Containerized Control Application Execution With Host Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing and configuring control applications in industrial automation systems require complex manual processes, are prone to errors, and lack efficient validation mechanisms, especially for future quantities of applications.

Innovation Solution

A method and system that utilize software-implemented containers on a host, where a check component calculates a check identifier using host-specific and application features, verified by a registration component to generate device and application instance certificates, enabling secure and automated configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration processes are used for securing control applications, then security can be maintained, but the process becomes complex and time-intensive

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs automatic self-configuration through the following process: when a control application is deployed, the host automatically generates a check identifier based on host-specific features and application features, communicates this to the registration component, which automatically verifies and issues certificates. This eliminates manual configuration while maintaining security through automated cryptographic verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The registration component performs preliminary verification of the check identifier against stored reference data before issuing certificates. This advance validation ensures that only authorized applications can be deployed, preventing security issues before they arise while eliminating the need for manual security configuration.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration is required for control applications, then security validation can be performed, but errors increase and time consumption increases

Engineering Contradiction:
Improvesecurity validationVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically performs security validation through automated cryptographic verification. The registration component verifies the check identifier against stored reference data and automatically issues certificates without manual intervention, reducing configuration time while maintaining reliable security validation through automated verification processes.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated container execution is implemented, then deployment efficiency improves, but security validation becomes more challenging

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidsecurity validation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs security validation before automated deployment by verifying the check identifier against stored reference data in the registration component. This preliminary verification ensures that only authorized applications are deployed automatically, maintaining security reliability while enabling efficient automated deployment through containerization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The registration component acts as an intermediary between the automated deployment system and the security validation process. It receives check identifiers from the automated container deployment, verifies them against stored reference data, and issues certificates, thereby enabling both automated deployment efficiency and reliable security validation through this intermediate verification layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12407527B2Host, method and system for the securely executing control applications
Publication Date: 2025.09.02 SIEMENS AG
  • US12407527B2 patent drawing
  • US12407527B2 patent drawing

AI summary

A method for securely executing control applications via software-implemented containers which are each loadable into a container runtime environment set up on a host and are executable there, wherein a check component of the respective host calculates a respective check identifier via host-specific features and via features of the respective control application, where the check identifier and an initial application certificate of the control application are communicated to a registration component, the registration component verifies the check identifier and the initial application certificate and, in cases of a positive verification result, creates a device configuration certificate and an application instance certificate and communicates them to the host, linking of the application instance certificate with the control application is authorized via the device configuration certificate, and where execution of the container providing the control application on the host is authorized by the application instance certificate.