Digital Certificate Security Classification Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices in installations and systems lack self-awareness of their security classification, making it difficult to verify compatibility with the security classification of their operational zones during autoconfiguration and communication, which is crucial for ensuring secure integration and operation.

Innovation Solution

Incorporating an identifier of security classification into digital certificates, which can be extended and verified against predetermined security rules, allowing devices to authenticate and ensure compatibility through secure communication and policy adherence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are used in installations and systems, then they can perform their functional operations, but they lack self-awareness of their security classification and cannot verify compatibility with operational zones

Engineering Contradiction:
Improvesecurity classification awarenessVSAvoiddevice self-awareness capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A certificate issuing apparatus is introduced as an intermediary that provides security classification information to devices through digital certificates. This mediator enables devices to become aware of their security classification without requiring complex self-assessment capabilities, resolving the contradiction by externalizing the verification function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where devices receive security classification information from the certificate issuing apparatus and use this information to verify compatibility with operational zones. This feedback loop enables devices to understand their security status and adjust their behavior accordingly.

Inventive Principle:
Principle #23Feedback

2Reliability

If digital certificates are extended with security classification identifiers, then device authentication and compatibility verification are enabled, but the certificate structure becomes more complex

Engineering Contradiction:
Improvedevice authentication capabilityVSAvoidcertificate structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The digital certificate structure is designed to serve multiple functions: traditional device authentication and additional security classification verification. By making the certificate multi-functional, the system avoids creating separate complex verification mechanisms while still enabling comprehensive security checks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Security classification information is prepared and included in the digital certificate before the device needs to authenticate. This preliminary action ensures that all necessary security verification data is already available, eliminating the need for complex real-time verification procedures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security classification verification is performed during autoconfiguration, then proper device integration is ensured, but the configuration process becomes more time-consuming

Engineering Contradiction:
Improvedevice integration compatibilityVSAvoidautoconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security classification information is obtained and verified before the autoconfiguration process begins. By performing this verification in advance, the actual configuration process does not need to include time-consuming security checks, thereby reducing overall configuration time while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once security classification verification is completed preliminarily, the autoconfiguration process can proceed rapidly through the remaining steps without repeated security verification. This allows the system to skip redundant verification steps during the main configuration phase.

Inventive Principle:
Principle #21Skipping (Rushing through)

4Reliability

If devices must adhere to security policies in high-security zones, then security compliance is ensured, but device operation flexibility is reduced

Engineering Contradiction:
Improvesecurity policy complianceVSAvoiddevice operation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Devices receive feedback about their security classification status and use this information to automatically adjust their operations to comply with security policies. This feedback mechanism enables compliance without requiring manual intervention or rigid predetermined configurations, maintaining operational flexibility.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system allows devices to dynamically adjust their operations based on their security classification and the security requirements of the operational zone. This dynamic adaptation enables devices to comply with security policies while maintaining the flexibility to perform their functions effectively.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11134072B2Method for verifying a security classification of a first device using a digital certificate, a first and second device and certificate issuing apparatus
Publication Date: 2021.09.28 SIEMENS AG
  • US11134072B2 patent drawing
  • US11134072B2 patent drawing
  • US11134072B2 patent drawing

AI summary

Provided is a method for checking a safety rating of a first device with the aid of an associated digital certificate, including the steps: sending the digital certificate having an identifier of a safety rating from the first device to a second device, checking the identifier of the safety rating with respect to a predefined safety rule by means of the second device, executing safety measures in accordance with the result of checking the safety rules.