Industrial Security Policy Translation Across Multi-Vendor Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring security for industrial automation environments is challenging due to the need for manual, vendor-specific settings on numerous devices, which is time-consuming and prone to errors, especially when dealing with diverse device vendors, leading to potential security risks and disabled security features.

Innovation Solution

A model-based security policy configuration system that groups industrial devices into security zones using a graphical interface, defines security policies, and translates these policies into device-specific instructions, abstracting from vendor-specific complexities and enabling automated deployment across multiple vendors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual vendor-specific configuration is used for each device, then security settings can be customized for individual devices, but the configuration process becomes time-consuming and error-prone

Engineering Contradiction:
Improvesecurity configuration reliabilityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the configuration process into two distinct layers: a vendor-agnostic security policy layer that defines security requirements, and vendor-specific implementation layers that translate these policies into device-specific configurations. This segmentation allows security policies to be defined once and automatically deployed across multiple vendor-specific devices, reducing configuration time while maintaining security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary translation layer that acts as a mediator between the high-level security policy definitions and the vendor-specific device configurations. This intermediary automatically translates abstract security policies into concrete device-specific settings, eliminating the need for manual vendor-specific configuration while ensuring accurate implementation of security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual configuration is performed for diverse device vendors, then device-specific security requirements can be met, but complexity increases and expertise is required

Engineering Contradiction:
Improvevendor-specific security adaptationVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal security policy framework that can be applied across multiple vendor-specific devices. The vendor-agnostic security policies serve as a universal configuration that automatically adapts to different device types and vendors through the translation layer, eliminating the need for separate manual configuration processes for each vendor while maintaining vendor-specific security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs a copying mechanism where a single security policy definition is automatically copied and translated into multiple vendor-specific configuration instances. This allows the same security intent to be replicated across diverse devices without requiring manual recreation of configurations for each device, reducing complexity while maintaining adaptability.

Inventive Principle:
Principle #26Copying

3Ease of operation

If security features are disabled to avoid configuration complexity, then deployment is easier, but security posture deteriorates

Engineering Contradiction:
Improvedeployment easeVSAvoidsecurity posture
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements self-service automation where the configuration platform automatically performs the complex vendor-specific configuration tasks without requiring manual intervention. This self-service capability maintains strong security postures by ensuring security policies are properly configured, while simultaneously providing ease of deployment through automated processes that eliminate manual configuration barriers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11575571B2Centralized security event generation policy
Publication Date: 2023.02.07 ROCKWELL AUTOMATION TECH INC
  • US11575571B2 patent drawing
  • US11575571B2 patent drawing
  • US11575571B2 patent drawing

AI summary

A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets for which diverse security policies are to be implemented. An interface allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets into security zones. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate device settings on one or more of the industrial assets to implement the security event management policies, and deploys these instructions to the appropriate assets in order to implement the defined policies.