Cryptographic Configuration File Updates Without OT Device Interruption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack automated processes for securely updating cipher configuration files on industrial automation devices without causing device interruption, especially with the rise of quantum computing threats, and there is a need for robust cryptographic primitives to ensure secure operation of OT devices.

Innovation Solution

A computer-implemented method and system that provides ciphered configuration files to computer devices through a device configuration manager component, which communicates with a system configuration manager via secure communication, enabling secure and automated updates of configuration files without interrupting device operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic configuration files are updated on industrial automation devices, then security and cryptographic robustness are improved, but device operation is interrupted

Engineering Contradiction:
Improvecryptographic securityVSAvoiddevice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by establishing secure communication channels and preparing cryptographic configuration files before device updates are needed. The configuration manager proactively manages cryptographic primitives and prepares updated configuration files in advance, allowing seamless deployment without interrupting device operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A configuration manager component acts as an intermediary between the external security infrastructure and industrial automation devices. This intermediary handles cryptographic configuration updates, manages secure communication protocols, and coordinates file transfers through secure channels, enabling updates without direct device intervention or operational interruption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual configuration processes are used for industrial devices, then cryptographic control is maintained, but update time and operational disruption increase

Engineering Contradiction:
Improvecryptographic controlVSAvoidupdate duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service capabilities where the configuration manager automatically discovers device cryptographic requirements, retrieves appropriate configuration files from secure storage, and deploys updates without manual intervention. The device itself can request and receive configuration updates through automated secure communication channels, eliminating the need for manual cryptographic control processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The configuration manager employs feedback mechanisms to monitor device cryptographic status, determine when updates are needed, and automatically initiate update processes. The system receives feedback from devices about their cryptographic configuration state and uses this information to trigger appropriate update actions, reducing both update time and operational disruption.

Inventive Principle:
Principle #23Feedback

3Reliability

If secure communication protocols are implemented, then cryptographic security is improved, but communication overhead and system complexity increase

Engineering Contradiction:
Improvecommunication securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The configuration manager serves multiple functions within a single system component: it manages cryptographic primitives, establishes secure communication channels, retrieves configuration files, and coordinates updates across multiple devices. This multi-functional approach consolidates security infrastructure complexity into a manageable centralized component rather than distributing complexity across all devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The configuration manager acts as an intermediary that handles the complexity of secure communication protocols, cryptographic primitive management, and encrypted file transfers. By centralizing these complex security functions in a dedicated intermediary component, the actual industrial automation devices can operate with simpler local configurations while maintaining high cryptographic security through the intermediary's coordinated protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250348326A1Computer system and method for providing cryptographic configuration files to computer applications
Publication Date: 2025.11.13 SCHNEIDER ELECTRIC USA INC
  • US20250348326A1 patent drawing
  • US20250348326A1 patent drawing
  • US20250348326A1 patent drawing

AI summary

A computer-implemented method and system for providing a ciphered configuration file to a computer device having at least one application requiring a configuration file for enabling operation of the computer device. Received in the computer device, from a coupled system configuration manager component, is a ciphered configuration file required for operation of the computer device. Upon reception of the ciphered configuration file in the computer device, the received ciphered configuration is pushed to the at least one application in the computer device for execution by the application of the computer device for enabling operation of the computer device.