Industrial Automation Cloud Authentication Using Mobile Token Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation devices face challenges in securely connecting to cloud services without hardcoded information, as they often require user interaction and authentication, which can be complex and insecure.

Innovation Solution

A system where a mobile device connects to an industrial automation device and a cloud service, generating and managing tokens for secure access, allowing the device to communicate directly with the cloud for information exchange without user involvement or hardcoded credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardcoded authentication information is stored in the industrial automation device, then the device can authenticate with cloud services, but the security is compromised and the setup is inflexible

Engineering Contradiction:
Improveauthentication securityVSAvoidsetup flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts authentication credentials from the industrial automation device itself and stores them externally in a secure element or cloud service. The device only holds a reference to the credentials, not the actual authentication data. This resolves the contradiction by removing hardcoded information (improving security) while allowing credentials to be updated or regenerated (improving flexibility).

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element or cloud service as an intermediary that actually stores and manages authentication credentials. The industrial automation device communicates with this intermediary during authentication, rather than using hardcoded credentials directly. This mediator approach enables secure credential management while maintaining device flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user interaction is required for authentication, then security can be verified, but the automation capability is reduced and complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice automation capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements preliminary authentication actions during device commissioning or initialization, where credentials are pre-configured in the secure element or cloud service. After this preliminary setup, the device can automatically authenticate without requiring user interaction during normal operation. This resolves the contradiction by performing security verification upfront while enabling subsequent automated operation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If complex authentication protocols are implemented, then security is improved, but the device complexity and difficulty of operation increase

Engineering Contradiction:
Improveconnection securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the secure element or cloud service automatically manages credential storage, retrieval, and rotation without requiring complex device-side authentication logic. The industrial automation device simply presents its identity reference, and the intermediary handles the complex security protocols. This resolves the contradiction by centralizing complexity in the intermediary while keeping the device simple.

Inventive Principle:
Principle #25Self-service

4Ease of manufacture

If hardcoded credentials are used, then setup is simple, but security is compromised and updates are difficult

Engineering Contradiction:
Improvedevice setup simplicityVSAvoidcredential security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements dynamic credential management where authentication credentials can be updated, rotated, or revoked without changing the device hardware or firmware. The secure element or cloud service dynamically manages credential versions, allowing simple device setup while maintaining high security and update capability. This resolves the contradiction by making credentials dynamic rather than static/hardcoded.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3511848B1Industrial automation device and cloud service
Publication Date: 2023.09.06 ABB (SCHWEIZ) AG
  • EP3511848B1 patent drawingFigure 1~2
  • EP3511848B1 patent drawingFigure 3~5
  • EP3511848B1 patent drawingFigure 6~7

AI summary

To provide an industrial automation device with a token to be used as authentication information in information exchange between a first cloud service and the industrial automation device, a mobile device is connected to the industrial automation device and to a cloud service that is the first cloud service or a second cloud service. After authenticating the user of the mobile device to the cloud service, a token is generated by the cloud service to the first cloud service, and forwarded via the mobile device to the industrial automation device. If the cloud service that generated the token is the second cloud service, the token is forwarded via the mobile device, after the mobile has been authenticated in the first cloud service, to the first cloud service. Thereafter the industrial automation device and the first cloud service may communicate directly with each other using the token for authentication.