Central Security Level Assignment for Industrial Control Components

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face challenges in safeguarding against cyber threats due to their heterogeneous and modular nature, with existing security measures being time-consuming and error-prone, and lacking a systematic way to determine overall security levels, especially in systems providing online access.

Innovation Solution

A security unit that centrally assigns and manages security levels to components of an industrial control system via a data network, allowing for unified security settings and real-time adjustments, with a database to track and output security information and instructions for users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual components or firewalls are configured separately to establish security, then security coverage is improved, but time consumption and error rate increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple individual security configurations into a single centralized security level assignment. By defining a system security level that automatically propagates to all components, the system merges numerous separate configuration tasks into one unified operation, dramatically reducing configuration time while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements a universal security level framework that can be applied across all components regardless of their specific functions or manufacturers. This multi-functional approach allows a single security level definition to serve multiple components simultaneously, eliminating the need for individualized security configurations for each component type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual components are configured separately for security, then comprehensive security control is achieved, but operational complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the complexity of individual component security configurations into a single centralized security level definition. The system automatically handles the propagation and application of security levels to all components, transforming a complex multi-step configuration process into a simple single-step operation for the user.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs self-service by automatically assigning and configuring security levels on all components based on the centrally defined system security level. This eliminates the need for users to manually configure each component, reducing operational complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #25Self-service

3Productivity

If centralized security level assignment is implemented, then configuration efficiency is improved, but adaptability to specific component requirements may be reduced

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidcomponent-specific security adaptation
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by allowing each component to receive and apply the centralized security level according to its specific characteristics and requirements. While the system security level is defined centrally, each component can interpret and implement it in a way that is appropriate for its specific function, manufacturer, and security needs, thus maintaining both efficiency and adaptability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11146591B2Security unit and method for an industrial control system
Publication Date: 2021.10.12 CODESYS HLDG GMBH
  • US11146591B2 patent drawing
  • US11146591B2 patent drawing
  • US11146591B2 patent drawing

AI summary

A security unit for an industrial control system comprises an interface adapted to communicate with a plurality of components of an industrial control system via a data network, a security assignor adapted to access a first component among the plurality of components via the interface, and further adapted to assign a first security level pertaining to the first component to the first component. The security assignor is further adapted to access a second component among the plurality of components via the interface, and to assign a second security level pertaining to the second component to the second component. The security assignor is adapted to assign the first security level and the second security level to the first component and the second component, respectively, in accordance with a system security level pertaining to the industrial control system.