Local Certificate Whitelist for Industrial Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial automation systems, certificate-based authentication for communication partners results in high data flow and bandwidth usage due to reliance on external access control servers, leading to inefficiencies and increased vulnerability to unauthorized communication.

Innovation Solution

A method where a list management device identifies a target framework for a device, generates a positive list of permitted communication partners' certificates, and stores it locally, allowing the device to independently authenticate partners without external queries, reducing control messages and enhancing security by using target frame-specific whitelists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication using external access control servers is used, then security against unauthorized communication is improved, but control message bandwidth and data flow increase

Engineering Contradiction:
ImprovesecurityVSAvoidcontrol message bandwidth
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the authentication decision-making function from the external access control server and places it locally in the communication device. The device stores a whitelist of permitted certificates locally and performs independent authentication by checking incoming certificates against this whitelist, eliminating the need for continuous external server queries and reducing control message bandwidth.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary action by pre-configuring the device with a whitelist of permitted communication partner certificates before operation. This whitelist is stored locally in the device's memory, enabling the device to perform immediate local authentication without requiring real-time communication with external access control servers during operation.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If external access control servers are used for authentication, then centralized security management is improved, but communication latency and network dependency increase

Engineering Contradiction:
Improvecentralized security managementVSAvoidcommunication latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The authentication function is extracted from the external server and embedded locally in each communication device. Each device maintains its own whitelist of permitted certificates and performs independent authentication checks, eliminating network dependency and communication latency while maintaining security policies through local decision-making.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If certificate validation is performed for every communication request, then authentication security is improved, but processing overhead and communication delay increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The device performs self-service authentication by independently validating incoming certificates against its locally stored whitelist. This eliminates the need for continuous external server verification, reducing processing overhead and communication delay while maintaining authentication security through local certificate validation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3058701B1Method, management apparatus and device for certificate-based authentication of communication partners in a device
Publication Date: 2019.08.14 SIEMENS AG
  • EP3058701B1 patent drawingFigure 1
  • EP3058701B1 patent drawingFigure 2~4

AI summary

The method according to the invention for certificate-based authentication of communication partners in a device has the first method step (11) of identification of a target frame for the device. All permitted communication partners for the identified target frame are ascertained (12) from a total quantity of possible communication partners, and a positive list that is specific to the target frame and that comprises a respective certificate for each ascertained permitted communication partner is produced (13). In the next method step (14), the positive list is stored on the device. A certificate received from a purported communication partner in the device is checked against the certificates in the positive list (15), with communication between the device and the purported communication partner being permitted (16) only if the certificate from the purported communication partner matches a certificate in the positive list. The management apparatus according to the invention and the device according to the invention are designed to carry out the described method.