Secure Node Configuration in Process Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Process control systems face security challenges when adding new computers or replacing existing ones, as existing methods lack robust security measures, and pre-loading software is time-consuming and costly, while web technologies pose security risks.

Innovation Solution

A method and device for secure node configuration in process control systems, where a setup control unit activates on the new computer, contacts a configuration control computer, supplies a setup tool identifier, receives node parameter data, and provides the necessary data to make the computer a secure system node, ensuring only authorized computers can join the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-loading software is performed on the computer before joining, then the computer can be configured to join the system, but the process becomes time-consuming and costly

Engineering Contradiction:
Improvesystem securityVSAvoidjoining time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The setup tool is prepared in advance and brought to the computer via portable medium, containing the necessary configuration capabilities. This preliminary preparation enables the computer to be configured on-demand without requiring pre-installation of full software packages, thus reducing both time and cost while maintaining security through controlled configuration delivery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The configuration functionality is extracted from the main system software and placed in a separate setup tool on a portable medium. This extraction allows the computer to receive only the specific configuration data needed for joining, rather than requiring pre-installation of entire software packages, thereby reducing joining time and costs while maintaining security through controlled data transfer.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If web technologies are used for downloading components, then the joining process can be simplified, but security problems arise

Engineering Contradiction:
Improvejoining process simplicityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A setup tool on a portable medium serves as an intermediary between the configuration control computer and the target computer. This intermediary physically carries the configuration data, eliminating the need for web-based downloads while maintaining security. The portable medium acts as a trusted carrier that prevents unauthorized access and ensures data integrity during the configuration process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If unauthorized computers are allowed to access the system, then system flexibility is improved, but security is compromised

Engineering Contradiction:
Improvesystem flexibilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The configuration control computer performs identity verification of the setup tool before providing configuration data. This feedback mechanism ensures that only authorized computers can receive system configuration, maintaining security while allowing flexibility for legitimate additions and replacements. The verification process enables the system to adapt to changes while preventing unauthorized access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9819539B2Joining a computer to a process control system
Publication Date: 2017.11.14 ABB (SCHWEIZ) AG
  • US9819539B2 patent drawing
  • US9819539B2 patent drawing
  • US9819539B2 patent drawing

AI summary

A setup control unit is configured to get activated via a first computer that is to become a node in the process control system and which activation is initiated by a setup tool being brought to the first computer. The setup control unit contacts a configuration control computer, supplies a setup tool identifier to the configuration control computer, accesses system information elements in the configuration control computer, presents system nodes to an operator using the system information elements, receives an operator selection of a system node, sends the node selection to the configuration control computer for registering, based on a setup tool identifier investigation, receives node parameter data associated with the selected system node from the configuration control computer and supplies the first computer with the node parameter data for making it into the selected system node.