Container Security Information Classification for Industrial Edge Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for industrial automation lack reliable methods to assess and communicate the security risks of application containers used in Edge devices, which are critical for protecting confidential data and preventing potential damage from unauthorized access.

Innovation Solution

A method and system that analyze the data access and processing activities of application containers by obtaining information from the source code, classifying confidentiality and processing levels, and generating security information to be associated with the container, allowing for automatic and reliable risk assessment and certification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If application containers are deployed in industrial edge devices to enable data interchange between automation networks and public networks, then productivity and adaptability are improved, but security risks and potential damage from unauthorized access increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing security analysis of application containers before they are deployed to edge devices. The system extracts information from container manifests and images, analyzes security configurations, and generates security information records that indicate potential security risks. This pre-deployment analysis allows administrators to review and approve containers before they are executed in the industrial automation environment, preventing unauthorized access and data breaches while maintaining the adaptability benefits of container technology.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security checks are performed on application containers before use, then reliability is improved, but time consumption and complexity of the deployment process increase

Engineering Contradiction:
ImprovereliabilityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies copying by creating security information records that contain extracted information from application container manifests and images. Instead of performing complex security analysis every time a container is deployed, the system generates these records once during the security check process and stores them for quick reference during deployment. This allows rapid verification of security compliance without repeating the full analysis, significantly reducing time consumption while maintaining high reliability through consistent security validation.

Inventive Principle:
Principle #26Copying

3Reliability

If detailed security information is provided about application containers, then reliability and security awareness are improved, but device complexity and information processing requirements increase

Engineering Contradiction:
ImprovereliabilityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies extraction by pulling out specific security-related information from application container manifests and images and organizing it into structured security information records. The system extracts key elements such as security configurations, access permissions, and potential risk indicators, separating this security information from the rest of the container data. This extracted information is then presented in a simplified format that improves reliability and security awareness without overwhelming administrators with excessive complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11500991B2Method and system for providing security information about an application container for an industrial edge device
Publication Date: 2022.11.15 SIEMENS AG
  • US11500991B2 patent drawing
  • US11500991B2 patent drawing

AI summary

A method and a system for providing security information about an application container for an Industrial Edge device, wherein the application container displays an application, runtime libraries and parts of an execution environment, where first information is obtained from the application or source code, second information is obtained from the application program or source code of the application, where confidentiality classes and processing classes are ascertained, and where the security information is formed by linking arising confidentiality classes to arising processing classes and the security information is associated with the application container such that specific and reliable security information about the application container or applications is generated and the security information is provided to a user or an installation system via association of the security information with the application container or the application to make information about the specific security problems or properties available before an application is used.