Authentication Framework for Secure Process Control Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing industrial control systems face challenges in integrating cloud-based components with the Purdue model, leading to complex, disorganized, and insecure data transfer practices, with issues such as hardcoded credentials, unpatched vulnerabilities, and increased latency due to the need for additional security infrastructure.

Innovation Solution

A next-generation process control system architecture utilizing a compute fabric agnostic to physical location, implemented in a shared and virtualized manner, with a transport network that provides secure communication between physical devices and a containerized application layer, enabling flexible and secure control functions without adhering to the Purdue model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based components are integrated with the Purdue model, then system functionality and connectivity are improved, but system security and organization deteriorate due to complex data transfer practices, hardcoded credentials, and unpatched vulnerabilities

Engineering Contradiction:
Improvesystem connectivityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments cloud-based components into isolated containerized units with defined communication interfaces. Each container operates in a controlled environment with restricted access, preventing security vulnerabilities from propagating across the entire system while maintaining individual component functionality and connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication and authorization framework that mediates all communications between cloud-based components and the Purdue model infrastructure. This intermediary layer enforces security policies, manages credentials dynamically, and prevents direct unsecured connections, thereby maintaining both connectivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional security infrastructure is added to protect cloud-based components, then system security is improved, but system latency and complexity increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication and authorization actions in advance by establishing security contexts and permissions before actual data transfers occur. Session tokens and access rights are pre-configured and cached, allowing subsequent communications to proceed with minimal security verification overhead, thus reducing latency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication and authorization framework operates autonomously within the containerized architecture, with each component self-managing its security credentials and access rights. This self-service approach eliminates the need for centralized security infrastructure that would introduce additional latency, as security decisions are made locally without requiring external intervention.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If cloud-based components are integrated into the control system, then system functionality is improved, but system organization deteriorates due to complex and disorganized data transfer practices

Engineering Contradiction:
Improvesystem functionalityVSAvoidsystem organization
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal containerized architecture that provides standardized interfaces and communication protocols for all cloud-based components. This universal framework handles authentication, authorization, and data transfer consistently across different components, eliminating the need for component-specific integration logic and thereby reducing system organizational complexity while maintaining enhanced functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12476973B2Authentication/authorization framework for a process control or automation system
Publication Date: 2025.11.18 FISHER ROSEMOUNT SYST INC
  • US12476973B2 patent drawing
  • US12476973B2 patent drawing
  • US12476973B2 patent drawing

AI summary

An architecture supporting a process control or automation system may include an authentication service which determines whether an entity (e.g., a human, automated, virtual, or physical entity) is the party that/who the entity claims to be, and an authorization service which determines whether a request of the entity to access a resource is allowed or denied. The authentication service provides unique identities of entities and respective security credentials, which may include tokens utilized during authorization. The authorization service authorizes an entity to access a requested resource based on role-based permissions of a role to which the entity is assigned and resource access permissions protecting the requested resource. The role-based permissions and/or the resource access permissions may be respectively scoped to limit or restrict actions, activities, operations, and/or resource access based on specified criteria. Each entity may be authenticated, and each request of an authenticated entity may be respectively authorized.