Automation Unit Allocation Using Certificate Revocation Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for transferring automation units between industrial installations are inconvenient, time-consuming, and error-prone, leading to productivity losses due to the need for repeated engineering changes and potential conflicts between automation servers.
Innovation Solution
A central management unit is introduced to manage certificates and communication between automation servers and units, ensuring that only one server can access an automation unit by revoking chains of trust and blocking certificates, thus preventing simultaneous access and allowing for efficient allocation of installation parts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If engineering changes are made to transfer automation units between installations, then the automation units can be allocated to different installations, but the process becomes time-consuming and error-prone
Solution Approach 1:
The system performs preliminary actions by pre-configuring the automation unit with a certificate containing a reference to a black list storage location before the unit is transferred. This allows the automation server to automatically validate certificates and manage access rights without requiring engineering changes during the transfer process, thereby reducing transfer time while maintaining allocation flexibility
Solution Approach 2:
The patent introduces a certificate and black list reference as intermediaries between the automation unit and automation servers. The certificate contains a reference to a black list storage location, which serves as a mediator to communicate access rights and restrictions. This intermediary mechanism eliminates the need for direct engineering changes during unit transfer, streamlining the allocation process
2Adaptability or versatility
If engineering changes are made to transfer automation units between installations, then the automation units can be allocated to different installations, but errors may occur during the transfer process
Solution Approach 1:
The automation server implements a feedback mechanism by automatically validating the certificate and checking the black list at runtime. This feedback loop ensures that the automation server can detect and prevent access conflicts or invalid configurations without human intervention, thereby improving transfer reliability while maintaining allocation flexibility
Solution Approach 2:
The system enables self-service by allowing the automation server to automatically manage certificate validation and black list checking without requiring engineering personnel to manually configure or modify settings during transfers. This automated self-service approach reduces human error and improves transfer reliability
3Adaptability or versatility
If multiple automation servers can access the same automation unit, then system flexibility is improved, but access conflicts occur between servers
Solution Approach 1:
The black list reference in the certificate serves as an intermediary mechanism to manage access rights. The automation server checks the black list to determine whether the automation unit is currently accessible, thereby preventing access conflicts while maintaining system flexibility. This intermediary approach allows multiple servers to potentially access units without direct conflicts
4Reliability
If engineering changes are required for each transfer, then precise control over automation unit allocation is achieved, but productivity is reduced
Solution Approach 1:
The system performs preliminary configuration by embedding a certificate with a black list reference in the automation unit before transfer. This preliminary setup enables automated validation and access control during transfers, eliminating the need for time-consuming engineering changes and improving transfer efficiency while maintaining precise allocation control
Solution Approach 2:
The patent replaces the mechanical process of engineering changes with an automated electronic validation system. The automation server electronically validates certificates and checks black lists programmatically, substituting manual engineering operations with automated digital processes. This substitution significantly improves transfer efficiency while maintaining allocation control
Data Source
AI summary
An automation system includes at least one automation unit, multiple automation servers and a central management unit interconnected via a communication network, wherein the automation servers communicate with the automation unit using a pre validated certificate of the automation unit, where in order to validate the certificate, the automation servers check a chain of trust of the respective certificate and, by accessing a black list, the validity thereof, where communication of the respective chain of trust only occurs when corresponding chains of trust are revoked from all other automation servers beforehand, corresponding certificates are entered into the black list or the certificate is otherwise invalid.


