Industrial Control System Internal Security Token Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial control systems (ICS) face complexity and administrative overhead in establishing secure network communications due to reliance on external provisioning of security tokens and third-party validation authorities, which complicates certificate and key management.

Innovation Solution

The system enables internal generation and auto-negotiation of security tokens within a known-good environment, allowing networked components to maintain their own key/certificate store, eliminating the need for external verification and simplifying the security setup process by commissioning the ICS in a controlled environment where encryption keys are exchanged without external download.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public/private key pairs are used with third-party validation authorities for secure communications, then security and authenticity are improved, but device complexity and administrative overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the third-party validation authority from the system, allowing ICS components to autonomously establish security tokens without external PKI infrastructure. This removes the complexity of certificate management while maintaining security through direct peer-to-peer token exchange.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ICS components perform self-service by autonomously negotiating and establishing security tokens with each other without requiring external provisioning or validation authorities. Each component generates and manages its own security credentials, eliminating administrative overhead.

Inventive Principle:
Principle #25Self-service

2Reliability

If third-party validation authorities are used for certificate management, then security binding is improved, but administrative overhead increases

Engineering Contradiction:
ImprovebindingVSAvoidoverhead
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service security management where ICS components autonomously establish binding relationships through direct token negotiation. No external validation authority is needed, and components automatically manage their own security credentials, eliminating administrative overhead.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces security tokens as intermediaries that enable direct binding between ICS components without requiring third-party validation authorities. These tokens facilitate secure peer-to-peer communication while eliminating the need for external certificate management infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If external provisioning of security tokens is used during commissioning, then security establishment is improved, but complexity of security setup increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security token generation where ICS components autonomously create and exchange security tokens during commissioning without external provisioning. This simplifies the setup process by eliminating the need for external security infrastructure while maintaining strong security bindings.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary security establishment during the commissioning phase in a known-good environment, allowing components to autonomously negotiate security tokens before deployment. This preliminary action simplifies later operations by pre-establishing security relationships without requiring external intervention.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If PKI infrastructure is used for secure communications, then confidentiality and integrity are improved, but infrastructure requirements increase

Engineering Contradiction:
ImproveconfidentialityVSAvoidinfrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the requirement for external PKI infrastructure by enabling ICS components to establish security tokens autonomously. This maintains confidentiality and integrity through direct component-to-component token exchange while eliminating the need for external certificate authorities and complex PKI management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements self-service security where components generate and manage their own security credentials without external PKI infrastructure. This maintains strong confidentiality and integrity protections while eliminating infrastructure requirements through autonomous security token negotiation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2896176B1Industrial control system with internal generation for secure network communications
Publication Date: 2020.05.13 SIEMENS AG
  • EP2896176B1 patent drawingFigure 1~2
  • EP2896176B1 patent drawingFigure 3~4

AI summary

Security for network communications is internally generated by an industrial control system (ICS). The ICS is assembled in a known-good environment prior to connecting to another network. While in the known-good environment, one or more components of the ICS auto-negotiate (40) with other components, assigning (42) security tokens. These certificates are used to internally secure communications between the components prior to any connection to other devices and without relying on external provisioning of the security tokens during commissioning (30) of the ICS.