Operator Station PKI Initialization for Role-Based Certificate Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of certificates for operator station servers in technical systems is inefficient, leading to unnecessary certificate installations, laborious renewal processes, and potential errors, which can impair system availability and security.

Innovation Solution

A method that initializes operator station servers by establishing connections between engineering and operator station servers, transmitting validation certificates, and configuring certification services to request only required certificates based on the server's role, ensuring efficient certificate management and secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all certificates are manually installed on operator station servers during installation and lifecycle, then certificate coverage is comprehensive, but device complexity and time consumption increase significantly

Engineering Contradiction:
Improvecertificate coverageVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The operator station server automatically determines its own role and requests only the certificates it needs from the certification authority, eliminating manual intervention. The server self-configures its certificate requirements based on its functional role in the technical system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The certificate management system transitions from a static manual installation process to a dynamic automated process where the operator station server adapts its certificate requests based on its determined role and lifecycle stage, receiving only necessary certificates at appropriate times.

Inventive Principle:
Principle #15Dynamics

2Reliability

If standard mechanisms monitor all stored certificates for expiry, then certificate security is maintained, but productivity decreases due to unnecessary renewal processes

Engineering Contradiction:
Improvecertificate securityVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of monitoring and renewing all certificates universally, the system applies partial action by monitoring only the specific certificates that are actually required and valid for the operator station server's current role, avoiding unnecessary renewal processes for irrelevant certificates.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The certification service receives feedback about the operator station server's role and actively manages certificate lifecycles based on this information, triggering renewal processes only when necessary for the actual operational requirements rather than following a blanket monitoring approach.

Inventive Principle:
Principle #23Feedback

3Reliability

If dedicated certificates are issued for each communication protocol and partner, then security is improved, but the quantity of certificates increases and management becomes more difficult

Engineering Contradiction:
Improvecommunication securityVSAvoidnumber of certificates
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The operator station server automatically determines which dedicated certificates are needed for its specific communication requirements based on its role, and requests only those specific certificates from the certification authority, avoiding accumulation of unnecessary certificates.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If manual certificate installation and renewal processes are used, then flexibility in certificate selection is maintained, but time consumption and potential for errors increase

Engineering Contradiction:
Improvecertificate selection flexibilityVSAvoidcertificate management time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The operator station server autonomously determines its certificate requirements based on its role and automatically requests the necessary certificates from the certification authority, eliminating manual selection processes while maintaining appropriate flexibility for different operational scenarios.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary determination of certificate requirements based on the operator station server's role before the actual certificate issuance, ensuring that only necessary certificates are requested and installed, thereby preventing time-consuming manual selection and installation processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3605253B1Automated public key infrastructure initialisation
Publication Date: 2023.05.10 SIEMENS AG
  • EP3605253B1 patent drawingFigure 1
  • EP3605253B1 patent drawingFigure 2
  • EP3605253B1 patent drawingFigure 3

AI summary

An operator station server (15, 16) of a technical facility is proposed, on which a certification service (37, 38) is implemented. The certification service (37, 38) is configured and intended to receive configuration information, dependent on a role of the operator station server (15, 16) in the technical facility, from an engineering station server (14) and/or from a registration service (19) of the technical facility. This configuration information includes details of which certificates the certification service (37, 38) of the operator station server (15, 16) must request from a certification authority (20, 23) of the technical facility.