Industrial Multiplexer Access Control With Physical Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems for industrial control systems are vulnerable to cyberattacks, allowing malicious individuals to gain remote access and disrupt critical infrastructure, as they rely primarily on firewalls and device login credentials, which are insufficient to prevent unauthorized access and identify attackers, especially when attacks originate from distant locations with limited law enforcement resources.
Innovation Solution
The implementation of a biometric authentication system combined with a token-based secure lockdown mechanism, where biometric sensors and encrypted tokens are used to authenticate users and ensure secure access to industrial control systems, with a default timer to reenter secure lockdown mode, preventing unauthorized modifications and operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls and device login credentials are used for security, then network access control is provided, but the system remains vulnerable to cyberattacks from remote locations
Solution Approach 1:
The patent introduces an authentication device as an intermediary between the user and the multiplexer. This device physically connects to the multiplexer and requires the presence of an authorized person to generate access tokens, thereby mediating the access control process and eliminating remote attack vectors while maintaining security reliability
Solution Approach 2:
The patent replaces the purely electronic/digital authentication system (firewalls and login credentials) with a hybrid system that incorporates physical mechanical elements. The authentication device requires physical connection and presence, substituting remote electronic access with local physical authentication, thereby eliminating the vulnerability to remote cyberattacks
2Ease of operation
If remote access is allowed for maintenance and upgrades, then system serviceability is improved, but the risk of unauthorized access increases
Solution Approach 1:
The authentication device serves as a mandatory intermediary that must be physically present at the multiplexer location to generate access tokens. This eliminates the possibility of remote unauthorized access while still allowing authorized personnel to perform maintenance and upgrades by physically connecting the authentication device to the system
3Reliability
If device login credentials are used for authentication, then access control is provided, but credentials can be stolen or shared by disgruntled employees
Solution Approach 1:
The authentication device acts as a secure intermediary that generates temporary access tokens rather than relying on static credentials. This eliminates the risk of credential theft and sharing because the authentication mechanism requires physical presence and does not depend on secret information that can be stolen or shared
Solution Approach 2:
The system uses short-lived access tokens generated by the authentication device instead of long-term credentials. These tokens are temporary and cannot be reused, making them ineffective for theft or sharing purposes while maintaining secure access control
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A secure control system includes a network of multiplexers that control end/field devices of an infrastructure system, such as an electric power grid. The multiplexers have a default secure lockdown state that prevents remote access to data on the multiplexers and prevents modification of software or firmware of the multiplexer. One or more of the multiplexers include a physical authentication device that confirms the physical proximity of a trusted individual when remote access is requested. A user accesses the network and one of the multiplexers remotely by way of login credentials. The trusted individual confirms the identity of the remote user and operates the physical authentication device connected with and in proximity to that multiplexer, thereby confirming that the remote user can be trusted to access data and reconfigure the multiplexers. The multiplexer connected with the physical authentication device generates a token that is passed to each of the multiplexers that the remote user needs access to. The token may specify a time period, after which, the multiplexers will reenter secure lockdown mode.