Industrial Monitoring Component Verification Using Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security anomaly detection tools in industrial monitoring systems are vulnerable to manipulation of component identities due to the use of unreliable and easily replicable MAC addresses, leading to potential system integrity and availability risks.
Innovation Solution
A system and method that utilizes a first module to establish a relationship of trust with components and request a component certificate, and a second module to check the certificate against trustworthy data, including trust chains and blacklists, ensuring authenticity and integrity of the component identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If MAC addresses are used to identify components, then automatic detection and inventory creation is simplified, but the reliability and trustworthiness of component identity verification deteriorates due to ease of replication and manipulation
Solution Approach 1:
The patent introduces a certificate authority as an intermediary that issues digital certificates to components. These certificates serve as trusted intermediaries that verify component identities, replacing the direct reliance on manipulable MAC addresses with a trusted third-party verification mechanism.
Solution Approach 2:
The patent creates a trusted copy of component identity information in the form of digital certificates issued by the certificate authority. Instead of directly using the original MAC address which can be copied and manipulated, the system uses a verified copy (certificate) that proves the component's authenticity.
2Reliability
If security verification mechanisms are implemented, then system security and component authenticity are improved, but the complexity of the monitoring system increases
Solution Approach 1:
The patent performs security verification in advance before components are fully integrated into the monitoring system. The certificate authority verifies component identities beforehand and issues certificates, so that when components join the network, the verification is already complete and does not add operational complexity.
Solution Approach 2:
Components automatically obtain and present their own certificates for verification without requiring manual intervention. The system self-verifies component identities through automated certificate checking, reducing the operational burden despite the added security layer.
Data Source
AI summary
A system for verifying components of an industrial monitoring system includes a first module which is configured to establish a trust relationship with a component of the industrial monitoring system and request a component certificate from the component. The component certificate contains relevant information relating to the component. A second module is configured to check, in interaction with the component, the component certificate on the basis of relevant data stored in a trusted database, and to generate a notification on the basis of the result of the checking process.


