Multiplexer Remote Reconfiguration With Physical Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems face significant security risks due to remote access vulnerabilities, allowing malicious actors to disrupt critical infrastructure by gaining unauthorized access through weak authentication methods and cyberattacks, which current firewalls and device login credentials cannot effectively prevent.
Innovation Solution
Implementing a network of multiplexers with a physical authentication device that requires a trusted individual's physical presence and biometric verification to generate a token for secure remote access, ensuring that only authorized personnel can modify settings or access the system, and using a token generator to manage secure lockdown modes with time limits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remote access is allowed via electronic communication network, then system maintenance and upgrades can be performed remotely, but security risk increases allowing malicious actors to gain unauthorized access
Solution Approach 1:
A token generator acts as an intermediary between the multiplexer and remote users. The token generator creates time-limited access tokens that mediate the connection, allowing remote access while preventing direct unauthorized access to the multiplexer configuration interfaces.
Solution Approach 2:
The system performs preliminary authentication by requiring physical presence verification and biometric authentication before generating access tokens. This preliminary action ensures that only authorized personnel can obtain tokens, preventing malicious actors from gaining unauthorized access.
2Reliability
If device login credentials are used for authentication, then access control is implemented, but weak passwords and credential theft make authentication vulnerable to cyberattacks
Solution Approach 1:
The patent replaces traditional mechanical/password-based authentication systems with biometric authentication (fingerprint, iris, facial recognition). This substitution eliminates weak password vulnerabilities and credential theft risks by using unique physiological traits that cannot be easily compromised.
Solution Approach 2:
The token generator serves as an intermediary that verifies biometric authentication and issues time-limited access tokens. This intermediary layer ensures that even if biometric data is compromised, the damage is limited due to the time constraints on token validity.
3Productivity
If multiplexer settings can be modified remotely, then system reconfiguration is efficient, but unauthorized changes can disrupt critical infrastructure operations
Solution Approach 1:
The authentication requirements dynamically adjust based on the operation being performed. Standard operations use token-based authentication, while configuration changes require enhanced authentication with physical presence verification and biometric validation, ensuring that more critical operations have higher security barriers.
Solution Approach 2:
The system performs preliminary verification of the user's identity and authorization level before allowing remote configuration changes. This preliminary action ensures that only properly authenticated and authorized personnel can modify multiplexer settings, preventing unauthorized disruptions.
4Object-affected harmful factors
If firewalls are used to block unauthorized access, then network security is improved, but firewalls cannot prevent attacks from trusted sources or internal threats
Solution Approach 1:
The system performs preliminary authentication using biometric verification and physical presence confirmation before granting access tokens. This preliminary authentication occurs regardless of the user's network location or firewall rules, ensuring that even trusted internal users must properly authenticate, thereby preventing internal threats and unauthorized access from any source.
Data Source
AI summary
A secure control system includes a network of multiplexers that control end/field devices of an infrastructure system, such as an electric power grid. The multiplexers have a default secure lockdown state that prevents remote access to data on the multiplexers and prevents modification of software or firmware of the multiplexer. One or more of the multiplexers include a physical authentication device that confirms the physical proximity of a trusted individual when remote access is requested. A user accesses the network and one of the multiplexers remotely by way of login credentials. The trusted individual confirms the identity of the remote user and operates the physical authentication device connected with and in proximity to that multiplexer, thereby confirming that the remote user can be trusted to access data and reconfigure the multiplexers. The multiplexer connected with the physical authentication device generates a token that is passed to each of the multiplexers that the remote user needs access to. The token may specify a time period, after which, the multiplexers will reenter secure lockdown mode.


