Context-Aware Security Assessment for Industrial Device Lifecycles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial devices require dynamic and context-aware security self-assessment due to varying usage scenarios and lifecycle stages, as static security settings are not sufficient to ensure security across different operational phases, unlike consumer devices.

Innovation Solution

A method and system for context-aware security self-assessment that allows industrial devices to assess their current context and adjust security settings based on predefined, customizable rules, providing suggested actions to operators for adapting settings to ensure security without requiring external computers, enabling dynamic security adjustments throughout the device's lifecycle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security self-assessment is implemented in industrial devices, then security awareness is improved and vendor trust is established, but the assessment cannot adapt to different usage scenarios and lifecycle stages

Engineering Contradiction:
Improvesecurity settings reliabilityVSAvoidadaptability to different usage scenarios
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security self-assessment that adapts to different lifecycle stages (engineering, commissioning, operation) and usage scenarios. The system dynamically adjusts assessment criteria based on the device's current context, enabling security settings to be evaluated appropriately for each phase rather than using fixed static rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes assessment parameters based on the device's lifecycle stage and operational context. Different security criteria and thresholds are applied depending on whether the device is in engineering mode, commissioning phase, or operational phase, allowing the same device to have different security requirements at different times.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If dynamic context-aware security self-assessment is implemented, then security settings adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveadaptability to lifecycle stagesVSAvoidself-assessment system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security self-assessment into distinct lifecycle stages (engineering, commissioning, operation), with specific assessment criteria for each stage. This segmentation allows the complex adaptive assessment to be broken down into manageable, context-specific evaluation modules rather than a single monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device performs self-assessment of its own security settings automatically based on its detected lifecycle stage and operational context. The system monitors itself and generates appropriate security assessments without requiring external intervention, reducing the operational overhead despite the increased internal complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If security settings are customized for each lifecycle stage, then security posture is improved, but operational overhead increases

Engineering Contradiction:
Improveoverall security postureVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-configures security assessment criteria and recommended settings for each lifecycle stage. When the device transitions between stages, the system automatically applies the pre-defined assessment rules for that stage, eliminating the need for manual security configuration and reducing operational overhead while maintaining appropriate security postures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides automated feedback to operators about security settings appropriate for the current lifecycle stage. This feedback mechanism guides operators in making correct security configurations without requiring extensive expertise or time, thereby improving security posture while minimizing operational overhead.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10990684B2Context-aware security self-assessment
Publication Date: 2021.04.27 HITACHI ENERGY LTD
  • US10990684B2 patent drawing
  • US10990684B2 patent drawing

AI summary

The present invention generally relates to a context-aware security self-assessment method or module that determines the context in which the device is used and based on this, assesses the devices security settings. The context may refer to the system environment, the applications the device is used for, and/or the current life-cycle stage of the device, without being limited to said contexts. The method of the present invention preferably prioritizes and rates the security relevant findings and presents them in combination with mitigation options through a web interface, a configuration tool, or through notifications in the control system.