Configuration Module Authorization for Secure Device Replacement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for configuring devices in IoT environments, particularly in industrial automation systems, fail to reliably distinguish between old and new devices during operation, leading to potential security vulnerabilities due to the sharing of configuration data without proper authentication.
Innovation Solution
A method involving a configuration module that requests and stores a configuration module-specific credential on a device's security storage unit, using device-specific information to authenticate the device and ensure only authorized devices are recognized within the network, with mechanisms for revoking credentials upon disconnection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If configuration data is stored on a detachable configuration module for rapid device replacement, then device replacement speed is improved, but device security is worsened because old and new devices cannot be distinguished during operation
Solution Approach 1:
The patent divides the authentication system into two parts: configuration data stored on the detachable configuration module and device-specific credentials stored in the security storage unit of each device. This segmentation allows the configuration module to be reused across multiple devices while each device maintains its own unique authentication credentials, resolving the contradiction between rapid replacement and security.
Solution Approach 2:
The patent introduces an authorization device as an intermediary that issues configuration module-specific credentials. This intermediary verifies the configuration module's device information and provides authenticated credentials to the first device, enabling secure authentication without compromising replacement speed. The authorization device acts as a trusted mediator between the configuration module and the device.
2Loss of time
If configuration data is transferred from a configuration module to enable rapid device replacement, then configuration time is reduced, but network security is worsened due to potential unauthorized access
Solution Approach 1:
The patent implements preliminary authentication by requiring the first device to request and receive configuration module-specific credentials from the authorization device before actual configuration transfer. This preliminary security check ensures that only authenticated devices can receive configuration data, preventing unauthorized access while maintaining rapid configuration deployment.
Solution Approach 2:
The patent establishes a feedback mechanism where the first device sends a request message containing device information to the authorization device, which then verifies the information and returns appropriate credentials. This feedback loop ensures that configuration data is only transferred to authorized devices, securing the network while enabling fast configuration.
3Reliability
If device credentials are stored on a security storage unit for better protection, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent employs a universal security storage unit design that can be integrated into various device types within the automation network. This standardized security storage component provides consistent credential protection across different devices, reducing overall system complexity despite the added security functionality. The same security storage architecture serves multiple devices and purposes.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
The invention relates to a method for setting up an authorisation verification for a first device (FD1), for example a field device in an automation system, wherein the first device (FD1) is configured by means of configuration data transmitted to the first device (FD1) from a configuration module (CM) that is detachably connected to the first device (FD1) and, for example, is implemented in the form of an SD card or a USB stick, having: detection of a connection (S1) of a configuration module (CM) to the first device (FD1), reading (S2) configuration module-specific device information (Kn) from the configuration module (CM), requesting (S3) configuration module-specific authorisation verification (C-Kn) for the configuration model-specific device information (Kn) from the first device (FD1) in an authorisation device (BE), and storing (S6) the requested configuration module-specific authorisation verification (C-Kn) on a security storage unit (SE) of the first device (FD1).