Industrial Security Policy Assignment for Zero-Touch Device Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring security for industrial automation environments is time-consuming and prone to human error due to the need for manual, vendor-specific settings across numerous devices, often leading to disabled security features due to complexity.

Innovation Solution

A model-based security policy configuration system that groups devices into security zones, defines policies for secure communication and event management, and translates these policies into device-specific instructions, abstracting from vendor-specific complexities and enabling automated deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual vendor-specific security settings are configured for each device, then security can be customized for each device, but the configuration process becomes time-consuming and error-prone

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service configuration where the security management system automatically discovers devices, assigns security policies based on device roles and zones, and configures security settings without manual intervention. This eliminates time-consuming manual configuration while maintaining security accuracy through automated policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the configuration approach from manual parameter-by-parameter setting to automated parameter assignment based on device attributes. Security policies are automatically applied by matching device characteristics (vendor, type, zone) with predefined policy parameters, dramatically reducing configuration time while ensuring consistent and accurate security settings.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual security configuration is performed, then security policies can be applied, but human error increases and security features are often disabled due to complexity

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces an intermediary security management platform that sits between administrators and devices. This intermediary automatically translates high-level security requirements into device-specific configuration commands, eliminating the need for administrators to directly handle complex vendor-specific settings while ensuring consistent policy enforcement across all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a universal security configuration approach that works across multiple device vendors and types through a single management interface. By abstracting vendor-specific complexities and using standardized security zones and policies, the system simplifies operation while maintaining comprehensive security enforcement across diverse device ecosystems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated security policy assignment is implemented, then configuration time is reduced, but device-specific customization may be compromised

Engineering Contradiction:
Improvedeployment speedVSAvoiddevice-specific security customization
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by assigning different security policies to different device zones and roles while maintaining automated deployment. Each security zone (e.g., operational technology, information technology, management) receives customized policy sets tailored to its specific security requirements, enabling device-specific customization through automated zone-based policy assignment rather than manual configuration.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11588856B2Automatic endpoint security policy assignment by zero-touch enrollment
Publication Date: 2023.02.21 ROCKWELL AUTOMATION TECH INC
  • US11588856B2 patent drawing
  • US11588856B2 patent drawing
  • US11588856B2 patent drawing

AI summary

A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets for which diverse security policies are to be implemented. An interface allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets into security zones. When new industrial devices are subsequently installed on the plant floor, the system determines whether a security policy defined by the model is applicable to the new device and commissions the new device to comply with any relevant security policies. This mitigates the necessity for a system administrator to manually configure individual devices to comply with plant-wide security policies.