Hierarchical Authentication for Embedded Device Function Blocks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Embedded devices like programmable logic controllers lack robust security mechanisms, making them vulnerable to unauthorized access, especially as they become increasingly networked and targeted by internet and data network attacks.

Innovation Solution

Implementing a hierarchical security structure where functional blocks are associated with multiple levels, requiring multiple authentications to access lower levels, using key-based cryptographic processes and separate certifications for each level, and integrating a firewall for additional protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate firewall or walled-off data network is used to protect embedded devices, then security protection is achieved, but attackers can still access embedded devices by overcoming the firewall

Engineering Contradiction:
Improvesecurity protectionVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the embedded device into multiple hierarchical security levels (level 1 being the most secure, level n being the least secure). Each level contains specific functional blocks and requires separate authentication. This segmentation ensures that even if an attacker breaches one level, they cannot access other levels without additional authentication, thus resolving the contradiction by making unauthorized access progressively more difficult while maintaining security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested security structure where multiple authentication layers are nested within each other. To access a functional block at a lower level, authentication is required for that level plus all higher levels. This nested approach creates multiple barriers, ensuring that firewall breaches do not lead to complete system compromise, thereby maintaining security protection while reducing the impact of harmful factors.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If multiple authentications are required for different levels, then security of the embedded device is significantly enhanced, but the complexity of the access control mechanism increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control mechanism is segmented into discrete hierarchical levels, each with its own authentication requirements. This segmentation allows the system to manage complexity by breaking down the authentication process into manageable, independent stages rather than a single complex barrier, thus enhancing security while controlling the growth of system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to access control, organizing functional blocks into multiple levels rather than a flat structure. This dimensional change allows the system to implement multiple authentications in a structured way, where each level adds a layer of security without proportionally increasing overall complexity, as the hierarchical framework provides a clear organizational pattern.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If functional blocks are divided into multiple hierarchical levels, then security is increased through multiple authentications, but the ease of operation for authorized users decreases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to functional blocks
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication actions in advance, establishing credentials and permissions for each hierarchical level before actual access is needed. This preliminary action allows authorized users to authenticate once at higher levels, and the system automatically manages the cascading authentication requirements for lower levels, thereby maintaining security while improving ease of operation for authorized users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system operates autonomously to manage the hierarchical access control. Once a user is authenticated at a higher level, the system automatically verifies and manages authentication for lower levels without requiring manual intervention from the user. This self-service approach maintains rigorous security checks while reducing the operational burden on authorized users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10867077B2Method of accessing functions of an embedded device
Publication Date: 2020.12.15 SCHNEIDER ELECTRIC AUTOMATION
  • US10867077B2 patent drawing
  • US10867077B2 patent drawing

AI summary

A method for accessing functions of an embedded device, for example a controller programmable from memory, wherein function blocks of the embedded device are assigned to at least two hierarchically superimposed levels, an access to a function block of the embedded device occurs from outside of the embedded device by a data interface, and for access an authentication must occur for the level to which the respective function block is assigned, and again for each individual level above the level to which the function block is assigned, to permit execution of a function of the function block, wherein the functions of the function blocks permit access to a firmware of the embedded device.