Industrial Control Command Authentication via Signed Action Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to unauthorized access and malicious software due to the lack of robust authentication mechanisms, which can lead to unauthorized changes in control parameters and data access.

Innovation Solution

Implementing a secure authentication path using action authenticators to sign and verify action requests, ensuring that only authenticated requests are processed by communications/control modules, thereby preventing malicious or unauthorized actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If operator authentication is used to control action requests, then ease of operation is improved, but system security deteriorates due to vulnerability to unauthorized access and malicious software

Engineering Contradiction:
Improveease of operationVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a digital signature verification mechanism as an intermediary between the operator authentication and the action request processing. The communications/control module verifies digital signatures on action requests before executing them, acting as a mediator that ensures the authenticity and integrity of commands while maintaining the ease of operator interface usage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital signature verification is implemented for all action requests, then system security is improved, but device complexity increases due to additional authentication path requirements

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary digital signature verification as a standard part of the action request processing workflow. By establishing this verification step in advance as a routine operation, the system prepares the authentication path beforehand, reducing the perceived complexity during actual operation while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If action requests require digital signatures, then protection from malware and unauthorized access is improved, but processing time increases due to verification requirements

Engineering Contradiction:
Improveprotection from malwareVSAvoidprocessing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent replaces manual security verification processes with automated digital signature verification mechanisms. This substitution eliminates the need for manual authentication checks while providing robust malware protection, thereby reducing the time loss associated with manual verification while maintaining strong security defenses.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3823425B1Operator action authentication in an industrial control system
Publication Date: 2024.02.28 BEDROCK AUTOMATION PLATFORMS INC
  • EP3823425B1 patent drawingFigure 1
  • EP3823425B1 patent drawingFigure 2
  • EP3823425B1 patent drawingFigure 3

AI summary

Operator actions and/or other commands or requests are secured via an authentication path from an action originator to a communications/control module or any other industrial element/controller. In implementations, an industrial control system includes an action authenticator configured to sign an action request generated by the action originator. The destination communications/control module or any other industrial element/controller is configured to receive the signed action request, verify the authenticity of the signed action request, and perform a requested action when the authenticity of the signed action request is verified.