Operator Station PKI Initialization for Role-Based Certificate Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual installation and management of certificates for operator station servers in technical installations are cumbersome, leading to inefficiencies and potential errors, particularly during certificate renewal and changes in certification authorities, which can impact the availability and security of the installation.

Innovation Solution

A method that automates the initialization of operator station servers by establishing connections between engineering and operator station servers, transmitting validation certificates, and using configuration information to request only necessary certificates from a certification service, reducing the need for manual intervention and ensuring only required certificates are installed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual installation and management of certificates is performed, then flexibility in certificate selection is maintained, but time consumption and potential for errors increase

Engineering Contradiction:
Improvecertificate managementVSAvoidcertificate installation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables automated self-service certificate management where the operator station server automatically receives configuration information from the engineering station server, identifies required certificates based on its role, and obtains them from the certification authority without manual intervention. This eliminates time-consuming manual certificate installation while maintaining operational flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The engineering station server performs preliminary actions by automatically determining the role of the operator station server and pre-configuring the necessary certificate information before the operator station server needs them. This preliminary configuration enables the operator station server to automatically obtain only the required certificates, reducing installation time and avoiding errors.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all possible certificates are installed manually, then complete coverage is ensured, but device complexity and configuration errors increase

Engineering Contradiction:
Improvecertificate coverageVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and installs only the specific certificates required for the operator station server's determined role, rather than installing all possible certificates. The engineering station server automatically identifies which certificates are necessary based on the server's function, reducing complexity while ensuring complete coverage for the required operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Each operator station server receives a customized set of certificates tailored to its specific role and requirements. The engineering station server determines the appropriate certificate subset for each server based on its local configuration and functional requirements, ensuring reliability without unnecessary complexity.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If manual certificate renewal is performed, then control over the process is maintained, but productivity and operational reliability decrease

Engineering Contradiction:
Improvecertificate renewal controlVSAvoidcertificate renewal efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The operator station server automatically monitors certificate expiration and initiates renewal processes without manual intervention. The server communicates with the engineering station server and certification authority to automatically renew certificates, maintaining control while significantly improving productivity and operational reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the operator station server continuously monitors the status of its certificates and automatically initiates renewal processes when needed. The engineering station server receives feedback about certificate status and coordinates renewal actions, ensuring both control and high efficiency.

Inventive Principle:
Principle #23Feedback

4Reliability

If comprehensive trust chains are manually configured, then security validation is ensured, but ease of operation and time consumption worsen

Engineering Contradiction:
Improvecertificate validation securityVSAvoidtrust chain configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The engineering station server performs preliminary configuration of complete trust chains including root certificates and intermediate certificates before the operator station server needs them. This preliminary setup ensures security validation is ready in advance, eliminating time-consuming manual trust chain configuration while maintaining comprehensive security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system merges the configuration of trust chains with the certificate distribution process. The engineering station server automatically bundles the necessary trust chain certificates with the operational certificates and transmits them together to the operator station server in a single automated operation, reducing time consumption while ensuring complete security validation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11558203B2Automated public key infrastructure initialization
Publication Date: 2023.01.17 SIEMENS AG
  • US11558203B2 patent drawing
  • US11558203B2 patent drawing
  • US11558203B2 patent drawing

AI summary

An operator station server of a technical installation upon which a certification service is implemented, wherein the certification service is configured to receive configuration information, which depends on a role of the operator station server in the technical installation, from at least one of (i) an engineering station server and (ii) a registration service of the technical installation, where the configuration information comprises information identifying which certificates of the certification service of the operator station server must be requested from a certification authority of the technical installation.