Controller Backplane Authentication Against Rogue Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face security vulnerabilities due to the lack of access control technology on the controller backplane, making it possible for rogue modules to disrupt control systems or access sensitive information.

Innovation Solution

Implementing an industrial controller module with a device authentication component that detects modular devices on the backplane, exchanges authentication data, and initiates or disables operation based on authentication results, ensuring only authorized devices can operate on the backplane.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control technology is implemented on the backplane, then security against rogue modules is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication by exchanging authentication data between the processor module and modular devices before allowing operation on the backplane. The device authentication component detects modular devices and performs authentication sequences in advance, verifying security credentials and generating challenge-response pairs before the devices are permitted to communicate over the backplane. This preliminary security check prevents rogue modules from gaining access without compromising the overall system architecture.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication sequences are performed for all modular devices, then security against unauthorized access is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials and security certificates are pre-provisioned to modular devices during manufacturing or initial setup. When a modular device is installed on the backplane, the authentication process utilizes these pre-existing credentials rather than requiring complex real-time verification from scratch. The processor module generates challenge data and compares it against pre-stored authentication information, significantly reducing the time required for authentication while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses certificate-based authentication where security credentials are copied and distributed to authorized modular devices in advance. Each modular device receives a digital certificate containing its authentication credentials, which it can present to the processor module for verification. This copying approach allows for rapid authentication by simply verifying the presented certificate against the issuer's public key, rather than performing complex computational authentication in real-time.

Inventive Principle:
Principle #26Copying

3Reliability

If security credential verification is implemented, then protection against counterfeit modules is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The device authentication component automatically performs authentication sequences with modular devices without requiring manual intervention from operators. When a modular device is installed, the system autonomously detects it, initiates the authentication process, exchanges security credentials, and either permits or denies operation based on verification results. This self-service approach eliminates the need for operators to manually verify security credentials or configure authentication settings, maintaining ease of operation while ensuring security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3518133B1Authenticated backplane access
Publication Date: 2025.06.04 ROCKWELL AUTOMATION TECH INC
  • EP3518133B1 patent drawingFigure 1
  • EP3518133B1 patent drawingFigure 2
  • EP3518133B1 patent drawingFigure 3

AI summary

Industrial controller modules are configured with security components that implement backplane-level security protocols, thereby preventing installation of unauthorized modular devices on the backplane of an industrial controller. When a modular device is installed in the controller's chassis and interface with the backplane, security components in the processor module or other supervisory module initiates exchange of authentication data with the modular device via the backplane. The authentication data can comprise one or more security challenges to which the modular device must respond correctly before the modular device is permitted to operate on the backplane. These backplane-level security protocols can prevent installation of rogue modules that may be used to collect proprietary control data or interfere with control processes.