Secure Runtime Hardware for Cloud-Based Automation Programs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments pose security risks for sensitive industrial automation programs due to unreliable data security and difficulties in porting manufacturer-specific programs to virtual machines, making it challenging to execute these programs securely in public cloud environments.

Innovation Solution

Dedicated computer hardware is provided within a cloud environment, equipped with a secure runtime environment, to execute automation programs, with data exchange occurring in encrypted form, allowing control and monitoring of industrial automation arrangements without revealing the hardware to local access, and enabling secure execution of sensitive information like recipes and instructions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If standard virtual machines on publicly accessible servers are used, then cloud computing resources are utilized, but data security and protection against spying are compromised

Engineering Contradiction:
Improvecloud computing resource utilizationVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the automation program execution into two parts: sensitive operations run on dedicated secure hardware (edge device) while non-sensitive functions run on standard cloud virtual machines. This segmentation allows cloud resource utilization while protecting critical data and algorithms from exposure in public cloud environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A dedicated edge device with secure hardware acts as an intermediary between the public cloud infrastructure and the industrial automation system. This intermediary executes sensitive automation programs in a protected environment while maintaining controlled data exchange with both the cloud and the automation system, preventing direct exposure of sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manufacturer-specific PLC programs are emulated on standard hardware, then cloud deployment is enabled, but security protection against spying is reduced

Engineering Contradiction:
Improvecloud deployment capabilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies different security qualities to different execution environments: dedicated secure hardware with protected runtime environments is used for sensitive manufacturer-specific PLC programs, while standard virtual machines handle less critical functions. This local quality differentiation enables cloud deployment of specialized programs while maintaining appropriate security levels for each type of workloads.

Inventive Principle:
Principle #3Local quality

3Reliability

If automation programs are run on dedicated hardware in cloud environment, then security against spying is enhanced, but device complexity increases

Engineering Contradiction:
Improveprotection against spyingVSAvoidhardware architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The dedicated edge device is designed as a multi-functional platform that can execute various types of automation programs (PLC programs, recipes, instructions) while providing unified security protection. This universal design reduces the need for multiple specialized secure devices, thereby managing complexity while maintaining enhanced security across different automation workloads.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3798878B1System and method for secure execution of an automation program in a cloud computation environment
Publication Date: 2022.11.09 SIEMENS AG
  • EP3798878B1 patent drawing

AI summary

The invention relates to an arrangement and a method for the secure execution of an automation program in a cloud computing environment (CL), wherein the automation program is installed on computer hardware (DHW) in a publicly accessible IT infrastructure, and wherein the computer hardware (DHW) is connected to a cloud server (CS), in particular a server of a cloud computing provider, via a data connection. The computer hardware (DHW) is dedicated hardware for executing the automation program, and the computer hardware (DHW) is equipped with a dedicated runtime environment for the automation program. The data connection and the runtime environment are configured such that the automation program can be transferred to the computer hardware (DHW) and the execution of the automation program can be controlled via the server and the data connection.This arrangement makes it possible to run the automation program and the sensitive information it contains, particularly recipes, instructions, process steps, and the like, in a protected environment, thus providing effective protection against espionage. Furthermore, the dedicated hardware has the advantage of being tailored to an existing automation program, allowing existing programs to run in the cloud or be made available via the cloud without modification, retesting, certification, or other costly adaptation steps.