Industrial Automation Cloud Access Using Mobile-Relayed Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connecting industrial automation devices with limited user-interaction capabilities to secure cloud services for remote monitoring is challenging due to authentication requirements.

Innovation Solution

A system that uses a mobile device to establish a secure connection between industrial automation devices and cloud services by generating and managing tokens for authentication, allowing secure information exchange without manual user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If industrial automation devices connect to cloud services with authentication requirements, then secure remote monitoring is enabled, but the complexity of connection establishment increases due to authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidconnection establishment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring the industrial automation device with authentication credentials (device ID, private key, or certificate) during manufacturing or initial setup. This allows the device to automatically perform authentication when connecting to cloud services without requiring manual user intervention during the connection process, thus maintaining security while reducing operational complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where a cloud service acts as a mediator between the industrial automation device and the monitoring system. The cloud service handles authentication requests, validates credentials, and manages token issuance, thereby shielding the device from complex authentication protocols while ensuring secure access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual user intervention is used for authentication, then secure connection can be established, but the automation and efficiency of the process decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements self-service authentication where the industrial automation device automatically performs authentication operations using pre-configured credentials. The device can independently establish secure connections, request tokens, and manage authentication without human intervention, achieving both high automation and maintained security through automated cryptographic operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical authentication processes (such as physical key entry or button pressing) with automated electronic authentication mechanisms. The device uses embedded software to automatically execute authentication protocols, manage cryptographic keys, and communicate with cloud services, substituting human-operated mechanical processes with automated electronic systems

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If hardcoded tokens are used for authentication, then device can connect to cloud service, but security is compromised and flexibility is reduced

Engineering Contradiction:
Improveconnection capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from static hardcoded tokens to dynamic token generation. The device obtains temporary authentication tokens from the cloud service that are valid only for specific time periods or specific operations. These tokens can be refreshed, revoked, or updated without changing the device's fundamental credentials, providing both ease of connection and enhanced security through time-limited access

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the authentication parameter from fixed hardcoded values to variable tokens with different validity periods, scopes, and renewal mechanisms. The cloud service can issue different types of tokens with varying permissions and expiration times, allowing flexible control over device access while maintaining security through parameter-based authentication management

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11303625B2Industrial automation device and cloud service
Publication Date: 2022.04.12 ABB (SCHWEIZ) AG
  • US11303625B2 patent drawing
  • US11303625B2 patent drawing
  • US11303625B2 patent drawing

AI summary

An industrial automation device with a token to be used as authentication information in information exchange between a first cloud service and the industrial automation device, a mobile device is connected to the industrial automation device and to a cloud service that is the first cloud service or a second cloud service. After authenticating the user of the mobile device to the cloud service, a token is generated by the cloud service to the first cloud service, and forwarded via the mobile device to the industrial automation device. If the cloud service that generated the token is the second cloud service, the token is forwarded via the mobile device, after the mobile has been authenticated in the first cloud service, the first cloud service. Thereafter the industrial automation device and the first cloud service may communicate directly with each other using the token for authentication.