Centralized Security Event Policy for Industrial Asset Zones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring security for industrial automation environments is challenging due to the need for manual, vendor-specific settings on numerous devices, leading to time-consuming processes and potential human errors, especially when dealing with diverse device vendors and complex network infrastructures.

Innovation Solution

A model-based security policy configuration system that groups industrial devices into security zones using a graphical interface, defines communication policies, and translates these policies into device-specific instructions, abstracting from vendor-specific complexities and enabling centralized management of security event policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual, vendor-specific settings are configured on numerous devices, then security coverage is achieved, but configuration time and human error increase

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a centralized security configuration system that acts as an intermediary between security policies and individual devices. This system translates high-level security policies into device-specific configurations automatically, eliminating the need for manual configuration on each device while maintaining comprehensive security coverage across the industrial automation environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables devices to self-configure by automatically receiving and applying security configurations from the centralized system. Each device can independently implement security settings based on its type and security zone requirements without requiring manual intervention, thereby reducing configuration time and potential human errors.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If manual configuration is performed on each device, then vendor-specific requirements are met, but complexity of management increases

Engineering Contradiction:
Improvevendor-specific configuration capabilityVSAvoidconfiguration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The centralized security configuration system provides a universal platform that can manage multiple vendor-specific device types through a single interface. It automatically adapts security policies to different device vendors and models, maintaining vendor-specific configuration requirements while simplifying overall management complexity through centralized control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts configuration parameters based on device type, vendor, and security zone requirements. By automatically modifying configuration parameters for each device according to its specific characteristics, the system maintains adaptability to vendor-specific requirements while eliminating the need for complex manual configuration management.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If centralized policy management is implemented, then configuration efficiency improves, but system complexity increases

Engineering Contradiction:
Improveconfiguration deployment efficiencyVSAvoidcentralized system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The centralized security configuration system is segmented into distinct functional modules including policy definition, translation engine, device discovery, and configuration deployment. This modular architecture improves configuration deployment efficiency by enabling independent operation of each module while managing system complexity through clear separation of concerns and standardized interfaces between components.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12052137B2Centralized security event generation policy
Publication Date: 2024.07.30 ROCKWELL AUTOMATION TECH INC
  • US12052137B2 patent drawing
  • US12052137B2 patent drawing
  • US12052137B2 patent drawing

AI summary

A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets for which diverse security policies are to be implemented. An interface allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets into security zones. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate device settings on one or more of the industrial assets to implement the security event management policies, and deploys these instructions to the appropriate assets in order to implement the defined policies.