Control Application Flow Monitoring for Secure Industrial Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges in preventing malicious manipulation of program code due to vulnerabilities, leading to false alarms and costly interruptions, as existing exploit protection concepts are not effectively applicable.

Innovation Solution

A system and method for secure execution of control applications, where events are defined and triggered upon potential manipulation of program code, allowing continued processing while signaling events to an inspection device for analysis using updatable rules, enabling transfer into a safe operating state to avoid immediate shutdown and allowing controlled measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing exploit protection concepts are used to detect threats in control applications, then security against code manipulation is improved, but false alarms increase causing costly interruptions

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an inspection device as an intermediary component that operates separately from the program flow control device. This inspection device monitors events signaled by the control device and performs independent analysis using inspection rules, acting as a mediator between the control system and security response actions to reduce false alarms while maintaining protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where events triggered by potential manipulations are signaled from the program flow control device to the inspection device. The inspection device analyzes these events and provides feedback through updatable inspection rules, allowing the system to learn from false positives and improve discrimination between real threats and benign events

Inventive Principle:
Principle #23Feedback

2Reliability

If immediate shutdown is implemented upon detecting potential code manipulation, then security response time is improved, but unnecessary interruptions increase due to false positives

Engineering Contradiction:
Improvethreat responseVSAvoidoperational downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent defines safe operating states in advance that can be transferred to control applications upon event detection. Instead of immediate shutdown, the system prepares predetermined safe states that maintain operational continuity while ensuring security, allowing controlled transition rather than abrupt interruption

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts its response based on inspection results. Rather than a static immediate-shutdown policy, the inspection device can update inspection rules and adjust the severity of responses based on the actual threat level, allowing the system to maintain operations when threats are false positives while still responding to real dangers

Inventive Principle:
Principle #15Dynamics

3Reliability

If control applications are stopped immediately upon event triggering, then security is improved, but system adaptability decreases as patches cannot be installed

Engineering Contradiction:
Improvesecurity enforcementVSAvoidsoftware update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent defines safe operating states in advance that include various operational modes. These predetermined states allow the system to maintain adaptability by having pre-planned responses that can accommodate software updates and patches without requiring immediate shutdown, enabling controlled transitions that preserve both security and update capability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240219879A1Method, System and Inspection Device for Securely Executing Control Applications
Publication Date: 2024.07.04 SIEMENS AG
  • US20240219879A1 patent drawing
  • US20240219879A1 patent drawing
  • US20240219879A1 patent drawing

AI summary

A system, inspection device and method for securely executing control applications, wherein at least one event is defined for at least one control application and the event is triggered upon potential manipulation of program code associated with the control application and/or of at least one peripheral connected to a program flow controller processing the program code, where the program flow controller monitors a flow of the control application for deviations from an expected flow behavior and triggers the defined event upon a deviation, following triggering of the defined event, the program code is processed further by the program flow controller and the event is reported to an inspection device separate from the program flow controller where the inspection device places the control application and control components with an interdependency thereon into a predefined safe operating state upon detecting a flow behavior of the control application that contravenes the inspection rules.