Legacy Device Lock Code Control for Firmware Change Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy devices in industrial process control and automation systems lack modern cybersecurity protections, making them vulnerable to attacks that can lead to unauthorized changes in configuration and firmware, potentially causing device shutdown or permanent damage.

Innovation Solution

Implementing a lock and unlock code system using a device index to secure legacy devices, where a lock code sets the device in a locked state preventing changes, and an unlock code allows authorized changes, with monitoring and enforcement software programs ensuring compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If legacy devices are deployed with older hardware technology, then device complexity is reduced and ease of manufacture is improved, but cybersecurity protection capability deteriorates

Engineering Contradiction:
Improveease of manufactureVSAvoidcybersecurity protection capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an intermediary security system that mediates between the legacy device and the network. This intermediary layer provides modern cybersecurity protections (authentication, encryption, firmware verification) without requiring modifications to the legacy device hardware, thus maintaining ease of manufacture while improving cybersecurity capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security functionality is segmented from the legacy device itself and placed in a separate security module or gateway. This segmentation allows the legacy device to remain simple and easy to manufacture, while the separate security component provides the necessary cybersecurity protections independently.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If legacy devices lack secure boot and signed firmware, then device complexity is reduced, but vulnerability to cyber attacks increases

Engineering Contradiction:
Improvedevice complexityVSAvoidvulnerability to cyber attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

A security intermediary is introduced that performs firmware signature verification and secure boot functions externally. The legacy device maintains its simple architecture without these complex security features, while the intermediary gateway provides the necessary protection against unauthorized firmware and cyber attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security verification actions are performed in advance by the intermediary system before firmware is executed on the legacy device. The gateway validates firmware signatures and ensures boot integrity beforehand, preventing malicious code from executing on the simple legacy hardware.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If legacy devices rely on layered system security, then individual device security requirements are reduced, but system security dependency increases

Engineering Contradiction:
Improvedevice complexityVSAvoidsystem security dependency
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent positions the security gateway as an intermediary that assumes the security burden, allowing legacy devices to remain simple without layered security. While this creates system-level security dependency, it centralizes security management and ensures consistent protection across all legacy devices in the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12361114B2System and method for providing security to legacy devices
Publication Date: 2025.07.15 HONEYWELL INTERNATIONAL INC
  • US12361114B2 patent drawing
  • US12361114B2 patent drawing
  • US12361114B2 patent drawing

AI summary

A system and method for securing a device of an industrial process control and automation system comprises setting a lock code in a device index of the device and executing a monitoring software program that reads the lock code and sets the device in a locked state. An enforcement software program prevents changes to the configuration and firmware of the device when the device is in the locked state. The device is further arranged to be released from the lock state by setting an unlock code in the device index and executing the monitoring software program to read the unlock code and set the device in an unlocked state.