Dynamic Security Module Deactivation for Industrial Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face a compromise between security and usability due to the reactive and non-selective measures taken to address cybercriminal threats, which often result in suboptimal performance and comfort, as well as increased vulnerability from outdated software modules.

Innovation Solution

Implementing a method to manage multiple security levels that define indispensable and optional functions, allowing for the dynamic deactivation of only non-essential modules affected by cyber threats based on current security levels, thereby minimizing functionality loss and maintaining essential operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protective measures against cybercriminal threats are increased, then security level is improved, but performance and usability are worsened

Engineering Contradiction:
Improvesecurity levelVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts security measures based on detected threats. Instead of static protective measures that always reduce usability, the system activates specific protective actions only when threats are detected, allowing the security level and usability to vary dynamically according to the operational context and threat level.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies protective measures locally to specific modules or functions that are vulnerable to detected threats, rather than applying blanket restrictions across the entire system. This allows critical functions to maintain high usability while vulnerable areas receive enhanced protection.

Inventive Principle:
Principle #3Local quality

2Reliability

If modules are deactivated to protect against threats, then security level is improved, but functionality is worsened

Engineering Contradiction:
Improvesecurity levelVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically determines which modules to deactivate based on real-time threat assessment. Instead of permanently deactivating modules, the system selectively disables only those modules that are currently vulnerable and relevant to the detected threat, preserving functionality for non-vulnerable modules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational state of modules based on threat parameters. When a threat is detected, the system modifies the activation state of specific modules rather than changing the overall system configuration, allowing flexible adjustment of functionality while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If reactive measures are taken after threats are known, then security response is simplified, but response time is worsened

Engineering Contradiction:
Improvemeasure complexityVSAvoidresponse time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system performs preliminary assessment of modules and their vulnerability to threats before actual threats are exploited. By pre-identifying vulnerable modules and establishing protective rules in advance, the system can respond rapidly when threats are detected, reducing the response time without increasing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors for threats and uses this feedback to automatically trigger protective measures. This closed-loop approach allows the system to detect threats in real-time and respond immediately, reducing the delay between threat detection and protective action while maintaining simple automated responses.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11093615B2Method and computer with protection against cybercriminal threats
Publication Date: 2021.08.17 SIEMENS AG
  • US11093615B2 patent drawing
  • US11093615B2 patent drawing

AI summary

A method and a computer for protecting a computer, particularly an industrial automation component, against cybercriminal threats, wherein application programs are installed on the computer, different application programs being required for different functions of the computer, where at least two security stages are defined, such that for each security stage, functions are defined that are either undeactivatable in the event of cybercriminal threats to the functions and/or deactivatable in the event of cybercriminal threats to the functions, where identified functions and modules are selected which are allowed to be deactivated, and where selected modules are blocked, and functions are deactivated such that it is possible to dynamically deactivate optional software modules depending on cybercriminal threats and security stage of the computer to thereby constantly and optimally adapt the usable functional scope of the computer to a threat location and applicable respective operating conditions.