Secondary Security Authority for Industrial Control Program Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation environments face challenges in protecting control system content from unauthorized access and usage, as existing solutions do not adequately restrict access to proprietary controller logic and data, potentially leading to system damage or misuse.

Innovation Solution

A dual-layer security authority system is implemented, where a primary security authority defines usage rights for control system content, and a secondary security authority further restricts these rights, allowing machine builders to control access and usage by internal and external users, and enabling end users to impose additional restrictions on proprietary content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single security authority is used to manage access to control system content, then the system is simpler to implement, but it cannot adequately restrict access to proprietary controller logic by both primary and secondary entities

Engineering Contradiction:
Improveprotection of control system contentVSAvoidsecurity authority structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security authority is segmented into two distinct layers: a primary security authority that manages access to control system content and a secondary security authority that manages access to proprietary controller logic. This segmentation allows each authority to independently enforce its own security policies, thereby providing comprehensive protection without requiring a single complex monolithic security system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secondary security authority is nested within the primary security authority structure. The secondary authority inherits the access rights granted by the primary authority and further restricts them for proprietary content. This nested arrangement allows the system to maintain a hierarchical security model where broader access controls are combined with more specific restrictions, achieving both simplicity and comprehensive protection.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Ease of operation

If access rights are broadly granted to enable operational flexibility, then the system is easier to operate, but proprietary data becomes vulnerable to unauthorized access and misuse

Engineering Contradiction:
Improveaccess to control system contentVSAvoidunauthorized access to proprietary data
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Different security restrictions are applied to different types of content within the control system. General operational content is accessible with broader permissions to maintain ease of operation, while proprietary controller logic and confidential data are subject to additional restrictive permissions. This local differentiation of security qualities allows operational flexibility while protecting sensitive areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The secondary security authority acts as an intermediary layer between users and proprietary controller logic. Even when users have broad access rights granted by the primary security authority, the secondary authority intercepts and filters access requests to proprietary content, allowing only authorized operations. This intermediary mechanism prevents unauthorized access while maintaining operational flexibility for non-proprietary content.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple layers of security restrictions are implemented to protect proprietary content, then data protection is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveprotection of proprietary dataVSAvoiddual-layer security authority
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security restrictions are established in advance through the configuration of primary and secondary security authorities before any access requests occur. The secondary authority is pre-configured with knowledge of which content is proprietary and what restrictions apply. This preliminary setup eliminates the need for complex real-time security decisions, reducing processing overhead while maintaining strong protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secondary security authority uses the access rights defined by the primary security authority as a template and creates restricted copies of these rights for proprietary content. Instead of implementing a completely independent security system, the secondary authority copies the primary authority's permission structure and selectively denies specific access rights, thereby simplifying the implementation of multi-layer security while reducing processing complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3098747B1Secondary security authority
Publication Date: 2021.05.26 ROCKWELL AUTOMATION TECH INC
  • EP3098747B1 patent drawingFigure 1
  • EP3098747B1 patent drawingFigure 2
  • EP3098747B1 patent drawingFigure 3

AI summary

Techniques to facilitate protecting control programs used in an industrial automation environment are disclosed herein. In at least one implementation, control system content provided by a primary entity is received along with a primary security authority provided by the primary entity, wherein the primary security authority defines primary usage rights for the control system content granted to a secondary entity. A secondary security authority provided by the secondary entity is received, wherein the secondary security authority defines secondary usage rights for the control system content that further restrict the primary usage rights. A request is received from a user associated with the secondary entity to perform an action associated with the control system content, and the request is processed with the secondary security authority to determine if the user is authorized to perform the action associated with the control system content based on the secondary usage rights.