Remote Access Appliance With Smart Card Authentication for ICS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a growing need for secure remote access to industrial control systems, particularly in critical sectors like power utilities, to reduce the risk of cyber attacks while ensuring secure and convenient access for employees and vendors.

Innovation Solution

A system utilizing hardware-based authentication through secure user authentication, secure interactive remote access, and remote access services, including two-factor and three-factor authentication with smart cards, and a managed Remote-Access Appliance (RAA) for secure machine-to-machine communication, along with technical cybersecurity controls and audit trails.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods are used for remote access, then ease of operation is improved, but security reliability deteriorates due to increased cyber attack risk

Engineering Contradiction:
Improveremote access convenienceVSAvoidcybersecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A remote access appliance serves as an intermediary device between the remote user and the industrial control system. The appliance terminates the remote connection and provides a secure gateway, preventing direct access to the control system while enabling remote operations through a trusted mediation layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Traditional password-based authentication is replaced with hardware-based authentication using secure elements and cryptographic keys. The mechanical/security model shifts from software-based credentials to hardware-anchored cryptographic verification, providing stronger security while maintaining user convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based authentication is implemented, then security reliability is improved, but device complexity increases due to additional authentication components

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic key storage and authentication verification functions are extracted from the main industrial control system and placed in dedicated hardware secure elements within the remote access appliance. This separation reduces the complexity burden on the control system while maintaining strong authentication capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The remote access appliance serves multiple functions: it acts as a VPN endpoint, provides hardware-based authentication, enables session management, and offers a secure gateway to the control system. This multi-functionality consolidates complexity into a single device rather than distributing it across multiple system components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If remote access is enabled for monitoring and maintenance, then productivity is improved, but vulnerability to cyber attacks increases

Engineering Contradiction:
Improveremote monitoring capabilityVSAvoidcyber attack pathway
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system implements preliminary security measures by requiring hardware-based authentication and establishing encrypted communication channels before any remote access is granted. Security controls are pre-configured and enforced at the appliance level, preventing malicious connections before they can reach the control system.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

Secure communication channels and authentication mechanisms are established in advance through the remote access appliance. The appliance pre-configures security policies, cryptographic credentials, and access controls, so that when remote access is needed, the secure pathway is already in place and ready for immediate use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20210377018A1Secure remote access to industrial control systems using hardware based authentication
Publication Date: 2021.12.02 ELECTRIC POWER RES INST INC
  • US20210377018A1 patent drawing
  • US20210377018A1 patent drawing

AI summary

A system and method for secure remote access to an industrial control system using hardware based authentication is provided, comprising secure user authentication, secure interactive remote access or secure machine-to-machine remote access or communication, and remote access services. Secure user authentication comprises two-factor authentication based on smart cards, and secure interactive remote access via a managed remote-access appliance comprises a virtual machine and software that can only be used with a smart card credential.