Configuration Module Credentials for Secure Device Replacement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for configuring devices in IoT and industrial networks fail to securely distinguish between old and new devices during replacement, as they share the same configuration data, leading to potential security vulnerabilities.
Innovation Solution
A method that involves recognizing the connection of a configuration module to a device, reading device-specific information, requesting a configuration module-specific credential from an authorization apparatus, and storing it on a security storage unit, which includes steps to check for existing credentials, request only when necessary, and revoke upon disconnection, ensuring secure authentication and differentiation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the same configuration data is used for both old and new devices during replacement, then fast device exchange is achieved, but security is compromised as devices cannot be distinguished
Solution Approach 1:
The patent segments the configuration data into two distinct parts: shared configuration data (stored on the configuration module for fast exchange) and device-specific credentials (stored securely in the device's security storage unit). This segmentation allows both fast exchange and device distinction to coexist.
Solution Approach 2:
The patent introduces configuration module-specific credentials as an intermediary element that bridges the configuration module and the device. These credentials are generated based on both the configuration module information and device information, enabling the system to distinguish between different device-configuration combinations while maintaining fast exchange capability.
2Ease of operation
If sensitive security configuration data is stored on the configuration module in plain text or encrypted with group key, then configuration exchange is simplified, but security protection is insufficient
Solution Approach 1:
The patent applies local quality by implementing different security measures for different types of data. Configuration data that doesn't require high security is stored on the configuration module, while device-specific credentials and sensitive security data are stored in the device's security storage unit with enhanced protection measures such as tamperproofing and secure cryptographic storage.
Solution Approach 2:
The patent changes the security parameters for storing configuration data. Instead of using plain text or simple group key encryption, it implements device-specific credential-based authentication and secure cryptographic storage with tamper detection capabilities, significantly enhancing security while maintaining operational simplicity.
3Reliability
If configuration module-specific credentials are requested and stored for each configuration module connection, then device authentication is enhanced, but computing capacity and transmission capacity are consumed
Solution Approach 1:
The patent implements preliminary action by checking whether a configuration module-specific credential already exists before initiating a new credential request. This prevents redundant cryptographic operations and network transmissions, reducing energy consumption while maintaining security.
Solution Approach 2:
The patent uses feedback mechanisms to track the status of credentials associated with configuration modules. The system monitors which credentials are currently active and uses this information to avoid generating duplicate credentials, thereby optimizing resource usage while maintaining authentication security.
Data Source
AI summary
Provided a method for setting up an authorization verification for a first device, for example a field device in an automation system, wherein the first device is configured by configuration data transmitted to the first device from a configuration module that is detachably connected to the first device and, for example, is implemented in the form of an SD card or a USB stick, having: detection of a connection of a configuration module to the first device, reading configuration module-specific device information from the configuration module, requesting configuration module-specific authorization verification for the configuration model-specific device information from the first device in an authorization device, and storing the requested configuration module-specific authorization verification on a security storage unit of the first device.


