Industrial Automation Cloud Authentication Using Mobile Token Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial automation devices face challenges in securely connecting to cloud services without hardcoded information, as they often require user interaction and authentication, which can be complex and insecure.
Innovation Solution
A system where a mobile device connects to an industrial automation device and a cloud service, generating and managing tokens for secure access, allowing the device to communicate directly with the cloud for information exchange without user involvement or hardcoded credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardcoded authentication information is stored in the industrial automation device, then the device can authenticate with cloud services, but the security is compromised and the setup is inflexible
Solution Approach 1:
The patent extracts authentication credentials from the industrial automation device itself and stores them externally in a secure element or cloud service. The device only holds a reference to the credentials, not the actual authentication data. This resolves the contradiction by removing hardcoded information (improving security) while allowing credentials to be updated or regenerated (improving flexibility).
Solution Approach 2:
The patent introduces a secure element or cloud service as an intermediary that actually stores and manages authentication credentials. The industrial automation device communicates with this intermediary during authentication, rather than using hardcoded credentials directly. This mediator approach enables secure credential management while maintaining device flexibility.
2Reliability
If user interaction is required for authentication, then security can be verified, but the automation capability is reduced and complexity increases
Solution Approach 1:
The patent implements preliminary authentication actions during device commissioning or initialization, where credentials are pre-configured in the secure element or cloud service. After this preliminary setup, the device can automatically authenticate without requiring user interaction during normal operation. This resolves the contradiction by performing security verification upfront while enabling subsequent automated operation.
3Reliability
If complex authentication protocols are implemented, then security is improved, but the device complexity and difficulty of operation increase
Solution Approach 1:
The patent implements self-service authentication where the secure element or cloud service automatically manages credential storage, retrieval, and rotation without requiring complex device-side authentication logic. The industrial automation device simply presents its identity reference, and the intermediary handles the complex security protocols. This resolves the contradiction by centralizing complexity in the intermediary while keeping the device simple.
4Ease of manufacture
If hardcoded credentials are used, then setup is simple, but security is compromised and updates are difficult
Solution Approach 1:
The patent implements dynamic credential management where authentication credentials can be updated, rotated, or revoked without changing the device hardware or firmware. The secure element or cloud service dynamically manages credential versions, allowing simple device setup while maintaining high security and update capability. This resolves the contradiction by making credentials dynamic rather than static/hardcoded.
Data Source
Figure 1~2
Figure 3~5
Figure 6~7
AI summary
To provide an industrial automation device with a token to be used as authentication information in information exchange between a first cloud service and the industrial automation device, a mobile device is connected to the industrial automation device and to a cloud service that is the first cloud service or a second cloud service. After authenticating the user of the mobile device to the cloud service, a token is generated by the cloud service to the first cloud service, and forwarded via the mobile device to the industrial automation device. If the cloud service that generated the token is the second cloud service, the token is forwarded via the mobile device, after the mobile has been authenticated in the first cloud service, to the first cloud service. Thereafter the industrial automation device and the first cloud service may communicate directly with each other using the token for authentication.