Hierarchical Authentication for Embedded Device Function Blocks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Embedded devices like programmable logic controllers lack robust security mechanisms, making them vulnerable to unauthorized access, especially as they become increasingly networked and targeted by internet and data network attacks.
Innovation Solution
Implementing a hierarchical security structure where functional blocks are associated with multiple levels, requiring multiple authentications to access lower levels, using key-based cryptographic processes and separate certifications for each level, and integrating a firewall for additional protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate firewall or walled-off data network is used to protect embedded devices, then security protection is achieved, but attackers can still access embedded devices by overcoming the firewall
Solution Approach 1:
The patent segments the embedded device into multiple hierarchical security levels (level 1 being the most secure, level n being the least secure). Each level contains specific functional blocks and requires separate authentication. This segmentation ensures that even if an attacker breaches one level, they cannot access other levels without additional authentication, thus resolving the contradiction by making unauthorized access progressively more difficult while maintaining security protection.
Solution Approach 2:
The patent implements a nested security structure where multiple authentication layers are nested within each other. To access a functional block at a lower level, authentication is required for that level plus all higher levels. This nested approach creates multiple barriers, ensuring that firewall breaches do not lead to complete system compromise, thereby maintaining security protection while reducing the impact of harmful factors.
2Reliability
If multiple authentications are required for different levels, then security of the embedded device is significantly enhanced, but the complexity of the access control mechanism increases
Solution Approach 1:
The access control mechanism is segmented into discrete hierarchical levels, each with its own authentication requirements. This segmentation allows the system to manage complexity by breaking down the authentication process into manageable, independent stages rather than a single complex barrier, thus enhancing security while controlling the growth of system complexity.
Solution Approach 2:
The patent introduces a hierarchical dimension to access control, organizing functional blocks into multiple levels rather than a flat structure. This dimensional change allows the system to implement multiple authentications in a structured way, where each level adds a layer of security without proportionally increasing overall complexity, as the hierarchical framework provides a clear organizational pattern.
3Reliability
If functional blocks are divided into multiple hierarchical levels, then security is increased through multiple authentications, but the ease of operation for authorized users decreases
Solution Approach 1:
The system performs preliminary authentication actions in advance, establishing credentials and permissions for each hierarchical level before actual access is needed. This preliminary action allows authorized users to authenticate once at higher levels, and the system automatically manages the cascading authentication requirements for lower levels, thereby maintaining security while improving ease of operation for authorized users.
Solution Approach 2:
The authentication system operates autonomously to manage the hierarchical access control. Once a user is authenticated at a higher level, the system automatically verifies and manages authentication for lower levels without requiring manual intervention from the user. This self-service approach maintains rigorous security checks while reducing the operational burden on authorized users.
Data Source
AI summary
A method for accessing functions of an embedded device, for example a controller programmable from memory, wherein function blocks of the embedded device are assigned to at least two hierarchically superimposed levels, an access to a function block of the embedded device occurs from outside of the embedded device by a data interface, and for access an authentication must occur for the level to which the respective function block is assigned, and again for each individual level above the level to which the function block is assigned, to permit execution of a function of the function block, wherein the functions of the function blocks permit access to a firmware of the embedded device.

