Cloud PKI for OT Device Certificate Lifecycle Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations operating industrial devices often lack the capability or desire to manage public key infrastructure (PKI) for their operational technology (OT) devices, and third parties face challenges interfacing with different PKIs managed by multiple customers, leading to difficulties in securing and managing these devices.

Innovation Solution

A cloud-based PKI managed by a third party, such as Rockwell Automation via a cloud-hosted service like FactoryTalk Hub, is provided as a service, allowing machine builders and system integrators to provision industrial equipment with certificates that define access levels and zones, enabling secure operation and easy certificate management across multiple organizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations manage their own PKI for OT devices, then security control and customization are improved, but operational complexity and management burden increase

Engineering Contradiction:
Improvesecurity controlVSAvoidPKI management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A cloud-based PKI service acts as an intermediary between certificate authorities and OT devices, managing certificate lifecycle operations (generation, renewal, revocation) remotely. This mediator approach allows organizations to maintain security control through centralized management while avoiding the operational complexity of direct PKI management on each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The PKI system enables automated self-service operations where certificates are automatically generated, renewed, and revoked based on predefined policies and expiration dates. The system monitors certificate validity periods and performs renewal operations without manual intervention, reducing the management burden while maintaining security standards.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If third parties interface with multiple customer PKIs, then service coverage and versatility are improved, but integration complexity and operational difficulty increase

Engineering Contradiction:
Improveservice coverageVSAvoidinterface complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The cloud-based PKI service provides a universal interface that works across multiple customer organizations and device types. By consolidating PKI management in the cloud, the system achieves multi-functionality serving diverse customers (device manufacturers, system integrators, end users) through a single standardized interface, eliminating the need for third parties to adapt to multiple different PKI implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple customer PKIs are merged into a single cloud-based management platform. Instead of third parties interfacing with separate PKI systems for each customer, all PKI operations are combined and managed centrally in the cloud, simplifying the interface to a single unified system while maintaining the ability to serve multiple organizations.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If certificates are manually managed on OT devices, then security precision is improved, but time consumption and operational efficiency decrease

Engineering Contradiction:
Improvecertificate securityVSAvoidcertificate management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-configuring certificate policies, expiration monitoring, and renewal workflows before certificates are needed. Certificate renewal operations are initiated automatically before expiration based on predefined time thresholds, ensuring security requirements are met while eliminating manual intervention and improving operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The PKI system implements continuous feedback monitoring of certificate validity periods, expiration dates, and renewal status. This feedback mechanism triggers automated renewal processes when certificates approach expiration, maintaining security precision while improving efficiency by eliminating manual tracking and intervention. The system provides status feedback to stakeholders about certificate health and renewal progress.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250106044A1Systems and methods for public key infrastructure
Publication Date: 2025.03.27 ROCKWELL AUTOMATION TECH INC
  • US20250106044A1 patent drawing
  • US20250106044A1 patent drawing
  • US20250106044A1 patent drawing

AI summary

A method includes receiving, at a certificate authority, from a first organization in possession of an operational technology (OT) device, a first certificate signing request and a public key, verifying the first certificate signing request, generating, a certificate, transmitting the certificate to the first organization for storage in memory of the OT device along with the public key, receiving, from a second organization in possession of the OT device, a second certificate signing request and the public key, verifying one or more second pieces of information in the second certificate signing request, generating a new certificate, and transmitting the new certificate to the second organization for storage in memory of the OT device along with the public key.