Local Certificate Whitelist for Industrial Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industrial automation systems, certificate-based authentication for communication partners results in high data flow and bandwidth usage due to reliance on external access control servers, leading to inefficiencies and increased vulnerability to unauthorized communication.
Innovation Solution
A method where a list management device identifies a target framework for a device, generates a positive list of permitted communication partners' certificates, and stores it locally, allowing the device to independently authenticate partners without external queries, reducing control messages and enhancing security by using target frame-specific whitelists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication using external access control servers is used, then security against unauthorized communication is improved, but control message bandwidth and data flow increase
Solution Approach 1:
The patent extracts the authentication decision-making function from the external access control server and places it locally in the communication device. The device stores a whitelist of permitted certificates locally and performs independent authentication by checking incoming certificates against this whitelist, eliminating the need for continuous external server queries and reducing control message bandwidth.
Solution Approach 2:
The patent implements preliminary action by pre-configuring the device with a whitelist of permitted communication partner certificates before operation. This whitelist is stored locally in the device's memory, enabling the device to perform immediate local authentication without requiring real-time communication with external access control servers during operation.
2Adaptability or versatility
If external access control servers are used for authentication, then centralized security management is improved, but communication latency and network dependency increase
Solution Approach 1:
The authentication function is extracted from the external server and embedded locally in each communication device. Each device maintains its own whitelist of permitted certificates and performs independent authentication checks, eliminating network dependency and communication latency while maintaining security policies through local decision-making.
3Reliability
If certificate validation is performed for every communication request, then authentication security is improved, but processing overhead and communication delay increase
Solution Approach 1:
The device performs self-service authentication by independently validating incoming certificates against its locally stored whitelist. This eliminates the need for continuous external server verification, reducing processing overhead and communication delay while maintaining authentication security through local certificate validation.
Data Source
Figure 1
Figure 2~4
AI summary
The method according to the invention for certificate-based authentication of communication partners in a device has the first method step (11) of identification of a target frame for the device. All permitted communication partners for the identified target frame are ascertained (12) from a total quantity of possible communication partners, and a positive list that is specific to the target frame and that comprises a respective certificate for each ascertained permitted communication partner is produced (13). In the next method step (14), the positive list is stored on the device. A certificate received from a purported communication partner in the device is checked against the certificates in the positive list (15), with communication between the device and the purported communication partner being permitted (16) only if the certificate from the purported communication partner matches a certificate in the positive list. The management apparatus according to the invention and the device according to the invention are designed to carry out the described method.