IACS Security Baseline Automation for Faster Commissioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commissioning industrial automation control systems, particularly substation automation systems, is a time-consuming and error-prone process due to the manual configuration and verification of security settings, which can lead to misconfigurations and security threats.

Innovation Solution

A computing device automates the generation of commands to set and verify security configurations using a machine-readable security baseline, enabling behavior-based and state-based verification, reducing the need for human intervention and minimizing errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and verification of security settings is performed, then system security can be configured, but the process is time-consuming and error-prone

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoidcommissioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-configuration of security settings by automatically reading the baseline configuration, parsing security parameters, and applying them to the IED device without requiring manual engineer intervention for each setting, thereby reducing both time and errors

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security baseline configuration is prepared in advance in a structured format (XML, JSON, or YAML) containing all required security parameters, firewalls, and access control settings, which are then automatically applied during commissioning, eliminating the need for manual configuration during the commissioning process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual verification of security configuration is performed, then security settings can be validated, but misconfigurations may occur leading to security threats

Engineering Contradiction:
Improvesecurity verification accuracyVSAvoidcommissioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically verifies the applied security configuration by comparing it against the baseline configuration and provides feedback on any discrepancies or misconfigurations, enabling immediate correction without manual intervention

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

A computing device acts as an intermediary between the security baseline and the IED device, automatically parsing, translating, and applying security parameters while verifying correctness, thereby simplifying the commissioning process while maintaining high verification accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated command generation is implemented, then commissioning time is reduced, but system complexity increases

Engineering Contradiction:
Improvecommissioning speedVSAvoidautomation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The manual mechanical process of configuring security settings is replaced with an automated computing system that parses baseline configurations, generates commands, and applies them to the IED device, significantly increasing commissioning speed while the structured approach keeps the automation manageable

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11438380B2Method and computing device for commissioning an industrial automation control system
Publication Date: 2022.09.06 ABB (SCHWEIZ) AG
  • US11438380B2 patent drawing
  • US11438380B2 patent drawing
  • US11438380B2 patent drawing

AI summary

To commission an industrial automation control system, IACS, a computing device generates commands to automatically set or verify a security configuration of the IACS. The commands are generated by the computing device based on a machine-readable security baseline, and, optionally, based on a machine-readable configuration file of the IACS.