PLC Trusted Boot Measurement for Firmware Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems, particularly PLCs, face vulnerabilities due to redundant functions and configurations, weak network boundary protection, and lack of secure authentication mechanisms, leading to potential safety hazards from unauthorized access and malicious programs.

Innovation Solution

A method for trusted booting of PLCs using a measurement mechanism, where a chip with trusted functions extends the Flash bus for loading and verifies the integrity of boot information, ensuring a trusted state through self-firmware verification and integrity checks, thereby creating a secure operating environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If standard information network technologies and products are used in industrial control systems, then control functions can be achieved, but security vulnerabilities and redundant functions are introduced

Engineering Contradiction:
Improvecontrol functionVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the industrial control system into multiple isolation zones (management network zone, production control network zone, etc.) with dedicated security gateways between them. This segmentation prevents standard network technologies from introducing vulnerabilities across the entire system while maintaining necessary control functions in each zone.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security gateways as intermediary devices between different network zones and between industrial control devices and standard network technologies. These gateways act as mediators that filter and control data transmission, preventing security vulnerabilities from propagating while allowing control functions to operate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network boundary protection measures are weakened to allow remote maintenance and diagnosis, then ease of operation improves, but unauthorized access and security hazards increase

Engineering Contradiction:
Improveremote maintenanceVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security gateways as intermediary devices between remote maintenance terminals and the industrial control system. These gateways enable remote maintenance operations while filtering and controlling data transmission to prevent unauthorized access and malicious attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different security policies to different network zones and devices. Remote maintenance is allowed in specific zones with appropriate security controls, while critical production control areas maintain stricter protection. This local quality approach enables remote maintenance without compromising overall system security.

Inventive Principle:
Principle #3Local quality

3Reliability

If integrity verification of boot information is implemented, then system security improves, but boot time increases

Engineering Contradiction:
Improvesystem securityVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary integrity verification of boot information during the boot process itself, before the full system operates. The security gateway verifies the integrity of boot information using cryptographic algorithms, ensuring system security is established early without significantly delaying subsequent operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11093258B2Method for trusted booting of PLC based on measurement mechanism
Publication Date: 2021.08.17 SHENYANG INST OF AUTOMATION - CHINESE ACAD OF SCI
  • US11093258B2 patent drawing
  • US11093258B2 patent drawing
  • US11093258B2 patent drawing

AI summary

The present invention discloses a method for trusted booting of PLC based on a measurement mechanism, comprising the following steps: a step of initializing self firmware verification; a step of reading and computing firmware information about a PLC; a step of checking and storing one by one; and a step of verifying at the operation start stage. In the method of the present invention, a chip with a trusted function is used as a core of hardware computation. The PLC extends a Flash bus for loading by hardware of the method of the present invention. The hardware of the method of the present invention recognizes necessary boot information, verifies the integrity of the boot loader necessary for the PLC system through the integrity check method and ensures that the booted PLC system is in a trusted state. On the basis of ensuring validity and feasibility for the safety of a terminal device, the present invention can build a safe and trusted industrial control system operating environment.