Hardware Security Module Integration for Industrial Control Chain-of-Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to unauthorized access, which can compromise the security of the entire platform, leading to potential degradation or damage of industrial assets.

Innovation Solution

Establishing a chain-of-trust through secure hardware, such as a hardware security module integrated with the processor, secure firmware with a secure boot mechanism, and secure data storage and communications, to ensure the integrity and confidentiality of the industrial control system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional industrial control systems are used without secure hardware modules, then device complexity is reduced and ease of manufacture is improved, but security vulnerability increases allowing unauthorized access

Engineering Contradiction:
Improvesystem securityVSAvoidhardware structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware security module is integrated within the processor structure, with the security module nested inside the processor unit. This nesting approach provides enhanced security functionality while minimizing the increase in overall device complexity, as the security module shares the processor's physical envelope and communication interfaces.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The hardware security module acts as an intermediary between the processor and external systems, mediating security-critical operations such as key generation, encryption, and authentication. This intermediary structure isolates security functions from the main processor logic, improving security without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure boot mechanisms are implemented to ensure trusted software execution, then system security is improved, but boot time and initialization complexity increase

Engineering Contradiction:
Improvesoftware integrityVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security credentials, cryptographic keys, and trusted boot signatures are pre-loaded into the hardware security module during manufacturing. This preliminary action allows the secure boot process to verify software integrity without requiring real-time key generation or external authentication, significantly reducing boot time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secure boot verification process is extracted from the main processor workflow and handled independently by the hardware security module. This extraction allows boot verification to occur in parallel with other initialization tasks, minimizing the impact on overall system startup time.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If hardware security modules are integrated with processors, then security against unauthorized access is enhanced, but manufacturing complexity and cost increase

Engineering Contradiction:
Improveaccess securityVSAvoidmanufacturing process
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The hardware security module and processor are merged into a single integrated unit, sharing common fabrication processes, packaging, and testing infrastructure. This merging approach leverages existing semiconductor manufacturing capabilities, avoiding the need for separate assembly lines or specialized manufacturing facilities, thereby minimizing the increase in manufacturing complexity.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If secure data storage and communications are implemented, then data confidentiality and integrity are protected, but system performance and processing speed may be reduced

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Cryptographic operations and security verification tasks are transferred from software-based processing to dedicated hardware circuits within the security module. This substitution of hardware-based cryptographic accelerators for software-based security processing significantly improves data processing speed while maintaining strong confidentiality and integrity protections.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10210333B2Secure industrial control platform
Publication Date: 2019.02.19 GE INFRASTRUCTURE TECH LLC
  • US10210333B2 patent drawing
  • US10210333B2 patent drawing
  • US10210333B2 patent drawing

AI summary

According to some embodiments, an overall chain-of-trust may be established for an industrial control system. Secure hardware may be provided, including a hardware security module coupled to or integrated with a processor of the industrial control system to provide a hardware root-of-trust. Similarly, secure firmware associated with a secure boot mechanism such that the processor executes a trusted operating system, wherein the secure boot mechanism includes one or more of a measured boot, a trusted boot, and a protected boot. Objects may be accessed via secure data storage, and data may be exchanged via secure communications in accordance with information stored in the hardware security model.