Industrial Security Policy Zoning for Vendor-Neutral Event Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring security for industrial automation environments is time-consuming and prone to human error due to the need for manual, vendor-specific settings across numerous devices, often leading to disabled security features due to complexity.
Innovation Solution
A model-based security policy configuration system that groups industrial devices into security zones using a graphical interface, generating device-specific instructions to enforce security policies, abstracting from vendor-specific complexities and enabling centralized management of security event policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual vendor-specific configuration is used for each industrial device, then security policies can be enforced on individual devices, but the configuration process becomes time-consuming and prone to human error
Solution Approach 1:
The system segments the configuration process into two distinct layers: a high-level abstract security policy definition layer and a device-specific implementation layer. The security policy is first defined in vendor-agnostic terms, then automatically translated into device-specific configurations. This segmentation eliminates manual vendor-specific configuration work while maintaining reliable security enforcement across all devices.
Solution Approach 2:
The patent introduces an intermediary translation layer that converts abstract security policies into device-specific configurations. This intermediary component acts as a mediator between the high-level security requirements and the vendor-specific device implementations, automatically generating the necessary configuration instructions without requiring manual intervention for each device.
2Reliability
If manual vendor-specific configuration is used for each industrial device, then security settings can be applied, but the complexity increases leading to disabled security features
Solution Approach 1:
The system creates and maintains an abstract model or template of security policies that can be copied and applied across multiple devices. Instead of manually configuring each device from scratch, the same verified security policy template is instantiated for each device through automatic translation, reducing complexity while ensuring security features remain activated.
Solution Approach 2:
The patent implements a universal security policy framework that works across multiple vendor-specific devices. The abstract security policy definition is vendor-agnostic and can be applied universally to different device types through automatic translation, eliminating the need for complex vendor-specific configuration procedures while maintaining security feature activation.
3Productivity
If centralized management of security policies is implemented, then configuration efficiency improves, but translation to vendor-specific instructions is required
Solution Approach 1:
The translation process is designed to be self-service and automated. The system automatically translates abstract security policies into vendor-specific device instructions without requiring manual intervention. The translation component self-manages the complexity of mapping high-level policies to device-specific configurations, improving productivity while containing translation complexity within the automated system.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets (120i) for which diverse security policies are to be implemented. An interface (114) allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets (114) into security zones. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate device settings on one or more of the industrial assets (120i) to implement the security event management policies, and deploys these instructions to the appropriate assets (120i) in order to implement the defined policies.