Security Group Key Lifetime Control for Multi-Publisher OPC UA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current key management systems in OPC UA publish-subscribe patterns are limited as they can only be used by a single publisher, and the key lifetime is fixed and not dynamically adjustable, making it inefficient for multiple publishers and vulnerable to changes in data transmission rates.

Innovation Solution

A method and device that allow dynamic modification of key lifetimes in a security group based on the bandwidth of added or changed publishers, enabling secure and efficient key management for multiple publishers by adjusting key expiration times according to their data transmission rates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the key lifetime is fixed and defined by a single publisher, then the key management is simple, but the system cannot accommodate multiple publishers with different bandwidth requirements

Engineering Contradiction:
Improvenumber of publishersVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic key lifetime adjustment by allowing the Security Key Service to modify key parameters on-demand. When a new publisher joins or leaves the security group, the SKS dynamically recalculates and updates the key lifetime based on the current set of publishers and their bandwidth requirements, transforming the static key management into a dynamic adaptive system

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the key lifetime parameter dynamically based on the composition of the security group. The SKS calculates the appropriate key lifetime by considering the bandwidth requirements of all publishers in the group and adjusts the key parameters accordingly, allowing the same security group to serve multiple publishers with different data transmission rates

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If multiple publishers are assigned to a single security group, then key management efforts are reduced, but the key lifetime must be fixed to ensure security

Engineering Contradiction:
Improvekey management effortVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the Security Key Service continuously monitors the composition and bandwidth requirements of publishers in the security group. When changes occur (new publishers joining or existing publishers changing bandwidth), the SKS receives feedback and automatically recalculates the appropriate key lifetime to maintain security while supporting multiple publishers

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary calculation of key lifetime by the Security Key Service before keys are distributed to publishers. The SKS proactively determines the appropriate key parameters based on the current security group composition and bandwidth requirements, ensuring security is maintained from the outset while supporting multiple publishers

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If the key lifetime is extended to accommodate multiple publishers, then key management is simplified, but security is compromised due to higher data transmission volume

Engineering Contradiction:
Improvenumber of security groupsVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent dynamically adjusts the key lifetime parameter based on the actual data transmission volume and bandwidth requirements of publishers in the security group. The SKS calculates the appropriate key lifetime by considering the cumulative bandwidth of all publishers, ensuring that keys are renewed at appropriate intervals to maintain security while supporting multiple publishers with different transmission rates

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent transforms the static key lifetime into a dynamic parameter that adapts to the actual usage patterns of the security group. The SKS continuously monitors the data transmission volume and adjusts the key lifetime accordingly, allowing longer lifetimes for low-bandwidth groups while maintaining shorter lifetimes for high-bandwidth groups, thus balancing security and operational simplicity

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12003621B2Method for managing keys of a security group
Publication Date: 2024.06.04 SIEMENS AG
  • US12003621B2 patent drawing
  • US12003621B2 patent drawing
  • US12003621B2 patent drawing

AI summary

A method of adding a first publisher to a security group includes receiving a key request for keys for the first publisher, wherein the key request has at least one credential associated with the first publisher and a key parameter index indicative of a bandwidth of the first publisher, includes modifying a lifetime value of the at least one key of the security group based on the key parameter index of the received key request, wherein an expiry of the at least one key is based on the lifetime value of the one or more keys; and includes transmitting the at least one key and the modified lifetime value of the at least one key to the first publisher, where the first publisher is configured to publish at least one message encrypted using the at least one key, prior to expiry of the at least one key.