Certificate Service for Industrial Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industrial control systems, the manual renewal and management of operational certificates lead to storage overloads and potential communication interruptions due to multiple identical certificates with varying validity periods, and the lack of automatic revocation mechanisms increases the risk of using revoked certificates.
Innovation Solution
A computer-implemented certificate service that checks for duplicate certificates based on validity periods and initiates the revocation and removal of the earliest-expiring certificates, ensuring only the latest valid certificate remains stored, with optional confirmation from a certification authority and logging for audit trails.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple operational certificates are stored in the certificate store for renewal purposes, then certificate renewal can be performed, but the certificate store becomes overloaded and search times increase
Solution Approach 1:
The patent extracts and removes expired or revoked certificates from the certificate store, keeping only valid certificates. The certificate service automatically detects and removes certificates that have exceeded their validity period or been revoked, preventing store overload while maintaining renewal capability for valid certificates.
Solution Approach 2:
The patent performs preliminary validation and revocation checking before certificates are added to the store. The certificate service checks whether renewal certificates are actually needed and valid before storing them, preventing unnecessary accumulation of certificates in advance.
2Ease of operation
If manual certificate management is used, then flexibility is maintained, but communication interruptions may occur due to use of revoked certificates
Solution Approach 1:
The patent implements automatic feedback mechanisms where the certificate service continuously monitors certificate validity status and revocation information. When a certificate is revoked or expires, the system automatically receives notification and takes corrective action, eliminating the need for manual monitoring while maintaining communication reliability.
Solution Approach 2:
The certificate service performs self-service by automatically detecting revoked or expired certificates and removing them without human intervention. The system autonomously manages certificate validity, preventing communication interruptions caused by using invalid certificates.
3Productivity
If automated certificate management is implemented, then certificate issuance is streamlined, but duplicate certificates with overlapping validity periods may be stored
Solution Approach 1:
The patent implements dynamic certificate management where the system automatically adjusts the certificate portfolio based on current validity requirements. The certificate service dynamically removes duplicates and expired certificates, adapting the store contents to actual needs rather than maintaining static accumulations.
Solution Approach 2:
The patent systematically discards duplicate and expired certificates while recovering only the necessary valid certificates for communication. The certificate service identifies and removes redundant certificates, keeping only those currently needed for operational purposes.
Data Source
AI summary
A control system for a technical installation, in particular a process or manufacturing installation, includes at least one component upon which a certificate service is computer implemented, wherein the certificate service is configured to check a certificate store that is assigned to the component or a further component to determine whether two or more certificates, which only differ from one another in terms of their validity period, are stored in the certificate store, and in the event of the check identifying two or more certificates of this type, to initiate revocation and removal from the certificate store of the certificate or certificates with the validity period that ends the earliest, such that only the certificate with the validity period that ends the latest remains stored in the certificate store.

