Registration Authority Automated Check for Industrial Certificate Issuance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current certificate management in industrial plants leads to the issuance of unnecessary certificates, resulting in increased communication volume, storage requirements, and administrative work, due to the forwarding of superfluous certificate applications and renewals, which can compromise normal operation and availability.
Innovation Solution
Implementing an automated two-stage check system where a plant component verifies if it can use a specific certificate profile and if the profile is needed within the industrial plant before submitting a certificate application to the certification authority, ensuring only valid and required certificates are issued.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the registration authority forwards all certificate applications to the certification authority without checking, then the certificate issuance process is simple and fast, but unnecessary certificates are issued increasing communication volume, storage requirements, and administrative work
Solution Approach 1:
The registration authority performs preliminary checks before forwarding certificate applications to the certification authority. The check determines whether the plant component can actually use the requested certificate profile and whether the profile is needed within the industrial plant based on stored information about automation relationships and component capabilities. This preliminary filtering action prevents unnecessary certificates from being issued in the first place.
2Quantity of substance
If the registration authority performs automated checks to verify certificate profile compatibility and necessity, then unnecessary certificates are prevented from being issued, but the system complexity and processing time increase
Solution Approach 1:
The registration authority automatically performs the checks using information that is already stored in the system about plant automation relationships and component capabilities. The system serves itself by using its own stored data to make authorization decisions, eliminating the need for manual verification and reducing the perceived complexity for users.
Solution Approach 2:
The registration authority acts as an intermediary between the plant component and the certification authority. It mediates the certificate issuance process by filtering applications based on stored information about which components can use which certificate profiles and whether those profiles are actually needed in the plant's automation context.
3Adaptability or versatility
If all plant components request certificates for all possible profiles, then any component can potentially communicate with any partner using any protocol, but communication volume and storage requirements increase significantly
Solution Approach 1:
Instead of giving all plant components all possible certificate profiles universally, the system applies local quality by assigning certificate profiles specifically to individual components based on their actual capabilities and their specific communication needs within the plant's automation relationships. Each component receives only the certificate profiles that are locally appropriate for its function and connections.
Data Source
AI summary
A method for issuing a certificate with a specific certificate profile to a plant component of an industrial plant by a certification authority of the industrial plant, wherein an automated check is performed to determine whether the specific certificate profile can be used by the plant component, and whether the specific certificate profile in the industrial plant is assignable to the plant component before a certificate application made by the plant component is transmitted to the certification authority, where the certificate application is transmitted to the certification authority which, in the event of a successful check of the certificate application, issues the requested certificate with the specific certificate profile for the plant component if both checks are successful.
