Graphical Challenge Authentication for Industrial Edge Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial edge devices in IoT-enabled industrial plants are vulnerable to malicious hacking due to insufficient authentication methods, posing a significant security risk.

Innovation Solution

Implementing a multi-factor authentication system that includes graphical authentication tasks, such as puzzles and CAPTCHA, along with credentials-based tasks, to verify user devices seeking access to industrial edge devices, using an authentication processor to determine access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for industrial edge devices, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication process is segmented into multiple distinct tasks: credential verification, graphical challenge presentation, and response validation. Each task handles a specific aspect of authentication, dividing the complex security process into manageable, sequential steps that maintain both security and usability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A graphical challenge-response mechanism serves as an intermediary between the user and the authentication system. The challenge task (displaying images, objects, or scenes) mediates the verification process by translating security requirements into intuitive visual interactions, making the authentication both secure and user-friendly

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-factor authentication with graphical tasks is implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication processor is designed with multi-functionality, handling credential verification, graphical challenge generation, response validation, and access control decisions within a single integrated system. This universal approach consolidates multiple authentication functions into one device, reducing overall system complexity while maintaining high security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically changes authentication parameters based on risk assessment and user context. The complexity of graphical challenges, verification thresholds, and task difficulty levels are adjustable parameters that can be modified to balance security requirements with system complexity, allowing the same authentication processor to handle both simple and complex authentication scenarios

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4650992A1Graphical user authentication for edge devices
Publication Date: 2025.11.19 SCHNEIDER ELECTRIC SYSTEMS USA INC
  • EP4650992A1 patent drawingFigure 1
  • EP4650992A1 patent drawingFigure 2
  • EP4650992A1 patent drawingFigure 3

AI summary

An authentication system for an industrial plant is configured for authenticating a user device to either permit or deny the user device access to an industrial edge device. The authentication system broadly comprises the industrial edge device, the user device, and the authentication processor. The industrial edge device is configured for at least one of monitoring and controlling an operation within the industrial plant. The user device is configured to communicate with the industrial edge device to request access to the industrial edge device. The authentication processor is associated with the industrial edge device, and the authentication processor is configured to communicate a graphical authentication task to the user device in response to the request for access. The authentication processor is further configured to verify a response to the graphical authentication task from the user device for determining whether to grant the user device access to the industrial edge device.