Flow Control Socket Permissions for Industrial Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial automation systems lack the ability to selectively and efficiently manage operations on sockets within a flow control environment, leading to inadequate control over admissible and inadmissible operations, particularly in distributed systems.

Innovation Solution

The system classifies flow control components based on configuration information and memory maps to create permissions profiles for socket access, generating tokens that define specific resource access guidelines, allowing for selective and dynamic protection of APIs and operations, and manages these securely through an orchestration system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If socket access is granted to flow control components in a container virtualization environment, then operational flexibility and resource access are improved, but security control and operational granularity are worsened

Engineering Contradiction:
Improvesocket access flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments socket access permissions into fine-grained operation types (read, write, connect, bind, listen, etc.) and assigns them individually to flow control components through security-critical resource specifications. This allows precise control over which operations each component can perform on sockets, resolving the contradiction between flexible access and security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different permission levels and operation types to different flow control components based on their specific security requirements and functional needs. Each component receives a tailored set of permissions rather than a blanket grant or denial, enabling localized security policies that maintain both flexibility and control.

Inventive Principle:
Principle #3Local quality

2Reliability

If socket access is restricted to individual operations, then security control is improved, but system complexity and permission management overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidpermission management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables flow control components to self-declare their security-critical resource requirements through specification files or configuration data. The system automatically processes these declarations and assigns appropriate permissions without requiring manual intervention for each component, reducing management overhead while maintaining fine-grained security control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent requires security-critical resource specifications to be defined in advance during component deployment or configuration. This preliminary action allows the system to pre-configure appropriate socket permissions before the components begin operation, simplifying runtime permission management and reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If fine-grained socket operation control is implemented, then security and operational control are improved, but system overhead and processing time increase

Engineering Contradiction:
Improveoperational controlVSAvoidpermission verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security-critical resource classification and permission assignment during component deployment or initialization before the components become operational. This preliminary action ensures that permission verification is already complete when components need to access sockets, minimizing runtime overhead and processing delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates and stores security-critical resource specifications and permission configurations as reusable templates or configuration files. These can be copied and applied to multiple components with similar requirements, avoiding redundant permission verification processes and reducing overall system overhead.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240019855A1Method and System for Providing Control Applications for Industrial Automation Devices
Publication Date: 2024.01.18 SIEMENS AG
  • US20240019855A1 patent drawing
  • US20240019855A1 patent drawing

AI summary

Method and system for providing control applications for industrial automation devices, wherein in order to provide control applications, which are each provided via flow control components, the flow control components are each classified, based on configuration information, or referenced memory maps, with respect to access to at least one socket of a flow control environment when their execution is started, where a classification for each of the flow control components is used to create or reference a permissions profile for socket access, an individual token, associated with a permissions profile, for the socket access is created for each flow control component and transferred to the respective flow control component, and where the tokens and/or the permissions profiles each have an application-specific resource access guideline combined with therewith which is transmitted to a control component for application, which control component opens the respective socket.