Graphical Authentication for Secure Industrial Edge Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial edge devices in IoT-enabled industrial plants are vulnerable to malicious hacking due to inadequate authentication methods, posing a significant security risk.
Innovation Solution
A multi-factor authentication system that includes graphical authentication tasks, such as puzzles and CAPTCHA, to verify user devices seeking access to industrial edge devices, using an authentication processor to determine access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication methods are used for industrial edge devices, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The patent introduces a graphical authentication task as an intermediary between the user device and the authentication processor. This mediator verifies human cognition by presenting puzzles or CAPTCHA challenges, preventing automated hacking attempts while maintaining secure access for legitimate users. The intermediary layer adds security without significantly impacting user experience.
2Reliability
If graphical authentication tasks are implemented, then security is improved, but device complexity increases
Solution Approach 1:
The authentication processor is designed to handle multiple authentication methods including traditional credentials and graphical tasks. This multi-functional approach allows the same device to serve both simple and complex authentication needs, reducing overall system complexity by consolidating authentication functions into a single versatile component.
3Reliability
If multi-factor authentication is implemented, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The system applies graphical authentication tasks selectively rather than universally. Low-risk operations may use traditional authentication, while high-risk operations trigger additional graphical verification. This partial application of multi-factor authentication maintains security for critical operations while preserving user convenience for routine tasks.
Data Source
AI summary
An authentication system for an industrial plant is configured for authenticating a user device to either permit or deny the user device access to an industrial edge device. The authentication system broadly comprises the industrial edge device, the user device, and the authentication processor. The industrial edge device is configured for at least one of monitoring and controlling an operation within the industrial plant. The user device is configured to communicate with the industrial edge device to request access to the industrial edge device. The authentication processor is associated with the industrial edge device, and the authentication processor is configured to communicate a graphical authentication task to the user device in response to the request for access. The authentication processor is further configured to verify a response to the graphical authentication task from the user device for determining whether to grant the user device access to the industrial edge device.


