Modular Automation Access Control for Dynamic Module Privileges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modular automation systems, the dynamic and flexible nature makes it difficult to detect malicious behavior, increasing the risk of compromised modules causing economic, physical, or indirect harm, necessitating a strict access control mechanism.

Innovation Solution

A method for managing access control within modular automation systems by generating privilege associations and an access control policy based on processing steps, ensuring only privileged entities can access operations or data, using a central operating unit to enforce this policy and monitor denied access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If modular automation systems use dynamic and flexible module combinations to adapt to market demands, then adaptability and productivity are improved, but system security and detection of malicious behavior deteriorate

Engineering Contradiction:
ImproveadaptabilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the automation system into modular units (automation modules) with defined interfaces and communication protocols. Each module operates semi-autonomously with established trust boundaries, allowing flexible reconfiguration while maintaining security through modular isolation. The system divides access control into module-level and system-level policies, enabling adaptive reconfiguration without compromising overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including a security manager, policy enforcement points, and communication intermediaries that mediate between automation modules. These intermediaries monitor and control inter-module communications, detect malicious behaviors, and enforce access control policies without restricting the dynamic reconfiguration capability of the modular system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control restrictions are imposed on automation modules to prevent malicious behavior, then system security is improved, but system flexibility and dynamic reconfiguration deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control policies that adapt to the operational context and security requirements. Access permissions are not static but are granted temporarily based on the specific task, time, and security clearance levels. This allows the system to maintain strict security controls while enabling flexible reconfiguration for different production scenarios, as permissions are dynamically adjusted rather than permanently restricted.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of access control from binary (allowed/not allowed) to multi-dimensional parameters including time-of-day restrictions, task-specific permissions, hierarchical authority levels, and conditional access rules. This enables the system to provide fine-grained security control that adapts to different operational modes and reconfiguration scenarios without sacrificing overall system flexibility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12019418B2Access control within a modular automation system
Publication Date: 2024.06.25 ABB (SCHWEIZ) AG
  • US12019418B2 patent drawing
  • US12019418B2 patent drawing
  • US12019418B2 patent drawing

AI summary

A method for managing access control within a modular automation system including at least two automation modules. Each automation module is associated with an operation or a set of operations for carrying out a specific task. The method includes: receiving a schema of a common process including at least the order of processing steps of the modular automation system, wherein each processing step includes one or more of the specific tasks of the automation modules; generating privilege associations for each processing step with one or more automation modules, based on the schema; and generating an access control policy for the automation modules based on the privilege associations.