Identification Credentials for Industrial Control System Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy industrial control systems lack sufficient computational resources to adapt to new networking protocols and cybersecurity standards, posing security threats and hindering information management and organizational modeling in modern industrial environments.

Innovation Solution

A system for issuing unique identification credentials to devices in industrial control systems, including a unique device identifier, identification authority component identifier, and location indication, which can be encrypted and embedded with biometrics, allowing for secure authentication and topology characterization of networked devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy devices are used to maintain operational reliability, then device availability is preserved, but cybersecurity protection is insufficient

Engineering Contradiction:
Improvedevice availabilityVSAvoidcybersecurity threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an identification authority component as an intermediary that issues identification credentials to legacy devices. This mediator enables legacy devices to participate in secure networked environments without requiring modifications to their core architecture, thus maintaining reliability while improving security posture through external credential verification mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security functionality from the legacy device itself by introducing separate identification credentials and an identification authority component. This segmentation allows the legacy device to maintain its original reliable operation while the security functions are handled by external components that issue and verify identification credentials.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If new networking protocols and encryption standards are implemented, then cybersecurity is improved, but legacy devices lack computational resources to support them

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidcomputational resource requirements
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent employs lightweight identification credentials that can be issued to legacy devices without requiring significant computational resources. These credentials serve as a simple, low-cost security mechanism that legacy devices can support, avoiding the need for complex encryption algorithms or heavy computational infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the security parameter from complex cryptographic protocols to simpler identification credential verification. By transitioning from computationally intensive encryption standards to lighter-weight identification mechanisms, legacy devices can achieve improved cybersecurity without exceeding their computational resource constraints.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If identification credentials are issued to all devices, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem architecture complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a universal identification credential system that can be applied across diverse legacy devices regardless of their specific protocols or manufacturers. This universal approach enhances security consistently across the network while avoiding the need for device-specific security implementations, thereby limiting the increase in system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The identification authority component automatically issues and manages identification credentials for legacy devices without requiring complex manual configuration or integration with each device's existing security infrastructure. This self-service approach enhances security coverage while minimizing the administrative complexity burden on system operators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8327130B2Unique identification of entities of an industrial control system
Publication Date: 2012.12.04 ROCKWELL AUTOMATION TECH INC
  • US8327130B2 patent drawing
  • US8327130B2 patent drawing
  • US8327130B2 patent drawing

AI summary

Systems and methods are provided for issuing unique identification credentials to a plurality of devices, and their constituent components, in an industrial control system. Identification credentials are granted by an identification authority and conveyed to each of the credentialed devices and/or component through an identity token. The identification credentials include (1) a unique device identifier, (2) an identification authority component identifier, and (3) an indication of the location of the identification authority component. To secure the issued credentials, such credentials are encrypted and the identification token can be embedded with biometrics features. Identification credentials provide for the following prominent features: (i) Secure access to a device form a client and (ii) determination a topology of a set of credentialed devices in an industrial control system. The topology is network agnostic and facilitates organizational modeling of processes in the industrial control system.