Controller Credential Synchronization for Security Consistency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Controller devices in industrial control systems are susceptible to unauthorized access due to inconsistent login credentials, which can lead to security threats and potential system compromise.

Innovation Solution

Implementing a system that synchronizes login credentials across multiple controllers in a redundant control system, using techniques such as first come first serve, round robin, or priority scheduling, to detect and alert discrepancies, thereby enhancing security by ensuring consistent credentials across all controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If login credentials are stored independently in each controller, then each controller can operate autonomously, but security vulnerability increases due to inconsistent credentials across controllers

Engineering Contradiction:
Improvecontroller autonomyVSAvoidsecurity consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges the credential storage function across distributed controllers by implementing a centralized credential repository that all controllers access. This combining approach ensures that all controllers use identical login credentials while maintaining their operational autonomy, thus resolving the contradiction between independence and security consistency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a credential synchronization mechanism as an intermediary component that mediates between the centralized repository and individual controllers. This intermediary ensures that credential updates are propagated consistently to all controllers, maintaining security reliability without compromising controller autonomy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credential synchronization is implemented across all controllers, then security consistency is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity consistencyVSAvoidsynchronization mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential repository that serves multiple controllers simultaneously, allowing a single synchronization mechanism to manage credentials across the entire control system. This multi-functional approach reduces overall system complexity compared to implementing separate synchronization mechanisms for each controller pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The synchronization mechanism is designed to automatically detect and propagate credential updates to all controllers without manual intervention. This self-service capability reduces operational complexity and eliminates the need for complex manual credential management procedures across multiple controllers.

Inventive Principle:
Principle #25Self-service

3Speed

If credential changes are detected and propagated immediately, then security response time is improved, but communication overhead increases

Engineering Contradiction:
Improvecredential update speedVSAvoidcommunication overhead
Core Design Contradiction:
SpeedVSLoss of energy

Solution Approach 1:

The patent implements periodic credential verification and synchronization cycles across controllers. Instead of continuous real-time synchronization, the system checks for credential changes at scheduled intervals, reducing communication overhead while maintaining timely security response. This periodic approach balances update speed with energy efficiency.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP2660751B1System and method for securing controllers
Publication Date: 2019.11.20 GENERAL ELECTRIC CO
  • EP2660751B1 patent drawingFigure 1
  • EP2660751B1 patent drawingFigure 2
  • EP2660751B1 patent drawingFigure 3

AI summary

A system includes a control system 12 having a plurality of controllers 26 configured to control a process. Each controller of the plurality of controllers further includes a secure repository 30 configured to store a login credential 28. The control system 28 is configured to authorize a user action by comparing a user credential against the login credential of each of the plurality of controllers 26.