Automated Configuration Management for CIP Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for capturing baseline configurations in critical infrastructure protection are tedious, error-prone, and unable to detect ongoing system changes, failing to efficiently comply with CIP standards.

Innovation Solution

A computerized system and method using a configuration management tool that collects system information from devices on a network, compares it to baseline configurations, and generates reports on changes, improving compliance and security by automating the tracking of configuration changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual methods (screen shots and command line output) are used to capture baseline configurations, then the process can be performed with simple tools, but it becomes tedious and time consuming

Engineering Contradiction:
Improveease of configuration captureVSAvoidtime to capture baseline
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical operations (screen shots, copying command line output) with an automated software tool that programmatically collects system information. The tool uses built-in system commands and automated scripts to gather configuration data, eliminating the need for manual intervention and significantly reducing the time required to capture baseline configurations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The configuration management tool performs self-service by automatically executing system commands, collecting configuration data, and generating baseline profiles without requiring manual operation. The tool independently navigates through system interfaces, captures relevant information, and structures it into usable baseline configurations, making the process autonomous and efficient.

Inventive Principle:
Principle #25Self-service

2Device complexity

If manual capturing techniques are used, then no additional software is required, but the process becomes error-prone

Engineering Contradiction:
Improvesoftware requirementsVSAvoidaccuracy of baseline capture
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces error-prone manual operations with automated software execution. The tool programmatically collects system information using built-in commands, eliminating human errors such as misreading screens, incorrect copying, or missing configuration details. The automated process ensures consistent and accurate data capture across all systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The configuration management tool incorporates feedback mechanisms to verify the accuracy and completeness of captured configuration data. The system validates collected information against expected formats and ranges, flags anomalies for review, and ensures data integrity before finalizing baseline profiles, thereby significantly improving reliability.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If existing software products are used to gather system parameters, then some automation is achieved, but they cannot capture all necessary system information and cannot detect changes on an on-going basis

Engineering Contradiction:
Improveautomation of configuration gatheringVSAvoidcompleteness of system information
Core Design Contradiction:
Extent of automationVSLoss of information

Solution Approach 1:

The patent implements a universal configuration management tool that performs multiple functions: it gathers comprehensive system parameters, establishes baselines, detects changes, and provides ongoing monitoring. The tool is designed to work across diverse system types and configurations, capturing all necessary information including hardware, software, network settings, and security configurations in a single integrated platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The configuration management tool enables continuous monitoring and detection of configuration changes by periodically comparing current system states against established baselines. The system operates on an ongoing basis rather than as a one-time capture tool, providing continuous security compliance verification and change detection across all managed systems.

Inventive Principle:
Principle #20Continuity of useful action

4Reliability

If comprehensive system information is collected, then better compliance and security are achieved, but the complexity of the system increases

Engineering Contradiction:
ImproveCIP compliance accuracyVSAvoidcomplexity of configuration management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the configuration management system into modular functional components: information collection modules, baseline establishment modules, change detection modules, and reporting modules. Each module handles specific aspects of configuration management independently, making the overall system more manageable and maintainable while comprehensively collecting and analyzing system information for CIP compliance.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11799875B2Computerized system for complying with certain critical infrastructure protection requirements
Publication Date: 2023.10.24 HOOSIER ENERGY RURAL ELECTRIC COOP
  • US11799875B2 patent drawing
  • US11799875B2 patent drawing
  • US11799875B2 patent drawing

AI summary

A computerized system for complying with critical infrastructure protection (“CIP”) standards concerning system configuration changes. The system can be used to automatically identify and track changes to computers on the network, improving system security and CIP compliance reporting. In certain embodiments, the system collects system information on servers and workstations using built-in commands. The configuration profiles of these computers/devices can be archived for audit purposes.