device from the mapping table.

[0045] Similarly, the configuration device 301 also distributes a configuration file 312 to the certificate management device 304. The configuration file 312 indicates whether an industrial device is trusted. As illustrated, the configuration file 312 includes a table of trusted device identifiers. For example, the device identifier may be IDevID according to IEEE 802.1AR. The table in configuration file 312 lists 3 IDevIDs, including DEV001, DEV002 and DEV003 of respective industrial devices. As a result, the certificate management device 304 is configured to verify devices being brought into the network of the industrial system according to the table of IDevIDs. In some example embodiments, when the devices, i.e., the components of the industrial system are purchased and obtained, the IDevIDs of the respective devices may be recorded into the table.

[0046] After the DHCP server 303 and the certificate management device 304 are properly configured, deployments of components of the industrial system may start. Fig. 3B schematically illustrates a schematic diagram of an example procedure 300B for allocating a network address in accordance with some embodiments of the present disclosure.

[0047] As illustrated in Fig. 3B, an industrial device 307-1 with a device identifier of DEV001 is mounted in the mounting slot 306-1 of a backplane 305. The backplane 305 supplies power to the industrial device 307-1 and connects the industrial device 307-1 to the industrial bus 302. Once the industrial device 307-1 is in the network by means of industrial bus 302, a provisioning process of the industrial device 307-1 automatically starts. In the process, the industrial device 307-1 connects to the mounting slot 306-1 and  reads the slot identifier SLOT001 of mounting slot 306-1 from a memory of the backplane 305. Then, the industrial device 307-1 include the slot identifier “SLOT001” in a DHCP discovery message. It should be appreciated that “SLOT001” is only one representation of the slot identifier. In some example embodiments, the slot identifier may be in a format same as the MAC address. In this way, the slot identifier may be included in the client identifier field of the DHCP discovery message. As a result, the DHCP server 303 does require configurations other than the mapping table.

[0048] The industrial device 307-1 broadcasts the DHCP discovery message in the network to announce its presence. When the DHCP server 303 receives the discovery message broadcasted by the industrial device 307-1, the DHCP server 303 extracts the slot identifier from the DHCP discovery message. The DHCP server 303 selects an available IP address from a IP address pool suitable for the slot identifier. According to the mapping table 313 of the IP addresses to the slot identifiers, the IP address which is assigned to the slot identifier “SLOT001” is “10.10.0.1” . The DHCP server 303 determines that the IP address should be “10.10.0.1” and unicasts a DHCP offer message to notify the industrial device 307 about the available IP address “10.10.0.1” . After the DHCP receives the DHCP offer message, the industrial device 307-1 determines to use the allocated IP address and broadcasts a DHCP request message in the network to confirm that the allocated IP address “10.10.0.1” is under application. One DHCP request message 309-1 is received by the DHCP server 303 and another DHCP request message 309-2 is received by the certificate management device 304. On one hand, upon receipt of the DHCP request message 309-1, the DHCP server 303 transmits a DHCP acknowledgement message to the industrial device 307-1.

[0049] On the other hand, when the certificate management device 304 receives the request message, the certificate management device 304 is also be notified about the IP address “10.10.0.1” . The certificate management device 304 connects to the industrial device 307 according to the IP address “10.10.0.1” . The certificate management device 304 requires device identifiers for verifying industrial devices and transmits a request for the device identifier to the industrial device 307-1. The industrial device 307-1 receives the request for the device identifier and transmits its device identifier for example in a response message. When the certificate management device 304 receives the device identifier from the industrial device 307-1, the certificate management device 304 compares the received device identifier with the trusted device identifiers in the identifier table 314 stored on the  certificate management device 304. The certificate management device 304 determines the received device identifier has been already registered or recorded in the identifier table 314. the certificate management device 304 verifies that the industrial device 307-1 is trusted. Then, the certificate management device 304 issues a certificate and pushes the certificate to the industrial device 307-1.

[0050] During the production process of the industrial system, the industrial device 307-1 may be defected due to some reasons. In this case, one field engineer replaces the defected industrial device 307-1 with a new industrial device 307-2 so that the same functions can be continuously provided. Fig. 3C schematically illustrates a schematic diagram of an example procedure 300C for allocating network addresses during a replacement of industrial devices in accordance with some embodiments of the present disclosure.

[0051] As illustrated in Fig. 3C, the defected industrial device 307-1 is pulled out of the mounting slot and the new industrial device 307-2 with a device identifier of DEV002 is mounted in the mounting slot 306-1 of the backplane 305. The backplane 305 supplies power to the industrial device 307-2 and connects the industrial device 307-2 to the industrial bus 302. Similarly, once the industrial device 307-2 is in the network by means of industrial bus 302, a provisioning process of the industrial device 307-2 also automatically starts. In the process, the industrial device 307-2 connects to the mounting slot 306-1 and reads the slot identifier SLOT001 of mounting slot 306-1 from the memory of the backplane 305. Then, the industrial device 307-2 also includes the slot identifier “SLOT001” in a DHCP discovery message.

[0052] The industrial device 307-2 broadcasts the DHCP discovery message in the network to announce its presence. When the DHCP server 303 receives the discovery message broadcasted by the industrial device 307-1, the DHCP server 303 extracts the slot identifier from the DHCP discovery message. The DHCP server 303 selects an available IP address from a IP address pool suitable corresponding to the slot identifier SLOT001. According to the mapping table 313 of the IP addresses to the slot identifiers, the IP address which is assigned to the slot identifier “SLOT001” is also “10.10.0.1” . The DHCP server 303 determines that the IP address should be “10.10.0.1” again and unicasts a DHCP offer message to notify the industrial device 307-2 about the available IP address “10.10.0.1” . After the industrial device 307-2 receives the DHCP offer message, the industrial device 307-2 determines to use the allocated IP address and broadcasts a DHCP request message in the network to confirm that the allocated IP address “10.10.0.1” is under application. One  DHCP request message 310-1 is received by the DHCP server 303 and another DHCP request message 310-2 is received by the certificate management device 304. On one hand, upon receipt of the DHCP request message 310-1, the DHCP server 303 transmits a DHCP acknowledgement message to the industrial device 307-2.

[0053] On the other hand, the certificate management device 304 receives the DHCP request message 310-2. In the case of the DHCP request message according to the standard, the DHCP request message may be configured to indicate the use of an allocated IP address, or indicate a request for an extension of the lease for the current IP address, or indicate a request for a verification of the current IP address. If the certificate management device 304 determines that the DHCP request message 310-2 indicates a request for an extension of the lease for the current IP address, or a request for a verification of the current IP address based on the content in the “option” field of the DHCP request message 310-2, the certificate management device 304 will ignore the DHCP request message 310-2. Only if the certificate management device 304 determines that the DHCP request message 310-2 indicate a use of an allocated IP address, the certificate management device 304 initiate the verification process.

[0054] Since the certificate management device 304 is also be notified about the IP address “10.10.0.1” the certificate management device 304 connects to the industrial device 307 according to the IP address “10.10.0.1” . The certificate management device 304 transmits a request for the device identifier to the industrial device 307-2. The industrial device 307-2 receives the request for the device identifier and transmits its device identifier “DEV002” in a response message to the certificate management device 304. When the certificate management device 304 receives the device identifier “DEV002” from the industrial device 307-2, the certificate management device 304 compares the received device identifier “DEV002” with the trusted device identifiers “DEV001” , “DEV002” and “DEV003” in the identifier table 314 stored on the certificate management device 304. The certificate management device 304 determines the received device identifier “DEV002” has been already registered or recorded in the identifier table 314, the certificate management device 304 verifies that the industrial device 307-2 is trusted. Then, the certificate management device 304 issues a certificate and pushes the certificate to the industrial device 307-2.

[0055] In the illustrated embodiment as illustrated in Figs. 3A-3C, both of the network address allocation and device verification processes are implemented automatically for  newly-mounted industrial device and replaced industrial device. In this way, when an industrial device is defected and replaced by a new device of the same model, the new device can obtain a same IP address which would facilitate the subsequent provisioning stage and a certificate for establishing secure communications thereby allowing the replacement process to be automatically and smoothly implemented.

[0056] Fig. 4 schematically illustrates a signaling diagram of an example procedure 400 for provisioning industrial devices in accordance with some embodiments of the present disclosure. For purpose of discussion, the procedure 400 will be described in association with Figs. 3A-3C. The procedure 400 is implemented by an industrial device 401, a network address server 403 and a DHCP server 407. For example, the industrial device 401 may be corresponding to the industrial device 307-1 or the industrial device 307-2 in Figs. 3A-3C. The certificate management device 403 may be corresponding to the certificate management device 304 in Figs. 3A-3C. The DHCP server 407 may be corresponding to the DHCP server 303 in Figs. 3A-3C. Correspondingly, the industrial device 401, the certificate management device 403 and the DHCP server 407 are deployed in an industrial system connected in an industrial network.

[0057] As illustrated in Fig. 4, at 402, the industrial device 401 obtains a slot identifier (for example one of the “SLOT001” , “SLOT002” , “SLOT003” and “SLOT004” ) of the mounting slot in which it is mounted. At 404, the industrial device 401 broadcasts DHCP discovery messages 405 to search for DHCP servers configured to allocate network addresses and the DHCP discovery messages 405 includes the slot identifier. At 406, the DHCP server 407 receives one of the DHCP discovery messages 405 from the industrial device 401. In this case, at 408, the certificate management device 403 also receives one of the DHCP discovery messages 405 from the industrial device 401.

[0058] At 410, the DHCP server 407 allocates an IP address corresponding to the slot identifier to the industrial device 401. For example, the DHCP server 407 determines that an IP address “10.10.0.1” is corresponding to the slot identifier “SLOT001” according to the mapping table stored on the DHCP server 407 and allocates the IP address “10.10.0.1” to the industrial device. At 412, the DHCP server 407 transmits a DHCP offer message 415 including the allocated IP address “10.10.0.1” to the industrial device 401. At 414, the industrial device 401 receives the DHCP offer message 415. At 416, the industrial device 401 broadcasts DHCP request messages 425 in the industrial network so that the DHCP server 407 can be notified about the selected network address. At 418, the DHCP server  407 receives one of the DHCP request messages 425 and at 420, the certificate management device 403 also receives one of the DHCP request messages 425 from the industrial device 401. At 422, the DHCP server 407 transmits an acknowledgement message 435 to confirm the receipt of the DHCP request messages 425 to complete the IP address allocation process. At 424, the industrial device 401 receives the acknowledgement message 435 from the DHCP server 407.

[0059] At 426, the certificate management device 403 transmits a request 435 for a device identifier of the industrial device 401 to the industrial devic401 upon receipt of the DHCP request message 425 broadcasted by the industrial device 401. At 428, the industrial device 401 receives the request 435 for its device identifier from the certificate management device 403 in the industrial network. At 430, the industrial device 401 transmits the device identifier 445, for example “DEV001” , to the certificate management device 403. At 432, the certificate management device 403 receives the device identifier “DEV001” from the industrial device. At 434, the certificate management device 403 determines that the device identifier “DEV001” is registered in a device table including trusted device identifiers such as “DEV001” , “DEV002” and “DEV003” , and verifies that the industrial device 401 is trusted. At 436, the certificate management device 403 issues a certificate 455 for establishing secure communications in the industrial network by to the industrial device 401. At 438, the industrial device 401 receives the certificate 455 for establishing secure communications in the industrial network from the certificate management device 403.

[0060] Fig. 5 schematically illustrates a flowchart of a method 500 for issuing certificates at a certificate management device in accordance with embodiments of the present disclosure. For purpose of discussion, the method 500 will be described in association with Fig. 1. For example, the method 500 may be implemented by the certificate management device 104 as illustrated in Fig. 1.

[0061] As illustrated in Fig. 5, at 502, the certificate management device receives a network address information broadcasted by the industrial device from an industrial device in the same industrial network. At 504, the certificate management device transmits a request for a device identifier of the industrial device to the industrial device. At 506, the certificate management device receives the device identifier from the industrial device. At 508, the certificate management device verifies that the industrial device is trusted based on the device identifier. At 510, the certificate management device issues a certificate for establishing secure communications in the industrial network to the industrial device.

[0062] Fig. 6 schematically illustrates a flowchart of a method 600 for obtaining certificates at an industrial device in accordance with embodiments of the present disclosure. For purpose of discussion, the method 600 will be described in association with Fig. 1. For example, the method 600 may be implemented by any one of the industrial devices 107 as illustrated in Fig. 1.

[0063] As illustrated in Fig. 6, at 602, the industrial devices 107 broadcasts network address information in an industrial network. At 604, the industrial devices 107 receives a device identifier request for a device identifier of the industrial device from a certificate management device in the industrial network. At 606, the industrial devices 107 transmits the device identifier to the certificate management device. At 608, the industrial devices 107 receives a certificate for establishing secure communications in the industrial network and from a certificate management device.

[0064] In some embodiments of the present disclosure, a computing device is provided for implementing the above methods 500 and 600. Fig. 7 illustrates a schematic diagram of an electronic device 700 for implementing a method in accordance with embodiments of the present disclosure. The electronic device 700 may be corresponding to the industrial devices 107, the certificate management device 104 in Fig. 1. The electronic device 700 comprises: at least one processor 710 and at least one memory 720. The at least one processor 710 may be coupled to the at least one memory 720. The at least one memory 720 comprises instructions 722 that when executed by the at least one processor 710 implements the methods 500 and 600.

[0065] In some embodiments of the present disclosure, a computer readable medium for adjusting robot path is provided. The computer readable medium has instructions stored thereon, and the instructions, when executed on at least one processor, may cause at least one processor to perform the method for managing a camera system as described in the preceding paragraphs, and details will be omitted hereinafter.

[0066] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial  representation, it will be appreciated that the blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.

[0067] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target real or virtual processor, to carry out the process or method as described above with reference to Figs. 2A-6. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as ideal in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.

[0068] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.

[0069] The above program code may be embodied on a machine readable medium, which may be any tangible medium that may contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine readable medium may be a machine readable signal medium or a machine readable storage medium. A machine readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash  memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0070] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. On the other hand, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.

[0071] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

[0072] It should be appreciated that the above detailed embodiments of the present disclosure are only to exemplify or explain principles of the present disclosure and not to limit the present disclosure. Therefore, any modifications, equivalent alternatives and improvement, etc. without departing from the spirit and scope of the present disclosure shall be included in the scope of protection of the present disclosure. Meanwhile, appended claims of the present disclosure aim to cover all the variations and modifications falling under the scope and boundary of the claims or equivalents of the scope and boundary.

[0073] It is to be understood that the summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.

Claims

1.A method for issuing a certificate for an industrial device, comprising:receiving, by a certificate management device and from an industrial device, network address information broadcasted by the industrial device;transmitting, by the certificate management device to the industrial device, a request for a device identifier of the industrial device;receiving, by the certificate management device and from the industrial device, the device identifier;verifying, by the certificate management device, that the industrial device is trusted based on the device identifier; andissuing, by the certificate management device to the industrial device, a certificate for establishing secure communications in the industrial network.2.The method of claim 1, wherein verifying that the industrial device is trusted comprises:obtaining, by the certificate management device, trusted device identifiers;determining, by the certificate management device, that the device identifier is included in the trusted device identifiers; anddetermining, by the certificate management device, that the device identifier is trusted.3.The method of claim 2, wherein the certificate management device is configured with an identifier table comprising the trusted device identifiers.4.The method of claim 1, wherein the network address information is included in a Dynamic Host Configuration Protocol (DHCP) request message broadcasted by the industrial device.5.The method of claim 4, wherein the identifier request is transmitted in response to  determining that the industrial device requires a verification andwherein determining that the industrial device requires the verification comprises:determining, by the certificate management device, option information of the DHCP request message upon receipt of the DHCP request message; andin response to determining that the option information indicating a response to a DHCP offer message providing an available network address, determining, by the certificate management device, that the industrial device requires the verification.6.The method of claim 5, wherein determining that the industrial device requires the verification further comprises:in response to determining that the option information indicating an extension of a lease or a verification for a previously-allocated network address, determining, by the certificate management device, that the industrial device does not require the verification.7.A method for obtaining a certificate for an industrial device, comprising:broadcasting, by an industrial device, network address information in an industrial network;receiving, by the industrial device and from a certificate management device in the industrial network, a request for a device identifier of the industrial device;transmitting, by the industrial device to the certificate management device, the device identifier; andreceiving, by the industrial device and from a certificate management device, a certificate for establishing secure communications in the industrial network.8.The method of claim 7, further comprising:obtaining, by the industrial device, a slot identifier of a mounting slot in a backplane, the industrial device being mounted on the mounting slot;broadcasting, by the industrial device, a discovery message for network address servers configured to allocate network addresses, the discovery message including the slot identifier; andreceiving, by the industrial device from a network address server, a network address allocated for the industrial device.9.The method of claim 8, further comprising:receiving, by the industrial device from the network address server, an acknowledgement message in response to the network address information.10.The method of claim 8, wherein the discover message is a Dynamic Host Configuration Protocol (DHCP) discover message and the network address information is comprised in a DHCP request message.11.The method of claim 10, wherein the DHCP discover message includes the slot identifier in a client identifier field.12.The method of claim 10, wherein the DHCP discover message includes an option field which indicates one of:a response to a DHCP offer message providing an available network address;an extension of a lease; ora verification for a previously-allocated network address.13.The method of claim 7, wherein the network address is allocated based on a mapping table of slot identifiers to the predefined network addresses.14.An electronic device comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the device to perform the method of any of claims 1-6 or any of claims 7-13.15.A computer program product comprising computer readable instructions stored  on a computer readable storage medium, wherein the computer readable instructions, when executed by a computer, cause the computer to perform the method for issuing a certificate for an industrial device of any of claims 1-6 or the method for obtaining a certificate for an industrial device of any of claims 7-13.

Citation Information

Patent Citations

  • Enabling zero-touch bootstrap for devices across network perimeter firewalls

    CN111226418A

  • System for automatically verifying the authenticity of a physical device

    DE202022101798U1

  • Method for IP assignment of board in wireless IPnetwork

    KR1020030071402A

  • Using public key infrastructure for automatic device configuration

    US20160246617A1