Runtime Control Applications With Expiration-Based Security Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face security risks due to the prolonged presence of control applications requiring extensive security authorizations, which act as potential attack targets and can lead to undesirable system states due to incomplete or repeated service requests.

Innovation Solution

Implement a system where control applications are executed via runtime control components, each assigned an identifier for security-critical status, with defined expiration conditions, ensuring termination upon condition occurrence, and utilizing a runtime environment for isolation and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control applications requiring extensive security authorizations are installed on automation devices, then the functionality and control capabilities are improved, but the security risks increase due to prolonged presence and potential attack targets

Engineering Contradiction:
Improvecontrol capabilitiesVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic lifecycle management for control applications by introducing expiration conditions and automatic termination mechanisms. Control applications are no longer statically installed but dynamically activated only when needed, with automatic deactivation based on time-based or event-based expiration conditions. This transforms the security model from static long-term installation to dynamic temporary execution, reducing the attack window while maintaining functional capabilities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic monitoring and evaluation of control application execution status against predefined expiration conditions. The runtime environment continuously checks whether control applications should still be active or need termination, creating a periodic security validation mechanism that ensures applications are not present longer than necessary, thereby reducing prolonged security risks.

Inventive Principle:
Principle #19Periodic action

2Ease of operation

If control applications are kept installed for extended periods, then ease of operation is improved, but security risks worsen due to long-term presence of potential attack targets

Engineering Contradiction:
Improveease of operationVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements self-service automation where the runtime environment automatically manages control application lifecycles without manual intervention. Expiration conditions are automatically evaluated, and control applications are automatically terminated when conditions are met. This eliminates the need for operators to manually track and remove applications, maintaining ease of operation while enforcing security through automated lifecycle management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system establishes a feedback loop where the runtime environment continuously monitors control application execution status and compares it against predefined expiration conditions. This feedback mechanism ensures that control applications are terminated at the appropriate time based on objective criteria rather than manual judgment, maintaining operational simplicity while enforcing security constraints.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If control applications are frequently activated and deactivated, then security risks are reduced, but device complexity increases due to lifecycle management requirements

Engineering Contradiction:
Improvesecurity risksVSAvoidlifecycle management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The runtime environment is designed as a universal platform that handles multiple control applications with different expiration conditions through a single unified management mechanism. Rather than requiring separate management systems for each application, the runtime environment provides generic lifecycle management capabilities that work across all control applications, reducing overall system complexity despite the sophisticated security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If runtime environments are used for isolation and monitoring, then security control is improved, but device complexity increases due to virtualization requirements

Engineering Contradiction:
Improvesecurity controlVSAvoidvirtualization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments control applications into isolated runtime environments that are independently managed and terminated based on their specific expiration conditions. This segmentation allows each control application to be controlled individually without affecting others, providing fine-grained security control while using standardized virtualization mechanisms that reduce overall complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12578699B2Method and system for providing control applications for an industrial automation system
Publication Date: 2026.03.17 SIEMENS AG
  • US12578699B2 patent drawing
  • US12578699B2 patent drawing

AI summary

A method for providing control applications, wherein each of the control applications is provided by a flow control component, which is loadable onto a flow control environment formed via a server device and that is executed thereon, where control applications that require selected security authorizations are assigned a respective label as security-critical control applications, at least one respective flow condition is ascertained for the selected security authorizations for the control applications that are assigned a label as a security-critical application, the flow control environment checks for the occurrence of the respective flow condition while the flow control components for the control applications are being executed, and where the execution of each of the flow control components is terminated when the respective flow condition occurs.