Secure Node Configuration in Process Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Process control systems face security challenges when adding new computers or replacing existing ones, as existing methods lack robust security measures, and pre-loading software is time-consuming and costly, while web technologies pose security risks.
Innovation Solution
A method and device for secure node configuration in process control systems, where a setup control unit activates on the new computer, contacts a configuration control computer, supplies a setup tool identifier, receives node parameter data, and provides the necessary data to make the computer a secure system node, ensuring only authorized computers can join the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-loading software is performed on the computer before joining, then the computer can be configured to join the system, but the process becomes time-consuming and costly
Solution Approach 1:
The setup tool is prepared in advance and brought to the computer via portable medium, containing the necessary configuration capabilities. This preliminary preparation enables the computer to be configured on-demand without requiring pre-installation of full software packages, thus reducing both time and cost while maintaining security through controlled configuration delivery.
Solution Approach 2:
The configuration functionality is extracted from the main system software and placed in a separate setup tool on a portable medium. This extraction allows the computer to receive only the specific configuration data needed for joining, rather than requiring pre-installation of entire software packages, thereby reducing joining time and costs while maintaining security through controlled data transfer.
2Ease of operation
If web technologies are used for downloading components, then the joining process can be simplified, but security problems arise
Solution Approach 1:
A setup tool on a portable medium serves as an intermediary between the configuration control computer and the target computer. This intermediary physically carries the configuration data, eliminating the need for web-based downloads while maintaining security. The portable medium acts as a trusted carrier that prevents unauthorized access and ensures data integrity during the configuration process.
3Adaptability or versatility
If unauthorized computers are allowed to access the system, then system flexibility is improved, but security is compromised
Solution Approach 1:
The configuration control computer performs identity verification of the setup tool before providing configuration data. This feedback mechanism ensures that only authorized computers can receive system configuration, maintaining security while allowing flexibility for legitimate additions and replacements. The verification process enables the system to adapt to changes while preventing unauthorized access.
Data Source
AI summary
A setup control unit is configured to get activated via a first computer that is to become a node in the process control system and which activation is initiated by a setup tool being brought to the first computer. The setup control unit contacts a configuration control computer, supplies a setup tool identifier to the configuration control computer, accesses system information elements in the configuration control computer, presents system nodes to an operator using the system information elements, receives an operator selection of a system node, sends the node selection to the configuration control computer for registering, based on a setup tool identifier investigation, receives node parameter data associated with the selected system node from the configuration control computer and supplies the first computer with the node parameter data for making it into the selected system node.


