Industrial Controller Certificate Generation Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Obtaining cryptographic certificates for industrial controller units is a time-consuming and error-prone process due to the need for detailed cryptographic knowledge and frequent updates, especially when multiple modules with different communication protocols are involved.

Innovation Solution

The industrial controller unit automatically generates cryptographic certificate requests based on its local configuration parameters, allowing for self-signed or externally signed certificates without user intervention, facilitating secure communication and central certificate management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual certificate generation is performed by users, then cryptographic security can be achieved, but the process becomes time-consuming and error-prone due to lack of cryptographic expertise

Engineering Contradiction:
Improvecertificate generation reliabilityVSAvoidcertificate generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The industrial controller unit automatically generates certificate requests using its own configuration parameters without requiring user intervention. The system extracts relevant configuration data (such as device identifiers, communication parameters) and uses this to autonomously create cryptographic certificate requests, eliminating the need for users to manually perform complex cryptographic operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary mechanism that bridges the configuration system and cryptographic certificate generation. This intermediary automatically maps configuration parameters to certificate request requirements, translating general device configuration into specific cryptographic parameters without requiring users to understand cryptographic protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If users generate certificates manually with detailed cryptographic knowledge, then accurate certificates can be obtained, but the complexity of the process increases significantly

Engineering Contradiction:
Improvecertificate accuracyVSAvoidcertificate generation complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring all necessary device parameters and identifiers that will be needed for certificate generation. These configuration parameters are prepared in advance during device setup, so when certificate generation is needed, the system can directly use these pre-prepared parameters without requiring users to gather or understand cryptographic requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal certificate generation mechanism that works across different communication protocols and device configurations. By using a standardized approach that leverages existing configuration parameters for various protocols (PROFIBUS, PROFINET, Ethernet IP, etc.), the system achieves protocol-independent certificate generation without requiring protocol-specific cryptographic expertise.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If certificates are renewed regularly as required, then security is maintained, but the frequent updates increase operational burden

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidcertificate management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements a feedback mechanism that automatically monitors certificate validity periods and renewal requirements. When certificates approach expiration or need renewal, the system automatically detects this condition and initiates the renewal process using the same automated generation procedures, eliminating the need for manual tracking and intervention in certificate lifecycle management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3700160A1Cryptographic certificates for an industrial controller
Publication Date: 2020.08.26 CODESYS HLDG GMBH
  • EP3700160A1 patent drawingFigure 1
  • EP3700160A1 patent drawingFigure 2
  • EP3700160A1 patent drawingFigure 3

AI summary

An industrial controller unit comprises an interface for a cryptographic data exchange via a network, and is adapted to obtain at least one configuration parameter pertaining to the industrial controller unit and/or the interface. The industrial controller unit is further adapted to generate a cryptographic certificate request based on the at least one configuration parameter, and to obtain a cryptographic certificate for the cryptographic data exchange based on the cryptographic certificate request.