OPC UA Endpoint Secure Certificate Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current OPC UA communication methods in industrial devices often lack secure certificate-based encryption, relying on insecure methods like username/password or pre-installed device certificates, which are cumbersome and insecure, especially in untrusted networks, leading to potential security breaches and validation issues.
Innovation Solution
A method that enables secure communication by opening an unsecured OPC UA Endpoint to provide security context data, requesting and validating an initial device certificate, encrypting and decrypting it using public and private keys, and establishing a secured OPC UA Endpoint for secure network access, allowing secure communication over an untrusted network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If pre-installed device certificates are used to establish trust relationship, then device integration is simplified, but certificate management becomes complex and validation issues occur
Solution Approach 1:
The device autonomously generates its own certificate using a self-signed mechanism, eliminating the need for external certificate authorities or complex certificate management infrastructure. This allows the device to independently establish secure communication without requiring manual certificate installation or management.
Solution Approach 2:
A certificate generation service acts as an intermediary between the device and external systems. This service automatically generates and manages certificates on behalf of the device, simplifying the integration process while avoiding the complexity of manual certificate handling and validation.
2Adaptability or versatility
If own device certificates are generated and installed on devices, then PKI integration is improved, but device access becomes cumbersome and security risks increase
Solution Approach 1:
The device performs self-registration with the PKI infrastructure by automatically generating its own certificate and registering it with the certificate authority. This eliminates the need for manual certificate installation and simplifies the integration process while maintaining full PKI compliance.
Solution Approach 2:
The certificate generation and registration process is performed automatically during device initialization or first connection, before any secure communication is required. This preliminary setup eliminates the need for subsequent manual certificate installation and simplifies ongoing device access.
3Ease of manufacture
If direct device access is used to install certificates, then certificate installation is possible, but security risks and operational complexity increase
Solution Approach 1:
The device autonomously generates and installs its own certificate without requiring direct physical or remote access from external systems. This self-service approach eliminates security risks associated with external access while ensuring proper certificate installation.
Solution Approach 2:
A secure communication channel acts as an intermediary for certificate transmission. The certificate is generated and exchanged through this protected channel, eliminating the need for direct device access while ensuring secure and reliable certificate installation.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This method allows for secure communication between OPC UA Server and Client over an untrusted network, mitigating security risks and enabling secure access to technical functions without requiring direct device access or proprietary software, ensuring secure certificate handling and integration with existing OPC UA frameworks.
Implementation Method 1
Asymmetric cryptography based on a public key infrastructure (PKI) is a way to secure such communication
Implementation Method 2
encrypting and integrity protected communication
Data Source
Figure 1
Figure 2
AI summary
A method for enabling a secure communication with a target device over a network is provided. The method includes: opening an unsecured OPC UA Endpoint by an OPC UA Server that runs on the target device, the unsecured OPC UA Endpoint providing security context data that is in conformity with an OPC UA information model, wherein the security context data indicates the presence of an initial device certificate stored on the target device; connecting to the OPC UA Server over the network by an OPC UA Client running on a first device, and requesting the initial device certificate; receiving, by the OPC UA Client, the initial device certificate from the OPC UA Server by unsecured communication over the network; validating, by the first device, the initial device certificate against a root certificate or intermediate certificate of the issuer of the initial device certificate; establishing, by the first device, a device certificate; encrypting, by the first device, at least the device certificate using an initial device public key of the initial device certificate to produce encrypted data; sending the encrypted data from the OPC UA Client to the OPC UA Server over the network; decrypting, by the target device, the encrypted data using an initial device private key associated with the initial device certificate to obtain at least the device certificate; storing the device certificate on the target device; and opening a secured OPC UA Endpoint by the OPC UA Server, the secured OPC UA Endpoint providing access to technical functions of the target device via secure communication over the network based on the device certificate.