PLC Virtual Patching for ICS Security Without Reboots

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial Control Systems (ICS) face challenges in security patching, requiring complete firmware updates and reboots, which can introduce new failures and vulnerabilities, and traditional patch management is manual and limited, increasing risk and cost in live production environments.

Innovation Solution

The implementation of virtual patching and automated distribution of security context information using a system with an industrial automation device, a distributed database, and a virtual patching engine security application that collects system information and applies virtual patches without reloading the software image, providing protection against vulnerabilities until a system upgrade can be performed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual patch management is performed, then patch compatibility can be tested, but productivity deteriorates due to long patch delays and increased operational time

Engineering Contradiction:
Improvepatch compatibilityVSAvoidpatch deployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables preliminary deployment of virtual patches before complete firmware updates are finalized or tested. The virtual patch can be applied immediately upon vulnerability identification, allowing the system to be protected in advance while compatibility testing of the full firmware update occurs in parallel, thereby accelerating overall patch deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial patching by deploying only the essential security fix (virtual patch) without waiting for the complete firmware update package. This partial action provides immediate protection while the remaining firmware components are updated separately, significantly reducing the time to achieve security remediation.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If full system reboot is performed for security patching, then vulnerability is fixed, but loss of time increases due to production downtime

Engineering Contradiction:
Improvevulnerability fixationVSAvoidproduction downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the patching operation so that the critical security fix (virtual patch) can be applied without triggering a full system reboot. By separating the security fix from the complete firmware replacement, the system avoids mandatory downtime while still achieving vulnerability remediation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a virtual copy or representation of the security patch that can be deployed without replacing the actual firmware. This virtual patch copy provides the necessary security protection without requiring the system to undergo a complete firmware update and reboot cycle, thereby eliminating production downtime.

Inventive Principle:
Principle #26Copying

3Reliability

If external security controls are deployed at network level, then additional protection is provided, but device complexity increases and controls are limited by network-level constraints

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity control architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the PLC to self-protect by incorporating the virtual patching engine directly within the device. Instead of relying on external network-level security controls, the PLC autonomously applies security fixes through the virtual patch mechanism, reducing the need for complex external security infrastructure while providing more effective, device-specific protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3475866B1PLC virtual patching and automated distribution of security context
Publication Date: 2024.09.04 SIEMENS AG
  • EP3475866B1 patent drawingFigure 1
  • EP3475866B1 patent drawingFigure 2
  • EP3475866B1 patent drawingFigure 3

AI summary

A system for virtual patching of security vulnerabilities in an industrial production environment includes an industrial automation device (e.g., a PLC). The industrial automation device comprises an instance of a distributed database spanning a plurality of industrial automation devices and storing one or more virtual patches and an app container comprising a virtual patching engine security application. The app container is configured to collect system information generated by the industrial automation device during operation, and apply the one or more virtual patches to the system information to identify one or more security attacks.