Dynamic Signature Security for Industrial Control Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to malicious attacks due to increased exposure through network and Internet connections, which can lead to physical damage and risk to human life, as traditional security measures are insufficient in protecting these systems from sophisticated cyber threats.

Innovation Solution

A security system that generates and analyzes dynamic signatures from industrial control devices, using a combination of device network ports, control device processors, and security controllers to detect tampering by monitoring dynamically changing patterns of operation, employing encryption, decryption, and multi-value range analysis, along with supervised machine learning to recognize correlations and interrelations among variables.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional physical security measures are used to protect industrial control systems, then physical access is limited, but network and Internet connections create new security vulnerabilities that physical security cannot address

Engineering Contradiction:
Improvesecurity protectionVSAvoidcyber attack exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security intermediary layer that sits between the control device and the network. This intermediary monitors and analyzes dynamic signatures of control device operations, acting as a mediator that detects malicious activity without blocking legitimate network communications. The intermediary translates complex security monitoring into actionable intelligence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/physical security measures with a software-based security system. Instead of relying on physical access controls, the system uses dynamic signature analysis, encryption, and decryption to provide security. This substitution allows the system to address network-based threats that physical security cannot prevent.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If dynamic signature analysis is implemented to detect tampering, then detection capability is improved, but system complexity increases due to encryption, decryption, and multi-value range analysis requirements

Engineering Contradiction:
Improvetampering detection accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security system into distinct functional modules: a control device that generates dynamic signatures, a security intermediary that analyzes signatures, and a control device that implements security policies. This segmentation allows each component to specialize in specific tasks, reducing overall system complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs dynamic signatures that change based on the operational state of the control device, rather than static signatures. This dynamic approach allows the security system to adapt to normal operational variations without requiring complex reconfiguration, simplifying the system while improving detection accuracy.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple control devices are monitored with integrated rules, then comprehensive security coverage is achieved, but analysis complexity increases due to correlations among multiple dynamic variables

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security monitoring across multiple control devices into a unified security intermediary that analyzes signatures from all devices. This consolidation allows the system to detect coordinated attacks and understand inter-device correlations without requiring separate analysis systems for each device, reducing overall complexity while improving coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where the security intermediary continuously monitors dynamic signatures and adjusts analysis rules based on observed patterns. This feedback loop allows the system to learn from operational data and refine its detection capabilities without manual reconfiguration, reducing analysis complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10042354B2Security system for industrial control infrastructure using dynamic signatures
Publication Date: 2018.08.07 ROCKWELL AUTOMATION TECH INC
  • US10042354B2 patent drawing
  • US10042354B2 patent drawing
  • US10042354B2 patent drawing

AI summary

An industrial control system hardened against malicious activity monitors highly dynamic control data to develop a dynamic thumbprint that can be evaluated to detect deviations from normal behavior of a type that suggest tampering or other attacks. Evaluation of the dynamic thumbprint may employ a set of ranges defining normal operation and reflecting known patterns of interrelationship between dynamic variables.