Endpoint Integrity Verification in Industrial Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial enterprise systems face challenges in verifying the integrity of endpoints, as existing methods rely on implicit trust and quality assurances from manufacturers, which are insufficient to detect potential security breaches or compromises after the devices leave the manufacturer's control.

Innovation Solution

Endpoints generate integrity measurements based on their state, which are compared to reference values to ensure they are in a trusted state before allowing communication on the network, using cryptographic checksums and standalone security chips to verify software, hardware, and configuration integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If implicit trust and manufacturer quality assurances are used to verify endpoint integrity, then device deployment is simplified and fast, but security reliability is insufficient to detect post-manufacturing compromises

Engineering Contradiction:
Improveendpoint integrity verificationVSAvoidintegrity verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary integrity verification by comparing endpoint integrity measurements against pre-established reference values before allowing network access. This advance verification ensures that only endpoints in a trusted state can communicate on the network, preventing compromised devices from accessing the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary integrity verification mechanism that acts as a mediator between the endpoint and the network. The system uses integrity measurements and reference values as intermediate elements to objectively assess endpoint trustworthiness, replacing the subjective implicit trust model with a measurable verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional trust-based access control is used, then network access is easily granted, but security against compromised endpoints is weak

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication access control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements a feedback mechanism where endpoint integrity measurements are continuously compared against reference values to determine access permissions. This closed-loop verification process provides real-time feedback on endpoint trustworthiness, dynamically controlling network access based on the current integrity state of each endpoint.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the fundamental parameter for access control from implicit trust to measurable integrity values. By transforming the abstract concept of trust into concrete, comparable parameters (integrity measurements and reference values), the system enables objective security decisions while maintaining operational simplicity through automated comparison and authorization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10051059B2Methods and apparatus to control communications of endpoints in an industrial enterprise system based on integrity
Publication Date: 2018.08.14 FISHER ROSEMOUNT SYST INC
  • US10051059B2 patent drawing
  • US10051059B2 patent drawing
  • US10051059B2 patent drawing

AI summary

Methods and apparatus to control communications of endpoints in an industrial enterprise system based on integrity are disclosed. An example apparatus includes an integrity measurement comparator to compare an integrity measurement to a reference value. The integrity measurement is generated by an endpoint in a network of an industrial enterprise system based on a state of the endpoint. The reference value corresponds to a trusted state of the endpoint. The example apparatus also includes an authorization controller to enable communications access for the endpoint on the network based on the comparison of the integrity measurement to the reference value.