Cloud Agent Authentication via Time-Limited Access Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial data collection and upload to cloud-based storage and processing infrastructure face challenges in secure authentication of on-premise cloud agents, which is crucial for secure communication and data integrity.

Innovation Solution

A system with an authentication component that authenticates cloud agent devices using access keys for a defined period, enabling secure communication and data processing, and includes a cloud data processing component that processes industrial data according to cloud platform instructions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud agents are authenticated using traditional methods, then security is improved, but authentication complexity and time consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the authentication mechanism by changing the parameter of authentication duration from permanent to temporary (time-limited). Access keys are issued with defined validity periods, requiring re-authentication after expiration. This temporal parameter change enhances security while maintaining operational simplicity through automated key management.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an authentication component as an intermediary between cloud agents and the cloud platform. This mediator issues time-limited access keys that enable secure communication without requiring complex continuous authentication protocols, simplifying the interaction while maintaining security through controlled access windows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If access keys are issued for long durations, then authentication overhead is reduced, but security risks increase

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies dynamics by making access key validity periods adjustable and configurable rather than fixed or permanent. The system can adapt key expiration times based on security requirements and operational needs, creating a dynamic balance between authentication efficiency and security risk management through flexible time-bound access control.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2924569B1Device authentication to faciliate secure cloud management of industrial data
Publication Date: 2020.11.11 ROCKWELL AUTOMATION TECH INC
  • EP2924569B1 patent drawingFigure 1
  • EP2924569B1 patent drawingFigure 2
  • EP2924569B1 patent drawingFigure 3

AI summary

Authentication of cloud agents that collect and/or process industrial data facilitates secure communications with a cloud platform. An authentication component receives an authentication request from a cloud agent device residing at an industrial facility. The authentication component also authenticate the cloud agent device in response to the authentication request for a defined period of time based on an access key that uniquely identifies the cloud agent device residing at the industrial facility. A cloud data processing component receives, at a cloud platform, one or more data packets from the cloud agent device during the defined period of time and processes industrial data contained in the one or more data packets according processing instructions associated with the cloud platform.