Security Group Key Lifetime Control for Multi-Publisher OPC UA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current key management systems in OPC UA publish-subscribe patterns are limited as they can only be used by a single publisher, and the key lifetime is fixed and not dynamically adjustable, making it inefficient for multiple publishers and vulnerable to changes in data transmission rates.
Innovation Solution
A method and device that allow dynamic modification of key lifetimes in a security group based on the bandwidth of added or changed publishers, enabling secure and efficient key management for multiple publishers by adjusting key expiration times according to their data transmission rates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the key lifetime is fixed and defined by a single publisher, then the key management is simple, but the system cannot accommodate multiple publishers with different bandwidth requirements
Solution Approach 1:
The patent implements dynamic key lifetime adjustment by allowing the Security Key Service to modify key parameters on-demand. When a new publisher joins or leaves the security group, the SKS dynamically recalculates and updates the key lifetime based on the current set of publishers and their bandwidth requirements, transforming the static key management into a dynamic adaptive system
Solution Approach 2:
The patent changes the key lifetime parameter dynamically based on the composition of the security group. The SKS calculates the appropriate key lifetime by considering the bandwidth requirements of all publishers in the group and adjusts the key parameters accordingly, allowing the same security group to serve multiple publishers with different data transmission rates
2Ease of operation
If multiple publishers are assigned to a single security group, then key management efforts are reduced, but the key lifetime must be fixed to ensure security
Solution Approach 1:
The patent implements a feedback mechanism where the Security Key Service continuously monitors the composition and bandwidth requirements of publishers in the security group. When changes occur (new publishers joining or existing publishers changing bandwidth), the SKS receives feedback and automatically recalculates the appropriate key lifetime to maintain security while supporting multiple publishers
Solution Approach 2:
The patent performs preliminary calculation of key lifetime by the Security Key Service before keys are distributed to publishers. The SKS proactively determines the appropriate key parameters based on the current security group composition and bandwidth requirements, ensuring security is maintained from the outset while supporting multiple publishers
3Device complexity
If the key lifetime is extended to accommodate multiple publishers, then key management is simplified, but security is compromised due to higher data transmission volume
Solution Approach 1:
The patent dynamically adjusts the key lifetime parameter based on the actual data transmission volume and bandwidth requirements of publishers in the security group. The SKS calculates the appropriate key lifetime by considering the cumulative bandwidth of all publishers, ensuring that keys are renewed at appropriate intervals to maintain security while supporting multiple publishers with different transmission rates
Solution Approach 2:
The patent transforms the static key lifetime into a dynamic parameter that adapts to the actual usage patterns of the security group. The SKS continuously monitors the data transmission volume and adjusts the key lifetime accordingly, allowing longer lifetimes for low-bandwidth groups while maintaining shorter lifetimes for high-bandwidth groups, thus balancing security and operational simplicity
Data Source
AI summary
A method of adding a first publisher to a security group includes receiving a key request for keys for the first publisher, wherein the key request has at least one credential associated with the first publisher and a key parameter index indicative of a bandwidth of the first publisher, includes modifying a lifetime value of the at least one key of the security group based on the key parameter index of the received key request, wherein an expiry of the at least one key is based on the lifetime value of the one or more keys; and includes transmitting the at least one key and the modified lifetime value of the at least one key to the first publisher, where the first publisher is configured to publish at least one message encrypted using the at least one key, prior to expiry of the at least one key.


