Automation Device Operator Data Binding to Authentication Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional automation systems insecurely provide device-specific operator data, allowing third parties to manipulate this data if they gain access to the system.
Innovation Solution
A method and system where device-specific operator data is securely provided by binding it to an authentication credential, such as a device certificate, using a policy enforcement server, ensuring only authenticated automation devices receive the data, which is digitally signed and periodically updated or requested.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device-specific operator data is provided in an unprotected manner in conventional automation systems, then the provision of operator data is simple and fast, but third parties can manipulate this data if they gain access to the automation system
Solution Approach 1:
The patent introduces an authentication server as an intermediary between automation devices and operator data. The authentication server verifies device identities using authentication credentials before allowing access to operator data, thereby preventing unauthorized manipulation while maintaining a structured and manageable authentication process
Solution Approach 2:
The patent implements preliminary authentication of automation devices before providing operator data. The authentication server verifies device credentials in advance, and only authenticated devices receive operator data through the policy enforcement server. This preliminary action ensures data integrity before transmission occurs
2Reliability
If authentication credentials and digital signatures are implemented to secure operator data, then manipulation by third parties is prevented, but the system complexity increases
Solution Approach 1:
The policy enforcement server acts as an intermediary that receives digitally signed operator data from the authentication server and distributes it to authenticated devices. This intermediary layer manages the complexity of cryptographic operations centrally, preventing third-party manipulation while avoiding the need for each device to implement complex security infrastructure independently
Solution Approach 2:
The patent replaces physical security mechanisms with cryptographic mechanisms. Instead of relying on physical access control, the system uses digital signatures and authentication credentials to secure operator data. This substitution enables secure data provision over networked systems while maintaining centralized control through the authentication server
Data Source
Figure 1
Figure 2~3
AI summary
Method and system for providing device-specific operator data for an automation device (2) in an automation installation (1), which automation device authenticates itself to an authentication server (7) in the automation installation (1) by means of at least one authentication credential, wherein if up-to-date device-specific operator data from the installation operator of the automation installation (1) are available for the automation device (2) then these up-to-date device-specific operator data are tied to the authentication credential of the authentication device (2).