ICS Software Deployment Using HSM Root of Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems (ICS) face significant cybersecurity vulnerabilities, particularly when connected to public and private cloud networks, lacking end-to-end encryption and CC-EAL3 security protection, which can lead to breaches and operational disruptions.

Innovation Solution

A system that securely deploys software components to ICS devices by generating validation credentials, establishing secure communication channels using private and public credentials, and implementing a root of trust, with components like hardware security modules and secure credential services to ensure the integrity and authenticity of software and data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ICS devices are connected to cloud networks for remote monitoring and management, then operational efficiency and accessibility are improved, but cybersecurity vulnerabilities and exposure to breaches increase

Engineering Contradiction:
Improveremote monitoring and management accessibilityVSAvoidcybersecurity vulnerabilities and breach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud gateway as an intermediary component that sits between the ICS devices and the cloud network. This gateway provides secure credential storage, authentication services, and encrypted communication channels, allowing remote monitoring and management while protecting the ICS devices from direct exposure to cloud network threats. The gateway acts as a security buffer that enables accessibility without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the communication architecture into distinct secure layers: ICS devices, cloud gateway, and cloud network. Each segment has specific security functions - ICS devices perform control operations, the gateway handles authentication and credential management, and the cloud network provides remote access. This segmentation isolates the vulnerable ICS devices from direct cloud connectivity while maintaining operational efficiency.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If traditional software deployment methods are used on ICS devices, then ease of software updates is maintained, but software integrity and authenticity cannot be verified

Engineering Contradiction:
Improvesoftware update simplicityVSAvoidsoftware integrity and authenticity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system performs preliminary actions by generating digital signatures and hash values for software components before deployment. Validation credentials are created in advance and stored securely in the cloud gateway. When software updates are deployed, these pre-established credentials enable automatic verification of software integrity and authenticity, maintaining update simplicity while ensuring reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the cloud gateway validates software components using digital signatures and hash values before allowing deployment to ICS devices. This verification feedback ensures that only authenticated and integrity-checked software is installed, maintaining both ease of updates and software reliability through automated validation loops.

Inventive Principle:
Principle #23Feedback

3Speed

If communication credentials are stored in accessible locations for easy retrieval, then communication efficiency is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvecommunication credential retrieval speedVSAvoidunauthorized access risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements nested security structures where hardware security modules (HSMs) are embedded within cloud gateway devices, which themselves are part of the larger ICS-cloud architecture. The HSMs provide secure credential storage with controlled access, enabling fast retrieval through hierarchical authentication while protecting credentials from unauthorized access through multiple security layers.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The cloud gateway acts as an intermediary that manages credential storage and retrieval. Instead of storing credentials in easily accessible but insecure locations, the gateway provides controlled access through authentication mechanisms, enabling efficient credential retrieval for authorized operations while preventing unauthorized access through security policies and encrypted storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If end-to-end encryption is implemented for all communications, then data security is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvedata security and protectionVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex encryption and decryption operations from the ICS devices and concentrates them in the cloud gateway, which has greater computational resources. The gateway manages cryptographic keys, performs authentication, and handles encrypted communication. This extraction maintains strong data security while reducing the complexity burden on resource-constrained ICS devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud gateway serves as an intermediary that manages the complexity of end-to-end encryption. It handles key generation, distribution, and management,以及encrypted communication protocols. By centralizing these complex functions in the gateway, the system achieves strong data security without overburdening the ICS devices with cryptographic complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3848794A1Secure deployment of software on industrial control systems
Publication Date: 2021.07.14 MYOMEGA SYST GMBH
  • EP3848794A1 patent drawingFigure 1
  • EP3848794A1 patent drawingFigure 2A
  • EP3848794A1 patent drawingFigure 2B~2C

AI summary

Securely deploying a software component to a control device of an industrial control system includes generating a first validation credential and a second validation credential corresponding to the first validation credential. The second credential is installed on the control device. A digital signature or a hash value is generated using the first validation credential and is associated with the software component, which is transmitted with the digital signature or the hash value to the control device. The digital signature or the hash value is validated using the second validation credential. In response to the digital signature or the hash value being valid, the software component is installed on the control device. The first validation credential may be generated and stored within a hardware security module and may be inaccessible from outside of the hardware security module. The second validation credential may be derived from the first validation credential.