PLC Trusted Boot Measurement for Firmware Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems, particularly PLCs, face vulnerabilities due to redundant functions and configurations, weak network boundary protection, and lack of secure authentication mechanisms, leading to potential safety hazards from unauthorized access and malicious programs.
Innovation Solution
A method for trusted booting of PLCs using a measurement mechanism, where a chip with trusted functions extends the Flash bus for loading and verifies the integrity of boot information, ensuring a trusted state through self-firmware verification and integrity checks, thereby creating a secure operating environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If standard information network technologies and products are used in industrial control systems, then control functions can be achieved, but security vulnerabilities and redundant functions are introduced
Solution Approach 1:
The patent segments the industrial control system into multiple isolation zones (management network zone, production control network zone, etc.) with dedicated security gateways between them. This segmentation prevents standard network technologies from introducing vulnerabilities across the entire system while maintaining necessary control functions in each zone.
Solution Approach 2:
The patent introduces security gateways as intermediary devices between different network zones and between industrial control devices and standard network technologies. These gateways act as mediators that filter and control data transmission, preventing security vulnerabilities from propagating while allowing control functions to operate.
2Ease of operation
If network boundary protection measures are weakened to allow remote maintenance and diagnosis, then ease of operation improves, but unauthorized access and security hazards increase
Solution Approach 1:
The patent introduces security gateways as intermediary devices between remote maintenance terminals and the industrial control system. These gateways enable remote maintenance operations while filtering and controlling data transmission to prevent unauthorized access and malicious attacks.
Solution Approach 2:
The patent applies different security policies to different network zones and devices. Remote maintenance is allowed in specific zones with appropriate security controls, while critical production control areas maintain stricter protection. This local quality approach enables remote maintenance without compromising overall system security.
3Reliability
If integrity verification of boot information is implemented, then system security improves, but boot time increases
Solution Approach 1:
The patent implements preliminary integrity verification of boot information during the boot process itself, before the full system operates. The security gateway verifies the integrity of boot information using cryptographic algorithms, ensuring system security is established early without significantly delaying subsequent operations.
Data Source
AI summary
The present invention discloses a method for trusted booting of PLC based on a measurement mechanism, comprising the following steps: a step of initializing self firmware verification; a step of reading and computing firmware information about a PLC; a step of checking and storing one by one; and a step of verifying at the operation start stage. In the method of the present invention, a chip with a trusted function is used as a core of hardware computation. The PLC extends a Flash bus for loading by hardware of the method of the present invention. The hardware of the method of the present invention recognizes necessary boot information, verifies the integrity of the boot loader necessary for the PLC system through the integrity check method and ensures that the booted PLC system is in a trusted state. On the basis of ensuring validity and feasibility for the safety of a terminal device, the present invention can build a safe and trusted industrial control system operating environment.


