Automation Configuration Checking via External Validation Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automation installations face significant risks due to erroneous or manipulated configuration data, which can lead to incorrect behavior, failure, or data breaches during reconfiguration, especially in flexible production environments like Industry 4.0.
Innovation Solution
A method and system that utilize a checking server separate from the automation components to verify configuration data for admissibility, considering the current operating mode, IT infrastructure, and context information such as production processes, whitelists, blacklists, and cryptographic signatures, ensuring improved operational and information security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If configuration data are adopted without checking during reconfiguration, then adaptability and ease of operation are improved, but reliability and security deteriorate due to risks of erroneous or manipulated configuration data
Solution Approach 1:
The patent implements preliminary checking of configuration data before adoption during reconfiguration. The checking server validates configuration data against admissibility criteria, whitelists, and blacklists before the data are applied to components, preventing erroneous or manipulated data from compromising system reliability while still enabling flexible reconfiguration.
Solution Approach 2:
The patent introduces a checking server as an intermediary between configuration data sources and automation components. This mediator validates configuration data independently before it reaches the components, separating the reconfiguration capability from the validation function and ensuring that adaptability does not compromise reliability.
2Reliability
If comprehensive checking of configuration data is implemented, then reliability and security are improved, but device complexity and checking time increase
Solution Approach 1:
The patent segments the configuration checking function into a separate checking server distinct from the automation components. This segmentation allows comprehensive validation without increasing the complexity of individual components, as the checking logic is centralized and specialized in the dedicated checking server.
Solution Approach 2:
The checking server implements multiple checking functions within a single system, including validation against admissibility criteria, whitelist verification, blacklist filtering, and cryptographic signature verification. This multi-functionality achieves comprehensive security without proportionally increasing system complexity.
3Speed
If configuration data are checked using only component-specific information, then checking speed is improved, but measurement precision and security coverage deteriorate due to lack of system-wide context
Solution Approach 1:
The patent implements feedback loops where the checking server continuously monitors and updates its understanding of system state, operating modes, and component configurations. This feedback mechanism enables the checking server to make precise validation decisions by considering both component-specific data and system-wide context, improving validation accuracy without significantly impacting checking speed.
Data Source
AI summary
Various embodiments of the teachings herein include methods and/or systems for checking a configuration of at least one component of an automation installation. An example method includes checking configuration data of the at least one component for admissibility using a checking server different from the at least one component.

