Device Identifier Generation for Secured Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Critical infrastructure systems, such as SCADA systems, are vulnerable to cyber-attacks due to the lack of effective security measures, particularly in networks using Ethernet and Internet platforms, which can lead to catastrophic consequences.
Innovation Solution
A method for generating a unique device identifier based on machine parameters like processor model, Ethernet interface MAC address, OS install date, and nonce values, used to establish secure private networks between field security devices and an authentication server, enhancing access control and security across public networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If critical infrastructure systems use Ethernet and Internet platforms for communication, then productivity and connectivity are improved, but vulnerability to cyber-attacks and security breaches increases
Solution Approach 1:
The patent segments the network authentication process into distinct components: device identifier generation from hardware parameters, transmission over public networks, and verification by authentication servers. This segmentation allows secure communication channels to be established without requiring complete network isolation, thus maintaining connectivity while improving security posture against cyber-attacks.
Solution Approach 2:
The patent introduces authentication servers as intermediary components between field security devices and the control network. These servers verify device identifiers and manage authentication, acting as a security buffer that allows Ethernet and Internet platform connectivity while preventing unauthorized direct access to critical infrastructure systems.
2Reliability
If device identifiers are generated using multiple machine parameters, then uniqueness and reliability of identification are improved, but device complexity and computational requirements increase
Solution Approach 1:
The patent performs preliminary action by generating device identifiers from hardware parameters (MAC addresses, processor IDs, memory IDs) at device initialization or manufacturing stages. These identifiers are stored and ready for authentication without requiring complex real-time computations during authentication operations, thus improving reliability while minimizing computational burden during critical authentication moments.
Solution Approach 2:
The patent uses copying by transmitting the generated device identifier over public networks to authentication servers for verification. Instead of performing complex validation computations at every authentication point, the system copies the identifier and compares it against stored values or cryptographic proofs, reducing computational requirements while maintaining uniqueness and reliability verification.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for ensuring secured communications for embedded platforms includes steps for receiving a device identifier at an authenticating server over a public network from an extended trust device, the authenticating server being communicatively coupled between a secured server and the public network and the device identifier derived from a plurality of machine parameters resident on the extended trust device, accessing a database of authorized device identifiers corresponding to known extended trust devices, and establishing, in response to the device identifier matching one of the authorized device identifiers, a secure private network between the extended trust device and the secured server. The machine parameters may be a combination of a user-configurable parameter and a non-user-configurable parameter. The method may be embodied as a series of process steps stored on a computer readable medium executable by a processor.