I/O Module Attestation for Secure Virtualized Automation Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing virtualization of automation functions in cyber-physical systems, where compute platforms are operated by third parties, necessitates enhanced security measures to protect against manipulation and ensure authorized access to actuator/sensor devices.

Innovation Solution

Implement a method involving cryptographically protected attestations to establish authenticated communication links between virtualized automation units and I/O modules, verifying authorization information to ensure secure access and operation, including features like digital certificates and cryptographic keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualized automation units are used to access actuator/sensor devices via network, then automation functionality and flexibility are improved, but security risks and vulnerability to manipulation increase

Engineering Contradiction:
Improveautomation functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an I/O module as an intermediary component between the virtualized automation unit and the actuator/sensor device. This mediator establishes an authenticated communication link that verifies the identity and authorization of the virtualized automation unit before allowing access to physical devices, thus maintaining security while enabling virtualization benefits

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and authorization checks through cryptographically protected attestation before the virtualized automation unit can access the actuator/sensor devices. This advance verification ensures that only authorized virtualized units can establish communication links with physical devices, preventing unauthorized manipulation

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If third-party compute platforms are used for virtualization, then infrastructure flexibility and resource utilization are improved, but control over security measures and protection against manipulation deteriorates

Engineering Contradiction:
Improveinfrastructure flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent extracts the security verification function from the compute platform layer and implements it at the I/O module level. By taking out the authentication and authorization checks from the virtualized environment control, the system ensures that security measures are enforced independently of the third-party compute platform, maintaining security control while allowing infrastructure flexibility

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If cryptographically protected attestation is implemented to verify authorization, then security and tamper-proof monitoring are improved, but system complexity and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The I/O module autonomously performs cryptographic verification of the virtualized automation unit's authorization without requiring external intervention. The module self-services the security function by maintaining authenticated communication links and verifying authorization information locally, reducing the need for complex external security infrastructure

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4476643B1Method and device for operating an automation system
Publication Date: 2025.11.05 SIEMENS AG
  • EP4476643B1 patent drawingFigure 1~2
  • EP4476643B1 patent drawingFigure 3~4

AI summary

The invention relates to a method for operating an automation system which comprises a first number of I/O modules and a computer system which is coupled to the first number of I/O modules via a network and which has a second number of virtualized automation units. Each I/O module has a respective number of actuator/sensor devices. The method has the following steps: a) providing a cryptographically protected attestation for specifying an authenticated communication connection between a specified I/O module of the first number and a specified virtualized automation unit of the second number, wherein the authenticated communication connection comprises an authenticated communication between the specified virtualized automation unit and the specified I/O module and between the specified virtualized automation unit and at least some of the actuator/sensor devices coupled to the specified I/O module, and b) checking the provided cryptographically protected attestation in order to ascertain authorization information on the basis of the access, which is confirmed by the checked attestation, of the specified virtualized automation unit to the specified I/O module and/or to the aforementioned actuator/sensor devices coupled to the specified I/O module.