Secure ML Deployment for Industrial Device Configuration Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation systems face vulnerabilities in network security threats due to lack of robust security features in communication protocols, making them susceptible to attacks despite isolation from IT networks.

Innovation Solution

A secure deployment management system that establishes direct, secure communication channels between industrial automation devices and a cloud services platform, using microcontroller units and machine learning models to authenticate and manage data transmissions, ensuring continuous security protocols and automated software updates without additional processing tasks on devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols are implemented in industrial automation communication systems, then security against network threats is improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud services platform as an intermediary that handles security protocols, authentication, and encryption/decryption operations. This mediator absorbs the complexity of security implementation from industrial automation devices, allowing them to maintain simple device architectures while still benefiting from robust security through the cloud platform's intermediary services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/security processing approaches at the device level with cloud-based computational security mechanisms. Security operations such as authentication, encryption, and threat detection are substituted from local device processing to remote cloud processing, reducing device complexity while maintaining or enhancing security capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If security operations are performed on configuration data, then security is improved, but processing time and computational resources increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary security operations where the cloud services platform pre-authenticates devices, pre-encrypts configuration data, and pre-establishes secure communication channels before actual data transmission occurs. This preliminary action ensures that when configuration data needs to be updated or transmitted, the security verification is already complete, significantly reducing processing time during critical operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes continuous secure communication channels between the cloud platform and industrial devices, maintaining persistent authenticated sessions. This continuity eliminates the need for repeated security operations on each data transmission, allowing configuration updates to be applied continuously without intermittent security processing delays.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If industrial devices perform additional processing tasks for security, then security is improved, but computing resources and operational efficiency decrease

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts security processing functions from industrial automation devices and relocates them to the cloud services platform. By taking out authentication, encryption, threat detection, and configuration validation operations from the device level and concentrating them in the cloud, the patent eliminates the burden of additional processing tasks on devices, allowing them to focus entirely on their primary operational functions with full security support.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12088553B2Implementing device modifications based on machine learning processes performed within a secure deployment system
Publication Date: 2024.09.10 ROCKWELL AUTOMATION TECH INC
  • US12088553B2 patent drawing
  • US12088553B2 patent drawing
  • US12088553B2 patent drawing

AI summary

A method may include receiving, via a secure deployment management (SDM) system, data associated with operations of an industrial device from a SDM node associated with the industrial device. The data is received via a secure communication channel established by the SDM system with the SDM node and security protocols. The SDM node is communicatively coupled with a machine learning system for sending and receiving data. The machine learning system may generate an updated machine learning model based on the data and a machine learning model representative of expected outputs associated with the operations of the industrial device and generate updated configuration data based on the updated machine learning model. The method may then include receiving the updated configuration data from the SDM node via the secure communication channel and sending the updated configuration data to the industrial device without performing security operations on the updated configuration data.