Authentication Framework for Secure Process Control Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing industrial control systems face challenges in integrating cloud-based components with the Purdue model, leading to complex, disorganized, and insecure data transfer practices, with issues such as hardcoded credentials, unpatched vulnerabilities, and increased latency due to the need for additional security infrastructure.
Innovation Solution
A next-generation process control system architecture utilizing a compute fabric agnostic to physical location, implemented in a shared and virtualized manner, with a transport network that provides secure communication between physical devices and a containerized application layer, enabling flexible and secure control functions without adhering to the Purdue model.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud-based components are integrated with the Purdue model, then system functionality and connectivity are improved, but system security and organization deteriorate due to complex data transfer practices, hardcoded credentials, and unpatched vulnerabilities
Solution Approach 1:
The system segments cloud-based components into isolated containerized units with defined communication interfaces. Each container operates in a controlled environment with restricted access, preventing security vulnerabilities from propagating across the entire system while maintaining individual component functionality and connectivity.
Solution Approach 2:
The patent introduces an intermediary authentication and authorization framework that mediates all communications between cloud-based components and the Purdue model infrastructure. This intermediary layer enforces security policies, manages credentials dynamically, and prevents direct unsecured connections, thereby maintaining both connectivity and security.
2Reliability
If additional security infrastructure is added to protect cloud-based components, then system security is improved, but system latency and complexity increase
Solution Approach 1:
The system performs authentication and authorization actions in advance by establishing security contexts and permissions before actual data transfers occur. Session tokens and access rights are pre-configured and cached, allowing subsequent communications to proceed with minimal security verification overhead, thus reducing latency while maintaining security.
Solution Approach 2:
The authentication and authorization framework operates autonomously within the containerized architecture, with each component self-managing its security credentials and access rights. This self-service approach eliminates the need for centralized security infrastructure that would introduce additional latency, as security decisions are made locally without requiring external intervention.
3Adaptability or versatility
If cloud-based components are integrated into the control system, then system functionality is improved, but system organization deteriorates due to complex and disorganized data transfer practices
Solution Approach 1:
The patent implements a universal containerized architecture that provides standardized interfaces and communication protocols for all cloud-based components. This universal framework handles authentication, authorization, and data transfer consistently across different components, eliminating the need for component-specific integration logic and thereby reducing system organizational complexity while maintaining enhanced functionality.
Data Source
AI summary
An architecture supporting a process control or automation system may include an authentication service which determines whether an entity (e.g., a human, automated, virtual, or physical entity) is the party that/who the entity claims to be, and an authorization service which determines whether a request of the entity to access a resource is allowed or denied. The authentication service provides unique identities of entities and respective security credentials, which may include tokens utilized during authorization. The authorization service authorizes an entity to access a requested resource based on role-based permissions of a role to which the entity is assigned and resource access permissions protecting the requested resource. The role-based permissions and/or the resource access permissions may be respectively scoped to limit or restrict actions, activities, operations, and/or resource access based on specified criteria. Each entity may be authenticated, and each request of an authenticated entity may be respectively authorized.


