Automation Device Onboarding With Separate Credential and Identity Checks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing automation systems require pre-installed credentials for incorporating automation devices, which lack protection against manipulation and are not suitable for edge computing environments, necessitating a secure and efficient method for onboarding without compromising security.
Innovation Solution
A method involving an authentication device connected to the automation device, generating an access credential and proof of identity, where the access credential is authenticated on an automation server, and the identity is verified separately to ensure secure incorporation into the automation system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If pre-installed credentials are used for authentication, then device incorporation is simplified, but security is compromised due to potential manipulation of configuration data
Solution Approach 1:
The patent applies preliminary action by pre-generating cryptographic key pairs on the automation device before it is incorporated into the system. The public key is prepared in advance and can be freely transmitted, while the private key remains securely stored on the device. This preliminary cryptographic setup enables secure authentication without requiring pre-installed credentials that could be manipulated, thus resolving the contradiction between ease of operation and security.
2Reliability
If asymmetric cryptographic credentials are used, then security is improved, but device complexity increases due to cryptographic storage modules
Solution Approach 1:
The patent applies the extraction principle by separating the cryptographic functions into two parts: the private key remains extracted and stored only on the automation device, while the public key is extracted and transmitted to the automation server. This separation eliminates the need for complex cryptographic storage modules on the device, as only simple key storage is required, while maintaining high security through asymmetric cryptography.
Solution Approach 2:
The patent uses the automation server as an intermediary that receives and stores the public key. This intermediary approach allows the device to use simple asymmetric cryptography without complex storage modules, while the server handles the cryptographic verification. The intermediary server bridges the security requirements with device simplicity.
3Reliability
If configuration data is protected against manipulation, then security is improved, but ease of parameterization is reduced
Solution Approach 1:
The patent applies preliminary action by establishing cryptographic authentication mechanisms before parameterization occurs. The asymmetric key pair is generated in advance, and the public key is registered with the automation server before any configuration data is exchanged. This preliminary cryptographic setup ensures that subsequent parameterization can proceed securely without compromising ease of operation, as the authentication framework is already in place.
Data Source
AI summary
Various teachings of the present disclosure include a method for incorporating an automation device into an automation system by using an authentication device. An example method includes: establishing an interface between the automation device and the authentication device and generating an access credential associated with the automation device; receiving and authenticating the access credential on an automation server of the automation system and assigning an access authorization to the automation device; and receiving and authenticating a proof of identity of the access-authorized automation device on the automation server and incorporating the automation device whose identity has been authenticated into the automation system.
