Secure Association Establishment in Industrial Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial process control and automation systems face challenges in establishing secure communications between components, leading to potential security vulnerabilities and interruptions due to non-deterministic secure channel negotiation times, which can result in lost process data and system instability.

Innovation Solution

The establishment of a secure association between devices using a Connection Policy ahead of a Process Data Policy, ensuring peer authentication and key exchange before deploying the Process Data Policy, thereby reducing negotiation thrashing and minimizing interruptions to process data publications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure channel negotiation is performed between devices in real-time, then security is improved, but system availability deteriorates due to non-deterministic negotiation times and potential interruptions to process data publications

Engineering Contradiction:
ImprovesecurityVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent establishes security associations between devices in advance before actual process data communication begins. This preliminary secure channel setup eliminates the need for real-time negotiation during data publication, thereby maintaining both security and system availability. The pre-established security associations allow immediate secure communication without negotiation thrashing.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If secure association is established before deploying Process Data Policy, then negotiation thrashing is reduced, but device complexity increases due to additional policy management layers

Engineering Contradiction:
Improvenegotiation efficiencyVSAvoidpolicy management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security policy into two distinct components: Connection Policy for establishing security associations, and Process Data Policy for data publication. This segmentation allows each policy to be managed independently with specific optimization - Connection Policy handles peer authentication and key exchange, while Process Data Policy handles data communication. This reduces negotiation thrashing by preventing simultaneous negotiations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If real-time secure channel negotiation is performed, then security updates are achieved, but process data publications are interrupted causing data loss

Engineering Contradiction:
Improvesecurity updatesVSAvoidprocess data loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs security association establishment in advance before process data publications begin. This preliminary action ensures that secure channels are already authenticated and ready when data communication starts, eliminating any interruptions to process data publications. The pre-negotiated security associations provide continuous secure communication without data loss.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3111617B1Apparatus and method for establishing seamless secure communications between components in an industrial control and automation system
Publication Date: 2019.06.12 HONEYWELL INTERNATIONAL INC
  • EP3111617B1 patent drawingFigure 1
  • EP3111617B1 patent drawingFigure 2
  • EP3111617B1 patent drawingFigure 3

AI summary

A method includes establishing (408), using a connection policy at a first device (202, 204, 302, 304, 306), a security association with a second device (202, 204, 302, 304, 306) of an industrial process control and automation system (100). The method also includes, once the security association is established, activating a process data policy at the first device. The security association is established during first and second types of negotiations (406). The process data policy is activated during the second type of negotiation (412) without the first type of negotiation. The second type of negotiation is faster than the first type of negotiation. The connection policy defines a communication channel between the devices using a non-process communication port of the first device. The process data policy defines a communication channel between the devices for real-time industrial process data. The first type of negotiation could include an IKE main mode negotiation, and the second type of negotiation could include an IKE quick mode negotiation.