Industrial Cipher Configuration for Security and CPU Bottlenecks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial devices often have inadequate cybersecurity configurations due to insufficient information at the time of manufacture, leading to inconsistent and inferior security, which can result in vulnerabilities and bottlenecks in CPU utilization, and these configurations become outdated as new security threats emerge, requiring costly and cumbersome expert intervention to update.

Innovation Solution

An automated method for configuring cryptographic algorithms in industrial devices based on system and device parameters, including computation power, hardware acceleration, and geographic location, which can be dynamically updated in response to changes in the threat landscape and regulatory requirements, using a central cypher configuration module that communicates with individual devices to provide optimal and customized configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If cypher configuration is made before device deployment with available information, then configuration can be established in advance, but the configuration may be inconsistent and inferior due to insufficient information about computation power and security requirements

Engineering Contradiction:
Improveconfiguration timeVSAvoidconfiguration quality
Core Design Contradiction:
Loss of timeVSManufacturing precision

Solution Approach 1:

The patent applies preliminary action by establishing a configuration framework and placeholder settings during manufacturing, while deferring the actual cypher configuration to be performed later at deployment time when full device parameters and security requirements are known. This resolves the contradiction by doing preliminary preparatory work without making final configuration decisions prematurely.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by making the cypher configuration adaptable and changeable after deployment. The configuration can be updated based on actual device performance, security threats, and operational requirements, transforming the static pre-configured system into a dynamic one that evolves with changing conditions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If high security cypher configuration is implemented, then security coverage is improved, but CPU utilization increases causing bottlenecks for real-time device communication

Engineering Contradiction:
Improvesecurity coverageVSAvoidreal-time communication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies parameter changes by allowing the cypher configuration parameters (algorithm type, key length, mode of operation) to be adjusted based on the specific device's computation power and security requirements. High-security configurations can be applied to devices with sufficient processing power, while lighter configurations are used for real-time communication devices, optimizing both security and performance.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements local quality by tailoring the cypher configuration to each device's specific characteristics and requirements rather than applying a uniform high-security configuration to all devices. Different parts of the system receive appropriately sized security measures based on their local needs and capabilities.

Inventive Principle:
Principle #3Local quality

3Stability of the object's composition

If cypher configuration is locked after initial setup, then configuration stability is maintained, but the configuration becomes outdated as new security threats develop

Engineering Contradiction:
Improveconfiguration stabilityVSAvoidadaptability to new threats
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by implementing a configuration system that can evolve over time. The cypher configuration is not permanently locked but can be updated through defined processes that allow adaptation to new security threats while maintaining operational stability through controlled change management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback mechanisms that monitor security threats and device performance, enabling the system to detect when configuration updates are needed and trigger appropriate reconfiguration processes, thus maintaining both stability and adaptability.

Inventive Principle:
Principle #23Feedback

4Manufacturing precision

If expert intervention is used to select and configure cypher settings, then configuration expertise is applied, but the process becomes costly and cumbersome

Engineering Contradiction:
Improveconfiguration expertiseVSAvoidconfiguration process simplicity
Core Design Contradiction:
Manufacturing precisionVSEase of manufacture

Solution Approach 1:

The patent applies self-service by enabling the system to automatically select and configure appropriate cypher settings based on device parameters, security requirements, and threat models. This eliminates or reduces the need for expert intervention while maintaining high-quality configurations through automated decision-making processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter changes to enable automated configuration by establishing clear relationships between device parameters (computation power, memory, communication requirements) and appropriate cypher configuration parameters, allowing systematic selection without expert knowledge.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4395392A1Automated cypher configuration of industrial devices
Publication Date: 2024.07.03 SCHNEIDER ELECTRIC USA INC
  • EP4395392A1 patent drawingFigure 1
  • EP4395392A1 patent drawingFigure 2
  • EP4395392A1 patent drawingFigure 3

AI summary

A method of automating cypher configuration for a plurality of industrial devices within an industrial system is provided. The method includes receiving system parameters for the industrial system and receiving from a data source device parameters for respective individual industrial devices of the plurality of industrial devices. The method further includes selecting, generating and/or updating an optimal cypher configuration for the respective individual industrial devices based on or using the system parameters for the industrial system and the device parameters for the respective individual devices. The method further includes providing the optimal cypher configuration to the respective individual industrial devices for configuration of the respective individual industrial devices' cypher configuration.