Secure Remote Access for Automation Components via One-Time Password

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In automation environments, service technicians face challenges in quickly and securely accessing remote automation terminals due to geographical separation and the need for service certificates, which often requires complex and costly PKI setups or pre-installed certificates from multiple companies.

Innovation Solution

A method using a one-time password, generated by a random number generator in network components, allows for a secure initial connection to be established, enabling the transmission of a service certificate for remote access, with the password delivered via SMS to facilitate quick and secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service certificates are transmitted via encrypted email requiring PKI infrastructure, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidPKI infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a VPN tunnel as an intermediary secure communication channel between the service technician's computer and the automation terminal. This tunnel serves as a mediator that enables secure certificate transmission without requiring complex PKI infrastructure, as the VPN provides the necessary encryption and security layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent establishes the VPN tunnel before transmitting the service certificate. By setting up the secure communication channel in advance, the system prepares the necessary security infrastructure beforehand, allowing subsequent certificate transmission to occur securely without requiring the recipient to have pre-configured PKI systems.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If service technicians pre-install all service certificates from multiple companies, then access speed is improved, but device complexity increases

Engineering Contradiction:
Improveaccess setup timeVSAvoidcertificate management complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system pre-configures the automation terminal with a repository of service certificates from multiple companies in advance. When a service technician needs access, the appropriate certificate is already available on the terminal side, eliminating the need for the technician to pre-install certificates or wait for manual provisioning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automation terminal autonomously manages the service certificate distribution process. Upon receiving a service request, the terminal automatically selects and transmits the appropriate service certificate through the VPN tunnel without requiring manual intervention from administrators or pre-configuration by service technicians.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If plaintext service certificate transmission is used, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improvecertificate transmission simplicityVSAvoidtransmission security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The VPN tunnel acts as a secure intermediary channel that encrypts all transmissions between the service technician's computer and the automation terminal. This allows the service certificate to be transmitted in a simplified manner through the tunnel while maintaining security, as the tunnel provides encryption without requiring complex client-side security configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9235204B2Method for establishing a secure connection from a service technician to a component of an automation environment that can be remotely diagnosed and/or maintained and is experiencing failure
Publication Date: 2016.01.12 SIEMENS AG
  • US9235204B2 patent drawing
  • US9235204B2 patent drawing
  • US9235204B2 patent drawing

AI summary

A method for establishing a secure connection from a service technician to a component of an automation environment that can be remotely diagnosed and/or maintained and is experiencing failure. A service certificate is required for establishing the secure connection, wherein a secure initial connection is first established to the automation environment by the service technician using a one-time password. With the initial connection, a service certificate required for establishing the secure connection to the component of the automation environment experiencing the failure is subsequently transmitted from the automation environment to the service technician. The secure connection from the service technician to the component experiencing the failure is then established by means of the service certificate. The invention further relates to an automation environment that is suitable for carrying out a method of said kind.