Role-Based Security Policy Templates for Industrial Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industrial automation environments, managing security policies for multiple objects is inefficient as individual policies need to be manually configured for each object, leading to tedious and time-consuming processes.

Innovation Solution

Implementing a role-based access control system that allows for the creation of security policy sets for various user types, which can be applied to multiple objects, streamlining the security configuration process by defining allowed actions for user groups and applying these policy sets to objects within the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If individual security policies are manually configured for each object, then security control precision is improved, but configuration time and operational complexity increase significantly

Engineering Contradiction:
Improvesecurity control precisionVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent segments security policies into two levels: template policies that define security rules for object types, and instance policies that apply templates to specific objects. This segmentation allows security administrators to configure policies once at the template level and automatically apply them to multiple objects, reducing configuration time while maintaining precise security control through object-specific customizations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by creating security policy templates in advance that contain pre-defined security rules and settings. These templates are configured once and can be automatically applied to multiple objects of the same type, eliminating the need to manually configure each object individually and significantly reducing configuration time.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If individual security policies are manually configured for each object, then security customization is improved, but device complexity and operational effort increase

Engineering Contradiction:
Improvesecurity customizationVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security configuration system into templates (containing reusable security rules) and object instances (receiving applied policies). This segmentation reduces configuration complexity by allowing administrators to work with standardized templates rather than configuring each object from scratch, while still enabling customization through template selection and modification at the instance level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal security policy templates that can be applied to multiple objects of the same type. These templates serve multiple functions: they define security rules, provide configuration defaults, and enable automatic policy application across numerous objects, thereby reducing operational effort while maintaining security customization through template-based flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If security policies are applied systematically to multiple objects, then productivity is improved, but security policy management complexity increases

Engineering Contradiction:
Improvesecurity configuration efficiencyVSAvoidpolicy management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments policy management into template management and instance management. Template management handles the creation and maintenance of reusable security policy definitions, while instance management handles the application and customization of templates to specific objects. This segmentation improves productivity by enabling bulk policy application while managing complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security policy templates as an intermediary layer between security administrators and individual objects. Templates mediate the policy application process by providing standardized, pre-configured security rules that can be automatically applied to multiple objects, thereby improving productivity while reducing the complexity of direct object-by-object configuration management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9767308B2Custom security policies for multiple objects
Publication Date: 2017.09.19 ROCKWELL AUTOMATION TECH INC
  • US9767308B2 patent drawing
  • US9767308B2 patent drawing
  • US9767308B2 patent drawing

AI summary

Techniques to facilitate controlling access to objects associated with an industrial automation environment are disclosed. In at least one implementation, a policy set associated with an object type is created, wherein the policy set defines one or more actions that are allowed for at least one user group to perform with respect to the object type. An object of the object type is identified for security configuration, and a selection of the policy set associated with the object type to apply to the object is received. In response to the selection of the policy set, security is configured for the object by applying the policy set associated with the object type to the object.