Multiplexer Remote Reconfiguration With Physical Token Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face significant security risks due to remote access vulnerabilities, allowing malicious actors to disrupt critical infrastructure by gaining unauthorized access through weak authentication methods and cyberattacks, which current firewalls and device login credentials cannot effectively prevent.

Innovation Solution

Implementing a network of multiplexers with a physical authentication device that requires a trusted individual's physical presence and biometric verification to generate a token for secure remote access, ensuring that only authorized personnel can modify settings or access the system, and using a token generator to manage secure lockdown modes with time limits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote access is allowed via electronic communication network, then system maintenance and upgrades can be performed remotely, but security risk increases allowing malicious actors to gain unauthorized access

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A token generator acts as an intermediary between the multiplexer and remote users. The token generator creates time-limited access tokens that mediate the connection, allowing remote access while preventing direct unauthorized access to the multiplexer configuration interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication by requiring physical presence verification and biometric authentication before generating access tokens. This preliminary action ensures that only authorized personnel can obtain tokens, preventing malicious actors from gaining unauthorized access.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device login credentials are used for authentication, then access control is implemented, but weak passwords and credential theft make authentication vulnerable to cyberattacks

Engineering Contradiction:
Improveauthentication securityVSAvoidcredential compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical/password-based authentication systems with biometric authentication (fingerprint, iris, facial recognition). This substitution eliminates weak password vulnerabilities and credential theft risks by using unique physiological traits that cannot be easily compromised.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The token generator serves as an intermediary that verifies biometric authentication and issues time-limited access tokens. This intermediary layer ensures that even if biometric data is compromised, the damage is limited due to the time constraints on token validity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If multiplexer settings can be modified remotely, then system reconfiguration is efficient, but unauthorized changes can disrupt critical infrastructure operations

Engineering Contradiction:
Improvereconfiguration efficiencyVSAvoidsystem operational stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The authentication requirements dynamically adjust based on the operation being performed. Standard operations use token-based authentication, while configuration changes require enhanced authentication with physical presence verification and biometric validation, ensuring that more critical operations have higher security barriers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary verification of the user's identity and authorization level before allowing remote configuration changes. This preliminary action ensures that only properly authenticated and authorized personnel can modify multiplexer settings, preventing unauthorized disruptions.

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If firewalls are used to block unauthorized access, then network security is improved, but firewalls cannot prevent attacks from trusted sources or internal threats

Engineering Contradiction:
Improvenetwork attack preventionVSAvoidsecurity system effectiveness against internal threats
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary authentication using biometric verification and physical presence confirmation before granting access tokens. This preliminary authentication occurs regardless of the user's network location or firewall rules, ensuring that even trusted internal users must properly authenticate, thereby preventing internal threats and unauthorized access from any source.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11652809B2System and method for securely changing network configuration settings to multiplexers in an industrial control system
Publication Date: 2023.05.16 HUBBELL INC
  • US11652809B2 patent drawing
  • US11652809B2 patent drawing
  • US11652809B2 patent drawing

AI summary

A secure control system includes a network of multiplexers that control end/field devices of an infrastructure system, such as an electric power grid. The multiplexers have a default secure lockdown state that prevents remote access to data on the multiplexers and prevents modification of software or firmware of the multiplexer. One or more of the multiplexers include a physical authentication device that confirms the physical proximity of a trusted individual when remote access is requested. A user accesses the network and one of the multiplexers remotely by way of login credentials. The trusted individual confirms the identity of the remote user and operates the physical authentication device connected with and in proximity to that multiplexer, thereby confirming that the remote user can be trusted to access data and reconfigure the multiplexers. The multiplexer connected with the physical authentication device generates a token that is passed to each of the multiplexers that the remote user needs access to. The token may specify a time period, after which, the multiplexers will reenter secure lockdown mode.