Mobile-Mediated Certificate Provisioning for ICS Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face challenges in securely configuring modules during commissioning, which is time-consuming and prone to errors, especially when connected to external networks, as initial detection and security certificate generation occur without secure connections.
Innovation Solution
A method using a mobile device with both short-range and long-range communication protocols to establish secure connections by generating and validating signed security certificates, where the mobile device acts as a secure interface to transmit the certificate signing request to a signing server and then back to the module, ensuring secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual configuration is used during module commissioning, then configuration accuracy can be ensured, but time consumption and labor intensity increase significantly
Solution Approach 1:
The system enables automatic module detection and configuration through the mobile device's camera scanning the module's identification features. The configuration software automatically retrieves module parameters and pushes settings without requiring manual technician intervention for each configuration step, allowing the system to configure itself autonomously
Solution Approach 2:
The patent replaces manual mechanical configuration actions (physically adjusting dials, switches, jumpers) with automated electronic configuration delivered through wireless communication. The mobile device captures module identification data via camera, transmits it to the server, and receives automated configuration parameters that are pushed to the module electronically
2Extent of automation
If network connection is established during initial module detection, then configuration can be automated, but security vulnerabilities increase due to lack of secure connections
Solution Approach 1:
The mobile device establishes a secure connection to the configuration software before the module connects to the network. The system performs preliminary security setup by having the technician authenticate and establish encrypted communication channels in advance, so that when the module later connects, the secure framework is already in place
Solution Approach 2:
The mobile device acts as an intermediary security layer between the module and the network. It captures module identification through camera, communicates with the configuration software through secure local connection, and facilitates the establishment of secure network connections, thereby preventing direct unsecured access between modules and the network
3Manufacturing precision
If technician manually configures each module, then configuration accuracy improves, but productivity and efficiency decrease
Solution Approach 1:
The system enables automatic module detection and configuration through the mobile device's camera scanning the module's identification features. The configuration software automatically retrieves module parameters and pushes settings without requiring manual technician intervention for each configuration step, allowing the system to configure itself autonomously
Solution Approach 2:
The mobile device's camera captures an optical copy (image) of the module's identification features, which is then processed to extract configuration parameters. This optical copying mechanism replaces manual reading and transcription, enabling rapid automated identification and configuration of multiple modules
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach reduces the risk of interference and errors during module provisioning by establishing secure connections, minimizing the need for manual technician intervention and reducing the vulnerability of modules during initial configuration.
Implementation Method 1
A first wireless communication connection is established between the secure device and the module via a first wireless communication protocol
Implementation Method 2
A second wireless communication connection is established between the secure device and a signing server via a wireless access point and a second wireless communication protocol
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A secure method for establishing communications to provision modules in an industrial control system generates a certificate signing request to obtain a signed security certificate. A mobile device is located proximate to the module with the certificate signing request, and the mobile device has previously established itself as a secure communication interface on the network. The mobile device establishes a first connection between the module and the mobile device via a short-range protocol and a s second connection between the mobile device and a signing server via a network. The mobile device retrieves the certificate signing request via the first connection and transmits the certificate signing request to the signing server via the second connection. Because the mobile device has previously established itself as a secure interface, the transmission of the certificate signing request to the signing server may be made via a secure connection.