Secure Deployment Management for Industrial Maintenance Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face vulnerabilities in network security, making them susceptible to attacks despite isolation from IT networks, as existing communication systems lack robust security features.

Innovation Solution

A secure deployment management system that establishes direct, secure communication channels between industrial automation devices and a cloud services platform, using microcontroller units and edge computing devices to authenticate connections, deploy software updates, and monitor data transmissions, thereby enhancing security protocols and reducing reliance on individual device security features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct communication channels are established between industrial automation devices and cloud services platform, then security vulnerabilities are reduced and communication integrity is improved, but device complexity and system infrastructure requirements increase

Engineering Contradiction:
Improvecommunication securityVSAvoidsystem infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud services platform as an intermediary between industrial automation devices and external networks. This platform establishes secure communication channels that mediate all data transmissions, eliminating the need for individual devices to implement complex security protocols while maintaining high security standards. The platform handles authentication, encryption, and threat detection centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If security protocols are centralized in the cloud services platform, then individual device security requirements are reduced, but network dependency and communication overhead increase

Engineering Contradiction:
Improvedevice security featuresVSAvoidcommunication efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system performs security authentication, encryption key exchange, and communication channel establishment in advance before actual data transmissions occur. This preliminary setup creates pre-secured pathways that enable efficient subsequent communications without repeated security handshakes, reducing communication overhead while maintaining centralized security management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure communication channels are established for each device, then security is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity protocol robustnessVSAvoidcommunication channel management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cloud services platform implements a universal security architecture that serves multiple devices through a single centralized system. Instead of each device requiring separate security implementations, the platform provides multi-functional security services including authentication, encryption, and threat detection that work across all connected devices, simplifying management while maintaining robust security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12088554B2Coordinating maintenance management operations via a secure deployment system
Publication Date: 2024.09.10 ROCKWELL AUTOMATION TECH INC
  • US12088554B2 patent drawing
  • US12088554B2 patent drawing
  • US12088554B2 patent drawing

AI summary

A method may include receiving, via a secure deployment management (SDM) system, data associated with one or more operations of an industrial device from a secure deployment management (SDM) node associated with the industrial device. The data is received via a secure communication channel established by the SDM system with the SDM node and security protocols. The method also includes sending the data to a computerized maintenance management system (CMMS) container component may perform tasks in conjunction with a computerized maintenance management system (CMMS) process, such that the CMMS container component may communicate with the CMMS process via a first firewall through which the SDM system is incapable of communicating. The SDM system may enable the data associated with the operations to communicate with the SDM node through a second firewall between the SDM system and the SDM node, the second firewall being different from the first firewall.