Local Certificate Registration for Runtime Device Replacement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial plants, device and application replacements during runtime require manual certificate reloading, leading to increased communication overhead and plant shutdowns, as existing systems lack knowledge of device topology and communication relationships, resulting in inefficient certificate management.

Innovation Solution

Implementing a local registration service that determines supported communication protocols and applications within the control system, allowing for device-specific certificate allocation and renewal without shutting down the plant, by integrating a software inventory that reflects configuration changes and network relationships, enabling efficient certificate management and runtime authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual certificate reloading is performed during device replacement, then certificate security is maintained, but plant shutdown is required and productivity is reduced

Engineering Contradiction:
Improvecertificate securityVSAvoidplant availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by maintaining a pre-configured software inventory and certificate database that enables immediate certificate issuance to replacement devices. The local registration authority is pre-prepared to authenticate and issue certificates without waiting for manual reloading procedures, thus maintaining security while avoiding shutdowns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated certificate management system enables self-service functionality where replacement devices can autonomously obtain certificates through automated authentication with the local registration authority. This eliminates the need for manual certificate reloading by personnel and allows continuous plant operation during device replacements.

Inventive Principle:
Principle #25Self-service

2Reliability

If devices request certificates individually based on situational needs, then certificate freshness is improved, but communication overhead increases

Engineering Contradiction:
Improvecertificate freshnessVSAvoidcommunication volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary actions by maintaining a pre-configured software inventory and certificate database that enables immediate certificate issuance to replacement devices. The local registration authority is pre-prepared to authenticate and issue certificates without waiting for manual reloading procedures, thus maintaining security while avoiding shutdowns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated certificate management system enables self-service functionality where replacement devices can autonomously obtain certificates through automated authentication with the local registration authority. This eliminates the need for manual certificate reloading by personnel and allows continuous plant operation during device replacements.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If certificate management functionalities are integrated into engineering components, then device replacement is simplified, but plant shutdown is required for certificate reloading

Engineering Contradiction:
Improvedevice replacement processVSAvoidplant availability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system performs preliminary actions by maintaining a pre-configured software inventory and certificate database that enables immediate certificate issuance to replacement devices. The local registration authority is pre-prepared to authenticate and issue certificates without waiting for manual reloading procedures, thus maintaining security while avoiding shutdowns.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated certificate management system enables self-service functionality where replacement devices can autonomously obtain certificates through automated authentication with the local registration authority. This eliminates the need for manual certificate reloading by personnel and allows continuous plant operation during device replacements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11163870B2Plant-specific, automated certificate management
Publication Date: 2021.11.02 SIEMENS AG
  • US11163870B2 patent drawing
  • US11163870B2 patent drawing
  • US11163870B2 patent drawing

AI summary

A method for authenticating devices and/or applications, specifically web applications, in a control system for an industrial plant, wherein the control system includes at least one local registration service and at least one software inventory, where the method includes determining by the at least one local registration service information about which communications protocols and/or applications are supported by the devices and/or applications and/or which communications protocols and/or applications are active, during authentication of the devices and/or applications within the control system, and storing the device-specific information determined by the local registration service in the at least one software inventory of the control system.