Control Network Certificate Provisioning for Automation Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional automation systems face challenges in efficiently constructing a safe network topology, leading to difficulties in managing communication networks effectively.

Innovation Solution

An information processing apparatus and method that involve transmitting a self-signed certificate to a management server, receiving a certificate authority signature certificate, and executing data communication in a control system based on the certificate authority signature certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional manual methods are used for constructing network topology and managing digital certificates, then engineering work can be performed, but the process is time-consuming and inefficient

Engineering Contradiction:
Improveengineering efficiencyVSAvoidtime for certificate management
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The control apparatus automatically generates self-signed certificates and transmits them to the management server without manual intervention. The system performs self-registration and automatically manages its own digital certificates, eliminating the need for manual certificate issuance and renewal processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The control apparatus pre-generates self-signed certificates before formal registration with the management server. This preliminary certificate generation enables the apparatus to autonomously initiate communication and complete the registration process without waiting for manual certificate provisioning.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If manual certificate management is performed, then digital certificates can be issued, but the process requires significant engineering work and manual intervention

Engineering Contradiction:
Improveease of certificate issuanceVSAvoidcomplexity of certificate management process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The control apparatus autonomously generates its own self-signed certificates using its device information, eliminating the need for manual certificate issuance. The apparatus independently manages its certificate lifecycle including generation, transmission, and renewal without requiring complex manual intervention procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of the management server issuing certificates to control apparatuses in the traditional top-down manner, the control apparatuses generate their own self-signed certificates first and then register them with the management server. This inverted approach simplifies the certificate issuance process by removing the manual intervention bottleneck.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If self-signed certificates are used without centralization, then autonomous operation is achieved, but network security and certificate validity cannot be ensured

Engineering Contradiction:
Improvecertificate validityVSAvoidautonomous certificate management
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The management server acts as an intermediary that receives self-signed certificates from control apparatuses, validates them against registered device information, and issues formal certificate authority signature certificates. This intermediary role ensures certificate validity and network security while allowing control apparatuses to maintain autonomous operation for certificate generation and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4539397A1Information processing apparatus, information processing method, and information processing program
Publication Date: 2025.04.16 YOKOGAWA ELECTRIC CORP
  • EP4539397A1 patent drawingFigure 1
  • EP4539397A1 patent drawingFigure 2
  • EP4539397A1 patent drawingFigure 3~4

AI summary

A control apparatus (10) transmits a self-signed certificate to a management server (20), receives a certificate authority signature certificate generated by the management server (20) according to the self-signed certificate, and executes data communication in the control system that executes control of a system on the basis of the certificate authority signature certificate.