Industrial Automation Gateway Dual Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face challenges in maintaining secure, private, and trusted communications from on-premises devices to cloud-hosted services, especially when dealing with vast amounts of data generated across geographically disparate locations.

Innovation Solution

An industrial automation gateway is implemented with a cloud communication interface, hardware memory, and a processor that verifies certificates from multiple root certificate authorities to ensure secure data transfer, using a subordinate certificate certified by both authorities before exchanging automation data with the cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate verification from multiple root certificate authorities is implemented, then communication security is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidgateway complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway pre-stores multiple root certificate authorities and their subordinate certificates in hardware memory before communication occurs. This preliminary preparation allows the gateway to quickly verify certificates during data transfer without performing complex real-time verification operations, thus enhancing security while minimizing the impact on device complexity during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces subordinate certificates as intermediaries between the root certificate authorities and the communication parties. These subordinate certificates simplify the verification process by acting as trusted intermediaries that inherit authority from multiple root CAs, reducing the computational burden on the gateway while maintaining security through the extended web of trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure certificate verification is implemented, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By pre-loading root certificates and subordinate certificates into hardware memory before communication sessions, the gateway eliminates the need for time-consuming real-time certificate retrieval and verification. The certificates are readily available for immediate verification, ensuring data integrity while minimizing verification time during actual data transfer operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10397007B2Enhanced security for industrial automation gateways
Publication Date: 2019.08.27 ROCKWELL AUTOMATION TECH INC
  • US10397007B2 patent drawing
  • US10397007B2 patent drawing
  • US10397007B2 patent drawing

AI summary

An industrial automation gateway providing an extended web of trust is provided. The industrial automation gateway includes a cloud communication interface coupled with a cloud automation facility, a hardware memory, and a processor coupled with the cloud communication interface and the hardware memory. The cloud automation facility includes a cloud hardware memory storing a cloud root certificate from a first root certificate authority and a subordinate certificate. The hardware memory stores a gateway root certificate from a second root certificate authority and the subordinate certificate. The processor is configured to determine if the subordinate certificate has been certified by the first root certificate authority and the second root certificate authority. The processor is also configured to transfer automation data to the cloud automation facility using the subordinate certificate only if the subordinate certificate has been certified by the first root certificate authority and the second root certificate authority.