Industrial Security Policy Zoning for Vendor-Neutral Event Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring security for industrial automation environments is time-consuming and prone to human error due to the need for manual, vendor-specific settings across numerous devices, often leading to disabled security features due to complexity.

Innovation Solution

A model-based security policy configuration system that groups industrial devices into security zones using a graphical interface, generating device-specific instructions to enforce security policies, abstracting from vendor-specific complexities and enabling centralized management of security event policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual vendor-specific configuration is used for each industrial device, then security policies can be enforced on individual devices, but the configuration process becomes time-consuming and prone to human error

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the configuration process into two distinct layers: a high-level abstract security policy definition layer and a device-specific implementation layer. The security policy is first defined in vendor-agnostic terms, then automatically translated into device-specific configurations. This segmentation eliminates manual vendor-specific configuration work while maintaining reliable security enforcement across all devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary translation layer that converts abstract security policies into device-specific configurations. This intermediary component acts as a mediator between the high-level security requirements and the vendor-specific device implementations, automatically generating the necessary configuration instructions without requiring manual intervention for each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual vendor-specific configuration is used for each industrial device, then security settings can be applied, but the complexity increases leading to disabled security features

Engineering Contradiction:
Improvesecurity feature activationVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates and maintains an abstract model or template of security policies that can be copied and applied across multiple devices. Instead of manually configuring each device from scratch, the same verified security policy template is instantiated for each device through automatic translation, reducing complexity while ensuring security features remain activated.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements a universal security policy framework that works across multiple vendor-specific devices. The abstract security policy definition is vendor-agnostic and can be applied universally to different device types through automatic translation, eliminating the need for complex vendor-specific configuration procedures while maintaining security feature activation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If centralized management of security policies is implemented, then configuration efficiency improves, but translation to vendor-specific instructions is required

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidtranslation process complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The translation process is designed to be self-service and automated. The system automatically translates abstract security policies into vendor-specific device instructions without requiring manual intervention. The translation component self-manages the complexity of mapping high-level policies to device-specific configurations, improving productivity while containing translation complexity within the automated system.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3907969A1Configuration of security event management in an industrial environment
Publication Date: 2021.11.10 ROCKWELL AUTOMATION TECH INC
  • EP3907969A1 patent drawingFigure 1
  • EP3907969A1 patent drawingFigure 2
  • EP3907969A1 patent drawingFigure 3

AI summary

A model-based industrial security policy configuration system implements a plant-wide industrial asset security policy in accordance with security policy definitions provided by a user. The configuration system models the collection of industrial assets (120i) for which diverse security policies are to be implemented. An interface (114) allows the user to define zone-specific security configuration and event management policies for a plant environment at a high-level based on a security model that groups the industrial assets (114) into security zones. Based on the model and these policy definitions, the system generates asset-level security setting instructions configured to set appropriate device settings on one or more of the industrial assets (120i) to implement the security event management policies, and deploys these instructions to the appropriate assets (120i) in order to implement the defined policies.