Security Token Service for Embedded Industrial Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial automation environments face challenges in implementing scalable security solutions that can interoperate with foreign security domains, particularly due to the resource-intensive nature of existing Internet-based technologies like HTTP and SOAP, which are not suitable for small embedded systems with limited processing capabilities.

Innovation Solution

A security token service is integrated within embedded devices or network appliances to authenticate and authorize users, using protocol buffers for message structures and communication, enabling interoperability with foreign security domains through WS-Trust and SAML standards, while remaining scalable for small embedded devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Internet-based technologies like HTTP and SOAP are used for security implementations, then security interoperability and standardization are improved, but resource consumption and processing requirements increase significantly

Engineering Contradiction:
Improvesecurity interoperabilityVSAvoidresource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the essential security functionality from resource-intensive Internet-based technologies and implements a streamlined security token service using protocol buffers. This extraction maintains core security interoperability capabilities while removing unnecessary overhead, enabling deployment on resource-constrained embedded devices without requiring full HTTP/SOAP stacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the communication protocol parameter from XML-based SOAP/HTTP to binary protocol buffers. This parameter change fundamentally reduces processing requirements, memory usage, and energy consumption while maintaining the ability to implement security tokens, claims, and authentication workflows. The binary format enables efficient serialization and deserialization on embedded devices.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If proprietary security solutions are employed within industrial automation environments, then security control and customization are improved, but interoperability with foreign security domains deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidinteroperability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal security token service that can operate both within proprietary industrial automation environments and interoperate with foreign security domains. The service supports multiple token formats and communication protocols, enabling a single implementation to serve both customized security control needs and cross-domain interoperability requirements without requiring separate proprietary solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If standard security specifications like WS-Security and SAML are implemented, then security interoperability is improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity interoperabilityVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs lightweight, efficiently serialized security tokens using protocol buffers instead of complex XML-based SAML/WS-Security implementations. The binary format enables rapid token creation, validation, and processing with minimal computational resources. Security claims and authentication data are encoded in compact binary structures that can be quickly parsed and verified on embedded devices without requiring complex XML parsing libraries.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9386015B2Security model for industrial devices
Publication Date: 2016.07.05 ROCKWELL AUTOMATION TECH INC
  • US9386015B2 patent drawing
  • US9386015B2 patent drawing
  • US9386015B2 patent drawing

AI summary

Systems and/or methods are described relating to a security model that provides interoperability with foreign security domains while remaining scalable to small embedded devices. A security token service is provided, which is configured to issue, renew, and/or validate security tokens in response to a token request. A communication protocol, corresponding message structures, and the security tokens are defined in accordance with protocol buffer definitions.