Industrial Control System Security Credential Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face increased cybersecurity threats due to expanded connectivity, outpacing existing security solutions, and require secure authentication mechanisms to protect critical infrastructure and operations.

Innovation Solution

A secure industrial control system is implemented, featuring a security credential source generating unique credentials for industrial elements, such as control and input/output modules, which are provisioned and managed to enable secure bi-directional communication and authentication, preventing unauthorized access and ensuring authenticity of components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If expanded connectivity is implemented in industrial control systems, then productivity and information access are improved, but cybersecurity vulnerability increases

Engineering Contradiction:
ImproveproductivityVSAvoidcybersecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Security credentials are generated and provisioned to industrial elements before they are deployed or connected to the network. This preliminary security configuration ensures that authentication mechanisms are in place before connectivity is established, preventing security vulnerabilities from arising during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A security credential implementer acts as an intermediary between the security credential source and industrial elements. This intermediary component manages the provisioning process, ensuring that security credentials are properly distributed and installed on control modules and I/O modules before they participate in network communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique security credentials are provisioned to each industrial element, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security credential implementer serves multiple functions: it receives credentials from the security credential source, installs them on industrial elements, and manages credential distribution across the entire system. This universal component simplifies the overall architecture by consolidating security management tasks into a single multi-functional entity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Industrial elements are automatically provisioned with security credentials through the security credential implementer without requiring manual configuration. The system performs self-service credential distribution, reducing the complexity of manual security setup while maintaining strong authentication security.

Inventive Principle:
Principle #25Self-service

3Reliability

If security credentials are generated and managed centrally, then security control is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security credential source and security credential implementer are integrated into a unified security management architecture. This merging of credential generation and distribution functions into coordinated system components simplifies the overall system structure while maintaining centralized security control, avoiding the complexity of separate distributed security systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3030942B1Secure industrial control system
Publication Date: 2019.11.27 BEDROCK AUTOMATION PLATFORMS INC
  • EP3030942B1 patent drawingFigure 1
  • EP3030942B1 patent drawingFigure 2
  • EP3030942B1 patent drawingFigure 3

AI summary

A secure industrial control system is disclosed herein. The industrial control system includes a plurality of industrial elements (e.g., modules, cables) which are provisioned during manufacture with their own unique security credentials. A key management entity of the secure industrial control system monitors and manages the security credentials of the industrial elements starting from the time they are manufactured up to and during their implementation within the industrial control system for promoting security of the industrial control system. An authentication process, based upon the security credentials, for authenticating the industrial elements being implemented in the industrial control system is performed for promoting security of the industrial control system. In one or more implementations, all industrial elements of the secure industrial control system are provisioned with the security credentials for providing security at multiple (e.g., all) levels of the system.