Industrial Control Security via Encrypted State Thumbprints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems are vulnerable to malicious attacks, particularly through Internet connections, which can lead to physical damage and risk to human life, as traditional security measures are insufficient in protecting distributed and networked systems.

Innovation Solution

A system that generates an encrypted state thumbprint at each distributed component, which includes operating software, configuration data, and environmental conditions, to monitor and detect tampering, configuration changes, and environmental variations, allowing for constant monitoring and minimal bandwidth consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional physical security measures are used to protect industrial control systems, then physical access is limited, but distributed systems and network connections create additional vulnerability points that physical security cannot address

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical security mechanisms with a digital security system that uses cryptographic hashing and digital fingerprinting to protect control systems. Instead of relying solely on physical barriers, the system uses software-based integrity verification through hash functions that continuously monitor and verify the authenticity of control devices, software, and configurations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary security layer that acts as a mediator between physical security and network security. This layer uses digital fingerprints and hash verification to bridge the gap between physical protection and network-based threats, providing comprehensive security across distributed systems without requiring complex multi-layered physical security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If constant monitoring of control devices is implemented to detect tampering, then security detection capability is improved, but bandwidth consumption increases

Engineering Contradiction:
Improvetampering detectionVSAvoidbandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent extracts only the essential security-critical information from control devices by generating compact digital fingerprints through hash functions. Instead of transmitting or monitoring entire control programs, configurations, or runtime data, the system extracts condensed hash values that represent the integrity state of these elements, dramatically reducing bandwidth requirements while maintaining detection precision.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms large volumes of control device data into compact hash parameters. By changing the representation from full control programs and configurations to condensed cryptographic hashes, the system achieves constant monitoring capability with minimal bandwidth consumption, as hash values are compact and can be transmitted efficiently.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive security monitoring of distributed control systems is implemented, then detection of unauthorized modifications is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveintegrity verificationVSAvoidsecurity implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring function into modular components: hash generation at individual control devices, fingerprint creation at the master controller, and verification processes distributed throughout the system. This segmentation allows each component to perform a specific, simple function, reducing implementation complexity while achieving comprehensive security coverage across distributed control systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security framework using hash functions that can verify integrity across multiple types of control devices, software versions, and configurations. The same cryptographic approach works for PLCs, HMI systems, control programs, and configuration files, providing a unified security solution that reduces implementation complexity compared to device-specific security mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3101491B1Security system for industrial control infrastructure
Publication Date: 2019.04.17 ROCKWELL AUTOMATION TECH INC
  • EP3101491B1 patent drawingFigure 1~2
  • EP3101491B1 patent drawingFigure 3~5
  • EP3101491B1 patent drawingFigure 4

AI summary

An industrial control system providing security against tampering or modification generates periodic state thumbprints defining a state of control elements that may be forwarded to a security or safety appliance for comparison to a benchmark thumbprint indicating no tampering. The transmitted state thumbprint may capture not only programs but also configuration and environmental states of the control element.